Hardenstep
Menu

ISC2 · CompTIA · ISACA — read 24 September 2026

Which layer are you actually defending?

Security certifications are sold as a ladder and bought as a lottery ticket. They are neither. Each one trains you to hold one ring of a system, and the only useful question is which ring you are standing on this year — so that is how this site is organised.

Five layers, five different jobs

A certification is not a rank. Each one trains you to hold one ring of a system, and the question that matters is which ring you are standing on this year.

  1. Governancepolicy, risk, who answers for itTrained for by CISM, CISSP
  2. Architecturehow the system is put togetherTrained for by CISSP, CCSP
  3. Operationsmonitoring, response, day to dayTrained for by Security+, CC
  4. Offensivefinding it before somebody elseTrained for by OSCP, CEH
  5. The assetthe data everything else guardsNo certification defends this — it is what the other four are for

Start from the ring, not the résumé

Pick the certification that matches the work you are doing or moving into, not the one with the biggest reputation. A governance credential will not make you better at incident response, and a hands-on lab subscription will not get you through a risk committee. Every page here begins by naming the layer, then names the credential that trains for it.

That framing does something useful to the money question too. Once you know which ring you are on, most of the catalogue stops being relevant, and the decision shrinks from thirty options to two or three.

What the letters actually cost

Exam fee, as the body publishes it

  • ISC2 CC ISC2$199
  • CISM ISACA$575 member
  • CCSP ISC2$599
  • CISSP ISC2$749
  • Security+ CompTIAnot published
US dollar list prices read at the bodies’ own pages on 24 September 2026. ISC2 charges the same figure across the Americas, Asia Pacific, the Middle East and Africa, and a converted amount in euro and sterling. The CISM figure is the ISACA member price; the non-member exam is $760. The dashed bar is not a small number — it is CompTIA declining to publish one anywhere we could read it.

The fee you are quoted is the sitting, not the certification. ISC2 lists CISSP at $749 in the Americas, Asia Pacific, the Middle East and Africa, and CCSP at $599; ISACA lists the CISM exam at $575 for members and $760 for non-members; ISC2's entry-level Certified in Cybersecurity exam is $199. Those are list prices read on the bodies' own pages on 24 September 2026.

One figure is missing from that list on purpose. CompTIA does not publish the Security+ voucher price on any page we could read: its store product URLs redirect to a certifications index, and its own article about what Security+ costs contains no number at all. Rather than repeat a figure from a reseller, we leave the bar empty and tell you where the price actually appears — at checkout in the CompTIA Store.

Three rules this site holds to

  • No pass rates. ISC2, CompTIA and ISACA do not publish them. Every percentage circulating online traces back to somebody selling training, so there is no pass rate anywhere on Hardenstep — not even a range, not even hedged.
  • No guarantees. No certification guarantees a pass, a job, a raise or a clearance, and any course promising one is describing a refund policy, not an outcome.
  • No dumps. Sites that resell live exam items break the agreement you sign before the exam starts. We do not link them, name them as an option or explain how to find them.

Who this is for

People spending their own money and their own evenings. If your employer is paying and has already chosen the credential, you need a study plan rather than a comparison. If the choice is yours, start with which certification fits the stage you are at, or go straight to the CISSP page if that is the one keeping you up at night.

The briefings

Every briefing

CCSP vs CISSP: the cloud one is a sequel, not an alternative

ISC2 accepts an active CISSP in place of CCSP's entire experience requirement — which tells you exactly how the two are meant to relate. Fees, domains and the case for sitting both.

Briefing · Sep 24, 2026

CISM vs CISSP: the same five years, two different jobs

Both demand five years. CISSP spreads across eight technical and governance domains; CISM covers four management domains and nothing else. The fees, the clauses and the honest way to choose.

Briefing · Sep 24, 2026

The eight CISSP domains, and what each one is worth

ISC2 publishes the weighting of every domain. Nothing exceeds 16%, nothing drops below 10%, and that flatness is the single most useful fact about how to study for this exam.

Briefing · Sep 24, 2026

CISSP exam cost: $749, and the three-year bill behind it

The sitting is $749 in the Americas. Holding the certification for a first three-year cycle is $1,154 before a single hour of training — with the reschedule and cancellation fees nobody mentions.

Briefing · Sep 24, 2026

CISSP requirements: the five years, and the way round them

ISC2 will let you sit CISSP with no experience at all — it just will not certify you. The experience clause, the one-year waiver and the Associate route, quoted from ISC2's own outline.

Briefing · Sep 24, 2026

Studying for CISSP: what to use, and what we will not send you to

A study plan built on the published exam outline, honest practice questions, and the one category of resource this site refuses to link — with the reason it is a risk to you, not a moral position.

Briefing · Sep 24, 2026

Questions people ask before they pay

Which cybersecurity certification should I start with?
Start with CompTIA Security+ if you already work in IT, and with ISC2's Certified in Cybersecurity if you do not. Security+ assumes you know what a subnet is — CompTIA recommends Network+ and two years in a security or systems administrator role, though it requires neither — while ISC2 states plainly that CC needs no work experience at all. Neither one is CISSP's junior version: CISSP will not certify you until you have five years behind you, so it is not a starting point but a destination.
What does the CISSP exam cost?
ISC2 lists the CISSP exam at $749 in the Americas, Asia Pacific, the Middle East and Africa, at €719.04 in the EMEA region and £606.69 in the UK, read on its own pricing page on 24 September 2026. That is the sitting alone. Keeping the certification costs an annual maintenance fee of $135, so three years of holding CISSP is $1,154 before a single hour of training, and rescheduling costs $50 while cancelling costs $100.
Can I take the CISSP exam without five years of experience?
Yes — you can sit and pass it, but you cannot hold it. ISC2's own exam outline says candidates need a minimum of five years cumulative, full-time experience in two or more of the eight domains, and that passing without the experience makes you an Associate of ISC2 with six years to complete the five years. A relevant bachelor's or master's degree, or an approved ISC2 credential, waives up to one year of it.
What is the CISSP pass rate?
Nobody who would know publishes one. ISC2 does not put a pass rate on its CISSP pages, CompTIA does not publish one for Security+, and ISACA does not publish one for CISM — so every percentage you have read came from a training company with something to sell, or from somebody repeating one. Hardenstep prints no pass-rate figure at all, not even a range, because an invented number reads exactly like a cited one.
Is there a free way into cybersecurity training?
Partly, and it is shrinking. TryHackMe's free tier gives limited access to learning paths, free rooms only and an hour a day of its browser attack box, which is genuinely enough to find out whether you like the work — and it pays us nothing when you stay on it. The large free door has closed: ISC2 stopped accepting new participants in One Million Certified in Cybersecurity on 20 May 2026, and its CC exam now costs $199 like any other.