The Complete CompTIA Certification Path: From A+ to SecurityX

Your complete CompTIA certification path for 2026: which certs to earn and in what order, from A+ to SecurityX — and how each maps to real IT careers.

The first question most people ask isn't which CompTIA cert they need. It's which one to start with. Skip ahead if you already know the answer — for most people it's A+, unless you've already done IT work for a couple of years, in which case it's probably Network+ or Security+. The harder question is what comes next, and that's what most of this post is actually about.

CompTIA has 12 active certifications right now, and the comptia certification path through them is more deliberate than most career-change blogs make it sound. The certs are designed to stack. You don't grab them randomly — you climb them.

How the certifications stack

CompTIA groups its certs into five tracks: core, infrastructure, cybersecurity, data, and specialty. The labels are mostly marketing. What actually matters is the dependency chain underneath.

A+ is the foundation. Network+ assumes you understand how IT systems work. Security+ assumes you understand both. From Security+ you branch into CySA+ (defense), PenTest+ (offense), or CASP+ — which, by the way, was renamed SecurityX in 2024. Same exam content, same DoD recognition, but you'll see both names in job listings for the next few years and it confuses everyone.

The infrastructure branch (Server+, Linux+, Cloud+) builds on A+ and Network+ but doesn't require Security+. The data certs (DataSys+, DataX) sit mostly on their own. Project+ has no real lineage and no prerequisites.

One thing most people miss: passing a higher-tier cert renews the lower ones automatically. Earn Security+ and your A+ resets for another three years. Earn CySA+ and your Security+ resets. Climb the ladder and you're maintaining everything below with a single recert. This is one of the under-discussed reasons CompTIA's stacking model is more useful than collecting random vendor certs.

Starting from zero: why this is the entry-level path

If you have no IT background, the entry-level CompTIA career path exists for you specifically. Most people moving into IT don't have a CS degree or prior experience — CompTIA certification with no experience is the norm, not the exception.

Two things make it different from almost every other cert path. No prerequisites: Cisco, AWS, and Microsoft certs either require or quietly assume you're already in the industry; CompTIA doesn't. And it's vendor-neutral: you learn what a server is and how a network is structured, not one vendor's product, which is why government and DoD roles lean on CompTIA so heavily for entry-level hiring. Pass A+ and you can apply for help desk jobs. Pass Security+ and you meet the DoD 8140 baseline — filter USAJobs.gov by "Security+" and there are thousands of listings where that one cert is the qualifier.

The trifecta — why everyone keeps recommending it

If you've spent any time on r/CompTIA, you've heard the term "trifecta": A+, Network+, Security+. It became the default entry path to cybersecurity careers because the math worked — most SOC analyst, junior security engineer, and InfoSec analyst job postings either require Security+ or strongly prefer it, and the underlying knowledge from the other two shows up in the interview even when it's not on the job description.

Here's the part people get wrong about the trifecta: it's not really about collecting three credentials. It's about whether you actually have the knowledge those credentials represent. I've watched people drill A+ practice questions for a month, pass the exam, and then flame out on Network+ because they couldn't reason about subnetting from scratch. They had the cert. They didn't have the foundation. The trifecta works when you actually learn it. It doesn't work as a pattern-matching exercise.

A few patterns worth knowing:

If you have zero IT experience, start with A+. Don't be tempted to skip it because you built your own gaming PC. A+ tests a specific kind of structured troubleshooting reasoning that most hobbyists haven't formalized, and Network+ assumes you've internalized it. Going straight to Security+ with zero experience is technically allowed and practically a mistake — I've watched people try to memorize Security+ material without knowing what a switch or a subnet was, get stuck, and quit. A+ isn't an obstacle to Security+; it's the map that makes Security+ make sense.

A+ is also where career changers either build a real foundation or build the cracks that sink them later. The two exams cover a huge amount of ground at shallow depth, and that breadth feels like studying forever without getting anywhere — you're actually building the scaffolding everything else in IT hangs off. The six-step troubleshooting methodology shows up on both A+ exams and in every IT job you'll ever have; memorize it early and use it on your own computer when something breaks.

