Certifications Hub

Books, roadmaps, costs, and study methods for major cybersecurity certifications.

Curated for practitioners. No affiliate links on this page. Updated for 2025–2026.

Certification paths and resources are community-curated. Verify current requirements with official bodies.

Quick Reference

41 certifications across 10 certification bodies. Costs are exam-only (training separate).

Exam facts at a glance, grouped by certification body. Exam fees only — training is costed separately in the cost summary.
Certification Level Domain Exam fee Format Passing Validity Experience
ISC2 6 certs
CISSPISC2 Advanced GRC / Management $749 · €690 3–6 hrs (CAT) · 100–175 700 / 1000 3 yrs + 40 CPE/yr 5 yrs in 2+ domains
CCSPISC2 Advanced Cloud Security $599 · €550 4 hrs · 150 700 / 1000 3 yrs + 30 CPE/yr 5 yrs IT (3 in security, 1 in cloud)
SSCPISC2 Intermediate Operations / Technical $249 · €230 4 hrs · 150 700 / 1000 3 yrs + 20 CPE/yr 1 yr in 1+ domain
CCISC2 Entry General Security $199 · €185 2 hrs · 100 700 / 1000 3 yrs + 15 CPE/yr None
CGRCISC2 Intermediate GRC $599 · €550 3 hrs · 125 700 / 1000 3 yrs + 20 CPE/yr 2 yrs in 1+ domain
CSSLPISC2 Advanced AppSec / SDLC $599 · €550 4 hrs · 175 700 / 1000 3 yrs + 30 CPE/yr 4 yrs in SDLC
ISACA 5 certs
CISAISACA Advanced Audit $760 · €700 4 hrs · 150 450 / 800 3 yrs + 20 CPE/yr 5 yrs in IS audit
CISMISACA Advanced Security Management $760 · €700 4 hrs · 150 450 / 800 3 yrs + 20 CPE/yr 5 yrs in infosec mgmt (3 in mgmt)
CRISCISACA Advanced Risk Management $760 · €700 4 hrs · 150 450 / 800 3 yrs + 20 CPE/yr 3 yrs in IT risk mgmt
CGEITISACA Expert IT Governance $760 · €700 4 hrs · 150 450 / 800 3 yrs + 20 CPE/yr 5 yrs in IT governance
CDPSEISACA Intermediate Privacy Engineering $760 · €700 3.5 hrs · 120 450 / 800 3 yrs + 20 CPE/yr 2 yrs in privacy
CompTIA 4 certs
Security+CompTIA Entry General Security $404 · €375 1.5 hrs · 90 max 750 / 900 3 yrs + CEUs None (2 yrs recommended)
CySA+CompTIA Intermediate Defensive / SOC $404 · €375 2.5 hrs · 85 max 750 / 900 3 yrs + CEUs 3–4 yrs hands-on
PenTest+CompTIA Intermediate Offensive $404 · €375 2.5 hrs · 85 max 750 / 900 3 yrs + CEUs 3–4 yrs hands-on
CASP+CompTIA Advanced Security Architecture $494 · €455 2.5 hrs · 90 max Pass / Fail 3 yrs + CEUs 10 yrs general IT (5 in security)
GIAC / SANS 10 certs
GSECGIAC / SANS Intermediate General Security $949 · €875 4–5 hrs · 106–180 73% 4 yrs + 36 CPE None (SEC401 recommended)
GPENGIAC / SANS Advanced Offensive $949 · €875 3 hrs · 82 75% 4 yrs + 36 CPE None (SEC560 recommended)
GCIHGIAC / SANS Intermediate Defensive / IR $949 · €875 4 hrs · 106 70% 4 yrs + 36 CPE None (SEC504 recommended)
GCIAGIAC / SANS Advanced Defensive / Network $949 · €875 4 hrs · 106 67% 4 yrs + 36 CPE None (SEC503 recommended)
GCFAGIAC / SANS Advanced DFIR $949 · €875 4 hrs · 82 72% 4 yrs + 36 CPE None (FOR508 recommended)
GCFEGIAC / SANS Intermediate DFIR $949 · €875 4 hrs · 82 71% 4 yrs + 36 CPE None (FOR500 recommended)
