The short version: build IT fundamentals (networking, Linux, one scripting language), pass one respected entry cert — CompTIA Security+ or the free ISC2 CC — then create public proof of skill with TryHackMe, a home lab and writeups. Aim your first applications at SOC or GRC roles and plan for 12–24 months, not six weeks.
Two things about cybersecurity hiring are true at the same time, and almost every “get into cyber” video only tells you one of them. The first: the industry is genuinely short of people — ISC2’s workforce research has put the global gap around 4.8 million. The second: entry-level postings get buried in hundreds of applications, because a decade of “cyber is the future” content aimed everyone at the same junior SOC jobs.
Both are real, and the resolution is simple once someone says it out loud: the shortage is at the experienced level. Security is rarely a first job. It’s a second job that sits on top of IT, networking, development or audit. So the actual game isn’t “break into cybersecurity” — it’s “become slightly overqualified for the bottom rung, fast, and have the evidence in public.” That’s what this cybersecurity roadmap is: the version we’d hand a friend, with prices, timelines, and the parts people skip.
The roadmap at a glance
Stages 0–2 are universal. The lane is where people burn months dithering, so we’ll give you a blunt selector further down.
Stage 0 — the unsexy foundations
Nobody wants to hear this stage exists, which is exactly why interviews keep filtering on it. You cannot triage alerts about a network you don’t understand, and you can’t harden a Linux box you’ve never actually used. Concretely, foundations means four things:
- Networking — what actually happens between typing a domain and getting a page: DNS, TCP vs UDP, ports, NAT, TLS. Professor Messer’s free Network+ material covers all of it.
- Linux — comfortable in a shell, not expert. OverTheWire: Bandit teaches this as a game, and it’s free.
- One scripting language — Python or PowerShell. Enough to automate something small and ugly, not to pass a software interview.
- Windows in organizations — Active Directory basics. Most corporate breaches walk through AD, and most junior candidates have never seen a domain controller.
A genuinely good weekend project: rent a $5 VPS and work through our Linux VPS hardening checklist end to end. By the last step you’ve touched SSH, firewalls, log reading and brute-force traffic — real attack noise, on a box you own, for the price of a coffee.
If you’re starting from zero, months one through six live here. Yes, six. The people who skip this stage don’t skip the material — they just meet it later, in an interview, in front of a hiring manager.
Stage 1 — one certificate, not five
Cert-collecting is the most expensive way to procrastinate. At entry level, a certificate does exactly one job: it gets your CV past the HR filter and signals baseline vocabulary. One respected cert does that completely. A second entry cert adds almost nothing except the fee.
For most people the answer is CompTIA Security+ (SY0-701). It’s the default checkbox in job postings, it satisfies US DoD workforce requirements, and nearly every employer recognizes it. CompTIA raised the retail price to $439 as of June 2026, though authorized resellers sell vouchers for around $394. Two to three months of study alongside a job is the normal pace.
If the budget is zero, take the ISC2 Certified in Cybersecurity — the exam is free for your first attempt under ISC2’s one-million-certified program. It’s lighter than Security+ and carries less HR weight, but free is free, and it’s a legitimate cert from the CISSP people.
There’s also a newer option worth knowing about: TryHackMe’s SAL1 (Security Analyst Level 1), $349 including three months of THM premium, or $297 if you already subscribe. Unlike Security+, it’s not multiple choice trivia — the exam drops you into a 24-hour window with a SOC simulator and makes you actually triage alerts. It has far less HR recognition (it launched in 2025), so it doesn’t replace Security+; but as a second signal for SOC roles specifically, it proves the thing the interview is really about.
Side by side, the realistic first-cert options look like this:
| Cert | Cost | Format | HR recognition | Our take |
|---|---|---|---|---|
| Security+ (SY0-701) | $439 ($394 voucher) | Multiple choice + PBQs | The default checkbox | Get this one, for most people |
| ISC2 CC | Free (first attempt) | Multiple choice | Decent, growing | The zero-budget start |
| THM SAL1 | $349 w/ 3-mo premium | 24h practical, SOC simulator | Low but rising | Strong second signal for SOC roles |
| CEH | ~$1,199+ | Multiple choice | Some gov/HR filters | Skip unless a posting demands it |
CEH deserves the short version of the long rant: it shows up in some government-adjacent HR filters, but practitioners consistently rate it below its price tag. And OSCP is not a first cert, whatever YouTube thumbnails imply — it assumes exactly the fundamentals this roadmap spends a year building. It lives in stage 3.