If you've been doing helpdesk for 2+ years, you can probably skip A+ entirely and go straight to Network+. Most hiring managers won't hold the missing A+ against you when your resume already shows the work. The deeper take on this trade-off is in the A+ vs Network+ post.

If you came from a NOC or networking background, you can sometimes jump straight to Security+. But take a Network+ practice exam first. The concepts will feel familiar, but CompTIA's question style isn't, and that catches a lot of experienced people off guard.

Picking your direction after the trifecta

This is where the path branches and where generic advice stops being useful. The right next cert depends entirely on what kind of role you actually want. Most people on this site are headed for security, so that track gets the most space.

The cybersecurity ladder: Security+ → CySA+ or PenTest+ → SecurityX

The CompTIA cybersecurity certification path is shorter than people think: Security+, then either CySA+ or PenTest+, then SecurityX (still "CASP+" in most job listings). Everything else CompTIA sells is either adjacent (Network+, Cloud+) or a specialized sidebar. Most people take 5–7 years to climb the whole thing, and the ones who move faster almost always have hands-on security work in their day job — not just study time.

Security+ is the floor. Typical roles: SOC analyst (Tier 1), security systems admin, junior security engineer, IT specialist with security duties, at roughly $65k–$95k depending on region and prior IT experience. The low end is "help desk person who just passed the exam"; the high end is "network admin of five years who finally moved into a security seat." Security+ doesn't make you a security professional. It gets you in the room.

The real fork is CySA+ vs PenTest+, and people get it wrong constantly — usually by deciding red team is obviously cooler, then spending two years running the same web app assessment for clients who barely read the report while the friend who "settled" for CySA+ is running incident response at a Fortune 500 and making $30k more. The cooler cert isn't always the better career.

CySA+ (blue team). Threat detection, behavioral analytics, vulnerability management, incident response. Titles: SOC analyst Tier 2–3, threat analyst, vulnerability analyst, incident responder. Roughly $80k–$115k. The defensive job market is enormous — every company with a SOC needs more people, and burnout keeps them hiring. The 2023 refresh leaned harder into cloud and detection engineering. Domain-level detail is in CySA+ vs Security+.

PenTest+ (red team). Authorized testing, exploitation, assessment, reporting. Titles: penetration tester, vulnerability assessor, red team operator, security consultant. Roughly $85k–$125k, with a higher ceiling once you're senior, especially in consulting. The trade-off: fewer positions, a tougher junior market, and less varied work than people expect — the interesting work (adversary emulation, physical testing) is senior-level, and there are maybe a few thousand of those jobs in the US. It's a meaningfully harder exam than Security+ (more on the PenTest+ difficulty jump), and honestly, the offensive security industry respects OSCP and eJPT more. PenTest+ is fine for HR filters, but if offensive work is the goal, plan on hands-on certs eventually.

If you have no idea which you'd prefer, pick CySA+ first — far more junior openings, and you can add PenTest+ later. Geography matters too: PenTest+ jobs concentrate in a few metros (DC, NYC, Bay Area) and remote consulting shops, while CySA+ roles are everywhere.

SecurityX (CASP+). The advanced technical cert for senior practitioners who want to stay hands-on rather than move into management. Security architect, senior security engineer, principal engineer — $110k–$150k+. The exam is performance-based: scenario-driven simulations where you're configuring, analyzing, and making architectural calls under time pressure, so people who ground through Security+ and CySA+ on question banks hit a wall. Plan on Security+ plus around 5 years of hands-on experience (or 6 with related IT) first. People who jump straight from Security+ to SecurityX "because they're experienced in IT" almost always fail the first attempt — CompTIA doesn't formally require CySA+ first, but the exam content punishes skipped rungs.

At the top you hit a choice that isn't really about CompTIA anymore. SecurityX keeps you technical. CISSP moves you toward strategy, risk, and management.

