← CertOwl Blog

Security+

Security+ with no IT experience: a realistic starting map

By SunTzu, founder of CertOwl Published 6 min read

Quick answer

You can sit Security+ with zero IT experience because the exam has no formal prerequisites, and people pass from a standing start every month. CompTIA recommends the Network+ plus around two years of IT experience with a security focus, but that is guidance, not a gate. Plan a longer runway instead, 12 to 16 weeks from zero, and expect the job hunt afterwards to lean on projects and fundamentals rather than the certificate alone.

Formal prerequisites noneCompTIA recommendation Network+ and about two years of IT experienceRunway from zero 12 to 16 weeksExam up to 90 questions in 90 minutesPassing 750 of 900

The belief that you need years behind a help desk before you are allowed near Security+ has ended more cybersecurity careers than the exam ever has. It is also wrong on the facts. SY0-701 has no formal prerequisites: no required certification, no minimum job history, nothing to prove at registration beyond payment. People with no IT background pass it every month, and employers keep listing it as the baseline for entry security roles. What separates the ones who make it from the ones who stall is not permission. It is an accurate map of the distance they have to cover.

This guide is that map: what the exam expects, how long the road is from each starting point, the two gaps that sink most beginners, and what the certificate does and does not do for you on the other side.

What the exam expects, not who it expects

Security+ does not ask who you are. It asks what you can reason through. The format is up to 90 questions in 90 minutes, a mix of multiple choice and performance-based questions, with a passing score of 750 on a scale from 100 to 900. That works out to roughly 83 percent, though the scoring is weighted, so it does not map cleanly onto a raw percentage. The structure and domains are broken down in our SY0-701 exam guide.

There is one line in the official material that scares beginners off: CompTIA suggests candidates hold the Network+ and have around two years of IT experience with a security focus. Read that sentence as a description of the average candidate, not a rule about you. It exists so that the difficulty makes sense in context. The exam spans five domains, with Security Operations alone carrying 28 percent of the weight, and questions lean on scenarios rather than definitions: given this alert, this log, this architecture, what do you do next? Experience makes those scenarios feel familiar. Study can make them feel familiar too. It just takes longer, which is a planning problem, not a wall.

How much harder that makes the exam depends entirely on where you start, which is exactly what how hard is Security+ unpacks question type by question type.

Where you are starting from

Runway is the variable that matters. These are the bands we use across the blog, and they hold up against what test takers report:

Starting pointRealistic runwayWhat to do first
Zero IT background12 to 16 weeksBuild the networking vocabulary before touching security topics: ports, protocols, addressing
Help desk or support job8 to 12 weeksMap what you already do, tickets, resets, escalation, onto the exam's operations language
Self-taught tinkerer with a home lab8 to 12 weeksTurn informal knowledge into exam framing: you know how, now learn what CompTIA calls it
Degree or bootcamp, no IT job yet8 to 12 weeksFill the hands-on gap with labs, since theory alone falls apart on performance-based questions

Two things about that table. First, the from-zero band is wide because life is: an hour a day lands you near week 16, two focused hours near week 12. Second, the shorter bands assume real exposure, not job titles. A year of resetting passwords without ever asking why the policy exists counts for less than three months of curious lab work. The full week-by-week breakdown lives in how long to study for Security+.

The two gaps that sink beginners

Beginners rarely fail because security concepts are beyond them. They fail on the ground the recommendation took for granted. Two gaps do most of the damage.

The networking gap. Security+ is not a networking exam, but it speaks networking fluently and expects you to keep up. Segmentation, firewall placement, VPN types, port numbers in scenario answers: if TCP versus UDP is a coin flip for you, every one of those questions costs double time. From zero, spend your first two to three weeks purely on network fundamentals. It feels like a detour. It is the road.

The hands-on gap. The performance-based questions at the front of the exam simulate doing rather than knowing: ordering incident response steps, matching controls to scenarios, reading logs. Candidates who have never touched a terminal freeze here, burn twenty minutes, and wreck their pacing for the remaining questions. The fix costs nothing: a virtual machine, a few evenings with command line basics, and the habit of flagging PBQs and returning to them later, which we cover in the PBQ guide.

Close those two gaps and the rest of the syllabus is patient, steady memorisation and scenario practice, the same work everyone else is doing.

A plan that survives a day job

The from-zero plan compresses into four phases. Weeks one to three: networking fundamentals only, no security yet. Weeks four to nine: the five domains in order of exam weight, so Security Operations and Threats get the most attention, with daily review of everything already covered. Weeks ten to thirteen: practice questions in volume, wrong answers driving what you restudy. The final stretch: timed 90-question simulations until pacing feels automatic, then book the seat.

On money: the voucher costs $439 in 2026, and a failed attempt costs the same again, which is the strongest argument for letting practice scores rather than a calendar date decide when you sit. The complete cost picture, including retake rules and bundle options, is in the exam cost breakdown. A fixed exam date three to four months out does more for consistency than any study technique, so book it once your practice scores stabilise, not before.

What the pass gets you without experience

A clear-eyed view of the other side keeps motivation from collapsing later. The certificate does two concrete things: it gets your CV past automated filters that list Security+ as a requirement, and it satisfies the DoD 8140 baseline that many US defense and contractor roles demand. What it does not do is substitute for evidence that you can work. Hiring managers reading a no-experience CV look for the pairing: certificate plus something you built, a home lab writeup, a TryHackMe streak, a documented project.

Expectations on pay should be calibrated the same way. For first security roles in the US in 2026, entry SOC analyst offers average about $57,800, with most landing between $40,000 and $62,500 depending on state and shift. After roughly 18 to 24 months of reading real logs and handling real incidents, roles above $75,000 start to open. The role-by-role map is in Security+ jobs at entry level and the full salary picture, including which numbers on salary sites to ignore, is in the salary guide.

When Network+ first is the smarter move

There is a fork worth naming. If the networking gap feels less like a gap and more like a canyon, taking the Network+ first is a legitimate route: it turns the hardest part of Security+ into revision, and it gives you a certificate along the way instead of sixteen weeks with nothing to show. The trade is time and a second voucher. If your goal is a security role and your budget is tight, going straight at Security+ with a longer runway is the cheaper path, and it is the one most career changers take. Either way, the decision should be about your networking comfort, not about permission.

Test yourself: 3 quick questions

Which three attributes does CompTIA use to compare attackers?

Actors are compared by: internal vs external (are they inside the organization), resources/funding (how much money and tooling), and sophistication/capability (how technically advanced). This helps assess how serious a threat the actor is to you specifically.

What is the difference between phishing, vishing, and smishing?

All three have the same goal (manipulate a person) but a different channel: phishing goes by email, vishing by phone/voice, smishing by SMS/text. Recognizing the channel helps you stay alert.

What is the defense against SQL injection?

SQL injection occurs when an application blindly inserts user input into an SQL statement. The defense is parameterized queries (placeholders $1, $2) where the input is treated as data, not as part of the command. Never concatenate user input into an SQL string.

Score: · Hundreds more with explanations, free in the app: Get CertOwl on the App Store

Frequently asked questions

Can Security+ really be someone's first certification ever?

Yes. There is no rule against it and no hidden penalty at registration. The cost is carried in study time: the 12 to 16 week runway exists because you are learning IT fundamentals and security on top of each other.

Do employers care that I passed without work experience?

Employers treat the certificate as a filter, not a verdict. Passing without experience gets you into the same pile as everyone else with the badge; what moves you up the pile is demonstrable work, labs, writeups, and how you talk through scenarios in interviews.

Should I do A+ and Network+ first to be safe?

The full ladder is rarely necessary for a security goal. A+ makes sense if you want a support job as a stepping stone. Network+ first makes sense if networking is your weak point and budget allows. If you can commit to the longer runway, Security+ directly is the fastest route to the credential that security job listings name.

CertOwl teaches Security+ with bite-size daily lessons, spaced repetition flashcards, and original practice questions built from the SY0-701 objectives, including full 90-question timed simulations. A few focused minutes a day, on your phone, even offline. The A+ and Network+ tracks are completely free, and Security+ is part of CertOwl Pro, which starts with a seven day free trial.

Get CertOwl on the App Store

Free download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations

More CompTIA guides