Is Security+ enough to get hired with no experience?

I passed Security+, I have sent more than a hundred applications, and I have not had one interview.

Short answer

No, not on its own. CompTIA itself recommends you hold Network+ and two years in a security or systems administrator job before you sit Security+, and in ISC2's own survey of 16,029 practitioners only 6 percent said they entered cybersecurity by earning a certification. Security+ is worth holding. It is not the thing that produces the interview.

Security+ passed with no IT job behind it is a credential that clears a filter and then stops. That is not a failure of your studying. CompTIA writes the exam for people who already hold Network+ and have spent two years in a security or systems administrator role, and the certificate you earned is identical whether or not you had that. What differs is everything else on the page. ISC2 asked 16,029 cybersecurity practitioners how they got in: 56 percent came through an IT job, and 6 percent came through certification. The realistic next move is a paid IT role, not another exam voucher.

What CompTIA says Security+ is for

CompTIA publishes the design assumptions for SY0-701 on the exam page. The current version launched on 7 November 2023, runs a maximum of 90 questions in 90 minutes, and passes at 750 on a scale of 100 to 900. Under exam details, CompTIA lists the recommended experience: "CompTIA Network+ and two years of experience working in a security/ systems administrator job role." Network+ carries its own stacked recommendation, listed on its exam page as "CompTIA A+ certification, with 9 to 12 months of hands-on experience in a junior network administrator or network support technician role." Read the two together and CompTIA is describing a candidate with roughly three years of paid technical work before Security+ becomes the natural next credential. Nothing stops you sitting it earlier. There is no experience requirement, no attestation, no employer signature. The certificate issued to someone with no job history is the same certificate. That is exactly why it does not distinguish you: the credential proves you passed a knowledge test, and the thing employers were using it as a proxy for was the three years underneath it. When you supply the certificate without the substrate, the hiring manager is looking at a resume where the strongest line is a multiple-choice exam.

What hiring managers say they will accept, in their own numbers

ISC2 surveyed 929 cybersecurity hiring managers in Canada, Germany, India, Japan, the UK and the US in December 2024, with a stated margin of error of plus or minus 3 percent at 95 percent confidence. Every respondent had entry- or junior-level cybersecurity staff on their team. The headline finding gets quoted as a win for certifications: 90 percent said they would consider a candidate with only previous IT work experience, and 89 percent would consider one holding only an entry-level cybersecurity certification, against 81 percent for a candidate with only education in IT, cybersecurity or computer science. Two things about that. First, "would consider" is the weakest verb in hiring; it describes who does not get discarded, not who gets called. Second, the gap between 90 and 89 sits inside the survey's own margin of error, so the certification and the IT job are not separable at that level of the question. The separation appears when ISC2 forced a ranking. Asked which attributes were critical rather than nice to have, 47 percent named IT and cybersecurity certifications, 44 percent named previous IT experience and 43 percent named relevant education. Those three are close enough that no one of them carries a candidate alone. ISC2 also reports that 84 percent of these managers use skills-based assessments or tests for entry- and junior-level applicants. The certificate buys a look. A practical test decides.

The number that should change your plan

The 2025 ISC2 Cybersecurity Workforce Study drew a record 16,029 cybersecurity practitioners and decision-makers. It asked how they entered the field. IT experience was the primary pathway at 56 percent, split between 36 percent who took on cybersecurity responsibilities while already in an IT role and 20 percent who moved directly from IT into a security post. Cybersecurity education accounted for 10 percent. Non-IT professional experience accounted for 8 percent. Earning cybersecurity certifications accounted for 6 percent. Self-directed exploration was 4 percent, military backgrounds 3 percent, internships or apprenticeships 3 percent. Roughly one working cybersecurity professional in sixteen got there the way you are attempting. That figure is published by ISC2, which sells the CC and the CISSP and has a direct commercial interest in the opposite finding, which is why it is worth taking seriously. The picture shifts slightly by age. Among participants aged 21 to 29, 38 percent came through IT and an equal 38 percent came through routes other than IT or cybersecurity education, including 7 percent through certifications and 8 percent through internships and apprenticeships. Among those over 45, the IT pathway rises to roughly 65 percent. Certification-first entry exists. It is a minority route, and it is more common for people who are also young, cheap to hire and available for an internship.

