Free Cyber Security Certifications: What's Left in 2026

11 min readBy Nathan House

If you searched for free cyber security certifications any time in the last three years, you were told the same thing first: get the ISC2 Certified in Cybersecurity. Free training, free exam, a real certification with a real body behind it.

That advice is now wrong, and most of the internet hasn't caught up. As I write this, the ISC2 page announcing that programme still sits at position three on Google for this exact search. The page it takes you to says "Program Closed" at the top.

So we went and checked every free certification we could find against the vendor's own page, on the same day, and wrote down what each one actually says. Some of what we found contradicts lists that are still being shared. Here's what's genuinely left.

TL;DR — if you've only got 30 seconds

The ISC2 CC free exam closed to new entrants on 20 May 2026. It was the only free option that was a proper proctored certification.

Seven are still genuinely free: Fortinet NSE 1-3, Cisco, AttackIQ, Centri BTJA, IBM, OPSWAT ICIP and Qualys.

None of them is independently proctored. They prove effort, not competence, and none will get you hired on its own.

The entry-level work these prepare you for is the work most exposed to automation. The rung above is AI-driven security engineering.

The free certification everyone recommends no longer exists

ISC2 ran a programme called One Million Certified in Cybersecurity. It gave away free training and a free exam for the CC, their entry-level certification. It was, for a few years, the single best answer to "what free cyber security certification is worth doing", because it wasn't a completion badge. It was a proper certification, proctored, from a body that HR departments recognise.

It closed on 20 May 2026.

ISC2's own words: "ISC2 is concluding new enrollments effective May 20, 2026" and "No new free exam seats will be issued once the program has concluded." If you already hold a voucher you can still sit the exam until 31 December 2026. If you don't, the CC now costs money like everything else.

This matters more than one item dropping off a list. The CC was the only free option that was a certification in the sense most people mean: independently invigilated, recognised on a CV, the kind of thing that gets past an HR filter. Everything else still free is a badge or a certificate of completion. That's not nothing, and I'll come to what they're genuinely good for, but the category changed shape in May and most advice hasn't.

Keyword data puts searches for that certification by name at roughly 2,900 a month (DataForSEO, August 2026). A good number of those people are about to find a closed door.

ISC2's official programme page →

How we verified this list

Every claim below comes from the vendor's own page, downloaded on 29 August 2026 and saved. Not from a summary, not from another blog, not from memory.

That sounds like an obvious standard. It isn't the norm, and the reason is that this stuff moves faster than anyone updates. While checking, we found six widely-repeated claims that had gone stale:

ISC2 CC free exam. Closed to new entrants.

MITRE ATT&CK Defender free tier. Now MAD20, a paid subscription.

Palo Alto PCCET. No longer in their portfolio; the old page 404s.

Microsoft SC-900 free vouchers. No free voucher route appears on the exam page now, only a paid retake bundle.

EC-Council "free" Essentials courses. $299 each.

"Qualys Certified Specialist." A credential name that appears on no Qualys page, including, until today, ours.

That last one was ours. An earlier draft of this article repeated it from other lists without checking. Qualys say you "get certified" but never name the credential, so neither do we. We cut it rather than print it.

Where a vendor doesn't state something, this article says so rather than filling the gap. Fortinet, for instance, says clearly that its self-paced courses are free but never prints a price for the exam itself. So that's how it's written below.

The best free cyber security certifications that are actually free

Seven, as of today. These are the free cyber security certifications with certificate attached, where the vendor's own page confirms you pay nothing for the credential itself.

A network firewall appliance filtering traffic between an untrusted and a protected side
Genuinely free

Fortinet NSE 1, 2 and 3

The current course names are NSE 1 Cybersecurity and Cloud Fundamentals, NSE 2 Introduction to Next Generation Firewall, and NSE 3 FortiGate Operator, so older guides pointing at different titles will confuse you. Fortinet's training site states that "All self-paced courses are open free of charge", the exam sits at the end of the course, and the certification runs for two years. Levels 4 and above are proctored through Pearson VUE and cost money. These three aren't. My own view, rather than anything Fortinet publishes: these probably carry the most weight with an employer of anything on this list, simply because Fortinet kit is in a lot of racks and the name means something to whoever reads your CV.

