Guide to Cybersecurity Certifications with Ranking — 2026 Update (the AI Era)

Cybersecurity certifications — 2026 update, ranking and the job market in the AI era

I wrote this post in April 2024, and it has since become one of the most-read pieces on this blog. There’s just one problem: in two years it has aged more than many guides do in a decade. 💥 CASP+ formally no longer exists, OSCP got a successor with an expiration date, CEH picked up AI modules, the free ISC2 program is over, and exam prices have climbed sharply. And something bigger happened along the way: AI started rearranging the very job market these certifications were supposed to be a ticket into.

So instead of writing a new post, I’m simply updating this one. Below you’ll find the same 6-level ranking, but with exam prices and versions as of August 2026, a fresh comparison of job-market demand (I repeated my Indeed analysis after two years — the conclusions are more interesting than I expected), and a new section on what AI is doing to certifications.

The biggest changes since 2024, in a nutshell:

  • CompTIA CASP+ has been rebranded as SecurityX (December 2024), and CompTIA exam prices rose by 20–30% on average
  • OffSec introduced OSCP+ — the same certification, but with a 3-year expiration date
  • CEH reached version 13, complete with AI modules
  • ISC2 ended its free CC program after crossing one million certified — today the exam costs $199
  • ISACA released its first strictly AI-focused certifications: AAIA (AI audit) and AAISM (AI security management), plus the hands-on CCOA for SOC analysts
  • CompTIA joined the race: SecAI+ ($298) debuted in February 2026 — a certification in securing AI systems and using AI for defense; SecOT+ is announced for December 2026
  • demand for entry-level certifications (A+, ITIL) dropped hard, while hands-on and cloud ones (OSCP, CCSP, CCSK) took off

Table of Contents

  1. What AI has done to the job market (and why you should know before picking a certification)
  2. The job market 2024 vs 2026 — I repeated my Indeed analysis
  3. The ranking: 6 levels of certification
  4. New players: the certifications the community fell in love with
  5. Comparison table of all certifications
  6. Do certifications still make sense in 2026?
  7. FAQ
  8. My subjective take and recommended learning resources

What AI has done to the job market (and why you should know before picking a certification)

Two years ago I wrote that certifications “don’t get you hired any more than money buys happiness, but they can significantly enrich a CV when you’re entering the job market.” Today I have to sharpen that sentence: “entering the job market” itself looks different than it did when most of these certifications were designed.

Louis Nyffenegger, founder of PentesterLab (the same platform I’ve been recommending at the end of this post for years), said something on a webinar that stuck with me: we’re going to become triagers of whatever AI spits out. That’s exactly what working in IT is starting to look like right now. Less and less “hunting for vulnerabilities from scratch,” more and more automating, verifying, filtering, and putting into business context what the tools have generated. The difference is that the tools have become incomparably smarter — and available to everyone.

What does the hard data say?

Stanford researchers (Erik Brynjolfsson’s team, the “Canaries in the Coal Mine” paper, November 2025) analyzed payroll data from the largest US payroll provider. The conclusion: employment of 22–25-year-olds in the occupations most exposed to generative AI fell by roughly 16% in relative terms — while employment of experienced specialists in the very same roles stayed stable or grew. Put plainly: AI isn’t firing seniors. AI is closing the door juniors used to walk through into the profession.

ISC2, in its Cybersecurity Workforce Study 2025 (16,000 respondents, December 2025), fills in the rest of the picture:

  • 59% of organizations report critical or significant skills gaps — a year earlier it was 44%. Gaps are no longer patched with headcount, but with specific skills.
  • The single biggest skills gap? AI — named by 41% of organizations. Ahead of cloud, ahead of application security, ahead of everything.
  • 39% of organizations have hiring freezes, and 24% have gone through layoffs in their security teams.
  • And my favorite number in the entire report: only 6% of respondents entered the industry through certifications. The largest share (56%) — through IT experience.
  • At the same time, 73% of respondents believe AI will create new, more specialized roles — not less work, but different work.

Lesson #1: A certification is no longer an entry ticket — it’s becoming an HR filter and a regulatory compliance requirement. The entry ticket in 2026 looks like this: you can verify whether what AI spat out is true — and what it means for the business. A certification can attest to that. But it won’t replace it.