Why the postings you are answering are impossible

Part of the silence is arithmetic on the employer side. ISC2 found that 38 percent of hiring managers said they require the ISACA CISA certification for entry-level positions, and noted in the same report that CISA "demands a minimum of five years of professional experience in information systems auditing, control, assurance or security." Separately, ISC2 reports that hiring managers expect around a third of entry-level (34 percent) and junior-level (33 percent) candidates to hold the CISSP, which requires a minimum of five years of cumulative, paid cybersecurity experience before ISC2 will certify anyone. ISC2 called this "a notable misalignment between employer expectations and feasibility." A posting labelled entry-level that names CISSP is not describing a job a beginner can hold. It is a mid-level role with an entry-level title, or a job description copied from a template nobody audited. When you send a hundred applications into a pool where a third of the entry-level listings are structurally closed to entry-level people, the response rate you are seeing is partly a property of the listings. Before you write another cover letter, open twenty postings you have applied to and count how many name a credential that requires years of experience you do not have. Whatever that count is, subtract those from your hundred. The remaining number is your real application total, and it is likely small enough to explain the silence without any theory about your resume.

The market conditions behind the silence

The 2025 ISC2 study measured what happened to cybersecurity budgets and headcount. Thirty-nine percent of respondent organisations reported hiring freezes, up one point on 2024. Thirty-six percent reported budget cuts, down one point from 37 percent. Cybersecurity layoffs were reported by 24 percent, down one point. Promotion freezes rose two points to 34 percent. Looking forward, 31 percent expected more cutbacks over the following twelve months and 26 percent expected more layoffs, higher than the 22 percent who predicted layoffs a year earlier. The pressure concentrates at the top of the size range: organisations with 10,000 or more staff reported layoffs at 32 percent against 17 percent for firms of 1 to 99 people, and 49 percent of those enterprises were running cybersecurity hiring freezes. Thirty-three percent of organisations said they did not have the budget to staff their teams adequately, and 29 percent said they could not afford to hire staff with the skills they needed. One inconsistency in the report is worth flagging rather than smoothing over: ISC2 gives the overall hiring-freeze rate as 39 percent in its trend section and as 34 percent in the passage comparing enterprises to smaller firms. We quote the 39 percent because it is the figure ISC2 states directly against the 2024 comparison, but the report does not reconcile the two. None of that is about your application. It means the number of open entry-level seats shrank while the number of certified applicants did not, and a hiring freeze does not send rejection emails.

Where the certificate is genuinely a hard condition

There is one setting where holding Security+ before you apply is straightforwardly correct, and it is federal. The Department of Defense issued DoD Manual 8140.03, Cyberspace Workforce Qualification and Management Program, on 15 February 2023, cancelling the older DoD 8570.01-M. The DoD CIO describes the manual as focusing on "the demonstration of capability, which ensures the cyber workforce is able to perform required functions in the job environment." CompTIA lists Security+ against DoD 8140 work roles including cyber defense analyst, incident responder, vulnerability analyst, security control assessor, system administrator and network specialist. On many cleared contracts the credential is a condition of occupying the seat, so a contractor cannot bill you against the role until you hold it. The DoD CIO put the size of the cyber workforce covered by 8140 at 225,000 civilians, military personnel and contractors when the manual was issued. Two honest qualifiers. The manual moved DoD away from a pure certification checklist toward demonstrated capability, so the certificate is one qualification option rather than the whole test. And a security clearance, which is sponsored by an employer and not something you can buy, is usually the harder gate on those contracts than any exam.