Stage 2 — proof you can actually do something
Here’s the uncomfortable part: hiring managers know certificates prove you can pass a multiple-choice exam. When two hundred CVs all say “Security+”, the shortlist is decided by the thing most applicants don’t have — visible evidence you’ve done the work. The good news is that building it costs nearly nothing but time:
- A TryHackMe or Hack The Box profile with real mileage. A six-month streak and a decent rank says more about you than a weekend cram ever could, precisely because it can’t be faked quickly.
- Ten to fifteen writeups on a plain GitHub repo or blog. Not masterpieces — clear notes on what you tried, what failed, what worked. Recruiters click one; hiring managers read three.
- A small home lab. Old hardware or a cheap VPS running a SIEM like Wazuh or Security Onion, feeding it logs from your own machines, plus a document describing what you built and what it caught.
This stage doubles as a self-test. If three months of boxes and lab-building feels like misery, that’s cheap information — the day job includes a lot of exactly this.
Stage 3 — pick a lane
The four lanes in the diagram cover most real career paths, and the selector is less mysterious than people make it:
Blue team is where the entry jobs actually are. SOC analyst L1 is the classic first role — alert triage, log reading, shift work included. The ladder runs from SAL1 or CySA+ ($439 since CompTIA’s June 2026 price bump) through HTB’s CDSA toward incident response and detection engineering. If you want the shortest path to a security paycheck, it’s this one.
Red team is the lane everyone requests and the one with the fewest junior seats. Nobody hires a pentester without proof, so the route is eJPT (about $250) as a warm-up, then HTB’s CPTS, then OSCP — $1,749 for the 90-day course bundle, $2,749 for a year of access — when you need the HR-recognized stamp. Budget for OSCP like the serious purchase it is, and expect to enter via a SOC or IT role first anyway.
Cloud security is the fastest-growing and quietly the best paid at mid-career, because it’s the intersection of two shortages. AWS Solutions Architect Associate first — you can’t secure what you can’t build — then the AWS Security Specialty. If you already have sysadmin or DevOps history, this lane converts it at the best exchange rate.
GRC — governance, risk, compliance — is the underrated one. No deep technical bar, heavy on reading, writing and talking to auditors, and with NIS2 and ISO 27001 work everywhere in Europe, demand is steady. Career changers from audit, law and project management land here faster than anywhere else. ISO 27001 Lead Auditor or CISA is the ladder.
Where the TryHackMe and Hack The Box certs fit
The platforms you grind boxes on in stage 2 now run their own certifications, and they’ve quietly become the best value in the industry — with one asterisk we’ll get to.
On the blue side, TryHackMe’s SAL1 ($349 with three months of premium included) tests you in a live SOC simulator, and Hack The Box’s CDSA goes further: a multi-day practical exam where you investigate a full incident and write the report. The smart way to buy CDSA is HTB Academy’s Silver annual plan — $490 for the year including one exam voucher plus the training path, instead of stacking a $210 voucher on monthly fees.
On the red side, HTB’s CPTS is the one causing arguments. People who hold both routinely describe it as technically harder and more complete than OSCP: a 10-day exam against a realistic multi-host environment plus another 10 days for the report, versus OffSec’s famous 24-hour sprint. All-in it costs around $700 — under half of OSCP’s bundle. There’s also CBBH for the bug-bounty/web-app crowd on the same pricing model.
Now the asterisk: HR software doesn’t know any of this yet. Recruiters grep for “OSCP” because that’s what the job template says, and SAL1 has only existed since 2025. So treat these certs as what they are — proof of skill at a fraction of the price — and sequence them accordingly: THM/HTB certs to become good and show it, the legacy certs (Security+, OSCP) to get past the filters. If a hiring manager actually reads your CV, CPTS with a public writeup portfolio beats a bare OSCP. The problem is getting read. Doing CPTS first and adding OSCP later, once an employer might pay for it, is the sequence we’d pick today.
