Skip to main content
Program Spotlight

Logging In to the Cybersecurity Program Opportunity


Cyberattacks, or the threat of them, are now a routine part of American life. But the attack targeting Canvas earlier this year that disrupted thousands of schools hit too close to home. It also underscores the need for talent in one of higher ed's fastest-growing fields of study: Cybersecurity.

With AI now assisting cybercriminals as much as it assists defenders, that need is only intensifying — but the credential market is changing. Master's degrees accounted for one-third of all cybersecurity credentials in 2018, compared to 24% in 2025, as undergraduate degrees and certificates gained ground.

So where does the cybersecurity market stand today, and which credential offers institutions the strongest opportunity?

Demand Across Credentials

Let’s start with completions across cybersecurity degrees and certificates, as shown in Figure 1 below. The bachelor’s degree anchored this market for most of the last decade, except for a brief period between 2018 and 2020, when the master’s degree took the lead. By 2025, bachelor’s programs accounted for 16,438 completions, and certificates for another 15,796. Together, they represented 60% of the nearly 54,000 credentials awarded that year.

The master’s market has grown substantially, increasing 99% over the last five years. But its growth has lagged behind every other credential category. Associate completions grew 115%, bachelor’s completions grew 124%, and certificates grew 108%. The master’s market is still expanding, but undergraduate degrees and certificates are gaining ground faster.

Years ago, the master’s degree was an attractive entry point for institutions because these programs required fewer courses and had a clear target audience: technology professionals who lacked formal cybersecurity education.

About 68% of master’s programs are offered online, making online delivery the market norm, not a differentiator. New entrants therefore need a sharper value proposition than simply offering another online master’s in cybersecurity.

Additionally, the master’s degree is more exposed to international enrollment pressures. International students accounted for 27% of conferrals, compared with just 2% of bachelor’s conferrals.

The growing scale of the undergraduate market is also visible in enrollment data. Undergraduate enrollment in this market reached nearly 175,000 in fall 2025, up 44% from fall 2022, although it was flat year over year. Figure 2 shows fall 2025 enrollment for undergraduate and graduate programs aligned to Cybersecurity and the percentage growth from fall 2022 and 2024.

Graduate enrollment, meanwhile, was just over 33,000 and down 13% from fall 2024. Undergraduates now outnumber graduate students roughly five-to-one. But is the recent graduate-level decline a cause for concern?

Two factors may be contributing to the decline, a pattern showing up across the broader computer science market as well. First, international graduate enrollment declined 6% between 2024 and 2025, and international students represent a larger share of master’s enrollment than bachelor’s enrollment. Second, growing AI-related career anxiety may be pushing some students toward programs perceived as safer bets. Yet that anxiety doesn’t align with what we see in the cybersecurity job market.

A Growing Talent Shortage

In the first half of 2026, there were nearly 700,000 job postings requiring cybersecurity skills. Over the last three years, employers posted an average of 84,000 cybersecurity job listings per month, reaching nearly 136,000 in June 2026 alone (see Figure 3). Notably, these postings represent cybersecurity skills across occupations, not a singular role.

Compared with roughly 54,000 credentials awarded in 2025, this job posting volume points to considerable employer demand. Of course, cybersecurity programs are not the only source of talent; graduates in information technology and computer science also gain cybersecurity skills through concentrations and coursework. Even so, there remains a substantial gap between the number of people being trained (supply) and the number of employers seeking cybersecurity capabilities (demand).

Salaries reinforce the demand story. Advertised salaries for cybersecurity skills-aligned roles increased from $115,000 to nearly $130,000 over three years, a 13% increase (not adjusted for inflation).

Figure 3 shows that rising demand for cybersecurity skills has been accompanied by rising advertised salaries.

For institutions, these salary levels provide a compelling earnings and ROI story to share with prospective students, regardless of credential level.

Again, the labor market data confirms the opportunity. The more difficult question for institutions is where to compete within it.

The Bottom Line

Cybersecurity demand is strong across credential levels, but growth is concentrated in bachelor’s degrees and certificates, which offer broader entry points into the market. The master’s degree remains viable, but its mature online market primarily serves working professionals and is more exposed to international enrollment shifts. Certificates and certifications may better serve career changers seeking faster entry.

For institutions considering a master’s degree, audience is the key differentiator. Programs should reach beyond technical specialists to seasoned cybersecurity professionals seeking fluency in leadership, risk management, compliance, and policy analysis.

With roughly half of cybersecurity job postings requiring a bachelor’s degree, the undergraduate credential remains the strongest entry point for many institutions. Three considerations should shape any new program:

  1. NSA Designation. The National Centers of Academic Excellence in Cybersecurity, or NCAE-C, provides standards related to curriculum, faculty competency, and community engagement. The designation offers a quality signal to students and employers, and nearly half of designated programs are at the bachelor’s level. For institutions entering the market, designation should be considered a program-quality strategy, not simply a marketing badge.
  2. Certifications aren’t optional. CISSP, Security+, and other cybersecurity certifications appeared in hundreds of thousands of job postings during the past three years. Institutions should map certification objectives to courses and embed exam preparation into the curriculum. Certifications should complement the degree, not be treated as an afterthought.
  3. AI will change the work. AI will alter how cybersecurity professionals identify threats, analyze systems, and respond to incidents. But it is more likely to change the skill mix than eliminate the need for cybersecurity talent. Programs should prepare students to manage, audit, and defend AI-enabled systems, while also using AI to improve cybersecurity practice.

Taken together, cybersecurity offers real, durable demand and a clear undersupply of qualified new entrants. For institutions deciding where to compete, the bachelor’s market is the stronger bet. The master’s market remains viable but requires intentional audience targeting and a differentiated value proposition to compete in a crowded market.

Like, Follow, Share.

Subscribe card logo

Never Miss Your

Wake-Up Call