The route the labour statistics actually describe

The Bureau of Labor Statistics publishes the entry conditions for both ends of this path. For information security analysts, the Occupational Outlook Handbook lists typical entry-level education as a bachelor's degree and work experience in a related occupation as "less than 5 years," with on-the-job training listed as none. Employment was 192,900 in 2025 with a May 2025 median wage of $129,180. BLS writes that analysts "may need to have work experience in a related occupation" and that "many analysts have experience in an information technology department, often as a network and computer systems administrator." For computer support specialists, BLS lists work experience in a related occupation as none, typical entry-level education as "See How to Become One," and notes that candidates "may qualify with a high school diploma plus relevant information technology (IT) certifications." Employment was 903,100 in 2025 with a median wage of $62,890. Divide the two BLS employment figures and that is 4.7 support jobs for every security analyst job, and the support jobs are the ones BLS says need no prior occupation. BLS also states that "many computer support specialists advance to other information technology positions, such as information security analysts." One caveat worth stating plainly: BLS projects computer support specialist employment to fall 3 percent between 2025 and 2035, a loss of 24,300 posts. It is a large on-ramp, not a growing one.

What to do with the next ninety days instead of another exam

Stop buying vouchers. A second certificate on a resume with no employment history changes the same variable twice. Apply for help desk, service desk, NOC and junior systems administration roles, which is where ISC2 says security hiring managers are already shopping: among the 22 percent of managers who sourced cybersecurity talent from other internal departments, 85 percent recruited from IT and 68 percent from technical support and help desk. Take the internship or apprenticeship if one is open to you, since 55 percent of managers rated internships and 46 percent rated apprenticeships effective for identifying early-career talent. Rewrite your resume against the tasks ISC2 says entry-level cyber staff actually get: documentation of processes and procedures (43 percent), alert and event management (35 percent), reporting (32 percent), physical access controls (30 percent) and user awareness training (29 percent). If you have done ticket triage, shift handover notes or account provisioning anywhere, including outside IT, that maps. Prepare for a practical test, because 84 percent of these managers run one. And audit what a recruiter finds when they search your name: 54 percent of the managers ISC2 surveyed said they had passed on a candidate because of their social media activity.

What this does not fix

This post does not claim that any other certification will fix the problem, and it does not claim Security+ was a waste of money. It cannot tell you how long your search will take, because ISC2 and BLS publish market conditions, not individual outcomes, and neither publishes a response rate for certified applicants with no work history. CompTIA publishes no Security+ pass rate and no employment outcome for holders, so nothing here rests on one. The DoD claims are sourced to the DoD CIO cyber workforce page and the DoD news release announcing DoDM 8140.03, not to the manual text, which we could not retrieve; no work-role qualification table is quoted from it.

Where an exam fits

  • CompTIA A+, if you are going after the help desk on-ramp and need the credential BLS says can substitute for a degree there
  • CompTIA Network+, if you are missing the networking base CompTIA names as the prerequisite it assumed you had
  • CompTIA CySA+, only once you have a year of paid alert triage or log review behind you
  • CISSP, only after five years of paid cybersecurity work, which is what ISC2 requires before it will certify you

Common questions

Is Security+ worthless without experience?

No, but it is not sufficient on its own. ISC2 found 89 percent of cybersecurity hiring managers would consider a candidate holding only an entry-level cybersecurity certification, which keeps you in the pile; it does not put you at the top of it. Security+ also remains a contractual condition for many DoD 8140 work roles, so for federal contract work it is worth holding before you apply.

How many people actually get into cybersecurity through certification alone?

Six percent, according to ISC2's own 2025 Workforce Study of 16,029 practitioners. IT experience was the pathway for 56 percent, cybersecurity education for 10 percent, non-IT professional experience for 8 percent. That figure comes from an organisation that sells certifications, which is why it is worth weighing.

Should I buy CySA+ or CISSP next?

Not yet. CISSP requires a minimum of five years of cumulative paid cybersecurity work before ISC2 will certify you, so you would be paying to become an Associate rather than a CISSP. CySA+ assumes hands-on alert handling. Adding a second knowledge credential to a resume with no employment history changes the same variable twice.