What the money actually looks like
Three honest footnotes before you anchor on those bars. They’re US averages — Western Europe generally runs lower, and averages include people with years of experience, so a first SOC offer will sit under that $90k bar, sometimes well under. Second, the jump from analyst to engineer is where compensation really moves, and that jump is powered by exactly the stage-2 skills, not by additional entry certs. Third, the CISO bar is there for trajectory, not planning — that’s a 15-to-20-year arc, and the total compensation ranges you see quoted ($400k+) are large-enterprise numbers.
The timeline nobody puts in the thumbnail
From absolute zero: 18 to 24 months to a security-titled role, and quite often the path runs through a helpdesk or junior sysadmin job first. That sideways step is not failure — it’s the standard route, and a year of real IT support experience answers interview questions no lab can. From an existing IT, dev or audit job: 6 to 12 months of evenings is realistic, and your current experience counts for more than you think — GRC in particular barely cares that your background says “project manager” if you can read a control framework.
While you’re studying, keep an eye on how the demand side is shifting: AI has eaten a chunk of the repetitive L1 triage work, which raises the bar slightly at the bottom while creating new work reviewing, tuning and securing the AI tooling itself. One more reason the “slightly overqualified” strategy wins.
What we’d skip
Five-figure bootcamps. The $10–15k programs teach material that exists free or nearly free (the entire stack in this post costs under $1,000 including Security+), and their job-placement statistics rarely survive close reading. Exceptions exist; verify outcomes independently before paying.
Cert stacking before the first job. Security+ plus CySA+ plus CEH plus three vendor badges on a CV with no hands-on evidence reads as “studies well, hasn’t done anything.” One HR cert, at most one practical cert in your lane, then spend the difference on lab time — the whole stack this post actually recommends (Security+ plus SAL1 or an HTB voucher year) lands under $1,000.
A master’s degree “to be safe.” Fine for some corporate and government tracks, but as an entry strategy it’s two years and real money spent polishing the credential that matters least at the technical entry level.
Waiting until you’re ready. Tutorial hell is real. The whole roadmap compresses to: learn a little, build a thing in public, repeat. Start the TryHackMe account this week, not after one more course.
The field rewards people who genuinely like taking systems apart to see how they fail. If that’s you, the 18 months go by fast — and you’ll have a stack of public evidence at the end that no flooded job board can ignore.
Frequently asked questions
Can I get into cybersecurity without a degree? Yes — people do it every month, usually via IT support, a recognized entry cert like Security+, and a public portfolio of hands-on work. A degree helps with some HR filters, but demonstrable skill plus a cert beats a degree with no hands-on work at most employers.
Which cybersecurity certification should I get first? For most people: CompTIA Security+ (SY0-701). It’s the default HR checkbox, DoD-recognized, and costs about $439. If budget is zero, the ISC2 Certified in Cybersecurity (CC) exam is free for your first attempt and covers similar fundamentals.
How long does it take to get into cybersecurity? From zero, plan on 18–24 months to a security-titled role, often with an IT support or sysadmin step in between. From an existing IT job, 6–12 months of focused study and portfolio work is realistic. Anyone promising six weeks is selling something.
Is cybersecurity oversaturated in 2026? At entry level, yes — junior postings get flooded. At the experienced level there’s still a real shortage; ISC2 estimates the global workforce gap in the millions. The winning move is to look overqualified for entry roles: cert plus visible hands-on proof.
Do I need to know how to code for cybersecurity? You need to read and script, not engineer software. One language — Python or PowerShell — used for automating small tasks covers most analyst work. GRC roles need even less; appsec and red team roles need more.
Is OSCP worth it as a first certification? No. OSCP is a specialization cert for the offensive path, it assumes solid fundamentals, and the course bundle starts around $1,749. Start with Security+ or ISC2 CC, build proof of work, and go after OSCP once you’ve chosen the red-team lane.
Are TryHackMe and Hack The Box certifications worth it? For skill, yes — THM’s SAL1 ($349) and HTB’s CDSA and CPTS (from $210, or $490 with a year of training) are practical exams that test real work, and CPTS is widely called technically harder than OSCP at half the price. Their weakness is HR recognition: use them to build and prove skill, and pair them with Security+ or OSCP to get past resume filters.
Sources: ISC2 workforce research; CompTIA Security+ pricing; OffSec PEN-200 pricing; TryHackMe certification pricing; HTB Academy pricing; StationX cybersecurity salary statistics; Kore1 2026 cybersecurity salary guide.