CompTIA Security+ → CEH or Specialist Certification → CISSP: Complete Cybersecurity Certification Roadmap
Quick Answer A strong cybersecurity certification path for many IT professionals is: CompTIA Security+ → Specialist Certification → CISSP The important point...
Quick Answer
A strong cybersecurity certification path for many IT professionals is:
CompTIA Security+ → Specialist Certification → CISSP
The important point is that CEH is only one possible specialist certification. Your second certification should ideally match the cybersecurity career you want to build.
For example:
| Career Direction | Suggested Path |
|---|---|
| General cybersecurity | Security+ → CySA+ → CISSP |
| Ethical hacking / penetration testing | Security+ → CEH / PenTest+ / practical offensive-security certification → CISSP |
| SOC / blue team | Security+ → CySA+ → CISSP |
| Network security | Security+ → Cisco security-focused certification → CISSP |
| Cloud security | Security+ → AWS/Azure security certification or CCSP → CISSP |
| Security management / governance | Security+ → CISM or governance/risk certification → CISSP |
| Security architecture | Security+ → advanced security/cloud/network certification → CISSP |
Think of the progression as:
Foundation → Specialization + Real Experience → Senior Security Expertise
CISSP should not simply be considered the "next exam" after Security+ or CEH. It is designed for experienced cybersecurity professionals and has formal work-experience requirements.
Complete Article
What Is the Security+ → Specialist → CISSP Path?
Cybersecurity is too broad for one certification to cover every career.
A better strategy is to develop your career in stages:
Stage 1 — Build cybersecurity fundamentals
→ CompTIA Security+
Stage 2 — Develop expertise in a particular security discipline
→ CEH, CySA+, PenTest+, CCSP, cloud security, network security, incident response, GRC, or another specialist credential
Stage 3 — Build substantial real-world security experience
→ Security administration, SOC operations, vulnerability management, IAM, network security, incident response, risk management, security architecture, cloud security, etc.
Stage 4 — Develop broad senior-level security knowledge
→ CISSP
This approach combines certification with the factor that ultimately matters most: real cybersecurity experience.
Stage 1: CompTIA Security+ — Build the Foundation
CompTIA Security+ is commonly used as an early cybersecurity certification because it introduces candidates to security concepts across multiple areas rather than concentrating exclusively on one product or technology.
It is particularly useful for IT professionals moving from:
- Desktop support
- Windows administration
- Server administration
- Networking
- Help desk
- Cloud administration
- System administration
into cybersecurity.
What Security+ Helps You Learn
Security+ develops knowledge in areas such as:
- Threats and vulnerabilities
- Security architecture
- Authentication and authorization
- Identity and access management
- Network security
- Cryptography
- Security operations
- Incident response
- Risk management
- Security policies
- Vulnerability management
- Security monitoring
- Business continuity concepts
This gives you the vocabulary and foundation required before moving deeper into a particular cybersecurity discipline.
Who Should Consider Security+?
Security+ can be useful for:
- IT Support Engineers
- Network Engineers
- System Administrators
- Windows Administrators
- Cloud Administrators
- Junior Security Analysts
- SOC Analysts
- Cybersecurity beginners
- IT professionals moving into security
However, passing Security+ alone does not make someone an experienced cybersecurity professional.
The certification should ideally be accompanied by practical work.
Stage 2: Choose Your Cybersecurity Specialization
This is where the certification roadmap should branch.
A common mistake is to assume:
Security+ → CEH → CISSP
is the required cybersecurity path.
It isn't.
CEH is appropriate when ethical hacking and offensive security match your career goals. Someone interested in SOC operations, cloud security, governance or security architecture may benefit much more from another intermediate certification.
Option 1: CEH — Ethical Hacking and Offensive Security
The Certified Ethical Hacker (CEH) from EC-Council focuses on ethical hacking concepts and techniques.
Its curriculum includes subjects such as:
- Reconnaissance
- Footprinting
- Network scanning
- Enumeration
- Vulnerability analysis
- System hacking
- Malware threats
- Packet sniffing
- Social engineering
- Web server security
- Web application attacks
- SQL injection
- Wireless security
- Cloud security
- IoT and OT security
- Cryptography
The CEH knowledge examination currently contains 125 questions with a four-hour duration. EC-Council also offers a separate CEH Practical examination involving hands-on challenges.
CEH Is Best Suited For
Consider CEH if you want to work toward roles such as:
- Ethical Hacker
- Vulnerability Analyst
- Penetration Tester
- Security Consultant
- Security Analyst
- Red Team professional
Important Distinction: CEH vs CEH Practical
The regular CEH examination primarily validates knowledge.
EC-Council's CEH Practical is designed to test application of ethical-hacking techniques through hands-on scenarios in a cyber range.
For someone pursuing a practical offensive-security career, hands-on labs and real technical practice are extremely important regardless of which certification is selected.
Option 2: CompTIA CySA+ — Defensive Security / SOC Path
If your interest is defending systems rather than attacking them, a cybersecurity analyst-oriented certification such as CompTIA CySA+ can be a more logical intermediate step.
This direction is useful for people interested in:
- Security Operations Centers
- Threat detection
- Security monitoring
- Vulnerability management
- Incident investigation
- Security analytics
- Incident response
A typical progression could therefore be:
Security+ → CySA+ → SOC/Security Experience → CISSP
This can be particularly relevant to system and network administrators transitioning toward defensive cybersecurity.
Option 3: Penetration Testing / Offensive Security
If your career objective is specifically penetration testing, consider building a path around practical offensive-security skills.
For example:
Security+ → Penetration-Testing Certification → Hands-On Labs → Professional Experience → CISSP
Important practical subjects include:
- Linux
- TCP/IP
- Windows and Active Directory
- PowerShell
- Python
- Web application security
- Network enumeration
- Vulnerability assessment
- Privilege escalation
- Authentication attacks
- Security reporting
Certification alone is insufficient for penetration testing. Practical labs are essential.
Option 4: Cloud Security
Cloud security has become an important specialization as organizations move applications, identity systems and infrastructure into public and hybrid cloud environments.
Possible progression:
Security+ → Azure/AWS/Google Cloud Security Skills → Cloud Security Experience → CCSP and/or CISSP
Important cloud-security subjects include:
- Cloud IAM
- Least privilege
- Conditional access
- Encryption
- Key management
- Network segmentation
- Cloud logging
- Security monitoring
- Data protection
- Workload security
- Zero Trust
- Incident response
- Compliance
For experienced professionals specializing in cloud security, ISC2's CCSP is another major certification option.
CCSP itself has professional-experience requirements. ISC2 currently specifies five years of cumulative IT experience, including three years in cybersecurity and one year in one or more of the six CCSP domains, subject to its permitted experience substitutions.
Option 5: Network Security
Network engineers can follow a security path concentrating on:
- Firewalls
- VPNs
- Routing security
- Network segmentation
- IDS/IPS
- NAC
- Zero Trust
- Secure remote access
- Wireless security
- Network monitoring
A possible progression is:
Network Fundamentals / CCNA → Security+ → Network Security Specialization → CISSP
This can be particularly effective because strong networking knowledge is extremely valuable in cybersecurity.
Option 6: Governance, Risk and Compliance — GRC
Not every cybersecurity career involves penetration testing or security operations.
Organizations also need professionals working in:
- Information security governance
- Risk assessment
- Compliance
- Security policies
- Audit
- Business continuity
- Vendor risk
- Data protection
- Security frameworks
Relevant knowledge may include:
- ISO/IEC 27001
- NIST Cybersecurity Framework
- Risk management
- Security policies
- Business continuity
- Incident-management processes
- Regulatory compliance
Professionals pursuing management and governance careers may therefore prefer a pathway involving credentials such as CISM or governance/risk-focused certifications before or alongside CISSP.
Stage 3: Gain Real Cybersecurity Experience
This is arguably the most important stage.
Do not build a certification roadmap consisting only of:
Exam → Exam → Exam → Exam
Instead build:
Learn → Practice → Certify → Work → Specialize → Gain Experience → Advance
Practical experience could involve:
- Managing Microsoft Defender
- Configuring firewalls
- Implementing MFA
- Managing Active Directory security
- Microsoft Entra ID administration
- Hardening Windows servers
- Patch management
- Vulnerability scanning
- Log analysis
- SIEM monitoring
- Endpoint security
- Backup and disaster recovery
- Security incident investigation
- IAM
- Network segmentation
- Security auditing
- Risk assessment
- Cloud security
A professional who understands these technologies in real environments will usually be better prepared for senior cybersecurity responsibilities than someone who has only accumulated certifications.
Stage 4: CISSP — Advanced Cybersecurity Certification
The Certified Information Systems Security Professional (CISSP) from ISC2 is designed for experienced security professionals.
It covers eight major domains:
- Security and Risk Management
- Asset Security
- Security Architecture and Engineering
- Communication and Network Security
- Identity and Access Management
- Security Assessment and Testing
- Security Operations
- Software Development Security
CISSP therefore moves beyond one narrow technical specialization.
It covers the broader knowledge needed to design, manage and evaluate an organization's information-security program.
CISSP Experience Requirement
This is one of the most important things to understand before planning for CISSP.
ISC2 currently requires a candidate to have at least:
Five years of cumulative full-time experience in two or more of the eight CISSP domains.
An eligible post-secondary degree or credential on ISC2's approved list can satisfy up to one year of this experience requirement. Only one year can be waived through this mechanism.
Interestingly, CompTIA Security+ is currently included on ISC2's approved credential list for the one-year CISSP experience waiver.
This makes Security+ potentially useful later in the certification journey as well as at the foundation stage.
Always verify the current ISC2 requirements before applying because certification policies and approved credential lists can change.
Can You Take CISSP Without Five Years of Experience?
You can pass the CISSP examination before satisfying the full professional-experience requirement.
In that situation, ISC2 provides the Associate of ISC2 pathway.
A candidate who passes the CISSP examination but does not yet have the required experience can become an Associate of ISC2 and has up to six years to obtain the required five years of experience.
Therefore:
Passing the CISSP exam ≠ immediately becoming CISSP-certified
The experience and other ISC2 certification requirements must also be satisfied.
Security+ vs CEH vs CISSP
| Feature | Security+ | CEH | CISSP |
|---|---|---|---|
| General level | Foundation / early career | Specialist | Advanced |
| Primary focus | Broad security fundamentals | Ethical hacking | Broad security architecture, operations, risk and management |
| Good starting certification | Yes | Usually after fundamentals | Usually no |
| Offensive security focus | Limited | Strong | Broad rather than penetration-testing focused |
| Governance/risk coverage | Foundation | Limited relative to CISSP | Strong |
| Best suited for | Entry/junior security and IT professionals | Ethical hacking/security testing path | Experienced security professionals |
| Practical experience important | Yes | Very important | Essential |
| Formal professional experience requirement for certification | Check current CompTIA policy | Depends on chosen EC-Council eligibility route | Yes |
Recommended Cybersecurity Certification Roadmaps
General Cybersecurity
IT Fundamentals → Networking → Security+ → Security Experience → CISSP
Good for professionals who do not yet know which security specialty they want.
SOC / Blue Team
Security+ → CySA+ → SOC Experience → CISSP
Good for:
- SOC analysts
- Security analysts
- Incident responders
- Threat analysts
Ethical Hacking / Penetration Testing
Security+ → CEH / Penetration-Testing Certification → Hands-On Labs → Security Experience → CISSP
Good for:
- Ethical hackers
- Penetration testers
- Vulnerability analysts
- Red team professionals
Cloud Security
Security+ → Cloud Platform Skills → Cloud Security Certification → CCSP and/or CISSP
Good for:
- Cloud administrators
- Cloud security engineers
- Cloud architects
- Security architects
Network Security
Network+ / CCNA → Security+ → Network Security Specialization → CISSP
Good for:
- Network engineers
- Firewall engineers
- Network security engineers
- Security architects
Security Management / GRC
Security+ → GRC/Risk/Audit Experience → CISM or Relevant Specialist Certification → CISSP
Good for:
- Security managers
- Risk professionals
- Security consultants
- IT auditors
- Information security managers
Do You Need CEH Before CISSP?
