New Cybersecurity PhD Programs 2026: Career Guide
Updated September 6, 20269 min read

New PhD Programs in Cybersecurity: Is One Right for You?

From George Mason's new engineering PhD to funded online options, here's what these programs mean for your career.

What you’ll learn in this article…

  • George Mason launches 72-credit cybersecurity engineering PhD in Fall 2026.
  • National University targets working professionals, while Old Dominion stays research-focused.
  • Fully funded programs can cost little, while self-funded online paths exceed $60,000.

In July 2026, Virginia's State Council of Higher Education approved George Mason University's PhD in Cybersecurity Engineering, making the university's Department of Cyber Security Engineering the first in Virginia to offer that degree. The approval reflects a wider shift: cybersecurity is separating from computer science and electrical engineering into its own doctoral discipline.

New programs embed security by design and AI throughout the curriculum. For working professionals comparing online cybersecurity programs and cybersecurity certifications, the calculation no longer hinges on whether a doctoral researcher is needed. It hinges on admissions selectivity, funding tradeoffs, and how quickly PhD-level expertise alters cybersecurity career path and leadership ceilings.

George Mason's New PHD in Cybersecurity Engineering

George Mason University's Department of Cyber Security Engineering received approval from the State Council of Higher Education for Virginia (SCHEV) in July 2026 to launch a 72-credit PhD in Cybersecurity Engineering. The program is scheduled to begin in Fall 2026.1

Why This Approval Matters

The approval makes CYSE the first department in Virginia to offer a PhD specifically in cybersecurity engineering. Department chair Paulo Cesar Costa described the main challenge with SCHEV as "convincing them that cybersecurity is its own discipline," rather than a subfield of computer science. He compared the shift to how computer science once emerged from electrical engineering. Unlike a cybersecurity concentration nested inside an information technology or computer science doctorate, this is a cybersecurity Ph.D. program.

Curriculum Built Around AI and Security by Design

The interdisciplinary curriculum emphasizes "security by design" and integrates artificial intelligence throughout. That approach treats security as a core design requirement, not a bolt-on afterthought. George Mason vice president and chief AI officer Amarda Shehu noted that AI creates new attack surfaces and new defenses, which means engineers need deeper training to manage both sides of that equation. The 72 credits break down into 48 credits of coursework and 24 credits of research, spanning technical systems, policy, and human factors.1

A Department Built on Undergraduate Demand

The new PhD grew out of existing demand. The cybersecurity engineering bachelor's program launched in 2015 and grew to more than 400 students, which led the university to create the stand-alone Department of Cyber Security Engineering. The doctoral program extends that pipeline for students pursuing cybersecurity Ph.D. career paths in research, academia, or senior government roles. The program's emphasis on producing researchers and leaders matches the university's stated goal of addressing the cybersecurity workforce shortage. More details are available in George Mason's College of Engineering and Computing announcement.

Other New and Emerging Cybersecurity PHD Programs

Prospective cybersecurity PhD students now face a choice between in-person research immersion and flexible, working-professional pathways. Old Dominion University and National University illustrate how new programs are splitting along those lines.

Old Dominion University: In-Person and Research-Focused

Old Dominion University's Ph.D. in Cybersecurity is accepting applications for a Fall 2026 start, with a deadline of July 1, 2026. The program is research-based and currently offered in-person only. Its interdisciplinary focus spans AI Security, generative AI security, cyber defense, digital forensics, privacy, critical infrastructure, human-centered cybersecurity, and secure machine learning. That breadth contrasts with George Mason's engineering-first model, which emphasizes security by design and integrates AI throughout the engineering curriculum. For students who want deep methodological training across policy, systems, and human factors rather than a single engineering lens, ODU's structure may be a closer fit.

National University: A Flexible Option to Watch

National University's PhD-CY is frequently described as a working-professional-oriented path, but current official program details are limited. The university's wider reputation for flexible graduate education makes it worth monitoring for applicants who cannot relocate or pause a career. Prospective students should verify delivery format, research focus, and start dates directly with National University before applying.

What This Mix Means for Applicants

No other newly launched cybersecurity PhD programs stood out in current research, but the ODU and George Mason launches signal a trend: doctoral training is moving beyond single-department computer science tracks to meet the cybersecurity workforce shortage. Applicants now have real choices in format and research emphasis, not just one flagship option. The next step is matching your career goal, academic research or government leadership, to the program structure that will support it.

Dedicated Cybersecurity PHD Vs. CS PHD With a Security Concentration

Should you apply to a dedicated cybersecurity PhD or a computer science PhD with a security concentration? The distinction shapes your coursework, research environment, and later job options.

