Most platforms add a feature or two a year and call it momentum. Our 2026 has been a different kind of year: three new hands-on certifications, a live skill score that replaced a static leaderboard ranking, the biggest rebuild the Jr Penetration Tester path has ever had, and an entirely new subscription tier built for people already working in the field. Taken individually, each is a solid update. Taken together, in order, they tell a clear story about where we are putting our effort, and why that effort is worth paying attention to whether you are just starting out or several years into a security career.
January 2026: SEC1 launches as a fully hands-on entry-level certification
Our first move of the year was launching the Cyber Security 101 (SEC1) certification on 28 January. SEC1 acts as a capstone to our Cyber Security 101 learning path, and its entire design is a reaction against how beginner certifications usually work: heavy on theory, multiple choice, and only loosely connected to what the job actually involves.
SEC1 has none of that. The exam runs 24 hours, entirely hands-on across seven practical sections covering OS and network fundamentals, offensive security, and defensive security, with no multiple choice questions anywhere. Every section pairs a scenario with technical questions you answer by actually doing the task inside a browser-based lab. It is valid for three years, includes one retake, and results are instant. For a beginner audience, this matters because it gives people something concrete to put in front of an employer, evidence of applied skill, rather than a certificate that only proves they sat an exam.
February 2026: SEC0 removes the last barrier to starting a cyber security career
A month later, on 25 February, we launched SEC0 (Pre Security), a certification we built specifically for people with zero prior technical background. Where most cyber security learning assumes at least some IT or computer science exposure, SEC0 deliberately starts a level earlier: how computers work, how networks move data, how systems connect and fail, before any security concept is introduced at all.
That ordering is the whole point. A huge number of people who could be excellent security practitioners talk themselves out of trying because the entry point assumes knowledge they do not have. SEC0 gives that group a genuine, structured first step, and it flows directly into SEC1 once the fundamentals are solid, with a 20% bundle discount available across both. Combined with SEC1, we now have a hands-on, no-theory certification path that covers absolute beginners through to demonstrable Cyber Security 101 competency.
March 2026: SAL2 becomes our most advanced defensive certification
The most significant certification launch of the year came on 25 March: Security Analyst Level 2 (SAL2), and it is worth spending real time on because of the specific problem we built it to solve. Most SOC-focused certifications test one domain and treat the analyst role as purely technical. SAL2 does neither.
The exam runs 72 hours, non-proctored, and puts candidates through 12 multi-stage scenarios across three simulated shifts, ranging from low-noise anomalies to high-severity incidents, using the same tools a real SOC runs on: SIEM platforms, EDR and threat intelligence applications, and access to actually compromised machines. Every scenario is graded on two dimensions equally. The technical component tests whether you can trace an attack chain from initial access through to impact across Cloud, Active Directory, Network, Web, and OS platforms. The non-technical component tests the skills almost no other certification measures at all: decision-making under time pressure, incident communication, MITRE mapping, and writing a clear incident report someone else can act on.
That second half is what makes SAL2 different from anything else in the market. A real Level 2 analyst is not just a technician, they are an investigator, a decision-maker, and a communicator, often simultaneously and under pressure. SAL2 is the first certification to actually evaluate all three at once, which is why we are positioning it as the credential for analysts ready to prove they operate at an elite level, not just SAL1 graduates looking for the next line on a CV.
March 2026: Capability Score replaces the Top 1% ranking with a living skill number
Days after SAL2, we made a quieter but structurally important change: retiring the old "Top 1%" leaderboard ranking in favour of Capability Score, documented 31 March. The old ranking rewarded historical volume, how many rooms you had ever completed. Capability Score rewards current ability instead.
The score runs 1 to 100 and is built from a Baseline, determined by the difficulty tier of rooms you have completed, adjusted by four weighted signals: Consistency (do you show up regularly), Relevance (are your completed rooms reflecting current threats and techniques, not legacy content), Versatility (can you operate across multiple security domains, not just one), and Depth (how far you have gone in your strongest specialism). Crucially, the score can go down. Stop engaging and Consistency decays over a rolling window; let your completed content fall too far behind what is current and even your Baseline can drop a bracket. It is a genuinely different signal to show an employer than a static leaderboard position, because it says something about your ability right now, not two years ago.
