Certifications · 10 min read

The Best Cybersecurity Certifications in 2026, Ranked by Cost per Study Hour

By Bilal Tahir · Published · Numbers rechecked yearly

CompTIA Security+ is the best first cybersecurity certification in 2026: $439 and 80-150 study hours buys the credential most often named in analyst job ads. CISSP, at $749 plus five years of experience, is a mid-career purchase and not a starter one.

The short answer

Buy CompTIA Security+ first. The SY0-701 voucher is $439 direct from CompTIA, up from $425 when prices rose across the whole CompTIA line on 29 May 2026 (Total Seminars, June 2026), and it takes 80-150 study hours. Nothing else on this page is named as often in a cybersecurity analyst job posting, and nothing else is an approved DoD 8140 IAT Level II baseline, which is the rule that gates a large share of US federal and defence-contractor security work.

Everything after that is sequencing, not shopping. The order that wastes the least money is: a cheap foundation course if you are starting from zero, Security+ as the credential that clears HR filters, one hands-on certification once you have a job, and CISSP only when you have the five years of paid experience ISC2 requires to convert a pass into an actual certification.

The honest caveat up front: certifications move you past filters, they do not produce offers. The junior end of this market is oversupplied with people holding exactly the certificates below. Budget at least as much time for a documented home lab as you do for any exam, and read how to get in without a degree before you spend anything.

Every cybersecurity certification worth considering, with real 2026 prices

Costs below are the all-in figures from the issuing bodies, not the marketing price. "All-in" means the exam voucher plus the realistic minimum of training you need to pass it; the high end of each range assumes an official bundle rather than free video courses and a $20 practice-exam set.

Two entries deserve an asterisk. The ISC2 Certified in Cybersecurity (CC) used to be free through the One Million Certified in Cybersecurity programme; ISC2 closed new enrolments on 20 May 2026, and holders of unexpired codes have until 31 December 2026 to sit the exam (ISC2, September 2026). After that it is $199 plus a $50 annual maintenance fee. And CySA+ V3 (CS0-003) is on the way out: CompTIA retires the English exam on 22 December 2026 (CompTIA, September 2026), so book V4 if you are starting now.

Cybersecurity certifications by all-in cost and study hours, checked September 2026
CertificationBodyAll-in costStudy hoursRenewalBuy it when
Google Cybersecurity CertificateGoogle / Coursera$147-$294132-180NoneYou have no IT background and need vocabulary and labs
ISC2 Certified in Cybersecurity (CC)ISC2$199 + $50/yr20-4045 CPEs / 3 yrsYou want a proctored credential cheaply before Security+
CompTIA Security+ (SY0-701)CompTIA$439-$1,50080-15050 CEUs / 3 yrsAlways. This is the one job ads name
CompTIA CySA+ (V4)CompTIA$439-$1,600100-18060 CEUs / 3 yrsYou are already in a SOC and want the tier-2 signal
HTB Certified Defensive Security AnalystHack The Box$490150-250None statedYou want hands-on proof, not another multiple-choice badge
CISSPISC2$900-$5,500150-300120 CPEs / 3 yrs + $135/yrYou have five years of paid domain experience
CISMISACA$625-$810 + $50 app fee120-20020 CPEs/yr + maintenance feeYou are moving into security management or GRC
OSCP / PEN-200OffSec$1,749-$2,749300-600None (OSCP+ expires in 3 yrs)You are committed to offensive security specifically
CEHEC-Council$950-$1,299 + $100 app fee80-120$80/yr + 120 ECEs / 3 yrsA specific employer or contract demands it by name

Source: totalsem.com/comptia-exam-price-change-2026/

Which certification has the best ROI per study hour?

Certification return per study hour, ranked. Cost and hours are mid-points of the all-in ranges on each certification page; pay lift is the percentage in our ROI inputs applied to the mid-career median of the career the credential most serves. A blank lift column means no credible published premium exists, not zero. Checked September 2026.
CertificationAll-in costStudy hoursReported pay liftLift per yearBreak-evenLift per study hour
CKA$6059010%$13,4050.5 months$149
PMP$1,91015016%$16,3711.4 months$109
AWS SAA-C03$3321158%$10,7240.4 months$93
CISSP$3,20022515%$18,6002.1 months$83
PL-300$258656%$5,2800.6 months$81
FRM$2,50050010%$40,0000.8 months$80
CompTIA Security+$9701157%$8,6801.3 months$75
CFA$6,5101,05015%$56,2501.4 months$54
CPA$4,90041012%$11,3705.2 months$28
Google Data Analytics Certificate$2202106%$5,2800.5 months$25
CFP$7,10070012%$13,8006.2 months$20
Google Cybersecurity Certificate$220156
SIE and Series 7$1,050165
SOA Exam P and FM$1,520700