Does that mean the ranking below is pointless? Quite the opposite. That’s exactly why I updated it: since certifications keep getting more expensive and their role is changing, it’s all the more important to pick the right one, at the right moment in your career — instead of collecting pieces of paper. Especially since the market doesn’t price them all the same, as the next section shows.

The job market 2024 vs 2026 — I repeated my Indeed analysis

In 2024 I did a simple thing: I typed certification names into Indeed’s job search (US market) and wrote down the number of postings. Not science — a quick demand poll. But repeated after two years with the same method (no filters, as of August 9, 2026), it gives you something more valuable than a single measurement: a direction.

Comparison table 2024 vs 2026: average annual salaries in USD and Indeed job posting counts for 17 cybersecurity certifications

Here’s what I read out of it (between the lines, as usual 😈):

CISSP is still the king — 10,350 postings, +43% in two years. If HR anywhere in the world knows one cybersecurity certification, it’s this one. That hasn’t changed, and probably won’t anytime soon.

Entry-level certifications are nosediving. CompTIA A+ fell from 6,096 to 2,833 postings (-54%), ITIL 4 Foundation dropped by half, SSCP and CCNA are in the red too. It’s exactly the same story the Stanford data tells: the “entry” positions these certifications used to be a pass into simply exist in smaller numbers. Helpdesk and first-line support are the easiest targets for automation.

Hands-on skills, cloud, and risk management are growing. OSCP +207% (627 → 1,925 postings). CCSK +188%, CCSP +175%, CRISC +122%, CISM +83%. The market pays for two things: a documented ability to actually do something with your hands, and the ability to manage risk it doesn’t understand itself. Both are hard to automate.

A treat for the persistent: 1,776 postings still require “CASP+” — a certification that formally hasn’t existed since December 2024. The new name, SecurityX, shows up in 749. Recruiters update themselves more slowly than certification vendors do. 😈 Meanwhile OSCP+ — the new variant with an expiration date — has already managed to appear in 1,435 postings.

Is there more of this work overall, or less? More. America’s CyberSeek counted 514,000 open cybersecurity positions in the 12 months to April 2025 — 57,000 (+12%) more than a year earlier. On top of that, the BLS projects +29% employment growth for security analysts in the decade to 2034 — several times faster than the average across all occupations. The paradox: at the very same time, 39% of organizations are freezing hiring (ISC2). How is that possible? The market is growing and raising the entry bar at the same time.

You can see it most clearly in the senior/junior split. I checked with the same method (Indeed, US, August 2026): the phrase “senior security” — 1,284 postings. “Junior security” — 116. “Entry level security” — 142. For every junior posting today there are about five senior ones. That’s exactly the picture from the Stanford data: cybersecurity work exists — but less and less of it is the kind you used to start a career with.

Salaries? Growing — calmly but steadily. The median for security analysts in the US is $124,910 a year (BLS, May 2024 data) versus $120,360 a year earlier — +3.8% year over year.

And which certification pays best? I counted the same way I did two years ago — straight from the postings. Methodology unchanged: for each certification I go through the Indeed results (US) and, for every posting that lists a salary range, I take the midpoint. This time that added up to 1,451 data points from over 2,000 postings (31 to 233 per certification). One note before you look at the table: all salaries here are in USD per year; the 2024 figures are converted from my original PLN analysis at the April 24, 2024 NBP rate of 4.0417.

What comes out of it:

  • The new salary king: CISM — an average of $166,405 a year (+29%). Two years ago cloud (CCSK) was on top; today it’s information security management. The market pays best not for clicking, but for taking responsibility.
  • Risk is chasing management: CRISC $156,814 (+29%). Paired with its +122% growth in postings, that makes it the strongest quiet winner of the whole comparison.
  • No revolution at the top: CISSP $153,702 (+19%), CCSK $150,853 (+16%), CCSP $148,989 (+22%) — management, risk, and cloud occupy the entire podium.
  • Declines: only CASP+ (−1%) and A+ (−12%). CASP+ is a job-ad zombie by now: the new, better-paying roles ask for SecurityX. And CEH? It barely moved (+2%) despite a +61% jump in demand — more and more postings, but in increasingly lower-priced roles.
  • The biggest percentage jump in pay: Security+ (+30%) — unless you count ITIL 4 Foundation’s +34%, which I’d take with a grain of salt: the phrase “ITIL 4 Foundation” appears today mostly in postings for senior management roles, not because the certification itself delivers that much.

