top of page

My Cert Stack: SC-900 in September, Security+ in Early 2027 — Here's Why I Won't Book It Yet

Sep 4
5 min read

I want to tell you about a decision I made this week, because the decision itself is the point.


The SC-900 is booked: September 20, online, on a free voucher from the AI Skills Fest. Locked in. Then, in the same planning session, I did something that felt uncomfortable in the moment and completely right by the end of it — I took Security+ off the rushed December date I'd been eyeing and didn't replace it with another one.


No new exam date. On purpose. I'm giving myself a window — early 2027 — and I'll book the day when my study rhythm tells me I'm ready, not when the calendar pressures me into it.


Five unhurried study months instead of six weeks of panic. That's the whole story. Let me tell you why the missing date is the strategy — not a lack of one — because watching myself decide it in real time taught me something about how I actually work.


The timeline shift is a decision, not a delay


Here's the trap I almost walked into. December was sitting right there. I could have jammed Security+ into the back half of the year, called it "momentum," and posted a triumphant "two certs in one quarter" update. It would have looked great. For about a week.


Then I did the honest math. Security+ isn't SC-900. SC-900 is Microsoft's entry-level Security, Compliance, and Identity Fundamentals cert — it asks you to know which Microsoft tool owns which job across security, compliance, and identity. Security+ is broad, hands-on-adjacent, and unforgiving of the kind of surface familiarity you can cram. Rushing it wouldn't have compressed the work; it would have just moved the failure earlier.


So here's the part that felt counterintuitive: instead of moving the date, I didn't set one. Picking a hard March or April date right now would be the exact same rushing instinct wearing a calmer outfit — committing to a day before I've done the work to know which day is real. A window — early 2027 — gives me five solid, unhurried study months without pretending I can predict today which morning I'll walk in ready. Five months of the every-other-day cadence I know works for me, because I just watched it work. I'll book the seat when the rhythm says so.


What SC-900 prep actually taught me about pacing


This is the part I didn't expect.


Going into SC-900, I thought the lesson would be about content — Entra, Conditional Access, Purview, the confusable-pairs problem where PIM and Entitlement Management blur together until you drill the exact verb each one owns. Yes, that's been the study grind.


But the real lesson was about rhythm. I've been running SC-900 study on a post-every-other-day cadence, and somewhere in there I noticed something: the every-other-day gap isn't dead time. It's when the material settles. The day I don't study is doing quiet work — the confusable pairs that felt slippery on Monday are cleaner by Wednesday, without me touching them. My brain was consolidating in the background the whole time.


That's not a hack I read in a productivity thread. That's a thing I observed about my own learning, mid-flight. Once you've seen your own pacing work, you can't un-see it — you start designing around it instead of fighting it.


Which is exactly why a rushed December Security+ suddenly looked like sabotage. It would've asked me to abandon the one rhythm I'd just proven.


Where the rhythm has actually gotten me


Pacing talk is cheap without receipts, so here's where I actually am. On Microsoft Learn, I've finished the entire SC-900 prep course — all four learning paths, all fifteen modules, every assessment passed:


  • Introduction to security, compliance, and identity concepts — the shared responsibility and Zero Trust models, encryption, and data residency vs. data sovereignty. The "which layer is my job vs. the cloud provider's" map that everything else sits on.

  • Introduction to Microsoft Entra — authentication vs. authorization, why identity is the new security perimeter, SSO, directory services and Entra ID, and how federation extends trust across organizational boundaries.

  • Introduction to Microsoft security solutions — the Defender and Sentinel side of the house: what actually detects, investigates, and responds.

  • Introduction to Microsoft Purview and privacy principles — the compliance and data-governance half of the exam that most people underweight.


Coursework done. From here it's consolidation and practice, not new material.


The through-line I kept hitting is the one that trips everyone up on this exam: the confusable pairs. PIM and Entitlement Management sound interchangeable until you drill the exact verb each one owns. ID Protection and Conditional Access blur together the same way. My whole study method for SC-900 became one question repeated — which branded tool owns this specific verb? — because that's the distinction the exam actually tests, and it's the same "find what doesn't belong" instinct I've been running since the storm days.



What five months of Security+ prep actually looks like


No booked date doesn't mean no plan. Here's the plan, out loud, so you can hold me to it — the window is early 2027, and this is what fills it:


  • Months 1–2: Breadth pass. Get the full domain map in my head — every-other-day cadence, no heroics, building the same "which tool owns this verb" muscle SC-900 built, but wider.

  • Months 3–4: Depth and weak-spot hunting. This is where I find my Domain 4 — the way Network Security was my soft spot on the ISC2 CC — and drill it before it becomes a scoreboard problem.

  • Month 5: Practice exams, timing, and the mental-game rehearsal. No new material. Just proving to myself I can show it, not just name it.


The gap between a skill you can name and one you can show — that's the line the whole detection lane is built on. Five months lets me land on the "show" side, and that's what tells me when to book — not the other way around. Six weeks would've left me stranded on "name."


Why I'm telling you all of this


Because I could have just posted the wins. "SC-900 booked!" "Security+ incoming!" Clean, confident, done.


The honest version — here's the date I refused to set, here's the fear I talked myself out of, here's what my own study habits taught me — is more useful to you, and frankly more useful to me. If you're mapping your own cert stack and staring down a date that feels too soon, I'd rather you see me sit with an open window than watch me pin a day just to look decisive. Sometimes the disciplined move is not booking yet.


The exam changes. The pressure to rush changes. The question underneath doesn't: am I building something I can actually show?


Storm to SOC, one honest decision at a time. See you at SC-900 on the 20th. 💜

Comments


Let's learn this together. Have a question, a better query, or just want to say hi? Drop a line below.

© 2026 by DataSec Chronicles. Data-Inspired, Instinct-Driven.    Privacy Policy    Terms & Conditions

bottom of page