SecurityX (CASP+) CISSP
Format Performance-based, scenario labs Multiple-choice + CAT, business-focused
Audience Senior practitioners Security leaders and managers
Focus Architecture, engineering, implementation Governance, risk, policy, strategy
Experience ~5 yrs hands-on (or 6 with IT) 5 yrs in 2+ CISSP domains
Direction Stay technical Move to management

CISSP has more name recognition with HR and recruiters outside federal work; SecurityX is respected by technical managers who've taken it and well-recognized in DoD-adjacent roles. Many senior people eventually get both, but they don't point at the same jobs.

A realistic ladder timeline, assuming a day job with real security work: Security+ in years 0–2, CySA+ or PenTest+ in years 3–5, and SecurityX or CISSP at year 5–7+. Without that day job it takes longer — exams can't replace experience.

The other tracks

Cloud roles. This is where CompTIA gets weakest. Cloud+ is vendor-neutral, which sounds great in theory but means it doesn't carry the weight of AWS Solutions Architect or Azure Administrator in actual cloud hiring. If you're building a cloud career, get a vendor-specific cert first. (More on Cloud+'s actual market value here.)

Systems / infrastructure. Server+ and Linux+ are both solid. Linux+ in particular has become more relevant as Linux skills get baked into more job descriptions. A+ → Network+ → Linux+ is a reasonable infrastructure-focused trifecta variant if you're not chasing security roles.

Data work. DataSys+ and DataX are CompTIA's newest additions and still earning their reputation. If your employer asks for them, get them; otherwise vendor certs (Snowflake, Databricks, AWS data) probably move the needle more right now.

Project management. Project+ is fine, but PMP is the cert that actually drives PM hiring in IT. Project+ is a bridge for people who don't yet have the documented project hours PMP requires.

The 12 certs at a glance

The practitioner's-eye view. CompTIA's official exam objectives are exhaustive if you need every detail.

Track Cert What it is
Core A+ (Core 1 + Core 2) Two exams, both required. Hardware, OS, networking and security basics, troubleshooting. Roughly three months from a cold start.
Core ITF+ Pre-A+ for total beginners. Skip.
Infrastructure Network+ TCP/IP, routing, switching, wireless. Heavier on subnetting than people expect — needs lab time.
Infrastructure Server+ Server hardware, virtualization, storage. Less essential as infrastructure goes cloud-native.
Infrastructure Linux+ Linux admin, command line, scripting, hardening. Recently refreshed and harder than its old reputation.
Infrastructure Cloud+ Vendor-neutral cloud. A supplement to vendor certs, not a substitute.
Cybersecurity Security+ Threats, cryptography, IAM, architecture, incident response. Plan on 2–3 months even with prior exposure — full timeline here.
Cybersecurity CySA+ Defensive analyst work. See the ladder above.
Cybersecurity PenTest+ Pentest methodology, scoping, reporting. HR-filter value, not proof of hands-on skill.
Cybersecurity SecurityX (CASP+) Senior security architecture. Renamed in 2024; content and DoD recognition unchanged.
Data DataSys+ Data administration and databases. Newer, still building recognition.
Data DataX Data analytics and BI. Even newer — check your local job market first.
Specialty Project+ Entry-level IT project management; a bridge toward PMP.

DoD 8140 and the government track

If federal contracting or DoD work is even a vague possibility for you, the certification math gets simpler — and a lot more important. If you're already in a DoD IT or cyber role (active duty, reserve, civilian, or contractor), your career is tied to DoD 8140, and for most of those roles CompTIA Security+ matters more than all the other certs combined.

8570 to 8140. DoD 8140 superseded 8570.01-M, but the transition hasn't been clean. The 8140 Manual (2023) replaced the old IAT/IAM/IASAE categories with the DoD Cyber Workforce Framework, which maps certifications to specific work roles instead of broad tiers. In practice, plenty of command-level policies and job postings still say "IAT II" or "IAM I," the approved cert lists overlap heavily, and the baseline you need now depends on your specific work role. Before committing, pull up the DoD 8140 Qualification Matrix for your role — not the category, and not what your buddy got three years ago.

