IT security master alongside your job
The master is the level where contributing turns into owning. This page covers entry, the ECTS trap, leadership and management systems, and when a certification delivers more than a degree. On the subject itself see IT security by distance learning.
When the master is the right level
And when a certification is the better deal.
The master is right if you want to move from delivery into responsibility: leading a security function, building and running an information security management system, security architecture beyond single systems, or consulting where you have to take a position towards clients and regulators. It is also the usual entry to a doctorate, see doctorate alongside work.
It is the wrong route if your goal is a specific role that requires a specific certification. This subject has two parallel worlds of evidence, and they do not replace each other. Certifications prove current method and tool knowledge, they are quick to acquire and have to be renewed regularly. The master delivers method, law and context, and it does not expire. The sober rule: read ten adverts for the role you want. If they ask for an academic degree, you need the master. If they ask for a certification, you need that, on top. Many adverts ask for both.
How the level works in general is under part-time master. If your first degree is not enough, the bachelor in IT security is the entry point.
Which bachelor is enough, and which is not
The technical and the organisational route open to different degrees.
What is required is a first degree that qualifies you for a profession. Clearly related are computer science, business informatics, IT security and technical engineering subjects. How far the door is open for first degrees from other fields depends on the orientation of the programme:
- Technically oriented masters require documented grounding in networks, operating systems and programming. If it is missing, bridging modules are added, usually one extra semester.
- Management oriented masters are more open. First degrees in business, law or administration are frequently accepted when relevant work experience comes with them, for example from internal review, compliance or quality management.
The second point costs more people their place than the first. Many master programmes require 210 ECTS on entry, while a part-time bachelor often carries only 180. You close that gap of 30 points with a 120 ECTS master that accepts 180, with bridging modules, or with credit for relevant professional practice. Without any first degree a master is possible only in narrow exceptions, see master without a bachelor. If you are coming from practice, the frame is under master after work experience.
How long it really takes
A master credits far less than a bachelor.
Master programmes sit between 60 and 120 ECTS. The arithmetic: 120 ECTS at 15 ECTS per semester makes eight semesters, so four years. At 10 ECTS per semester it becomes six. A 90 ECTS programme at 15 ECTS per semester takes three years. The thesis usually occupies one of those semesters and needs more connected time than any module before it, which alongside on-call duty is the hardest stretch.
On credit transfer, a sober expectation: at master level universities credit far more cautiously than in a bachelor. Work experience rarely turns into a block of points here, it is more useful as an admission argument or as the topic of your thesis. Realistically creditable are single modules from an earlier, unfinished master programme and university certificates that carry ECTS. Pure vendor certifications without a university link are rarely translated into points, however valuable they are professionally.
How the process works is under crediting ECTS and credit for work experience. Which universities in the German-speaking region run suitable programmes is best compared on Hochschulnavigator.
The levels in this subject compared
Four routes, one field, very different purposes.
| Level | ECTS | Part-time duration | Access | Purpose |
|---|---|---|---|---|
| University certificate | 5 to 30 | 1 to 2 semesters | often without a first degree, work experience is frequently enough | add one topic, no academic degree |
| Bachelor | 180, sometimes 210 | 6 to 9 years, 4 to 6 with credit | A-levels or vocational training plus years of work | first degree and foundations, entry into security operations and support work |
| Master | 60 to 120 | 3 to 5 years | a first higher education degree, often 210 ECTS required | leadership, management systems, architecture, access to a doctorate |
| MBA | 60 to 120 | 2 to 4 years | first degree plus several years of work experience | leadership and business administration, no depth in security itself |
Calculated with 10 to 15 ECTS per semester and 30 hours per ECTS. The ranges are guide values, the binding source is each programme's examination regulations. If you want general leadership rather than subject depth, see MBA or master and part-time MBA.
Which step is realistic afterwards
The master opens responsibility, not automatically the next pay grade.
The realistic step leads in three directions. Into leadership, meaning responsibility for a security function, a team and a budget. Into management systems, where you build an ISMS, assess risk, own audits and provide evidence to clients and regulators. And into architecture and consulting, where you carry requirements into projects, review designs and assess suppliers. The third field has the most predictable hours, the first the most responsibility.
And the limits: the master replaces neither practice nor certification. Many leadership roles expect both, and without years in operations you lack credibility with your own team. In public authorities, defence and critical infrastructure there are clearances and proofs that run independently of the degree. On salary the same applies as everywhere: the changed role moves it, not the title, see salary after your degree. If you are moving in from another discipline, the frame is under career change through a degree.
Master in IT security
The questions that come up about this level in almost every conversation.
Can I enter an IT security master with a bachelor from another field?
Often yes, but usually with conditions. Technical programmes require documented grounding in networks, operating systems and programming. Management oriented programmes are more open and accept first degrees in business, law or administration when relevant work experience comes with them. Always submit module descriptions, not just the certificate.
What do I do if my bachelor only has 180 ECTS?
Three routes come into question. A 120 ECTS master that accepts 180 on entry, because the usual 300 ECTS are reached at the end. A programme that closes the gap with bridging modules. Or credit for relevant professional practice against the missing points. The university decides case by case.
Master or certification, which counts more for a leadership role?
It depends on what is being filtered. Many adverts for security leadership list both, because a certification evidences current method knowledge and the master the formal qualification. Where a specific certification is explicitly required, no degree replaces it. Where an academic degree is the condition, no certificate replaces that.
Do I need the master to build an ISMS?
Formally no. Building an information security management system is not a protected activity, what counts is method knowledge and experience. The master helps in two places: it delivers risk method, law and audit logic as a coherent whole, and in larger organisations and the public sector it is frequently the formal condition for the role.
Does the master open the route to a doctorate?
As a rule yes, a master is the usual entry to a doctorate. Whether a faculty accepts you also depends on your grade average, your topic and a supervision commitment. If you know the goal early, choose a programme with a solid research component and write the master thesis towards your later topic.
Which level carries in your case
Entry, the ECTS gap, credit transfer and a fitting programme, settled in one conversation.
The information on this page is general in nature and based on my advisory practice (last updated 31.07.2026). It does not replace an official credit transfer or recognition decision by the respective university and is not legal advice. Specific decisions are made by universities, the ZAB (Germany), the BMBWF (Austria), or the SBFI (Switzerland). I clarify binding next steps with you in the initial consultation.
