Want a sequenced plan instead of a list? Join the structured learning tracks

Certification catalog

Four tracks, one table each. Filter by track, level or study-notes availability, or search by name, provider or job title.

64 certifications

Offensive Security 29

Offensive Security certifications
Cert name Target job title Level Prerequisites Study notes Recent updates
CRTA CyberWarFare Labs Junior Red Team Analyst Entry Networking, Linux/Windows basics and introductory web and Active Directory knowledge. Coming Soon Entry-level red team cert covering the external-to-internal kill chain: web foothold, pivoting and Active Directory abuse.
CEH EC-Council Ethical Hacker / Junior Penetration Tester Entry Two years of infosec experience, or official EC-Council training (which waives the experience requirement). CEH Notes v13 (312-50v13) is the current version, with AI woven into all five hacking phases. The optional 6-hour CEH Practical plus CEH earns CEH Master.
OSWP OffSec Wireless Penetration Tester Entry Linux command line and networking fundamentals. OSWP Notes PEN-210 is included in OffSec's Learn subscriptions. Short proctored practical exam (under 4 hours) on Wi-Fi attacks.
eJPT INE Security Junior Penetration Tester Entry None. Networking and Linux basics help. eJPT Notes Rebuilt on 31 March 2026: new web-app and recon content, a new Offensive AI course, and a revised practical exam.
TryHackMe PT1 TryHackMe Junior Penetration Tester Entry TryHackMe's Jr Penetration Tester path recommended. THM PT1 Notes Positioned by TryHackMe as the practical step before OSCP. Business list price includes training and a free retake.
HackTheBox CJCA Hack The Box Junior Security Analyst / Junior Pentester Entry Complete the HTB Academy Junior Cybersecurity Associate path. HackTheBox CJCA Notes HTB's entry-level certification, covering offensive and defensive fundamentals before CPTS or CDSA.
OSCP OffSec Penetration Tester Intermediate No formal prerequisite. Comfortable with Linux/Windows, TCP/IP, web basics and light scripting (Python/Bash). OSCP Notes Passing PEN-200 now awards both OSCP (lifetime) and OSCP+ (valid 3 years, renewable via CPE or another OffSec exam). Bonus points are gone and the Active Directory set is scored with partial credit.
HackTheBox CPTS Hack The Box Penetration Tester Intermediate Complete the HTB Academy Penetration Tester job-role path (required before the exam voucher can be used). HackTheBox CPTS Notes Exam voucher is bundled with HTB Academy's Silver Annual plan. 10-day practical engagement ending in a commercial-grade report.
CRTP Altered Security Active Directory Pentester / Junior Red Teamer Intermediate Basic Active Directory concepts, PowerShell and Windows administration. No formal prerequisite. CRTP Notes Still the most common first Active Directory attack cert. 24-hour hands-on exam against an AD lab followed by a report.
OSWA OffSec Web Application Penetration Tester Intermediate HTTP, HTML/JavaScript basics, Burp Suite familiarity and Linux command line. OSWA Notes WEB-200 focuses on black-box web testing (XSS, SQLi, SSTI, SSRF and more) with a 24-hour proctored exam.
CompTIA PenTest+ CompTIA Penetration Tester / Vulnerability Analyst Intermediate None required. Network+/Security+ and 3–4 years of hands-on security experience recommended. COMPTIA Pentest+ Notes PT0-003 is the current version, adding AI, cloud and attack-surface management topics. DoD 8140 approved.
eCPPT INE Security Penetration Tester Intermediate eJPT-level skills; Active Directory and basic exploit development knowledge. eCPPT Notes Current v3 format is a hands-on practical exam aligned to INE's Professional Penetration Tester path.
TCM PNPT TCM Security Penetration Tester Intermediate Networking, Linux and Active Directory basics. PJPT is a useful stepping stone. TCM PNPT Notes 5-day practical engagement (OSINT → external → Active Directory), 2 days for the report, then a live debrief.
