Updated by
Hi, I'm Jack, the owner of Cybersecurity Jobs List, and co-founder of Himalayas (himalayas.app) and Cavuno (cavuno.com). Across all my platforms, I work with application security daily: dependency vulnerability scanning, secure authentication, API security, and data protection across hundreds of thousands of users. My technical background is in computer science (UNSW), where he studied security engineering and computer networks, and worked as a research assistant on VR experiments that were published in the Journal of Experimental Psychology. I also work with cybersecurity hiring data every day, tracking which companies are posting, what certifications actually appear in listings, how salaries differ by sub-discipline and clearance level, and where the talent gaps are widest. That combination of security practice, engineering at scale, and daily immersion in the hiring data is what shapes the content on this site. I'm currently based in Sydney, Australia.

If you're new to cybersecurity and choosing between CompTIA Security+ and ISC2 Certified in Cybersecurity (CC), start with the gap you're trying to close. CC is a reasonable starting point when you need a structured introduction. Security+ may be the more direct choice when you already have IT foundations and the jobs you're targeting specifically ask for it.
You don't automatically need both. Before paying for either exam, compare the current objectives with what you know and check the wording in a few jobs you could realistically apply for.
Exam details and US prices checked on October 8, 2026. This comparison uses Security+ V7 (SY0-701) and the CC outline effective September 1, 2026. Prices, taxes and availability vary by region.
Security+ vs ISC2 CC at a glance
| Decision | ISC2 CC | CompTIA Security+ V7 |
|---|---|---|
| Who should consider it first? | Someone building security foundations, especially without prior IT experience. | Someone with IT foundations whose target roles or learning goals justify broader applied security study. |
| Experience guidance | ISC2 says no experience is required. | CompTIA recommends Network+ and two years in a security or systems administrator role. |
| Exam format | Adaptive exam with 100–125 items, including multiple-choice and advanced item types; two hours. | Up to 90 multiple-choice and performance-based questions; 90 minutes. |
| US exam price | $199, before the first $50 annual maintenance fee. | $439 for the standard exam voucher. |
| Keeping it current | 45 CPE credits over three years, plus annual maintenance fees. | Three-year renewal cycle; the CEU route requires 50 CEUs and a $150 total CE fee. |
The reader-fit recommendations are our judgment. Exam and experience details come from ISC2's CC page, its current exam outline and CompTIA's V7 page. Costs and renewal choices are explained below.
What will you actually learn?
Both cover security foundations, so you'll encounter shared ideas such as access control, risk and responding to incidents. The useful question is how much explanation and practice you need before those ideas make sense in a workplace.
The current CC outline groups learning into security principles, security governance, identity and access management, networking and cloud security, and security operations and incident response. It's a way to organize the vocabulary and concepts you keep encountering when you read security job descriptions.
Security+ V7 covers general security concepts; threats, vulnerabilities and mitigations; security architecture; security operations; and security program management and oversight. Its objectives include interpreting security data and applying controls. Performance-based questions mean preparation should go beyond recognizing definitions.
For example, knowing what multi-factor authentication means is a start. Explaining how you'd investigate an unexpected sign-in, which evidence you'd preserve and when you'd escalate it takes another kind of practice. Neither certificate, by itself, demonstrates that you've handled a real incident.
Which is harder if you're starting from scratch?
Our recommendation is to treat CC as the more approachable first learning structure if networking, operating systems and account permissions are all new to you. Security+ becomes a more sensible starting point when you can already explain those foundations and want to apply security concepts to them.
That isn't a promise that CC will be easy or that Security+ requires a particular number of study weeks. Use the objectives to make a three-column list: can explain, need to learn, need to practice. Put a topic in the first column only if you can explain it without reading a definition back.
The exam formats also need different preparation. ISC2's CC assessment is adaptive, and its exam FAQ says you cannot skip a question and return later. Security+ includes performance-based questions. Practice with legitimate materials that match the current format rather than relying entirely on vocabulary flashcards.
Compare the full cost, not just the voucher
At the time of checking, the US “Buy Now” section on CompTIA's Security+ V7 page lists the standard voucher at $439. ISC2 lists the US CC exam at $199.
For CC, passing the exam isn't the last step. After passing and completing the certification application, you'll pay the first $50 annual maintenance fee. That makes the standard US exam plus first maintenance payment $249, before any other costs. The fee then falls due annually on your certification anniversary, as explained in ISC2's FAQ.
Add training materials, any lab subscriptions you choose, taxes, travel and a possible retake to your own budget. CC currently requires an in-person test, so travel can matter if your nearest test center is far away. Check the actual appointment options before deciding that an exam is affordable.
Is ISC2 CC still free?