May 2026: The Jr Penetration Tester path gets its biggest rebuild yet
On 21 May, we shipped the most significant rework the Jr Penetration Tester path has had since it launched, and given how many learners have used it as their first real introduction to offensive security, that is a high bar to clear. This was not a refresh. It was a ground-up rebuild.
The headline addition is a full nine-room Active Directory module we built, up from a single introductory room, covering Kerberos, NTLM relay, authenticated enumeration, credential harvesting, and lateral movement, reflecting how central AD has become to real junior pentesting interviews. We rewrote every room in the Web Security module end to end, adding a new CSRF room to complete full OWASP Top 10 (2025) coverage. The path now closes with three full kill-chain capstone challenges we built specifically to mirror what real junior pentester interviews and assessments look like, and which double as the canonical preparation route for the Jr Penetration Tester certification (PT1). The result is 89 rooms across 17 modules, roughly 70 to 90 hours of hands-on lab time, every single room paired with a live vulnerable target you attack directly in-browser. If you completed the original version of this path, the AD module and capstones alone make it worth coming back for.
May 2026: AI Security becomes our newest certification track
Just over a week after the Jr Penetration Tester rebuild, we turned our attention to the fastest-growing skill gap in the industry: AI security. The AI Security learning path and its accompanying AI Security (AI1) certification, documented 29 May, formalise a structured, hands-on route from fundamentals to a credential that proves you can secure a live AI system, not just discuss the risks in the abstract.
The path runs five modules and 25 rooms, covering how AI systems are actually built, where they break, LLM vulnerabilities, prompt injection and jailbreaking, AI supply chain security, and RAG security, using MITRE ATLAS as the threat modelling framework rather than treating AI risk as a vague, undefined category. It is included with Premium and takes an estimated 40 to 60 hours for someone who already has a general security background.
The AI1 exam is where the certification earns its weight. It runs 48 hours, non-proctored, entirely browser-based, across four sections and 13 hands-on scenarios spanning static sites and live AI chatbots: Threat Modelling Assessment, Prompt Injection and Jailbreaking, AI Supply Chain Security, and Data Poisoning. No prior AI or machine learning background is required, only a general security foundation, which matters because AI security is genuinely new ground for most practitioners, including experienced ones. Technical sections are graded automatically, written mitigation plans and threat reports are evaluated with AI-assisted grading within 24 to 48 hours, the pass mark is 70%, and the credential is valid for three years with a shareable Credly badge and public verification.
This might be the update with the longest shadow of anything on this list. Organisations are deploying AI into production faster than most security teams can secure it, and until now there has been no widely recognised, genuinely hands-on way to prove someone can operate on the defending side of that gap. AI1 is our answer, and given how early the industry still is on AI security specifically, being one of the first practitioners holding a credential like this carries real weight.
June 2026: MAX launches as our most powerful plan to date
The biggest update of the year, and the one that ties everything above together, landed on 29 June: TryHackMe MAX. MAX sits above Premium, and we built it specifically for the working practitioners we have accumulated in huge numbers over the years, SOC analysts, security engineers, penetration testers, incident responders, people who have outgrown what a general subscription is built to offer.
Four paths that previously sat under Premium moved to MAX for new subscribers: Red Teaming, SOC Level 2, Web Application Red Teaming, and Advanced Endpoint Investigation, the paths that map directly to mid-career roles rather than entry-level ones. Existing Premium subscribers keep access to all four under a grace period running until 30 July 2027, provided their subscription stays active. More significantly, we opened AWS 101 (Attacking and Defending AWS) and Azure 101 (Azure Security) to individual subscribers for the first time ever, both previously restricted to business plans only. Alongside that, we added Recent Threats, a continuously updated module with hands-on labs built around the latest CVEs as they emerge, a Persistent AttackBox that keeps your files and installed tools alive between sessions instead of resetting every time, and a 40% certification discount for annual subscribers, more than double what Premium offers.