GREMGIAC / SANS Advanced Malware Analysis $949 · €875 4 hrs · 75 73% 4 yrs + 36 CPE None (FOR610 recommended)
GWAPTGIAC / SANS Intermediate Offensive / Web $949 · €875 4 hrs · 82 71% 4 yrs + 36 CPE None (SEC542 recommended)
GFACTGIAC / SANS Entry General Security $949 · €875 2 hrs · 75 71% 4 yrs + 36 CPE None
GXPNGIAC / SANS Expert Offensive / Exploit Dev $949 · €875 3 hrs · 60 67% 4 yrs + 36 CPE None (SEC660 recommended)
OffSec 6 certs
OSCPOffSec Intermediate Offensive $1,749 · €1,610 23 hrs 45 min · Practical (3 standalone + AD set) 70 points Lifetime None (PEN-200 course required)
OSEPOffSec Advanced Offensive / Evasion $1,749 · €1,610 47 hrs 45 min · Practical Secret flag(s) Lifetime OSCP or equivalent
OSWEOffSec Advanced Offensive / Web $1,749 · €1,610 47 hrs 45 min · Practical Secret flag(s) Lifetime OSCP or equivalent + web dev knowledge
OSWPOffSec Intermediate Offensive / Wireless $799 · €735 3 hrs 45 min · Practical Not disclosed Lifetime Basic networking
OSEDOffSec Expert Offensive / Exploit Dev $1,749 · €1,610 47 hrs 45 min · Practical Not disclosed Lifetime OSCP + programming
OSDAOffSec Intermediate Defensive / SOC $1,749 · €1,610 23 hrs 45 min · Practical Not disclosed Lifetime Basic security knowledge
EC-Council 2 certs
CEHEC-Council Intermediate Offensive $1,199 · €1,100 4 hrs · 125 70% 3 yrs + 120 ECE 2 yrs in infosec (or official training)
CHFIEC-Council Intermediate DFIR $1,199 · €1,100 4 hrs · 150 70% 3 yrs + 120 ECE 2 yrs in infosec (or official training)
INE / eLearnSecurity 2 certs
eJPTINE / eLearnSecurity Entry Offensive $249 · €230 48 hrs · Practical + MCQ 70% 3 yrs None
eCPPTINE / eLearnSecurity Intermediate Offensive $400 · €370 14 days (7 days exam + 7 days report) · Practical + Report Report-based 3 yrs eJPT or equivalent
TCM Security 1 certs
PNPTTCM Security Intermediate Offensive $399 · €370 5 days (pentest) + 2 days (report) · Practical + Report + Debrief Report-based + debrief Lifetime None
Cisco 2 certs
CyberOps AssociateCisco Entry Defensive / SOC $330 · €305 2 hrs · 95–105 Not publicly disclosed 3 yrs None
CCNP SecurityCisco Advanced Network Security $660 · €610 2 hrs (core) + 1.5 hrs (concentration) · ~100 per exam Not publicly disclosed 3 yrs 3–5 yrs networking
Cloud Vendors (AWS, Azure, GCP) 3 certs
AWS Security SpecialtyCloud Vendors (AWS, Azure, GCP) Advanced Cloud Security $300 · €275 2.5 hrs · 65 750 / 1000 3 yrs 5 yrs IT security + 2 yrs AWS
AZ-500Cloud Vendors (AWS, Azure, GCP) Intermediate Cloud Security $165 · €155 2.5 hrs · 40–60 700 / 1000 1 yr (annual renewal via free assessment) 1–2 yrs Azure security
GCP Security EngineerCloud Vendors (AWS, Azure, GCP) Advanced Cloud Security $200 · €185 2 hrs · 50–60 Not publicly disclosed 2 yrs 3+ yrs industry + 1 yr GCP
◆ ◆ ◆

Certification Roadmaps by Role

Six paths, start to senior. Read the fit line first — ruling a path out is as useful as picking one. Every step links to its full profile.

