› reference · certifications

Cybersecurity certifications

Each cert is mapped to the domains it centrally covers in the SecProve Cyber Systems Model, plus known coverage gaps, cost, and typical study time. Click any cert for the full breakdown.

Directory of 466 certifications · grouped by domain · sub-grouped by level so you can read the progression.

↔ Compare certificationsPick up to 3 to see cost, exam, salary, and domain coverage side-by-side.

Personalised cert recommendations

Signed-in users get a tailored shortlist computed from their career goal, their per-domain proficiency, and the cert's SecProve quality score — no guessing.

GCFA
GIAC / SANS
Personalised reasoning hidden until sign-in.
A+
CompTIA
Personalised reasoning hidden until sign-in.
GCIH
GIAC / SANS
Personalised reasoning hidden until sign-in.
Sign in to compute
kind
region
≥7/10 in

A · Cybersecurity

22 domains
A1Governance, Risk & Compliance107 certs
AssociateSome security or adjacent experience assumed. Stepping stones from entry to professional.
APMG 20000F·APMG-International

APMG ISO/IEC 20000 Foundation

1 core domains$400
APMG 27001F·APMG-International

APMG ISO/IEC 27001 Foundation

25.5/40
1 core domains$400
BCS FISMP·BCS

BCS Foundation Certificate in Information Security Management Principles

1 core domains$200
C CS F·Mile2

IBITGQ Certified Cyber Security Foundation

1 core domains$400
CIISec ICSF·CIISec

CIISec Information and Cybersecurity Fundamentals

1 core domains$250
CIS F·IBITGQ

IBITGQ Certified ISO 27001 Information Security Management Specialist Foundation

1 core domains$295
CITGP·Identity Management Institute

IBITGQ Certified in Implementing IT Governance - Foundation & Principles

1 core domains$295
DACRP·DRI International

DRI Associate Cyber Resilience Professional

1 core domains$800
EXIN 27001F·EXIN

EXIN ISO/IEC 27001 Foundation

1 core domains$295
Fair Fdn·The Open Group

Fair Institute Analysis Fundamentals

1 core domains$195
FEXIN·EXIN

EXIN Information Security Foundation

1 core domains$295
GFACT·GIAC

GIAC Foundational Cybersecurity Technologies

25.0/40
2 core domains$97960120 hrs
GISF·GIAC

GIAC Information Security Fundamentals

22.0/40
1 core domains$9794080 hrs
ITIL Fdn·Axelos

ITIL Foundation is the established entry point into IT service management and teaches the common vocabulary and core principles of the ITIL framework. The certification is widely recognized globally and is required by many organizations as a baseline qualification for IT operations roles. In February 2026, ITIL Version 5 was released with AI-native enhancements and a unified product and service lifecycle model; ITIL-4 holders can transition via a shortened upgrade path. The exam content itself is conceptual and practice-oriented, but not a technical deep-dive – candidates without IT operations experience typically find it more challenging than expected. For pure cybersecurity careers, the certificate has limited depth, but is valuable for anyone working in security-relevant service management roles.

29.5/40
1 core domains$310
M_o_R Fdn·Axelos

Axelos M_o_R Framework Foundation

1 core domains$310
PECB 27001F·PECB

PECB ISO/IEC 27001 Foundation

26.0/40
1 core domains$1,1004080 hrs
PECB 27005F·PECB

PECB ISO/IEC 27005 Foundation

24.0/40
1 core domains$1,1004080 hrs
PECB 27032F·PECB

PECB ISO/IEC 27032 Foundation

21.5/40
1 core domains$1,1004080 hrs
S-ISF·SECO

SECO Information Security Foundation

1 core domains$295
SABSA SCF·SABSA

SABSA Chartered Security Architect - Foundation Certificate

22.0/40
2 core domains$1,10060120 hrs
SC-900·Microsoft

Microsoft Certified: Security, Compliance, and Identity Fundamentals

26.5/40
3 core domains$992060 hrs
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
AIGP·IAPP

AI risk, governance, and regulatory literacy (EU AI Act, NIST AI RMF).

20.5/40
3 core domains$550 + $250/yr4080 hrs
APMG 20000A·APMG-International

APMG ISO/IEC 20000 Auditor

25.5/40
1 core domains$400
APMG 20000P·APMG-International

APMG ISO/IEC 20000 Practitioner

1 core domains$400
APMG 27001A·APMG-International

APMG ISO/IEC 27001 Auditor

28.0/40
1 core domains$400
APMG 27001P·APMG-International

APMG ISO/IEC 27001 Practitioner

27.5/40
1 core domains$400
BCS PCIAA·BCS

BCS Practitioner Certificate in Information Assurance Architecture

25.5/40
1 core domains$350
BCS PCIRM·BCS

BCS Practitioner Certificate in Information Risk Management

25.5/40
1 core domains$350
C)HISSP·Mile2

Mile2 Certified Healthcare Information Systems Security Practitioner

1 core domains$400
C)ISCAP·Mile2

Mile2 Information Systems Certification and Accreditation Professional

1 core domains$400
C)ISMS-LA·Mile2

Mile2 Certified Information security Management Systems Lead Auditor

1 core domains$400
C)ISRM·Mile2

Mile2 Certified Information Systems Risk Manager

1 core domains$400
C)ISSA·Mile2

Mile2 Certified Information Systems Security Auditor

1 core domains$400
C)ISSM·Mile2

Mile2 Certified Information Systems Security Manager

1 core domains$400
C)ISSO·Mile2

Mile2 Certified Information Systems Security Officer

1 core domains$400
CC·ISC2

The CC is ISC2's entry-level certification without experience requirements and explicitly targets career starters, career changers, and students. Notably, ISC2 periodically offers CC training and the exam for free (as part of the 'One Million Certified' initiative), which has significantly increased market penetration. Content covers five domains: Security Principles, Incident Response, Access Control, Network Security, and Security Operations – at a solid but intentionally broad entry level. As a stepping stone to SSCP or CISSP it is well-suited; as a standalone credential it carries less weight than Security+. From September 2026, a new Exam Outline applies.

25.5/40
2 core domains$0 + $125/yr3080 hrs
CCP·Unbekannt

EC First Certified CCMC Professional

1 core domains$500
CCRMP·Risk Management Society (RIMS)

IBITGQ Certified in Managing Cyber Security Risk

1 core domains$685
CCSA·Check Point

EC First Certified Cyber Security Architect

27.5/40
1 core domains$250
CGRC·ISC2

(ISC)2 Certified in Governance, Risk and Compliance

22.0/40
1 core domains$599 + $125/yr60120 hrs
CIPM·IAPP

Running a privacy program end-to-end.

22.0/40
2 core domains$550 + $250/yr40100 hrs
CIPP·IAPP

IAPP Certified Information Privacy Professional

25.5/40
2 core domains$55060120 hrs
CIS IA·IBITGQ

IBITGQ Certified ISO 27001 Information Security Management Specialist Internal Auditor

1 core domains$595
CIS LA·IBITGQ

IBITGQ Certified ISO 27001 Information Security Management Specialist Lead Auditor

1 core domains$695
CIS RM·IBITGQ

IBITGQ Certified ISO 27005 Information Security Management Specialist Risk Management

1 core domains$595
CISA·ISACA

IS audit, governance, control testing, and assurance.

