New to security
Pick one foundation, then one hands-on cert in the track that interests you. Don't stack theory certs.
Security+ or ISC2 CC, then BTL1 or SAL1 for blue team, eJPT or PT1 for red team.
All entry-level certs64 certifications from 21 providers, each with the job title it targets, what you need before you start, what changed recently, and study notes where they exist. Read the map bottom-up: start low in your track and climb.
marks certs with study notes available. Select any cert for its full profile.
Pick one foundation, then one hands-on cert in the track that interests you. Don't stack theory certs.
Security+ or ISC2 CC, then BTL1 or SAL1 for blue team, eJPT or PT1 for red team.
All entry-level certsYour existing experience changes which first cert makes sense. Auditors, IT admins and developers each have a shortcut that a generic list won't show.
Ex-IT ops toward defensive, audit and finance toward GRC, developers toward web security.
Get a roadmap built for your backgroundYour next cert should either deepen your current role or open the next one. Check the experience gates before you buy anything.
OSEP, CRTE and OSAI for operators, BTL2 and CCDL2 for analysts, CISSP and CISM toward management.
Follow a structured learning trackCheat sheets, command references and exam-day extras for when you already know the material and need it fast and in one place.
Mid-prep and the final week before an exam.
Browse prep resourcesOne-to-one guidance and a roadmap built around your background, target role and timeline, so you stop guessing which cert comes next.
Career switchers and anyone stuck choosing between paths.
See coaching programsMembership with role- and cert-based learning tracks: roadmaps, cheat sheets, assessments, exclusive writeups and member pricing on notes.
Learners who want a sequenced plan and steady progress.
Join the learning tracksMost certification lists rank by popularity. That's the wrong question. The useful questions are which job a cert actually gets you closer to, what it assumes you already know, and whether the exam changed since the blog post you're reading was written. This catalog answers those three for every entry, across offensive security, defensive security, GRC and leadership, and links straight to the study notes when they exist.
Recent changes are tracked because they matter: CySA+ moved to CS0-004 in June 2026, CISSP's experience-waiver list was cut in April, and Security+ SY0-801 is on the way. Studying for last year's exam is the most expensive mistake on this page.