The comparison in chart form below:

Charts: average annual salaries in USD and job posting counts for cybersecurity certifications — 2024 vs 2026 comparison

For the record: Skillsoft’s global survey (2025) shows a matching top of the table — cloud and risk management at the peak — so this isn’t an artifact of my sample.

On my home market, in Poland, there’s no per-certification data at all. The reference point we do have: according to the HackerU/Devire report (2023/24 data), salary ranges for security engineers stretched from about PLN 10k gross a month for juniors to about PLN 30k for seniors — I haven’t seen a newer, equally comprehensive edition yet. If you know fresher Polish per-certification data, drop it in a comment.

Lesson #2: Don’t ask “which certification is easiest to get” — ask “what is the market paying more and more for.” In 2026 the answer is: hands-on offensive skills, cloud security, and risk management. Entry-level certifications still make sense — but no longer as a guarantee of a first job, rather as a structured curriculum for learning the basics.

The ranking: 6 levels of certification

Pyramid of the 6 cybersecurity certification levels — 2026 edition, from CompTIA A+ and ISC2 CC to CISSP and CCSK

The criteria haven’t changed: industry recognition and name value, market salary on offer, certification costs, difficulty, and how practical the knowledge is. All prices are official vendor rates in USD, as of August 2026 (depending on where you live, VAT and exchange rates come on top, and some vendors use regional pricing).

What’s changed in the ranking versus 2024:

  • The levels get new names. I’m swapping the old “First/Starter/Getting-hooked…” labels for something I know from work better than my own pocket: the anatomy of a real attack. Learning this trade follows exactly the same path — first reconnaissance, then the first foothold, until one day you’re holding the keys to the kingdom. The order and contents of the levels are unchanged; only the signage changes (and the subtitles stay, because you like them).
  • Security+ moves from level 5 down to level 3. In 2024 I placed it high because that’s how recruiters see it — but I kept describing it as “foundational,” and that was an inconsistency several of you rightly called out. Its name recognition is world-class; its difficulty — solidly foundational. Consider this housekeeping.
  • OSCP becomes OSCP+ (more on the difference below), CASP+ becomes SecurityX.
  • From the ISACA lineup, CSX-P is out (retired by the vendor); CCOA, AAIA, and AAISM are in. There’s also a CompTIA newcomer — SecAI+.
  • Everything else stays — this structure has held up for two years and I’m not going to break it just for the sake of change.

1. Reconnaissance — “You’ve started doing something!”

Every attack starts with scoping out the terrain. So does a career: at this level you’re checking whether this industry is for you at all.

CompTIA A+ — $274 per exam (you need two: $548 total)

CompTIA A+ certification logo

The absolute entry ticket to IT: hardware, operating systems, networks, security basics, and troubleshooting. Since 2025 a new exam series is in effect — 220-1201 and 220-1202 (the previous 220-110x series was retired). No formal prerequisites; CompTIA recommends 9–12 months of hands-on experience. Mind the price change: in 2024 the pair cost $438, today it’s $548 — while demand in job postings has halved. If your goal is security rather than helpdesk, consider starting straight with CC or Security+.

CC – Certified in Cybersecurity (ISC2) — $199

CC – Certified in Cybersecurity (ISC2) certification logo

A big change here: ISC2 ended its “One Million Certified in Cybersecurity” program, under which the exam was free — the goal of one million certified was reached. Today you pay $199. CC is still a great, honest “first security certification”: core security concepts, governance, operations, incident response. A good signal to an employer that you take the subject seriously — but no longer free, so do the cost/benefit math.

2. Initial Access — “The first step is behind you”

In an attack, this is the moment you gain your first foothold in the victim’s network. You’re grabbing your own first foothold in the industry: the fundamentals without which you can’t go any further.

CompTIA Network+ — $399

CompTIA Network+ certification logo

Networking from the ground up: configuring and maintaining devices, routing, segmentation, network security standards, troubleshooting. A fun fact from my Indeed analysis: it’s one of the strongest climbers in job postings (+101%). Networks are still the foundation — for security people too. The price went up from $319 (2024) to $399.

CompTIA PenTest+ — $439

CompTIA PenTest+ certification logo

Penetration testing theory: planning, reconnaissance, scanning, exploitation, reporting. The current exam version, PT0-003, also covers attacks on cloud environments and AI-related topics. Honestly, though: it’s still an exam about pentesting, not an exam in pentesting — real practice only gets verified by OSCP+ or actual labs.