Why Security+ for military and DoD roles. Security+ maps to more DoD work roles than any other single CompTIA credential. It's the baseline for most IAT II positions under 8570 and a qualifying cert for a large number of 8140 roles, especially on the defensive and analyst side; in a cleared environment it's frequently the minimum credential to touch the network — not "preferred," minimum. Many contractors hire on condition that you earn it within 30, 60, or 90 days of start, so walking in already certified turns a conditional offer into a straight offer, sometimes at a higher rate. Realistically that's 6–10 weeks of steady daily study around operational duties, not two weeks of cramming; the Security+ week-by-week plan is a decent scaffold to adapt.

Where the rest of the lineup fits:

Cert Where it fits in DoD
A+ Entry-level IT support and help desk; IAT I-equivalent roles and technician pipelines. Often the cert that gets someone from a non-IT MOS into an IT job on base.
Network+ Network operations, telecom, infrastructure. Frequently bundled with Security+ for NetOps roles.
Security+ IAT II baseline and the broadest 8140 coverage. Get this first.
CySA+ Defensive Cyber Operations, SOC analyst, threat hunting. Harder and more hands-on than Security+ — not a first cert.
PenTest+ Red team and offensive cyber ops. Less commonly required than defensive certs.
SecurityX (CASP+) Senior engineer, architect, technical director. Most DoD listings still say CASP+. Budget three to four months minimum; Security+ knowledge won't carry you far.

Funding. Service members and DoD civilians paying for their own vouchers almost never have to. Tuition Assistance covers CompTIA exams and study materials across most branches when tied to a career development path — your Education Services Officer can pull up current policy in five minutes. COOL (each branch has its own portal) covers certs tied to your MOS, AFSC, or rate. Command-level professional development funds are the one most people miss — ask your supervisor or training NCO, especially about end-of-fiscal-year leftovers. Contractors: training is usually baked into the contract and often billable, so if your employer won't pay for a cert the contract requires, that's a flag.

Studying around operational tempo. The biggest reality is discontinuity — weeks where you can grind two hours a night and weeks where a field problem or deployment spin-up takes you offline entirely. Long timelines with short daily blocks beat short timelines with long blocks, because short blocks survive busy weeks. The service members I've seen pass while deployed used a mobile-first method — practice questions on a phone in the chow line or waiting for a vehicle — instead of waiting for a quiet hour that never came. Tell your chain of command before you're three weeks out so a good NCO can protect study time. Don't test within two weeks of returning from field or deployment; sleep debt has blown plenty of two-month study investments, and a fail costs around $400 plus a two-week eligibility reset. And people who let certs lapse during deployments pay for it later — continuing education credits are far cheaper than retesting from scratch.

Before you pick a cert: look up your specific work role in the 8140 matrix, verify with your supervisor or ESO which cert your command is tracking you for, default to Security+ if you have a choice, confirm funding before paying anything, and take a diagnostic before you build a plan. DoD requirements change slowly, so certs recognized today will almost certainly still be recognized five years out. If you're also weighing ISC2 certs for senior DoD roles, ISC2 and DoD 8140 covers that side.

How long the path actually takes

Honest answer: somewhere between 12 months and 4 years, depending on how aggressive you are and what you're starting with.

A reasonable timeline for someone working full-time with limited prior IT experience:

  • A+ — about 3 months
  • Network+ — about 3 months
  • Security+ — 2 to 3 months
  • One advanced cert (CySA+, PenTest+, Cloud+, etc.) — 3 to 4 months

That's roughly 12 to 15 months from zero to Security+ plus one specialization. Each additional advanced cert adds another 6 to 9 months.

The most successful career-changer version doesn't wait to finish the trifecta before applying. Months 1–3: pass A+. Months 3–4: start applying for help desk roles (entry-level postings often sit open 6–10 weeks) while studying Network+ in the background. Months 4–5: land the job and cut study hours in half while you adjust. Months 5–7: finish Network+ in evenings and weekends. Months 7–10: pass Security+ while working. Months 10–12: use experience plus the trifecta to move into a SOC analyst, junior sysadmin, or security admin role — often internally.

