Cyber security 7 min read

Where do you start with cyber security at Level 2?

Where do you start with cyber security at Level 2?
Share this article
Facebook LinkedIn X WhatsApp

Search for a way into cyber security and almost everything that comes back is either a Level 3 qualification that assumes you already know the vocabulary, or a bootcamp that wants several thousand pounds and six months of evenings. Level 2 is the rung that gets skipped, and for most people starting out it is the right one.

What is a Level 2 cyber security qualification?

Level 2 is broadly the standard of a good GCSE pass. In cyber security it means the principles rather than the tooling: the kinds of threat organisations actually face, why people remain the most reliable way into a system, what an organisation is obliged to do with the data it holds, and the basic controls that stop most attacks before they start.

It is not a penetration testing course and it does not pretend to be. What it does is give you the words. A great deal of cyber security writing is impenetrable until somebody explains what is meant by a threat actor, an attack surface or a control, and once that lands the Level 3 material stops looking like another language.

Who is Level 2 actually for?

Three groups, in our experience. People moving into an IT or support role who have picked things up on the job and want the underpinning knowledge written down. People in a non-technical job, often in a small organisation, who have quietly become the person responsible for security because nobody else was. And people who intend to go on to Level 3 but know they would be guessing if they started there.

Do you need qualifications to start one?

No. A Level 2 certificate of this kind has no formal entry requirements. Being comfortable reading and writing in English at around Level 1 will make it easier, and curiosity about how systems fail is worth more than any prior certificate.

How is it assessed?

By portfolio rather than by examination. You build evidence against each assessment criterion, it is marked internally and then quality assured externally by the awarding organisation. There is no exam hall and no single day everything rests on, which is the reason most adults studying alongside a job choose this route. We have written about what portfolio assessment actually involves in more detail.

What does it lead to?

The natural next step is a Level 3 qualification in the same field, such as the Level 3 Certificate in Cyber Security Practices, which goes into threat intelligence, incident response and the practical work of defending a network. If you are weighing up a career change rather than a first qualification, our piece on changing career into cyber security in your thirties sets out what that route realistically looks like.

Is Level 2 worth doing if you want a job in cyber security?

On its own, a Level 2 certificate will not get you hired into a security role. What it does is make the next qualification achievable and give you something regulated to put on an application while you are working towards it. Employers hiring at entry level are usually looking for evidence that you can learn the discipline, and a completed regulated qualification is better evidence than an unfinished harder one.

How long does it take?

The qualification we offer at this level, the NCFE Level 2 Certificate in the Principles of Cyber Security, is studied online and at your own pace, so the honest answer is that it depends on the hours you give it. People doing a few hours a week generally finish inside a few months. There are no fixed term dates and no deadline imposed on you.

Found this useful? Share it
Facebook LinkedIn X WhatsApp

Before you pay for a course

A free guide: how to check in five minutes that a qualification is genuinely regulated, the seven questions to ask any provider including us, and what your fee should actually buy. Enter your email and we will send you a confirmation link. Confirm it and the guide is yours, along with an email whenever we publish something new. No spam, unsubscribe any time.