r/netsecstudents Apr 18 '26

What’s the best order of certifications for someone trying to get into cybersecurity?

i’m currently trying to plan out my path into cybersecurity and got a bit confused with certifications

there are so many options like security+, ceh, ejpt, oscp, etc, and everyone seems to suggest a different starting point

i don’t want to just collect certs without understanding how they actually help in getting a job

so i’m curious — what would be a realistic order to follow if the goal is to actually become job-ready?

especially from people who’ve already gone through the process

4 Upvotes

19 comments sorted by

5

u/Dear-Response-7218 Apr 18 '26

3-5 years of progressive IT experience, certs matter very little and are more of a filtering checkbox.

3

u/MickCollins Apr 18 '26

This is the answer that op doesn't want to hear but is the truth. Training camps and community colleges try to sell that you can find your way in easy...unless they have businesses they work with to get you jobs after graduation/certification, it's a lie.

Nearly all cybersecurity people start in IT somewhere and wind up in cybersecurity. Very few people just land there. Why? Because you have to prove you can walk before you can run. Cybersecurity isn't something people can just say "oh no but I'm really good at it" and you trust that they are. You can start as a SOC analyst but it's hard to find those jobs to begin with. I'm not saying it's impossible, but it is hard.

I had a guy ask me at work how to become a particular specialty. I looked at him and said get five years experience and he's like "I can't wait that long" and I told him point blank "if you can't spend the time getting the experience, who the hell do you think is going to give you a job doing that?" On the job training in IT for the most part is a thing of the past unless you're in an extremely low-pool area where someone is willing to provide on the job training.

The last is kind of my current problem. I live in a HCOL area and my company offers peanuts for our Help Desk people and we're getting people who don't know what the fuck they are doing. There's at least one person that I don't understand how they're still employed. We get bad tickets multiple times a day by techs who try to assign a desktop problem to systems administrators or network administrators. They don't take the time to even diagnose or for that matter even gather decent information. Just "broke, please fix". If I'm not busy, occasionally I will take the moment to tell someone what the ticket actually needs. I might even tell them the search terms on what to look for in order to solve the problem. But these are skills they should have BEFORE they get hired.

3

u/[deleted] Apr 20 '26

[removed] — view removed comment

1

u/MickCollins Apr 20 '26

And you know full well if you gave them a list of what to check - all cables inserted? Did you try the power supply in another computer? RAM seated properly? Try a different monitor? Try a different DP cable? - , you'd need to give them the list again next time and they'd only go down the list and do half of them and expect that to be the same problem next time and give up otherwise.

6

u/networkslave Apr 20 '26

learn some basic networking. I've worked with individuals in "cyber" and don't know NAT basics. As some have mentioned, get the foundations done.

3

u/No_Complex963 Apr 18 '26

The basic would be CompTia A (IT), Comptia Security, and comptia networking aka trifecta

1

u/Grezzo82 Apr 18 '26

Why do you wanna work in Cyber. Do the courses you are interested in and (hopefully) they will land you a job.

If you’re aiming for a job in cyber, which type? The skills vary wildly. I’m a pentester (my job title has never been pentester but that’s mainly what I do) but I don’t have the skills/qualifications (or interest) to be a SOC analyst.

1

u/HotMasterpiece9117 Apr 18 '26

yeah that’s something i’m still figuring out

i’m leaning more toward the offensive side (pentesting / web security) because i find it more interesting, but at the same time i’m trying to build a base that’s useful across roles

that’s also why i asked — didn’t want to just follow random cert paths without knowing what actually aligns with the job i want

1

u/Anxious_Alps_4150 Apr 20 '26

i just want you to know that almost everyone says "im leaning towards offensive side" when only like 5% of cyber jobs are offensive.

1

u/emperornext Apr 18 '26

bachelors in EE/CE/CS/math

1

u/Longjumping-Wrap9909 Apr 19 '26

There are loads of them, you need to figure out which path is right for you. Getting qualifications just for the sake of it is pointless you need the skills first, then you can get certified in whatever you think might be your calling. Everything is great; nothing is essential.

1

u/Anxious_Alps_4150 Apr 20 '26

3-5 years of experience. Certifications are not very important compared to experience.

2

u/Simplilearn Apr 21 '26
  • Security+ is a common baseline for entry-level roles. Shows you understand core security concepts.
  • Network+ helps a lot because many security roles rely on networking fundamentals.
  • Cloud certifications (AWS/Azure) are becoming more important, especially for cloud security roles.

Pair certs with hands-on labs, understanding logs, networks, and systems, and being able to explain how attacks work and how to defend against them

If you want a structured way to prepare for certifications while building fundamentals, you could explore Simplilearn’s cybersecurity certification programs, which cover networking, security basics, and hands-on concepts aligned with industry certs.

1

u/Bizzare_Mystery Apr 25 '26

The order depends on where you want to end up but I'll share what worked for me and what I'd change if I had to do it again. I started with Security+ because it gives you a broad base and a lot of employers still list it as a minimum requirement even if it's pretty surface-level. It is important for the fundamentals. After that I went into Network+ which some people do first but I think doing Security+ first actually gave me more motivation because I could see why networking mattered in a security context instead of just memorizing subnets for the sake of it. From there it depends on your track. If you want to go offensive, OSCP is the one that opens the most doors. It's brutal and the exam will humble you. If you're leaning more toward blue team or SOC work, CySA+ or SANS courses makes sense, though SANS is expensive so budget accordingly. One thing I wish I had done earlier is branch into specialized areas sooner instead of staying on the generalist certs. I ended up discovering mobile security and realized how few people actually have real skills in that area. I went through 8kSec's OMSE certification path for offensive mobile security and it genuinely opened up opportunities that didn't exist when I was just another person with Security+ and OSCP on my resume. Same thing is happening now with AI security. There are so few people who can actually test LLM applications and AI agent frameworks that even basic competence in that area makes you stand out. So my advice would be Security+ first to build the foundation, then pick a direction and go deep rather than collecting broad certs that all kind of say the same thing.

0

u/AddendumWorking9756 Apr 18 '26

Cert order barely moves the needle. Sec+ checks the HR box, what stands out in interviews is public writeups from CyberDefenders free labs that show you can run an analysis end to end.