Books, roadmaps, costs, and study methods for major cybersecurity certifications.
Curated for practitioners. No affiliate links. Updated for 2025–2026.
Certification paths and resources are community-curated. Verify current requirements with official bodies.
Quick Reference
41 certifications across 10 certification bodies. Costs are exam-only (training separate).
Cert
Body
Level
Domain
USD
EUR
Duration
Questions
Passing
Validity
Experience
CISSP
ISC2
Advanced
GRC / Management
$749
€690
3–6 hrs (CAT)
100–175
700 / 1000
3 yrs + 40 CPE/yr
5 yrs in 2+ domains
CCSP
ISC2
Advanced
Cloud Security
$599
€550
4 hrs
150
700 / 1000
3 yrs + 30 CPE/yr
5 yrs IT (3 in security, 1 in cloud)
SSCP
ISC2
Intermediate
Operations / Technical
$249
€230
4 hrs
150
700 / 1000
3 yrs + 20 CPE/yr
1 yr in 1+ domain
CC
ISC2
Entry
General Security
$199
€185
2 hrs
100
700 / 1000
3 yrs + 15 CPE/yr
None
CGRC
ISC2
Intermediate
GRC
$599
€550
3 hrs
125
700 / 1000
3 yrs + 20 CPE/yr
2 yrs in 1+ domain
CSSLP
ISC2
Advanced
AppSec / SDLC
$599
€550
4 hrs
175
700 / 1000
3 yrs + 30 CPE/yr
4 yrs in SDLC
CISA
ISACA
Advanced
Audit
$760
€700
4 hrs
150
450 / 800
3 yrs + 20 CPE/yr
5 yrs in IS audit
CISM
ISACA
Advanced
Security Management
$760
€700
4 hrs
150
450 / 800
3 yrs + 20 CPE/yr
5 yrs in infosec mgmt (3 in mgmt)
CRISC
ISACA
Advanced
Risk Management
$760
€700
4 hrs
150
450 / 800
3 yrs + 20 CPE/yr
3 yrs in IT risk mgmt
CGEIT
ISACA
Expert
IT Governance
$760
€700
4 hrs
150
450 / 800
3 yrs + 20 CPE/yr
5 yrs in IT governance
CDPSE
ISACA
Intermediate
Privacy Engineering
$760
€700
3.5 hrs
120
450 / 800
3 yrs + 20 CPE/yr
2 yrs in privacy
Security+
CompTIA
Entry
General Security
$404
€375
1.5 hrs
90 max
750 / 900
3 yrs + CEUs
None (2 yrs recommended)
CySA+
CompTIA
Intermediate
Defensive / SOC
$404
€375
2.5 hrs
85 max
750 / 900
3 yrs + CEUs
3–4 yrs hands-on
PenTest+
CompTIA
Intermediate
Offensive
$404
€375
2.5 hrs
85 max
750 / 900
3 yrs + CEUs
3–4 yrs hands-on
CASP+
CompTIA
Advanced
Security Architecture
$494
€455
2.5 hrs
90 max
Pass / Fail
3 yrs + CEUs
10 yrs general IT (5 in security)
GSEC
GIAC / SANS
Intermediate
General Security
$949
€875
4–5 hrs
106–180
73%
4 yrs + 36 CPE
None (SEC401 recommended)
GPEN
GIAC / SANS
Advanced
Offensive
$949
€875
3 hrs
82
75%
4 yrs + 36 CPE
None (SEC560 recommended)
GCIH
GIAC / SANS
Intermediate
Defensive / IR
$949
€875
4 hrs
106
70%
4 yrs + 36 CPE
None (SEC504 recommended)
GCIA
GIAC / SANS
Advanced
Defensive / Network
$949
€875
4 hrs
106
67%
4 yrs + 36 CPE
None (SEC503 recommended)
GCFA
GIAC / SANS
Advanced
DFIR
$949
€875
4 hrs
82
72%
4 yrs + 36 CPE
None (FOR508 recommended)
GCFE
GIAC / SANS
Intermediate
DFIR
$949
€875
4 hrs
82
71%
4 yrs + 36 CPE
None (FOR500 recommended)
GREM
GIAC / SANS
Advanced
Malware Analysis
$949
€875
4 hrs
75
73%
4 yrs + 36 CPE
None (FOR610 recommended)
GWAPT
GIAC / SANS
Intermediate
Offensive / Web
$949
€875
4 hrs
82
71%
4 yrs + 36 CPE
None (SEC542 recommended)
GFACT
GIAC / SANS
Entry
General Security
$949
€875
2 hrs
75
71%
4 yrs + 36 CPE
None
GXPN
GIAC / SANS
Expert
Offensive / Exploit Dev
$949
€875
3 hrs
60
67%
4 yrs + 36 CPE
None (SEC660 recommended)
OSCP
OffSec
Intermediate
Offensive
$1,749
€1,610
23 hrs 45 min
Practical (3 standalone + AD set)
70 points
Lifetime
None (PEN-200 course required)
OSEP
OffSec
Advanced
Offensive / Evasion
$1,749
€1,610
47 hrs 45 min
Practical
Secret flag(s)
Lifetime
OSCP or equivalent
OSWE
OffSec
Advanced
Offensive / Web
$1,749
€1,610
47 hrs 45 min
Practical
Secret flag(s)
Lifetime
OSCP or equivalent + web dev knowledge
OSWP
OffSec
Intermediate
Offensive / Wireless
$799
€735
3 hrs 45 min
Practical
Not disclosed
Lifetime
Basic networking
OSED
OffSec
Expert
Offensive / Exploit Dev
$1,749
€1,610
47 hrs 45 min
Practical
Not disclosed
Lifetime
OSCP + programming
OSDA
OffSec
Intermediate
Defensive / SOC
$1,749
€1,610
23 hrs 45 min
Practical
Not disclosed
Lifetime
Basic security knowledge
CEH
EC-Council
Intermediate
Offensive
$1,199
€1,100
4 hrs
125
70%
3 yrs + 120 ECE
2 yrs in infosec (or official training)
CHFI
EC-Council
Intermediate
DFIR
$1,199
€1,100
4 hrs
150
70%
3 yrs + 120 ECE
2 yrs in infosec (or official training)
eJPT
INE / eLearnSecurity
Entry
Offensive
$249
€230
48 hrs
Practical + MCQ
70%
3 yrs
None
eCPPT
INE / eLearnSecurity
Intermediate
Offensive
$400
€370
14 days (7 days exam + 7 days report)
Practical + Report
Report-based
3 yrs
eJPT or equivalent
PNPT
TCM Security
Intermediate
Offensive
$399
€370
5 days (pentest) + 2 days (report)
Practical + Report + Debrief
Report-based + debrief
Lifetime
None
CyberOps Associate
Cisco
Entry
Defensive / SOC
$330
€305
2 hrs
95–105
Not publicly disclosed
3 yrs
None
CCNP Security
Cisco
Advanced
Network Security
$660
€610
2 hrs (core) + 1.5 hrs (concentration)
~100 per exam
Not publicly disclosed
3 yrs
3–5 yrs networking
AWS Security Specialty
Cloud Vendors (AWS, Azure, GCP)
Advanced
Cloud Security
$300
€275
2.5 hrs
65
750 / 1000
3 yrs
5 yrs IT security + 2 yrs AWS
AZ-500
Cloud Vendors (AWS, Azure, GCP)
Intermediate
Cloud Security
$165
€155
2.5 hrs
40–60
700 / 1000
1 yr (annual renewal via free assessment)
1–2 yrs Azure security
GCP Security Engineer
Cloud Vendors (AWS, Azure, GCP)
Advanced
Cloud Security
$200
€185
2 hrs
50–60
Not publicly disclosed
2 yrs
3+ yrs industry + 1 yr GCP
◆ ◆ ◆
Certification Deep Dives
Detailed profiles with books, study resources, preparation advice, and realistic timelines.
