The short answer
Security+ first, almost always. If you do not already hold it, it is the cert that unlocks the most doors per study hour in entry and tier-1 security, and it is the one that appears as a hard filter on the most job ads. CySA+ is a strong second cert, but it is a specialisation, and specialising before you have the baseline is a common way to end up over-certified for the roles you can actually get interviews for.
The exception, which I will get to, is if you are aiming squarely at a detection-and-response role on a government or defence-adjacent contract. In that narrow case the order can flip.
What each cert actually proves
Security+ (SY0-701) is a breadth cert. It proves you understand the whole landscape at a working level: threats and attacks, architecture, identity and access, risk and governance, cryptography basics, incident response at a conceptual level. It is the cert that says "this person can hold a security conversation and will not do anything obviously dangerous". That is exactly what a hiring manager filling a tier-1 or junior security role needs to know.
CySA+ (CS0-004) is a depth cert in one slice: detection and response. It goes deep on log analysis, threat hunting, vulnerability management, and the day-to-day of a SOC analyst. It assumes you already have the breadth and tests whether you can do the analyst job. That is genuinely valuable, but only once you are pointed at the job it describes.
The mistake is reading "CySA+ is harder and more advanced" as "CySA+ is better". It is not better, it is narrower. A narrower cert is more valuable when it matches your target role and less valuable when it does not.
What the job ads actually say
When I read through current SOC analyst and security-tier-1 postings, the pattern was consistent enough to plan around. Security+ showed up as a stated requirement far more often than CySA+, and it showed up in the part of the ad that screens applications. CySA+ tended to appear in the "desirable" or "or equivalent experience" section, the part a recruiter does not actually filter on.
There is a real reason for that beyond habit. Security+ is the cert that satisfies the baseline certification requirements a lot of employers and contracts are written against. In the US defence space specifically, Security+ is an approved baseline for IAT Level II roles under DoD 8140 (the framework that replaced 8570). That single fact puts Security+ on an enormous number of cleared and contractor job descriptions as a non-negotiable, which is why it behaves like a filter and CySA+ behaves like a bonus.
So if you are optimising for "get past the application screen", Security+ does more work. If you already have it, the question becomes whether CySA+ moves you past a different screen, and for most non-SOC-specific roles it does not.
When CySA+ first is actually the right call
Flip the order if all of this is true: you are specifically targeting a SOC analyst or detection-and-response role, you are on or aiming at a US government or defence contract, and the role lists CySA+ as the cyber-defence baseline. DoD 8140 maps certain analyst-track work roles (the cyber defence analyst lane) to CySA+ specifically, not Security+. If that is your exact target, CySA+ is the cert on the filter and Security+ is the bonus, and the order I just argued for reverses.
That is a narrow case. For the much larger pool of people who are 1 to 3 years into a helpdesk or tier-1 role and want to move toward security generally, you are not in it. Security+ first.
The CS0-004 update most posts have not caught up to
If you are reading older advice, you will see CySA+ referred to as CS0-003. That version has moved on. The current exam is CS0-004, and a lot of "should I do CySA+" threads are quietly out of date because they are weighing up the old objectives.
The practical effect for your decision is small but worth knowing: the detection-and-response focus is, if anything, sharper in the current version, which makes the "only do this if you are aiming at the analyst job" advice stronger, not weaker. It is more of a specialist cert now, not less. Check you are studying CS0-004 materials and not CS0-003 leftovers, because the objectives shifted and so did some of the tooling emphasis.
The order I would actually do
1. Security+ (SY0-701) first. Get the baseline that clears the most filters.
2. Then work, not another cert. The single biggest return after Security+ is hands-on time in a role where you touch security work, even tangentially. CySA+ studied with zero analyst exposure is abstract and fades fast. CySA+ studied while you are doing or shadowing SOC work sticks, because the labs map to things you have actually seen.
3. CySA+ (CS0-004) when you are SOC-bound. Once you are pointed at a detection-and-response role, or you are already adjacent to one and want the credential to make the move official, that is when CySA+ earns its study hours.
The thing to avoid is treating certs as a ladder you climb in sequence regardless of where you are trying to go. The ladder framing is why people end up with three certs and no interviews. Match the cert to the next job, not to the cert you did last.
Where ReadRoost fits
Whichever order you land on, the part that actually moves the needle is reps on exam-style questions with explanations, not re-watching videos you have already seen. ReadRoost has practice packs for both Security+ (SY0-701) and CySA+ (CS0-004), with per-domain analytics so you can see which objectives are dragging your score before exam day rather than after. Create a free account, start with the cert that matches your next job, and use the weak-domain breakdown to spend your study time where it changes the result.