SSCP (ISC2) — $249

SSCP (ISC2) certification logo

One of the few prices that haven’t moved. A solid certification for system and network administrators pivoting toward security: seven domains from access control through cryptography to incident response. It’s slipping a bit in postings (-17%), but as a way to structure “admin” knowledge for security — still a good option.

ITIL 4 Foundation — ~€370 (exam via PeopleCert; prices vary by region)

ITIL 4 Foundation certification logo

IT service management: the value chain, practices, the four dimensions of ITSM. Postings are down by half — and frankly, on a purely security-focused path ITIL was always a supplement, never a foundation. I’m keeping it in the ranking for people aiming at roles where operations meet security.

3. Privilege Escalation — “You’re starting to get it”

At this stage the attacker turns a regular user account into an account with real power. You’re turning “I do a bit of everything” into an actual specialization.

CompTIA Security+ — $439 (moved down from level 5)

CompTIA Security+ certification logo

The most recognizable foundational security certification in the world — partly because it’s a requirement in many US public institutions. Cryptography, IAM, network and application security, threats, regulatory compliance. Postings up +60%. Sadly, the price “grew in strength” too: $349 → $439. If you’re going to do one theoretical certification at the start of your journey — I’d still point to this one.

CompTIA CySA+ — $439

CompTIA CySA+ certification logo

Security analytics: monitoring, detection, threat analysis, response. A good direction for future SOC analysts — and demand is growing (+52%). Worth weighing against ISACA’s new CCOA (below), which targets the same role.

CCNA (Cisco) — $300

CCNA (Cisco) certification logo

The networking classic: routing and switching, wireless, automation, security fundamentals. A slight dip in postings (-14%) — but CCNA is still one of those certifications “everyone knows,” and a strong foundation for network security.

CEH (EC-Council) — $1,199 (exam at a Pearson VUE center) + $100 application fee

CEH (EC-Council) certification logo

I stand by what I wrote two years ago: mocked by veterans for being theoretical, adored by recruiters. Since September 2024 version v13 is in effect, heavily marketed as “AI-powered” — it added modules on attacking and leveraging AI tools. Postings +61%, so the HR value is holding up well. But the ratio of price to practical knowledge is still the worst in the entire lineup. For that money you’re almost at an OSCP+.

GSEC (GIAC) — $999

GSEC (GIAC) certification logo

A broad, solid “security essentials” certification from GIAC/SANS: network defense, cryptography, system hardening, intrusion detection. The price jumped from $949 to $999 (and with a SANS course attached it’s a different price league entirely). Demand is stable. Quality — as always with SANS — beyond reproach.

Professional Cloud Security Engineer (Google) — $200

Google Professional Cloud Security Engineer certification logo

Security on GCP: IAM, network configuration, data protection, monitoring (Security Command Center, Cloud Armor, IAP). Still the cheapest way to document cloud skills with one of the big three.

AWS Certified Security – Specialty — $300

AWS Certified Security – Specialty certification logo

An advanced specialization for people working with AWS (current exam: SCS-C03): IAM, KMS, Security Hub, GuardDuty, security automation. And note: according to Skillsoft this is the best-paying IT certification, full stop (~$204k a year in the global data). Cloud + security is currently the most lucrative intersection of skills on the market.

SecAI+ (CompTIA) — $298 (new: launched February 17, 2026)

CompTIA’s first certification in its new AI security series (exam CY0-001): protecting AI systems, data, and models, defending against adversarial attacks, using AI in detection and response, plus compliance (NIST AI RMF, GDPR). Recommended 2+ years of security experience. It’s too fresh to judge its pull in recruiting — but it’s a clear signal that “AI security” is no longer a niche. CompTIA has already announced the next certification in the series (SecOT+, December 2026).

4. Lateral Movement — “Well, well, someone’s been doing great work!”

At this stage the attacker moves freely between the victim’s systems. Professionally, it’s the senior level — someone who fluently combines several areas at once.