🛡 SOC Analyst (L1 → L3)

You want to work in a monitoring team, triaging alerts and running detections. The most common way into the industry, and the easiest to get hired for with no prior security experience.

Start with
CC
Steps
6
Exam fees, full path
~$4,580
Realistic duration
3–5 years to L3
  1. Security+ · $404 or CC · $199 Baseline security knowledge. DoD 8570 compliant.
  2. CyberOps Associate · $330 SOC-specific fundamentals and monitoring skills.
  3. CySA+ · $404 Deeper analyst skills: threat detection, SIEM, vulnerability management.
  4. OSDA · $1,749 Practical SOC skills validated by hands-on exam.
  5. GCIH · $949 Incident handling expertise via SANS SEC504.
  6. GCIA · $949 Advanced network analysis and intrusion detection.

Worth knowing: Shift work is common at L1. The first two steps are enough to get hired — do not stall at the bottom collecting entry certs.

🖤 Penetration Tester (Junior → Senior)

You want to test systems hands-on and write up what you broke. Suits people who enjoy long unstructured problem-solving and can self-direct through lab work.

Start with
eJPT
Steps
6
Exam fees, full path
~$5,499
Realistic duration
3–6 years to senior
  1. eJPT · $249 Affordable, practical entry point. Builds foundational pentest skills.
  2. Security+ · $404 or PenTest+ · $404 Broad security knowledge base. Meets compliance requirements.
  3. PNPT · $399 Real-world pentest methodology with report writing and debrief.
  4. OSCP · $1,749 Industry gold standard. Validates hands-on exploitation skills.
  5. OSEP · $1,749 Advanced evasion, AD attacks, and red team techniques.
  6. GXPN · $949 or OSED · $1,749 Expert-level exploit development and advanced offensive research.

Worth knowing: The most oversubscribed path in security — junior offensive roles are scarce. Certifications alone will not get you hired without lab work and write-ups to show.

📋 GRC / Compliance Analyst

You want to work on audit, risk and regulation rather than systems. The most accessible path for career changers from audit, law, finance or project management.

Start with
CC
Steps
6
Exam fees, full path
~$3,827
Realistic duration
4–7 years to senior
  1. CC · $199 or Security+ · $404 Security fundamentals baseline.
  2. CISA · $760 IT audit skills — essential for compliance roles.
  3. CRISC · $760 IT risk management specialization.
  4. CISM · $760 Security management and governance perspective.
  5. CGRC · $599 RMF and authorization specialization (government/regulated sectors).
  6. CISSP · $749 Broad management credential. Opens CISO-track opportunities.

Worth knowing: ISACA certifications need verified work experience before they are awarded — you can pass the exam years before you can use the letters.

☁ Cloud Security Engineer

You already work in cloud, platform or DevOps and want to move sideways into security. The fastest path to a well-paid role if you have engineering experience already.

Start with
Security+
Steps
5
Exam fees, full path
~$2,321
Realistic duration
2–4 years
  1. Security+ · $404 Security fundamentals baseline.
  2. AZ-500 · $165 or AWS Security Specialty · $300 or GCP Security Engineer · $200 Platform-specific security skills for your primary cloud.
  3. CySA+ · $404 Defensive monitoring skills applicable to cloud SOC.
  4. CCSP · $599 Vendor-neutral cloud security architecture and governance.
  5. CISSP · $749 Senior security leadership credential.

Worth knowing: Vendor certifications expire on a short cycle and track a moving product. Pick the cloud your employer actually runs before you buy anything.

🔍 DFIR / Threat Hunter

You want to work incidents end to end and reconstruct what happened. Usually entered from a SOC role rather than directly — expect this to be a second move, not a first job.