By month 10 you have a year of real IT work on your resume instead of just three certs, and if your employer offers tuition reimbursement, they just paid for two of them. "IT support technician, 6 months" outweighs another cert sitting next to it. Don't wait until you feel ready to apply — nobody does.

What's reachable at each stage:

After Common job titles Typical US salary
A+ Help desk, IT support tech, desktop support $35k–$50k
A+ + Network+ NOC tech, junior network admin, infrastructure support $45k–$60k
Full trifecta SOC analyst, junior sysadmin, security administrator $55k–$80k

These skew higher in major metros and DoD contracting, lower in rural areas and small shops. Much of the trifecta jump isn't Security+ magically unlocking a $70k role — by the time someone finishes all three, they've usually been working in IT for 6–12 months. Entry-level SOC jobs with just Security+ and no experience exist, but they're harder to land than forum posts suggest.

A few honest things about timelines:

People underestimate how much study time gets eaten by life. You'll have weeks where you put in 15 hours and weeks where you put in zero. Setting an exam date 90 days out and working backward is more effective than trying to study "consistently" without a deadline — vague timelines have a way of becoming permanent. Same for booking: if you've done 6–8 weeks of real prep and you're above 80% on full-length practice exams, book it. Waiting another month rarely moves the needle.

Failed exams are common and not the disaster they feel like. CompTIA exams are pass/fail, the failure doesn't go on your record, and most people who fail Security+ pass on the second attempt with another month of focused work on their weak domains.

The trifecta tends to compress as you go — A+ takes the longest because the foundations are new, and each cert after it goes faster because the study habits and concepts carry over. You can compress further without skipping rungs. Get hands-on at your current job even if security isn't in your title — ask to own patch management, the phishing simulation, or vulnerability scanning. Use your employer's cert budget; most IT employers reimburse relevant exams and a lot of people never ask. Build a home lab (VMs, a pfSense firewall, a Security Onion install) — near-zero cost, massive transfer into CySA+ and PenTest+. And stack exams while the material overlaps: CySA+ is much easier to knock out 6–9 months after Security+ than two years later.

Studying when you've never done this before

How career changers study is the single biggest reason people fail a first attempt. Passive study doesn't work. Forty hours of Professor Messer videos (genuinely great content) builds recognition, not recall — and the exam tests recall. People who fail A+ almost all followed the same approach: watch videos → read book → take one practice exam → panic → cram → sit the exam. The people who pass started practice questions in week 2, even while getting 40% wrong, because that's how you find out what you don't know while there's still time to fix it.

A reasonable study week from zero: read a chapter or watch the matching video segment (1–2 hours); 30–50 practice questions on that chapter (about an hour); review every wrong answer, plus the ones you got right for the wrong reason (30–60 minutes); and build or break something related to what you learned in a VirtualBox VM. Career changers who do that last step learn two to three times faster than people who only study on paper.

Take a full-length timed practice exam a week before you book — a full 90-question, 90-minute simulation, not a topic quiz. Below 80%, don't book yet. At 95%+ on the same bank you've been drilling, you're memorizing questions, not learning material — switch sources. People who skip full-length sims overestimate their readiness by 10–15 points and discover on question 30 that they can't pace.

And don't study in isolation — r/CompTIA's "just passed, here's what I used" threads and the free CompTIA Discord servers give you someone to ask when you're stuck. Most people who don't make it through the trifecta didn't fail the exams; they stopped studying around month 2 and never picked it back up.

What to actually do next

If you're starting from zero, the move isn't picking a study plan — it's figuring out where you actually stand. Most people overestimate how much they know about networking and underestimate how much they know about security, and that mismatch wrecks otherwise reasonable study plans.

Take a free CompTIA diagnostic before you commit to a track. LearnZapp's covers the core domains across the trifecta with no signup, and the per-domain breakdown will tell you in about 20 minutes whether A+, Network+, or Security+ is actually the right starting point for you — instead of going off what worked for someone else two years ago.

Take the free CompTIA diagnostic.

Contact Us

Have a question or feedback? We typically respond within 24 hours.

We'll reply to your email address. No spam, ever.