Certifications Hub

Books, roadmaps, costs, and study methods for major cybersecurity certifications.

Curated for practitioners. No affiliate links. Updated for 2025–2026.

Certification paths and resources are community-curated. Verify current requirements with official bodies.

Quick Reference

41 certifications across 10 certification bodies. Costs are exam-only (training separate).

Cert Body Level Domain USD EUR Duration Questions Passing Validity Experience
CISSP ISC2 Advanced GRC / Management $749 €690 3–6 hrs (CAT) 100–175 700 / 1000 3 yrs + 40 CPE/yr 5 yrs in 2+ domains
CCSP ISC2 Advanced Cloud Security $599 €550 4 hrs 150 700 / 1000 3 yrs + 30 CPE/yr 5 yrs IT (3 in security, 1 in cloud)
SSCP ISC2 Intermediate Operations / Technical $249 €230 4 hrs 150 700 / 1000 3 yrs + 20 CPE/yr 1 yr in 1+ domain
CC ISC2 Entry General Security $199 €185 2 hrs 100 700 / 1000 3 yrs + 15 CPE/yr None
CGRC ISC2 Intermediate GRC $599 €550 3 hrs 125 700 / 1000 3 yrs + 20 CPE/yr 2 yrs in 1+ domain
CSSLP ISC2 Advanced AppSec / SDLC $599 €550 4 hrs 175 700 / 1000 3 yrs + 30 CPE/yr 4 yrs in SDLC
CISA ISACA Advanced Audit $760 €700 4 hrs 150 450 / 800 3 yrs + 20 CPE/yr 5 yrs in IS audit
CISM ISACA Advanced Security Management $760 €700 4 hrs 150 450 / 800 3 yrs + 20 CPE/yr 5 yrs in infosec mgmt (3 in mgmt)
CRISC ISACA Advanced Risk Management $760 €700 4 hrs 150 450 / 800 3 yrs + 20 CPE/yr 3 yrs in IT risk mgmt
CGEIT ISACA Expert IT Governance $760 €700 4 hrs 150 450 / 800 3 yrs + 20 CPE/yr 5 yrs in IT governance
CDPSE ISACA Intermediate Privacy Engineering $760 €700 3.5 hrs 120 450 / 800 3 yrs + 20 CPE/yr 2 yrs in privacy
Security+ CompTIA Entry General Security $404 €375 1.5 hrs 90 max 750 / 900 3 yrs + CEUs None (2 yrs recommended)
CySA+ CompTIA Intermediate Defensive / SOC $404 €375 2.5 hrs 85 max 750 / 900 3 yrs + CEUs 3–4 yrs hands-on
PenTest+ CompTIA Intermediate Offensive $404 €375 2.5 hrs 85 max 750 / 900 3 yrs + CEUs 3–4 yrs hands-on
CASP+ CompTIA Advanced Security Architecture $494 €455 2.5 hrs 90 max Pass / Fail 3 yrs + CEUs 10 yrs general IT (5 in security)
GSEC GIAC / SANS Intermediate General Security $949 €875 4–5 hrs 106–180 73% 4 yrs + 36 CPE None (SEC401 recommended)
GPEN GIAC / SANS Advanced Offensive $949 €875 3 hrs 82 75% 4 yrs + 36 CPE None (SEC560 recommended)
GCIH GIAC / SANS Intermediate Defensive / IR $949 €875 4 hrs 106 70% 4 yrs + 36 CPE None (SEC504 recommended)
GCIA GIAC / SANS Advanced Defensive / Network $949 €875 4 hrs 106 67% 4 yrs + 36 CPE None (SEC503 recommended)
GCFA GIAC / SANS Advanced DFIR $949 €875 4 hrs 82 72% 4 yrs + 36 CPE None (FOR508 recommended)
GCFE GIAC / SANS Intermediate DFIR $949 €875 4 hrs 82 71% 4 yrs + 36 CPE None (FOR500 recommended)
GREM GIAC / SANS Advanced Malware Analysis $949 €875 4 hrs 75 73% 4 yrs + 36 CPE None (FOR610 recommended)
GWAPT GIAC / SANS Intermediate Offensive / Web $949 €875 4 hrs 82 71% 4 yrs + 36 CPE None (SEC542 recommended)
GFACT GIAC / SANS Entry General Security $949 €875 2 hrs 75 71% 4 yrs + 36 CPE None
GXPN GIAC / SANS Expert Offensive / Exploit Dev $949 €875 3 hrs 60 67% 4 yrs + 36 CPE None (SEC660 recommended)
OSCP OffSec Intermediate Offensive $1,749 €1,610 23 hrs 45 min Practical (3 standalone + AD set) 70 points Lifetime None (PEN-200 course required)
OSEP OffSec Advanced Offensive / Evasion $1,749 €1,610 47 hrs 45 min Practical Secret flag(s) Lifetime OSCP or equivalent
OSWE OffSec Advanced Offensive / Web $1,749 €1,610 47 hrs 45 min Practical Secret flag(s) Lifetime OSCP or equivalent + web dev knowledge
OSWP OffSec Intermediate Offensive / Wireless $799 €735 3 hrs 45 min Practical Not disclosed Lifetime Basic networking
OSED OffSec Expert Offensive / Exploit Dev $1,749 €1,610 47 hrs 45 min Practical Not disclosed Lifetime OSCP + programming
OSDA OffSec Intermediate Defensive / SOC $1,749 €1,610 23 hrs 45 min Practical Not disclosed Lifetime Basic security knowledge
CEH EC-Council Intermediate Offensive $1,199 €1,100 4 hrs 125 70% 3 yrs + 120 ECE 2 yrs in infosec (or official training)
CHFI EC-Council Intermediate DFIR $1,199 €1,100 4 hrs 150 70% 3 yrs + 120 ECE 2 yrs in infosec (or official training)
eJPT INE / eLearnSecurity Entry Offensive $249 €230 48 hrs Practical + MCQ 70% 3 yrs None
eCPPT INE / eLearnSecurity Intermediate Offensive $400 €370 14 days (7 days exam + 7 days report) Practical + Report Report-based 3 yrs eJPT or equivalent
PNPT TCM Security Intermediate Offensive $399 €370 5 days (pentest) + 2 days (report) Practical + Report + Debrief Report-based + debrief Lifetime None
CyberOps Associate Cisco Entry Defensive / SOC $330 €305 2 hrs 95–105 Not publicly disclosed 3 yrs None
CCNP Security Cisco Advanced Network Security $660 €610 2 hrs (core) + 1.5 hrs (concentration) ~100 per exam Not publicly disclosed 3 yrs 3–5 yrs networking
AWS Security Specialty Cloud Vendors (AWS, Azure, GCP) Advanced Cloud Security $300 €275 2.5 hrs 65 750 / 1000 3 yrs 5 yrs IT security + 2 yrs AWS
AZ-500 Cloud Vendors (AWS, Azure, GCP) Intermediate Cloud Security $165 €155 2.5 hrs 40–60 700 / 1000 1 yr (annual renewal via free assessment) 1–2 yrs Azure security
GCP Security Engineer Cloud Vendors (AWS, Azure, GCP) Advanced Cloud Security $200 €185 2 hrs 50–60 Not publicly disclosed 2 yrs 3+ yrs industry + 1 yr GCP
◆ ◆ ◆

