What you’ll learn in this article…
- George Mason launches 72-credit cybersecurity engineering PhD in Fall 2026.
- National University targets working professionals, while Old Dominion stays research-focused.
- Fully funded programs can cost little, while self-funded online paths exceed $60,000.
In July 2026, Virginia's State Council of Higher Education approved George Mason University's PhD in Cybersecurity Engineering, making the university's Department of Cyber Security Engineering the first in Virginia to offer that degree. The approval reflects a wider shift: cybersecurity is separating from computer science and electrical engineering into its own doctoral discipline.
New programs embed security by design and AI throughout the curriculum. For working professionals comparing online cybersecurity programs and cybersecurity certifications, the calculation no longer hinges on whether a doctoral researcher is needed. It hinges on admissions selectivity, funding tradeoffs, and how quickly PhD-level expertise alters cybersecurity career path and leadership ceilings.
George Mason's New PHD in Cybersecurity Engineering
George Mason University's Department of Cyber Security Engineering received approval from the State Council of Higher Education for Virginia (SCHEV) in July 2026 to launch a 72-credit PhD in Cybersecurity Engineering. The program is scheduled to begin in Fall 2026.1
Why This Approval Matters
The approval makes CYSE the first department in Virginia to offer a PhD specifically in cybersecurity engineering. Department chair Paulo Cesar Costa described the main challenge with SCHEV as "convincing them that cybersecurity is its own discipline," rather than a subfield of computer science. He compared the shift to how computer science once emerged from electrical engineering. Unlike a cybersecurity concentration nested inside an information technology or computer science doctorate, this is a cybersecurity Ph.D. program.
Curriculum Built Around AI and Security by Design
The interdisciplinary curriculum emphasizes "security by design" and integrates artificial intelligence throughout. That approach treats security as a core design requirement, not a bolt-on afterthought. George Mason vice president and chief AI officer Amarda Shehu noted that AI creates new attack surfaces and new defenses, which means engineers need deeper training to manage both sides of that equation. The 72 credits break down into 48 credits of coursework and 24 credits of research, spanning technical systems, policy, and human factors.1
A Department Built on Undergraduate Demand
The new PhD grew out of existing demand. The cybersecurity engineering bachelor's program launched in 2015 and grew to more than 400 students, which led the university to create the stand-alone Department of Cyber Security Engineering. The doctoral program extends that pipeline for students pursuing cybersecurity Ph.D. career paths in research, academia, or senior government roles. The program's emphasis on producing researchers and leaders matches the university's stated goal of addressing the cybersecurity workforce shortage. More details are available in George Mason's College of Engineering and Computing announcement.
Other New and Emerging Cybersecurity PHD Programs
Prospective cybersecurity PhD students now face a choice between in-person research immersion and flexible, working-professional pathways. Old Dominion University and National University illustrate how new programs are splitting along those lines.
Old Dominion University: In-Person and Research-Focused
Old Dominion University's Ph.D. in Cybersecurity is accepting applications for a Fall 2026 start, with a deadline of July 1, 2026. The program is research-based and currently offered in-person only. Its interdisciplinary focus spans AI Security, generative AI security, cyber defense, digital forensics, privacy, critical infrastructure, human-centered cybersecurity, and secure machine learning. That breadth contrasts with George Mason's engineering-first model, which emphasizes security by design and integrates AI throughout the engineering curriculum. For students who want deep methodological training across policy, systems, and human factors rather than a single engineering lens, ODU's structure may be a closer fit.
National University: A Flexible Option to Watch
National University's PhD-CY is frequently described as a working-professional-oriented path, but current official program details are limited. The university's wider reputation for flexible graduate education makes it worth monitoring for applicants who cannot relocate or pause a career. Prospective students should verify delivery format, research focus, and start dates directly with National University before applying.
What This Mix Means for Applicants
No other newly launched cybersecurity PhD programs stood out in current research, but the ODU and George Mason launches signal a trend: doctoral training is moving beyond single-department computer science tracks to meet the cybersecurity workforce shortage. Applicants now have real choices in format and research emphasis, not just one flagship option. The next step is matching your career goal, academic research or government leadership, to the program structure that will support it.
Dedicated Cybersecurity PHD Vs. CS PHD With a Security Concentration
Should you apply to a dedicated cybersecurity PhD or a computer science PhD with a security concentration? The distinction shapes your coursework, research environment, and later job options.
