Cybersecurity shows up on almost every "safe career" list right now, usually backed by a workforce-gap number pulled from somewhere. The credible version of that number comes from ISC2's own 2024 Cybersecurity Workforce Study: a global gap of roughly 4.76 million people, against an estimated global workforce of about 5.47 million -- meaning the field currently has, by ISC2's own measure, nearly as many unfilled seats as filled ones. (That figure measures what organizations say they need to be properly secured, not literal open job postings, which is a narrower and smaller number -- worth knowing before repeating it as "4.8 million open jobs.") What most "should I major in cybersecurity" advice skips is that there's no single accredited "cybersecurity major" the way there's a single MD or JD -- it's a patchwork of computer science, computer engineering, and dedicated information-security degrees, and one federally-run designation that actually tells you which programs meet a real technical bar.

What to major in depends on which side of the field you're headed toward

  • Deeply technical, hands-on roles -- penetration testing, offensive security, cyber operations for a government agency -- generally require a computer science, computer engineering, or electrical engineering foundation. The NSA's own technical track for this (covered below) explicitly requires programs to be "grounded in computer science, engineering, or electrical engineering," not a standalone security curriculum layered on top of a lighter technical base.
  • Broader cyber defense and security-operations roles -- the largest single slice of entry-level jobs, think SOC analyst, network defense, incident response -- are open to a wider set of majors, including a dedicated cybersecurity or information technology/information systems degree, which most CAE-designated schools now offer at the bachelor's level.
  • Governance, risk, and compliance (GRC) roles -- increasingly a large and non-technical share of the field as regulation expands -- draw from information systems, business, and even policy or law backgrounds layered with security certifications, not a computer science degree at all.
  • Research and next-generation defense work (cryptography, AI-security, national-security-adjacent research) sits mostly in graduate programs, often at the small set of schools research-vetted specifically for it.

The honest version of "what major" is closer to "which of these four buckets are you actually aiming at" than a single answer -- a computer science degree and a business-school information-systems degree can both lead to real cybersecurity careers, just very different ones.

The one federal designation that actually validates a program: CAE-C

The National Centers of Academic Excellence in Cybersecurity (NCAE-C) program is run by the NSA's National Cryptologic School, with CISA, the FBI, NIST, NSF, the DoD-CIO, and U.S. Cyber Command as federal partners -- not a marketing badge, a curriculum standard that a school has to formally apply for and get validated against. It splits into four tracks, and which one a school holds tells you something concrete about the program:

  • CAE-CD (Cyber Defense) -- the broadest track, open to associate, bachelor's, and graduate programs at any regionally accredited school.
  • CAE-CO (Cyber Operations) -- the deeply technical track, reserved for programs "grounded in computer science, engineering, or electrical engineering" with real hands-on lab work -- the closest match to the offensive-security and cyber-ops jobs above.
  • CAE-R (Cyber Research) -- limited to DoD schools, PhD-producing military academies, and research-intensive universities (Carnegie R1, R2, or R3).
  • Cyber AI -- a newer track layered on top of an existing CD or CO designation, specific to AI-security work.

Designations run in five-year cycles and have to be renewed, not held permanently -- Liberty University, for example, was first designated CAE-CD in 2018 and had that renewed through the 2028-29 academic year, while the University of Kansas has held CAE-CD since 2009 and added the separate CAE-R research designation in 2019, one of a small number of schools holding both.

Why it's worth checking: it gates a real, full scholarship

The practical reason to care which schools hold this designation is the CyberCorps: Scholarship for Service (SFS) program, run by NSF with OPM and DHS. SFS pays for up to three years of undergraduate or graduate cybersecurity education, and in exchange, a recipient commits to working for the U.S. government in a cybersecurity role for a period equal to however long they were funded. It isn't open at every school -- to even apply, an institution has to already hold a CAE designation (CD, CO, or R) and then separately win a competitive NSF proposal on top of that. That two-step gate is exactly why checking a school's CAE status before applying matters in dollar terms, not just prestige terms: at a non-designated school, this specific funding path doesn't exist at all, regardless of how strong the computer science program otherwise is.

How to actually check a school on your list

The designation isn't a ranking system, and there's no honest "best schools for cybersecurity" list to hand you -- hundreds of schools across nearly every state hold some form of it, spanning community colleges through research universities. The authoritative way to check any specific school is the CAE Community's own institution map, not a third-party "top 10" roundup. Check which specific track a school holds (CD alone is common; CO and R are narrower and signal something more specific about technical depth or research strength), and separately confirm current SFS participation directly on the NSF's own listing, since CAE status and active SFS funding are two different things a school can hold independently.

What this means for you

  • Pick a major based on which of the four buckets you're actually aiming at -- technical cyber-ops work wants a CS/CE/EE-grounded degree, broader defense and GRC roles are open to a dedicated cybersecurity or IT/IS degree, and non-technical GRC work is reachable from a business or policy background plus certifications.
  • If federal funding is part of your plan, verify CAE status before applying, not after. CyberCorps SFS is a real full-scholarship-plus-service-commitment program, but it's structurally unavailable at schools without the designation.
  • Don't treat CAE-CD as automatically equal to CAE-CO or CAE-R. They signal different things -- broad program validity versus deep technical rigor versus research strength -- and the one that matters depends on which bucket above you're headed toward.
  • Confirm directly with the CAE Community's institution map and the school's own financial aid office, the same way checking a school's own net price calculator beats guessing from a ranking -- designations and funding eligibility change on five-year cycles and shouldn't be assumed from an outdated list.
  • If you're weighing a technical major against a school that isn't known for it, our piece on majoring "off-brand" at a specialized school and why engineering admissions are often more competitive than the school's overall admit rate both cover angles that apply directly to a CS/CE-grounded cybersecurity path.

Sources