Cybersecurity Programs 2026: Security+, Degrees & Pay

Information security analysts earn a median salary of $129,180 per year (BLS OEWS, May 2025), and BLS Employment Projections, 2024-34 projects 28.5 percent growth in the occupation with about 16,000 openings per year. Cybersecurity programs train you to protect networks, systems, and data from attack: monitoring for intrusions, analyzing vulnerabilities, responding to incidents, and building the controls that keep organizations compliant. Training routes range from certificate programs aligned to CompTIA Security+ to associate and bachelor’s degrees, including programs designated by the NSA as National Centers of Academic Excellence in Cyber Defense (CAE-CD). This page explains the routes, what you will learn, how certification fits, and what BLS data says about pay and outlook.


Cybersecurity Salary Snapshot

U.S.
U.S. Median Pay $106,195 $51.06 per hour
Job Outlook 16.4% 54,900 jobs (2024–2034)
25,600 openings/yr

What Is a Cybersecurity Program?

A cybersecurity program typically covers the technical and procedural skills used to defend information systems. Coursework builds from networking and operating system fundamentals into security-specific topics: threat identification, vulnerability assessment, cryptography, identity and access management, security monitoring, incident response, digital forensics, and governance and compliance frameworks. Strong programs pair every concept with lab work in a security information and event management (SIEM) platform, a penetration testing environment, or a simulated security operations center.

There are three main routes. Certificate programs, typically at community colleges or bootcamps, focus on the technical core and align to CompTIA Security+ and sometimes CySA+. Associate degrees add networking, systems, and general education courses and often stack into a bachelor’s program. Bachelor’s degrees in cybersecurity or information assurance go deeper into security architecture, risk management, secure software, and policy, and they are the route most often listed as a requirement for analyst roles at government agencies, defense contractors, and large enterprises.


What You’ll Learn

  • Networking and operating system fundamentals as the foundation for everything that follows
  • Threat actors, attack vectors, malware analysis, and social engineering
  • Vulnerability scanning and management, and the basics of penetration testing
  • Cryptography, public key infrastructure, and secure communications
  • Identity and access management, authentication, and authorization models
  • Security monitoring with SIEM tools, log analysis, and alert triage
  • Incident response procedures, containment, and recovery
  • Digital forensics and evidence handling
  • Cloud security concepts on AWS, Azure, or Google Cloud
  • Governance, risk, and compliance frameworks such as NIST and ISO 27001
  • Scripting with Python or PowerShell for automation and analysis

How Long Does Training Take?

A certificate program aligned to Security+ typically runs a few months to a year, depending on whether it is a single-exam course or a stacked sequence that includes Network+ first. An associate degree in cybersecurity typically takes two years of full-time study. A bachelor’s degree typically takes four years, though many programs accept transfer credit from an associate degree so the total is not doubled. Bootcamps compress the certificate material into an intensive cohort over several weeks or months. Most degree programs include a capstone or internship with a real security operations component, and many bachelor’s programs also prepare students for additional certifications along the way.


Admissions & Requirements

  • High school diploma or GED for certificate and associate programs; bachelor’s programs have standard college admission requirements
  • Networking fundamentals are a prerequisite or first-semester course in most programs; some require or recommend A+ or Network+ before Security+ coursework
  • Math and reading placement testing at community colleges
  • No prior security experience is typically required for entry-level programs; advanced certificate programs may expect IT work experience
  • Background checks are common for internships, and some government-affiliated placements require U.S. citizenship and eligibility for a security clearance
  • Reliable computer and internet access for virtual lab environments

Licensing & Certification

Cybersecurity is not state-licensed, so industry certifications serve as the portable credential. CompTIA Security+ is the common entry certification: it is vendor-neutral, covers baseline security skills, and is one of the certifications accepted for many U.S. Department of Defense information assurance roles under DoD 8140. Most entry-level programs align their curriculum to it. CompTIA Network+ is often taken first because so much of security depends on understanding networks.