Why do entry-level cybersecurity postings ask for CISSP?

Because a large share of them are written without checking the credential's own requirements. ISC2 found 38 percent of hiring managers require CISA for entry-level positions, and that managers expect around a third of entry-level candidates (34 percent) to hold CISSP, and described this as a misalignment between employer expectations and feasibility. Those listings are not describing jobs a beginner can hold.

Is help desk really the route, and is it a dead end?

It is the route the data describes, and it is shrinking rather than dead. BLS records 903,100 computer support specialist jobs in 2025 against 192,900 information security analyst jobs, lists no prior occupation as required for support, and states that many support specialists advance to positions including information security analyst. BLS also projects support employment to fall 3 percent by 2035, so move through it rather than settle in it.

Am I not getting interviews because of the job market or because of me?

Partly the market. ISC2 recorded 39 percent of organisations running cybersecurity hiring freezes in 2025, 36 percent cutting budgets and 24 percent making cybersecurity layoffs, with 49 percent of organisations over 10,000 staff freezing hiring. A frozen requisition stays posted and never sends a rejection.

What should I put on my resume if I have no security job yet?

Map your history to the tasks ISC2 says entry-level cyber staff are actually assigned: documentation of processes and procedures (43 percent), alert and event management (35 percent), reporting (32 percent), physical access controls (30 percent) and user awareness training (29 percent). Ticket triage, shift handovers and account provisioning from any job count against those. Then prepare for a practical test, because 84 percent of these managers run one.