🔒
ISC2
Gold Standard
ISC2 (International Information System Security Certification Consortium) is the world's leading cybersecurity professional organization, best known for the CISSP. All ISC2 exams are delivered via Pearson VUE.
Exam delivery: Pearson VUE (test center or online proctored)Retake: 30-day wait after 1st attempt, 60 days after 2nd, 90 days after 3rd. Max 3 retakes per year.Renewal: Annual CPE credits required (varies by cert). Annual Maintenance Fee (AMF).
Eight domains: Security & Risk Management, Asset Security, Security Architecture, Communication & Network Security, IAM, Security Assessment, Security Operations, and Software Development Security. Tests managerial and architectural thinking, not just technical knowledge.
Who It’s For
Senior security professionals, security managers, architects, consultants, and CISO-track candidates. Typically requires 5+ years of broad security experience.
Preparation Advice
Plan 3–5 months of study. Start with the Official Study Guide for domain coverage, then use the All-in-One for depth on weak areas. The CAT format means questions adapt — focus on understanding concepts deeply rather than memorizing facts. Practice "think like a manager" for exam mindset.
Recommended Books
Primary
ISC2 CISSP Official Study Guide, 10th Edition
Chapple, Stewart, Gibson — Sybex, 2024
Standard primary text, fully updated to April 2024 outline. 900+ practice questions.
Complementary
CISSP All-in-One Exam Guide, 9th Edition
Shon Harris, Fernando Maymí — McGraw-Hill
Deep narrative-style coverage. Excellent for second-pass conceptual depth.
Last-Week
Eleventh Hour CISSP, 3rd Edition
Eric Conrad et al.
Focused summary of highest-yield material for final review.
Practice
ISC2 CISSP Official Practice Tests
Chapple et al.
High-quality exam-style question bank.
Online Platforms
ISC2 Official Training — Self-paced and instructor-led options.
Destination Certification MindMap — Free YouTube series mapping all 8 domains visually.
Thor Teaches (Udemy) — Popular video course covering all domains.
Practice Exams
Boson CISSP Practice Exams — Widely regarded as closest to real exam difficulty.
ISC2 Official Practice Tests — Domain-mapped questions from the cert body.
Realistic Timeline
Experience Level
Estimated Prep Time
Beginner
5–7 months
Intermediate
3–5 months
Expert
4–8 weeks
$599 / €5504 hrs150 — MCQPass: 700 / 10003 yrs + 30 CPE/yrExp: 5 yrs IT (3 in security, 1 in cloud)
What It Covers
Six domains covering cloud concepts, architecture, data security, platform security, application security, and security operations in cloud environments.
Who It’s For
Cloud architects, security engineers, and consultants working with cloud deployments. Pairs well with CISSP.
Preparation Advice
Study the CSA Cloud Controls Matrix alongside the study guide. Focus on understanding shared responsibility models deeply.
Recommended Books
Primary
CCSP Official Study Guide, 3rd Edition
Sybex
Primary prep aligned with current cloud security domains.
Practice
CCSP Official Practice Tests
Sybex
Exam-style questions.
Online Platforms
ISC2 Official Training — Self-paced option available.
Practice Exams
Boson CCSP — Practice exam engine.
Realistic Timeline
Experience Level
Estimated Prep Time
Intermediate
2–4 months
Expert
3–6 weeks
$249 / €2304 hrs150 — MCQPass: 700 / 10003 yrs + 20 CPE/yrExp: 1 yr in 1+ domain
Software developers, architects, and DevSecOps engineers focused on secure development practices.
Preparation Advice
Focus on understanding secure SDLC phases and how security integrates into each stage.
Recommended Books
Primary
Official (ISC)2 Guide to the CSSLP CBK, 2nd Edition
Domain reference for secure SDLC topics.
Complementary
CSSLP Certification All-in-One Exam Guide
McGraw-Hill
Supplementary explanations and practice questions.
Realistic Timeline
Experience Level
Estimated Prep Time
Intermediate
2–4 months
📊
ISACA
Governance & Audit
ISACA focuses on IT governance, risk, compliance, and audit. Their certifications are globally recognized in GRC roles. Exams via PSI or ISACA remote proctoring.