After Security+, CompTIA CySA+ certifies security analyst skills such as threat detection and incident response, and PenTest+ certifies offensive testing skills. The CISSP from ISC2 is the recognized management-level credential and requires documented professional experience in security domains before the credential is granted, which is why programs describe it as a target for experienced professionals rather than graduates. Cloud security certifications from AWS, Microsoft, and Google are increasingly common additions. Certifications generally expire after three years and are renewed through continuing education or a higher-level exam.

For degree programs, look for the NSA National Centers of Academic Excellence in Cyber Defense (CAE-CD) designation. It is awarded to institutions whose cybersecurity curriculum meets a defined set of knowledge units and is a useful signal of program depth, particularly if you are interested in government or defense work. Programs should also hold institutional accreditation from a recognized regional or national accreditor, and some bachelor’s programs hold program-level accreditation through ABET.


Career Outlook & Salary

Information security analysts (SOC 15-1212) earn a median wage of $129,180 per year according to BLS OEWS, May 2025, with the 10th percentile at $75,090 and the 90th percentile at $199,850. Employment stands at 190,650. BLS Employment Projections, 2024-34 projects 28.5 percent growth over the decade, among the highest of any occupation BLS tracks, with about 16,000 openings per year from growth and turnover combined.

It is worth being clear about what that median represents. Information security analyst is not typically a first job out of a certificate program; most people enter through IT support, network support, or a junior security operations role and move into the analyst title after building experience. The computer network support specialist occupation (SOC 15-1231) is a common intermediate step. BLS OEWS, May 2025 reports a median of $76,220 for that role, with the 10th percentile at $47,120 and the 90th percentile at $127,780, and BLS Employment Projections, 2024-34 projects 1.8 percent growth with about 9,600 openings per year.


Where You’ll Work

Security analysts work in security operations centers at large enterprises, managed security service providers that monitor many clients at once, financial services firms, healthcare systems, defense contractors, and federal, state, and local government agencies. Consulting firms employ analysts and penetration testers who work across client environments. Remote and hybrid arrangements are common for monitoring and analysis roles, while positions that require a security clearance or handle classified systems are on-site. Shift work is standard at 24/7 security operations centers.


Online vs In-Person Options

Cybersecurity is well suited to online delivery because the core lab environments (SIEM platforms, virtual networks, capture-the-flag ranges) are cloud-hosted in most programs regardless of format. Many community colleges and universities, including CAE-CD designated institutions, offer fully online certificates and degrees. In-person programs add physical networking labs, local employer connections, and cybersecurity competitions that can be valuable for building a portfolio. When comparing options, confirm the program provides hands-on lab access rather than lecture-only delivery, ask what tools the labs use, and check whether the program has an internship or capstone with a real security operations component.


Browse by Location



Cybersecurity Salary by State

BLS OEWS, May 2025

StateMedian annualTop 10% annual
Alabama$111,177$157,127
Alaska$100,550$127,405
Arizona$108,392$159,651
Arkansas$81,400$121,609
California$110,863$187,377
Colorado$111,985$172,184
Connecticut$110,086$155,960
Delaware$113,003$158,703
District of Columbia$125,052$180,765
Florida$105,249$154,925
Georgia$108,367$158,552
Hawaii$110,206$151,001
Idaho$63,340$100,980
Illinois$92,484$134,168
Indiana$81,880$134,073
Iowa$85,356$122,331
Kansas$94,744$147,213
Kentucky$103,630$157,810
Louisiana$70,970$107,563
Maine$83,634$123,466
Maryland$118,734$194,311
Massachusetts$124,812$203,660
Michigan$88,906$141,039
Minnesota$102,136$135,917
Mississippi$70,186$109,075
Missouri$86,720$144,023
Montana$67,374$112,704
Nebraska$77,595$126,025
Nevada$92,952$134,204
New Hampshire$96,334$145,783
New Jersey$115,419$176,392
New Mexico$107,477$173,924
New York$110,890$179,654
North Carolina$131,540$173,670
North Dakota$86,559$122,156
Ohio$88,079$144,291
Oklahoma$85,731$144,187
Oregon$68,900$99,660
Pennsylvania$99,135$149,633
Rhode Island$97,090$151,193
South Carolina$88,182$134,495
South Dakota$92,452$127,777
Tennessee$98,648$191,879
Texas$105,842$152,647
Utah$99,690$168,830
Vermont$96,568$150,404
Virginia$121,638$187,885
Washington$136,127$197,424
West Virginia$46,840$75,150
Wisconsin$94,389$143,288
Wyoming$74,390$128,906

