Quick answer

For most candidates, the Kubernetes certification path is not a straight line. KCNA and KCSA are foundational associate credentials; CKA and CKAD are different hands-on professional roles; CKS is the security specialization that requires a previous CKA pass.

If your goal is Kubestronaut status, the current program uses KCNA, KCSA, CKA, CKAD and CKS, but that is a broader goal than most candidates need for one job decision.

Which Certification Branch Fits Your Role?

Choose the Kubernetes branch by role: KCNA for foundations, KCSA for foundational security, CKA for administration, CKAD for application development and CKS for advanced security after CKA. The path is not a compulsory linear sequence.

GoalBest-fit credentialWhat changes next
Understand Kubernetes/cloud-native fundamentalsKCNAMove to CKA for administration or CKAD for application development when you need hands-on validation.
Understand cloud-native security foundationsKCSABuild administration depth with CKA if your goal is eventually CKS.
Operate Kubernetes clustersCKAAdd CKS when security specialization is relevant.
Build/deploy Kubernetes applicationsCKADCKA is optional unless your role also includes cluster administration or you later want CKS.
Secure Kubernetes platformsCKSYou must have previously passed CKA before attempting CKS.

What Is Required and What Is Merely Helpful?

The current Linux Foundation/CNCF program information makes CKA the stated prerequisite for CKS. KCNA and KCSA can be useful preparation stages, but they are not stated prerequisites for CKA, CKAD or CKS.

Is Kubestronaut a Useful Optional Portfolio Goal?

The current Kubestronaut program is built around five Kubernetes certifications: KCNA, KCSA, CKA, CKAD and CKS. Linux Foundation also sells a Kubestronaut bundle. That can make sense if the status itself is your explicit goal; it is excessive if you only need one role-specific credential.

How Does Renewal Affect Certification Path Planning?

CARE can change the most efficient Kubernetes renewal path because qualifying higher-level certifications can renew or reinstate previously earned lower-level credentials. Current relationships include CKA or CKAD → KCNA from 1 January 2026, CKS → KCSA from 1 January 2026, and CKS → CKA from 18 June 2026; Linux Foundation also describes a CKS cascade that can keep eligible KCSA, CKA and KCNA credentials current together.

See validity and renewal rules →

Should You Plan One Certification at a Time?

Start with the credential that matches your next concrete role objective. If you later decide to pursue multiple exams, compare bundle pricing at that point rather than buying a large certification bundle months before you are ready.

Frequently asked questions

What is the first Kubernetes certification?

There is no mandatory first exam. KCNA is the foundational associate credential; experienced candidates can choose CKA or CKAD directly because those programs currently state no prerequisites.

Do I need CKA before CKS?

Yes. You must have previously passed CKA before attempting CKS.

Which certifications are used for Kubestronaut?

The current program uses KCNA, KCSA, CKA, CKAD and CKS.

Can CKA or CKAD renew KCNA?

Yes. Under current CARE rules, achieving or recertifying CKA or CKAD on or after 1 January 2026 can renew or reinstate a previously earned KCNA.

Can CKS renew KCSA and CKA?

Yes. Current CARE rules allow CKS to renew or reinstate a previously earned KCSA from 1 January 2026 and a previously earned CKA from 18 June 2026; eligible KCNA renewal can cascade through CKA.

Sources checked

Current KCNA, KCSA, CKA, CKAD and CKS role paths, formats, prerequisites and 2026 CARE renewal relationships on this page were rechecked against the first-party sources below on 7 Sep 2026. Recheck the official product or policy page before purchase or exam day because changeable terms can move.

Last fact check: 7 Sep 2026