Exam delivery: PSI (test center or remote proctored)Retake: Can retake after waiting period. Additional exam fees apply per attempt.Renewal: 20 CPE hours/year, 120 CPE over 3-year cycle. Annual maintenance fee.
$760 / €7004 hrs150 — MCQPass: 450 / 8003 yrs + 20 CPE/yrExp: 5 yrs in IS audit
What It Covers
Five domains: Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition/Development/Implementation, Information Systems Operations and Business Resilience, Protection of Information Assets.
Who It’s For
IT auditors, compliance managers, and governance professionals. Often required for Big Four audit roles.
Preparation Advice
The ISACA Review Manual is essential — the exam questions are written by the same organization. Focus on understanding the "ISACA way" of thinking about audit controls and risk.
Recommended Books
Primary
ISACA CISA Review Manual (latest edition)
ISACA
The definitive text for the 5 CISA domains.
Practice
CISA Review QAE Database
ISACA
Domain-mapped question practice.
Online Platforms
ISACA Online Review Course — Self-paced with practice questions.
Practice Exams
ISACA QAE Database — Official question bank — essential.
Privacy governance, architecture, data lifecycle, and technology implementation for privacy compliance.
Who It’s For
Privacy engineers, DPOs, and engineers implementing GDPR/privacy controls in systems.
Preparation Advice
Understand privacy-by-design principles and how they translate to technical controls.
Recommended Books
Primary
ISACA CDPSE Review Manual
ISACA
Main prep reference for privacy engineering.
Realistic Timeline
Experience Level
Estimated Prep Time
Intermediate
2–3 months
💻
CompTIA
Industry Foundation
CompTIA offers vendor-neutral IT certifications recognized worldwide. Security+, CySA+, PenTest+, and CASP+ form the cybersecurity pathway. Exams via Pearson VUE.
Exam delivery: Pearson VUE (test center or online)Retake: No wait after 1st fail. 14-day wait for subsequent retakes. Full fee per attempt.Renewal: 3-year renewal cycle. Renew via CEUs or by passing a higher cert. CertMaster CE available.
General security concepts, threats/vulnerabilities/mitigations, security architecture, security operations, and security program management/oversight.
Who It’s For
Entry-level security professionals, IT administrators moving into security, DoD 8570 baseline certification. Most widely required entry-level security cert.
Preparation Advice
Performance-based questions (PBQs) require hands-on skills — set up a home lab. Study the exam objectives checklist methodically. Don't skip the PBQs in practice.
Recommended Books
Primary
CompTIA Security+ Study Guide (SY0-701)
Sybex
Updated to current objectives with chapter reviews and online practice.
Complementary
CompTIA Security+ (SY0-701) Certification Guide
Ian Neil
Focused, exam-driven book with discount voucher. Frequently recommended 2024–2026.
Online Platforms
Professor Messer (YouTube) — Free complete video course covering all objectives.
CompTIA CertMaster — Official adaptive learning and labs.
Practice Exams
Dion Training Practice Exams — Highly rated, includes PBQ simulations.
Professor Messer Practice Exams — Affordable, well-aligned with exam difficulty.
Planning and scoping, information gathering, attacks and exploits, reporting and communication, and tools and code analysis.
Who It’s For
Aspiring penetration testers. Bridges Security+ to OSCP-level skills.
Preparation Advice
Combine book study with hands-on lab practice. TryHackMe and HackTheBox are good complements.
Recommended Books
Primary
CompTIA PenTest+ All-in-One Exam Guide
McGraw-Hill
Comprehensive coverage with scenario-style questions.
Alternative
PenTest+ Study Guide
Sybex
Alternative primary aligned with exam objectives.
Online Platforms
TryHackMe — Guided pentesting rooms and paths.
HackTheBox — Practical hacking challenges.
