CompTIA Certification Path: Which Order to Take Them (2026)

Search "which CompTIA cert should I get" and you'll find a dozen confident, contradictory answers. The reason is simple: there is no single right order — there's a right order for your goal. CompTIA's certifications form a stack, and the smart move is to climb the two or three rungs that lead toward the job you actually want, not to collect the whole set.
This guide lays out the full CompTIA map for 2026, the sequence most people should follow, and how to adjust it if you're aiming at help desk, networking, cybersecurity, or cloud. By the end you'll know exactly which exam to book first — and which ones you can safely skip.
The CompTIA stack, from foundational to advanced
CompTIA groups its certifications into tiers. You don't need every cert in a tier; think of them as options at each level of depth.
- Foundational — ITF+ and the newer Tech+. Absolute-beginner certs that prove you understand basic IT concepts. Optional for most career-changers; genuinely useful if you've never touched IT.
- Core — A+ (support/help desk), Network+ (networking), and Security+ (cybersecurity baseline). This is the backbone of the CompTIA path and where most careers are built.
- Infrastructure — Server+, Cloud+, and Linux+. For people running servers, cloud, and Linux systems.
- Cybersecurity — Security+, then CySA+ (defensive/SOC analyst), PenTest+ (offensive/pen testing), and SecurityX (the advanced practitioner cert, formerly CASP+).
- Additional — Data+ (data analytics) and Project+ (project management), which sit outside the main technical ladder.
The path most people should take
If you're new to IT and not yet sure of your specialism, the classic, employer-recognised sequence still holds up in 2026:
- A+ — proves you can support and troubleshoot devices, operating systems, and users. It's the standard ticket into help desk and desktop support, the roles most IT careers start in.
- Network+ — teaches how networks actually move data: IP addressing, routing, switching, and the vocabulary every higher cert assumes you already know.
- Security+ — the most in-demand baseline security certification, and the one that opens the most doors. It's approved under the U.S. DoD 8140 framework, which is why so many employers list it by name.
Get those three and you're qualified for a huge range of entry-to-mid IT roles. From there, you specialise.
Can you skip A+ or Network+?
Yes — and many people should. A+ is the most time-consuming Core cert (it's two exams, Core 1 and Core 2), and if you already work in IT or you're aiming straight at cybersecurity, its hardware-and-support focus may be more than you need. A common shortcut for security-bound candidates is to go Network+ → Security+ and skip A+ entirely, because Security+ leans on networking knowledge far more than on help-desk skills.
The honest rule: get A+ if you want a support job or you're brand new; skip it if you already have IT experience or you're going straight for security. Network+ is harder to skip — almost every security and cloud cert assumes you understand networking.
The certs at a glance
| Certification | Level | Best for | Rough study time |
|---|---|---|---|
| A+ | Core | Help desk, desktop support | 2–3 months |
| Network+ | Core | Network technician, NOC | 1–2 months |
| Security+ (SY0-701) | Core | Security analyst, any security-adjacent role | 1–2 months |
| CySA+ | Cyber (intermediate) | SOC analyst, threat detection (defence) | 2–3 months |
| PenTest+ | Cyber (intermediate) | Penetration tester (offence) | 2–3 months |
| SecurityX (ex-CASP+) | Cyber (advanced) | Security architect/engineer | 3–4 months |
| Cloud+ / Linux+ / Server+ | Infrastructure | Sysadmin, cloud, Linux roles | 1–3 months each |
Choose your path by goal
Help desk / general IT support
A+ → Network+. A+ gets you hired; Network+ gets you promoted out of the first tier. Add Security+ once you're working — every modern support role touches security.
Cybersecurity
(A+ optional) → Network+ → Security+ → CySA+ or PenTest+. Security+ is the non-negotiable baseline. Then pick your side: CySA+ if you want to defend (SOC, blue team), PenTest+ if you want to attack (pen testing, red team). SecurityX comes later, once you have experience. If you're weighing the intermediate options, see our comparisons of Security+ vs CySA+ and CySA+ vs CISA.
Networking
Network+ → then vendor certs (Cisco CCNA). Network+ is the vendor-neutral foundation; most networking careers then move to Cisco. Our Network+ vs CCNA guide covers which to take first.
Cloud / systems
A+ or Network+ → Linux+ and/or Cloud+ → a vendor cloud cert (AWS, Azure). CompTIA's infrastructure certs build the fundamentals; the vendor certs get you hired for a specific platform.
How long does the whole path take?
Studying part-time around a job, most people complete the A+ → Network+ → Security+ core in roughly six to nine months, then add a specialisation over the following few months. There's no prize for rushing: certifications you can't back up in an interview don't help. Study deliberately, practise with real exam-style questions, and only book the exam when you're consistently scoring well on practice tests.
Do CompTIA certifications expire?
Most of them, yes — and it changes how you should think about the path. The Core and higher certs (A+, Network+, Security+, CySA+, PenTest+, SecurityX) are valid for three years, then need renewing through CompTIA's Continuing Education (CE) program. You keep a cert active by earning Continuing Education Units (CEUs) — through training, higher exams, or approved activities — or by paying a renewal fee.
Here's the useful part: earning a higher cert automatically renews the lower ones beneath it. Pass Security+ and it renews your A+ and Network+ for another three years. That's another reason to treat the path as a ladder rather than a pile — climbing keeps the whole stack current with no extra admin. (ITF+/Tech+ foundational certs are for-life and don't expire.)
CompTIA vs vendor certifications — where each fits
CompTIA certs are vendor-neutral: they teach the concepts that apply everywhere, which is exactly what makes them a strong foundation and why so many job listings ask for them by name. Vendor certifications — Cisco (CCNA), Microsoft (Azure), AWS, Google Cloud — go deep on one platform and are what employers want once you're specialising in that platform's ecosystem.
The pattern that works: use CompTIA to build the fundamentals, then add the vendor cert for the platform your target job runs on. Network+ before CCNA. Security+ before a cloud-security specialisation. Cloud+ before AWS or Azure. The CompTIA cert makes the vendor material click faster, and together they make a far stronger résumé than either alone.
One certification at a time
The mistake that stalls more careers than any other is trying to plan all seven certs before booking the first one. Don't. Pick the single next rung — for most beginners that's A+ or, if you're security-bound, Network+ — and commit to it. Momentum from one pass beats a perfect five-year plan you never start.
When you're ready to test yourself, run through a free Security+ SY0-701 practice quiz to see where you stand, and read how to study for IT certification exams for a study method that actually sticks.
Ready to Practice?
Try our free exam simulator. No signup, no paywall, 100% private.