Who Should Pay for GSEC? A 2026 Guide to the GIAC Exam

By Donald Korinchak, MBA, PMP, CISSP, SecurityX, ITILv3   Published: 09/26/26   Updated: 09/26/26   7 min read

Last updated September 2026

The first question about GIAC Security Essentials (GSEC) isn’t “is it good?” It’s “who’s paying?” A certification attempt alone costs $999, and the SANS SEC401 course built around it is listed at $8,780 in the U.S. With an employer covering that, GSEC is one of the best foundations you can get. Out of pocket, the math is harder.

What you get for the money is a practitioner cert that goes well beyond vocabulary: 106 questions in four hours, including CyberLive hands-on questions in real virtual machines. GIAC set the passing score at 72% for everyone who receives the exam version released on or after April 6, 2026 (GIAC, GIAC).

Employer-funded or self-funded? That decides it

Most GSEC holders earned it through employer-funded SANS training. If you’re paying yourself, compare the $999 attempt with Security+, which costs much less and is the more common entry-level choice. If your employer offers SANS, take it.

Who GSEC suits

GIAC lists no formal prerequisites. SANS describes SEC401 as assuming a basic understanding of technology, networks and security. With no IT background at all, start with CompTIA A+ or Network+ instead.

The exam itself

ItemDetails
LevelGIAC practitioner certification with CyberLive hands-on testing
ExamOne proctored exam
Questions106
Time limit4 hours
Passing score72% (exam versions released on or after April 6, 2026)
Where you testRemote proctoring through ProctorU or on site at Pearson VUE
Attempt window120 days from activation to complete your attempt
Price$999 per certification attempt; $899 retake; $479 extension
RenewalEvery four years: 36 CPE credits plus a $499 renewal fee

Sources: GIAC’s GSEC page, pricing page and renewal page (September 2026). GIAC tells candidates to confirm the format and passing score that apply to their own attempt in their GIAC account.

Twenty-six objectives, no weights

GIAC publishes 26 GSEC objectives rather than weighted domains. Grouped by theme (GIAC):

ThemeGSEC objectives
Networking and network defenseNetworking and protocols, defensible network architecture, network security devices (firewalls, NIDS, NIPS), wireless network security
Defense in depth and accessDefense in depth, access control and password management, security frameworks and CIS Controls (with the NIST CSF and MITRE ATT&CK), data loss prevention and mobile device security
Attacks and responseVulnerability scanning and penetration testing, malicious code and exploit mitigation, web communication security, log management and SIEM, incident handling and response
CryptographyCryptography concepts and algorithms, and applying cryptography with VPNs, GPG and PKI
Endpoints and platformsEndpoint security, Windows security infrastructure, Windows as a service, Windows access controls, enforcing Windows security policy, Windows automation, auditing and forensics, Windows services and Microsoft cloud, Linux fundamentals, Linux security and hardening, container and macOS security
Cloud and AIVirtualization, cloud security and AI essentials

What makes GSEC hard

Ten weeks of self-study (or follow SEC401)

Plan on eight to ten hours a week with some IT experience behind you. If you take SEC401, follow its six sections in order instead of this plan.

How employers read GSEC

As tested, hands-on fundamentals. GSEC is widely recognized in government and defense work and by employers who know SANS training, and in those places it’s taken seriously. It won’t set your salary on its own. For a benchmark, BLS reports a median pay of $129,180 in May 2025 for information security analysts, with 21% projected growth from 2025 to 2035 (BLS).

GSEC compared with Security+, CISSP and CySA+

Weighing GSEC against the rest of the defensive track? The certification roadmap puts it in order.

Best Cybersecurity Certifications in 2026 shows where GSEC lands among the other options.

Security news moves every week. Stay current in five minutes. GSEC’s scope is basically the list of places attackers get in. The CyberExperts Daily Brief shows you which ones they’re using this month, weekday mornings. Get tomorrow’s brief.

GSEC questions

Is GSEC worth it if I pay myself?

It’s a strong cert, but at $999 for an attempt it costs much more than Security+, which is the more common entry-level choice. GSEC is the better deal when your employer funds SANS training.

How is the GSEC exam structured?

106 questions in four hours, including CyberLive hands-on questions in real virtual machines. The passing score is 72% for exam versions released on or after April 6, 2026; GIAC says to confirm the score for your own attempt in your GIAC account.

How much does GSEC cost?

$999 for a certification attempt on its own, and a retake is $899. SANS SEC401 training is listed at $8,780 in the U.S., and adding a certification attempt to the course includes two practice tests.

Do I need SANS training to take GSEC?

No. You can buy a GSEC attempt on its own from GIAC and self-study, though most candidates take SANS SEC401.

How do I renew GSEC?

Every four years, with 36 CPE credits and a $499 renewal fee.

Where do I take the exam?

Online with ProctorU remote proctoring or in person at a Pearson VUE test center. You have 120 days from activation to take it.

Sources

Donald Korinchak, MBA, PMP, CISSP, SecurityX, ITILv3

Donald Korinchak is a Cybersecurity Professional in the Washington DC area. Donald holds an MBA from the University of Pittsburgh Katz School of Business. Donald is considered a thought leader in business, leadership, and cybersecurity issues.