Certifications · 10 min read
The Best Cybersecurity Certifications in 2026, Ranked by Cost per Study Hour
By Bilal Tahir · Published · Numbers rechecked yearly
CompTIA Security+ is the best first cybersecurity certification in 2026: $439 and 80-150 study hours buys the credential most often named in analyst job ads. CISSP, at $749 plus five years of experience, is a mid-career purchase and not a starter one.
The short answer
Buy CompTIA Security+ first. The SY0-701 voucher is $439 direct from CompTIA, up from $425 when prices rose across the whole CompTIA line on 29 May 2026 (Total Seminars, June 2026), and it takes 80-150 study hours. Nothing else on this page is named as often in a cybersecurity analyst job posting, and nothing else is an approved DoD 8140 IAT Level II baseline, which is the rule that gates a large share of US federal and defence-contractor security work.
Everything after that is sequencing, not shopping. The order that wastes the least money is: a cheap foundation course if you are starting from zero, Security+ as the credential that clears HR filters, one hands-on certification once you have a job, and CISSP only when you have the five years of paid experience ISC2 requires to convert a pass into an actual certification.
The honest caveat up front: certifications move you past filters, they do not produce offers. The junior end of this market is oversupplied with people holding exactly the certificates below. Budget at least as much time for a documented home lab as you do for any exam, and read how to get in without a degree before you spend anything.
Every cybersecurity certification worth considering, with real 2026 prices
Costs below are the all-in figures from the issuing bodies, not the marketing price. "All-in" means the exam voucher plus the realistic minimum of training you need to pass it; the high end of each range assumes an official bundle rather than free video courses and a $20 practice-exam set.
Two entries deserve an asterisk. The ISC2 Certified in Cybersecurity (CC) used to be free through the One Million Certified in Cybersecurity programme; ISC2 closed new enrolments on 20 May 2026, and holders of unexpired codes have until 31 December 2026 to sit the exam (ISC2, September 2026). After that it is $199 plus a $50 annual maintenance fee. And CySA+ V3 (CS0-003) is on the way out: CompTIA retires the English exam on 22 December 2026 (CompTIA, September 2026), so book V4 if you are starting now.
| Certification | Body | All-in cost | Study hours | Renewal | Buy it when |
|---|---|---|---|---|---|
| Google Cybersecurity Certificate | Google / Coursera | $147-$294 | 132-180 | None | You have no IT background and need vocabulary and labs |
| ISC2 Certified in Cybersecurity (CC) | ISC2 | $199 + $50/yr | 20-40 | 45 CPEs / 3 yrs | You want a proctored credential cheaply before Security+ |
| CompTIA Security+ (SY0-701) | CompTIA | $439-$1,500 | 80-150 | 50 CEUs / 3 yrs | Always. This is the one job ads name |
| CompTIA CySA+ (V4) | CompTIA | $439-$1,600 | 100-180 | 60 CEUs / 3 yrs | You are already in a SOC and want the tier-2 signal |
| HTB Certified Defensive Security Analyst | Hack The Box | $490 | 150-250 | None stated | You want hands-on proof, not another multiple-choice badge |
| CISSP | ISC2 | $900-$5,500 | 150-300 | 120 CPEs / 3 yrs + $135/yr | You have five years of paid domain experience |
| CISM | ISACA | $625-$810 + $50 app fee | 120-200 | 20 CPEs/yr + maintenance fee | You are moving into security management or GRC |
| OSCP / PEN-200 | OffSec | $1,749-$2,749 | 300-600 | None (OSCP+ expires in 3 yrs) | You are committed to offensive security specifically |
| CEH | EC-Council | $950-$1,299 + $100 app fee | 80-120 | $80/yr + 120 ECEs / 3 yrs | A specific employer or contract demands it by name |
Which certification has the best ROI per study hour?