SecurityX (formerly CASP+, CompTIA) — $544

SecurityX, formerly CASP+ (CompTIA) certification logo

December 2024: CompTIA rebranded CASP+ as SecurityX and pulled it into the “Xpert” series. Substantively it’s still the same profile: advanced security architecture, engineering, risk, response — for practitioners who don’t want to go down the purely managerial path (that’s what sets it apart from CISSP). The funny part: in job postings the old name still beats the new one 1,776 to 749 — when updating your CV, it’s worth listing both for now. 😉

GSE (GIAC Security Expert) — new path: GX exams at $499 each ($1,299 without the prerequisite certification)

GSE (GIAC) certification logo

GIAC’s most prestigious path has been thoroughly rebuilt. Instead of the legendary one-shot practical exam (which you had to fly out to take on site), GSE is now earned in stages: 6 Practitioner certifications + 4 four-hour Applied Knowledge exams from the GX series. Each GX exam costs $499 if you hold the required base certification ($1,299 if you don’t) — the full set of four comes to about $2,000, still cheaper than the old formula with travel and its “all or nothing” risk. This remains the “show you can do everything at once” league.

5. Domain Admin — “Now they see you, expert!”

The Domain Admin account controls the entire domain — it’s the goal of most pentests. Professionally: you’re the expert who gets the call when things get serious.

OSCP / OSCP+ (OffSec) — $1,749 (PEN-200 course + one exam attempt)

OSCP (OffSec) certification logo

The most important change in the entire ranking. Since November 2024, passing the same legendary 24-hour practical exam earns you two titles: OSCP (lifetime, as before) and OSCP+ — valid for 3 years and renewable through recertification, another OffSec exam, or CPE credits. Why the change? The market (and regulators) increasingly demand certifications that are “current,” not earned once and forever. The price rose from $1,499 to $1,749 (a retake is $249; the annual Learn One subscription is $2,749). In postings OSCP grew by +207% — the most in the whole comparison. If you want to do pentesting professionally, this is still the one certification that actually proves something.

ISACA certifications — $575 (members) / $760 (non-members) per exam

ISACA certifications logo

Some housekeeping in the lineup. The pillars are unchanged: CISA (systems audit — 3,289 postings on Indeed), CISM (information security management, +83% demand), CRISC (IT risk, +122%), CGEIT (IT governance), CDPSE (privacy/data protection engineering). The hands-on CSX-P has been retired. In its place, ISACA released three newcomers that show exactly where the industry is heading: CCOA (Certified Cybersecurity Operations Analyst — a hands-on cert for SOC analysts, 2025) and the first strictly AI certifications on the market: AAIA (Advanced in AI Audit) and AAISM (Advanced in AI Security Management). Too early to judge their recruiting power — but if you audit or manage systems with an AI component, this is the direction I’d watch closely.

CCSP (ISC2) — $599

CCSP (ISC2) certification logo

Cloud security at the architecture level: design, operations, compliance, cryptography. Price unchanged, but demand is up +175% — the third-best result in the comparison. In times when “everything is in the cloud,” CCSP has stopped being a niche and become one of the most profitable career moves (per Skillsoft, ~$172k a year).

Azure Security Engineer Associate (AZ-500, Microsoft) — $165 (US price; elsewhere you pay the regional equivalent at Pearson VUE)

Azure Security Engineer Associate (Microsoft) certification logo

Securing Azure and hybrid environments: identity, platform protection, data, applications. A small correction versus 2024: the tool I described back then as “Azure Security Center” is now called Microsoft Defender for Cloud. Microsoft uses regional pricing, so what you pay depends on where you live.

6. Holy Grail — “You’ve achieved mastery. Time to retire!”

In an attack, the Holy Grail is the data you came for in the first place. In a career: certifications earned no longer for permissions, but for prestige.

CISSP (ISC2) — $749 (€719 in Europe)

CISSP (ISC2) certification logo

The king hasn’t changed. It requires five documented years of experience in at least two security domains, and it appears in job postings more often than any other security certification in the world (10,350 offers on Indeed, +43%). Eight domains from risk management to software security. If you’re aiming for architect, manager, or CISO roles — sooner or later someone will ask you about it.

CCSK (Cloud Security Alliance) — $445 (version v5, two attempts included)

CCSK (Cloud Security Alliance) certification logo

Still the most universal (vendor-neutral) cloud security certification — and still great value for money, despite the increase from $395. The current v5 version (2024) added, among other things, zero trust and AI topics. In my Indeed comparison it’s the second-fastest-growing certification in percentage terms (+188%, albeit from a low base). The cloud equivalent of the rule “learn fundamentals, not interfaces.”

