Security+, CEH, CISSP, CISM, OSCP — the acronyms sound interchangeable, but they aren’t. They differ so much in target audience, entry requirements, exam format and maintenance costs that the wrong choice can easily cost you two years. This overview sorts the key certifications by what actually matters in practice.
The first question isn’t “which one”, but “can I even get in”
The biggest difference between providers is the entry requirement. That’s what you should sort by first.
Possible immediately, with no prerequisites: All CompTIA certifications and the OSCP. With CompTIA, experience guidance is explicitly a recommendation, never an admission requirement. OffSec’s OSCP has no prerequisites at all — difficulty is the only barrier.
Exam now, title later: With ISC2 (CISSP, CCSP) and ISACA (CISA, CISM, CRISC), work experience is not a requirement for sitting the exam, but for certification. You sit the exam, pass it, and with ISC2 you initially become an “Associate of ISC2” with six years to prove your experience. With ISACA, five years remain after passing the exam to apply for certification — but until then you may not use the title.
Approval before the exam: With EC-Council’s CEH, it’s the other way round and stricter. Without official training, you must first prove two years of relevant experience, plus a non-refundable application fee of 100 US dollars, with five to ten working days for processing. Anyone who attends the official training is automatically eligible to sit the exam.
The entry point: CompTIA Security+
The current code is SY0-701. A maximum of 90 questions in 90 minutes, with a pass mark of 750 out of 900. Valid for three years, renewable via 50 CEUs. Network+ and around two years of practical experience are recommended, but neither is required.
Security+ is the pragmatic entry point if you’re coming from IT support, systems administration or networking and want to move into security. Version 8 is in development, but with no officially published date. As things stand, SY0-701 will remain usable well into 2027 — there’s no reason to wait.
The analyst role: CompTIA CySA+
Here’s the most important update in this article: CS0-004 has been in effect since 23 June 2026. The previous version, CS0-003, will be withdrawn in English on 22 December 2026, with translated versions following in March 2027. Anyone starting to study now should go straight for the new version.
New in version 4 is a dedicated AI section (AI in the SOC, AI risks, AI governance), plus EPSS-based vulnerability prioritisation, SBOM and Zero Trust Network Access. Format: a maximum of 85 questions in 165 minutes. The target audience is SOC analysts, vulnerability analysts and threat intelligence analysts.
Offensive security: CEH, PenTest+ and OSCP
These three are frequently confused, even though they could hardly be more different.
CEH v13 from EC-Council is knowledge-based: 125 multiple-choice questions in four hours. There is also CEH Practical — 20 real-world tasks on a cyber range over six hours. Anyone who passes both earns the title CEH Master; there is no third exam for this. One detail for budget planning: the exam voucher costs different amounts depending on the delivery channel — considerably more via Pearson VUE than via EC-Council’s own testing centre.
CompTIA PenTest+ (PT0-003) sits in between: multiple choice plus hands-on tasks, 165 minutes, with no entry requirement.
OSCP from OffSec is the toughest exam in this selection: 23 hours 45 minutes of practical hacking, followed by 24 hours for documentation. Three individual machines worth 20 points each, plus an Active Directory set worth 40 points, with 70 out of 100 points needed to pass.
Since November 2024 there have been two titles: the OSCP never expires, the OSCP+ expires after three years. Anyone who passes the exam receives both automatically. If the Plus expires, the OSCP itself remains valid indefinitely. This puts into perspective the common claim that the OSCP has now become subject to maintenance — only the Plus is.
The management track: CISSP, CISM, CISA, CRISC
CISSP is explicitly not an entry-level certification. Five years of experience in at least two of eight domains, with one year replaceable through a degree or a recognised certification. Watch out with older prep books: since 2024 the exam has run with 100 to 150 adaptive questions in three hours — not 125 to 175 in four hours, as almost all German-language overviews still state.
CCSP is the cloud variant. An active CISSP replaces the entire experience requirement. Here too: an adaptive format has replaced the linear exam since October 2025, and a new Exam Content Outline has applied since 1 August 2026. Older prep materials simply describe the exam incorrectly.
CISM from ISACA is aimed at leaders in information security — management, not technology. This is the only certification in this selection with a firmly scheduled content change: a new Exam Content Outline applies from 3 November 2026. Anyone starting in autumn 2026 should consciously decide whether to sit the exam before or after that date — existing study material doesn’t cover the new content.
CISA is the classic for IT audit and assurance, in high demand in the Swiss banking, insurance and audit sectors. 150 questions in four hours, pass mark 450 on a scale of 200 to 800. Five years of experience, up to three years replaceable through credits.
CRISC requires the least experience in the ISACA portfolio, at three years — but the official site lists no credits for it at all. In that respect, CRISC is actually stricter than CISA.
What the certifications cost to maintain
This point is almost always overlooked in comparisons, but it makes a significant difference over ten years.
- CompTIA has no annual fee, just a one-off fee per three-year cycle — and it can be avoided entirely, for example via CertMaster CE or by passing a higher-level certification. In terms of maintenance, CompTIA is clearly the cheapest family.
- ISC2 charges an annual fee, but only once — regardless of how many ISC2 certifications you hold. Anyone with both CISSP and CCSP doesn’t pay twice. On top of that: 120 CPEs over three years for the CISSP, 90 for the CCSP.
- ISACA charges per certification, with a volume discount from the third one onwards. Anyone holding CISA, CISM and CRISC is almost always better off with an ISACA membership — it also noticeably reduces every exam fee.
- EC-Council charges an annual continuing education fee and requires 120 ECE credits per certification over three years, reported by 1 February each year.
- OffSec: zero maintenance for the OSCP, an annual fee only for the OSCP+.
The 2026 trend: AI security
All the major providers are currently building AI security certifications. CompTIA launched SecAI+ in February 2026, explicitly as a supplement to, not a replacement for, Security+ or CySA+. ISACA has AAISM (requires an active CISM or CISSP) and, since April 2026, AAIR for AI risk. EC-Council launched COASP for offensive AI security in March 2026. ISC2 is still in the definition phase, with a pilot exam planned for late 2026 and full availability expected in 2027.
For career planning, this means: these titles are add-ons, not starting points. The foundation remains Security+, CySA+ or CISSP.
A pragmatic recommendation
- Switching into security: Security+, then CySA+ (go straight for CS0-004).
- Heading towards pentesting: Security+, then PenTest+ or CEH as proof of knowledge, OSCP as proof of skill.
- Heading towards leadership: CISM or CISSP, depending on whether you lean more towards managing or more towards architecting.
- Heading towards audit and compliance: CISA, complemented by CRISC.
- Heading towards cloud: CCSP, ideally after the CISSP.
All information in this article comes from the official pages of the respective providers, as of August 2026. Exam fees and dates change; please check them before registering.
Not sure which path fits your profile? Give us a call and we’ll walk through it with you in ten minutes.