Start with
Security+
Steps
6
Exam fees, full path
~$4,604
Realistic duration
4–6 years
  1. Security+ · $404 Security baseline.
  2. CySA+ · $404 Detection and analysis fundamentals.
  3. GCIH · $949 Incident handling via SANS SEC504.
  4. GCFE · $949 Windows forensics fundamentals via SANS FOR500.
  5. GCFA · $949 Advanced forensics and threat hunting via SANS FOR508.
  6. GREM · $949 Malware reverse engineering for deep analysis.

Worth knowing: The strongest certifications here are GIAC, and GIAC is priced around SANS training. Without an employer paying, this is the most expensive path on the page.

🏢 Security Architect / CISO Track

You already have several years in a technical security role and want to move into design and leadership. Not an entry path — the credentials at the top require verified experience.

Start with
Security+
Steps
6
Exam fees, full path
~$3,571
Realistic duration
6–10 years
  1. Security+ · $404 Baseline.
  2. CySA+ · $404 or GSEC · $949 Technical depth in defense or broad security.
  3. CASP+ · $494 or CCSP · $599 Advanced technical architecture skills.
  4. CISSP · $749 The management-level credential for senior roles.
  5. CISM · $760 Security program management — complements CISSP.
  6. CGEIT · $760 Enterprise IT governance for board-level communication.

Worth knowing: CISSP needs five years of paid experience across two domains. Passing early makes you an Associate of ISC2, not a CISSP.

◆ ◆ ◆

Certification Deep Dives

Detailed profiles with books, study resources, preparation advice, and realistic timelines.

ISC2

Gold Standard

ISC2 (International Information System Security Certification Consortium) is the world's leading cybersecurity professional organization, best known for the CISSP. All ISC2 exams are delivered via Pearson VUE.

Exam delivery: Pearson VUE (test center or online proctored) Retake: 30-day wait after 1st attempt, 60 days after 2nd, 90 days after 3rd. Max 3 retakes per year. Renewal: Annual CPE credits required (varies by cert). Annual Maintenance Fee (AMF).

ISACA

Governance & Audit

ISACA focuses on IT governance, risk, compliance, and audit. Their certifications are globally recognized in GRC roles. Exams via PSI or ISACA remote proctoring.

Exam delivery: PSI (test center or remote proctored) Retake: Can retake after waiting period. Additional exam fees apply per attempt. Renewal: 20 CPE hours/year, 120 CPE over 3-year cycle. Annual maintenance fee.

CompTIA

Industry Foundation

CompTIA offers vendor-neutral IT certifications recognized worldwide. Security+, CySA+, PenTest+, and CASP+ form the cybersecurity pathway. Exams via Pearson VUE.

Exam delivery: Pearson VUE (test center or online) Retake: No wait after 1st fail. 14-day wait for subsequent retakes. Full fee per attempt. Renewal: 3-year renewal cycle. Renew via CEUs or by passing a higher cert. CertMaster CE available.

GIAC / SANS

Training-Coupled

GIAC certifications validate skills taught in SANS courses. Exams are proctored via ProctorU or Pearson VUE. The associated SANS training is separate and expensive, but the exam can be taken independently.

Exam delivery: ProctorU (remote) or Pearson VUE Retake: 30-day wait. Retake fee applies. 2 retakes per certification attempt. Renewal: 36 CPE credits every 4 years. $479 renewal fee.

OffSec

Hands-On Offensive

OffSec (formerly Offensive Security) offers practical, hands-on certifications. Exams are 100% practical — no multiple choice. OSCP is the gold standard for penetration testers.

Exam delivery: OffSec proctored (remote, VPN-based lab exam) Retake: Retake included with active Learn subscription. Otherwise ~$249 per retake. Renewal: No expiration. Certification is lifetime once earned.

EC-Council

Ethical Hacking

EC-Council is known for the Certified Ethical Hacker (CEH) and related certifications. Exams via Pearson VUE or EC-Council Exam Center.

