IT security bachelor alongside your job
The subject is settled, this page is about the level. Who the bachelor suits, how you get in, how much credit transfer shortens it and which roles it opens. Everything about the subject itself is under IT security by distance learning.
When the bachelor is the right level
And why the question of route is decided exactly here.
The bachelor is the first degree. It is right if you work in IT but hold no higher education qualification and that is what you are missing: for internal promotion, for public sector vacancies, for roles with formal responsibility. It is also right if you have been maintaining what someone else designed and want to design yourself.
What makes this level special in IT security: the choice between the technical and the organisational route is made here, and it is made with the programme, not later. A degree with lab components, cryptography and secure development leads to the systems. A degree with standards, risk analysis, law and audit method leads into rules and evidence. Both are in demand, but the working day afterwards is a completely different one. Check the module plan, not the name of the programme.
The bachelor is the wrong level in two cases. If you already hold a degree, even in another field, the master in IT security is the shorter route. And if you only need one specific method, for instance for an upcoming certification, a university certificate is enough, see continuing education alongside work. How the level works in general is under part-time bachelor.
How you get into this bachelor
For the organisational route, audit experience counts almost as much as IT practice.
Without A-levels the routes run as everywhere else: vocational training plus years of work for a subject-related degree, an advanced vocational qualification that often carries general university access, or a trial semester. The detail is under studying without the Abitur. What differs from other subjects is what counts as subject-related here:
- IT occupations such as systems integration or IT systems electronics are the direct route, above all into the technical side.
- Advanced IT qualifications usually bring admission and credit together and are therefore worth double.
- Commercial and administrative roles with an audit background, for example internal review, quality management or compliance, carry the organisational route. Anyone who already knows audits from the other side starts with a real advantage.
An honest note on the first year: if you lack programming and network practice, that is not a knock-out, but it costs time. Keep the semester load low in year one and plan a preparatory course if you need one.
How long it really takes
In this subject, credit transfer is the strongest lever there is.
A bachelor covers 180 ECTS, some programmes 210. What typically gets credited are foundation modules in networks, operating systems, databases and programming, which is exactly what vocational IT training documents. An advanced vocational qualification usually adds a considerably larger block.
The arithmetic on a typical case: 180 ECTS minus 60 leaves 120 open. At 10 ECTS per semester, realistic alongside operations and on-call duty, that is six years instead of nine. At 15 ECTS per semester it becomes four instead of six. For learning acquired outside higher education, an upper limit of 50 percent of a programme's ECTS usually applies.
Your security certificates are a special case. Some universities credit recognised certificates against individual modules, others not at all, and nobody can promise it in advance. Submit them anyway, together with the workload and proof of assessment. How the process works is under crediting ECTS and credit for work experience. Which universities qualify is best compared on Hochschulnavigator.
The levels in this subject compared
Four routes, one field, very different purposes.
| Level | ECTS | Part-time duration | Access | Purpose |
|---|---|---|---|---|
| University certificate | 5 to 30 | 1 to 2 semesters | often without a first degree, work experience is frequently enough | add one topic, no academic degree |
| Bachelor | 180, sometimes 210 | 6 to 9 years, 4 to 6 with credit | A-levels or vocational training plus years of work | first degree and foundations, entry into security operations and support work |
| Master | 60 to 120 | 3 to 5 years | a first higher education degree, often 210 ECTS required | leadership, management systems, architecture, access to a doctorate |
| MBA | 60 to 120 | 2 to 4 years | first degree plus several years of work experience | leadership and business administration, no depth in security itself |
Calculated with 10 to 15 ECTS per semester and 30 hours per ECTS. The ranges are guide values, the binding source is each programme's examination regulations. On the difference between master and MBA see MBA or master.
What the bachelor opens professionally
And where something else is required on top.
The bachelor opens entry into security operations: monitoring, incident handling, hardening systems, vulnerability management. On the organisational route it opens support work on an information security management system, so documentation, evidence and audit preparation. Both are roles you grow in, and in both the degree is often the formal condition for being considered at all.
Three limits belong with that. First, the bachelor does not lead into the leadership of a security function, which expects years of practice and usually a master or relevant certifications. Second, it is not enough for offensive security: anyone running attack simulations needs demonstrable practice, as a rule relevant certifications and a clean written engagement, because testing systems you do not own without permission is a criminal offence. Third, in public authorities, defence and critical infrastructure there are additional clearances and proofs that run independently of your degree.
An honest word on salary: the degree alone rarely changes it, the move into a security role with your own responsibility does. More under salary after your degree. What applies in your case is quickest to settle in an initial consultation.
Bachelor in IT security
The questions that come up about this level in almost every conversation.
Do I have to commit to one route already in the bachelor?
Not on day one, but with your choice of programme. The module plan decides whether your degree hangs on systems and labs or on standards, risk and audit method. The final semesters and the thesis then make the focus visible. So check the module plan before you enrol, not the name of the programme.
Do I need vocational IT training for the bachelor?
Not necessarily for admission. Without A-levels, a commercial or administrative qualification with an audit or internal review background also opens a subject-related degree, especially for the organisational route. If you lack hands-on work with networks and operating systems, that will cost you time in the first year.
How long does the bachelor take with credit transfer?
A bachelor covers 180 ECTS. If 60 are credited from IT training and an advanced qualification, 120 remain. At 10 ECTS per semester that is six years instead of nine, at 15 ECTS four instead of six. The upper limit for learning acquired outside higher education is usually 50 percent of the ECTS.
Which entry roles does the bachelor open, and which not?
It opens entry into security operations, vulnerability management and support work on an information security management system. It does not open the leadership of a security function, no offensive security without demonstrable practice, and no role that requires an official clearance or a specific certification.
Can I go straight into a master after the bachelor?
As a rule yes, if the bachelor is subject-related. Watch the volume: many master programmes require 210 ECTS on entry, so a 180 ECTS bachelor has to close the gap through bridging modules or creditable practice. Better to clarify that before you choose the bachelor than afterwards.
Which level carries in your case
Route, admission, credit transfer and a fitting programme, settled in one conversation.
The information on this page is general in nature and based on my advisory practice (last updated 31.07.2026). It does not replace an official credit transfer or recognition decision by the respective university and is not legal advice. Specific decisions are made by universities, the ZAB (Germany), the BMBWF (Austria), or the SBFI (Switzerland). I clarify binding next steps with you in the initial consultation.