HackTheBox CWES Hack The Box Web Application Pentester / Bug Bounty Hunter Intermediate Complete the HTB Academy Bug Bounty Hunter path. HackTheBox CWES Notes Renamed from CBBH to CWES. Exam voucher is bundled with HTB Academy's Silver Annual plan.
CRTO Zero-Point Security Red Team Operator Intermediate OSCP-level skills and Active Directory fundamentals. Coming Soon Adversary simulation with Cobalt Strike, from initial access to reporting. The credential does not expire.
BSCP PortSwigger Web Application Pentester Intermediate Complete PortSwigger Web Security Academy practitioner-level labs. Coming Soon 4-hour practical exam: two web apps, each to be fully compromised using Burp Suite.
GPEN GIAC Penetration Tester Intermediate None formal. SANS SEC560 is the aligned course. Coming Soon Proctored exam that includes CyberLive hands-on questions. Renewal every 4 years.
CARTP Altered Security Cloud Red Teamer Intermediate Active Directory attack basics and working knowledge of Azure and Entra ID. Coming Soon Hands-on Azure/Entra ID attack lab with a 24-hour practical exam.
CRTE Altered Security Red Team Operator Advanced CRTP-level Active Directory attack skills; comfort with multi-forest trusts and PowerShell tradecraft. CRTE Notes 48-hour practical exam across multiple domains and forests, followed by a report.
OSEP OffSec Red Team Operator / Senior Penetration Tester Advanced OSCP-level skills plus C#/PowerShell and Active Directory exploitation. OSEP Notes 48-hour proctored exam centred on AV/EDR evasion, lateral movement and Active Directory attacks.
OSED OffSec Exploit Developer / Vulnerability Researcher Advanced x86 assembly, C, Python and debugging with WinDbg. OSED Notes 48-hour exam on Windows user-mode exploit development: DEP/ASLR bypass, ROP chains and custom shellcode.
OSAI OffSec AI Red Teamer / AI Security Engineer Advanced OSCP-level offensive skills, Python, and working knowledge of LLM applications, RAG and AI agents. OSAI Notes AI-300 launched in 2026. Passing the proctored practical exam against an AI-enabled enterprise environment awards OSAI plus the 3-year OSAI+.
HackTheBox CAPE Hack The Box Active Directory Pentester / Red Teamer Advanced Complete the HTB Academy Active Directory Penetration Tester path; CPTS-level skills strongly recommended. HackTheBox CAPE Notes Exam voucher is bundled with HTB Academy's Gold Annual plan. Expert-level multi-day AD engagement with a commercial report.
TryHackMe PT2 TryHackMe Penetration Tester Advanced PT1 or equivalent hands-on pentest experience across web, AD and cloud. Coming Soon Launched 2026: one graded engagement spanning Active Directory, cloud, container breakout and an AI/LLM target.
OSWE OffSec Senior Application Security Engineer / Web Pentester Advanced Ability to read PHP, Java, .NET, JavaScript and Python code; OSWA-level web skills. OSWE Notes 48-hour exam on white-box source review, chaining auth bypasses into remote code execution.
HackTheBox COAE Hack The Box AI Red Teamer Expert Complete the AI Red Teamer job-role path (co-developed with Google); solid Python and ML fundamentals. HackTheBox COAE Notes Launched April 2026: a 7-day practical assessment of AI-driven infrastructure plus a commercial-grade report. Available on the Silver Annual plan.
CRTL Zero-Point Security Red Team Lead / Senior Operator Expert CRTO-level tradecraft, C programming, Windows internals and EDR evasion. Coming Soon Zero-Point Security has joined Fortra, the company behind Cobalt Strike. CRTL remains the advanced evasion-focused follow-on to CRTO.
OSEE OffSec Senior Exploit Developer Expert OSED-level exploit development plus Windows kernel internals. Coming Soon EXP-401 is delivered as live training only; the exam is a 72-hour practical.
HackTheBox CWEE Hack The Box Senior Web Pentester / AppSec Researcher Expert Complete the HTB Academy Senior Web Penetration Tester path. Coming Soon Advanced black-box and white-box web exploitation. Voucher bundled with the Gold Annual plan.