Source: salaryroadmap.com/tools/roi-calculator/

The table above ranks every certification the site tracks by dollars of reported annual pay lift per hour of study. Read it with two warnings. First, the pay-lift percentages are the credential's own survey figures, and issuing bodies have an obvious incentive. Second, a lift figure applied to a mid-career median flatters any certification that is mostly held by people who were already senior. CISSP holders earn about $168,060 on average in Skillsoft's IT Skills and Salary Report, but they earn it because they have a decade of experience, not because they passed a 100-150 question adaptive exam.

Security+ scores modestly on this metric and is still the right first purchase. Its value is not a raise; it is eligibility. A DoD 8140 IAT Level II requirement is binary - you either hold an approved baseline or your application cannot be forwarded - and no pay-lift percentage captures the difference between being screened out and being screened in.

The Google Cybersecurity Certificate has no reported lift figure at all, which is why it sits in the unranked tail. Google and Coursera report that 75% of US graduates report a positive career outcome within six months (Coursera, September 2026), but that is a self-selected graduate survey from 2022 data, not a compensation study. Treat it as a training purchase, not a credential purchase.

Entry level: Google Cybersecurity, ISC2 CC and Security+

If you have never worked in IT, the cheapest competent start is the Google Cybersecurity Certificate. It is nine courses and 170 hours of instruction at $49 a month after a seven-day trial, so $147 at a three-month pace and $294 at Coursera's suggested six (Coursera, September 2026). It covers frameworks, networking, Linux, SQL, SIEM workflows and introductory Python, and it is explicitly aligned to the Security+ objectives, with a discounted voucher and a dual Credly badge for graduates who pass both.

It is a completion certificate, not a proctored exam. Hiring managers discount it accordingly. Its job is to make the Security+ syllabus legible, and it does that well. The full comparison is in Google Cybersecurity Certificate vs CompTIA Security+.

ISC2 Certified in Cybersecurity is the awkward middle option now that the free programme has closed. At $199 plus a $50 annual fee for a proctored, no-experience-required credential, it is defensible if you want an exam result on your CV in a month. But it appears in far fewer job ads than Security+, so if you can only buy one exam, buy Security+.

Security+ itself is 90 questions in 90 minutes, pass mark 750 on a 100-900 scale, with performance-based simulations first. CompTIA publishes no pass rate. Done cheaply - Professor Messer's free video course, a $20 Jason Dion practice set and a $373-$394 reseller voucher - the whole thing is under $450. Note the clock: CompTIA retires the English SY0-701 exam on 11 June 2027 (CompTIA, September 2026), so a voucher bought today should be used, not shelved.

Mid-level: CySA+, cloud security and the hands-on options

Once you are inside a SOC, the useful certifications change shape. The question stops being "will this get me an interview" and becomes "does this prove I can do tier-2 work".

CySA+ is CompTIA's answer, at the same $439 retail price as Security+ (Total Seminars, June 2026), covering detection, threat intelligence and incident response. Its strongest practical feature is that passing it automatically renews your Security+ for another three years, which removes the CEU treadmill for one cycle. Take V4; V3 English retires 22 December 2026.

Cloud security is where the money moved. Most breaches you will investigate now happen in someone's cloud tenancy, and the cloud engineering track pays comparably. The Google Cloud Cybersecurity Certificate at 94 hours and the Microsoft Cybersecurity Analyst Certificate at 190 hours, which includes a 50% discount voucher for the SC-900 exam, are both cheap ways to attach a named cloud platform to your CV. The IBM Cybersecurity Analyst Certificate at 152 hours is the closest thing to a second opinion on the Google material.

Hack The Box CDSA at $490 is the contrarian pick. It is a practical exam with a written report deliverable, which is closer to the actual job than any multiple-choice paper, and a hiring manager who knows the platform will weight it heavily. A hiring manager who does not will not recognise it at all. That asymmetry is the whole argument for and against it.

Senior: CISSP and CISM

CISSP is the credential most reliably named in security manager, architect and GRC lead postings. The exam is $749 in the Americas and the annual maintenance fee is $135 once certified (ISC2, September 2026). Renewal is 120 CPE credits over three years, minimum 40 a year.

The gate is the point. CISSP requires five years of cumulative paid experience across at least two of the eight domains, reducible to four with an approved degree or credential - and Security+ is on that approved list. Pass without the experience and you are an Associate of ISC2, with six years to earn it and a reduced $50 annual fee. Associate status carries a fraction of the weight, which is why sitting CISSP early is usually a waste of $749.