No.
CEH is not a prerequisite for CISSP.
You should select CEH if ethical hacking fits your career objective.
For example, someone working primarily with:
- Windows Server
- Active Directory
- Microsoft 365
- Networking
- Firewalls
- Endpoint protection
- Cloud infrastructure
may find that Security+, defensive-security training, cloud security or network-security specialization aligns more closely with their day-to-day career than CEH.
The best certification is not necessarily the most famous certification.
It is the certification that supports the skills required for your intended job.
Certifications Do Not Replace Networking and System Administration Knowledge
Cybersecurity professionals benefit greatly from understanding the systems they are protecting.
Before specializing deeply, develop practical knowledge of:
Networking
Understand:
- TCP/IP
- IPv4 and IPv6
- DNS
- DHCP
- VLANs
- Routing
- NAT
- Firewalls
- VPNs
- Ports and protocols
Windows
Understand:
- Active Directory
- Group Policy
- NTFS permissions
- Windows Firewall
- Event Viewer
- PowerShell
- Windows Defender
- BitLocker
- Windows Server
- RDP security
Linux
Understand:
- Users and groups
- Permissions
- SSH
- Services
- Processes
- Logs
- Package management
- Shell commands
- Network configuration
Cloud
Understand at least one major cloud ecosystem such as:
- Microsoft Azure
- Amazon Web Services
- Google Cloud
Security becomes much easier to understand when you already understand the infrastructure being secured.
Build a Cybersecurity Home Lab
A home lab can provide practical experience alongside certification study.
For example:
Internet / NAT
↓
Firewall
↓
Windows Server
↓
Active Directory Domain
↓
Windows Client
↓
Linux Server
↓
Security Monitoring System
Virtualization platforms can be used to create isolated test environments.
Practice activities can include:
- Creating Active Directory users
- Configuring Group Policy
- Implementing password policies
- Enabling MFA where applicable
- Reviewing Windows Event Logs
- Testing firewall rules
- Running vulnerability scans against systems you own or are explicitly authorized to test
- Hardening Windows
- Hardening Linux
- Analyzing network traffic
- Testing backup and recovery
- Investigating simulated security incidents
Important: Perform penetration testing and vulnerability scanning only against systems you own or have explicit authorization to test.
Certification Alone Is Not Enough
Consider two candidates.
Candidate A
Has:
Security+ → CEH → CISSP-related study
but little practical experience.
Candidate B
Has:
Security+ + several years of system/network/security administration + incident response + firewall management + vulnerability management + Active Directory security.
Candidate B may be significantly better prepared for many real cybersecurity roles.
The strongest combination is:
Certification + Knowledge + Labs + Real Experience + Continuous Learning
Cybersecurity Career Progression Example
A practical career progression could look like:
IT Support Engineer
↓
System / Network Administrator
↓
CompTIA Security+
↓
Junior Security Analyst
↓
Specialist Certification
↓
Security Analyst / Engineer
↓
Several Years of Security Experience
↓
CISSP
↓
Senior Security Engineer / Security Consultant / Security Architect / Security Manager
↓
CISO / Head of Information Security
This is only an example. Cybersecurity careers do not follow one mandatory sequence.
Frequently Asked Questions
Is Security+ required before CEH?
No. Security+ is not universally required before CEH.
However, studying security fundamentals first can make advanced security concepts easier to understand.
Is CEH required before CISSP?
No.
CEH is not a CISSP prerequisite.
Choose CEH primarily when ethical hacking or offensive security aligns with your career.
Which is better after Security+: CEH or CySA+?
It depends on your objective.
Choose an ethical-hacking-focused path if you are interested in offensive security and penetration testing.
Choose CySA+ or a similar defensive-security path if you are interested in SOC operations, threat detection, monitoring and incident response.