Realistic Timeline
Experience Level
Estimated Prep Time
Beginner
3–5 months
Intermediate
2–3 months
$494 / €4552.5 hrs90 max — MCQ + Performance-BasedPass: Pass / Fail3 yrs + CEUsExp: 10 yrs general IT (5 in security)
What It Covers
Security architecture, operations, engineering, cryptography, and governance/risk/compliance at an enterprise level.
Who It’s For
Senior security architects and engineers. Technical counterpart to CISSP (hands-on vs management).
Preparation Advice
Focus on enterprise scenarios and architectural decision-making. PBQs are significant.
Recommended Books
Primary
CASP+ CompTIA Advanced Security Practitioner Study Guide
Sybex
Enterprise security architecture with hands-on scenarios.
Realistic Timeline
Experience Level
Estimated Prep Time
Intermediate
2–4 months
Expert
4–6 weeks
🎓
GIAC / SANS
Training-Coupled
GIAC certifications validate skills taught in SANS courses. Exams are proctored via ProctorU or Pearson VUE. The associated SANS training is separate and expensive, but the exam can be taken independently.
Exam delivery: ProctorU (remote) or Pearson VUERetake: 30-day wait. Retake fee applies. 2 retakes per certification attempt.Renewal: 36 CPE credits every 4 years. $479 renewal fee.
Advanced exploitation techniques, network attacks, crypto attacks, fuzzing, and exploit development. Aligned with SANS SEC660.
Who It’s For
Advanced penetration testers and exploit developers.
Preparation Advice
SEC660 is extremely technical. Strong programming and networking knowledge required beforehand.
Recommended Books
Primary
SANS SEC660 Course Materials
SANS Institute
Course books are the exam prep.
Realistic Timeline
Experience Level
Estimated Prep Time
Expert
2–4 months
🖤
OffSec
Hands-On Offensive
OffSec (formerly Offensive Security) offers practical, hands-on certifications. Exams are 100% practical — no multiple choice. OSCP is the gold standard for penetration testers.
Exam delivery: OffSec proctored (remote, VPN-based lab exam)Retake: Retake included with active Learn subscription. Otherwise ~$249 per retake.Renewal: No expiration. Certification is lifetime once earned.
Network penetration testing, web application attacks, Active Directory exploitation, privilege escalation, client-side attacks, and report writing.
Who It’s For
Aspiring and practicing penetration testers. The industry's most recognized hands-on offensive certification.
Preparation Advice
Complete ALL PEN-200 lab machines. Practice on HackTheBox and Proving Grounds. The exam is 100% practical — 23 hours 45 minutes to compromise machines and write a report. Time management and methodology are critical. Document everything during labs.
Recommended Books
Primary
OffSec PEN-200 Course Materials
OffSec
PDFs and labs that come with enrollment. No substitute.
Community
The Web Application Hacker's Handbook
Stuttard & Pinto
Deep web exploitation reference.
Community
Penetration Testing: A Hands-On Introduction
Georgia Weidman
Broad practical intro to penetration testing.
Community
The Hacker Playbook series
Scenario-style offensive playbooks.
Online Platforms
OffSec Proving Grounds — Practice machines similar to OSCP labs.
HackTheBox — Retired machines with walkthroughs. TJNull's OSCP list is essential.
TryHackMe — Guided offensive paths for building fundamentals.
Practice Exams
OffSec Proving Grounds Practice — Closest to actual exam machines.
SOC analysts and defensive security practitioners.
Preparation Advice
OffSec's defensive cert. Focus on practical detection and analysis skills.
Recommended Books
Primary
OffSec SOC-200 Course Materials
OffSec
Course materials and labs.
Realistic Timeline
Experience Level
Estimated Prep Time
Intermediate
2–4 months
🔭
EC-Council
Ethical Hacking
EC-Council is known for the Certified Ethical Hacker (CEH) and related certifications. Exams via Pearson VUE or EC-Council Exam Center.
Exam delivery: Pearson VUE or ECC Exam CenterRetake: Wait period varies. Retake voucher required.Renewal: 3-year renewal. 120 ECE credits over 3 years. $80/year membership fee.
