Sign in

Learning Paths

Each path takes you to a named certification or a job: the courses to learn it, and the hands-on labs to prove you can do it. 30 certification paths, grouped by level, and 15 career paths.

Search everything · Lab catalogue

Foundation

AWS Certified Cloud Practitioner (CLF-C02) · CLF-C02
The entry point to the AWS certification track — services, pricing, security model and the shared responsibility boundary.
3 courses 37 labs + Labs+
CompTIA A+ (220-1201 / 220-1202) · 220-1201 / 220-1202
The standard first IT certification and the usual route into a helpdesk or support role. Two exams: Core 1 hardware and networking, Core 2 operating systems and security.
9 courses 65 labs
CompTIA Tech+ (FC0-U71) · FC0-U71
The starting point if you are new to IT altogether — core terminology, hardware, software and basic security before A+.
3 courses 15 labs + Labs+
ISC2 Certified in Cybersecurity (CC) · CC
A free-to-sit entry certification from the body behind CISSP. A good first credential if you want security specifically, rather than general IT.
2 courses 33 labs + Labs+
ITIL 4 Foundation · ITIL 4
IT service management. Not a security certification, but frequently required for senior IT roles and useful context for anyone running security as a service.
5 courses
Microsoft Azure Fundamentals (AZ-900) · AZ-900
The entry point to the Azure track — cloud concepts, core Azure services, and how Microsoft prices and secures them.
1 course 24 labs + Labs+
Microsoft Security, Compliance and Identity Fundamentals (SC-900) · SC-900
The entry Microsoft security certification — the security, compliance and identity story across Microsoft 365 and Azure.
1 course 18 labs + Labs+

Core

Cisco CCNA (200-301) · 200-301
The networking certification employers know by name. Deeper and more vendor-specific than Network+, and the standard credential for network roles.
9 courses 25 labs + Labs+
CompTIA Network+ (N10-009) · N10-009
Networking is the foundation security is built on. The recommended step between A+ and Security+, and the one most people skip and regret.
9 courses 44 labs + Labs+
CompTIA Security+ (SY0-701) · SY0-701
The industry-standard entry certification for a security role. Five exam domains, taught end to end, then proven in hands-on labs across Windows and Linux.
11 courses 155 labs + Labs+

Intermediate

AWS Certified Solutions Architect — Associate · SAA-C03
Design resilient, cost-effective architectures on AWS. The most in-demand AWS certification by job-advert volume.
1 course 49 labs + Labs+
Certified Ethical Hacker (CEH) · CEH
Widely requested in job adverts, especially in government and defence contracting. Broad tooling coverage across the attack lifecycle.
1 course 82 labs + Labs+
Cisco CyberOps Associate (200-201) · 200-201
Cisco's SOC-analyst certification — monitoring, intrusion analysis and incident response from a network operations perspective.
1 course 35 labs
CompTIA Cloud+ (CV0-004) · CV0-004
Vendor-neutral cloud operations — deployment, security, maintenance and troubleshooting across providers rather than one.
3 courses 39 labs + Labs+
CompTIA CySA+ (CS0-003) · CS0-003
The blue-team analyst certification and the natural step after Security+. Detection, threat hunting, incident response and vulnerability management.
5 courses 230 labs + Labs+
CompTIA Linux+ (v8) · XK0-006
Linux administration to a professional standard — the platform most security tooling and most servers run on.
2 courses 70 labs + Labs+
CompTIA PenTest+ (v3) · PT0-003
The offensive counterpart to CySA+. Scoping, reconnaissance, exploitation and — the part most people underrate — writing the report.
4 courses 89 labs + Labs+
ISO/IEC 27001:2022 — Lead Implementer and Auditor · ISO 27001:2022
The international standard for information security management. The credential that gets asked for whenever a customer sends a security questionnaire.
5 courses 22 labs
Microsoft Azure Administrator (AZ-104) · AZ-104
Administer Azure in production — identity, governance, storage, compute, networking and monitoring.
2 courses 85 labs + Labs+
Microsoft Identity and Access Administrator (SC-300) · SC-300
Identity is the new perimeter. SC-300 covers Entra ID, access management, governance and identity protection in depth.
2 courses 54 labs + Labs+