New players: the certifications the community fell in love with (and recruiters haven’t yet)

They weren’t in the 2024 ranking, and over the past two years they’ve taken the community by storm — mostly as a cheaper, very hands-on alternative to OSCP:

  • HTB CPTS (Hack The Box — Certified Penetration Testing Specialist) — a 10-day practical exam capped with a full report. A voucher runs ~$210, and the best deal is the HTB Academy Silver subscription ($490/year, voucher included).
  • PNPT (TCM Security — Practical Network Penetration Tester) — $499 for the training + exam with a free retake included: 5 days of testing (OSINT, Active Directory), 2 days for the report, and a 15-minute live debrief of your results with pentesters. Of all the exams I know, this one looks the most like a real engagement.
  • CRTO (Zero-Point Security — Red Team Ops) — a £365 course with an exam attempt included. A way into the world of red teaming and C2 frameworks without pawning a kidney.
  • BSCP (PortSwigger — Burp Suite Certified Practitioner) — ~$99 per attempt; an exam from the makers of Burp and of the free WebSecurityAcademy, which I recommend below.

And now the bucket of cold water — I checked them with the same Indeed method: CPTS appears in… 1 posting (the full phrase “HTB CPTS” — in 6), BSCP in 3, eJPT in 10. PNPT and CRTO couldn’t be counted honestly, because the acronyms collide with postings from entirely different industries (greetings to the pediatric nurse practitioners in the “PNPT” results 😉). For comparison: OSCP — 1,925 postings. Fun fact: the phrase “Hack The Box” itself appears in 63 postings — but almost always as “experience with platforms like HTB is a plus,” i.e. as a place to learn, not a required credential. And that’s this whole story in a nutshell: everyone knows the platform, almost no one requires the certificate.

Lesson #3: The community and recruiters live in different worlds. Community certifications can teach you more than many a “big” one — but they don’t exist in recruiting systems yet. The strategy for 2026: learn on them, and add one to your CV that HR will recognize without googling.

Comparison table — all certifications in one place

CertificationVendorLevelPrice (USD, Aug 2026)Who it’s for
CompTIA A+CompTIA1 — Reconnaissance$548 (2 exams)getting into IT
CCISC21 — Reconnaissance$199first step in security
Network+CompTIA2 — Initial Access$399networking foundation
PenTest+CompTIA2 — Initial Access$439pentesting theory
SSCPISC22 — Initial Access$249admins → security
ITIL 4 FoundationPeopleCert2 — Initial Access~€370*where IT meets process
Security+CompTIA3 — Privilege Escalation$439universal security start
CySA+CompTIA3 — Privilege Escalation$439SOC analyst
CCNACisco3 — Privilege Escalation$300networking + security
CEHEC-Council3 — Privilege Escalation$1,199 + $100for the recruiters
GSECGIAC3 — Privilege Escalation$999broad fundamentals, SANS quality
Professional Cloud Security EngineerGoogle3 — Privilege Escalation$200GCP security
AWS Security – SpecialtyAWS3 — Privilege Escalation$300AWS security, top pay
SecAI+ (new for 2026)CompTIA3 — Privilege Escalation$298AI in security operations
SecurityX (form. CASP+)CompTIA4 — Lateral Movement$544senior practitioner
GSE (GX path)GIAC4 — Lateral Movement$499/GX exam (×4)the GIAC elite
OSCP / OSCP+OffSec5 — Domain Admin$1,749professional pentesters
CISA / CISM / CRISC / CGEIT / CDPSEISACA5 — Domain Admin$575–760/examaudit, management, risk
CCOA / AAIA / AAISM (new)ISACA5 — Domain Admin$575–760/exam*SOC / AI audit and security
CCSPISC25 — Domain Admin$599cloud architecture
AZ-500Microsoft5 — Domain Admin$165*Azure security
CISSPISC26 — Holy Grail$749architects, managers, CISOs
CCSKCSA6 — Holy Grail$445cloud, vendor-neutral

* regional pricing or to be confirmed with the vendor — details in the descriptions above.

Do certifications still make sense in 2026?

Short version: yes, but not the way they used to.