CISM is the alternative if your trajectory is management rather than architecture. ISACA charges $575 for members and $760 for non-members, plus a one-time $50 application processing fee (ISACA, September 2026). Membership costs enough that joining first is roughly break-even on a single exam. CISM is narrower than CISSP - governance, risk, incident management and programme development - and it is the better fit if you are coming from audit, compliance or IT management rather than from engineering.

Neither is a technical certification. Neither will help you pass a hands-on interview, write a detection rule or triage a live incident. If that is the job you want, spend the money on labs.

The certification order that wastes the least money

  1. Months 0-3, $0-$294. Google Cybersecurity Certificate, or free equivalents if you are disciplined. Skip this entirely if you already work in IT support or sysadmin.
  2. Months 3-6, $373-$450. Security+. Use a reseller voucher, Professor Messer's free videos and one paid practice-exam set. Sit the exam within three months of finishing your foundation course, while the material is fresh.
  3. Months 4-9, $0-$200. The home lab. Wazuh or Security Onion, Sysmon on a Windows VM, real detections mapped to MITRE ATT&CK, written up in a public repository. This is the artefact that separates you from the other applicants holding the same two certificates.
  4. After your first job, employer-funded. CySA+, a cloud security certification, or HTB CDSA. Employers in this field routinely pay; do not spend your own money here if you can avoid it.
  5. Year five onwards, $749-$5,500. CISSP or CISM, once the experience requirement is actually satisfied.

That sequence costs roughly $400-$750 of your own money to reach a first security job. Use the ROI calculator with your own salary numbers before buying anything above step two, and the study planner to check the hours fit your week.

What certifications will not do for you

They will not get you hired on their own. This is the part the certification industry does not print. CyberSeek counted 514,359 US cybersecurity job listings in the twelve months to April 2025 (CyberSeek, September 2026), and the headline "skills shortage" is real - but it is concentrated in roles wanting three or more years of hands-on experience. Tier-1 SOC openings draw very large applicant pools, and a large fraction of those applicants hold Security+.

They will not close the pay gap you are imagining either. The BLS median of $129,180 for information security analysts (May 2025) covers engineers and architects as well as analysts (BLS, September 2026). Levels.fyi entry-level security analyst reports sit at a $90,000 median with a 10th percentile of $58,000, and non-metro tier-1 roles are routinely $55,000-$75,000.

They also carry a tail. Security+ needs 50 CEUs and a fee every three years. CISSP needs 120 CPEs and $135 a year, permanently, and lapsing means re-sitting a $749 exam. Four active certifications is a part-time administrative job.

And they expire in a second sense: exam versions retire. SY0-701 goes in June 2027, CySA+ V3 in December 2026. A certification bought as a trophy rather than as a step in a plan will be stale before it has earned anything back.

Courses mentioned

Coursera · GoogleGoogle Cybersecurity Professional Certificate170 h · $49/mo after 7-day free trial (most finish under $300); included in Coursera Plus ($59/mo or $399/yr) · ★ 4.8The largest entry-level security program by a wide margin (1.6M learners, 4.8 rating) and it targets the SOC analyst role specifically rather than generic security theory.Coursera · IBMIBM Cybersecurity Analyst Professional Certificate152 h · Free to enroll; certificate included in Coursera Plus ($59/mo or $399/yr) · ★ 4.6Fourteen courses that explicitly prepare for CompTIA Security+, the certification most US security job postings name, plus ACE credit for up to 10 credits.Coursera · MicrosoftMicrosoft Cybersecurity Analyst Professional Certificate190 h · Free to enroll; includes 50% discount voucher for the SC-900 exam; included in Coursera Plus ($59/mo or $399/yr) · ★ 4.7Most corporate security teams run on Microsoft tooling; this is the only major cert built around Azure AD and Defender with an SC-900 exam discount included.Coursera · Google CloudGoogle Cloud Cybersecurity Professional Certificate94 h · Free to enroll; included in Coursera Plus ($59/mo or $399/yr) · ★ 4.5Cloud security analysts out-earn on-prem SOC analysts; this 94-hour cert is the shortest bridge between the two if you already hold a general security cert.other · ISC2Certified in Cybersecurity (CC)Self-paced training in 90-day or 180-day access bundles; exam fee and bundle pricing quoted at registration (unverified on the certification page)The only entry-level certification from ISC2, the body behind CISSP, and it requires no work experience, so it is the credential to hold while you build toward CISSP.