Exam delivery: Pearson VUE or ECC Exam Center Retake: Wait period varies. Retake voucher required. Renewal: 3-year renewal. 120 ECE credits over 3 years. $80/year membership fee.

INE / eLearnSecurity

Practical Training

INE (formerly eLearnSecurity) offers practical, lab-based certifications. Exams are hands-on penetration tests and report writing. Growing reputation as affordable practical alternatives.

Exam delivery: INE platform (remote, lab-based) Retake: Retake included with active INE Premium subscription. Renewal: No formal CPE. Certification valid for 3 years.

TCM Security

Practical & Affordable

TCM Security offers practical certifications focused on real-world penetration testing. Founded by Heath Adams (TheCyberMentor). Growing community recognition.

Exam delivery: TCM platform (remote, practical exam) Retake: Free retake included. Renewal: No expiration.

Cisco

Network Security

Cisco security certifications validate network security skills on Cisco platforms. The CyberOps track focuses on SOC operations.

Exam delivery: Pearson VUE Retake: 5-day wait for different exam, 14-day wait for same exam. Renewal: 3-year validity. Recertify via exam or CE credits.

Cloud Vendors (AWS, Azure, GCP)

Cloud Security

Major cloud providers offer security-specific certifications validating platform security skills. Each has its own exam delivery and renewal process.

Exam delivery: Pearson VUE (AWS, Azure) / Kryterion (GCP) Retake: 14-day wait (varies by provider). Renewal: 2–3 year validity. Recertify by passing current exam version.
◆ ◆ ◆

Evidence-Based Study Methods

Research-backed techniques that measurably improve certification exam outcomes.

Spaced Retrieval Practice

Meta-analyses of spacing and retrieval practice show medium-to-large improvements in long-term retention (effect size g ≈ 0.74) compared to massed study or rereading alone. This is the single highest-leverage study technique available.

  • After each chapter, close the book and write down everything you can recall. Check what you missed. This single act of retrieval creates stronger memory traces than re-reading.
  • Convert chapter end-questions, key tables, and definitions into flashcards. Use spaced repetition software (Anki, RemNote) to schedule reviews at expanding intervals.
  • For MCQ-based certs (CISSP, CISA, Security+): create cards that mirror exam question format — scenario-based with 4 options, not simple fact recall.
  • For practical certs (OSCP, PNPT): keep a “lab journal” documenting each machine compromised, techniques used, and mistakes made. Review periodically.

Active Study Patterns

  • Primary book as linear pass: Read through all domains once, creating question-style notes as you go. Don’t try to memorize everything — build a map of the material.
  • Complementary books for weak domains only: Use the second book for targeted reinforcement, not as another linear read. This prevents diminishing returns.
  • Interleave domains: Mix practice questions from different domains rather than studying one domain exhaustively before moving to the next. Interleaving improves discrimination between similar concepts.
  • Pomodoro technique: 25-minute focused blocks with 5-minute breaks. After 4 blocks, take a 15–30 minute break. RCT meta-analyses show structured breaks improve sustained attention and reduce fatigue.

Practice Exam Strategy

  • Diagnostic mode first: Take one full practice exam cold at the start of your study to identify weak domains. Don’t score-chase — use it to guide your study plan.
  • Domain-specific drilling: After studying each domain, take domain-specific practice sets. Review every wrong answer — understand why the correct answer is right and why yours was wrong.
  • Simulation mode last: 1–2 weeks before exam day, take a timed, full-length practice exam under exam conditions. No notes, no breaks beyond what the real exam allows. This calibrates your time management and stamina.
  • Never memorize practice answers: If you recognize a question from a previous attempt, skip it. The goal is pattern recognition, not answer memorization.

Practical Exam Preparation (OSCP, PNPT, etc.)