Certification Deep Dives

Detailed profiles with books, study resources, preparation advice, and realistic timelines.

🔒

ISC2

Gold Standard

ISC2 (International Information System Security Certification Consortium) is the world's leading cybersecurity professional organization, best known for the CISSP. All ISC2 exams are delivered via Pearson VUE.

Exam delivery: Pearson VUE (test center or online proctored) Retake: 30-day wait after 1st attempt, 60 days after 2nd, 90 days after 3rd. Max 3 retakes per year. Renewal: Annual CPE credits required (varies by cert). Annual Maintenance Fee (AMF).
📊

ISACA

Governance & Audit

ISACA focuses on IT governance, risk, compliance, and audit. Their certifications are globally recognized in GRC roles. Exams via PSI or ISACA remote proctoring.

Exam delivery: PSI (test center or remote proctored) Retake: Can retake after waiting period. Additional exam fees apply per attempt. Renewal: 20 CPE hours/year, 120 CPE over 3-year cycle. Annual maintenance fee.
💻

CompTIA

Industry Foundation

CompTIA offers vendor-neutral IT certifications recognized worldwide. Security+, CySA+, PenTest+, and CASP+ form the cybersecurity pathway. Exams via Pearson VUE.

Exam delivery: Pearson VUE (test center or online) Retake: No wait after 1st fail. 14-day wait for subsequent retakes. Full fee per attempt. Renewal: 3-year renewal cycle. Renew via CEUs or by passing a higher cert. CertMaster CE available.
🎓

GIAC / SANS

Training-Coupled

GIAC certifications validate skills taught in SANS courses. Exams are proctored via ProctorU or Pearson VUE. The associated SANS training is separate and expensive, but the exam can be taken independently.

Exam delivery: ProctorU (remote) or Pearson VUE Retake: 30-day wait. Retake fee applies. 2 retakes per certification attempt. Renewal: 36 CPE credits every 4 years. $479 renewal fee.
🖤

OffSec

Hands-On Offensive

OffSec (formerly Offensive Security) offers practical, hands-on certifications. Exams are 100% practical — no multiple choice. OSCP is the gold standard for penetration testers.

Exam delivery: OffSec proctored (remote, VPN-based lab exam) Retake: Retake included with active Learn subscription. Otherwise ~$249 per retake. Renewal: No expiration. Certification is lifetime once earned.
🔭

EC-Council

Ethical Hacking

EC-Council is known for the Certified Ethical Hacker (CEH) and related certifications. Exams via Pearson VUE or EC-Council Exam Center.

Exam delivery: Pearson VUE or ECC Exam Center Retake: Wait period varies. Retake voucher required. Renewal: 3-year renewal. 120 ECE credits over 3 years. $80/year membership fee.
🌱

INE / eLearnSecurity

Practical Training

INE (formerly eLearnSecurity) offers practical, lab-based certifications. Exams are hands-on penetration tests and report writing. Growing reputation as affordable practical alternatives.

Exam delivery: INE platform (remote, lab-based) Retake: Retake included with active INE Premium subscription. Renewal: No formal CPE. Certification valid for 3 years.
🛠

TCM Security

Practical & Affordable

TCM Security offers practical certifications focused on real-world penetration testing. Founded by Heath Adams (TheCyberMentor). Growing community recognition.

Exam delivery: TCM platform (remote, practical exam) Retake: Free retake included. Renewal: No expiration.
📡

Cisco

Network Security

Cisco security certifications validate network security skills on Cisco platforms. The CyberOps track focuses on SOC operations.

Exam delivery: Pearson VUE Retake: 5-day wait for different exam, 14-day wait for same exam. Renewal: 3-year validity. Recertify via exam or CE credits.

Cloud Vendors (AWS, Azure, GCP)

Cloud Security

Major cloud providers offer security-specific certifications validating platform security skills. Each has its own exam delivery and renewal process.

Exam delivery: Pearson VUE (AWS, Azure) / Kryterion (GCP) Retake: 14-day wait (varies by provider). Renewal: 2–3 year validity. Recertify by passing current exam version.
◆ ◆ ◆

Certification Roadmaps by Role

Recommended certification paths. Start from the top of each path and work down.

