Hardenstep
Menu

Ordered by the stage it suits · fees read 24 September 2026

The best cybersecurity certification is the one you can hold

Six credentials, ordered by the stage of a career they fit rather than by prestige. Every fee, experience rule and renewal cost below was read at ISC2, CompTIA or ISACA on 24 September 2026 and is quoted in the body's own words.

The route this page recommends

  1. No experience neededISC2 CCISC2 asks for none at all
  2. Two years suggestedSecurity+CompTIA recommends, never requires
  3. Five years requiredCISSP · CISMThe clause, not the exam, is the gate
  4. Then specialiseCCSP · OSCPDepth on top of breadth
The rings thicken with the experience the body demands, not with prestige. Two of the four stations are reachable today by anyone; the third is a five-year clause that no course, no bootcamp and no amount of study can shorten.

The short answer, by where you are standing

If you already work in IT and want the first credential that hiring managers recognise, sit CompTIA Security+. If you are coming from outside technology entirely, sit ISC2's Certified in Cybersecurity first, because ISC2 states that it needs No Work Experience Required and Security+ assumes a couple of years of systems work. If you have five years behind you and want the credential that opens architecture and leadership doors, it is CISSP — unless your work is governance and programme management, in which case CISM describes it better.

Two more sit off that main line. CCSP is the cloud specialisation you add after CISSP rather than instead of it, and ISC2 makes that explicit by accepting an active CISSP in place of the entire CCSP experience requirement. OSCP is the one employers read as proof you can actually do the work, and the only credential here whose full price OffSec publishes openly.

Nothing here is ranked by what it pays us. The order is the order a career usually runs in, and the two credentials at the top of it — ISC2 CC and Security+ — are issued by bodies that pay us nothing at all.

The six, side by side

Read at ISC2, CompTIA, ISACA and OffSec on 24 September 2026
CertificationIssued byFee to sitExperience ruleKeeping it
ISC2 Certified in CybersecurityISC2$199None$50 a year maintenance fee
CompTIA Security+CompTIANot published outside the storeTwo years recommended, none requiredThree years; 50 CEUs plus $150 in CE fees
ISC2 CISSPISC2$749Five years in two or more of eight domains$135 a year, 120 CPE credits per three years
ISACA CISMISACA$575 member, $760 non-memberFive years, three of the four domains120 CPE hours per three years, 20 a year minimum
ISC2 CCSPISC2$599Five years IT, three in security, one in a domainCovered by the same $135 ISC2 fee
OffSec OSCPOffSec$1,749 with the course, one attemptNone publishedNo renewal fee published

The table is deliberately short on adjectives. Every cell is either a figure from the issuing body's own page or a plain statement that the body does not publish one.

What each exam costs to sit

Exam fee, as the body publishes it

  • ISC2 CC ISC2$199
  • CISM ISACA$575 member
  • CCSP ISC2$599
  • CISSP ISC2$749
  • Security+ CompTIAnot published
US dollar list prices read at the bodies’ own pages on 24 September 2026. ISC2 charges the same figure across the Americas, Asia Pacific, the Middle East and Africa, and a converted amount in euro and sterling. The CISM figure is the ISACA member price; the non-member exam is $760. The dashed bar is not a small number — it is CompTIA declining to publish one anywhere we could read it.

ISC2 publishes a single fee table covering every one of its exams, and the same dollar figure applies across the Americas, Asia Pacific, the Middle East and Africa, with converted amounts in euro and sterling. CISSP is $749, CCSP is $599 and Certified in Cybersecurity is $199. ISACA lists CISM at $575 for members and $760 for everyone else, plus a $50 application processing fee once you apply for the certification itself.

The gap in that list matters more than the numbers in it. CompTIA does not publish the Security+ voucher price anywhere we could read on 24 September 2026 — the store product pages redirect to a certifications index, and CompTIA's own explainer on what Security+ costs points at the store without quoting a figure. Plenty of sites will tell you the number anyway. We would rather show you an empty bar than a number we did not read.

Two smaller fees are worth knowing before you book: ISC2 charges $50 to reschedule and $100 to cancel, so a date you are not sure about is not a free option.

The gate that decides whether you can hold it

Years of experience the body asks for

  • ISC2 CCnoneno work experience required
  • Security+2 yearstwo years recommended, not required
  • CISSP5 yearsfive years in two or more of eight domains
  • CCSP5 yearsfive years IT, three in security, one in a domain
  • CISM5 yearsfive years, three of the four domains, within ten
Five squares, one per year, filled to the requirement the body publishes. Recommended is not required: CompTIA suggests two years for Security+ and gates nothing on it, while ISC2 and ISACA will not certify you at all until the years are there — though ISC2 lets you pass the exam first and hold Associate status while you earn them.

Passing and holding are different events, and the experience clause is where candidates get caught. ISC2's CISSP outline requires a minimum of five years cumulative, full-time experience in two or more of the eight domains, with a relevant bachelor's or master's degree or an approved ISC2 credential waiving up to one year of it. Pass without the years and you become an Associate of ISC2, with six years to finish earning them.

