Want a sequenced plan instead of a list? Join the structured learning tracks

Defensive Security certifications

SOC analysis, incident response, threat hunting, DFIR and detection engineering.

Clear

18 certifications match these filters

Defensive Security 18

Defensive Security certifications
Cert name Target job title Level Prerequisites Study notes Recent updates
BTL1 Centri (formerly Security Blue Team) SOC Analyst (Tier 1) Entry None. Basic networking and operating-system knowledge helps. BTL1 Notes Security Blue Team rebranded as Centri on 1 June 2026. Still a 24-hour practical incident-response exam with lifetime certification.
TryHackMe SAL1 TryHackMe SOC Analyst (Tier 1) Entry TryHackMe's SOC Level 1 path recommended. TryHackMe SAL1 Notes First rung of TryHackMe's SEC1 → SAL1 → SAL2 defensive ladder. Business list price includes training and a free retake.
CompTIA Security+ CompTIA Security Analyst / Security Administrator Entry None required. Network+ and 2 years of IT experience recommended. COMPTIA SEC+ Notes SY0-701 is live; its objectives were refreshed in April 2026. SY0-801, with a dedicated LLM objective, has a tentative preview launch around 20 October 2026.
Google Cybersecurity Google Junior SOC Analyst / Cybersecurity Associate Entry None. Designed for complete beginners. Google CyberSecurity Notes Self-paced on Coursera; covers Linux, SQL, Python, SIEM tools and incident-response basics. Often paired with Security+.
Microsoft SC-900 Microsoft IT / Security Associate (Microsoft stack) Entry None. Microsoft SC-900 Notes Still an active Fundamentals exam. Microsoft's 2026 security path adds SC-500 (Cloud & AI Security Engineer) while AZ-500 retired on 31 August 2026.
ISC2 CC ISC2 Entry-level Security Analyst / IT Support moving into security Entry None. Coming Soon New exam outline effective 1 September 2026, the first major update since launch, adding AI and stronger GRC coverage.
CCDL1 CyberDefenders SOC Analyst (Tier 1) Entry Networking and operating-system fundamentals. Coming Soon CyberDefenders' associate-level cert. All CyberDefenders certs are valid four years, renewable by retake or 36 CPEs.
HackTheBox CDSA Hack The Box SOC Analyst / Incident Responder Intermediate Complete the HTB Academy SOC Analyst path. HackTheBox CDSA Notes Multi-day practical incident investigation ending in a report. Voucher bundled with the Silver Annual plan.
TryHackMe SAL2 TryHackMe SOC Analyst (Tier 2) / Incident Responder Intermediate SAL1, or comfort with alert handling, log analysis and investigation workflows. Coming Soon Launched 25 March 2026 with NCC Group. Grades both technical and communication skills; valid for three years.
CompTIA CySA+ CompTIA SOC Analyst / Threat Intelligence Analyst Intermediate None required. Security+/Network+ and about 4 years of hands-on experience recommended. COMPTIA CYSA+ Notes CS0-004 launched 23 June 2026, adding AI and automation in security operations.
CompTIA SecAI+ CompTIA AI Security Analyst / Security Engineer Intermediate None required. 3–4 years in IT with 2+ years in security; Security+, CySA+ or PenTest+ recommended. COMPTIA SEC AI+ Notes Launched 17 February 2026 as the first of CompTIA's Expansion Series. Valid three years.
SPLK-5001 Splunk SOC Analyst (Splunk environments) Intermediate None required. Splunk Power User-level knowledge recommended. SPLK-5001 Notes 66 multiple-choice questions in 75 minutes via Pearson VUE. Splunk is now part of Cisco.
OSDA OffSec SOC Analyst Intermediate Networking, Windows/Linux logging and familiarity with common attack techniques. Coming Soon SOC-200 teaches detecting attacks in a SIEM; the exam is a 24-hour practical.
GCIH GIAC Incident Responder Intermediate None formal. SANS SEC504 is the aligned course. Coming Soon Includes CyberLive hands-on questions. Renewal every 4 years.
Microsoft SC-200 Microsoft SOC Analyst (Defender / Sentinel) Intermediate None required. SC-900 and KQL basics help. Coming Soon Covers Defender XDR, Microsoft Sentinel and KQL hunting. Free annual renewal assessment on Microsoft Learn.
BTL2 Centri (formerly Security Blue Team) Threat Hunter / SOC Analyst (Tier 2–3) Advanced BTL1 recommended; 2–4 years in security operations. BTL2 Notes Up to 72-hour practical threat-hunting exam with a written report; certification valid for four years.
CCDL2 CyberDefenders SOC Analyst (Tier 2) / DFIR Analyst Advanced SOC fundamentals, Windows/Linux artefacts and networking. CCDL1 is the associate-level step. CCDL2 Notes Renamed from CCD to CCDL2 when CCDL1 launched; existing CCD badges were updated automatically. 48-hour Elastic-based investigation exam.
CompTIA SecurityX CompTIA Security Architect / Senior Security Engineer Advanced None required. 10 years in IT with 5 years hands-on security recommended. Coming Soon CASP+ was rebranded SecurityX with the CAS-005 exam as part of CompTIA's Xpert Series.

Not sure which one is yours?

Coaching & cert roadmaps

One-to-one guidance and a roadmap built around your background, target role and timeline, so you stop guessing which cert comes next.

See coaching programs

Structured learning tracks

Membership with role- and cert-based learning tracks: roadmaps, cheat sheets, assessments, exclusive writeups and member pricing on notes.

Join the learning tracks

Prep resources & cheat sheets

Cheat sheets, command references and exam-day extras for when you already know the material and need it fast and in one place.

Browse prep resources