Difficulty and ROI ratings are based on my own exam experience, preparation path, and what I personally got back from the investment. Someone in a different role or career stage may get a very different return.
ISC2
Certified Information Systems Security Professional (CISSP)
Issued Nov 13, 2024. Expires Nov 30, 2027.
My take: CISSP was a goal from day one in InfoSec. Its reputation is daunting, but the exam itself was not as tough as I expected. A domain-focused video course was extremely helpful for me, especially Thor Pedersen's material. My best advice is to zoom out and answer from a manager or executive perspective instead of staying locked into an analyst mindset.
Difficulty: 6/10 | Personal ROI: 10/10
View Credly badge
ISACA
Certified Information Security Manager (CISM)
Issued Feb 6, 2025. Expires Feb 2028.
My take: I took CISM immediately after CISSP because I expected meaningful domain overlap. In my experience, it was significantly harder. It leaned much more heavily into governance and risk, and it felt less forgiving than CISSP.
Difficulty: 8/10 | Personal ROI: 6/10
View Credly badge
CompTIA
CompTIA SecurityX ce Certification
Issued Jul 8, 2024. Expires Jul 8, 2027.
My take: SecurityX, formerly CASP+, was the end of the line for my CompTIA path and the last stepping stone from A+ toward CISSP. It was more focused on technology, standards, architecture, and engineering than CISSP or CISM. You still need judgment, but you stay more grounded in technical best practices.
Difficulty: 7/10 | Personal ROI: 4/10
View Credly badge
ISC2
Certified in Cybersecurity (CC)
Issued Feb 1, 2024. Expires Feb 28, 2027.
My take: I took CC mostly because it was free and gave me a low-risk look at ISC2 exams after only having experience with CompTIA. That experiment was useful: ISC2 did not let me go back to prior questions, so once I answered something it was locked in. The exam itself was very basic, around Security+ level or slightly easier. The downside is paying annual maintenance fees for a cert that few employers seem to ask about.
Difficulty: 3/10 | Personal ROI: 2/10
View Credly badge
Coursera
Google Cybersecurity Professional Certificate V2
Issued Sep 1, 2023. Does not expire on Credly.
My take: I took this Coursera program for the discounted Security+ voucher. Since I already had about five years in InfoSec, the material was extremely simple for me. For someone coming into the field cold, though, it is a strong introduction to foundational concepts. If you are already moderately seasoned, you probably will not get much from it.
Difficulty: 1/10 | Personal ROI: 6/10 for beginners, 2/10 for experienced practitioners
View Credly badge
CompTIA
CompTIA A+ ce Certification
Issued Jun 7, 2023. Expires Dec 19, 2029.
My take: A+ started my certification journey. I already had nearly five years of experience before taking it, but it was still arguably one of the harder exams I have taken because the scope is so broad. Even knowledgeable, seasoned professionals can get tripped up by how much ground it covers. Professor Messer was excellent for this one.
Difficulty: 6/10 | Personal ROI: 3/10
View Credly badge
CompTIA
CompTIA Network+ ce Certification
Issued Aug 28, 2023. Expires Dec 19, 2029.
My take: I studied for Network+ longer than any other CompTIA exam. You need a good grasp of network and routing protocols, cabling standards, and subnetting. It was not overly difficult in the end, but it is another mile-wide, inch-deep exam. Professor Messer was my recommendation here as well.
Difficulty: 5/10 | Personal ROI: 3/10
View Credly badge
CompTIA
CompTIA Security+ ce Certification
Issued Sep 25, 2023. Expires Dec 19, 2029.
My take: Security+ is the gold standard entry-level security cert. It opens doors for people trying to move into security from other technical or tech-adjacent roles. Know your common ports, secure versus insecure protocols, basic definitions, the CIA triad, and the general InfoSec loop around incident response, policy, and risk. Professor Messer is again a strong resource.
Difficulty: 5/10 | Personal ROI: 7/10
View Credly badge
CompTIA
CompTIA Cloud+ ce Certification
Issued Feb 24, 2024. Expires Feb 24, 2027.
My take: I took Cloud+ as part of a cheap beta opportunity and otherwise probably would not have pursued it. The exam was very easy and did not go deep. A foundational understanding of cloud technology was enough to pass in my experience.
Difficulty: 2/10 | Personal ROI: 2/10
View Credly badge
CompTIA
CompTIA CySA+ ce Certification
Issued Apr 19, 2024. Expires Jul 8, 2027.
My take: CySA+ has been my favorite cert so far and was extremely fun to study for. It gave a more in-depth look at incident response, risk management, and vulnerability assessment than CC or Security+. It also felt more aligned with the day-to-day work of someone in InfoSec than many other certs.
Difficulty: 4/10 | Personal ROI: 5/10
View Credly badge
CompTIA
CompTIA PenTest+ ce Certification
Issued Dec 19, 2023. Expires Dec 19, 2029.
My take: I worked on PenTest+ so I could take over some red team duties at my job at the time. In practice, it felt more like a vocabulary-heavy exam than a deep technical assessment. The ROI was low for me.
Difficulty: 3/10 | Personal ROI: 2/10
View Credly badge