Not for new enrollments in the One Million CC program. ISC2 closed those enrollments on May 20, 2026. If you already received an unexpired exam code, ISC2 says you must schedule and sit the exam by December 31, 2026. An earlier expiry on your code still matters; the year-end deadline doesn't extend it. Check your account and the official program terms before budgeting around a free attempt.
A free exam code also doesn't remove the maintenance fee after certification. If an older comparison says “CC costs $0,” find out whether it means an eligible exam attempt, training access or the whole certification process.
What about renewal?
ISC2's member policy requires CC holders to earn 45 qualifying continuing professional education credits over a three-year cycle. Keep that commitment alongside the annual fee in your decision.
For Security+, the continuing education route requires 50 CEUs over three years. The $150 CE fee is the total for that cycle when renewing by uploading CEUs, not a mandatory $150 annual charge. Other renewal routes, including passing the latest exam, earning a qualifying higher-level certification or using CertMaster CE, don't carry that CE fee, although the activity itself may cost money.
Let your target jobs help you choose
A credential can be a hiring requirement, a preference or simply absent from a listing. Those aren't interchangeable. If a job explicitly requires Security+, don't assume CC satisfies it unless the employer says so. Equally, don't buy Security+ solely because a comparison page calls it the universal entry ticket.
Start with a small set of roles that fit your location, work eligibility and current experience. Read the employer's own listing, then copy this worksheet into your notes:
- Role and source: title, employer, source link and date checked.
- Certification wording: copy the exact requirement, including “preferred,” “or equivalent” or “within six months.”
- Other entry conditions: experience, work authorization, clearance, location and shifts.
- Skills I can demonstrate: specific work or project examples.
- Skills I still need: map these to the current exam objectives.
- Decision and budget: which credential helps, what it costs and what practical work comes next.
You can start with current cybersecurity job listings, then verify the requirements on the employer's application page. The goal is a decision about your own shortlist, not an invented percentage of employers who prefer one certificate.
A worked example: one budget, two possible choices
This is a fictional scenario to show how to use the worksheet, not a report about a real vacancy.
Maya works on a help desk, understands account permissions and basic networking, and has a $450 study-and-exam budget. One role on her hypothetical shortlist explicitly requires Security+. Another lists security knowledge as desirable but names no certification.
For the first role, a $439 Security+ voucher would leave only $11 before tax, materials, travel or a retake. CC's $199 exam plus first $50 maintenance fee would leave $201, but that saving wouldn't satisfy the named Security+ requirement. Maya needs to check whether she can fund preparation and meet the role's other conditions before booking.
For the second role, neither credential is an explicit entry condition. She could study the relevant objectives and build a useful work sample before deciding to pay for an exam. If her main gap is understanding basic security concepts, CC could give that study structure. If she's already comfortable with those concepts, buying a second foundation credential may add less than practicing the missing skill.
If your background resembles Maya's, our help-desk-to-cybersecurity guide can help you turn existing support work into evidence for an application.
Check the exam version before buying materials
There are two date-sensitive details to check in October 2026.
CC changed its outline on September 1, 2026. Match your course or question bank to the current outline. An older resource may still explain a concept well, but its domain list or practice format may no longer match your exam.
Security+ V7 is available now. CompTIA says V8 is expected on or around November 17, 2026. Its V7 page lists June 11, 2027 as the English exam's retirement date. Check the issuer page again before booking, especially if your study plan extends into next year or you're testing in another language.
You don't need to abandon suitable study materials just because a newer version is approaching. Choose a version you can prepare for and sit while it's available, and confirm that your voucher, course and appointment all match.
Do you need CC before Security+?
We wouldn't make paying for CC a default first step for everyone planning Security+. CompTIA's experience guidance is a recommendation for preparation, and it doesn't name CC as the preceding credential.
Taking both can make sense if CC helped you build foundations and a later role makes Security+ useful. But if you already have CC, pause before buying another course. Identify what the next exam would add to your target-role requirements or your knowledge. Overlapping study isn't automatically a better application.
Whichever path you choose, give yourself something practical to explain afterwards. Here's a small learning exercise: imagine an employee reports an unexpected sign-in. Write a one-page triage note separating the reported facts from assumptions, listing the logs you'd want, and explaining what would need approval before changing access. Use a fictional scenario or your own isolated lab, not an employer's live systems.
Then review the note for gaps. Did you jump from an alert to a conclusion? Did you record the time and scope? Could someone else follow your reasoning? This exercise isn't an exam-readiness test or proof of incident-response experience. It's a way to turn abstract study into a piece of work you can discuss honestly.
Our cybersecurity project guide has more examples of work you can document. Choose the certification that addresses a real gap, then make room for the practice that gives you something to say beyond its name.


