Before I started studying for my first certification, I did something that was probably both useful and slightly insane.
I researched almost the entire certification ecosystem.
Before answering a single practice question, I looked at the different providers, their certification paths, how employers viewed them, how useful their content appeared to be and where they seemed to fit into an actual IT or cybersecurity career.
I looked at CompTIA, Cisco, Microsoft, AWS, ISC2, ISACA, OffSec, GIAC and many others. I compared entry-level certifications, professional certifications, technical certifications, management certifications and certifications that seemed to exist mainly because companies like putting logos into job descriptions.
I ranked them for myself.
Which ones seemed valuable for HR?
Which ones appeared technically useful?
Which ones had practical exams?
Which ones were respected by people actually working in the field?
Which ones built on each other?
Which ones looked impressive but probably would not teach me much at my current level?
I had probably researched half of the certification internet before I had properly started learning for one exam.
And every time I learned more about the ecosystem, I changed my roadmap again.
The Five Roadmaps Before the First Exam#
I made at least five different certification roadmaps.
The first one was probably terrible.
Then I found new certification providers, read more discussions, watched more videos and realized that some certifications I had originally considered important did not really fit what I wanted to learn.
So I changed the roadmap.
Then I understood a little more about the difference between cloud security, offensive security, defensive security, governance, networking and general IT.
So I changed it again.
My focus kept shifting because I was only slowly finding out what I actually wanted to know. At the beginning, I did not even have enough knowledge to design a good learning path. Researching the ecosystem was therefore already part of the learning process.
Looking back, this was a very long way to begin. I could probably have asked someone experienced and received a reasonable roadmap within twenty minutes.
But I did not really have someone who could show me the full path.
So I built one myself.
The basic idea behind all versions of the roadmap stayed the same:
I know almost nothing compared to what exists, so I should start at the bottom and work my way upward.
I did not want to jump directly into an advanced certification, memorize the content required for that exam and then still have enormous gaps underneath it.
I wanted to move through the layers.
General IT first. Then hardware, operating systems, troubleshooting, networking, servers, security, cloud and eventually more advanced offensive and defensive security.
The plan was ambitious, inefficient and probably much larger than necessary.
But it was a plan.
At that point, I felt that I had two options: either I would finally start properly and follow the path through, or I would continue collecting random pieces of knowledge for another few years.
I decided to start.
Starting at the Bottom#
I began with foundation-level certifications such as IT Fundamentals+, Cloud Essentials+ and Tech+.
I had already worked in IT before that. I had been a working student in first- and second-level support, had started my first full-time position and later switched roles inside the same company.
But I had not completed certifications during that period.
My certification journey really began after I moved into consulting for the first time.
The early certifications were not extremely difficult compared to what came later. Their purpose was also not to impress anyone.
I used them to check my foundation.
I wanted to see which areas I actually understood and which ones only felt familiar because I had heard the terminology before.
There is a large difference between recognizing a concept and being able to explain how it works.
That difference became very clear once I reached A+.
A+ Connected Almost Everything at Once#
A+ was probably the single most important certification in my entire IT learning journey.
That may sound exaggerated for an entry-level certification, but for me it is the truth.
Before A+, I already had several years of exposure to IT. I had troubleshot devices, changed settings, followed remediation procedures and worked with different enterprise technologies.
I was able to perform the work.
But the knowledge was spread across different jobs, systems and individual problems. A lot of it existed in isolation.
I knew that changing a specific setting could solve an issue, but I did not always understand why the setting existed there.
I knew which remediation steps to follow, but I could not necessarily explain the complete path between the endpoint, operating system, network, identity and backend service.
There were many pieces in my head, but somebody had thrown the puzzle box away.
While studying for A+, it honestly felt as if around 80 percent of the synapses connected at once.
Almost everything I had seen during my working-student role and my first full-time jobs suddenly had a place.
Hardware, operating systems, storage, permissions, authentication, troubleshooting, networking and security were no longer random individual subjects. They became parts of one larger abstraction.
For the first time, I felt that I understood IT.
Not every product, command or implementation. I obviously did not suddenly know everything.
But I understood the construct.
I knew roughly where something started, where it ended, what it depended on and where it belonged.
When I came across a new technology, I finally had questions I could ask:
- Which layer does this operate on?
- What does it communicate with?
- What comes before it?
- What happens after it?
- Which part is hardware, operating system, network, application or identity?
- Where could the process fail?
Before A+, every unfamiliar subject could become a new black box.
After A+, I had a framework for opening those boxes.
That framework was far more valuable than any individual exam objective.
Network+ Opened the Next Major Door#
The next milestone of a similar size was Network+.
Networking had always been one of those areas where I knew many individual terms without properly understanding the complete process.
I knew what IP addresses, ports, DNS, DHCP, routers, switches and firewalls were. I had dealt with connectivity problems and had seen network-related settings throughout my previous roles.
But knowing the pieces is not the same as seeing the network.
Network+ gave me the larger model.
Together with the framework I had gained from A+, it opened my eyes to an enormous number of other areas.
Suddenly, applications were not just applications. They were services communicating over networks.
Authentication was not just entering a username and password. It involved clients, protocols, identity providers, directories, tokens and network paths.
Cloud was not a magical location somewhere outside the building. It was still compute, storage, networking, identity and software, only arranged and managed differently.
Security tools were also no longer isolated products. They collected telemetry from endpoints, network connections, identities, applications and infrastructure.