I’ll say it straight, even though I’m sawing at the branch this post sits on: if you have one budget of money and time to spend, then in 2026 a certification alone is a worse investment than it was in 2024. You can’t buy an entry ticket to the industry anymore — that door is now guarded by AI and frozen hiring budgets. A certification works in three situations: when it gets you through the HR filter and ATS — the systems that automatically screen CVs (CISSP, Security+); when a regulation or a client requires it (the post-NIS2/DORA world loves “papers”); and when the curriculum behind it genuinely builds a skill the market needs (OSCP+, cloud certs).

If I were starting from zero today, I’d do it like this: CC or Security+ to structure the basics → hundreds of hours of practice (labs, CTFs, PentesterLab, my own projects) → OSCP+ or the cloud path (CCSK/CCSP/AWS), depending on what excites me. And alongside that — and this is new versus 2024 — I’d learn to work with AI from day one: not “prompting,” but verifying. Because the triager Louis was talking about isn’t someone who clicks “approve.” It’s someone who knows when to click “reject.”

Lesson #4: A certification is proof that you’ve been through a structured learning process. In an era when AI spits out ready-made answers, it’s the process that holds the value — because only the process gives you the right to say “this is nonsense” with full conviction.

FAQ — the most common questions

Which certification should you start your cybersecurity journey with in 2026?

With CC (ISC2, $199) if you want a cheap way to check whether this industry is for you, or with Security+ (CompTIA, $439) if you want the most recognizable foundational certification right away. But neither replaces practice — treat them as a curriculum, not a pass.

How much does a cybersecurity certification cost?

Entry-level: $199–550. Intermediate: $300–1,300. Professional hands-on (OSCP+): $1,749 including the course. On top of that, there are often annual membership fees (e.g. ISC2 $50, ISACA) and recertification costs. Most vendors raised prices by 15–30% versus 2024 (CompTIA, OffSec, GIAC, CSA); ISC2, ISACA, AWS, and Google are holding their rates, and the steepest “price increase” hit CC — because it stopped being free.

Is CEH still worth it?

Depends what you’re optimizing for. For recruiters and formal requirements (including US institutions) — it works, and demand in postings grew by 61%. For real skills — for $1,299 (exam + application) you’re almost at a full OSCP+, which teaches incomparably more practice.

Will AI take pentesters’ and security analysts’ jobs?

It won’t take them — it’s changing their nature. The data shows two things at once: employment of people starting their careers in AI-exposed roles fell by about 16% (Stanford), but 73% of professionals expect new, more specialized roles (ISC2). The value of verification, context, and responsibility is rising — the things you can’t delegate to a model.

Which certification pays the most?

According to my analysis of salary ranges in Indeed postings (US, August 2026): CISM (~$166k/year), CRISC (~$157k), and CISSP (~$154k) — in other words: management, risk, and architecture. In Skillsoft’s global survey, AWS Security – Specialty rounds out the top. Don’t map these numbers 1:1 onto your local market, but the “management + risk + cloud” direction is universal.

My subjective take and recommended learning resources

Personally I believe — perhaps against popular opinion — that the best foundation for learning is still academic rigor. With solid fundamentals, commercial certifications come much easier. As for commercial resources, I only recommend the ones I know well myself (the order is not accidental):

  • PentesterLab — the best learning platform I know. Louis Nyffenegger has not only built a place to practice a huge number of vulnerabilities, but in many spots he explains in depth how a given vulnerability actually works. The same Louis I quote above — I also recommend following his thinking on AI in pentesting.
  • WebSecurityAcademy — a free hands-on platform from the makers of Burp Suite. I know of no better introduction to web application security.
  • INE Security — the exams capture the essence of a pentester’s job well: beyond getting “root,” what counts is finding all the vulnerabilities and writing a sensible report.

From my home turf, Poland:

Summary

Two years ago this post ended with a list of courses. Today I’m ending it differently, because the times are different: certifications aren’t dead — they’ve changed function. From an entry ticket they’ve turned into a multiplier: they amplify someone who has practice, and they’re increasingly bad at masking its absence. So don’t pick the certification that’s easiest to pass — pick the one whose curriculum will teach you something AI won’t do for you. And then go and do the work — labs, CTFs, your own projects. The paper can wait.

And if you represent a company and, rather than collecting certificates, you’d prefer to see how your systems would handle contact with a real attacker — that’s what penetration tests are for. Price a pentest in the calculator or simply drop me a line. 🔓

Sources 📚


Updated: August 2026. Original version of this post: April 2024.

Tagged , , , , , , , , , , , . Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *