Which Cybersecurity Certification to Get First (A Real Decision Framework)
Every week I get some version of the same question: “Should I get Security+ or something else first?” And every week I resist giving the one-line answer, because the one-line answer is almost always wrong for the person asking it.
Most certification advice online is really just a popularity contest. Security+ gets recommended constantly, not because it’s right for everyone, but because it’s the answer that’s safe to give without knowing anything about you. I want to give you something more useful: an actual framework for deciding, based on where you’re starting from and where you’re trying to go.
Prefer to read the full breakdown? Keep scrolling. Prefer to watch? Full video above.
Start With the Question Nobody Asks First
Before you pick a certification, answer this: what job do you actually want in eighteen months? Not “something in cybersecurity.” A specific role. SOC analyst. GRC analyst. Cloud security engineer. Pentester. The certification that makes sense depends almost entirely on this answer, and most people skip it because it feels like a distraction from “just getting started.”
It’s not a distraction. It’s the whole decision.
The Framework
If you don’t yet know which direction you want to go: Security+ is genuinely the right call here, not because it’s magic, but because it’s broad enough to keep every door open while you figure out what you actually like. Think of it as a map, not a destination.
If you already know you want GRC, audit, or risk work: Skip straight past Security+ debates and look at something like a GRC-focused credential or even a foundational risk certification. Employers hiring for GRC roles care more about whether you can talk intelligently about frameworks and risk language than whether you hold a broad technical cert.
If you know you want hands-on technical work (SOC, blue team): A cert with a lab component matters more here than a multiple-choice exam. If the certification doesn’t make you actually configure something, investigate a log, or respond to a simulated incident, it’s teaching you vocabulary, not skill.
If you’re already employed in IT and transitioning internally: Your existing job is worth more than any certification. In this case, I’d actually recommend spending less time studying and more time asking your security team if you can shadow an investigation or sit in on an incident call. A cert plus real internal exposure beats two certs and no exposure, every time.
What I’d Push Back On
Here’s where I disagree with a lot of the advice floating around: stacking certifications early does not compound the way people think it does. I’ve interviewed candidates with four certifications and zero ability to explain what any of them actually taught them beyond exam content. A hiring manager can tell the difference in about ninety seconds between someone who studied for a test and someone who understands the material, and it has nothing to do with how many letters follow your name.
One certification, deeply understood and tied to a role you can talk about with real conviction, beats three certifications you crammed for back to back.
What I’d Actually Recommend
Pick one certification based on the framework above. Give yourself a real timeline, not an open-ended “whenever I get to it.” And while you’re studying, start building something alongside it: a home lab, a writeup of a CTF challenge, a mock incident response you talk through out loud. The certification proves you can pass a test. The project proves you can think. Hiring managers are increasingly looking for the second thing, and most candidates only bring the first.
My Take
If I had to bet on which of two candidates gets hired first, one with two certifications and nothing else, one with a single relevant certification and a documented project they can talk through in detail, I’d bet on the second person every time. The certification gets you past the resume filter. What you did with what you learned is what gets you the job.
Figure out the role first. Let the certification follow the role, not the other way around.
Enjoyed this article?
Subscribe to Professor Simon's weekly newsletter for practical insights, career guidance, and leadership lessons delivered every Friday.
A confirmation email will be sent. If you don't receive it, please check your spam or junk folder.
No spam. Unsubscribe anytime.
Prefer to Listen?
Listen to Professor Simon’s IT & Cybersecurity Podcast for practical conversations about cybersecurity careers, certifications, security leadership, and real-world lessons from the field.
Listen on Spotify