Defensive Security 18

Defensive Security certifications
Cert name Target job title Level Prerequisites Study notes Recent updates
BTL1 Centri (formerly Security Blue Team) SOC Analyst (Tier 1) Entry None. Basic networking and operating-system knowledge helps. BTL1 Notes Security Blue Team rebranded as Centri on 1 June 2026. Still a 24-hour practical incident-response exam with lifetime certification.
TryHackMe SAL1 TryHackMe SOC Analyst (Tier 1) Entry TryHackMe's SOC Level 1 path recommended. TryHackMe SAL1 Notes First rung of TryHackMe's SEC1 → SAL1 → SAL2 defensive ladder. Business list price includes training and a free retake.
CompTIA Security+ CompTIA Security Analyst / Security Administrator Entry None required. Network+ and 2 years of IT experience recommended. COMPTIA SEC+ Notes SY0-701 is live; its objectives were refreshed in April 2026. SY0-801, with a dedicated LLM objective, has a tentative preview launch around 20 October 2026.
Google Cybersecurity Google Junior SOC Analyst / Cybersecurity Associate Entry None. Designed for complete beginners. Google CyberSecurity Notes Self-paced on Coursera; covers Linux, SQL, Python, SIEM tools and incident-response basics. Often paired with Security+.
Microsoft SC-900 Microsoft IT / Security Associate (Microsoft stack) Entry None. Microsoft SC-900 Notes Still an active Fundamentals exam. Microsoft's 2026 security path adds SC-500 (Cloud & AI Security Engineer) while AZ-500 retired on 31 August 2026.
ISC2 CC ISC2 Entry-level Security Analyst / IT Support moving into security Entry None. Coming Soon New exam outline effective 1 September 2026, the first major update since launch, adding AI and stronger GRC coverage.
CCDL1 CyberDefenders SOC Analyst (Tier 1) Entry Networking and operating-system fundamentals. Coming Soon CyberDefenders' associate-level cert. All CyberDefenders certs are valid four years, renewable by retake or 36 CPEs.
HackTheBox CDSA Hack The Box SOC Analyst / Incident Responder Intermediate Complete the HTB Academy SOC Analyst path. HackTheBox CDSA Notes Multi-day practical incident investigation ending in a report. Voucher bundled with the Silver Annual plan.
TryHackMe SAL2 TryHackMe SOC Analyst (Tier 2) / Incident Responder Intermediate SAL1, or comfort with alert handling, log analysis and investigation workflows. Coming Soon Launched 25 March 2026 with NCC Group. Grades both technical and communication skills; valid for three years.
CompTIA CySA+ CompTIA SOC Analyst / Threat Intelligence Analyst Intermediate None required. Security+/Network+ and about 4 years of hands-on experience recommended. COMPTIA CYSA+ Notes CS0-004 launched 23 June 2026, adding AI and automation in security operations.
CompTIA SecAI+ CompTIA AI Security Analyst / Security Engineer Intermediate None required. 3–4 years in IT with 2+ years in security; Security+, CySA+ or PenTest+ recommended. COMPTIA SEC AI+ Notes Launched 17 February 2026 as the first of CompTIA's Expansion Series. Valid three years.
SPLK-5001 Splunk SOC Analyst (Splunk environments) Intermediate None required. Splunk Power User-level knowledge recommended. SPLK-5001 Notes 66 multiple-choice questions in 75 minutes via Pearson VUE. Splunk is now part of Cisco.
OSDA OffSec SOC Analyst Intermediate Networking, Windows/Linux logging and familiarity with common attack techniques. Coming Soon SOC-200 teaches detecting attacks in a SIEM; the exam is a 24-hour practical.
GCIH GIAC Incident Responder Intermediate None formal. SANS SEC504 is the aligned course. Coming Soon Includes CyberLive hands-on questions. Renewal every 4 years.
Microsoft SC-200 Microsoft SOC Analyst (Defender / Sentinel) Intermediate None required. SC-900 and KQL basics help. Coming Soon Covers Defender XDR, Microsoft Sentinel and KQL hunting. Free annual renewal assessment on Microsoft Learn.
BTL2 Centri (formerly Security Blue Team) Threat Hunter / SOC Analyst (Tier 2–3) Advanced BTL1 recommended; 2–4 years in security operations. BTL2 Notes Up to 72-hour practical threat-hunting exam with a written report; certification valid for four years.
CCDL2 CyberDefenders SOC Analyst (Tier 2) / DFIR Analyst Advanced SOC fundamentals, Windows/Linux artefacts and networking. CCDL1 is the associate-level step. CCDL2 Notes Renamed from CCD to CCDL2 when CCDL1 launched; existing CCD badges were updated automatically. 48-hour Elastic-based investigation exam.
CompTIA SecurityX CompTIA Security Architect / Senior Security Engineer Advanced None required. 10 years in IT with 5 years hands-on security recommended. Coming Soon CASP+ was rebranded SecurityX with the CAS-005 exam as part of CompTIA's Xpert Series.

