thinQmaster Virtual testing partner Adaptive practice exams that find your weak spots and drill them. Every answer explained. From $99

thinQmaster

Find your exam

Five questions free, before you decide.

Step 1 · choose a vendor

In one of our camps? Your practice exams come with the tuition — they are on your study page already.

thinQcompass

Tell us where you are standing and which way you want to go. We will lay out which certifications to take, in what order, and how long each one is likely to take you — including the ones we do not teach.

Plan my direction
Have a job in mind? Paste the details and we will read them

Paste the details of the position or offer — the requirements section is the part that matters. We will pull out the job title, the certifications it asks for, the experience and the pay, show you what we matched, and build the route from there.

GRC / Compliance Analyst

Mapping controls to frameworks, gathering evidence, running audits and translating between engineers and regulators.

$129,180Median pay
12 moYour horizon
8 hrsPer week
4Steps in range

Pay is the US Bureau of Labor Statistics median for Information Security Analysts, May 2025 — the occupation this job is counted inside, which is usually broader than the job title itself. GRC work is counted within information security analysts. Study times are our own estimates for someone working 8 hours a week, and they are ranges for a reason.

ISC2 CGRC: Two years in the relevant domains; associate status is available in the meantime.
ISACA CRISC: Three years in risk management. Pass first, certify later, is permitted.
ISACA CISA: Five years of audit or control experience, with some substitutions allowed for degrees.
Most postings for GRC / Compliance Analyst name a bachelor's degree. Plenty of people hold this job without one, and certifications plus demonstrable experience are how they got there - but expect the résumé screen to be the hard part, not the interview.
GRC / Compliance Analyst is not usually a first job. The realistic route is an audit, compliance or IT support role. GRC also takes people from outside IT - auditors, paralegals, quality staff - more readily than most security jobs. The plan below is still the right study order for getting there - it is the timeline to the title that is longer than the timeline to the certifications.
1 further step sits past your 12-month horizon. It is shown so you can see the whole route; it is not lost, only later.

What are you aiming to earn?

$129,000
$62,000 $176,000

GRC / Compliance Analyst reaches this. Its median is $129,180.

Your sequence

In order. Each step assumes the one above it.
Scroll the steps — the marker follows  
$62,890 · Computer Support Specialists $129,180 · Information Security Analysts

Both ends are US Bureau of Labor Statistics medians, May 2025. Everything between them is a straight line we drew, not data: nobody publishes pay per certification, and real pay moves when you change job, not when you pass an exam.

  1. 1

    CompTIA Security+

    1.8-2.8 months · from month 1

    The baseline security credential, and DoD 8140 approved - which is what unlocks federal and contractor roles.

    ~$76,148 modelled Associate We teach this See dates →
    Other ways to take this step
    • Cisco CCST Cybersecurity — if you want to show security intent before you are ready to sit Security+
  2. 2

    ISC2 CGRC

    2.8-3.9 months · from month 3

    Authorisation and risk management, heavily used in federal work.

    ~$89,406 modelled Professional We teach this See dates →

    Experience requirement. Two years in the relevant domains; associate status is available in the meantime.

  3. 3

    ISACA CRISC

    2.8-3.9 months · from month 7

    Risk, in the language executives and auditors use.

    ~$102,664 modelled Professional We teach this See dates →

    Experience requirement. Three years in risk management. Pass first, certify later, is permitted.

  4. 4

    ISACA CISA

    3.2-4.4 months · from month 11

    The audit credential. If you want to be the person reviewing controls, this is it.

    ~$115,922 modelled Professional We teach this See dates →

    Experience requirement. Five years of audit or control experience, with some substitutions allowed for degrees.

Past your 12-month horizon
  1. 5

    ISACA CISM

    3.2-5.1 months · from month 15

    Security management rather than security engineering. Needs five years experience.

    ~$129,180 modelled Expert We teach this See dates →

    On the model, this is the step that reaches your $129,000 goal.

    Experience requirement. ISACA wants five years in information security management. You can pass first and certify once the experience is documented.

Change your answers

Nothing is saved and no account is needed. Your answers live in the page address.

What interests you?

Pick as many as apply. If you are not sure, pick the one you would read about on a Saturday.

Where you are now

Both of these change the plan. Experience especially — it decides what we skip and how fast we think you will move.

How much time you have

Be honest rather than optimistic. A plan built on hours you will not find is a plan you abandon in week five.

$62,000 $129,000 $176,000

Anything you already hold

Tick these and we will not sell you a course you do not need.

I already hold some certifications

Free, and it will tell you about certifications we do not sell. If the honest answer is that you need something we do not teach, the plan says so.