For most complete beginners, CompTIA Security+ is the better first certification: it has no eligibility hurdle, covers the broad foundations every security job uses, and maps directly to entry-level defensive roles. CEH (Certified Ethical Hacker, from EC-Council) makes more sense as a second step for someone who already has some IT or security experience and knows they want offensive work, or whose target employers specifically ask for it.
That’s the short answer. The rest of this post explains why, fairly, because both certifications have real strengths and both have critics.
Security+ and CEH at a glance
| CompTIA Security+ | EC-Council CEH | |
|---|---|---|
| Current version | SY0-701 (a new version is expected; see below) | CEH, currently branded “CEH AI” (v13) |
| Focus | Broad security foundations, mostly defensive | Offensive techniques and attacker methodology |
| Eligibility | None required (CompTIA recommends prior networking knowledge) | Official EC-Council training, or two years' information security experience via an eligibility application |
| Core exam | Up to 90 questions, 90 minutes, multiple choice and performance-based | 125 multiple-choice questions, 4 hours |
| Practical exam | Performance-based questions within the main exam | Separate, optional CEH Practical: 6 hours, 20 challenges in a cyber range |
| Pass mark | 750 on a 100–900 scale | Varies by question bank (EC-Council quotes 60% to 85%) |
| Typical first job it supports | SOC analyst, security administrator, IT roles with security duties | Junior penetration tester, vulnerability assessment, red-team-adjacent roles |
Sources: CompTIA Security+ and EC-Council CEH. Prices change and vary by country, so check each official page for current fees rather than trusting a figure in a blog post.
What does Security+ actually test?
Security+ SY0-701 is built around five domains:
| Domain | Weighting |
|---|---|
| General Security Concepts | 12% |
| Threats, Vulnerabilities & Mitigations | 22% |
| Security Architecture | 18% |
| Security Operations | 28% |
| Security Program Management & Oversight | 20% |
A timing note: CompTIA says the next version of Security+ is expected to launch on or around 17 November 2026. SY0-701 is still available, and CompTIA hasn’t confirmed its retirement date, so check CompTIA’s Security+ page for the current exam version before you book.
Notice that Security Operations is the biggest slice. Security+ wants you to understand how an organisation runs security day to day: hardening, identity and access management, vulnerability management, monitoring, incident response, and the governance that sits above it. Attacks appear, but mainly so you can recognise and mitigate them.
The exam includes performance-based questions, small simulations where you configure or analyse something rather than pick from four options. That makes it more than a vocabulary test, though it’s still not a full hands-on lab exam.
Our Security+ SY0-701 study guide breaks each domain into a study plan.
What does CEH actually test?
CEH is organised around the attacker’s process: reconnaissance and footprinting, scanning and enumeration, vulnerability analysis, system hacking, malware, sniffing, social engineering, denial of service, session hijacking, web application and wireless attacks, mobile, IoT and cloud, and cryptography. EC-Council describes the current programme as 20 modules, and the latest version adds AI-assisted techniques throughout.
There are two exams:
- The CEH knowledge exam (125 multiple-choice questions, 4 hours) earns the CEH certification.
- The CEH Practical (6 hours, 20 challenges in EC-Council’s cyber range) is optional. Pass both and you hold CEH Master.
This distinction matters in any fair comparison. The most common criticism of CEH is that the knowledge exam is multiple choice, so it proves you know about hacking tools rather than that you can use them. That’s a fair point about the knowledge exam alone. The Practical exists precisely to address it, and if you go the CEH route, the Practical is the half that says the most about your skills.
Can a beginner even sit CEH?
This is where the two differ most for a newcomer. EC-Council’s eligibility process gives two routes:
- Complete official EC-Council training (through an accredited training centre, EC-Council’s own online learning, or an approved academic institution). You’re then eligible to attempt the exam.
- Apply with at least two years' information security work experience. EC-Council verifies this with the referees you list, and there is a non-refundable application fee.