28.5/40
1 core domains$760 + $45/yr120250 hrs
CLCSM·PECB

PECB Lead Cloud Security Manager

24.0/40
2 core domains$1,10080160 hrs
CRAGE·EC-Council

EC-Council certification for responsible AI governance and ethics. Focus on oversight, risk management, regulatory alignment (NIST AI RMF, ISO 42001), accountability across the AI lifecycle. Brand new since February 2026.

13.5/40
2 core domains$450 + $80/yr4080 hrs
CRAI·ISACA

AI risk management and governance — emerging blueprint, expect revisions.

18.0/40
3 core domains$575 + $45/yr4080 hrs
CRISC·ISACA

Enterprise risk identification, assessment, and response + IT controls.

24.0/40
2 core domains$760 + $45/yr100200 hrs
CSBA·ISBOK

QAI Certified Software Business Analyst

1 core domains$200
CSCS·Tigerscheme

EC First Certified Security Compliance Specialist

1 core domains$1,500
CTPRA·Shared Assessments

Shared Assessment Certified Third-Party Risk Assessor

1 core domains$800
CTPRP·Shared Assessments

Shared Assessment Certified Third-Party Risk Professional

30.0/40
1 core domains$800
DCBCA·INE/eLearnSecurity

DRI Certified Business Continuity Auditor

1 core domains$200
DCBCLA·INE/eLearnSecurity

DRI Certified Business Continuity Lead Auditor

1 core domains$200
DCCRP·DRI International

DRI Certified Cyber Resilience Professional

27.0/40
1 core domains$800
DCRMP·Risk Management Society (RIMS)

DRI Certified Risk Management Professional

1 core domains$350
ECSS·EC-Council

EC Council Certified Security Specialist

16.5/40
2 core domains$250 + $80/yr4080 hrs
EISM·EC-Council

EC Council Information Security Manager

13.5/40
2 core domains$450 + $80/yr80160 hrs
EXIN 27001P·EXIN

EXIN ISO/IEC 27001 Professional

1 core domains$295
EXIN CIT·EXIN

EXIN Cyber & IT Security

1 core domains$295
GCCC·GIAC

GIAC Critical Controls Certification

24.5/40
2 core domains$979100200 hrs
GCIP·GIAC

GIAC Critical Infrastructure Protection

20.0/40
2 core domains$97980160 hrs
GISP·GIAC

GIAC Information Security Professional

22.0/40
2 core domains$979100200 hrs
GLEG·GIAC

GIAC Law of Data Security & Investigations

22.5/40
1 core domains$979100200 hrs
GRCA·OCEG

OCEG Governance, Risk, and Compliance Auditor

1 core domains$995
GRCP·OCEG

OCEG Governance, Risk, and Compliance Professional

26.5/40
1 core domains$995
GSNA·GIAC

GIAC Systems and Network Auditor

23.5/40
2 core domains$979100200 hrs
HCISPP·ISC2

ISC2 certification for healthcare security and privacy. Will be retired in December 2026. Focus on data protection, compliance, and risk management in healthcare. Relevant in the US (HIPAA), less so in Europe.

21.0/40
2 core domains$599 + $125/yr80160 hrs
IIA CIA·IIA

The Institute of Internal Auditors Certified Internal Auditor

1 core domains$725
IIBA CCA·IIBA

IIBA Certification in Cybersecurity Analysis

1 core domains$375
IS20·Mile2

Mile2 IS20 Controls

1 core domains$400
ISO 42001 LA·PECB

PECB certification for auditing AI Management Systems according to ISO/IEC 42001. Complementary to Lead Implementer. Growing demand through third-party AI audits and regulatory requirements.

27.0/40
2 core domains$1,10080160 hrs
ISO 42001 LI·PECB

The PECB ISO/IEC 42001 Lead Implementer certificate qualifies professionals to establish and lead an AI Management System (AIMS) according to the international standard ISO/IEC 42001 within an organization—analogous to the well-known ISO 27001 Lead Implementer in the ISMS domain. It is the implementation-oriented counterpart to the Lead Auditor and targets individuals responsible for AIMS rollout. Strength: Strong anchoring in the ISO framework, internationally recognized as a compliance reference for AI governance; practical focus on project management and implementation. Weakness: PECB is a commercial provider with less market recognition than IAPP or CompTIA; the certificate requires substantial professional experience and is therefore not an entry-level certification. The market for ISO-42001-compliant AIMS implementations is still young, which currently limits demand for the certificate.

27.0/40
2 core domains$1,10080160 hrs
ITS-C·TestOut / Pearson

Certiport IT Specialist - Cybersecurity

1 core domains$130
M_o_R P·Axelos

Axelos M_o_R Practitioner Risk Management

1 core domains$410
NCSC CCPLP·NCSC

NCSC Certified Cybersecurity Professional - Lead Practitioner

27.5/40
2 core domains$0120240 hrs
NCSC CCPP·NCSC

NCSC Certified Cybersecurity Professional - Practitioner

26.0/40
1 core domains$080160 hrs
NCSC CCPSP·NCSC

NCSC Certified Cybersecurity Professional - Senior Practitioner

26.0/40
1 core domains$0100200 hrs
PCCET·Palo Alto

Palo Alto Networks Certified Cybersecurity Entry-level Technician

24.5/40
2 core domains$2003080 hrs
PCI QSA·PCI Security Standards Council

PCI Qualified Security Assessor

30.5/40
2 core domains$080160 hrs
PECB 27001LA·PECB

The PECB ISO/IEC 27001 Lead Auditor is aimed at professionals who want to independently lead or conduct ISMS audits according to ISO 27001. The certificate is well established in Europe and is recognized by many organizations as proof of audit competence. The exam is demanding and combines standards knowledge with practical auditor expertise. Compared to ISO auditor certifications from other providers, PECB positions itself in the mid-price segment with broad international distribution. For beginners without audit experience, the Foundation level is recommended first.

30.5/40
1 core domains$1,10080160 hrs
PECB 27001LI·PECB

The PECB ISO/IEC 27001 Lead Implementer qualifies holders to establish, implement, and manage an ISMS according to ISO 27001. The certificate is the implementation counterpart to the Lead Auditor and is aimed at individuals who lead ISMS projects internally or as external consultants. It is valued by organizations looking to introduce or maintain ISO 27001. The exam is designed to be practical but requires a solid understanding of the standard. Without real project experience, the learning material often remains abstract.

30.5/40
1 core domains$1,10080160 hrs
PECB 27005LM·PECB

PECB ISO/IEC 27005 Lead Risk Manager

27.0/40
1 core domains$1,10080160 hrs
PECB 27005RM·PECB

PECB ISO/IEC 27005 Risk Manager

27.0/40
1 core domains$1,10060120 hrs
PECB 27032CM·PECB

PECB ISO/IEC 27032 Lead Cybersecurity Manager

24.5/40
2 core domains$1,10080160 hrs
S-ISP·SECO

SECO Information Security Practitioner

1 core domains$295
SABSA SCP·SABSA

The SABSA Chartered Practitioner (SCP) certification is the most internationally recognized qualification for risk-based security architecture at enterprise level. The SABSA framework pursues a consistently business-driven, attribute-based approach to security architecture, clearly distinguishing itself from technology-heavy frameworks. The market for SABSA is niche but highly specialized: the certification is known and valued particularly in large enterprises, the financial sector, and critical infrastructure. The assignment-based exam requires real practical application and cannot be passed through mere memorization – this increases the credibility of the credential. Limited adoption and lengthy training paths are the main limitations.

24.0/40
2 core domains$2,200120240 hrs
SACP·SAFe / Scaled Agile

The H Layer Security Awareness and Culture Professional

1 core domains$250
SailPoint Identity Engineer·SailPoint

Designs and engineers SailPoint identity solutions across IdentityIQ and Identity Security Cloud (ISC).

22.0/40
2 core domains$60080160 hrs
SailPoint IdentityIQ Admin·SailPoint

Identity governance and administration (IGA) at enterprise scale.

18.5/40
2 core domains$60060120 hrs
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
AAIA·ISACA

ISACA specialization for AI Audit. First certification worldwide specifically for auditing AI systems. Requires active CISA (or comparable audit certification). Three domains: AI Governance & Risk, AI Operations, AI Auditing.

21.0/40
2 core domains$399 + $45/yr60120 hrs
AAIR·ISACA

ISACA specialization for AI risk management. Beta phase since April 2026. Requires active ISACA or equivalent certification. Focus on AI Risk Governance, AI Risk Program Management, and AI Life Cycle Risk Management.

21.0/40
2 core domains$399 + $45/yr60120 hrs
AAISM·ISACA

ISACA specialization for AI Security Management. Requires active CISM or CISSP. Focus on AI Governance & Program Management, AI Risk Management, and AI Technologies & Controls. For security leaders managing AI risks.

21.0/40
3 core domains$399 + $45/yr60120 hrs
CISSP·ISC2

Breadth across security engineering, architecture, operations, and governance at senior-IC / manager level. The default senior-generalist signal.

28.0/40
10 core domains$749 + $135/yr150300 hrs
CISSP-ISSAP·ISC2

Architecture concentration on top of CISSP — trust boundaries, identity / crypto / network composition, defense-in-depth design.

22.0/40
7 core domains$599150300 hrs
CM)ISSO·Mile2

Mile2 Certified Master Information Systems Security Officer

1 core domains$400
EXIN 27001E·EXIN

EXIN ISO/IEC 27001 Expert

1 core domains$295
ISSEP·ISC2

ISC2 specialization for security engineering, developed in cooperation with NSA. Focus on Systems Security Engineering, Risk Management, and Security Planning. Particularly relevant in US Government/Defense context.

18.5/40
3 core domains$599 + $125/yr150300 hrs
ISSMP·ISC2

ISC2 specialization for security management. Requires CISSP. Focus on Leadership, Risk Management, Security Operations, and Compliance Management. For CISOs and senior security executives.

19.0/40
3 core domains$599 + $125/yr120250 hrs
S-ISME·SECO

SECO Information Security Management Expert

23.0/40
2 core domains$29580160 hrs
SABSA SCM·SABSA

SABSA Chartered Security Architect - Master Certificate

25.5/40
2 core domains$3,500300600 hrs
A2Network Security61 certs
AssociateSome security or adjacent experience assumed. Stepping stones from entry to professional.
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
A+·CompTIA

CompTIA A+

30.0/40
1 core domains$24660150 hrs
CC·ISC2

The CC is ISC2's entry-level certification without experience requirements and explicitly targets career starters, career changers, and students. Notably, ISC2 periodically offers CC training and the exam for free (as part of the 'One Million Certified' initiative), which has significantly increased market penetration. Content covers five domains: Security Principles, Incident Response, Access Control, Network Security, and Security Operations – at a solid but intentionally broad entry level. As a stepping stone to SSCP or CISSP it is well-suited; as a standalone credential it carries less weight than Security+. From September 2026, a new Exam Outline applies.

25.5/40
2 core domains$0 + $125/yr3080 hrs
CCNP Ent·Cisco

Cisco Certified Network Professional - Enterprise

33.0/40
1 core domains$300200400 hrs
CCNP Sec·Cisco

Cisco Certified Network Professional - Security

32.5/40
2 core domains$300200400 hrs
CCT·Cisco

Cisco Certified Technician

24.0/40
1 core domains$30040100 hrs
CND·EC-Council

EC Council Certified Network Defender

25.0/40
2 core domains$950 + $80/yr80160 hrs
CNDA·EC-Council

EC Council Certified Network Defense Architect

22.0/40
2 core domains$450 + $80/yr80160 hrs
CPENT·EC-Council

EC Council Certified Penetration Testing Professional

27.0/40
2 core domains$999 + $80/yr200400 hrs
CRTO·Zero-Point Security

The CRTO from Zero-Point Security has established itself as one of the most practice-oriented red team certifications on the market. The associated course 'Red Team Ops' focuses on Cobalt Strike, Active Directory attacks, and realistic adversary simulation with OPSEC considerations. The exam format is purely practical and evaluates not only objective achievement but also operational behavior – points are deducted for triggered detections. Particularly attractive is the price-performance ratio compared to SANS certifications, as the course and exam are significantly more affordable. For experienced pentesters looking to develop towards red teaming and C2 deployment, the CRTO is a highly relevant qualification.

30.0/40
3 core domains$399200400 hrs
DevNet Pro·Cisco

Cisco DevNet Professional

29.0/40
2 core domains$300150300 hrs
ECSS·EC-Council

EC Council Certified Security Specialist

16.5/40
2 core domains$250 + $80/yr4080 hrs
F5 CA·F5

F5 Big-IP Certified Administrator

24.0/40
2 core domains$13560120 hrs
FCP NS·Fortinet

Fortinet Certified Professional - Network Security

28.0/40
1 core domains$40080160 hrs
FCSS NS·Fortinet

Fortinet Certified Solution Specialist - Network Security

28.5/40
1 core domains$400120240 hrs
FCSS PCS·Fortinet

Fortinet Certified Solution Specialist - Public Cloud Security

28.5/40
2 core domains$40080160 hrs
FCSS ZTA·Fortinet

Fortinet Certified Solution Specialist - Zero Trust Access

28.0/40
2 core domains$40080160 hrs
GAWN·GIAC

GIAC Assessing Wireless Networks

26.0/40
3 core domains$979120240 hrs
GCIA·GIAC / SANS

Packet and log analysis, detection engineering fundamentals.

27.5/40
3 core domains$979120220 hrs
GCWN·GIAC

GIAC Certified Windows Security Administrator

23.0/40
2 core domains$979100200 hrs
GICSP·GIAC / SANS

IT + engineering overlap for industrial control systems.

29.0/40
2 core domains$979100200 hrs
GNFA·GIAC

GIAC Network Forensic Analyst

27.5/40
3 core domains$979150280 hrs
GPEN·GIAC / SANS

Penetration testing methodology + documentation.

28.5/40
2 core domains$979100200 hrs
HTB CPTS·Hack The Box

Hack the Box Certified Penetration Testing Specialist

30.5/40
3 core domains$215300500 hrs
JNCIP Sec·Juniper

Juniper Networks Certified Internet Professional, Security

29.5/40
2 core domains$300200400 hrs
JNCIS Sec·Juniper

Juniper Networks Certified Internet Specialist, Security

27.5/40
1 core domains$300100200 hrs
Linux+·CompTIA

CompTIA Linux+

27.0/40
1 core domains$35880160 hrs
Net+·CompTIA

CompTIA Network+

29.5/40
1 core domains$35840100 hrs
OSCP·OffSec

Hands-on penetration testing — exploitation, privilege escalation, AD attacks.

34.5/40
4 core domains$1,649300600 hrs
OSEP·OffSec

The OffSec Experienced Penetration Tester (OSEP) is based on the PEN-300 course and addresses advanced techniques around antivirus evasion, Active Directory attacks, and living-off-the-land methods. The fully practical 48-hour exam (47:45 hrs exam + 24 hrs report) in a simulated enterprise environment is the key difference from knowledge-based certifications—it tests real attack capabilities. OSEP is considered credible proof of high-level offensive competence in red team circles, but requires solid OSCP knowledge. Together with OSED and OSWE, OSEP forms the OSCE³ trio.

32.0/40
3 core domains$1,649300600 hrs
OSWP·OffSec

Offensive Security Wireless Professional

23.5/40
3 core domains$79940100 hrs
PCCET·Palo Alto

Palo Alto Networks Certified Cybersecurity Entry-level Technician

24.5/40
2 core domains$2003080 hrs
PCNSA·Palo Alto

Palo Alto Networks Certified Network Security Administrator

29.0/40
1 core domains$20060120 hrs
PCNSE·Palo Alto

Palo Alto Networks Certified Network Security Engineer

31.5/40
2 core domains$200100200 hrs
PNPT·TCM Security

Hands-on network + AD pentesting with OSINT + reporting.

28.5/40
3 core domains$449200400 hrs
RHCA·Red Hat

Red Hat Certified Architect

33.0/40
2 core domains$4006001200 hrs
RHCE·Red Hat

Red Hat Certified Engineer

33.0/40
1 core domains$400120240 hrs
RHCSA·Red Hat

Red Hat Certified System Administrator

33.0/40
1 core domains$40080160 hrs
Server+·CompTIA

CompTIA Server+

26.0/40
1 core domains$35860120 hrs
SSCP·ISC2

The SSCP is ISC2's entry-level certification below the CISSP and targets technically active security professionals with initial work experience. Since October 2025, the exam uses Computerized Adaptive Testing (CAT), which customizes the exam experience individually and increases integrity. The SSCP covers seven technical domains, from access control through cryptography to network security, and positions itself as practical proof of operational security competence. It is less well-known than Security+ or GSEC, but benefits from ISC2's strong brand and serves well as an intermediate step toward the CISSP. The effort for annual certification maintenance (AMF + CPEs) is moderate.

24.0/40
4 core domains$249 + $125/yr60150 hrs
VCP DCV·VMware

VMware Certified Professional in Datacenter Virtualization

28.0/40
2 core domains$25080160 hrs
VCP NV·VMware

VMware Certified Professional in Network Virtualization

27.0/40
1 core domains$25080160 hrs
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
CCDE·Cisco

Cisco Certified Design Expert

31.5/40
2 core domains$1,7508001600 hrs
CCIE Ent·Cisco

Cisco Certified Internetwork Expert - Enterprise Infrastructure

35.0/40
2 core domains$1,75012002400 hrs
CCIE Sec·Cisco

Cisco Certified Implementation Expert - Security

35.0/40
3 core domains$1,75012002400 hrs
CISSP·ISC2

Breadth across security engineering, architecture, operations, and governance at senior-IC / manager level. The default senior-generalist signal.

28.0/40
10 core domains$749 + $135/yr150300 hrs
CISSP-ISSAP·ISC2

Architecture concentration on top of CISSP — trust boundaries, identity / crypto / network composition, defense-in-depth design.

22.0/40
7 core domains$599150300 hrs
F5 CSE Sec·F5

F5 Big-IP Certified Solution Expert - Security

26.5/40
2 core domains$135100200 hrs
GSE·GIAC

The GIAC Security Expert (GSE) is the highest distinction in the GIAC certification system and was fundamentally reformed in 2023/2024: Instead of a single exam, it is now awarded as a portfolio certification. Those who demonstrate six Practitioner and four Applied Knowledge certifications (hands-on, proctored lab exams) automatically receive GSE status. The model enforces genuine breadth and depth – which increases credibility compared to earlier pure knowledge tests. However, the effort (cost, time, multiple exams) is considerable; the GSE is therefore clearly aimed at experienced experts pursuing SANS/GIAC as a career path. In Europe, awareness outside the SANS community is still limited.

34.5/40
4 core domains$97910002000 hrs
ISA CE·ISA

ISA Cybersecurity Expert

28.0/40
2 core domains$750100200 hrs
JNCIE Sec·Juniper

Juniper Networks Certified Internet Expert, Security

31.0/40
2 core domains$3008001600 hrs
VCIX NV·VMware

VMware Certified Implementation Expert in Network Virtualization

28.5/40
2 core domains$250200400 hrs
A3Zero Trust Architecture15 certs
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
CREST CRTSA·CREST

CREST Registered Technical Security Architect

27.0/40
2 core domains$700150300 hrs
CSA CZT·Cloud Security Alliance

Vendor-neutral Zero Trust architecture and governance — NIST SP 800-207, ZTA pillars, and program implementation.

19.5/40
2 core domains$6753060 hrs
CyberArk Sentry·CyberArk

Designs and deploys CyberArk PAM at enterprise scale — vault architecture, HA/DR, and complex onboarding.

22.0/40
2 core domains$20060120 hrs
FCSS SASE·Fortinet

Fortinet Certified Solution Specialist - Secure Access Service Edge

27.0/40
1 core domains$40060120 hrs
FCSS ZTA·Fortinet

Fortinet Certified Solution Specialist - Zero Trust Access

28.0/40
2 core domains$40080160 hrs
GDSA·GIAC

GIAC Defensible Security Architecture

25.5/40
2 core domains$979100200 hrs
SC-100·Microsoft

The Microsoft Certified: Cybersecurity Architect Expert (SC-100) is Microsoft's highest security certification and targets experienced professionals who design security architectures for hybrid and cloud-native environments based on the Microsoft platform. It requires at least one associate-level security certification (e.g., AZ-500, SC-200, or SC-300) and builds on that knowledge. The certification addresses zero-trust architectures, compliance requirements, identity governance, and infrastructure protection from a strategic perspective. For organizations heavily invested in Microsoft 365 and Azure, SC-100 is valuable proof of expertise; outside the Microsoft ecosystem, its relevance is more limited. The exam will be updated in April 2026.

31.0/40
3 core domains$165100200 hrs
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
A4Application Security28 certs
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
BSCP·Unbekannt

Portswigger Burp Suite Certified Practioner

30.0/40
2 core domains$9980160 hrs
C)SWAE·Mile2

Mile2 Secure Web Application Engineer

1 core domains$400
CASE·EC-Council

EC Council Certified Application Security Engineer (.NET or Java)

23.5/40
1 core domains$450 + $80/yr80160 hrs
CCSC·CertNexus

CertNexus Cyber Secure Coder

26.5/40
1 core domains$250
CDPSE·ISACA

ISACA certification for Privacy Engineering. Focus on technical implementation of privacy requirements: Privacy Governance, Privacy Architecture, and Data Lifecycle Management. Bridge between privacy and technology.

23.5/40
3 core domains$760 + $45/yr60120 hrs
CIPT·IAPP

Privacy engineering, privacy-by-design in products and platforms.

24.0/40
2 core domains$550 + $250/yr4080 hrs
CREST CCTAPP·CREST

CREST Certified Web Application Tester

26.5/40
2 core domains$700200400 hrs
CREST CSAM·CREST

CREST Certified Simulated Attack Manager

26.5/40
2 core domains$700120240 hrs
CSSLP·ISC2

Secure SDLC, threat modelling, secure architecture across product teams.

23.5/40
3 core domains$59980150 hrs
F5 CA·F5

F5 Big-IP Certified Administrator

24.0/40
2 core domains$13560120 hrs
GCSA·GIAC / SANS

Security-as-code: IaC hardening, CI/CD guardrails, automated cloud response.

28.5/40
3 core domains$979100180 hrs
GMOB·GIAC

GIAC Mobile Device Security Analyst

26.0/40
2 core domains$979120240 hrs
GWAPT·GIAC

GIAC Web Application Penetration Tester

29.0/40
2 core domains$979120220 hrs
GWEB·GIAC / SANS

Defender-side AppSec — OWASP Top 10, API security, secure design patterns.

24.5/40
1 core domains$979100180 hrs
HTB CBBH·Hack The Box

Hack the Box Certified Bug Bounty Hunter

28.5/40
2 core domains$215200400 hrs
OSCP·OffSec

Hands-on penetration testing — exploitation, privilege escalation, AD attacks.

34.5/40
4 core domains$1,649300600 hrs
OSWA·OffSec

Offensive Security Web Assessor

28.5/40
2 core domains$1,649150300 hrs
SOG CAP·Mile2

SecOps Group Certified AppSec Practitioner

1 core domains$400
SSAP·SANS/GIAC

SANS Security Awareness Professional

26.5/40
2 core domains$979150280 hrs
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
LeadershipExecutive / CISO / governance credentials. Years of management experience.
A5Cloud Security43 certs
AssociateSome security or adjacent experience assumed. Stepping stones from entry to professional.
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
AWS CP·AWS

Amazon Web Services Certified Cloud Practitioner

28.5/40
1 core domains$1002060 hrs
AWS CSS·AWS

The AWS Security Specialty is AWS's most demanding security certification and requires solid practical experience with AWS workloads. It covers a broad spectrum: from IAM and data encryption to incident response, logging, and compliance. The practical relevance is high; pure textbook candidates typically fail. The certification has high market value potential, as it is regarded as proof of quality for security architects in cloud environments. Important: Version SCS-C02 was superseded in December 2025; SCS-C03 is now current.

32.0/40
2 core domains$300100200 hrs
AWS SAP·AWS

Amazon Web Services Certified Solutions Architect - Professional

32.5/40
3 core domains$300120240 hrs
AWS Security Specialty·Amazon Web Services

Deep AWS security: IAM, data protection, detection, incident response within AWS primitives.

33.5/40
5 core domains$30080150 hrs
C)CSO·Mile2

Mile2 Certified Cloud Security Officer

1 core domains$400
CCSP·ISC2

Cloud security architecture: shared responsibility, identity, data protection, crypto, and cloud-native detection.

28.0/40
6 core domains$599 + $135/yr100180 hrs
Cloud+·CompTIA

CompTIA Cloud+

26.0/40
1 core domains$35860120 hrs
CSA CCSK·Cloud Security Alliance

The CCSK from the Cloud Security Alliance is one of the most widespread vendor-neutral cloud security certifications worldwide. It is based on three core sources: the CSA Security Guidance v4, the ENISA Cloud Computing Risk Assessment, and the CSA Cloud Controls Matrix (CCM). The exam is fully online and open-book — this lowers the entry barrier but also means less practical proof than e.g. CCSP. No professional experience required, no expiration date. Good as an entry point into cloud security and as preparation for the CCSP, but not a strong career building block on its own.

26.5/40
1 core domains$29540100 hrs
CSA CGC·Cloud Security Alliance

Cloud Security Alliance Cloud Governance & Compliance

26.0/40
1 core domains$395
EXIN PCA·EXIN

EXIN Professional Cloud Administrator

1 core domains$295
EXIN PCD·EXIN

EXIN Professional Cloud Developer

1 core domains$295
EXIN PCSA·EXIN

EXIN Professional Cloud Solution Architect

1 core domains$295
EXIN PCSerM·EXIN

EXIN Professional Cloud Service Manager

1 core domains$295
EXIN PCSM·EXIN

EXIN Professional Cloud Security Manager

1 core domains$295
FCP PCS·Fortinet

Fortinet Certified Professional - Public Cloud Security

28.5/40
1 core domains$400
GCFR·GIAC

GIAC Cloud Forensics Responder

27.5/40
2 core domains$979120240 hrs
GCP Professional Cloud Security Engineer·Google Cloud

GCP-specific security engineering: identity, VPC SC, secrets, logging, compliance.

31.0/40
4 core domains$20080160 hrs
GCPN·GIAC

GIAC Cloud Penetration Tester

27.5/40
2 core domains$979150280 hrs
GCSA·GIAC / SANS

Security-as-code: IaC hardening, CI/CD guardrails, automated cloud response.

28.5/40
3 core domains$979100180 hrs
Google PCSA·Google

Google Professional Cloud Architect

31.5/40
1 core domains$125
Google PCSE·Google

Google Professional Cloud Security Engineer

31.0/40
1 core domains$200
GPCS·GIAC

GIAC Public Cloud Security

28.0/40
1 core domains$979150280 hrs
SC-100·Microsoft

The Microsoft Certified: Cybersecurity Architect Expert (SC-100) is Microsoft's highest security certification and targets experienced professionals who design security architectures for hybrid and cloud-native environments based on the Microsoft platform. It requires at least one associate-level security certification (e.g., AZ-500, SC-200, or SC-300) and builds on that knowledge. The certification addresses zero-trust architectures, compliance requirements, identity governance, and infrastructure protection from a strategic perspective. For organizations heavily invested in Microsoft 365 and Azure, SC-100 is valuable proof of expertise; outside the Microsoft ecosystem, its relevance is more limited. The exam will be updated in April 2026.

31.0/40
3 core domains$165100200 hrs
SFCCCC·Tigerscheme

SalesForce Certified Community Cloud Consultant

1 core domains$1,500
SOG CCSP-AWS·Mile2

SecOps Group Certified Cloud Security Practitioner - AWS

1 core domains$400
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
A6Identity & Access Management42 certs
AssociateSome security or adjacent experience assumed. Stepping stones from entry to professional.
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
AWS Security Specialty·Amazon Web Services

Deep AWS security: IAM, data protection, detection, incident response within AWS primitives.

33.5/40
5 core domains$30080150 hrs
CAMS·ACAMS

IMI Certfied Access Management Specialist

1 core domains$1,395
CCNP Sec·Cisco

Cisco Certified Network Professional - Security

32.5/40
2 core domains$300200400 hrs
CCSP·ISC2

Cloud security architecture: shared responsibility, identity, data protection, crypto, and cloud-native detection.

28.0/40
6 core domains$599 + $135/yr100180 hrs
CDPSE·ISACA

ISACA certification for Privacy Engineering. Focus on technical implementation of privacy requirements: Privacy Governance, Privacy Architecture, and Data Lifecycle Management. Bridge between privacy and technology.

23.5/40
3 core domains$760 + $45/yr60120 hrs
CIAM·Identity Management Institute

Identify Management Institute Certified Identify and Access Manager

1 core domains$295
CIDPRO·IDPro

IDPro Certified Identity Professional

1 core domains$280
CIMP·DRI International

Identify Management Institute Certified Identity Management Professional

1 core domains$800
CIST·Tigerscheme

IMI Certified Identity and Security Technologist

1 core domains$1,500
CRTO·Zero-Point Security

The CRTO from Zero-Point Security has established itself as one of the most practice-oriented red team certifications on the market. The associated course 'Red Team Ops' focuses on Cobalt Strike, Active Directory attacks, and realistic adversary simulation with OPSEC considerations. The exam format is purely practical and evaluates not only objective achievement but also operational behavior – points are deducted for triggered detections. Particularly attractive is the price-performance ratio compared to SANS certifications, as the course and exam are significantly more affordable. For experienced pentesters looking to develop towards red teaming and C2 deployment, the CRTO is a highly relevant qualification.

30.0/40
3 core domains$399200400 hrs
CRTP·Altered Security

Hands-on Active Directory attacker — Kerberos abuse, trust attacks, and lateral movement against a real multi-domain forest.

31.0/40
2 core domains$49980160 hrs
CSA CZT·Cloud Security Alliance

Vendor-neutral Zero Trust architecture and governance — NIST SP 800-207, ZTA pillars, and program implementation.

19.5/40
2 core domains$6753060 hrs
CyberArk Sentry·CyberArk

Designs and deploys CyberArk PAM at enterprise scale — vault architecture, HA/DR, and complex onboarding.

22.0/40
2 core domains$20060120 hrs
F5 CTS APM·F5

F5 Big-IP Certified Technical Specialist - Access Policy Manager

25.0/40
1 core domains$13580160 hrs
FCSS PCS·Fortinet

Fortinet Certified Solution Specialist - Public Cloud Security

28.5/40
2 core domains$40080160 hrs
GCP Professional Cloud Security Engineer·Google Cloud

GCP-specific security engineering: identity, VPC SC, secrets, logging, compliance.

31.0/40
4 core domains$20080160 hrs
GCWN·GIAC

GIAC Certified Windows Security Administrator

23.0/40
2 core domains$979100200 hrs
HTB CPTS·Hack The Box

Hack the Box Certified Penetration Testing Specialist

30.5/40
3 core domains$215300500 hrs
OSCP·OffSec

Hands-on penetration testing — exploitation, privilege escalation, AD attacks.

34.5/40
4 core domains$1,649300600 hrs
OSEP·OffSec

The OffSec Experienced Penetration Tester (OSEP) is based on the PEN-300 course and addresses advanced techniques around antivirus evasion, Active Directory attacks, and living-off-the-land methods. The fully practical 48-hour exam (47:45 hrs exam + 24 hrs report) in a simulated enterprise environment is the key difference from knowledge-based certifications—it tests real attack capabilities. OSEP is considered credible proof of high-level offensive competence in red team circles, but requires solid OSCP knowledge. Together with OSED and OSWE, OSEP forms the OSCE³ trio.

32.0/40
3 core domains$1,649300600 hrs
PCNSE·Palo Alto

Palo Alto Networks Certified Network Security Engineer

31.5/40
2 core domains$200100200 hrs
PNPT·TCM Security

Hands-on network + AD pentesting with OSINT + reporting.

28.5/40
3 core domains$449200400 hrs
SailPoint Identity Engineer·SailPoint

Designs and engineers SailPoint identity solutions across IdentityIQ and Identity Security Cloud (ISC).

22.0/40
2 core domains$60080160 hrs
SailPoint IdentityIQ Admin·SailPoint

Identity governance and administration (IGA) at enterprise scale.

18.5/40
2 core domains$60060120 hrs
SF CIAMD·Unbekannt

SalesForce Certified Identity and Access Management Designer

1 core domains$295
SSCP·ISC2

The SSCP is ISC2's entry-level certification below the CISSP and targets technically active security professionals with initial work experience. Since October 2025, the exam uses Computerized Adaptive Testing (CAT), which customizes the exam experience individually and increases integrity. The SSCP covers seven technical domains, from access control through cryptography to network security, and positions itself as practical proof of operational security competence. It is less well-known than Security+ or GSEC, but benefits from ISC2's strong brand and serves well as an intermediate step toward the CISSP. The effort for annual certification maintenance (AMF + CPEs) is moderate.

24.0/40
4 core domains$249 + $125/yr60150 hrs
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
A7Incident Response & Forensics29 certs
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
ASIS PCI·ASIS

ASIS Professional Certified Investigator

28.0/40
2 core domains$425100200 hrs
BTL1·Security Blue Team

The BTL1 is one of the most practical entry-level certifications in the defensive area of cybersecurity. The exam is a complete 24-hour incident response scenario in a real lab environment – not a multiple-choice test. For career changers and entry-level professionals, it is a credible proof of competency that offers employers more meaningful value than many purely knowledge-based certificates. The course covers phishing analysis, SIEM, digital forensics, threat intelligence, and incident response. The certificate never expires, making it attractive long-term.

29.5/40
3 core domains$53080160 hrs
BTL2·Security Blue Team

Security Blue Team Level 2

29.0/40
3 core domains$700150300 hrs
CCD·CyberDefenders

Certified CyberDefender

28.0/40
3 core domains$200120240 hrs
CFCE·INE/eLearnSecurity

IACIS Certified Forensic Computer Examiner

30.0/40
1 core domains$295200400 hrs
CHFI·EC-Council

EC Council Computer Hacking Forensics Investigator

22.0/40
2 core domains$950 + $80/yr80150 hrs
CREST CPIA·CREST

CREST Practitioner Intrusion Analyst

27.5/40
2 core domains$700200400 hrs
CREST CRIA·CREST

CREST Registered Intrusion Analyst

27.5/40
2 core domains$700150300 hrs
CSFA·Unbekannt

CSIAC CyberSecurity Forensic Analyst

24.0/40
1 core domains$600100200 hrs
CSX-P·ISACA

ISACA Cybersecurity Practitioner

24.5/40
3 core domains$760 + $45/yr80160 hrs
ECIH·EC-Council

EC Council Certified Incident Handler

25.0/40
2 core domains$450 + $80/yr80160 hrs
EDRP·EC-Council

EC Council Disaster Recovery Professional

21.0/40
2 core domains$450 + $80/yr80160 hrs
EnCE·OpenText (EnCase)

OpenText EnCase Certified Examiner

27.5/40
1 core domains$200120240 hrs
GCFA·GIAC / SANS

Advanced host forensics, memory analysis, timeline reconstruction.

32.5/40
2 core domains$979150250 hrs
GCFE·GIAC / SANS

Windows host forensics and digital investigation.

28.0/40
1 core domains$979120200 hrs
GCFR·GIAC

GIAC Cloud Forensics Responder

27.5/40
2 core domains$979120240 hrs
GCIH·GIAC / SANS

Incident handling methodology and lifecycle.

29.5/40
2 core domains$97980150 hrs
GIME·GIAC

GIAC iOS and MacOS Examiner

25.0/40
2 core domains$979150280 hrs
GNFA·GIAC

GIAC Network Forensic Analyst

27.5/40
3 core domains$979150280 hrs
GRID·GIAC / SANS

Active defense and incident response for ICS environments.

28.0/40
3 core domains$979100180 hrs
GSOC·GIAC / SANS

SOC operations, alert triage, metrics, SOAR.

27.0/40
3 core domains$979100180 hrs
HTB CDSA·Hack The Box

Hack the Box Certified Defensive Security Analyst

28.0/40
3 core domains$215150300 hrs
OSDA·OffSec

Offensive Security Defense Analyst

28.5/40
3 core domains$1,649200400 hrs
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
A8Threat Intelligence12 certs
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
CREST CPTIA·CREST

CREST Practitioner Threat Intelligence Analyst

28.5/40
1 core domains$700200400 hrs
CREST CRTIA·CREST

CREST Registered Threat Intelligence Analyst

28.0/40
1 core domains$700150300 hrs
CTIA·EC-Council

EC Council Certified Threat Intelligence Analyst

23.0/40
2 core domains$450 + $80/yr80160 hrs
GCTI·GIAC / SANS

Structured threat intel production, ATT&CK, analytic tradecraft.

26.5/40
2 core domains$979100180 hrs
GOAA·GIAC

GOAA is GIAC's specialized certification for offensive AI techniques and targets red teamers, penetration testers, and SOC analysts who need to understand and simulate AI-enabled attack tools. It is based on SANS course SEC535 and features GIAC's well-known exam structure with optional CyberLive component (practical lab environment). Strength: GIAC certifications enjoy high credibility in the security industry, and the offensive perspective on AI is a differentiating unique selling point. Weakness: The certification does not cover defensive controls, AI supply chain security, or governance frameworks – it is clearly tailored to offensive specialists and thus addresses only a small segment of the market. At 999 USD exam fee plus additional SANS course costs, the financial investment is substantial.

26.0/40
1 core domains$979100200 hrs
GOSI·GIAC

GIAC Open Source Intelligence

27.0/40
1 core domains$979100200 hrs
MAD CTI·MITRE Engenuity

MAD20 track for applying the ATT&CK framework in Cyber Threat Intelligence. 18 lectures, focus on identification, development, analysis and application of ATT&CK-mapped threat intelligence. Badge upon course completion (13 CPE hours).

27.0/40
1 core domains$060120 hrs
MAD Threat Hunting·MITRE Engenuity

MAD20 track for Threat Hunting and Detection Engineering with ATT&CK. 28 lectures, complete analytics walkthroughs, 60+ range scenarios. Covers systematic development of detection rules and hunting hypotheses based on ATT&CK techniques. Badge upon completion (9 CPE hours).

27.5/40
2 core domains$080160 hrs
Splunk ES Admin·Splunk

Operates and tunes Splunk Enterprise Security — content, correlation searches, notable events, and risk-based alerting.

22.0/40
3 core domains$13060120 hrs
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
A9Penetration Testing & Red Teaming70 certs
EntryNo real prerequisites. Good first credentials for HR screens and breaking in.
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
BSCP·Unbekannt

Portswigger Burp Suite Certified Practioner

30.0/40
2 core domains$9980160 hrs
C)PEH·Mile2

Mile2 Certified Professional Ethical Hacker

1 core domains$400
C)PSH·Mile2

Mile2 Certified Powershell Hacker

1 core domains$400
C)PTC·Mile2

Mile2 Certified Penetration Testing Consultant

1 core domains$400
C)PTE·Mile2

Mile2 Certified Penetration Testing Engineer

1 core domains$400
C)VA·Mile2

Mile2 Certified Vulnerability Assessor

1 core domains$400
CHA·SECO

ISECOM Certified Hacker Analyst

1 core domains$295
CHAT·SECO

ISECOM Certified Hacker Analyst Trainer

1 core domains$295
CPENT·EC-Council

EC Council Certified Penetration Testing Professional

27.0/40
2 core domains$999 + $80/yr200400 hrs
CREST CCSAS·CREST

CREST Certified Simulated Attack Specialist

27.5/40
1 core domains$700200400 hrs
CREST CCTAPP·CREST

CREST Certified Web Application Tester

26.5/40
2 core domains$700200400 hrs
CREST CCTIM·CREST

CREST Certified Threat Intelligence Manager

29.5/40
1 core domains$700
CREST CCTINF·CREST

CREST Certified Infrastructure Tester

32.5/40
1 core domains$700
CREST CPSA·CREST

CREST Practitioner Security Analyst

25.5/40
1 core domains$700100200 hrs
CREST CRT·CREST

The CREST Registered Penetration Tester is a practical, UK-oriented certification that has established itself as an important industry standard for penetration testers, particularly in the UK market and for organizations with CHECK requirements. Unlike purely theory-based certifications, the CRT exam includes a technical, partially practical component in a controlled test environment. The combination of multiple-choice, flags, and short answers distinguishes CRT from pure CTF formats like OSCP. Outside the UK and Australia, market penetration is limited; internationally, OSCP is significantly better known. However, for testers seeking to work in the UK public sector or at CREST-accredited firms, CRT is effectively mandatory.

