The consensus on certifications flipped a while back.
Somewhere between the bootcamp boom and the current job market, the default position became that they are paper. Nobody checks. The industry sells hope to people who cannot get hired. Build a homelab instead, contribute to an open source project, skip the exam. That take shows up several times a week in every security feed, and it collects agreement every time, because it asks nothing of the reader and confirms something they already suspected.
Say something positive about a credential in that environment and you are the one arguing against the room.
So here is the argument against the room, followed by the part that actually helps: where to start, what each credential is good for, and what changed this year.
Certifications are not badges. The serious ones represent months of unpaid evenings, sustained technical work under conditions designed to break you, and in several cases years of verified experience that somebody else had to attest to by name. The people dismissing them are usually describing the weakest products in the category and applying that description to all of them. That is not analysis. It is a rhetorical shortcut, and it has cost a lot of people opportunities they were qualified for.
What the serious ones actually ask of you#
Consider a practical offensive exam. The OSCP runs 23 hours and 45 minutes of hands-on exploitation, followed by 24 hours to produce the report, with 70 of 100 points required to pass. The Active Directory set is mandatory, worth 40 points, and bonus points were removed. The arithmetic is unforgiving. Without compromising the full AD chain, the three standalone machines cap you at 60 points, below the threshold. The exam is proctored with identity and environment checks, tool restrictions, and a documented prohibition on AI assistance.
That is two consecutive days of sustained technical execution under observation, ending in a written deliverable that mirrors what a client actually reads after an engagement. OffSec does not publish pass rates, but community reporting puts first-attempt failure high enough that most people who sit it do not clear it the first time. Behind each one who does are typically three to six months of evenings and weekends, unpaid, on top of a full-time job.
The reporting requirement deserves particular attention, because it is the piece most often dismissed as busywork. Writing a clear, defensible, technically accurate report under a deadline is the single most transferable skill in offensive security, and it is the one most practitioners are weakest at. An exam that fails you for a bad report is measuring something real.
The governance side is demanding in a different direction. CISSP requires five years of cumulative paid full-time experience across at least two of the eight domains, verified through an endorsement process before the certification is issued. Endorsement must be completed within nine months by an active member in good standing. You cannot study your way past that. The credential encodes years of work that a peer was willing to attach their name to.
What four credentials did for one career#
I started with an MCSE. At the time it was the credential that got a systems administrator taken seriously, and preparing for it taught me Active Directory, Windows internals, and networking at a depth I would not have reached on my own. Microsoft retired that certification years ago. The badge is gone. The knowledge is still the foundation everything since has been built on.
From there I moved into security through the CEH, which opened the door to security-specific roles that were not going to interview a systems engineer without something on paper. Then the CISSP, which was the one that changed the shape of my career. The CISSP is what opened the door to the assessment work that followed, which is where I learned how often a credential is a contract term rather than a preference.
Four credentials, roughly two decades. At three separate points, a piece of paper was the difference between being considered and being filtered. At every point, the preparation made me better at the work.
That second part is what gets lost in the current discourse. The exam is a sample. The months of preparation are the substance, and nobody hands those back when the credential retires.
The gate is real, and in places it is written down#
There is a reason the dismissive take comes so often from people already inside. They were hired in a different labor market, frequently through a personal referral, and are now senior enough that their work history speaks for itself. That is advice about whether a gate exists, delivered by someone standing on the far side of it.
In several parts of this industry the gate is not a hiring preference at all. Government and defense work runs against approved credential lists. Consulting and assessment engagements name specific certifications in the statement of work, which means a firm cannot staff you to that engagement regardless of how capable you are. Managed service providers use credential counts to qualify for partner tiers. In those contexts the credential is a contractual line item, and no amount of homelab work substitutes for it.
The asymmetry in who absorbs the cost of bad advice is stark. Someone who tells ten thousand people to skip the certification faces nothing when three hundred of them stall at the resume screen. The reader carries that alone.