Sources

  1. 01CompTIA's published exam details for Security+ SY0-701, including recommended experience and DoD 8140 work roles Launched 7 November 2023; maximum 90 questions in 90 minutes; passing score 750 on a scale of 100 to 900; recommended experience "CompTIA Network+ and two years of experience working in a security/ systems administrator job role"; DoD 8140 work roles listed include cyber defense analyst, incident responder, vulnerability analyst, security control assessor, system administrator and network specialist
    CompTIA checked 2026-08-28
  2. 02CompTIA's stated recommended experience for Network+ N10-009 CompTIA A+ certification, with 9 to 12 months of hands-on experience in a junior network administrator or network support technician role
    CompTIA checked 2026-08-28
  3. 03Cybersecurity hiring managers who would consider a candidate with only prior IT work experience, versus only an entry-level cybersecurity certification, versus only relevant education 90 percent, 89 percent and 81 percent respectively, from 929 hiring managers surveyed December 2024 (Canada 158, Germany 155, India 152, Japan 154, UK 155, US 155); margin of error plus or minus 3 percent at 95 percent confidence
    ISC2 2025 Cybersecurity Hiring Trends Report checked 2026-08-28
  4. 04Attributes hiring managers rated critical rather than nice to have for early-career cybersecurity hires IT/cybersecurity certifications 47 percent, previous IT experience 44 percent, relevant education 43 percent
    ISC2 2025 Cybersecurity Hiring Trends Report checked 2026-08-28
  5. 05Cybersecurity hiring managers using skills-based assessments or tests for entry- and junior-level applicants 84 percent
    ISC2 2025 Cybersecurity Hiring Trends Report checked 2026-08-28
  6. 06How working cybersecurity professionals entered the field 56 percent via IT experience (36 percent took on cybersecurity duties while in an IT role, 20 percent moved directly from IT), 10 percent via cybersecurity education, 8 percent via non-IT professional experience, 6 percent by earning cybersecurity certifications, 4 percent self-directed, 3 percent military, 3 percent internship or apprenticeship, from 16,029 respondents surveyed July and August 2025
    2025 ISC2 Cybersecurity Workforce Study checked 2026-08-28
  7. 07Hiring managers requiring experience-gated certifications for entry-level cybersecurity roles 38 percent of hiring managers require CISA for entry-level positions, a certification ISC2 notes demands a minimum of five years of professional experience; managers expect around a third of entry-level (34 percent) and junior-level (33 percent) candidates to hold CISSP, which requires five years of cumulative paid cybersecurity experience
    ISC2 2025 Cybersecurity Hiring Trends Report checked 2026-08-28
  8. 08Economic pressure on cybersecurity teams reported in 2025 39 percent hiring freezes (up 1 point on 2024), 36 percent budget cuts (down from 37 percent), 34 percent promotion freezes (up 2 points), 24 percent layoffs (down 1 point); 31 percent expect more cutbacks in the next 12 months and 26 percent more layoffs, against 22 percent predicted a year earlier
    2025 ISC2 Cybersecurity Workforce Study checked 2026-08-28
  9. 09Information security analyst entry requirements and size of the occupation Typical entry-level education bachelor's degree, work experience in a related occupation less than 5 years, 192,900 jobs in 2025, May 2025 median pay $129,180
    U.S. Bureau of Labor Statistics, Occupational Outlook Handbook checked 2026-08-28
  10. 10Computer support specialist entry requirements, size and outlook Work experience in a related occupation: none; 903,100 jobs in 2025; May 2025 median pay $62,890; projected minus 3 percent (minus 24,300 jobs) 2025 to 2035
    U.S. Bureau of Labor Statistics, Occupational Outlook Handbook checked 2026-08-28
  11. 11DoD Manual 8140.03 status and stated basis Signed 15 February 2023, cancelling DoD 8570.01-M; focuses on demonstration of capability in the job environment
    Department of Defense Chief Information Officer checked 2026-08-28
  12. 12Size of the DoD cyber workforce covered by DoD 8140 at issuance of the manual 225,000 civilians, military personnel and contractors
    U.S. Department of Defense news release, DoD CIO Issues DoD Manual 8140 checked 2026-08-28
  13. 13How cybersecurity entry pathways differ by age Among participants aged 21 to 29, 38 percent entered through IT and an equal 38 percent through routes other than IT or cybersecurity education, within which internships or apprenticeships accounted for 8 percent and cybersecurity certifications 7 percent; the IT pathway rises to 54 percent for ages 30 to 44 and around 65 percent for those over 45
    2025 ISC2 Cybersecurity Workforce Study checked 2026-08-28
  14. 14How cybersecurity economic pressure varies by organisation size, and what drives staff shortages Organisations of 10,000 or more staff report cybersecurity layoffs at 32 percent against 17 percent for firms of 1 to 99; 49 percent of enterprise organisations are running cybersecurity hiring freezes; 33 percent of organisations lack the budget to staff teams adequately and 29 percent cannot afford staff with the skills they need
    2025 ISC2 Cybersecurity Workforce Study checked 2026-08-28
  15. 15Where cybersecurity hiring managers source early-career talent internally, and which early-career channels they rate Among the 22 percent of hiring managers who sourced cybersecurity talent from other internal departments, 85 percent recruited from IT and 68 percent from technical support and help desk; internships (55 percent) and apprenticeships (46 percent) are treated as tools for identifying and recruiting early-career talent
    ISC2 2025 Cybersecurity Hiring Trends Report checked 2026-08-28
  16. 16Top tasks hiring managers assign to entry-level cybersecurity professionals Documentation of processes and procedures 43 percent, alert and event management 35 percent, reporting 32 percent, physical access controls 30 percent, user awareness training 29 percent
    ISC2 news release on the 2025 Cybersecurity Hiring Trends research checked 2026-08-28
  17. 17Hiring managers who have rejected a candidate over social media activity 54 percent
    ISC2 2025 Cybersecurity Hiring Trends Report checked 2026-08-28

Related

I think a robot is deleting my resume before a human ever sees it, and I want to know if a certification would stop that.

I crossed the six-month line, I have started fudging the dates on my resume, and I am starting to believe I am permanently damaged goods.

I separate in a few months, everyone tells me the certification money is free, and every search result is a bootcamp trying to sell me a course I am not sure I need.

I am competing against resumes that look padded, and I want to know whether anyone actually checks any of this.