Source: U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics (OEWS), May 2025.


Technology training paths that feed into or build on cybersecurity:


Career Guide

The most reliable route into security runs through general IT. A common sequence is a help desk or network support role with A+ and Network+, then Security+, then a junior security operations center analyst position handling alerts and tickets, then CySA+ and a move to a full analyst title. From there, people specialize into incident response, penetration testing, cloud security, governance and compliance, or security engineering, and CISSP becomes relevant once the experience requirement is met. Degree programs, especially CAE-CD designated bachelor’s programs with internships, can shorten the front end of that sequence for students who start in school rather than in the workforce.

For how Security+, CySA+, CISSP, and the cloud certifications fit together, read the IT Certifications guide.


Career Questions

Common questions people ask before enrolling, answered with BLS data:

FAQs

Do I need a degree to work in cybersecurity?

Not for every role. Junior security operations positions frequently hire on Security+ plus IT experience, and many analysts entered through help desk or network support without a degree. That said, government agencies, defense contractors, and many large enterprises list a bachelor’s degree as a requirement or strong preference for analyst roles. A common strategy is to start with a certificate and a support job and complete a degree, often online, while working.

What is the NSA CAE-CD designation and does it matter?

The National Centers of Academic Excellence in Cyber Defense program is run by the National Security Agency and designates institutions whose cybersecurity curriculum maps to a defined set of knowledge units. It is a signal of program depth and rigor and is particularly relevant if you are interested in government, defense, or intelligence work, where some hiring programs are tied to CAE institutions. It is not required for a private-sector career, and many strong programs are not designated.

Is Security+ enough to get hired?

Security+ is the common entry certification and satisfies the baseline requirement for many junior roles, but employers typically pair it with evidence of hands-on skill: lab work, a home lab, capture-the-flag results, an internship, or prior IT support experience. Programs that include a security operations capstone or internship give you that evidence before graduation.

How is a cybersecurity certificate different from an associate degree?

A certificate concentrates on the technical core and Security+ alignment and can be completed in a few months to a year. An associate degree adds networking, systems, and general education courses, typically takes two years, and transfers into bachelor’s programs. Many community colleges build the certificate as the first stage of the associate degree so you can stop or continue.

Can I learn cybersecurity entirely online?

Yes. Because most lab environments are cloud-hosted, fully online certificates and degrees are widely available, including from CAE-CD designated institutions. The main things you give up are in-person networking labs, local employer relationships, and campus competition teams. Confirm that an online program provides real hands-on lab access rather than video lectures alone.

What does an information security analyst actually do day to day?

Typical tasks include monitoring security tools for alerts, investigating suspicious activity, running vulnerability scans and coordinating fixes, responding to incidents, maintaining security controls such as firewalls and identity systems, writing reports, and helping the organization meet compliance requirements. Entry-level analysts in a security operations center spend most of their time on alert triage; senior analysts move toward incident response, threat hunting, and architecture.


Salary and employment data reflect U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics (OEWS) for May 2025 and Employment Projections for 2024-34. Actual salaries vary by location, experience, and employer. Program availability varies by school.


Browse Cybersecurity Schools by State

Alabama, Alaska, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, District of Columbia, Florida, Georgia, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, Washington, West Virginia, Wisconsin, Wyoming

Notice an update we should make?
We strive for accuracy. Contact us here if you see incorrect or outdated info on this page.