That said, the market is not clean. There are credentials sustained by brand recognition long after the content stopped describing the work. Braindump sites have hollowed out the signal value of more than one multiple-choice exam. Four-figure training packages get sold around exams that cost a fraction of that, on the implication that the course is required when it usually is not. Take those criticisms seriously, because they are exactly why choosing carefully matters. The answer is not to write off the category. It is to know which product you are buying.
Start here: the credentials that get you read#
Before role specialization, there is a baseline problem to solve. Automated screening filters on keywords, and a resume with no recognized credential frequently does not reach a human. These are the ones that fix that.
CompTIA Security+. The default entry signal, and still the most efficient one. It is vendor-neutral, widely recognized by both commercial and government employers, and remains on the ISC2 experience waiver list after the 2026 revision. If you are coming from help desk, systems administration, or networking, this is the credential that gets your resume read rather than discarded. Nobody will be impressed by it. That is not its job.
ISC2 Certified in Cybersecurity. An entry-level option for people with no professional background at all, useful mainly as proof of seriousness before you have anything else. Less recognized by hiring managers than Security+, so treat it as a stepping stone rather than a destination.
Network+ or CCNA. Worth considering if your networking fundamentals are genuinely weak. Most security work eventually reduces to understanding what traffic should look like, and people who skipped this layer tend to hit a ceiling later. CCNA carries more weight than Network+ and takes considerably longer.
If you have infrastructure experience already, go straight to Security+ and skip the rest of this section. If you are changing careers with no technical background, expect this stage to take six months and treat it as the foundation rather than the goal.
Then pick by where you are headed#
Defender and security operations. After Security+, CySA+ moves you toward analysis and triage rather than theory. Microsoft SC-200 is the stronger choice if the environment you are targeting runs on the Microsoft security stack, which a large share of mid-market organizations do. Beyond that, GIAC’s incident response and forensics credentials carry the most weight with practitioners and hiring managers, and they are the ones people actually respect in a SOC. They are also expensive, and the price is driven by the training package rather than the exam. If an employer is not paying, look at the exam-only pricing before assuming it is out of reach.
Penetration testing and offensive work. OSCP remains the credential that clears the resume screen at consulting firms, MSSPs, and enterprise red teams. Treat it as a floor for senior offensive work rather than a ceiling. It also assumes competence you need before you start, specifically the ability to enumerate a Linux host and move laterally without a script doing it for you. If you do not have that, build it somewhere cheaper first. Practical alternatives from smaller training providers have gained real traction with mid-size firms and cost substantially less, though they do not yet clear the same automated filters.
Security engineering and cloud. Match the platform your employer actually runs. This is the one track where reputation matters less than environment fit, because the work is implementation and the implementation is platform-specific. The vendor tracks also move fastest, which makes retirement schedules a live concern rather than a footnote.
Management, architecture, and governance. CISSP is the breadth credential and the one that most reliably changes what roles you are considered for. CISM is the better fit if you are specifically heading toward security leadership rather than architecture. CISA remains the recognized audit credential. CGRC covers authorization and control frameworks. This track rewards accumulated experience more visibly than the others, and the credentials hold value longer because the underlying frameworks move slowly.
If you want the two that open the most doors regardless of direction: Security+ early, CISSP once the experience is behind you. Everything else is optimization.
What changed in 2026#
Route advice from experienced people needs checking, including mine.
ISC2 revised the CISSP exam experience waiver list effective April 1, 2026. To stay on the list, a certification must have a publicly available exam outline, hold ANAB ISO/IEC 17024 accreditation or come from a reputable organization with a proctored exam, and align at least 90 percent with two or more CISSP domains. Certifications that did not meet those standards were removed.
Reporting on the revision indicates the surviving list retained the CompTIA track, the ISC2 portfolio, CISM, several Cisco and cloud provider credentials, and the Microsoft Cybersecurity Architect credential. Among those reported removed are CEH, CISA, CRISC, OSCP, and the majority of GIAC certifications.
The CEH was my own bridge from infrastructure into security. It no longer buys the waiver year it once did. A path that worked is not the same as a path that still works.