Checked on the provider's page on 16 September 2026. Some links are affiliate links; see the disclosure.

Questions people ask

What is the cheapest cybersecurity certification that employers actually recognise in 2026?

CompTIA Security+ at $439 direct, or $373-$394 through an authorised reseller, is the cheapest credential that is widely named in job postings and accepted as a DoD 8140 IAT Level II baseline. ISC2's Certified in Cybersecurity is cheaper at $199 plus a $50 annual fee, and it is proctored, but it appears in far fewer job ads. The free One Million Certified in Cybersecurity route closed to new enrolments on 20 May 2026, so that arbitrage is gone. Academic vouchers can cut Security+ to roughly half price if you qualify.

Should I take Security+ or CySA+ first as a cybersecurity analyst?

Security+ first, without exception. Both cost $439 retail as of September 2026, but Security+ is the credential HR filters screen for and the one that satisfies DoD 8140 baseline requirements; CySA+ assumes you already understand the material Security+ covers. The useful sequencing detail is that passing CySA+ later automatically renews your Security+ for another three years, so taking CySA+ as your second exam once you are working saves you a full continuing-education cycle. If you are starting CySA+ now, sit V4 rather than V3, which retires in English on 22 December 2026.

Is CISSP worth it without five years of experience?

No. Anyone may sit the $749 exam, but passing without the required five years of paid work across two of the eight domains makes you an Associate of ISC2, not a CISSP. Associate status carries a fraction of the weight in hiring, you still pay a $50 annual fee, and you have six years to accrue the experience before it lapses. One year is waived for a four-year degree or an approved credential such as Security+, bringing it to four years. Spend the $749 on labs, a cloud security certification or a CySA+ voucher instead, and come back to CISSP when the experience is real.

How many cybersecurity certifications do I need to get a first job?

One proctored exam plus evidence. Security+ clears the filter; a documented home lab gets you through the interview. Stacking three entry-level certificates is a common and expensive mistake, because the second and third add almost nothing to a screening decision that has already been made on the first. Employers in this field routinely fund certifications once you are inside, so the certifications worth paying for yourself are the ones that get you the first badge. After that, let your employer buy CySA+, a cloud security credential or Hack The Box CDSA.

Does the Google Cybersecurity Certificate count as a real certification?

Not in the way Security+ does. It is a completion certificate with no proctored exam, no pass rate and no expiry, so hiring managers discount it heavily. Its real value is as training and as a pipeline: the curriculum maps to the Security+ objectives, graduates get a discounted Security+ voucher, and completing both earns a dual credential badge through Credly. At $147-$294 for 170 hours of instruction it is good value as a course. Treat it as the on-ramp to a proctored exam rather than as a destination, and expect very little if you stop there.

Which cybersecurity certification pays the most in 2026?

CISSP, by reported average salary. Skillsoft's IT Skills and Salary Report ranks it sixth among the highest-paying IT certifications worldwide at roughly $168,060 in the US. That figure reflects who holds it rather than what it does: CISSP requires five years of paid experience, so holders are senior by definition. No entry-level certification has a comparable number, and the correct reading of the ranking is that senior security people earn a lot, not that a $749 exam produces a $168,000 salary.

Do cybersecurity certifications expire and what does renewal cost?

Most do. Security+ is valid three years and renews with 50 continuing education units plus a fee of roughly $50 a year, or automatically if you pass a higher CompTIA exam such as CySA+ or SecurityX. CISSP runs a three-year cycle needing 120 CPE credits, minimum 40 a year, plus a $135 annual maintenance fee that also covers ISC2 membership. ISC2 Certified in Cybersecurity costs $50 a year. The Google Cybersecurity Certificate never expires and has no maintenance fee. Budget for the tail before you stack four credentials.

Cite this page

Salary Roadmap, “The Best Cybersecurity Certifications in 2026, Ranked by Cost per Study Hour”, updated 16 September 2026, https://www.salaryroadmap.com/guides/best-certifications-for-cybersecurity-analyst/.

Sources

Every number on this page traces to one of these. Page checked 16 September 2026.

  1. comptia.org/en-us/certifications/security/
  2. comptia.org/en-us/certifications/cybersecurity-analyst/
  3. totalsem.com/comptia-exam-price-change-2026/
  4. isc2.org/certifications/cissp
  5. isc2.org/landing/1mcc
  6. isaca.org/credentialing/cism
  7. coursera.org/professional-certificates/google-cybersecurity
  8. bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm
  9. cyberseek.org/
  10. skillsoft.com/blog/tech-salaries-climbed-5--thanks-to-skills-and-certifications