🛡 SOC Analyst (L1 → L3)
  1. Security+ or CC
    Baseline security knowledge. DoD 8570 compliant.
  2. CyberOps Associate
    SOC-specific fundamentals and monitoring skills.
  3. CySA+
    Deeper analyst skills: threat detection, SIEM, vulnerability management.
  4. OSDA (SOC-200)
    Practical SOC skills validated by hands-on exam.
  5. GCIH
    Incident handling expertise via SANS SEC504.
  6. GCIA
    Advanced network analysis and intrusion detection.
🖤 Penetration Tester (Junior → Senior)
  1. eJPT
    Affordable, practical entry point. Builds foundational pentest skills.
  2. Security+ or PenTest+
    Broad security knowledge base. Meets compliance requirements.
  3. PNPT
    Real-world pentest methodology with report writing and debrief.
  4. OSCP (PEN-200)
    Industry gold standard. Validates hands-on exploitation skills.
  5. OSEP (PEN-300)
    Advanced evasion, AD attacks, and red team techniques.
  6. GXPN or OSED
    Expert-level exploit development and advanced offensive research.
📋 GRC / Compliance Analyst
  1. CC or Security+
    Security fundamentals baseline.
  2. CISA
    IT audit skills — essential for compliance roles.
  3. CRISC
    IT risk management specialization.
  4. CISM
    Security management and governance perspective.
  5. CGRC
    RMF and authorization specialization (government/regulated sectors).
  6. CISSP
    Broad management credential. Opens CISO-track opportunities.
☁ Cloud Security Engineer
  1. Security+
    Security fundamentals baseline.
  2. AZ-500, AWS Security, or GCP Security
    Platform-specific security skills for your primary cloud.
  3. CySA+
    Defensive monitoring skills applicable to cloud SOC.
  4. CCSP
    Vendor-neutral cloud security architecture and governance.
  5. CISSP
    Senior security leadership credential.
🔍 DFIR / Threat Hunter
  1. Security+
    Security baseline.
  2. CySA+
    Detection and analysis fundamentals.
  3. GCIH
    Incident handling via SANS SEC504.
  4. GCFE
    Windows forensics fundamentals via SANS FOR500.
  5. GCFA
    Advanced forensics and threat hunting via SANS FOR508.
  6. GREM
    Malware reverse engineering for deep analysis.
🏢 Security Architect / CISO Track
  1. Security+
    Baseline.
  2. CySA+ or GSEC
    Technical depth in defense or broad security.
  3. CASP+ or CCSP
    Advanced technical architecture skills.
  4. CISSP
    The management-level credential for senior roles.
  5. CISM
    Security program management — complements CISSP.
  6. CGEIT
    Enterprise IT governance for board-level communication.
◆ ◆ ◆

Evidence-Based Study Methods

Research-backed techniques that measurably improve certification exam outcomes.

Spaced Retrieval Practice

Meta-analyses of spacing and retrieval practice show medium-to-large improvements in long-term retention (effect size g ≈ 0.74) compared to massed study or rereading alone. This is the single highest-leverage study technique available.

  • After each chapter, close the book and write down everything you can recall. Check what you missed. This single act of retrieval creates stronger memory traces than re-reading.
  • Convert chapter end-questions, key tables, and definitions into flashcards. Use spaced repetition software (Anki, RemNote) to schedule reviews at expanding intervals.
  • For MCQ-based certs (CISSP, CISA, Security+): create cards that mirror exam question format — scenario-based with 4 options, not simple fact recall.
  • For practical certs (OSCP, PNPT): keep a “lab journal” documenting each machine compromised, techniques used, and mistakes made. Review periodically.

Active Study Patterns

  • Primary book as linear pass: Read through all domains once, creating question-style notes as you go. Don’t try to memorize everything — build a map of the material.
  • Complementary books for weak domains only: Use the second book for targeted reinforcement, not as another linear read. This prevents diminishing returns.
  • Interleave domains: Mix practice questions from different domains rather than studying one domain exhaustively before moving to the next. Interleaving improves discrimination between similar concepts.
  • Pomodoro technique: 25-minute focused blocks with 5-minute breaks. After 4 blocks, take a 15–30 minute break. RCT meta-analyses show structured breaks improve sustained attention and reduce fatigue.