What the structure actually looks like

A dedicated cybersecurity PhD, such as George Mason's new program, builds the core around security-by-design, cryptography, secure systems engineering, and AI-enabled defense. These programs often live inside engineering departments, so research leans applied, mission-driven, and closely tied to government or industry partners.

A CS PhD with a security concentration keeps the general computer science core: algorithms, operating systems, theory, and programming languages. Security becomes a cluster of electives layered on top. That path can give you stronger theoretical CS breadth and more room to pivot toward software engineering, AI, or distributed systems if your interests shift.

How to choose

  • Choose the dedicated PhD if you already know you want specialized cybersecurity R&D, faculty roles in security, or leadership positions shaping policy and defense strategy.
  • Choose the CS concentration if keeping options open across software, AI, and security matters more than having security in the program title.

Both can lead to advanced cybersecurity career paths. The real question is whether you want security to be the entire frame or one strong specialty inside a broader CS identity.

Admissions Requirements: What It Takes to Get In

Requirements vary, but most programs look for quantitative preparation, research potential, and a strong academic record.

  • Degree background
    A bachelor's or master's in computer science, engineering, cybersecurity, or a related quantitative field is typical; some programs also accept strong applicants from psychology, management, criminology, or other social sciences.
  • GPA expectations
    Published minimums range from 3.0 to 3.5+, with selective on-campus programs often clustering around 3.5. Arizona State and Northeastern list 3.5, Old Dominion 3.0–3.25, and Augusta 3.0.
  • Standardized tests
    Many programs have made the GRE optional or no longer require it, though international applicants usually need TOEFL or IELTS. Some programs may consider GRE quantitative scores if GPA is borderline.
  • Research and writing
    A strong statement of purpose, writing sample, or prior research experience can be a key differentiator. Some programs expect publications or professional cybersecurity experience to strengthen candidacy.
  • Math and coding prerequisites
    Common expectations include calculus, discrete math, statistics or probability, and linear algebra, plus programming and networking or operating systems coursework. George Mason's program lists calculus, differential equations, linear algebra, discrete structures, probability, and statistics.
  • Competitiveness
    Acceptance rates are rarely published, but selectivity appears to be rising through higher GPA and math prerequisites, especially at flagship in-person programs versus more flexible online tracks.
Did You Know?

Amarda Shehu, George Mason's vice president and chief AI officer, points out that AI creates new attack surfaces and new defenses, which means engineers need deeper training. That is why new cybersecurity PhD programs weave "security by design" and AI throughout the curriculum rather than treating AI as an elective add-on.

Funding, Duration, and Cost: What to Expect

The first decision most applicants face is simple: fully funded and full-time, or flexible and self-funded. The cybersecurity degree cost can range from close to nothing in a funded research program to over $60,000 in a pay-as-you-go online format. A funded program typically requires relocation and full-time study, while an online PhD lets you keep working but shifts the cost to you. The right answer depends on whether you can relocate, how fast you need to finish, and how much service obligation you are willing to accept.

Fully Funded Research PhDs

  • MIT: EECS PhD students working in cybersecurity are fully funded, with full tuition and health insurance coverage plus a $4,695 monthly stipend for the 2025-26 academic year.
  • Purdue: The CS PhD, including security-focused research, offers full tuition remission and a $23,289 academic-year stipend as of 2023-2024.
  • Old Dominion University: As of 2025, cybersecurity PhD assistantships provide a 100% tuition waiver and $10,000 per semester for 20-hour-per-week roles. As of 2025-2026, in-state tuition runs $486 per credit and out-of-state $1,334.50 per credit, before a $154 per-credit mandatory fee. With the fee, the totals are $640 in-state and $1,488.50 out-of-state.
  • George Mason University: The CyberCorps Scholarship for Service pathway can cover up to three years with full tuition, a $37,000 yearly living stipend, and a $6,000 annual professional allowance, but it carries a government service commitment. For students without an assistantship, GMU's IT PhD with cybersecurity concentrations lists estimated annual tuition of $18,060 in-state and $41,124 out-of-state for 2025-26, though rates vary by program.

Self Funded Online Programs

  • National University: The online PhD in Cybersecurity charges $1,039 per credit across 60 credits, totaling about $65,490 before fees, plus a $135 course material fee. Funding is need-based only, with no research or teaching assistantships.
  • Duration: The typical timeline is 40 to 44 months, faster than most research PhDs, but some working professionals stretch toward seven years.

How Long It Takes

  • Research-focused PhDs usually run four to six years full time.
  • Online programs can compress to under four years, but part-time students may take longer.
AI creates new attack surfaces and defenses, requiring engineers with deep training.
Amarda Shehu, George Mason University vice president and chief AI officer

Recent News

Recent Articles

In this article

Follow us