What you get

Three certifications, exam included, valid for two years. Free badge.

The catch

Fortinet never prints a price for the exam itself, only that the courses are free.

training.fortinet.com →
A network of connected nodes forming the shape of a protective shield
Genuinely free

Cisco Introduction to Cybersecurity

Cisco titles the page "Introduction to Cybersecurity by Cisco: Free Online Course". Their enrolment page is JavaScript-rendered and we could not capture the body text, so treat the free status as Cisco's own title claim rather than something we read in their terms. The badge criteria we did verify, from Cisco's Credly page: you need a "Passing score on Cisco Networking Academy comprehensive final exam", not just the videos. It's a clean first badge and the Cisco name travels.

What you get

Free course (per Cisco's page title) plus a Credly badge that verifies publicly.

The catch

Explicitly an introduction. It won't move a CV on its own, and you must pass the final exam.

netacad.com →
A simulated red attack being fired at a blue defensive grid, the purple team model
Genuinely free

AttackIQ Academy

The best content on this list, and I don't think it's close. Their Foundations series covers breach and attack simulation, purple teaming, cyber threat intelligence, CTEM, operationalising MITRE ATT&CK, and AI security. Their site says to register for AttackIQ Academy today, that "it's free and takes only seconds".

What you get

Six Foundations courses, digital badges and CPE credits (issuer unnamed), all free.

The catch

They say "CPE credits" but never name ISC2. Confirm with your awarding body before counting them.

academy.attackiq.com →
A blue team analyst at a multi-monitor workstation reviewing packet captures and logs
Genuinely free

Centri Blue Team Junior Analyst Pathway

Centri is what Security Blue Team renamed itself to, which trips people up when the old URLs 404. They publish a set of free introduction courses; six of them make up the BTJA pathway. Their own page: "Since the courses making up the BTJA training pathway are free, no discounts are necessary or available." On time: their bundle page says around 30 hours, while their own FAQ on the same site says 6 to 7. Budget somewhere in between. It's hands-on with real tools: Wireshark, CyberChef, Redline, steghide. If you want the free option that most looks like actual defensive work, this is it.

What you get

Six free courses earning a BTJA certificate of completion.

The catch

A certificate of completion, not a proctored certification. The paid BTL1 line is separate.

centri.org →
A solid foundation stone block secured with a padlock, representing an entry-level building block
Genuinely free

IBM Cybersecurity Fundamentals

The Credly badge page reads "Cost: Free", it needs 80% on the end-of-course assessment, and it's open to any registered adult learner. Be aware some other IBM security badges are restricted. Getting Started with Cybersecurity says it's "only available to registered users who are working directly with organizations as part of the IBM SkillsBuild program". Fundamentals isn't one of those.

What you get

Credly badge, free, open to any registered adult learner.

The catch

Needs 80% on the assessment. Some other IBM security badges are restricted to organisation programmes.

skillsbuild.org →
An industrial control system plant protected inside a shield, representing critical infrastructure security
Genuinely free

OPSWAT Introduction to Critical Infrastructure Protection

This one's odd. OPSWAT never writes the word free anywhere on the page. The course is listed at $50, but the Enroll button they publish carries a coupon that takes it to $0.00 at their own checkout. Eighteen minutes long. Their other courses render at $50 with no such coupon. Small, but real, and relevant if you're anywhere near OT or ICS.

What you get

Completion certificate, half a CPE credit, one year validity.

The catch

Listed at $50. It only reaches $0.00 through the coupon in OPSWAT's own Enroll link.

opswatacademy.com →
A radar sweep scanning server and database assets, finding and marking weak points
Genuinely free

Qualys certified courses

Qualys says you can "take free training courses" and "get certified" across their product range: Vulnerability Management Detection and Response, TotalAppSec, Policy Audit, Container Security and more. Anyone can "Create an account"; you don't need to be a customer. Note there is no named credential here. The phrase "Qualys Certified Specialist" appears nowhere on their site, whatever other lists tell you, and Qualys never states what the credential is actually called.