Practice Exam Strategy

  • Diagnostic mode first: Take one full practice exam cold at the start of your study to identify weak domains. Don’t score-chase — use it to guide your study plan.
  • Domain-specific drilling: After studying each domain, take domain-specific practice sets. Review every wrong answer — understand why the correct answer is right and why yours was wrong.
  • Simulation mode last: 1–2 weeks before exam day, take a timed, full-length practice exam under exam conditions. No notes, no breaks beyond what the real exam allows. This calibrates your time management and stamina.
  • Never memorize practice answers: If you recognize a question from a previous attempt, skip it. The goal is pattern recognition, not answer memorization.

Practical Exam Preparation (OSCP, PNPT, etc.)

  • Build a personal methodology: Document your enumeration, exploitation, and post-exploitation workflow. Follow it consistently in labs so it becomes automatic under exam pressure.
  • Lab journaling: For every machine, record: initial scan results, attack path taken, dead ends, final exploit chain, and lessons learned. This is your most valuable study resource.
  • Report template: Build your report template before exam day. Practice writing findings on lab machines so the format is second nature during the timed exam.
  • Time management: In OSCP, allocate approximate time per machine. If stuck after your time budget, move on. Coming back with fresh eyes after other successes often breaks the block.
◆ ◆ ◆

Exam Day Logistics

What to expect and how to prepare for exam delivery.

Pearson VUE (ISC2, CompTIA, Cisco, EC-Council, AWS)
  • Create a Pearson VUE account and link it to your certification body account.
  • Schedule via the Pearson VUE website or the certification body’s portal.
  • Test center or OnVUE (online proctored) — online requires a private room, clear desk, webcam, and stable internet.
  • Bring two forms of government-issued ID (one with photo, one with signature). Names must match your registration exactly.
  • Arrive 15 minutes early for test center. For online, start the check-in process 30 minutes before.
  • No personal items allowed: no phones, watches, notes, food, or drinks (test center provides lockers).
PSI (ISACA)
  • Schedule through ISACA’s certification portal, which connects to PSI.
  • Test center or remote proctoring available.
  • Remote proctoring requirements similar to Pearson VUE: private room, clear desk, webcam.
  • One government-issued photo ID required.
OffSec Exams
  • Schedule through the OffSec portal once you have an active course subscription.
  • All exams are remote, proctored via webcam. You connect to the exam VPN.
  • OSCP: 23 hours 45 minutes active exam + 24 hours to write and submit your report.
  • Prepare your Kali VM and tools in advance. Test your VPN connection.
  • Take screenshots of every step — your report must contain proof of exploitation.
  • Plan for breaks, food, and sleep (especially for 24-hour exams).
GIAC / SANS Exams
  • Schedule through the GIAC portal via ProctorU (remote) or Pearson VUE (test center).
  • Most GIAC exams are open-book: you can bring printed/handwritten notes and course materials.
  • Build a thorough index of your SANS books before the exam — this is the most critical prep step for GIAC.
  • Two practice exams are included with each exam attempt.
If You Fail
  • Most bodies provide a score breakdown by domain. Focus your restudy on weak domains.
  • Wait periods vary: 30 days (ISC2, GIAC), 14 days (CompTIA after 2nd attempt), varies (ISACA, OffSec).
  • Full exam fee typically applies for retakes (exceptions: OffSec with active subscription, TCM includes one free retake).
  • Don’t rush the retake. Analyze what went wrong, rebuild your study plan, and aim for a 2–4 week restudy minimum.
  • Score review / appeals: ISC2 and ISACA offer formal appeal processes, but overturns are rare. CompTIA and GIAC do not typically offer appeals.
Remote vs. Test Center
  • Test center pros: No home setup worries, reliable hardware, familiar “exam feel,” whiteboard/scratch paper provided.
  • Test center cons: Travel time, scheduling constraints, potential noise from other test-takers.
  • Remote pros: Convenience, flexible scheduling, familiar environment.
  • Remote cons: Strict room requirements, internet dependency (disconnection can void exam), potential proctor delays, no scratch paper (digital whiteboard only).
  • Recommendation: If you’ve never taken a remote proctored exam, try your least important certification first to learn the process.
◆ ◆ ◆

Cost Summary

Exam fees, estimated training costs, and annual renewal. All prices approximate, 2025–2026. Costs may vary by region.