$1,199 / €1,1004 hrs125 — MCQPass: 70%3 yrs + 120 ECEExp: 2 yrs in infosec (or official training)
What It Covers
Footprinting, scanning, enumeration, system hacking, malware, sniffing, social engineering, DoS, session hijacking, web server/app hacking, SQL injection, wireless, mobile, IoT, cloud, and cryptography.
Who It’s For
Security professionals seeking a broad ethical hacking certification. Often required for government/DoD roles.
Preparation Advice
CEH is knowledge-based (MCQ), not hands-on like OSCP. Focus on memorizing tool names, attack categories, and methodology steps. CEH Practical (separate exam) adds a hands-on component.
Recommended Books
Primary
CEH v13 Official Courseware
EC-Council
Official curriculum covering all exam domains.
Complementary
CEH All-in-One Exam Guide
Matt Walker — McGraw-Hill
Comprehensive exam-focused coverage.
Online Platforms
EC-Council iLabs — Official hands-on practice environment.
Practice Exams
Boson CEH Practice Exams — Well-regarded practice questions.
Realistic Timeline
Experience Level
Estimated Prep Time
Beginner
3–4 months
Intermediate
1–2 months
$1,199 / €1,1004 hrs150 — MCQPass: 70%3 yrs + 120 ECEExp: 2 yrs in infosec (or official training)
What It Covers
Digital forensics process, evidence handling, OS forensics, network forensics, web forensics, database forensics, cloud forensics, and malware forensics.
Who It’s For
Digital forensic investigators and law enforcement professionals.
Preparation Advice
Study the forensic methodology and evidence handling procedures thoroughly.
Recommended Books
Primary
CHFI Official Courseware
EC-Council
Official curriculum.
Realistic Timeline
Experience Level
Estimated Prep Time
Intermediate
2–3 months
🌱
INE / eLearnSecurity
Practical Training
INE (formerly eLearnSecurity) offers practical, lab-based certifications. Exams are hands-on penetration tests and report writing. Growing reputation as affordable practical alternatives.
Exam delivery: INE platform (remote, lab-based)Retake: Retake included with active INE Premium subscription.Renewal: No formal CPE. Certification valid for 3 years.
Networking, web application testing, host and network penetration testing, and assessment methodologies.
Who It’s For
Career starters in penetration testing. Affordable, practical alternative to start before OSCP.
Preparation Advice
Complete the INE PTS (Penetration Testing Student) course. The exam is hands-on — practice on lab environments.
Recommended Books
Primary
INE PTS Course Materials
INE
Free course content covering exam topics.
Online Platforms
INE Free Starter Pass — Free access to foundational courses.
TryHackMe — Complementary hands-on practice.
Realistic Timeline
Experience Level
Estimated Prep Time
Beginner
2–4 months
Intermediate
2–4 weeks
$400 / €37014 days (7 days exam + 7 days report)Practical + Report — 100% Practical + Written ReportPass: Report-based3 yrsExp: eJPT or equivalent
What It Covers
Advanced penetration testing including pivoting, exploitation, post-exploitation, and professional reporting.
Who It’s For
Penetration testers building toward OSCP-level skills. Good bridge certification.
Preparation Advice
Focus on pivoting and report writing. The report is a critical component of the exam.
Recommended Books
Primary
INE PTP Course Materials
INE
Penetration Testing Professional course.
Online Platforms
INE Premium — Full course access with labs.
Realistic Timeline
Experience Level
Estimated Prep Time
Beginner
3–5 months
Intermediate
1–3 months
🛠
TCM Security
Practical & Affordable
TCM Security offers practical certifications focused on real-world penetration testing. Founded by Heath Adams (TheCyberMentor). Growing community recognition.
AZ-500, AWS Security, or GCP Security Platform-specific security skills for your primary cloud.
CySA+ Defensive monitoring skills applicable to cloud SOC.
CCSP Vendor-neutral cloud security architecture and governance.
CISSP Senior security leadership credential.
🔍 DFIR / Threat Hunter
Security+ Security baseline.
CySA+ Detection and analysis fundamentals.