Advanced

Advanced Security Practice (SecurityX / CASP+ aligned)
Advanced, labs-led security practice aligned to the SecurityX (CASP+) domains — architecture, enterprise risk and advanced operations. Hands-on practice, not exam preparation: we have no SecurityX course, so this path proves skills rather than coaching you through CAS-005.
1 course 97 labs + Labs+
AWS Certified Security — Specialty · SCS-C02
Specialist AWS security — identity, detection, infrastructure protection, data protection and incident response in AWS.
27 labs + Labs+
CCSP — Certified Cloud Security Professional · CCSP
Cloud security at architect level, vendor-neutral. The usual next step for a CISSP holder whose estate has moved to cloud.
4 courses 31 labs + Labs+
CISA — Certified Information Systems Auditor · CISA
The audit and assurance certification. The standard credential for IT audit, and increasingly asked for in compliance-heavy sectors.
3 courses 30 labs
CISM — Certified Information Security Manager · CISM
The management-track certification: governance, programme development and incident management. Pairs with CISSP for anyone moving into leadership.
10 courses 34 labs
CISSP — Certified Information Systems Security Professional · CISSP
The senior security certification, spanning eight domains. Requires five years of experience to certify fully. This is the management and architecture track, not a hands-on one.
18 courses 43 labs + Labs+
CompTIA SecAI+ (CY0-001) · CY0-001
CompTIA's newest certification, covering AI security — securing AI systems, and using AI in security operations. New enough that few people hold it.
3 courses 40 labs
CRISC — Certified in Risk and Information Systems Control · CRISC
Enterprise IT risk management — identification, assessment, response and control monitoring. The most risk-focused of the ISACA credentials.
1 course 22 labs
Microsoft Cybersecurity Architect (SC-100) · SC-100
Microsoft's expert-level security certification. Design a Zero Trust strategy and security architecture across an estate. Requires a prior SC-200/SC-300/AZ-500 pass.
2 courses 33 labs + Labs+
Offensive Security Certified Professional (OSCP) · PEN-200
A 24-hour practical exam with no multiple choice. The most respected hands-on offensive certification, and the hardest work on this list.
1 course 102 labs + Labs+

Career paths

Each career path follows the certification paths the job requires, then adds the skills it is actually hired for.

Security Administrator — career path
The first security job for many: keep the systems patched, the accounts right and the controls on. A+, Network+ and Security+ in order, then Linux and Windows administration on real machines.
4 courses 50 labs follows 3 cert paths + Labs+
Cyber Security Compliance Officer — career path
The GRC career at its entry: keep the organisation on the right side of the standards and the regulators. Security+ and ITIL for the grounding, GRC and privacy for the substance, then ISO 27001 and CISA.
4 courses follows 4 cert paths + Labs+
Incident Responder — career path
When it goes wrong, this is who gets called. Security+ and blue-team fundamentals, the CySA+ incident-response labs, then evidence handling, malware triage and building the response process itself.
6 courses 61 labs follows 2 cert paths + Labs+
Network Security Engineer — career path
Networks first, then the security of them: Network+ and CCNA for the plumbing, Security+ for the controls, then firewalls, IDS and packet analysis on real machines.
4 courses 84 labs follows 3 cert paths + Labs+
Penetration Tester — career path
The offensive career: find and prove weaknesses before an attacker does. Security+ as the baseline, then the hacking courses employers look for, then PenTest+ to certify it.
9 courses 24 labs follows 2 cert paths + Labs+
Security Auditor — career path
The independent check: test controls against the standard and report what you find. Security+ and ITIL for the grounding, the controls and GRC for the substance, then ISO 27001 lead auditor and CISA.
1 course 31 labs follows 4 cert paths + Labs+
SOC Analyst — career path
The practical skills a security operations centre actually hires for. Security+ first, then defence, traffic analysis and detection, CySA+ to certify it, then forensics and malware analysis.
6 courses 154 labs follows 2 cert paths + Labs+
Cloud Security Engineer — career path
Secure what runs in AWS and Azure. Security+ and both cloud foundations first, then identity, the CCSP and AWS security paths, detection in the cloud, and containers and automation.
2 courses 70 labs follows 5 cert paths + Labs+
Cyber Security Manager — career path
From practitioner to the person who runs the programme: the technical baseline, then governance, risk and compliance, then CISSP and CISM — the two certifications management adverts ask for.
2 courses follows 4 cert paths + Labs+
Cyber Security Risk Manager — career path
The GRC career at its senior end: identify, measure and own the organisation's cyber risk. Security+ for the technical grounding, GRC and ISO 27001 for the method, then CRISC and CISM.
3 courses follows 4 cert paths + Labs+
Digital Forensics Analyst — career path
Recover, preserve and explain what happened on a machine or a network. Security+ first, then disk, network, malware and document forensics, with the deepest lab series on the platform.
6 courses 165 labs follows 1 cert path + Labs+
Security Architect — career path
The designer of the whole defence: threat models, zero trust, identity and cloud architecture, backed by CISSP and a cloud architect certification.
4 courses 24 labs follows 3 cert paths + Labs+
Security Engineer — career path
The builder of defences: harden the systems, secure the network and the cloud, then prove it with the certification employers ask for. Security+ first, then Linux and Windows hardening, network security, cloud, then CISSP.
9 courses 80 labs follows 2 cert paths + Labs+
Threat Hunter — career path
The defender who goes looking. Security+ and SOC fundamentals first, then packet analysis, intelligence, ATT&CK and detection engineering, then CySA+ to certify it.
7 courses 38 labs follows 2 cert paths + Labs+
Threat Intelligence Analyst — career path
Know the adversary before they arrive. Security+ first, then open-source intelligence tradecraft, the CTI models and frameworks, and the intelligence labs — CySA+ is the natural certification after it.
6 courses 29 labs follows 1 cert path + Labs+