Seen against everything else in this piece, MAX is not an isolated pricing change. It is us formalising a split our own certification and path updates had already been pointing toward all year: rigorous, practical validation at every stage, from SEC0 for someone who has never touched a terminal, through SAL2 for a working Level 2 analyst, up to MAX for the practitioner who needs cloud labs, current threat content, and infrastructure that does not reset overnight.
| Date | Update | Why it matters |
|---|---|---|
| 28 Jan 2026 | SEC1 (Cyber Security 101) certification launched | First fully hands-on, no-MCQ entry-level certification |
| 25 Feb 2026 | SEC0 (Pre Security) certification launched | Genuine zero-experience starting point, flows into SEC1 |
| 25 Mar 2026 | SAL2 certification launched | Most advanced defensive cert to date, tests technical and non-technical skills together |
| 31 Mar 2026 | Capability Score replaces Top 1% ranking | Live 1 to 100 score reflecting current ability, not historical volume |
| 21 May 2026 | Jr Penetration Tester path rebuilt | New AD module, full web security rewrite, 89 rooms across 17 modules |
| 29 Jun 2026 | TryHackMe MAX launched | New top-tier plan: AWS 101 and Azure 101 for individuals, Recent Threats, Persistent AttackBox |
The six moments above are just the major releases, the ones significant enough to warrant their own announcement. They don't count the many new rooms, labs, and smaller but significant updates we ship on an ongoing basis, the events we run throughout the year, including hosting our first ever in-person CTF, or the constant stream of smaller modifications our team works hard on every day to keep improving the experience and delighting our users. Consider this the highlight reel, not the full picture.
Why this year of updates actually matters
It would be easy to read the list above as us simply shipping more things, and miss what actually changed. The real shift in 2026 is in what we are willing to validate, and how rigorously. SEC0 and SEC1 proved we could build hands-on, no-theory certification for complete beginners without diluting it. SAL2 proved we could do the same at the opposite end of the spectrum, building an exam that genuinely tests whether someone can operate as a working Level 2 analyst, not just recite one. Capability Score proved we are willing to make your own progress accountable to the present, not your history. And MAX proved all of that seriousness has commercial backing: a whole tier built for the practitioners this content is aimed at.
None of that is guaranteed from a training platform. Content libraries are easy to grow. Rebuilding our most-used path from the ground up, building a certification that assesses judgement as well as technical skill, and opening cloud content to individuals for the first time were decisions that cost real effort. That is the actual argument for why 2026 is worth paying attention to: not the volume of updates, but what they collectively prove about how seriously we are investing in making our credentials and content genuinely match the job.
Frequently asked questions
Do I need SEC0 before I can take SEC1? Not strictly, but it is the recommended order. SEC0 builds the fundamentals of how computers and networks actually work, which SEC1's offensive, defensive, and investigative scenarios assume you already understand. Bundling both together also saves 20% on each.
Is SAL2 worth taking if I already hold SAL1? Yes, if you are ready for it. SAL1 validates entry-level SOC skills. SAL2 is built for analysts operating at Level 2 already, or Level 1 analysts performing above their grade, and it is the only certification currently testing technical investigation and non-technical judgement together across every major SOC domain.
Does my Capability Score replace my certifications? No, they measure different things. Certifications are a fixed, point-in-time validation of a specific skill set. Capability Score is a continuously updated signal of your current, general activity and breadth on the platform. Employers are likely to value both, for different reasons.
Should I redo the Jr Penetration Tester path if I already completed the old version? If you completed it before May 2026, yes, it is worth it. The new Active Directory module alone did not exist in the old path, and the three capstone challenges are new additions built specifically as PT1 certification preparation.
Is TryHackMe MAX worth it if I am still a beginner? Probably not yet. MAX is built around advanced, mid-career content: Red Teaming, SOC Level 2, Web Application Red Teaming, cloud security, and Recent Threats. Most beginners get more immediate value from Premium and the foundational certifications, and MAX becomes worth it once that foundation is in place.
What happens to my access if a path I am using moves to MAX? If you were an existing Premium subscriber on or before 29 June 2026, you keep access to the four paths that moved (Red Teaming, SOC Level 2, Web Application Red Teaming, Advanced Endpoint Investigation) until 30 July 2027, as long as your subscription stays active without a lapse.



Nick O'Grady