  • Build a personal methodology: Document your enumeration, exploitation, and post-exploitation workflow. Follow it consistently in labs so it becomes automatic under exam pressure.
  • Lab journaling: For every machine, record: initial scan results, attack path taken, dead ends, final exploit chain, and lessons learned. This is your most valuable study resource.
  • Report template: Build your report template before exam day. Practice writing findings on lab machines so the format is second nature during the timed exam.
  • Time management: In OSCP, allocate approximate time per machine. If stuck after your time budget, move on. Coming back with fresh eyes after other successes often breaks the block.
◆ ◆ ◆

Exam Day Logistics

What to expect and how to prepare for exam delivery.

Pearson VUE (ISC2, CompTIA, Cisco, EC-Council, AWS)
  • Create a Pearson VUE account and link it to your certification body account.
  • Schedule via the Pearson VUE website or the certification body’s portal.
  • Test center or OnVUE (online proctored) — online requires a private room, clear desk, webcam, and stable internet.
  • Bring two forms of government-issued ID (one with photo, one with signature). Names must match your registration exactly.
  • Arrive 15 minutes early for test center. For online, start the check-in process 30 minutes before.
  • No personal items allowed: no phones, watches, notes, food, or drinks (test center provides lockers).
PSI (ISACA)
  • Schedule through ISACA’s certification portal, which connects to PSI.
  • Test center or remote proctoring available.
  • Remote proctoring requirements similar to Pearson VUE: private room, clear desk, webcam.
  • One government-issued photo ID required.
OffSec Exams
  • Schedule through the OffSec portal once you have an active course subscription.
  • All exams are remote, proctored via webcam. You connect to the exam VPN.
  • OSCP: 23 hours 45 minutes active exam + 24 hours to write and submit your report.
  • Prepare your Kali VM and tools in advance. Test your VPN connection.
  • Take screenshots of every step — your report must contain proof of exploitation.
  • Plan for breaks, food, and sleep (especially for 24-hour exams).
GIAC / SANS Exams
  • Schedule through the GIAC portal via ProctorU (remote) or Pearson VUE (test center).
  • Most GIAC exams are open-book: you can bring printed/handwritten notes and course materials.
  • Build a thorough index of your SANS books before the exam — this is the most critical prep step for GIAC.
  • Two practice exams are included with each exam attempt.
If You Fail
  • Most bodies provide a score breakdown by domain. Focus your restudy on weak domains.
  • Wait periods vary: 30 days (ISC2, GIAC), 14 days (CompTIA after 2nd attempt), varies (ISACA, OffSec).
  • Full exam fee typically applies for retakes (exceptions: OffSec with active subscription, TCM includes one free retake).
  • Don’t rush the retake. Analyze what went wrong, rebuild your study plan, and aim for a 2–4 week restudy minimum.
  • Score review / appeals: ISC2 and ISACA offer formal appeal processes, but overturns are rare. CompTIA and GIAC do not typically offer appeals.
Remote vs. Test Center
  • Test center pros: No home setup worries, reliable hardware, familiar “exam feel,” whiteboard/scratch paper provided.
  • Test center cons: Travel time, scheduling constraints, potential noise from other test-takers.
  • Remote pros: Convenience, flexible scheduling, familiar environment.
  • Remote cons: Strict room requirements, internet dependency (disconnection can void exam), potential proctor delays, no scratch paper (digital whiteboard only).
  • Recommendation: If you’ve never taken a remote proctored exam, try your least important certification first to learn the process.
◆ ◆ ◆

Cost Summary

Exam fees, estimated training costs, and annual renewal. All prices approximate, 2025–2026. Costs may vary by region.