| Certification | All-in cost | Study hours | Reported pay lift | Lift per year | Break-even | Lift per study hour |
|---|---|---|---|---|---|---|
| CKA | $605 | 90 | 10% | $13,405 | 0.5 months | $149 |
| PMP | $1,910 | 150 | 16% | $16,371 | 1.4 months | $109 |
| AWS SAA-C03 | $332 | 115 | 8% | $10,724 | 0.4 months | $93 |
| CISSP | $3,200 | 225 | 15% | $18,600 | 2.1 months | $83 |
| PL-300 | $258 | 65 | 6% | $5,280 | 0.6 months | $81 |
| FRM | $2,500 | 500 | 10% | $40,000 | 0.8 months | $80 |
| CompTIA Security+ | $970 | 115 | 7% | $8,680 | 1.3 months | $75 |
| CFA | $6,510 | 1,050 | 15% | $56,250 | 1.4 months | $54 |
| CPA | $4,900 | 410 | 12% | $11,370 | 5.2 months | $28 |
| Google Data Analytics Certificate | $220 | 210 | 6% | $5,280 | 0.5 months | $25 |
| CFP | $7,100 | 700 | 12% | $13,800 | 6.2 months | $20 |
| Google Cybersecurity Certificate | $220 | 156 | ||||
| SIE and Series 7 | $1,050 | 165 | ||||
| SOA Exam P and FM | $1,520 | 700 |
Source: salaryroadmap.com/tools/roi-calculator/
The table above ranks every certification the site tracks by dollars of reported annual pay lift per hour of study. Read it with two warnings. First, the pay-lift percentages are the credential's own survey figures, and issuing bodies have an obvious incentive. Second, a lift figure applied to a mid-career median flatters any certification that is mostly held by people who were already senior. CISSP holders earn about $168,060 on average in Skillsoft's IT Skills and Salary Report, but they earn it because they have a decade of experience, not because they passed a 100-150 question adaptive exam.
Security+ scores modestly on this metric and is still the right first purchase. Its value is not a raise; it is eligibility. A DoD 8140 IAT Level II requirement is binary - you either hold an approved baseline or your application cannot be forwarded - and no pay-lift percentage captures the difference between being screened out and being screened in.
The Google Cybersecurity Certificate has no reported lift figure at all, which is why it sits in the unranked tail. Google and Coursera report that 75% of US graduates report a positive career outcome within six months (Coursera, September 2026), but that is a self-selected graduate survey from 2022 data, not a compensation study. Treat it as a training purchase, not a credential purchase.
Entry level: Google Cybersecurity, ISC2 CC and Security+
If you have never worked in IT, the cheapest competent start is the Google Cybersecurity Certificate. It is nine courses and 170 hours of instruction at $49 a month after a seven-day trial, so $147 at a three-month pace and $294 at Coursera's suggested six (Coursera, September 2026). It covers frameworks, networking, Linux, SQL, SIEM workflows and introductory Python, and it is explicitly aligned to the Security+ objectives, with a discounted voucher and a dual Credly badge for graduates who pass both.
It is a completion certificate, not a proctored exam. Hiring managers discount it accordingly. Its job is to make the Security+ syllabus legible, and it does that well. The full comparison is in Google Cybersecurity Certificate vs CompTIA Security+.
ISC2 Certified in Cybersecurity is the awkward middle option now that the free programme has closed. At $199 plus a $50 annual fee for a proctored, no-experience-required credential, it is defensible if you want an exam result on your CV in a month. But it appears in far fewer job ads than Security+, so if you can only buy one exam, buy Security+.
Security+ itself is 90 questions in 90 minutes, pass mark 750 on a 100-900 scale, with performance-based simulations first. CompTIA publishes no pass rate. Done cheaply - Professor Messer's free video course, a $20 Jason Dion practice set and a $373-$394 reseller voucher - the whole thing is under $450. Note the clock: CompTIA retires the English SY0-701 exam on 11 June 2027 (CompTIA, September 2026), so a voucher bought today should be used, not shelved.
Mid-level: CySA+, cloud security and the hands-on options
Once you are inside a SOC, the useful certifications change shape. The question stops being "will this get me an interview" and becomes "does this prove I can do tier-2 work".
CySA+ is CompTIA's answer, at the same $439 retail price as Security+ (Total Seminars, June 2026), covering detection, threat intelligence and incident response. Its strongest practical feature is that passing it automatically renews your Security+ for another three years, which removes the CEU treadmill for one cycle. Take V4; V3 English retires 22 December 2026.
Cloud security is where the money moved. Most breaches you will investigate now happen in someone's cloud tenancy, and the cloud engineering track pays comparably. The Google Cloud Cybersecurity Certificate at 94 hours and the Microsoft Cybersecurity Analyst Certificate at 190 hours, which includes a 50% discount voucher for the SC-900 exam, are both cheap ways to attach a named cloud platform to your CV. The IBM Cybersecurity Analyst Certificate at 152 hours is the closest thing to a second opinion on the Google material.
Hack The Box CDSA at $490 is the contrarian pick. It is a practical exam with a written report deliverable, which is closer to the actual job than any multiple-choice paper, and a hiring manager who knows the platform will weight it heavily. A hiring manager who does not will not recognise it at all. That asymmetry is the whole argument for and against it.
Senior: CISSP and CISM
CISSP is the credential most reliably named in security manager, architect and GRC lead postings. The exam is $749 in the Americas and the annual maintenance fee is $135 once certified (ISC2, September 2026). Renewal is 120 CPE credits over three years, minimum 40 a year.
The gate is the point. CISSP requires five years of cumulative paid experience across at least two of the eight domains, reducible to four with an approved degree or credential - and Security+ is on that approved list. Pass without the experience and you are an Associate of ISC2, with six years to earn it and a reduced $50 annual fee. Associate status carries a fraction of the weight, which is why sitting CISSP early is usually a waste of $749.
CISM is the alternative if your trajectory is management rather than architecture. ISACA charges $575 for members and $760 for non-members, plus a one-time $50 application processing fee (ISACA, September 2026). Membership costs enough that joining first is roughly break-even on a single exam. CISM is narrower than CISSP - governance, risk, incident management and programme development - and it is the better fit if you are coming from audit, compliance or IT management rather than from engineering.
Neither is a technical certification. Neither will help you pass a hands-on interview, write a detection rule or triage a live incident. If that is the job you want, spend the money on labs.
The certification order that wastes the least money
- Months 0-3, $0-$294. Google Cybersecurity Certificate, or free equivalents if you are disciplined. Skip this entirely if you already work in IT support or sysadmin.
- Months 3-6, $373-$450. Security+. Use a reseller voucher, Professor Messer's free videos and one paid practice-exam set. Sit the exam within three months of finishing your foundation course, while the material is fresh.
- Months 4-9, $0-$200. The home lab. Wazuh or Security Onion, Sysmon on a Windows VM, real detections mapped to MITRE ATT&CK, written up in a public repository. This is the artefact that separates you from the other applicants holding the same two certificates.
- After your first job, employer-funded. CySA+, a cloud security certification, or HTB CDSA. Employers in this field routinely pay; do not spend your own money here if you can avoid it.
- Year five onwards, $749-$5,500. CISSP or CISM, once the experience requirement is actually satisfied.
That sequence costs roughly $400-$750 of your own money to reach a first security job. Use the ROI calculator with your own salary numbers before buying anything above step two, and the study planner to check the hours fit your week.
What certifications will not do for you
They will not get you hired on their own. This is the part the certification industry does not print. CyberSeek counted 514,359 US cybersecurity job listings in the twelve months to April 2025 (CyberSeek, September 2026), and the headline "skills shortage" is real - but it is concentrated in roles wanting three or more years of hands-on experience. Tier-1 SOC openings draw very large applicant pools, and a large fraction of those applicants hold Security+.
They will not close the pay gap you are imagining either. The BLS median of $129,180 for information security analysts (May 2025) covers engineers and architects as well as analysts (BLS, September 2026). Levels.fyi entry-level security analyst reports sit at a $90,000 median with a 10th percentile of $58,000, and non-metro tier-1 roles are routinely $55,000-$75,000.
They also carry a tail. Security+ needs 50 CEUs and a fee every three years. CISSP needs 120 CPEs and $135 a year, permanently, and lapsing means re-sitting a $749 exam. Four active certifications is a part-time administrative job.
And they expire in a second sense: exam versions retire. SY0-701 goes in June 2027, CySA+ V3 in December 2026. A certification bought as a trophy rather than as a step in a plan will be stale before it has earned anything back.
Courses mentioned
Checked on the provider's page on 16 September 2026. Some links are affiliate links; see the disclosure.
Questions people ask
What is the cheapest cybersecurity certification that employers actually recognise in 2026?
CompTIA Security+ at $439 direct, or $373-$394 through an authorised reseller, is the cheapest credential that is widely named in job postings and accepted as a DoD 8140 IAT Level II baseline. ISC2's Certified in Cybersecurity is cheaper at $199 plus a $50 annual fee, and it is proctored, but it appears in far fewer job ads. The free One Million Certified in Cybersecurity route closed to new enrolments on 20 May 2026, so that arbitrage is gone. Academic vouchers can cut Security+ to roughly half price if you qualify.
Should I take Security+ or CySA+ first as a cybersecurity analyst?
Security+ first, without exception. Both cost $439 retail as of September 2026, but Security+ is the credential HR filters screen for and the one that satisfies DoD 8140 baseline requirements; CySA+ assumes you already understand the material Security+ covers. The useful sequencing detail is that passing CySA+ later automatically renews your Security+ for another three years, so taking CySA+ as your second exam once you are working saves you a full continuing-education cycle. If you are starting CySA+ now, sit V4 rather than V3, which retires in English on 22 December 2026.
Is CISSP worth it without five years of experience?
No. Anyone may sit the $749 exam, but passing without the required five years of paid work across two of the eight domains makes you an Associate of ISC2, not a CISSP. Associate status carries a fraction of the weight in hiring, you still pay a $50 annual fee, and you have six years to accrue the experience before it lapses. One year is waived for a four-year degree or an approved credential such as Security+, bringing it to four years. Spend the $749 on labs, a cloud security certification or a CySA+ voucher instead, and come back to CISSP when the experience is real.
How many cybersecurity certifications do I need to get a first job?
One proctored exam plus evidence. Security+ clears the filter; a documented home lab gets you through the interview. Stacking three entry-level certificates is a common and expensive mistake, because the second and third add almost nothing to a screening decision that has already been made on the first. Employers in this field routinely fund certifications once you are inside, so the certifications worth paying for yourself are the ones that get you the first badge. After that, let your employer buy CySA+, a cloud security credential or Hack The Box CDSA.
Does the Google Cybersecurity Certificate count as a real certification?
Not in the way Security+ does. It is a completion certificate with no proctored exam, no pass rate and no expiry, so hiring managers discount it heavily. Its real value is as training and as a pipeline: the curriculum maps to the Security+ objectives, graduates get a discounted Security+ voucher, and completing both earns a dual credential badge through Credly. At $147-$294 for 170 hours of instruction it is good value as a course. Treat it as the on-ramp to a proctored exam rather than as a destination, and expect very little if you stop there.
Which cybersecurity certification pays the most in 2026?
CISSP, by reported average salary. Skillsoft's IT Skills and Salary Report ranks it sixth among the highest-paying IT certifications worldwide at roughly $168,060 in the US. That figure reflects who holds it rather than what it does: CISSP requires five years of paid experience, so holders are senior by definition. No entry-level certification has a comparable number, and the correct reading of the ranking is that senior security people earn a lot, not that a $749 exam produces a $168,000 salary.
Do cybersecurity certifications expire and what does renewal cost?
Most do. Security+ is valid three years and renews with 50 continuing education units plus a fee of roughly $50 a year, or automatically if you pass a higher CompTIA exam such as CySA+ or SecurityX. CISSP runs a three-year cycle needing 120 CPE credits, minimum 40 a year, plus a $135 annual maintenance fee that also covers ISC2 membership. ISC2 Certified in Cybersecurity costs $50 a year. The Google Cybersecurity Certificate never expires and has no maintenance fee. Budget for the tail before you stack four credentials.
Cite this page
Salary Roadmap, “The Best Cybersecurity Certifications in 2026, Ranked by Cost per Study Hour”, updated 16 September 2026, https://www.salaryroadmap.com/guides/best-certifications-for-cybersecurity-analyst/.
Sources
Every number on this page traces to one of these. Page checked 16 September 2026.
- comptia.org/en-us/certifications/security/
- comptia.org/en-us/certifications/cybersecurity-analyst/
- totalsem.com/comptia-exam-price-change-2026/
- isc2.org/certifications/cissp
- isc2.org/landing/1mcc
- isaca.org/credentialing/cism
- coursera.org/professional-certificates/google-cybersecurity
- bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm
- cyberseek.org/
- skillsoft.com/blog/tech-salaries-climbed-5--thanks-to-skills-and-certifications