If you want the short answer: get CompTIA Security+ first. It is the one entry-level certification that shows up in job postings across commercial, federal, and defense contractor hiring, it satisfies DoD 8140 for a whole tier of cleared jobs, and as of 2026 it costs roughly $439 for the exam voucher. Everything else on this list is either a cheaper warm-up (ISC2 CC), a role-specific second cert (CySA+, CCNA), or a knowledge supplement that hiring managers treat as nice-to-have (Google, SC-900).
I rank these by one thing: how often the cert unlocks an actual interview. I am a DoD ISSO, I watch who gets hired onto DoD programs, and I have seen a resume with Security+ and a home lab beat a resume with four vendor badges and no lab. Here is the ranking, with approximate costs, honest time estimates, and where each one leads.
The ranking at a glance
- 1. CompTIA Security+ (SY0-701): the default. Roughly $439 as of 2026, 6 to 10 weeks of study from zero, required or preferred in nearly every entry-level posting I see, and a DoD 8140 baseline qualifier.
- 2. ISC2 Certified in Cybersecurity (CC): the on-ramp. $199 exam as of 2026 (the free program ended in May 2026), 2 to 4 weeks, respected by federal hiring, weak on its own in commercial postings.
- 3. CompTIA CySA+ (CS0-003): the SOC analyst multiplier. Roughly $425, 6 to 10 weeks after Security+, appears in blue-team and DoD analyst postings.
- 4. Cisco CCNA (200-301): the network foundation. Roughly $300, 8 to 16 weeks, wins network security and infrastructure roles rather than pure security ones.
- 5. Microsoft SC-900 and AZ-900: the cheap cloud literacy signal. Roughly $99 each, 1 to 2 weeks apiece, useful as a second line on a resume, rarely a requirement.
- 6. Google Cybersecurity Professional Certificate: the structured course. Roughly $49 a month on Coursera, 3 to 6 months, good for learning, not a hiring filter by itself.
The six certifications, in detail
1. CompTIA Security+: the one you actually need
Security+ is ranked first because it is the cert that job posting filters are written around. It covers general security concepts, threats and vulnerabilities, architecture, operations, and governance at a level that proves you speak the language without proving you can do any one job well. That is exactly what an entry-level filter is supposed to test.
The DoD angle is where it becomes non-negotiable. Under DoD 8140, a large share of cleared cybersecurity work roles accept Security+ as the baseline qualification, which means a contractor cannot legally seat you on the contract without it or an equivalent. When I onboard a new junior on my program, the first question from our facility security officer is not about their degree. It is “do they have their 8140 cert yet.” If you are aiming at the cleared route, read which certifications qualify you under DoD 8140 before you spend a dollar on anything else.
Cost as of 2026 is roughly $439 for the voucher, less if you catch a CompTIA student discount or a bundle. Study time from zero IT background runs 6 to 10 weeks at an hour or two a day. If you already do help desk or sysadmin work, 4 weeks is realistic. I laid out the week-by-week plan in the Security+ SY0-701 eight-week study plan, and the one piece of advice that matters is to take a full-length practice exam by week three, before you feel ready. Feeling ready is not a data point. A practice score is.
2. ISC2 Certified in Cybersecurity (CC): the cheapest credible start
The CC is the entry-level cert from the organization that runs the CISSP, and that association is the bulk of its value. It covers the same ground as Security+ at a lighter depth. ISC2 ran a free “One Million Certified in Cybersecurity” program for a few years; that ended in May 2026, and as of this writing the exam is $199 plus an annual maintenance fee of roughly $50.
Who should take it: someone who has never studied security formally and wants a confidence win in 2 to 4 weeks before committing to Security+. Federal HR specialists recognize the ISC2 name, and I have seen CC listed as an acceptable alternative on a few GS-2210 announcements. Who should skip it: anyone with IT experience who can go straight to Security+.
3. CompTIA CySA+: the second cert for SOC and analyst jobs
CySA+ (Cybersecurity Analyst+) is what you take after Security+ when your target is a SOC, threat detection, or vulnerability management role. It covers log analysis, threat intelligence, vulnerability scanning and prioritization, and incident response in more depth than Security+, and the performance-based questions expect you to read actual output: Nessus results, packet captures, log lines. Cost is roughly $425 as of 2026. Study time is 6 to 10 weeks if you have Security+ already, longer if you have never looked at a SIEM.
CySA+ also sits on the DoD 8140 lists at a higher tier than Security+, which matters for cleared analyst roles at the Cybersecurity Service Provider (CSSP) level. I would not make it a first cert; it assumes vocabulary that Security+ teaches.
4. Cisco CCNA: the network foundation that security people underrate
The CCNA is not a security certification, and that is exactly why it is on this list. Roughly half of the entry-level “security” mistakes I see from new analysts are networking gaps: not knowing what a subnet boundary means for a scan, or why a firewall rule with “any” in the source field is a finding. CCNA fixes that in one credential.