CCSP asks for the same five years of IT, of which three years must be in cybersecurity and one in one of the six cloud domains — and an active CISSP satisfies the whole requirement outright. ISACA wants five years of information security management experience in at least three of the four CISM domains, earned within the ten years before you apply, and gives you five years after passing to submit the application.

At the other end, CompTIA only suggests: Security+ recommends Network+ and two years of experience working in a security/systems administrator job role, and gates nothing on either. ISC2's CC page is blunter still — No Work Experience Required.

The bill nobody quotes: three years of holding it

What three years of holding it costs

  • CISSP$1,154$749 exam + AMF $135 × 3 = $405 to keep it
  • CCSP$1,004$599 exam + AMF $135 × 3 = $405 to keep it
  • Security+exam price not publishedexam voucher, price unread + CE fees, whole cycle = $150 to keep it
Emerald is the exam, steel is what the body charges over the next three years. Training is not in here at all, and for most people training is the larger number. ISC2 charges one annual maintenance fee however many of its certifications you hold, so a CISSP who adds CCSP pays the exam fee and nothing more each year.

Certifications are subscriptions with an exam attached. ISC2 charges an annual maintenance fee of $135 for CISSP, CCSP and its other professional credentials, and $50 for Certified in Cybersecurity and Associates. So CISSP is a $749 exam plus $135 a year, which is $1,154 across a first three-year cycle, and CCSP works out at $1,004 on the same arithmetic. Neither figure includes a single hour of training.

There is one genuine bargain in that structure: ISC2 states that members pay a single annual fee regardless of how many of its certifications they hold. Adding CCSP to an existing CISSP costs the $599 exam and nothing more each year.

CompTIA works differently. Security+ lasts three years from the day you earn it, and you renew either with 50 continuing-education units or with a single qualifying activity such as a higher-level certification. If you renew by uploading CEUs, CompTIA charges $150 for the whole three-year period — not per year — and the fee is only due if you are renewing that way. ISACA asks CISM holders for 120 CPE hours per three-year period with a minimum of 20 hours a year.

If you are starting from nothing

The honest order is CC, then Security+, then work, then everything else. Certified in Cybersecurity exists precisely for people with no security experience and costs $199 to sit, which is the cheapest credible entry on this page. Security+ is the one that shows up in job adverts, and although CompTIA recommends two years of systems experience, nothing stops you sitting it earlier if the objectives make sense to you.

Be aware of one recent change before you plan around free training. ISC2 ran a programme called One Million Certified in Cybersecurity that gave away the CC course and exam, and it closed: “Starting May 20, 2026, ISC2 will stop accepting new participants.” People already holding unexpired codes can sit by 31 December 2026. If you missed it, CC is a paid exam like any other now.

Coursera's Google Cybersecurity certificate

This is the route most beginners actually take, and it needs one distinction made carefully. It is a certificate of completion, not a certification — nobody is verifying your experience or putting you on a register. Coursera lists it as nine courses at “6 months at 7 hours a week”, priced at “$49 per month after the initial 7-day free trial period” in the US and Canada, typically under $300 in total, included with Coursera Plus, with financial aid available. Coursera says it helps prepare you for Security+ and that graduates can access the Security+ exam and training at a discounted price; the size of that discount is not published there, so we cannot tell you what it is worth.

Paid link, tagged sponsored and nofollow: if you subscribe after using it, the provider pays us a share and you pay the same price you would have paid anyway. It buys no place in any ranking on this site — the exam facts above come from the certifying body, which pays us nothing and never will.

If you have five years

This is where CISSP, CISM and CCSP diverge on subject matter rather than difficulty. CISSP is broad by design — no single domain exceeds 16% of the paper — and it is the credential that signals you can hold an architecture or leadership conversation across the whole stack. CISM is narrower and more managerial: governance, risk, programme and incident management, and nothing about writing a firewall rule. CCSP is CISSP's cloud sibling, weighted heaviest on cloud data security at 20%.

If your job title contains the word manager and your week contains committee meetings, CISM describes your work better. If you are the person other engineers escalate to, CISSP does. If your estate is entirely somebody else's data centre, CCSP does.

Instructor-led preparation with Simplilearn

Paid bootcamps are the standard way people at this level prepare, and they are the one part of this page where a link earns us anything. Simplilearn runs a CISSP training course that advertises an included exam voucher; its price is not shown in the page body and appears only after you request a quote or reach checkout, so we cannot quote it here and will not guess. Treat any price you are shown as a promotion with an expiry unless the page says otherwise.

Paid link, tagged sponsored and nofollow: if you subscribe after using it, the provider pays us a share and you pay the same price you would have paid anyway. It buys no place in any ranking on this site — the exam facts above come from the certifying body, which pays us nothing and never will.

The same in a different format: KnowledgeHut

KnowledgeHut sells comparable instructor-led certification bootcamps. Its CISSP course URL returned a 404 when we checked on 24 September 2026, so we have no course facts of our own to give you and are passing on that fact rather than describing a page we could not open.

Paid link, tagged sponsored and nofollow: if you subscribe after using it, the provider pays us a share and you pay the same price you would have paid anyway. It buys no place in any ranking on this site — the exam facts above come from the certifying body, which pays us nothing and never will.

If you want your hands on a keyboard

Paper credentials say you understand security; lab credentials say you have done it. OSCP is the one hiring managers treat as proof, and OffSec's pricing is unusually transparent: a course and certification bundle at $1,749 as a one-time payment, giving 90 days of course access, labs and one exam attempt, or Learn One at $2,749 a year with two attempts. OffSec runs no affiliate programme we are part of, so that recommendation earns us nothing.

The subscription labs are how most people get ready for it, and those do pay us.

Hack The Box Academy

HTB Academy sells structured modules and job-role paths with a browser-based attack machine. Read on 24 September 2026, the monthly plans were Student $8, Silver $18, Gold $38 and Platinum $68, with annual access plans at $490 for Silver and $1,260 for Gold. Those numbers have a shelf life: Hack The Box announced on 3 September 2026 that from 12 October 2026 the monthly plans move to $10, $30, $95 and $125 and the annual plans to $550 and $1,400, with monthly plans switching from fixed cubes to tier-based access. Existing monthly subscribers get a one-month grace period at their old rate and annual subscribers get one more cycle at theirs.

Paid link, tagged sponsored and nofollow: if you subscribe after using it, the provider pays us a share and you pay the same price you would have paid anyway. It buys no place in any ranking on this site — the exam facts above come from the certifying body, which pays us nothing and never will.

TryHackMe

TryHackMe is the gentler on-ramp and has a genuinely usable free tier: limited access to learning paths, free rooms only, and one hour a day on its browser attack box. On the page served to us on 24 September 2026 — priced in euro, so you may see your own currency — Premium was €10.50 a month billed annually against €16.99 month to month, and MAX was €17.99 billed annually against €29.11 month to month.

Paid link, tagged sponsored and nofollow: if you subscribe after using it, the provider pays us a share and you pay the same price you would have paid anyway. It buys no place in any ranking on this site — the exam facts above come from the certifying body, which pays us nothing and never will.

Where the free routes still are

Three of them are real. TryHackMe's free tier is enough to find out whether you enjoy the work before you spend anything, and staying on it pays us nothing. Coursera's financial aid applies to the Google certificate, and its seven-day trial means a determined month can cost very little. And the cheapest route of all is the one nobody sells: read the exam outline on the body's own site, which is free, and find out how much of it you already know.

What is no longer free is the ISC2 entry exam, as of 20 May 2026. If a page still tells you CC is free, it has not been updated this year.

What we will not tell you

We will not tell you a pass rate, because none of these bodies publishes one. We will not tell you what a certification pays, because neither ISC2 nor ISACA publishes salary by credential; the nearest honest figure is occupational, and the US Bureau of Labor Statistics puts the median for information security analysts at $129,180 a year as of May 2025, with 21% growth projected for 2025–35 — a figure about a job, not about letters after a name.

And we will never point you at an exam dump. Reproducing live exam items breaks the agreement you accept before the exam starts, and it is the one shortcut that can cost you the credential you paid for.

Before you book anything

Which cybersecurity certification is best for beginners?
ISC2's Certified in Cybersecurity if you are new to technology, and CompTIA Security+ if you already work in IT. ISC2 states that CC requires no work experience, and its exam is $199; CompTIA recommends Network+ and two years in a security or systems administrator role for Security+ but does not require either. CISSP is not a beginner certification in any sense — ISC2 will not certify you until five years of qualifying experience are on file.
Is CISSP worth $749?
It is worth it if you already have the five years, because the exam fee is the small part of the decision. Holding CISSP costs the $749 sitting plus a $135 annual maintenance fee and 120 CPE credits every three years, which is $1,154 across a first cycle before training. If you do not yet have the experience, the same money spent on Security+ and hands-on labs will do more for you this year.
Can I put CISSP on my CV after passing the exam?
No. Passing without the experience makes you an Associate of ISC2, and ISC2 is explicit that Associates may not use the certification marks until endorsement is complete. You may accurately say you have passed the CISSP examination and hold Associate status, and you have six years to complete the five years of experience.
Do cybersecurity certifications expire?
All of the ones on this page except OSCP do. CompTIA certifications last three years and renew with 50 CEUs plus $150 in continuing-education fees for the cycle, or with a single qualifying activity. ISC2 requires 120 CPE credits per three-year cycle and an annual maintenance fee. ISACA requires 120 CPE hours per three years with at least 20 a year. OffSec publishes no renewal requirement for OSCP.
How many cybersecurity certifications should I hold at once?
One that matches your current work, and at most one you are studying for. Stacking credentials across layers you do not work on is expensive and unconvincing, and the renewal arithmetic compounds — each CompTIA certification carries its own cycle and fees, while ISC2 charges one annual fee however many of its certifications you hold.