Skip to content
h4ckercademy
Back to the blog

Cybersecurity certifications: which one to choose in 2026

August 22, 20266 min read

It's the question I get most, and it's almost always framed wrong. There is no certification that's better than another: there's one that fits where you are, and others that are money thrown away if you take them too early.

Let's go in order.

The rule that settles 90% of the doubt

Always favour hands-on exams. Multiple-choice ones certify that you memorised a syllabus; practical ones certify that you can do the work. In a technical interview that difference shows within ten minutes, and the person interviewing you knows it.

And the second rule, which stings more: a certification doesn't replace practice, it certifies it. If you take it to learn, you'll fail. If you take it once you already know, it's an expensive formality that pays for itself.

Entry level

eJPT (INE Security)

The most sensible way in. A 48-hour hands-on exam against a lab, no trick questions. It covers recon, scanning, basic exploitation and pivoting.

  • Approximate price: in the region of $250-300 per attempt.
  • Who it's for: someone who has already solved a handful of easy machines and wants their first piece of paper.
  • The good: cheap, practical and respected as a first rung.
  • The bad: no report component, and the report is half the real job.

Before you consider it, you should be comfortable in a terminal and with Nmap. The Kali Linux course covers exactly that prior level, and it's free.

CompTIA Security+

Not offensive and it won't teach you to attack anything, but it's the one that appears most often as a requirement at large companies, banks and public administration. Multiple choice.

  • Approximate price: around €400.
  • Who it's for: anyone aiming at a SOC or a company with a large HR department.
  • The bad: as offensive technical validation, zero.

Intermediate

PNPT (TCM Security)

My recommendation if you're only going to take one at this level. A five-day exam against a full Active Directory plus the delivery of a professional report, followed by a live debrief with an assessor.

  • Approximate price: around $400-500 with the courses included.
  • Who it's for: anyone who wants a certification that resembles a real engagement.
  • The good: the report and the debrief. It's the closest thing to actual work at this price.
  • The bad: less recognised by HR than the OSCP, though well respected among technical people.

CPTS (Hack The Box)

Very demanding for what it costs, and the study material is excellent. A ten-day exam that also requires a report.

  • Approximate price: the exam is around €500, with the material separate by subscription.
  • Who it's for: someone who already lives on HTB and wants to turn those hours into a credential.
  • The good: the syllabus is probably the best on this list.

If you come from that platform, the Hack The Box course gives you a systematic method for solving machines instead of trying things at random.

High level

OSCP (OffSec)

Still the benchmark in Spain. 24 hours of exam against a lab with Active Directory, plus 24 hours to deliver the report. If you don't deliver the report you fail, even having compromised everything.

  • Approximate price: from about $1,600 for the basic package, considerably more for extended lab options.
  • Who it's for: someone who already solves medium machines without looking at the solution.
  • The good: it's the one that opens doors. Plenty of job ads name it.
  • The bad: the price, and the fact that its reputation has created the idea that without it you're nobody. That isn't true.

CEH (EC-Council)

The best known outside the industry and the worst regarded inside it. Multiple choice, broad and shallow syllabus, high price.

  • Approximate price: above €1,000.
  • Who it's for: if a public tender or a client demands it by name, you take it and move on. Otherwise there are better options for less money.

The order that makes sense

  1. Learn and practise until you can solve easy machines unaided.
  2. eJPT or PNPT, depending on budget and urgency.
  3. Work for a year. You'll learn more there than in any syllabus.
  4. OSCP when your employer pays for it, or when the salary jump justifies it.
  5. Specialise after that: cloud, advanced Active Directory, hardware, mobile.

What does not make sense is starting with the OSCP because it's the famous one. You spend $1,600 failing something you weren't ready for.

What's worth as much as a certification

And I'm not making this up: on technical teams it weighs the same or more.

  • A repository of your own write-ups. Ten machines documented well say more about you than any PDF.
  • Published tooling. Even small things. A script that automates something that used to hurt shows you understood the problem.
  • Bug bounty findings, even low severity ones.
  • Course certificates with a deliverable. At h4ckercademy every completed course issues a verifiable certificate with a public code anyone can check. It doesn't replace an OSCP, but it evidences hours and specific content, and on a junior CV it adds up.

What it all costs, in summary

CertificationApprox. priceFormatReport
eJPT$250-300Hands-on, 48 hNo
Security+~€400Multiple choiceNo
PNPT$400-500Hands-on, 5 daysYes
CPTS~€500 + materialHands-on, 10 daysYes
OSCPfrom ~$1,600Hands-on, 24 hYes
CEH>€1,000Multiple choiceNo

Prices change every year and move with promotions and exchange rates: treat them as orders of magnitude and confirm on the vendor's site before paying.

So which one do I start with?

If you're in a hurry and short on budget, eJPT. If you can wait three more months and want something that resembles real work, PNPT. And if you can't yet solve easy machines on your own, none of them yet: practice first.

Start there. The free Kali Linux course takes you from an empty lab to your first documented audit, which is exactly the level you need before paying for your first exam. And for the full map of the road, see how to become an ethical hacker from scratch.

Carry on here

The course this article leads into

Frequently asked questions

What is the best cybersecurity certification to start with?

The eJPT if you want something affordable and hands-on, or the PNPT if you'd rather take one certification that already includes writing the report. Both are practical exams, which is what actually validates you to an employer.

Is the OSCP still worth it?

Yes, it still carries the most weight on a pentesting CV in Spain. But it's expensive and hard, so it makes sense once you already solve medium-difficulty machines unaided — not as a first certification.

Is the CEH worth anything?

It's useful for getting past HR filters and for public tenders that require it by name. As technical validation it's worth considerably less than any hands-on exam, and it costs more.

Can I get a job with no certifications at all?

Yes. What you can't do is get one with no evidence. A repository of your own write-ups, published tooling and solved machines does the same job, and on technical teams it's usually valued more.

#certifications#ethical hacking#pentesting#career

Keep reading

h4ckercademy

The whole catalogue on one subscription

A single monthly or yearly payment and access to every course, the current ones and whatever comes next.

See pricing