Cost is roughly $300 as of 2026. Study time is the longest on this list, 8 to 16 weeks, because the subnetting and the CLI work do not compress. If your target has “network” or “engineer” in the title, CCNA is worth the extra weeks; if it is analyst or GRC, Security+ then CySA+ is shorter.
5. Microsoft SC-900 and AZ-900: cheap, fast, and honestly optional
SC-900 (Security, Compliance, and Identity Fundamentals) and AZ-900 (Azure Fundamentals) are roughly $99 each as of 2026 and take one to two weeks apiece. They are multiple choice, they are not hard, and they will not be the reason you get hired. So why list them? Because a growing share of enterprise and federal environments run on Microsoft identity, and a resume that shows you know what Entra ID, conditional access, and Defender are reads as more current than one that does not. Treat them as a second line under Security+, not a substitute for it.
6. Google Cybersecurity Professional Certificate: a course, not a credential
The Google certificate on Coursera is a well-built eight-course sequence covering security fundamentals, Linux, SQL, Python basics, SIEM tools, and incident response. It costs roughly $49 a month as of 2026 and takes 3 to 6 months at a normal pace. As a learning product it is good. As a hiring credential it is weak, because it is not proctored, it is not on the DoD 8140 lists, and applicant tracking systems do not key on it.
Use it as a structured curriculum while you study for Security+ (Google bundles a voucher discount). Do not make it the only line on your resume. Pair it, do not lead with it.
How to choose based on the job you want
Certs are tools, and the right one depends on the door you are trying to open. Here is how I would sequence them by target role.
- SOC analyst or detection engineer: Security+, then CySA+, with a Wazuh or Splunk home lab in between. Total cost roughly $865 in exams, 4 to 6 months.
- GRC analyst or DoD ISSO: Security+, then start reading NIST 800-53 and the RMF process instead of buying another cert. The second cert on this path is CISSP or CAP down the road, not CySA+.
- Network security or infrastructure: CCNA first, Security+ second (or in parallel). This is the one path where Security+ can wait a few months.
- Federal or cleared work of any kind: Security+ before anything else, because the contract requires it. Then whatever the role calls for.
If you are still deciding whether to aim high early, the Security+ versus CISSP comparison explains why the CISSP is a five-year-experience cert and why chasing it first wastes time you could spend getting hired.
Where the cleared route changes the math
One paragraph on the thing I know best. In the DoD contractor world, the cert is not a preference, it is a compliance requirement, and that flips the usual dynamic. A commercial employer weighs Security+ against your portfolio and your interview. A defense contractor with an open seat on a contract needs someone who is 8140-qualified and clearable, and if you are both, your lack of a degree or a long resume matters far less. I have watched candidates with Security+, two years of IT, and a clean record get sponsored for a Secret clearance and start above what commercial entry-level roles pay. The adjudication wait is real, but the cert is what gets you into the queue. My earlier post on the federal and DoD route into cybersecurity covers who actually sponsors new people.
Study materials that are worth the money
For anyone whose long game is the DoD ISSO or GRC path, it is worth knowing what the top of the ladder looks like even while you study for the bottom rung. The ISC2 CISSP Official Study Guide is the standard text for the CISSP, and skimming its risk management and security governance chapters while you prepare for Security+ will make the Security+ governance domain click faster. Do not buy it to take the CISSP next year. Buy it, if at all, to understand where the vocabulary you are memorizing eventually leads.
Common mistakes with entry-level certs
- Collecting badges instead of building a lab. Three fundamentals certs and no hands-on project reads as someone who likes tests.
- Taking CySA+ or CCNA first because they sound more serious. The filter is Security+. Pass the filter, then specialize.
- Letting a cert expire. Security+ and CySA+ need continuing education units every three years. A lapsed Security+ on a DoD contract is a same-week problem for your program manager.
The realistic timeline from zero
Here is what I tell career changers who message me on TikTok. Month one: ISC2 CC if you need a confidence win, otherwise start Security+ directly. Months two and three: Security+, with a small home lab running alongside it. Month four: apply everywhere, including cleared roles that say “must be able to obtain a clearance,” while starting CySA+ or CCNA depending on your target. Months five and six: interviews and a first offer. The full version of that schedule, including what to do each week, is in the six-month plan for getting a cybersecurity job with no experience.
Certifications do not get you hired. They get you past the first screen so that the rest of your preparation can. Pick Security+, set the exam date this week, and build the rest of your plan around it. If you want that plan already written out month by month, with the cert schedule, the lab, and the application cadence in one place, that is what Zero to Hired is for.
As an Amazon Associate, RMF Insider earns from qualifying purchases.

Leave a Reply