What you get

Free self-paced training with labs across their product range. Qualys says you "get certified".

The catch

Qualys never names the credential and never states whether the exam itself is free.

qualys.com/training →

Free training, paid certificate

This is where several lists of free cyber security certifications online get sloppy, because "free course" and "free certification" get used as if they mean the same thing.

It is also why you will not find TryHackMe or Hack The Box below. Both have genuinely useful free tiers and both are worth your evenings, but neither issues a credential, so neither belongs on a list of certifications. That is a scope decision, not an oversight.

A browser window with an injection payload being intercepted by a proxy shield
Training free, certificate paid

PortSwigger Web Security Academy

Their words: "It's also why the Academy is 100% free." Written by the people who build Burp Suite. If you want to learn web security, this is better than most paid courses, and I'd tell anyone to do it regardless of whether they ever sit an exam. The certification is a different matter. Their FAQ is blunt that the exam "cannot be completed with either Burp Suite Community Edition or any other web application security testing toolkit", so budgeting for the exam fee alone will catch you out.

What you get

Hundreds of labs, entirely free. The best free training on this page.

The catch

The BSCP exam is £69/$99 and needs a Burp Pro licence at £419/$499 a year. Real cost: about $598.

portswigger.net/web-security →

Google Cybersecurity Certificate

Free to audit, $49 a month to certify. Coursera's own page says most people finish for under $300. We've written a fuller assessment of what the Google certificate does and doesn't get you.

Microsoft SC-900

Free training on Microsoft Learn, $99 for the exam. There used to be free vouchers through Virtual Training Days; there's no sign of them on the exam page now, only a paid retake bundle.

Free entry level cyber security certifications that no longer are

Worth naming, because they still show up on lists:

CertificationStatus now
ISC2 CC (One Million Certified)Closed to new entrants, 20 May 2026
MITRE ATT&CK DefenderNow MAD20. Their FAQ: "solely available to paid subscribers". $99/month, $579/year, $2,499/year
EC-Council Essentials (NDE, EHE, DFE)$299 each. The word free no longer appears on the Essentials course pages at all
Palo Alto PCCETGone. Absent from the current portfolio; the old product page 404s
SANS Cyber AcesRetired 1 June 2023. SANS: the content is now out-of-date
Microsoft SC-900 vouchersNo longer offered on the exam page

EC-Council deserves a specific mention because it's on nearly every free list. It should not be. Their own page now carries the line "Buy This Course Now For $299", and when we searched the Network Defense, Ethical Hacking and Digital Forensics Essentials pages on 29 August 2026, the word "free" did not appear on any of them. What used to be a free-courseware route with a paid certificate is now a single $299 product with the exam voucher included. Any list still calling these free is quoting a version of the page that no longer exists.

What a free certificate actually gets you

Here's the part I'd want someone to tell me straight, especially if you're looking at cyber security certifications for beginners free of charge as a way in.

None of the seven above is a certification in the way Security+ or OSCP is. None is proctored by an independent invigilator. None will, by itself, get you hired.

What they do is narrower and still worth having. They prove to yourself that the field fits before you spend £300 on an exam. They give a career-changer something verifiable on LinkedIn while they save up. They fill the gap on a CV that would otherwise be blank. And in the case of Centri and AttackIQ, they teach you something real with tools you'll actually use.

That's a fair trade for a few evenings and nothing. It just isn't what "free certification" implies, and I'd rather say so than sell you the list.

💡 One thing nobody tells you: these lapse. Fortinet's certifications run two years, OPSWAT's certificate one. None of the vendors state what re-certifying costs once the free window closes, and none of them commit to the free tier still existing then. On CPEs, which is the other reason people stack free credentials: AttackIQ and OPSWAT both mention CPE credits but neither names the awarding body they count toward, so confirm with whoever holds your renewal before you rely on them. Where a vendor does not say, we have not filled it in.