Can I directly take CISSP after Security+?
You can prepare for and sit the CISSP exam, but earning the CISSP certification requires satisfying ISC2's professional-experience and other certification requirements.
Candidates without the required experience may qualify for the Associate of ISC2 pathway after passing the examination.
Does Security+ reduce the CISSP experience requirement?
Under ISC2's current 2026 approved credential list, Security+ is one of the credentials that can satisfy one year of the CISSP work-experience requirement. ISC2 allows a maximum one-year waiver through an eligible degree or approved credential.
Always verify the current ISC2 policy when you are ready to apply.
Should a network engineer learn cybersecurity?
Yes.
Network engineers already work with technologies fundamental to security, including TCP/IP, routing, DNS, VPNs, firewalls and access control.
Security+ followed by a network-security specialization can therefore be a logical progression.
Should a Windows administrator take Security+?
It can be valuable.
Windows administrators already encounter many security-related technologies, including Active Directory, Group Policy, NTFS permissions, Defender, BitLocker, Windows Firewall, RDP, auditing and identity management.
Security+ can help connect these technologies to broader cybersecurity principles.
Is CISSP only for managers?
No.
CISSP covers both technical and managerial security knowledge and is relevant to experienced professionals in roles such as security engineering, architecture, consulting, operations and management.
ISC2 describes CISSP as validating the technical and managerial knowledge needed to design, engineer and manage an organization's overall security posture.
What should I learn besides certifications?
Develop practical skills in:
- Networking
- Windows
- Linux
- Active Directory
- PowerShell
- Cloud computing
- Firewalls
- Endpoint security
- SIEM
- Vulnerability management
- Identity management
- Incident response
- Security frameworks
- Risk management
Certifications should validate and organize your learning rather than replace practical experience.
Final Recommendation / Conclusion
For most IT professionals entering cybersecurity, a sensible strategy is:
CompTIA Security+
↓
Choose Your Specialization
↓
CEH / CySA+ / Penetration Testing / Network Security / Cloud Security / GRC
↓
Build Real Cybersecurity Experience
↓
CISSP
Do not assume that everybody needs:
Security+ → CEH → CISSP
A better model is:
Security+ → Specialist Certification Relevant to Your Career → Experience → CISSP
If your objective is ethical hacking, CEH or another penetration-testing path makes sense.
If your objective is SOC and defensive security, consider CySA+ or another blue-team specialization.
If you work heavily with Azure, AWS or cloud infrastructure, cloud security may provide greater career value.
If you work with routers, switches, VPNs and firewalls, network security may be the better specialization.
If you intend to move toward governance and management, risk, audit and security-management certifications may be more appropriate.
Finally, treat CISSP as an experienced-professional milestone, not merely the third exam in a certification sequence.
The strongest cybersecurity professional is not the person with the longest list of certificates. It is the person who can combine:
Strong Fundamentals + Specialized Knowledge + Practical Skills + Professional Experience + Recognized Certifications
#CompTIASecurityPlus #SecurityPlus #CEH #CISSP #Cybersecurity #CyberSecurityCertification #CybersecurityCareer #CybersecurityRoadmap #CertificationRoadmap #EthicalHacking #CertifiedEthicalHacker #PenetrationTesting #PenTester #CySAPlus #SOCAnalyst #SecurityAnalyst #SecurityEngineer #SecurityArchitect #InformationSecurity #ITSecurity #NetworkSecurity #CloudSecurity #CCSP #CISM #GRC #RiskManagement #SecurityOperations #IncidentResponse #VulnerabilityManagement #BlueTeam #RedTeam #OffensiveSecurity #DefensiveSecurity #EthicalHacker #ISC2 #CompTIA #ECCouncil #CybersecurityTraining #CybersecuritySkills #CybersecurityJobs #CareerDevelopment #ITCareer #SystemAdministrator #NetworkEngineer #WindowsSecurity #LinuxSecurity #ActiveDirectorySecurity #CloudComputing #SecurityCertification #CybersecurityProfessional
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.