Search for a way into cyber security and almost everything that comes back is
either a Level 3 qualification that assumes you already know the vocabulary, or a
bootcamp that wants several thousand pounds and six months of evenings. Level 2 is
the rung that gets skipped, and for most people starting out it is the right one.
What is a Level 2 cyber security qualification?
Level 2 is broadly the standard of a good GCSE pass. In cyber security it means
the principles rather than the tooling: the kinds of threat organisations actually
face, why people remain the most reliable way into a system, what an organisation is
obliged to do with the data it holds, and the basic controls that stop most attacks
before they start.
It is not a penetration testing course and it does not pretend to be. What it does
is give you the words. A great deal of cyber security writing is impenetrable until
somebody explains what is meant by a threat actor, an attack surface or a control,
and once that lands the Level 3 material stops looking like another language.
Who is Level 2 actually for?
Three groups, in our experience. People moving into an IT or support role who have
picked things up on the job and want the underpinning knowledge written down. People
in a non-technical job, often in a small organisation, who have quietly become the
person responsible for security because nobody else was. And people who intend to go
on to Level 3 but know they would be guessing if they started there.
Do you need qualifications to start one?
No. A Level 2 certificate of this kind has no formal entry requirements. Being
comfortable reading and writing in English at around Level 1 will make it easier, and
curiosity about how systems fail is worth more than any prior certificate.
How is it assessed?
By portfolio rather than by examination. You build evidence against each assessment
criterion, it is marked internally and then quality assured externally by the awarding
organisation. There is no exam hall and no single day everything rests on, which is the
reason most adults studying alongside a job choose this route. We have written about
what portfolio
assessment actually involves in more detail.
What does it lead to?
The natural next step is a Level 3 qualification in the same field, such as the
Level 3
Certificate in Cyber Security Practices, which goes into threat intelligence,
incident response and the practical work of defending a network. If you are weighing
up a career change rather than a first qualification, our piece on
changing career into cyber
security in your thirties sets out what that route realistically looks like.
Is Level 2 worth doing if you want a job in cyber security?
On its own, a Level 2 certificate will not get you hired into a security role. What
it does is make the next qualification achievable and give you something regulated to
put on an application while you are working towards it. Employers hiring at entry level
are usually looking for evidence that you can learn the discipline, and a completed
regulated qualification is better evidence than an unfinished harder one.
How long does it take?
The qualification we offer at this level, the
NCFE
Level 2 Certificate in the Principles of Cyber Security, is studied online and at
your own pace, so the honest answer is that it depends on the hours you give it. People
doing a few hours a week generally finish inside a few months. There are no fixed term
dates and no deadline imposed on you.
A free guide: how to check in five minutes that a qualification is genuinely regulated, the seven questions to ask any provider including us, and what your fee should actually buy. Enter your
email and we will send you a confirmation link. Confirm it and the guide is yours, along with an
email whenever we publish something new. No spam, unsubscribe any time.