GRC 9

GRC certifications
Cert name Target job title Level Prerequisites Study notes Recent updates
CISA ISACA IT Auditor / IS Assurance Analyst Intermediate 5 years of IS audit, control or security experience (up to 3 years can be waived). Coming Soon Current job practice since August 2024. An active CISA unlocks ISACA's AAIA AI-audit credential.
ISC2 CGRC ISC2 GRC Analyst / Authorization Officer (RMF) Intermediate 2 years of paid experience in at least one of the CGRC domains. Coming Soon Renamed from CAP. Also listed as a qualifying credential for ISACA's AAIR.
ISO 27001 Lead Implementer PECB ISMS Implementer / GRC Consultant Intermediate ISMS fundamentals. The full credential requires professional experience (PECB: 5 years, 2 in information security management). Coming Soon Aligned to ISO/IEC 27001:2022. Certified organisations had to transition from the 2013 edition by 31 October 2025.
ISO 27001 Lead Auditor PECB ISMS Auditor / Compliance Auditor Intermediate ISMS fundamentals plus audit experience for the full credential. Coming Soon Audits now run against the 2022 edition's 93 Annex A controls; the 2013 transition window has closed.
CIPP/E IAPP Privacy Analyst / Data Protection Officer Intermediate None. Coming Soon Body of knowledge centres on GDPR. Recertify every 2 years with 20 CPE credits.
AIGP IAPP AI Governance Lead / Responsible AI Analyst Intermediate None. Coming Soon Maps AI governance to the EU AI Act, NIST AI RMF and related frameworks.
CRISC ISACA IT Risk Manager / Risk & Control Analyst Advanced 3 years of experience in IT risk management and IS control. Coming Soon Counts as a qualifying credential for ISACA's new AI-risk certification (AAIR).
AAIA ISACA AI Auditor / Senior IT Auditor Advanced Active CISA, or a qualifying audit designation (CIA, US CPA, ACCA/FCCA, Canadian, Australian or Japanese CPA). Coming Soon Eligibility was expanded beyond CISA/CIA/CPA to include ACCA and several international CPA designations.
AAIR ISACA AI Risk Manager Advanced One of about 25 qualifying credentials, including CRISC, CISA, CISM, CISSP and CGRC. Coming Soon The newest of ISACA's AI trio alongside AAIA (audit) and AAISM (security management).

Leadership 8

Leadership certifications
Cert name Target job title Level Prerequisites Study notes Recent updates
CISSP ISC2 Security Manager / Security Architect (CISO track) Advanced 5 years of paid work in 2+ of the 8 domains (one year can be waived). Pass without it and you become an Associate of ISC2. CISSP Notes The experience-waiver list was cut from about 50 to 25 credentials on 1 April 2026 (CEH, CISA, CRISC and OSCP removed).
CISM ISACA Information Security Manager Advanced 5 years in information security, including 3 in security management. Coming Soon New exam content outline from 3 November 2026, adding enterprise and information security architecture.
AAISM ISACA AI Security Manager Advanced Active CISM or CISSP. Coming Soon Part of ISACA's 2025–2026 AI credential line-up; gated behind an active CISM or CISSP.
GSLC GIAC Security Leader / Security Manager Advanced None formal. SANS LDR512 is the aligned course. Coming Soon Covers security program management, risk and team leadership. Renewal every 4 years.
CCSP ISC2 Cloud Security Architect / Cloud Security Manager Advanced 5 years in IT, including 3 in security and 1 in a CCSP domain. An active CISSP substitutes the whole requirement. Coming Soon New exam outline from 1 August 2026 folds AI/ML security into all six domains; adaptive (CAT) format since October 2025.
CCISO EC-Council CISO / Security Executive Expert 5 years in each of 3 of the 5 CCISO domains (training can reduce this); eligibility application required. Coming Soon Executive-level program focused on governance, risk, strategy and finance rather than hands-on skills.
CGEIT ISACA IT Governance Director Expert 5 years managing or advising on enterprise IT governance. Coming Soon Board- and executive-level governance credential; qualifies for ISACA's AAIR.
ISSMP ISC2 Security Program Manager Expert Active CISSP plus 2 years of security management experience. Coming Soon CISSP concentration focused on leading and governing a security program.

Not sure which one is yours?

Coaching & cert roadmaps

One-to-one guidance and a roadmap built around your background, target role and timeline, so you stop guessing which cert comes next.

See coaching programs

Structured learning tracks

Membership with role- and cert-based learning tracks: roadmaps, cheat sheets, assessments, exclusive writeups and member pricing on notes.

Join the learning tracks

Prep resources & cheat sheets

Cheat sheets, command references and exam-day extras for when you already know the material and need it fast and in one place.

Browse prep resources