Not sure which certification to chase? Pick the role that fits where you are headed, then work the decks in order, look up the language as you go, and read the frameworks that the role lives in. Everything here is free and stays in your browser.
Foundations (start here)
Brand new to security, or switching in from IT? Build the vocabulary and the mental model first, then everything else gets easier. Start with fundamentals, then earn a broad entry certification.
SOC analyst & blue team
Detection, triage, and response: the people watching the alerts and running down incidents. Grow from the Security+ base into analyst and hands-on defensive certifications, with forensics for when things go wrong.
Governance, risk & compliance (GRC)
Audit, risk management, and the policies that hold a program together. This track is heavy on management certifications and on frameworks; the tools here (assessments, roadmap, the CMMC scorer) are the day job.
Cloud security
Securing workloads and identities across AWS, Azure, and GCP. Pair a broad base with the two vendor-neutral cloud certifications, and lean hard on identity and protocol fluency.
Offensive security & pentesting
Red team, ethical hacking, and hands-on penetration testing. This track runs from the survey-level certifications into the practical, exam-in-a-lab credentials, with attack and app-security vocabulary throughout.
Security leadership & management
The CISO track: strategy, risk in business terms, and running the program. Management certifications carry this path, and the frameworks and planning tools here are what leadership actually operates.
Certifications appear on more than one path on purpose: a CISSP serves both GRC and leadership, and Security+ underpins almost everything. Follow the path, not the exact order.