The same instability shows on the offensive side. Since November 1, 2024, passing the OSCP exam awards both OSCP and OSCP+. The base OSCP remains lifetime. OSCP+ expires three years from issuance and is maintained through a recertification exam, another qualifying OffSec certification, or the CPE program. The credential a hiring manager screens for and the credential that expires are now two different things carrying the same name.
The vendor tracks move faster still. Microsoft’s role-based certifications run in six lanes, priced per exam and renewed annually through Microsoft Learn, and 2026 brought the largest overhaul since the move to role-based credentials in 2019.
My MCSE took roughly twenty years to become obsolete. Its modern counterpart has a retirement date measured in months, published in advance on a schedule anyone can read. That is not a reason to skip it. It is a reason to read the schedule before you spend.
If you feel behind on AI, the numbers say otherwise#
There is a version of career anxiety specific to this moment, which is the sense that the AI shift already happened and you missed it. The data does not support that feeling.
A Federal Reserve analysis published in April 2026 found that roughly 18 percent of US firms had adopted AI as of year-end 2025, drawing on Census Bureau business survey data. Work-related generative AI use reported by individuals sat at about 41 percent as of November, with the strongest growth in the most recent quarter measured.
Read those two numbers together. Individual adoption is running well ahead of organizational adoption, which means most of the AI use in this industry is people figuring it out on their own, inside companies that have not formalized anything yet.
The agent layer is earlier still. In the most recent Stack Overflow developer survey, 52 percent of developers either do not use agents at all or stay with simpler AI tools, and 38 percent report no plans to adopt them.
That is not a closed race. That is the second lap.
None of which means the technology is a passing thing. Adoption of AI coding tools reached a record 84 percent in that same survey, and the tools have settled into workflows the way version control and linters did, used because the work demands it rather than because anyone is excited. It is infrastructure now. It is not going anywhere, and the useful posture is neither panic nor dismissal.
Here is the part that matters for anyone with an infrastructure background.
The barrier these tools removed is syntax. Writing correct code in an unfamiliar language used to be a real gate, and it kept a lot of capable systems people out of work they could otherwise have done. That gate is largely gone. What it did not remove, and what it has arguably made more valuable, is knowing what the code should do.
The single most common developer frustration in that survey, cited by 66 percent of respondents, is AI output that is almost right but not quite. Only 3 percent report highly trusting AI-generated code. Review time is climbing relative to authoring time across multiple industry surveys.
Review is the bottleneck. And reviewing generated code well is not primarily a language skill. It is asking whether this will hold up under load, whether the error handling is real or decorative, whether that dependency should be trusted, what happens when the network is slow, and where the credentials are coming from. Those questions come from having run systems, not from having written syntax.
If you administered servers, understand how networks actually behave, and can write enough scripting to be dangerous, you already hold the part these tools do not supply. The gap between a systems person and a software engineer narrowed considerably in the last two years, and it narrowed from the direction that favors you. The mental model is the asset. The implementation was always the commodity, and now it is priced like one.
That is also why the certification argument and the AI argument are the same argument. What the preparation builds is judgment. Judgment is the thing that has appreciated.
Sequencing, which is where most of the money gets wasted#
The most common expensive mistake is buying the senior credential before the experience exists to support it. People pass the CISSP exam, discover they cannot be endorsed for another three years, and spend that time holding an associate designation while paying maintenance fees. That is not a failure of the credential. It is a sequencing error.
A workable order looks like this. Establish the baseline that clears automated screens. Add the role-specific credential matching the work you are doing right now, not the work you want in five years. Let experience accumulate. Then take the senior credential when the endorsement is a formality rather than an obstacle.
Treat every certification as a decision with two columns. What does the preparation teach me, and what door does the paper open. If a credential scores well on only one of those, it may still be worth buying. If it scores well on neither, no amount of brand recognition fixes that.
The critics have the shelf life right. Credentials expire, get retired, and fall off approved lists, and anyone selling you permanence is not being straight with you. Where they go wrong is the conclusion. The good ones are difficult enough that finishing them changes what you can do, and that difficulty is precisely why the market reads them as a signal at all.
Pick the ones where the preparation maps to work you actually want to be doing. Then the credential is a byproduct of getting better rather than a substitute for it.