What the structure actually looks like
A dedicated cybersecurity PhD, such as George Mason's new program, builds the core around security-by-design, cryptography, secure systems engineering, and AI-enabled defense. These programs often live inside engineering departments, so research leans applied, mission-driven, and closely tied to government or industry partners.
A CS PhD with a security concentration keeps the general computer science core: algorithms, operating systems, theory, and programming languages. Security becomes a cluster of electives layered on top. That path can give you stronger theoretical CS breadth and more room to pivot toward software engineering, AI, or distributed systems if your interests shift.
How to choose
- Choose the dedicated PhD if you already know you want specialized cybersecurity R&D, faculty roles in security, or leadership positions shaping policy and defense strategy.
- Choose the CS concentration if keeping options open across software, AI, and security matters more than having security in the program title.
Both can lead to advanced cybersecurity career paths. The real question is whether you want security to be the entire frame or one strong specialty inside a broader CS identity.
Admissions Requirements: What It Takes to Get In
Requirements vary, but most programs look for quantitative preparation, research potential, and a strong academic record.
- Degree backgroundA bachelor's or master's in computer science, engineering, cybersecurity, or a related quantitative field is typical; some programs also accept strong applicants from psychology, management, criminology, or other social sciences.
- GPA expectationsPublished minimums range from 3.0 to 3.5+, with selective on-campus programs often clustering around 3.5. Arizona State and Northeastern list 3.5, Old Dominion 3.0–3.25, and Augusta 3.0.
- Standardized testsMany programs have made the GRE optional or no longer require it, though international applicants usually need TOEFL or IELTS. Some programs may consider GRE quantitative scores if GPA is borderline.
- Research and writingA strong statement of purpose, writing sample, or prior research experience can be a key differentiator. Some programs expect publications or professional cybersecurity experience to strengthen candidacy.
- Math and coding prerequisitesCommon expectations include calculus, discrete math, statistics or probability, and linear algebra, plus programming and networking or operating systems coursework. George Mason's program lists calculus, differential equations, linear algebra, discrete structures, probability, and statistics.
- CompetitivenessAcceptance rates are rarely published, but selectivity appears to be rising through higher GPA and math prerequisites, especially at flagship in-person programs versus more flexible online tracks.
Related Articles
Amarda Shehu, George Mason's vice president and chief AI officer, points out that AI creates new attack surfaces and new defenses, which means engineers need deeper training. That is why new cybersecurity PhD programs weave "security by design" and AI throughout the curriculum rather than treating AI as an elective add-on.
Funding, Duration, and Cost: What to Expect
The first decision most applicants face is simple: fully funded and full-time, or flexible and self-funded. The cybersecurity degree cost can range from close to nothing in a funded research program to over $60,000 in a pay-as-you-go online format. A funded program typically requires relocation and full-time study, while an online PhD lets you keep working but shifts the cost to you. The right answer depends on whether you can relocate, how fast you need to finish, and how much service obligation you are willing to accept.
Fully Funded Research PhDs
- MIT: EECS PhD students working in cybersecurity are fully funded, with full tuition and health insurance coverage plus a $4,695 monthly stipend for the 2025-26 academic year.
- Purdue: The CS PhD, including security-focused research, offers full tuition remission and a $23,289 academic-year stipend as of 2023-2024.
- Old Dominion University: As of 2025, cybersecurity PhD assistantships provide a 100% tuition waiver and $10,000 per semester for 20-hour-per-week roles. As of 2025-2026, in-state tuition runs $486 per credit and out-of-state $1,334.50 per credit, before a $154 per-credit mandatory fee. With the fee, the totals are $640 in-state and $1,488.50 out-of-state.
- George Mason University: The CyberCorps Scholarship for Service pathway can cover up to three years with full tuition, a $37,000 yearly living stipend, and a $6,000 annual professional allowance, but it carries a government service commitment. For students without an assistantship, GMU's IT PhD with cybersecurity concentrations lists estimated annual tuition of $18,060 in-state and $41,124 out-of-state for 2025-26, though rates vary by program.
Self Funded Online Programs
- National University: The online PhD in Cybersecurity charges $1,039 per credit across 60 credits, totaling about $65,490 before fees, plus a $135 course material fee. Funding is need-based only, with no research or teaching assistantships.
- Duration: The typical timeline is 40 to 44 months, faster than most research PhDs, but some working professionals stretch toward seven years.
How Long It Takes
- Research-focused PhDs usually run four to six years full time.
- Online programs can compress to under four years, but part-time students may take longer.
AI creates new attack surfaces and defenses, requiring engineers with deep training.