GCIH Incident handling via SANS SEC504.
GCFE Windows forensics fundamentals via SANS FOR500.
GCFA Advanced forensics and threat hunting via SANS FOR508.
GREM Malware reverse engineering for deep analysis.
🏢 Security Architect / CISO Track
Security+ Baseline.
CySA+ or GSEC Technical depth in defense or broad security.
CASP+ or CCSP Advanced technical architecture skills.
CISSP The management-level credential for senior roles.
CISM Security program management — complements CISSP.
CGEIT Enterprise IT governance for board-level communication.
◆ ◆ ◆
Evidence-Based Study Methods
Research-backed techniques that measurably improve certification exam outcomes.
Spaced Retrieval Practice
Meta-analyses of spacing and retrieval practice show medium-to-large improvements in long-term retention (effect size g ≈ 0.74) compared to massed study or rereading alone. This is the single highest-leverage study technique available.
After each chapter, close the book and write down everything you can recall. Check what you missed. This single act of retrieval creates stronger memory traces than re-reading.
Convert chapter end-questions, key tables, and definitions into flashcards. Use spaced repetition software (Anki, RemNote) to schedule reviews at expanding intervals.
For MCQ-based certs (CISSP, CISA, Security+): create cards that mirror exam question format — scenario-based with 4 options, not simple fact recall.
For practical certs (OSCP, PNPT): keep a “lab journal” documenting each machine compromised, techniques used, and mistakes made. Review periodically.
Active Study Patterns
Primary book as linear pass: Read through all domains once, creating question-style notes as you go. Don’t try to memorize everything — build a map of the material.
Complementary books for weak domains only: Use the second book for targeted reinforcement, not as another linear read. This prevents diminishing returns.
Interleave domains: Mix practice questions from different domains rather than studying one domain exhaustively before moving to the next. Interleaving improves discrimination between similar concepts.
Pomodoro technique: 25-minute focused blocks with 5-minute breaks. After 4 blocks, take a 15–30 minute break. RCT meta-analyses show structured breaks improve sustained attention and reduce fatigue.
Practice Exam Strategy
Diagnostic mode first: Take one full practice exam cold at the start of your study to identify weak domains. Don’t score-chase — use it to guide your study plan.
Domain-specific drilling: After studying each domain, take domain-specific practice sets. Review every wrong answer — understand why the correct answer is right and why yours was wrong.
Simulation mode last: 1–2 weeks before exam day, take a timed, full-length practice exam under exam conditions. No notes, no breaks beyond what the real exam allows. This calibrates your time management and stamina.
Never memorize practice answers: If you recognize a question from a previous attempt, skip it. The goal is pattern recognition, not answer memorization.
Practical Exam Preparation (OSCP, PNPT, etc.)
Build a personal methodology: Document your enumeration, exploitation, and post-exploitation workflow. Follow it consistently in labs so it becomes automatic under exam pressure.
Lab journaling: For every machine, record: initial scan results, attack path taken, dead ends, final exploit chain, and lessons learned. This is your most valuable study resource.
Report template: Build your report template before exam day. Practice writing findings on lab machines so the format is second nature during the timed exam.
Time management: In OSCP, allocate approximate time per machine. If stuck after your time budget, move on. Coming back with fresh eyes after other successes often breaks the block.
◆ ◆ ◆
Exam Day Logistics
What to expect and how to prepare for exam delivery.
Remote cons: Strict room requirements, internet dependency (disconnection can void exam), potential proctor delays, no scratch paper (digital whiteboard only).
Recommendation: If you’ve never taken a remote proctored exam, try your least important certification first to learn the process.
◆ ◆ ◆
Cost Summary
Exam fees, estimated training costs, and annual renewal. All prices approximate, 2025–2026. Costs may vary by region.
Cert
Exam USD
Exam EUR
Training (Self-Study)
Training (Official)
Annual Renewal
Total (Self-Study Est.)
