Skip to content
Cyber SecurityAdvanced

CompTIA Security+ → CEH or Specialist Certification → CISSP: Complete Cybersecurity Certification Roadmap

Quick Answer A strong cybersecurity certification path for many IT professionals is: CompTIA Security+ → Specialist Certification → CISSP The important point...

BI
Bison Technical Team Enterprise IT specialists
Updated 05 Sep 2026 13 min read 3 total views

Quick Answer

A strong cybersecurity certification path for many IT professionals is:

CompTIA Security+ → Specialist Certification → CISSP

Advertisement

The important point is that CEH is only one possible specialist certification. Your second certification should ideally match the cybersecurity career you want to build.

For example:

Career Direction Suggested Path
General cybersecurity Security+ → CySA+ → CISSP
Ethical hacking / penetration testing Security+ → CEH / PenTest+ / practical offensive-security certification → CISSP
SOC / blue team Security+ → CySA+ → CISSP
Network security Security+ → Cisco security-focused certification → CISSP
Cloud security Security+ → AWS/Azure security certification or CCSP → CISSP
Security management / governance Security+ → CISM or governance/risk certification → CISSP
Security architecture Security+ → advanced security/cloud/network certification → CISSP

Think of the progression as:

Foundation → Specialization + Real Experience → Senior Security Expertise

CISSP should not simply be considered the "next exam" after Security+ or CEH. It is designed for experienced cybersecurity professionals and has formal work-experience requirements.


Complete Article

What Is the Security+ → Specialist → CISSP Path?

Cybersecurity is too broad for one certification to cover every career.

A better strategy is to develop your career in stages:

Stage 1 — Build cybersecurity fundamentals

→ CompTIA Security+

Stage 2 — Develop expertise in a particular security discipline

→ CEH, CySA+, PenTest+, CCSP, cloud security, network security, incident response, GRC, or another specialist credential

Stage 3 — Build substantial real-world security experience

→ Security administration, SOC operations, vulnerability management, IAM, network security, incident response, risk management, security architecture, cloud security, etc.

Stage 4 — Develop broad senior-level security knowledge

→ CISSP

This approach combines certification with the factor that ultimately matters most: real cybersecurity experience.


Stage 1: CompTIA Security+ — Build the Foundation

CompTIA Security+ is commonly used as an early cybersecurity certification because it introduces candidates to security concepts across multiple areas rather than concentrating exclusively on one product or technology.

It is particularly useful for IT professionals moving from:

  • Desktop support
  • Windows administration
  • Server administration
  • Networking
  • Help desk
  • Cloud administration
  • System administration

into cybersecurity.

What Security+ Helps You Learn

Security+ develops knowledge in areas such as:

  • Threats and vulnerabilities
  • Security architecture
  • Authentication and authorization
  • Identity and access management
  • Network security
  • Cryptography
  • Security operations
  • Incident response
  • Risk management
  • Security policies
  • Vulnerability management
  • Security monitoring
  • Business continuity concepts

This gives you the vocabulary and foundation required before moving deeper into a particular cybersecurity discipline.


Who Should Consider Security+?

Security+ can be useful for:

  • IT Support Engineers
  • Network Engineers
  • System Administrators
  • Windows Administrators
  • Cloud Administrators
  • Junior Security Analysts
  • SOC Analysts
  • Cybersecurity beginners
  • IT professionals moving into security

However, passing Security+ alone does not make someone an experienced cybersecurity professional.

The certification should ideally be accompanied by practical work.


Stage 2: Choose Your Cybersecurity Specialization

This is where the certification roadmap should branch.

A common mistake is to assume:

Security+ → CEH → CISSP

is the required cybersecurity path.

It isn't.

CEH is appropriate when ethical hacking and offensive security match your career goals. Someone interested in SOC operations, cloud security, governance or security architecture may benefit much more from another intermediate certification.


Option 1: CEH — Ethical Hacking and Offensive Security

The Certified Ethical Hacker (CEH) from EC-Council focuses on ethical hacking concepts and techniques.

Its curriculum includes subjects such as:

  • Reconnaissance
  • Footprinting
  • Network scanning
  • Enumeration
  • Vulnerability analysis
  • System hacking
  • Malware threats
  • Packet sniffing
  • Social engineering
  • Web server security
  • Web application attacks
  • SQL injection
  • Wireless security
  • Cloud security
  • IoT and OT security
  • Cryptography

The CEH knowledge examination currently contains 125 questions with a four-hour duration. EC-Council also offers a separate CEH Practical examination involving hands-on challenges.

CEH Is Best Suited For

Consider CEH if you want to work toward roles such as:

  • Ethical Hacker
  • Vulnerability Analyst
  • Penetration Tester
  • Security Consultant
  • Security Analyst
  • Red Team professional

Important Distinction: CEH vs CEH Practical

The regular CEH examination primarily validates knowledge.

EC-Council's CEH Practical is designed to test application of ethical-hacking techniques through hands-on scenarios in a cyber range.

For someone pursuing a practical offensive-security career, hands-on labs and real technical practice are extremely important regardless of which certification is selected.


Option 2: CompTIA CySA+ — Defensive Security / SOC Path

If your interest is defending systems rather than attacking them, a cybersecurity analyst-oriented certification such as CompTIA CySA+ can be a more logical intermediate step.

This direction is useful for people interested in:

  • Security Operations Centers
  • Threat detection
  • Security monitoring
  • Vulnerability management
  • Incident investigation
  • Security analytics
  • Incident response

A typical progression could therefore be:

Security+ → CySA+ → SOC/Security Experience → CISSP

This can be particularly relevant to system and network administrators transitioning toward defensive cybersecurity.


Option 3: Penetration Testing / Offensive Security

If your career objective is specifically penetration testing, consider building a path around practical offensive-security skills.

For example:

Security+ → Penetration-Testing Certification → Hands-On Labs → Professional Experience → CISSP

Important practical subjects include:

  • Linux
  • TCP/IP
  • Windows and Active Directory
  • PowerShell
  • Python
  • Web application security
  • Network enumeration
  • Vulnerability assessment
  • Privilege escalation
  • Authentication attacks
  • Security reporting

Certification alone is insufficient for penetration testing. Practical labs are essential.


Option 4: Cloud Security

Cloud security has become an important specialization as organizations move applications, identity systems and infrastructure into public and hybrid cloud environments.

Possible progression:

Security+ → Azure/AWS/Google Cloud Security Skills → Cloud Security Experience → CCSP and/or CISSP

Important cloud-security subjects include:

  • Cloud IAM
  • Least privilege
  • Conditional access
  • Encryption
  • Key management
  • Network segmentation
  • Cloud logging
  • Security monitoring
  • Data protection
  • Workload security
  • Zero Trust
  • Incident response
  • Compliance

For experienced professionals specializing in cloud security, ISC2's CCSP is another major certification option.

CCSP itself has professional-experience requirements. ISC2 currently specifies five years of cumulative IT experience, including three years in cybersecurity and one year in one or more of the six CCSP domains, subject to its permitted experience substitutions.


Option 5: Network Security

Network engineers can follow a security path concentrating on:

  • Firewalls
  • VPNs
  • Routing security
  • Network segmentation
  • IDS/IPS
  • NAC
  • Zero Trust
  • Secure remote access
  • Wireless security
  • Network monitoring

A possible progression is:

Network Fundamentals / CCNA → Security+ → Network Security Specialization → CISSP

This can be particularly effective because strong networking knowledge is extremely valuable in cybersecurity.


Option 6: Governance, Risk and Compliance — GRC

Not every cybersecurity career involves penetration testing or security operations.

Organizations also need professionals working in:

  • Information security governance
  • Risk assessment
  • Compliance
  • Security policies
  • Audit
  • Business continuity
  • Vendor risk
  • Data protection
  • Security frameworks

Relevant knowledge may include:

  • ISO/IEC 27001
  • NIST Cybersecurity Framework
  • Risk management
  • Security policies
  • Business continuity
  • Incident-management processes
  • Regulatory compliance

Professionals pursuing management and governance careers may therefore prefer a pathway involving credentials such as CISM or governance/risk-focused certifications before or alongside CISSP.


Stage 3: Gain Real Cybersecurity Experience

This is arguably the most important stage.

Do not build a certification roadmap consisting only of:

Exam → Exam → Exam → Exam

Instead build:

Learn → Practice → Certify → Work → Specialize → Gain Experience → Advance

Practical experience could involve:

  • Managing Microsoft Defender
  • Configuring firewalls
  • Implementing MFA
  • Managing Active Directory security
  • Microsoft Entra ID administration
  • Hardening Windows servers
  • Patch management
  • Vulnerability scanning
  • Log analysis
  • SIEM monitoring
  • Endpoint security
  • Backup and disaster recovery
  • Security incident investigation
  • IAM
  • Network segmentation
  • Security auditing
  • Risk assessment
  • Cloud security

A professional who understands these technologies in real environments will usually be better prepared for senior cybersecurity responsibilities than someone who has only accumulated certifications.


Stage 4: CISSP — Advanced Cybersecurity Certification

The Certified Information Systems Security Professional (CISSP) from ISC2 is designed for experienced security professionals.

It covers eight major domains:

  1. Security and Risk Management
  2. Asset Security
  3. Security Architecture and Engineering
  4. Communication and Network Security
  5. Identity and Access Management
  6. Security Assessment and Testing
  7. Security Operations
  8. Software Development Security

CISSP therefore moves beyond one narrow technical specialization.

It covers the broader knowledge needed to design, manage and evaluate an organization's information-security program.


CISSP Experience Requirement

This is one of the most important things to understand before planning for CISSP.

ISC2 currently requires a candidate to have at least:

Five years of cumulative full-time experience in two or more of the eight CISSP domains.

An eligible post-secondary degree or credential on ISC2's approved list can satisfy up to one year of this experience requirement. Only one year can be waived through this mechanism.

Interestingly, CompTIA Security+ is currently included on ISC2's approved credential list for the one-year CISSP experience waiver.

This makes Security+ potentially useful later in the certification journey as well as at the foundation stage.

Always verify the current ISC2 requirements before applying because certification policies and approved credential lists can change.


Can You Take CISSP Without Five Years of Experience?

You can pass the CISSP examination before satisfying the full professional-experience requirement.

In that situation, ISC2 provides the Associate of ISC2 pathway.

A candidate who passes the CISSP examination but does not yet have the required experience can become an Associate of ISC2 and has up to six years to obtain the required five years of experience.

Therefore:

Passing the CISSP exam ≠ immediately becoming CISSP-certified

The experience and other ISC2 certification requirements must also be satisfied.


Security+ vs CEH vs CISSP

Feature Security+ CEH CISSP
General level Foundation / early career Specialist Advanced
Primary focus Broad security fundamentals Ethical hacking Broad security architecture, operations, risk and management
Good starting certification Yes Usually after fundamentals Usually no
Offensive security focus Limited Strong Broad rather than penetration-testing focused
Governance/risk coverage Foundation Limited relative to CISSP Strong
Best suited for Entry/junior security and IT professionals Ethical hacking/security testing path Experienced security professionals
Practical experience important Yes Very important Essential
Formal professional experience requirement for certification Check current CompTIA policy Depends on chosen EC-Council eligibility route Yes

Recommended Cybersecurity Certification Roadmaps

General Cybersecurity

IT Fundamentals → Networking → Security+ → Security Experience → CISSP

Good for professionals who do not yet know which security specialty they want.

SOC / Blue Team

Security+ → CySA+ → SOC Experience → CISSP

Good for:

  • SOC analysts
  • Security analysts
  • Incident responders
  • Threat analysts

Ethical Hacking / Penetration Testing

Security+ → CEH / Penetration-Testing Certification → Hands-On Labs → Security Experience → CISSP

Good for:

  • Ethical hackers
  • Penetration testers
  • Vulnerability analysts
  • Red team professionals

Cloud Security

Security+ → Cloud Platform Skills → Cloud Security Certification → CCSP and/or CISSP

Good for:

  • Cloud administrators
  • Cloud security engineers
  • Cloud architects
  • Security architects

Network Security

Network+ / CCNA → Security+ → Network Security Specialization → CISSP

Good for:

  • Network engineers
  • Firewall engineers
  • Network security engineers
  • Security architects

Security Management / GRC

Security+ → GRC/Risk/Audit Experience → CISM or Relevant Specialist Certification → CISSP

Good for:

  • Security managers
  • Risk professionals
  • Security consultants
  • IT auditors
  • Information security managers

Do You Need CEH Before CISSP?

No.

CEH is not a prerequisite for CISSP.

You should select CEH if ethical hacking fits your career objective.

For example, someone working primarily with:

  • Windows Server
  • Active Directory
  • Microsoft 365
  • Networking
  • Firewalls
  • Endpoint protection
  • Cloud infrastructure

may find that Security+, defensive-security training, cloud security or network-security specialization aligns more closely with their day-to-day career than CEH.

The best certification is not necessarily the most famous certification.

It is the certification that supports the skills required for your intended job.


Certifications Do Not Replace Networking and System Administration Knowledge

Cybersecurity professionals benefit greatly from understanding the systems they are protecting.

Before specializing deeply, develop practical knowledge of:

Networking

Understand:

  • TCP/IP
  • IPv4 and IPv6
  • DNS
  • DHCP
  • VLANs
  • Routing
  • NAT
  • Firewalls
  • VPNs
  • Ports and protocols

Windows

Understand:

  • Active Directory
  • Group Policy
  • NTFS permissions
  • Windows Firewall
  • Event Viewer
  • PowerShell
  • Windows Defender
  • BitLocker
  • Windows Server
  • RDP security

Linux

Understand:

  • Users and groups
  • Permissions
  • SSH
  • Services
  • Processes
  • Logs
  • Package management
  • Shell commands
  • Network configuration

Cloud

Understand at least one major cloud ecosystem such as:

  • Microsoft Azure
  • Amazon Web Services
  • Google Cloud

Security becomes much easier to understand when you already understand the infrastructure being secured.


Build a Cybersecurity Home Lab

A home lab can provide practical experience alongside certification study.

For example:

Internet / NAT

Firewall

Windows Server

Active Directory Domain

Windows Client

Linux Server

Security Monitoring System

Virtualization platforms can be used to create isolated test environments.

Practice activities can include:

  • Creating Active Directory users
  • Configuring Group Policy
  • Implementing password policies
  • Enabling MFA where applicable
  • Reviewing Windows Event Logs
  • Testing firewall rules
  • Running vulnerability scans against systems you own or are explicitly authorized to test
  • Hardening Windows
  • Hardening Linux
  • Analyzing network traffic
  • Testing backup and recovery
  • Investigating simulated security incidents

Important: Perform penetration testing and vulnerability scanning only against systems you own or have explicit authorization to test.


Certification Alone Is Not Enough

Consider two candidates.

Candidate A

Has:

Security+ → CEH → CISSP-related study

but little practical experience.

Candidate B

Has:

Security+ + several years of system/network/security administration + incident response + firewall management + vulnerability management + Active Directory security.

Candidate B may be significantly better prepared for many real cybersecurity roles.

The strongest combination is:

Certification + Knowledge + Labs + Real Experience + Continuous Learning


Cybersecurity Career Progression Example

A practical career progression could look like:

IT Support Engineer

System / Network Administrator

CompTIA Security+

Junior Security Analyst

Specialist Certification

Security Analyst / Engineer

Several Years of Security Experience

CISSP

Senior Security Engineer / Security Consultant / Security Architect / Security Manager

CISO / Head of Information Security

This is only an example. Cybersecurity careers do not follow one mandatory sequence.


Frequently Asked Questions

Is Security+ required before CEH?

No. Security+ is not universally required before CEH.

However, studying security fundamentals first can make advanced security concepts easier to understand.


Is CEH required before CISSP?

No.

CEH is not a CISSP prerequisite.

Choose CEH primarily when ethical hacking or offensive security aligns with your career.


Which is better after Security+: CEH or CySA+?

It depends on your objective.

Choose an ethical-hacking-focused path if you are interested in offensive security and penetration testing.

Choose CySA+ or a similar defensive-security path if you are interested in SOC operations, threat detection, monitoring and incident response.


Can I directly take CISSP after Security+?

You can prepare for and sit the CISSP exam, but earning the CISSP certification requires satisfying ISC2's professional-experience and other certification requirements.

Candidates without the required experience may qualify for the Associate of ISC2 pathway after passing the examination.


Does Security+ reduce the CISSP experience requirement?

Under ISC2's current 2026 approved credential list, Security+ is one of the credentials that can satisfy one year of the CISSP work-experience requirement. ISC2 allows a maximum one-year waiver through an eligible degree or approved credential.

Always verify the current ISC2 policy when you are ready to apply.


Should a network engineer learn cybersecurity?

Yes.

Network engineers already work with technologies fundamental to security, including TCP/IP, routing, DNS, VPNs, firewalls and access control.

Security+ followed by a network-security specialization can therefore be a logical progression.


Should a Windows administrator take Security+?

It can be valuable.

Windows administrators already encounter many security-related technologies, including Active Directory, Group Policy, NTFS permissions, Defender, BitLocker, Windows Firewall, RDP, auditing and identity management.

Security+ can help connect these technologies to broader cybersecurity principles.


Is CISSP only for managers?

No.

CISSP covers both technical and managerial security knowledge and is relevant to experienced professionals in roles such as security engineering, architecture, consulting, operations and management.

ISC2 describes CISSP as validating the technical and managerial knowledge needed to design, engineer and manage an organization's overall security posture.


What should I learn besides certifications?

Develop practical skills in:

  • Networking
  • Windows
  • Linux
  • Active Directory
  • PowerShell
  • Cloud computing
  • Firewalls
  • Endpoint security
  • SIEM
  • Vulnerability management
  • Identity management
  • Incident response
  • Security frameworks
  • Risk management

Certifications should validate and organize your learning rather than replace practical experience.


Final Recommendation / Conclusion

For most IT professionals entering cybersecurity, a sensible strategy is:

CompTIA Security+

Choose Your Specialization

CEH / CySA+ / Penetration Testing / Network Security / Cloud Security / GRC

Build Real Cybersecurity Experience

CISSP

Do not assume that everybody needs:

Security+ → CEH → CISSP

A better model is:

Security+ → Specialist Certification Relevant to Your Career → Experience → CISSP

If your objective is ethical hacking, CEH or another penetration-testing path makes sense.

If your objective is SOC and defensive security, consider CySA+ or another blue-team specialization.

If you work heavily with Azure, AWS or cloud infrastructure, cloud security may provide greater career value.

If you work with routers, switches, VPNs and firewalls, network security may be the better specialization.

If you intend to move toward governance and management, risk, audit and security-management certifications may be more appropriate.

Finally, treat CISSP as an experienced-professional milestone, not merely the third exam in a certification sequence.

The strongest cybersecurity professional is not the person with the longest list of certificates. It is the person who can combine:

Strong Fundamentals + Specialized Knowledge + Practical Skills + Professional Experience + Recognized Certifications

 

#CompTIASecurityPlus #SecurityPlus #CEH #CISSP #Cybersecurity #CyberSecurityCertification #CybersecurityCareer #CybersecurityRoadmap #CertificationRoadmap #EthicalHacking #CertifiedEthicalHacker #PenetrationTesting #PenTester #CySAPlus #SOCAnalyst #SecurityAnalyst #SecurityEngineer #SecurityArchitect #InformationSecurity #ITSecurity #NetworkSecurity #CloudSecurity #CCSP #CISM #GRC #RiskManagement #SecurityOperations #IncidentResponse #VulnerabilityManagement #BlueTeam #RedTeam #OffensiveSecurity #DefensiveSecurity #EthicalHacker #ISC2 #CompTIA #ECCouncil #CybersecurityTraining #CybersecuritySkills #CybersecurityJobs #CareerDevelopment #ITCareer #SystemAdministrator #NetworkEngineer #WindowsSecurity #LinuxSecurity #ActiveDirectorySecurity #CloudComputing #SecurityCertification #CybersecurityProfessional

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.