Exam fee, the two realistic ways to prepare, and what it costs to stay certified. Estimated total assumes the self-study route.
Certification Exam fee Self-study Official training Renewal Est. total
ISC2 6 certs
CISSP $749 · €690 $50–150 $2,500–3,500 $125/yr AMF $749+
CCSP $599 · €550 $50–100 $2,500–3,000 $125/yr AMF $599+
SSCP $249 · €230 $40–80 $1,500–2,500 $65/yr AMF $249+
CC $199 · €185 Free–$30 Free (ISC2) $50/yr AMF $199+
CGRC $599 · €550 $40–80 $2,000–3,000 $125/yr AMF $599+
CSSLP $599 · €550 $50–100 $2,500–3,000 $125/yr AMF $599+
ISACA 5 certs
CISA $760 · €700 $50–150 $800–1,200 $45–85/yr $760+
CISM $760 · €700 $50–150 $800–1,200 $45–85/yr $760+
CRISC $760 · €700 $50–100 $800–1,200 $45–85/yr $760+
CGEIT $760 · €700 $50–100 $800–1,200 $45–85/yr $760+
CDPSE $760 · €700 $50–100 $800–1,200 $45–85/yr $760+
CompTIA 4 certs
Security+ $404 · €375 $30–80 $350–500 $75/3yr CE $404+
CySA+ $404 · €375 $30–80 $350–500 $75/3yr CE $404+
PenTest+ $404 · €375 $30–80 $350–500 $75/3yr CE $404+
CASP+ $494 · €455 $40–80 $350–500 $75/3yr CE $494+
GIAC / SANS 10 certs
GSEC $949 · €875 N/A $7,000–9,000 $479/4yr $949+
GPEN $949 · €875 N/A $7,000–9,000 $479/4yr $949+
GCIH $949 · €875 N/A $7,000–9,000 $479/4yr $949+
GCIA $949 · €875 N/A $7,000–9,000 $479/4yr $949+
GCFA $949 · €875 N/A $7,000–9,000 $479/4yr $949+
GCFE $949 · €875 N/A $7,000–9,000 $479/4yr $949+
GREM $949 · €875 N/A $7,000–9,000 $479/4yr $949+
GWAPT $949 · €875 N/A $7,000–9,000 $479/4yr $949+
GFACT $949 · €875 N/A $3,000–5,000 $479/4yr $949+
GXPN $949 · €875 N/A $7,000–9,000 $479/4yr $949+
OffSec 6 certs
OSCP $1,749 · €1,610 Included $1,749 (bundle) None (lifetime) $1,749+
OSEP $1,749 · €1,610 Included $1,749 (bundle) None (lifetime) $1,749+
OSWE $1,749 · €1,610 Included $1,749 (bundle) None (lifetime) $1,749+
OSWP $799 · €735 Included $799 (bundle) None (lifetime) $799+
OSED $1,749 · €1,610 Included $1,749 (bundle) None (lifetime) $1,749+
OSDA $1,749 · €1,610 Included $1,749 (bundle) None (lifetime) $1,749+
EC-Council 2 certs
CEH $1,199 · €1,100 $50–100 $2,000–3,500 $80/yr $1,199+
CHFI $1,199 · €1,100 $50–100 $2,000–3,500 $80/yr $1,199+
INE / eLearnSecurity 2 certs
eJPT $249 · €230 Free–$50 $299–499 (INE) None/3yr $249+
eCPPT $400 · €370 Included $499+ (INE) None/3yr $400+
TCM Security 1 certs
PNPT $399 · €370 $30–100 $399 (bundle) None (lifetime) $399+
Cisco 2 certs
CyberOps Associate $330 · €305 $30–60 $300–500 Recertify/3yr $330+
CCNP Security $660 · €610 $50–100 $1,000–2,500 Recertify/3yr $660+
Cloud Vendors (AWS, Azure, GCP) 3 certs
AWS Security Specialty $300 · €275 $30–60 $300–600 Recertify/3yr $300+
AZ-500 $165 · €155 Free–$30 Free (MS Learn) Free renewal/yr $165+
GCP Security Engineer $200 · €185 $30–60 $300–600 Recertify/2yr $200+
Costs are approximate and may vary by region, membership status, and promotional pricing. GIAC exam-only pricing ($949) is available without SANS training, but the course is the primary study material. OffSec prices include course + labs + one exam attempt. ISACA member pricing is lower than non-member.
⚙ This page is informational only. No affiliate links here, no tracking, no data collection. Prices verified March 2026. The only referral links on this site live on the recommended services page, clearly labelled.