CISSP
$749
€690
$50–150
$2,500–3,500
$125/yr AMF
$749+
CCSP
$599
€550
$50–100
$2,500–3,000
$125/yr AMF
$599+
SSCP
$249
€230
$40–80
$1,500–2,500
$65/yr AMF
$249+
CC
$199
€185
Free–$30
Free (ISC2)
$50/yr AMF
$199+
CGRC
$599
€550
$40–80
$2,000–3,000
$125/yr AMF
$599+
CSSLP
$599
€550
$50–100
$2,500–3,000
$125/yr AMF
$599+
CISA
$760
€700
$50–150
$800–1,200
$45–85/yr
$760+
CISM
$760
€700
$50–150
$800–1,200
$45–85/yr
$760+
CRISC
$760
€700
$50–100
$800–1,200
$45–85/yr
$760+
CGEIT
$760
€700
$50–100
$800–1,200
$45–85/yr
$760+
CDPSE
$760
€700
$50–100
$800–1,200
$45–85/yr
$760+
Security+
$404
€375
$30–80
$350–500
$75/3yr CE
$404+
CySA+
$404
€375
$30–80
$350–500
$75/3yr CE
$404+
PenTest+
$404
€375
$30–80
$350–500
$75/3yr CE
$404+
CASP+
$494
€455
$40–80
$350–500
$75/3yr CE
$494+
GSEC
$949
€875
N/A
$7,000–9,000
$479/4yr
$949+
GPEN
$949
€875
N/A
$7,000–9,000
$479/4yr
$949+
GCIH
$949
€875
N/A
$7,000–9,000
$479/4yr
$949+
GCIA
$949
€875
N/A
$7,000–9,000
$479/4yr
$949+
GCFA
$949
€875
N/A
$7,000–9,000
$479/4yr
$949+
GCFE
$949
€875
N/A
$7,000–9,000
$479/4yr
$949+
GREM
$949
€875
N/A
$7,000–9,000
$479/4yr
$949+
GWAPT
$949
€875
N/A
$7,000–9,000
$479/4yr
$949+
GFACT
$949
€875
N/A
$3,000–5,000
$479/4yr
$949+
GXPN
$949
€875
N/A
$7,000–9,000
$479/4yr
$949+
OSCP
$1,749
€1,610
Included
$1,749 (bundle)
None (lifetime)
$1,749+
OSEP
$1,749
€1,610
Included
$1,749 (bundle)
None (lifetime)
$1,749+
OSWE
$1,749
€1,610
Included
$1,749 (bundle)
None (lifetime)
$1,749+
OSWP
$799
€735
Included
$799 (bundle)
None (lifetime)
$799+
OSED
$1,749
€1,610
Included
$1,749 (bundle)
None (lifetime)
$1,749+
OSDA
$1,749
€1,610
Included
$1,749 (bundle)
None (lifetime)
$1,749+
CEH
$1,199
€1,100
$50–100
$2,000–3,500
$80/yr
$1,199+
CHFI
$1,199
€1,100
$50–100
$2,000–3,500
$80/yr
$1,199+
eJPT
$249
€230
Free–$50
$299–499 (INE)
None/3yr
$249+
eCPPT
$400
€370
Included
$499+ (INE)
None/3yr
$400+
PNPT
$399
€370
$30–100
$399 (bundle)
None (lifetime)
$399+
CyberOps Associate
$330
€305
$30–60
$300–500
Recertify/3yr
$330+
CCNP Security
$660
€610
$50–100
$1,000–2,500
Recertify/3yr
$660+
AWS Security Specialty
$300
€275
$30–60
$300–600
Recertify/3yr
$300+
AZ-500
$165
€155
Free–$30
Free (MS Learn)
Free renewal/yr
$165+
GCP Security Engineer
$200
€185
$30–60
$300–600
Recertify/2yr
$200+
Costs are approximate and may vary by region, membership status, and promotional pricing. GIAC exam-only pricing ($949) is available without SANS training, but the course is the primary study material. OffSec prices include course + labs + one exam attempt. ISACA member pricing is lower than non-member.
⚙ This page is informational only. No affiliate links, no tracking, no data collection. Prices verified March 2026.