Hardenstep
Menu

Security+ vs CISSP: not two rungs of one ladder

Published Sep 24, 2026Sources re-read Sep 24, 2026

Security+ and CISSP get compared as beginner and advanced, and that framing causes real mistakes — people spending $749 too early, and people sitting on Security+ for years after it has stopped telling anyone anything new. They are different instruments. One gets you considered for a job; the other gets you considered for a decision.

The two exams, as published

CompTIA publishes Security+ V7, exam code SY0-701, as a maximum of 90 questions mixing multiple-choice and performance-based items, 90 minutes long, with a passing score of 750 on a scale of 100 to 900. It is available in English, Japanese, Portuguese, Spanish and Thai.

ISC2 publishes CISSP as three hours, 100 to 150 questions, computerised adaptive testing for all exams, with a pass mark of 700 out of 1000 points, in Chinese, English, German, Japanese and Spanish.

Performance-based questions are the interesting difference in kind: Security+ asks you to do small things, CISSP asks you to judge. Neither body publishes a pass rate, so anyone telling you one is harder by the numbers is inventing the numbers.

What Security+ weighs most heavily

Security+ V7 domain weightings, CompTIA

5DOMAINS
  • 28%Security Operations
  • 22%Threats, Vulnerabilities, and Mitigations
  • 20%Security Program Management and Oversight
  • 18%Security Architecture
  • 12%General Security Concepts
  • 100% in total — the weightings add up, which is how we check we copied them correctly.
Security+ concentrates: two domains carry half the paper between them. Weightings read at CompTIA's Security+ V7 page on 24 September 2026.

CompTIA's V7 objectives put Security Operations at 28%, the single heaviest domain in either exam. Threats, Vulnerabilities, and Mitigations at 22% follows, then Security Program Management and Oversight at 20%, Security Architecture at 18% and General Security Concepts at 12%. The five add to 100.

Set that against CISSP's spread — 16% at the top, 10% at the bottom, across eight domains — and the character of each exam is obvious. Security+ concentrates: half the paper is operations and threats. CISSP levels: no subject dominates, and a weak domain cannot be hidden.

The gate, which is the real difference

CompTIA recommends that Security+ candidates hold Network+ and two years of experience working in a security/systems administrator job role, and requires neither. Nothing stops you sitting it in your first month in IT.

ISC2 requires a minimum of five years cumulative, full-time experience in two or more of the eight domains before it will certify you, with up to one year waived by a relevant degree or an approved credential. You may sit the exam without the experience, but you hold Associate of ISC2 status rather than CISSP, and you may not use the CISSP marks until endorsement is complete.

That is the whole decision for most people. If you do not have five years, CISSP is not a choice you are making this year.

What they cost to keep

Security+ lasts three years from the day it is earned. You renew either with 50 continuing-education units or with a single qualifying activity — CompTIA names its own CertMaster CE course, a higher-level CompTIA certification, or an approved non-CompTIA certification. If you renew by uploading CEUs, CompTIA charges $150 for the whole three-year period, and states that the fee is only due if you are renewing that way and must be paid by the certification's expiration date.

CISSP costs $749 to sit, then a $135 annual maintenance fee, plus 120 CPE credits per three-year cycle with at least 90 in Group A. CompTIA does not publish the Security+ voucher price anywhere we could read, so we cannot give you a clean total for the CompTIA side — which is itself worth knowing before you budget.

One more date to plan around

Security+ has a version cycle, and it is public. V7 launched on 7 November 2023 and retires on 11 June 2027 for English, and 13 August 2027 for Japanese, Portuguese, Spanish and Thai. CompTIA expects Security+ V8 on 17 November 2026.

That changes the calculus for anyone studying now. If you sit V7 before it retires you hold a current certification for three years from the date you earn it regardless of the version cycle — but if you are starting study in mid-2027, you will be learning objectives that are on their way out. There is no equivalent published retirement schedule for CISSP.

So which one

Sit Security+ if you are inside your first few years of IT, if job adverts you want mention it, or if you need a credential that proves you took the subject seriously before anyone will let you near it professionally. Sit CISSP when you have the five years and your work has moved from doing to deciding.

If you are between the two, the useful next question is which layer you are defending rather than which certificate is more impressive — the comparison by career stage lays that out. And if CISSP is the target but the experience clause is what is blocking you, the five-year rule in detail is the page to read next.

The performance-based questions are the thing to practise

CompTIA's format note deserves more attention than it usually gets: Security+ is a maximum of 90 questions mixing multiple-choice with performance-based items, in 90 minutes. Those performance-based questions are simulations — configure something, interpret output, place controls correctly — and candidates who have only drilled multiple choice find them slow.

Slow is the problem, because the clock does not care. Ninety items in ninety minutes averages a minute each, and a performance-based question can absorb five. The standard advice is the right advice here: move past them on the first pass, bank the multiple-choice marks, and come back with whatever time is left.

CISSP has no equivalent. Its advanced item types are still assessment rather than simulation, and its three hours for up to 150 questions is a gentler ratio than Security+ offers.

What each one signals to a hiring manager

Security+ signals that you took the subject seriously and can be trusted with the vocabulary. In a lot of organisations it also satisfies a procurement or compliance requirement, which is why it appears in adverts for roles that have nothing obviously to do with it.

CISSP signals something different and narrower: that an independent body has checked five years of your experience against eight domains and that somebody already certified vouched for you. That verification step — the endorsement — is the part most people forget is in there, and it is the reason the credential carries weight in senior hiring that a longer exam alone would not give it.

Choosing between them

Can I skip Security+ and go straight to CISSP?
You can sit CISSP without Security+, because ISC2 has no prerequisite certification. What you cannot skip is the five years of experience ISC2 requires before it will certify you; pass without them and you hold Associate of ISC2 status, not CISSP. For most people early in their career, Security+ is the credential that actually opens the door this year.
Is Security+ still worth it in 2026?
It remains the entry-level security certification most commonly named in job adverts, and CompTIA is actively maintaining it — V7 runs until June 2027 in English and V8 is expected on 17 November 2026. What it does not do is substitute for experience or carry weight in senior hiring, which is where it stops being the right answer.
How long is Security+ valid?
Three years from the date you earn it. Renewal is 50 CEUs plus $150 in continuing-education fees for the cycle, or a single qualifying activity such as CompTIA's CertMaster CE course or a higher-level certification, which avoids the CEU route entirely.
Does CISSP replace Security+?
In practice yes, and CompTIA's own renewal rules acknowledge something similar: an approved non-CompTIA certification can renew a CompTIA one. Holding both is normal for a while and unnecessary long-term — nobody reads Security+ on the CV of a certified security architect.

Still deciding between credentials? Work through which cybersecurity certification fits the stage you are at, or read how every figure on this site is checked. Fees, formats and eligibility rules change without warning — open the certifying body’s page before you pay for anything.