The CompTIA certification path, explained for 2026
By the founder of CertOwl • Published • 3 min read
Quick answer
The core CompTIA path is A+, then Network+, then Security+. After Security+ you specialize, with CySA+ for defensive analyst work or PenTest+ for offensive testing, and SecurityX sits at the top. No step is a formal prerequisite, so you join the ladder wherever your experience already puts you.
CompTIA draws its certifications as a ladder, and for once the marketing picture matches how hiring works. Each rung maps to a job level: support technician, network or systems admin, security analyst, senior specialist. What the picture does not tell you is what each rung costs, how the top half changed recently, and that nobody checks whether you climbed the rungs below. This is the whole path in one place.
The ladder at a glance
At the bottom sits Tech+, the old ITF+, a pre-career certificate for people still deciding whether IT is for them. Most job seekers skip it. The real path starts with the core three: A+ for IT support, Network+ for networking, Security+ for security fundamentals. Above them come the specialist certifications, CySA+ on the defensive side and PenTest+ on the offensive side, and at the top sits SecurityX, the expert level exam that used to be called CASP+.
One rule shapes everything else: none of these requires any of the others. CompTIA publishes recommended experience for each exam, but recommendations are not prerequisites. You can register for any rung tomorrow.
The core three
The A+ is the entry point for people coming from outside IT. It is two exams, 220-1201 and 220-1202, at about $274 each, so roughly $548 before study materials. It teaches hardware, operating systems and troubleshooting, and help desk postings ask for it by name.
Network+ (N10-009, $399) covers subnetting, routing, switching and wireless, the layer every later certification quietly assumes. Security+ (SY0-701, $439) is the most requested security certification in entry level postings and a formal requirement across US defense work, which we covered in our DoD 8140 guide.
Together the three run about $1,386 at list price, less through authorized resellers, and a motivated beginner can clear all three in roughly a year. Whether you need all three is a different question: our guide to picking your first CompTIA certification walks through who should start where, and who can skip a rung entirely.
After Security+: defense or offense
This is where the path forks. CySA+ is the blue team branch, aimed at SOC analyst and threat detection work: log analysis, incident response, vulnerability management. It moved to a new exam version, CS0-004, in June 2026, adding cloud and AI related coverage, and the voucher costs $439.
PenTest+ (PT0-003, also $439) is the red team branch: scoping, running and reporting penetration tests. Neither is better in the abstract. Defensive roles are far more numerous; offensive roles are more specialized and harder to land as a first security job. A useful side effect: passing either one renews your Security+ automatically, since a higher CompTIA exam renews everything below it.
The top rung: SecurityX
SecurityX (CAS-005, $509) is the expert level exam, renamed from CASP+ in CompTIA's rebrand of its advanced lineup. Unlike management focused certifications at this level, it stays technical: architecture, engineering and operations questions for people who still work hands-on. It is aimed at practitioners with years of security experience behind them, so it belongs at the end of a plan, not the start of one.
Join the ladder where you already stand
The most common mistake with this path is treating it as a queue you must enter at the back. If you already fix computers for a living, the A+ mostly certifies what you know. If you already hold a networking role, Security+ is a reasonable next exam. Paying $548 for a certification that will not change your job prospects is the failure mode to avoid, and every rung you skip is money kept. Our cost calculator adds up any combination you are considering, retakes included.
The reverse mistake exists too. Jumping to CySA+ or PenTest+ without the Security+ level fundamentals tends to end in an expensive retake, because the specialist exams assume that vocabulary on every page.
Test yourself: 3 quick questions
Why, in a mature awareness program, are users given targeted, role-based training instead of a single identical training for all employees?
Role-based training aligns content with the actual risks and duties of each group (developers on secure coding, finance on BEC fraud, etc.), making it more effective than generic training. It does not replace technical controls nor serve as a means of punishment.
A company stores and processes customers' payment card data. Which regulatory framework directly defines the security requirements for handling such data?
The correct answer is PCI DSS because it is the industry standard that directly prescribes controls for protecting cardholder data, for example encryption, network segmentation, and access control. HIPAA relates to health data, SOX to financial reporting of public companies, and GDPR to personal data of EU citizens, so none of them specifically target card data.
An organization forms a committee that meets regularly to review and approve proposed changes to IT systems before they are implemented in production. What is such a body called?
A CAB (Change Advisory Board) is a body that evaluates, prioritizes, and approves change requests as part of the change management process. A steering committee provides strategic direction, but does not approve individual technical changes.
Score: · Hundreds more with explanations, free in the app: Get CertOwl on the App Store
Frequently asked questions
Do I have to take CompTIA certifications in order?
No. The order is a recommendation, not a rule. Any exam is open to anyone, and employers see only what you passed, not what you skipped.
Does a higher certification renew the lower ones?
Yes. Passing a higher CompTIA exam, such as CySA+ after Security+, renews the lower certifications automatically under the continuing education program.
How long does the whole path take?
The core three take most beginners about a year combined. The specialist rungs usually come after a year or two in a real role, because their material leans on work experience.
CertOwl covers the core of this path in one app, and the A+ and Network+ tracks are completely free: bite-size daily lessons, spaced repetition flashcards, and original practice questions written from the published exam objectives. A few focused minutes a day, on your phone, even offline.
Get CertOwl on the App StoreFree download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations