Where to Publish in Cybersecurity: A Guide for Doctoral Researchers
Most advice about publishing in security starts and stops with four conferences. IEEE S&P, CCS, USENIX Security and NDSS are the venues that get named in hiring committees and grant reports, and they are where the field’s flagship work goes.
They are also, for a first doctoral paper, close to the worst place to start.
We track 48 distinct security and cryptography conference series. This is what the ladder actually looks like, and where a first paper realistically lands.
The Big Four, and why the numbers are misleading
Here is what our data holds for acceptance rates at the top:
| Venue | Rate | Rank |
|---|---|---|
| CCS | 14.5% | A* |
| IEEE S&P | 14.8% | A* |
| NDSS | 16.1% | A* |
| USENIX Security | 17.0% | A |
A tight band between 14 and 17%. Those four reject roughly five papers in six.
But look at what happens when you stay at A* and move sideways into cryptography:
| Venue | Rate | Rank |
|---|---|---|
| Eurocrypt | 21.0% | A* |
| CRYPTO | 24.3% | A* |
| Asiacrypt | 29.3% | A* |
Same tier, twice the acceptance rate. This is not a difference in quality bar, it is a difference in submission culture, and it is the single most useful thing to understand before you pick a target. We found the same pattern across all of computer science in our acceptance-rate analysis: the number tracks your subfield far more than it tracks prestige.
If your work is cryptographic, the IACR conferences are a more open door than the systems security flagships, at no cost to how the paper is read. If your work is systems or network security, you are in the 14 to 17% band whether you like it or not.
The tier that actually takes first papers
This is the part the standard advice skips. Between the Big Four and nowhere, there is a substantial middle:
| Venue | Rate | Rank |
|---|---|---|
| SOUPS | 19.1% | B |
| ACSAC | 20.7% | A |
| RAID | 25.0% | A |
| PETS | 26.0% | A |
ACSAC and RAID are both CORE A and both take roughly one paper in four. ESORICS, DSN, AsiaCCS, CSF and WiSec sit in the same territory. For applied cryptography, ACNS, CHES, TCC and Financial Cryptography are all real venues that will read a good paper seriously.
Below that again is a tier of Springer LNCS conferences that exists more or less for the purpose you need it for. ISC, ICICS, ACISP, CANS and IFIP SEC all publish in indexed series, run conventional review, and are navigable in a way a 3,000-submission conference is not. ARES belongs here too and is worth singling out, because its workshop programme is enormous: recent editions have run fourteen regular workshops alongside eight EU project workshops.
None of these will carry a job talk on their own. All of them will get your work indexed, get you a talk, and get you the feedback that makes the next paper better.
Two things about deadlines nobody tells you
Several security venues run more than one submission round per year. This changes the planning maths completely, because missing a deadline stops being a twelve-month setback.
- HOST runs two rounds. For 2027 they closed 22 July and 8 November 2026.
- ICICS runs two. For 2026 they were 12 March and 1 June.
- ACISP runs two. For 2026, 27 November 2025 and 26 February 2026.
- ACNS runs two cycles.
If a paper is three weeks from ready and the deadline is tomorrow, a two-round venue is often the better call than a rushed submission to a single-round one.
The second thing is the gap between notification and conference. Across the security venues we track it runs long, but not always. We measured this across the whole dataset in how conference timing actually works, and the tail is genuinely brutal: Eurocrypt 2026 notified authors six days before the conference opened. Do not assume you can wait for the accept email before booking anything.
What is open right now
These are the security deadlines we currently hold for the coming year:
| Deadline | Venue | Rank | Notification |
|---|---|---|---|
| 21 Aug 2026 | AsiaCCS 2027 | A | 13 Nov 2026 |
| 17 Sep 2026 | Eurocrypt 2027 | A* | 18 Jan 2027 |
| 17 Sep 2026 | Financial Cryptography 2027 | - | 5 Nov 2026 |
| 24 Sep 2026 | ACNS 2027 | B | 26 Nov 2026 |
| 8 Nov 2026 | HOST 2027 | - | TBA |
| 2 Dec 2026 | DSN 2027 | A | 18 Mar 2027 |
That is what we have recorded, not a complete census: plenty of venues have not published their next CFP yet. The deadlines page is kept current and sorted by what closes soonest.
Workshops are a legitimate first venue
A workshop paper is not a conference paper and nobody pretends otherwise. It is still the fastest way to get work in front of the right people, and several of the best ones attach to the venues you eventually want.
USENIX Security co-locates WOOT, the Workshop on Offensive Technologies, and VehicleSec. It also runs GREPSEC, which is explicitly a research workshop for PhD students and exists to bring people into the field. If you are early and unsure, that is close to a purpose-built answer.
CCS, NDSS and S&P all carry substantial workshop programmes on the same model. A workshop at a top venue puts you in the building, in the hallway conversations, and on a programme that the people you want to know are also attending.
Industry conferences are a different currency
Black Hat USA, DEF CON, RSAC and OWASP Global AppSec are not publication venues in the sense your committee cares about. Black Hat Briefings are peer reviewed, but the review is for a practitioner audience and the output is a talk rather than an indexed paper.
They matter for different reasons: reach, industry contact, and the chance to find out whether the people who would deploy your work think it survives contact with reality. We wrote about that trade-off in more detail in choosing between academic and industry conferences.
The practical answer for most doctoral researchers is not either/or. Publish in the academic venues, then take the same work to a practitioner conference once it is out.
A sequence that works
If you are one or two years in and have a first result:
- Target the accessible tier first. ESORICS, ACSAC, RAID, PETS or an LNCS venue like ISC or ICICS. Get the paper published, indexed and presented.
- Use a multi-round venue if the timing is tight. A second round in three months beats a rushed submission now.
- Submit a workshop paper in parallel at a venue you eventually want to publish at properly.
- Aim at the Big Four with your second or third substantial result, once you know what a finished security paper looks like and have had a programme committee tell you.
The mistake is not aiming high. It is aiming only high, collecting three rejections in eighteen months, and finishing your second year with nothing indexed.
Caveats worth stating
Acceptance rates here are drawn from different years, mostly 2024 and 2025, and we record the year against each. They are self-reported and inconsistently defined: some venues count full research-track papers only, others fold in short papers and posters. Treat them as a band, not a decimal.
Ranks are CORE where we hold one. Several strong venues, including Financial Cryptography and most of the LNCS tier, are unranked, and that reflects the portal’s coverage rather than the venue’s quality.
We track 48 security series with dates, venues and deadlines, and update them as new editions publish. If something here is wrong or out of date, tell us.