So here's how I'd actually sequence it, having watched a lot of people try to do this in the wrong order.

1

Dip your toe in with the free ones. That is genuinely what they are for. Find out whether you like this work before anyone asks you for money.

2

Get the base. Security+ is still the main one for general cyber security. CompTIA list it at $439 for the exam voucher, and it is the credential that clears the HR filter the free ones cannot. SC-900 at $99 is the cheaper alternative if you are heading towards Microsoft environments. The free voucher route for it is gone, but the training on Microsoft Learn still is not.

3

Pick a specialisation and certify into it. Pentesting, cloud, defence, GRC. This is where the specialist certs earn their money, and where a specific career path and the certification roadmap are more useful than another general list.

4

Then add AI-driven engineering on top. This is our own programme, so weigh it accordingly. It is also the part that is new, and it is the part almost nobody has yet. A security base plus a specialisation plus the ability to direct AI systems to do the work is the combination employers are now writing job adverts for.

The order matters. AI-driven engineering on top of a security base makes you unusually valuable right now. AI-driven engineering with no security underneath it makes you someone who can prompt a model, which is not the same thing and does not pay the same.

The rung above: where the jobs are actually going

There's a bigger thing happening underneath this, and it changes what a beginner should aim at.

The entry-level work these certifications prepare you for, tier-one triage, alert queues and first-pass vulnerability review, is the work most exposed to automation right now. Not gone, but shrinking, and shrinking from the bottom, which is exactly where someone with a free badge is trying to get in.

Meanwhile a different kind of role is being posted: people who direct AI systems to do security engineering work rather than doing each task by hand. We track these openings on our AI-driven cyber security jobs page: real listings from named employers, each one captured and archived with its original wording on the day it was posted, so you can check them the same way we checked the certifications above. The titles vary. The requirement underneath doesn't: can you make an AI system do useful security work, and can you tell when it's wrong.

That is why step 4 above matters more than it looks. If you want to see what the work actually is before you commit to it, the case for making this shift lays out the evidence, and AI-driven engineering covers the practice itself.

So do the free certifications. They're a decent first rung, and free is free. Just be clear that the rung is lower than it was in 2023, and the ladder above it has been rearranged.

Where to go next. Our free web-book, Become the Cyber Security Expert the AI Era Demands, covers the shift and what to build instead. It costs nothing, which by the standards of this article makes it one of the better free things on the internet.

Frequently asked questions

Is the ISC2 Certified in Cybersecurity still free?

No. ISC2 closed new enrolments to the One Million Certified in Cybersecurity programme on 20 May 2026. Existing voucher holders can sit the exam until 31 December 2026. New candidates pay.

Can a free cyber security certification get me a job?

Not on its own. None of the genuinely free options is an independently proctored certification, so they don't clear an HR filter the way Security+ does. They're useful for proving interest, building a CV while you save for a paid exam, and finding out whether the field suits you.

Which free cyber security certification is best?

For content, AttackIQ Academy. For hands-on defensive work, Centri's BTJA pathway. For a name an employer recognises, Fortinet NSE 1 to 3. It depends what you want it to do.

Is the PortSwigger Web Security Academy really free?

The training is, entirely. The Burp Suite Certified Practitioner exam is £69 (about $99) and also requires a Burp Suite Professional licence at £419 ($499) a year, so certifying costs roughly £488, or about $598 in total.

Are there any free proctored cyber security certifications left?

Not that we could verify as of August 2026. The ISC2 CC was the last widely available one.

Where can I find a list of cyber security certifications free of charge that is actually current?

That's the problem this article exists to solve. Most lists are copied from other lists and go stale within months. Check the vendor's own page before you enrol, and treat any list without a verification date with suspicion, including this one after a few months have passed.

All certification details verified against vendor pages on 29 August 2026. Free tiers and pricing change often, so check the vendor's own page before enrolling.

About the Author

Nathan House

Nathan House, Founder & CEO of StationX

Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.