For a true beginner with no security experience, that usually means route 1: official training. Security+ has no equivalent requirement. You can study however you like and book the exam.
Neither route is a problem in itself, but it changes the total cost and timeline, so factor it in.
Which one do employers ask for?
The honest answer: it depends on your market and the role, and the only reliable way to know is to look. Before you spend money on either, do this:
- Search a job board for 20 roles you would realistically apply for in the next year.
- Note every certification mentioned, and whether it’s “required” or “desirable”.
- Count.
As a rough pattern, Security+ tends to be listed for SOC, security administration and general security roles, while CEH appears more in penetration testing and vulnerability assessment adverts, and sometimes in government or contractor work. Treat that as a starting hypothesis: your 20 adverts beat it, and they beat any statistic you’ll find online.
One more point: certifications get you past filters; they don’t do the interview for you. Hiring managers for testing roles will ask you to explain an attack. Hiring managers for SOC roles will hand you a log and ask what happened.
Security+ vs CEH: which job are you aiming at?
Use this as a decision table.
| If you… | Start with |
|---|---|
| Have no IT background and want your first security role | Security+ (consider Network+ first, see below) |
| Want a SOC analyst or blue-team role | Security+ |
| Work in IT already and want to move into security generally | Security+ |
| Have a couple of years in security and want to move into offensive work | CEH (aim for the Practical too) or CompTIA PenTest+ |
| See CEH named as required in the specific adverts you’re targeting | CEH, ideally after Security+ |
| Want a GRC or compliance role | Security+ plus framework study (ISO 27001, NIST CSF) |
If offensive security is your goal, compare CEH with CompTIA PenTest+ (PT0-003) as well. Both target penetration testing; they differ in style, eligibility and cost. Our guide on how to become a penetration tester from scratch puts certifications in the context of the practical skills you’ll need regardless.
The case for Security+
- No barrier to entry. You can start studying today with free and low-cost resources.
- Broad foundations. Networking concepts, identity, cryptography, governance and operations are used in every security role, including penetration testing.
- Vendor-neutral and widely recognised. It’s often the baseline certification in job adverts for entry-level roles.
- A sensible base for later certifications, including CySA+ for analysts and PenTest+ for testers.
The fair criticism: Security+ is wide rather than deep. It won’t teach you to run a penetration test or investigate a complex intrusion. It tells an employer you have the foundations to be trained.
The case for CEH
- Offensive vocabulary and methodology. It gives structure to how attacks unfold, which helps defenders too.
- Recognition in some sectors. Some employers and contracts name it specifically.
- The Practical adds real evidence of hands-on ability when you take it.
- Structured training included, if you take the official training route, which some learners prefer to self-study.
The fair criticism: the knowledge exam on its own is multiple choice, the eligibility rules push beginners towards paid official training, and many practitioners prefer exams that are entirely hands-on. Taking the Practical answers most of this.
What about Security+ vs CCNA?
People often weigh these against each other too, but they cover different ground. Cisco’s CCNA (exam 200-301) is a networking certification: routing, switching, IP addressing, wireless and network automation, with a Cisco flavour. Security+ is a security certification that assumes some networking knowledge.
If your weak spot is networking, a networking certification before Security+ is sensible. Many people choose CompTIA Network+ (N10-009) instead of CCNA because it’s vendor-neutral; CCNA is the stronger choice if you’re aiming at network engineering or employers that run Cisco kit. See our comparison of Security+ vs Network+ for that decision.
A sensible order for most beginners
Illustrative example, not a real student: someone with no IT background who wants to end up in penetration testing.
- Months 1–3: networking and Linux fundamentals; optional Network+.
- Months 4–6: Security+ SY0-701, plus a home lab where they practise what each domain describes.
- Months 7–12: an entry-level SOC or IT role if possible, while practising web and network attacks in their own lab.
- Year two: an offensive certification (CEH with the Practical, or PenTest+) once they understand what they’re attacking.
Only test systems you own or have written permission to test, including while studying for either exam.