Cert Exam USD Exam EUR Training (Self-Study) Training (Official) Annual Renewal Total (Self-Study Est.)
CISSP $749 €690 $50–150 $2,500–3,500 $125/yr AMF $749+
CCSP $599 €550 $50–100 $2,500–3,000 $125/yr AMF $599+
SSCP $249 €230 $40–80 $1,500–2,500 $65/yr AMF $249+
CC $199 €185 Free–$30 Free (ISC2) $50/yr AMF $199+
CGRC $599 €550 $40–80 $2,000–3,000 $125/yr AMF $599+
CSSLP $599 €550 $50–100 $2,500–3,000 $125/yr AMF $599+
CISA $760 €700 $50–150 $800–1,200 $45–85/yr $760+
CISM $760 €700 $50–150 $800–1,200 $45–85/yr $760+
CRISC $760 €700 $50–100 $800–1,200 $45–85/yr $760+
CGEIT $760 €700 $50–100 $800–1,200 $45–85/yr $760+
CDPSE $760 €700 $50–100 $800–1,200 $45–85/yr $760+
Security+ $404 €375 $30–80 $350–500 $75/3yr CE $404+
CySA+ $404 €375 $30–80 $350–500 $75/3yr CE $404+
PenTest+ $404 €375 $30–80 $350–500 $75/3yr CE $404+
CASP+ $494 €455 $40–80 $350–500 $75/3yr CE $494+
GSEC $949 €875 N/A $7,000–9,000 $479/4yr $949+
GPEN $949 €875 N/A $7,000–9,000 $479/4yr $949+
GCIH $949 €875 N/A $7,000–9,000 $479/4yr $949+
GCIA $949 €875 N/A $7,000–9,000 $479/4yr $949+
GCFA $949 €875 N/A $7,000–9,000 $479/4yr $949+
GCFE $949 €875 N/A $7,000–9,000 $479/4yr $949+
GREM $949 €875 N/A $7,000–9,000 $479/4yr $949+
GWAPT $949 €875 N/A $7,000–9,000 $479/4yr $949+
GFACT $949 €875 N/A $3,000–5,000 $479/4yr $949+
GXPN $949 €875 N/A $7,000–9,000 $479/4yr $949+
OSCP $1,749 €1,610 Included $1,749 (bundle) None (lifetime) $1,749+
OSEP $1,749 €1,610 Included $1,749 (bundle) None (lifetime) $1,749+
OSWE $1,749 €1,610 Included $1,749 (bundle) None (lifetime) $1,749+
OSWP $799 €735 Included $799 (bundle) None (lifetime) $799+
OSED $1,749 €1,610 Included $1,749 (bundle) None (lifetime) $1,749+
OSDA $1,749 €1,610 Included $1,749 (bundle) None (lifetime) $1,749+
CEH $1,199 €1,100 $50–100 $2,000–3,500 $80/yr $1,199+
CHFI $1,199 €1,100 $50–100 $2,000–3,500 $80/yr $1,199+
eJPT $249 €230 Free–$50 $299–499 (INE) None/3yr $249+
eCPPT $400 €370 Included $499+ (INE) None/3yr $400+
PNPT $399 €370 $30–100 $399 (bundle) None (lifetime) $399+
CyberOps Associate $330 €305 $30–60 $300–500 Recertify/3yr $330+
CCNP Security $660 €610 $50–100 $1,000–2,500 Recertify/3yr $660+
AWS Security Specialty $300 €275 $30–60 $300–600 Recertify/3yr $300+
AZ-500 $165 €155 Free–$30 Free (MS Learn) Free renewal/yr $165+
GCP Security Engineer $200 €185 $30–60 $300–600 Recertify/2yr $200+
Costs are approximate and may vary by region, membership status, and promotional pricing. GIAC exam-only pricing ($949) is available without SANS training, but the course is the primary study material. OffSec prices include course + labs + one exam attempt. ISACA member pricing is lower than non-member.
⚙ This page is informational only. No affiliate links, no tracking, no data collection. Prices verified March 2026.