Network+ did not turn me into a network engineer. But it gave me the ability to reason through networked systems.
When something failed, I could ask whether the issue existed on the endpoint, during name resolution, in routing, at a firewall, during authentication or inside the application itself.
That may sound basic to somebody who has understood networking since childhood.
For me, it was a massive shift.
A+ and Network+ are still the two certifications I consider the most important decisions in my IT learning path.
They gave me the architecture in my head that everything else could attach to.
Security+ Gave Me the Enterprise Security Language#
Security+ came afterward and helped me understand how security is structured and described inside larger organizations.
I had already encountered many security-related technologies and processes, but I did not always know the common terminology or how the individual controls were categorized.
Security+ connected subjects such as identity, access control, vulnerabilities, cryptography, architecture, risk management, incident response and security operations.
It gave names to things I had already seen and placed them into a broader enterprise-security model.
That was useful, but it was still mostly conceptual.
I understood the language of security better.
The first time I felt that I was actually applying security across several areas came with OffSec SEC-100 and the OSCC-SEC exam.
SEC-100 Was Where Security Became Real#
SEC-100 was different from my previous certifications.
I was no longer only learning concepts, recognizing terminology or selecting the correct answer from four possibilities.
I had to use the knowledge.
I spent around three months working through the material and practical labs. At the end, I took a six-hour practical exam.
That was the first time I had to perform live hacking during an examination.
The experience pushed me forward more than I expected.
Before SEC-100, my general IT understanding had already moved much further than my practical security understanding. I could reason about computers, operating systems, networks and infrastructure, but security still consisted of many separate concepts and products.
During SEC-100, I had to connect the system, the vulnerability, the attack, the evidence and the defense.
I had to interact with the environment instead of only reading about it.
I had to investigate, test assumptions and produce actual results.
Passing the exam did not turn me into an elite hacker overnight. No six-hour exam does that.
But the three months of preparation and the practical examination moved me forward by what felt like several years of passive learning.
It was the point where my security knowledge began catching up with the IT framework I had already built.
And after that, my actual learning journey really started.
Learning How to Learn#
Of course I had learned things before.
I had studied, worked in IT and gained professional experience.
But after A+, Network+ and SEC-100, I finally understood how I personally need to approach difficult technical subjects.
A+ gave me the general IT framework.
Network+ showed me how systems communicate and depend on each other.
Security+ gave me the common language and structure of enterprise security.
SEC-100 forced me to apply knowledge and connect offensive and defensive thinking.
After that, complex and abstract systems stopped feeling impossible.
That does not mean every implementation became easy.
I could not immediately configure every product, write every program or perform every attack.
But I could understand the architecture and the concept much faster.
I knew where to begin.
I could ask:
- What is this system supposed to do?
- Where does it sit in the architecture?
- What does it depend on?
- Which data enters and leaves it?
- Where are the trust boundaries?
- What can fail?
- How could somebody misuse it?
- Which evidence would that activity leave?
The applications and products still required work.
The underlying concepts no longer felt unreachable.
That difference changed everything.
Was My Certification Roadmap Efficient?#
Probably not.
There was redundancy.
Some certifications repeated topics I had already covered. Some exam objectives added little new knowledge. With the benefit of hindsight, I could design a shorter and more targeted roadmap today.
But that is easy to say now that I have the knowledge required to design one.
At the beginning, I did not know what I did not know.
The long route gave me structure when I had none.
It exposed gaps I would otherwise have missed and gave me a reason to move through subjects systematically instead of following whatever happened to be interesting that week.
It may not have been the most efficient path.
But it was a path, and I followed it.
That matters.
Why I Disagree With “Certifications Are Useless”#
I regularly hear people say that certifications do not matter and that only practical experience counts.
I disagree completely.
A certification alone does not prove deep competence. Someone can memorize exam questions, pass a test and forget most of the material shortly afterward.
But the opposite statement is just as wrong.
Practical experience without theory can leave you repeating processes without understanding why they work.
You may become very good at one product, one procedure or one environment and still struggle when the context changes.
Theory gives you the models, terminology, architecture and concepts needed to transfer knowledge from one situation to another.
Practice shows whether you can actually apply that knowledge when the system is messy, incomplete or behaving differently from the textbook.
For me, the relationship is roughly 50/50.
Theory is at least half the job.
Practice is the other half.
Without practice, theory remains abstract.
Without theory, practice can become a collection of habits and memorized remediations.
The strongest learning happens when both sides continuously correct each other.
That is also why I value certifications differently today. I do not judge them only by the badge, difficulty or reputation.
I ask what the certification forces me to understand and whether I can connect that understanding to real systems afterward.
Where I Am Now#
My strongest professional area today is cyber defense, especially detection engineering, security monitoring, SIEM, XDR and security operations.
At the same time, I continue learning across general IT, networking, infrastructure, cloud, secure coding, offensive security and defensive security.
I am not trying to collect every certification that exists, even though my original roadmaps occasionally looked as if that was the plan.
The certifications are supposed to give the journey structure.
Labs, projects, writing, talks and professional experience are what turn that structure into actual ability.
Looking back, the most important result of my certification journey is not the number of certificates.
It is that I stopped approaching every new subject as a completely separate problem.
Before, I collected knowledge.
A+ gave it a structure.
Network+ connected the systems.
SEC-100 made me apply it.
After that, I finally knew how to continue on my own.