29.0/40
1 core domains$700200400 hrs
CRTO·Zero-Point Security

The CRTO from Zero-Point Security has established itself as one of the most practice-oriented red team certifications on the market. The associated course 'Red Team Ops' focuses on Cobalt Strike, Active Directory attacks, and realistic adversary simulation with OPSEC considerations. The exam format is purely practical and evaluates not only objective achievement but also operational behavior – points are deducted for triggered detections. Particularly attractive is the price-performance ratio compared to SANS certifications, as the course and exam are significantly more affordable. For experienced pentesters looking to develop towards red teaming and C2 deployment, the CRTO is a highly relevant qualification.

30.0/40
3 core domains$399200400 hrs
CRTO II·Zero-Point Security

Zero Point Security Red Team Operator II

29.0/40
2 core domains$799300500 hrs
CRTP·Altered Security

Hands-on Active Directory attacker — Kerberos abuse, trust attacks, and lateral movement against a real multi-domain forest.

31.0/40
2 core domains$49980160 hrs
CSR·Compliance & Risk Group

Cyber Struggle Ranger

1 core domains$350
CSTM·Tigerscheme

Cyber Scheme Team Member

1 core domains$1,500
DV MoS·Dark Vortex

Dark Vortex Malware on Steroids

1 core domains$800
DV OTD·Dark Vortex

Dark Vortex Offensive Tool Development

1 core domains$800
DV RTOS·Dark Vortex

Dark Vortex Red Team & Operational Security

1 core domains$1,200
eCPPT·INE/eLearnSecurity

eLearnSecurity Certified Professional Penetration Tester

27.5/40
1 core domains$200
eMAPT·INE/eLearnSecurity

eLearnSecurity Mobile Application Penetration Tester

26.5/40
1 core domains$200
eWPT·INE/eLearnSecurity

eLearnSecurity Web Application Penetration Tester

28.0/40
1 core domains$200
eWPTX·INE/eLearnSecurity

eLearnSecurity Web Application Penetration Tester eXtreme

29.5/40
1 core domains$200
GAWN·GIAC

GIAC Assessing Wireless Networks

26.0/40
3 core domains$979120240 hrs
GCPN·GIAC

GIAC Cloud Penetration Tester

27.5/40
2 core domains$979150280 hrs
GPEN·GIAC / SANS

Penetration testing methodology + documentation.

28.5/40
2 core domains$979100200 hrs
GRTP·GIAC

GIAC Red Team Professional

29.5/40
1 core domains$979
GWAPT·GIAC

GIAC Web Application Penetration Tester

29.0/40
2 core domains$979120220 hrs
GX-PT·GIAC

GIAC Experienced Penetration Tester

29.5/40
1 core domains$979
HTB CBBH·Hack The Box

Hack the Box Certified Bug Bounty Hunter

28.5/40
2 core domains$215200400 hrs
HTB CPTS·Hack The Box

Hack the Box Certified Penetration Testing Specialist

30.5/40
3 core domains$215300500 hrs
KLCP·Linux Foundation

Kali Linux Certified Professional

28.0/40
1 core domains$300
LPT·EC-Council

EC Council Licensed Penetration Tester

25.5/40
1 core domains$899 + $80/yr300500 hrs
MAD Adv. Emulation·MITRE Engenuity

The most hands-on intensive MAD20 track: Adversary Emulation based on ATT&CK. 30 lectures, 7 hands-on labs, 60+ range scenarios via the ARENAS platform. Covers planning, development and execution of adversary emulation plans. Badge upon completion (21 CPE hours).

28.0/40
1 core domains$0100200 hrs
MAD Purple Teaming·MITRE Engenuity

MAD20 track for Purple Teaming with ATT&CK methodology. 32 lectures, planning and execution walkthroughs. Covers coordination between red and blue teams using the ATT&CK framework. Badge upon completion (13 CPE hours).

27.5/40
2 core domains$080160 hrs
OPST·SECO

ISECOM OSSTMM Professional Security Tester

1 core domains$295
OSCP·OffSec

Hands-on penetration testing — exploitation, privilege escalation, AD attacks.

34.5/40
4 core domains$1,649300600 hrs
OSED·OffSec

Offensive Security Exploit Developer

30.5/40
2 core domains$1,649300600 hrs
OSEP·OffSec

The OffSec Experienced Penetration Tester (OSEP) is based on the PEN-300 course and addresses advanced techniques around antivirus evasion, Active Directory attacks, and living-off-the-land methods. The fully practical 48-hour exam (47:45 hrs exam + 24 hrs report) in a simulated enterprise environment is the key difference from knowledge-based certifications—it tests real attack capabilities. OSEP is considered credible proof of high-level offensive competence in red team circles, but requires solid OSCP knowledge. Together with OSED and OSWE, OSEP forms the OSCE³ trio.

32.0/40
3 core domains$1,649300600 hrs
OSMR·OffSec

Offensive Security MacOS Researcher

28.0/40
2 core domains$1,649250500 hrs
OSWA·OffSec

Offensive Security Web Assessor

28.5/40
2 core domains$1,649150300 hrs
OSWP·OffSec

Offensive Security Wireless Professional

23.5/40
3 core domains$79940100 hrs
PACES·ITGSI

Pentester Academy Certified Enterprise Security Specialist

1 core domains$600
PNPT·TCM Security

Hands-on network + AD pentesting with OSINT + reporting.

28.5/40
3 core domains$449200400 hrs
S-EHP·SECO

SECO Ethical Hacking Practitioner

1 core domains$295
SOG CAPen·Mile2

The SecOps Group Certified AppSec Pentester

1 core domains$400
SOG CMPen And·Mile2

The SecOps Group Certified Mobile Pentester - Android

1 core domains$400
SOG CMPen iOS·Mile2

The SecOps Group Certified Mobile Pentester - iOS

1 core domains$400
SOG CNPen·Mile2

The SecOps Group Certified Network Pentester

1 core domains$400
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
A10Security Operations64 certs
AssociateSome security or adjacent experience assumed. Stepping stones from entry to professional.
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
ACE·AccessData

AccessData Certified Examiner

1 core domains$0
AWS Security Specialty·Amazon Web Services

Deep AWS security: IAM, data protection, detection, incident response within AWS primitives.

33.5/40
5 core domains$30080150 hrs
BTL1·Security Blue Team

The BTL1 is one of the most practical entry-level certifications in the defensive area of cybersecurity. The exam is a complete 24-hour incident response scenario in a real lab environment – not a multiple-choice test. For career changers and entry-level professionals, it is a credible proof of competency that offers employers more meaningful value than many purely knowledge-based certificates. The course covers phishing analysis, SIEM, digital forensics, threat intelligence, and incident response. The certificate never expires, making it attractive long-term.

29.5/40
3 core domains$53080160 hrs
BTL2·Security Blue Team

Security Blue Team Level 2

29.0/40
3 core domains$700150300 hrs
C)CSA·Mile2

Mile2 Certified Cybersecurity Analyst

1 core domains$400
C)DRE·Mile2

Mile2 Certified Disaster Recovery Engineer

1 core domains$400
C)IHE·Mile2

Mile2 Certified Incident Handling Engineer

1 core domains$400
C)SP·Mile2

Mile2 Certified Security Principles

1 core domains$400
C)TIA·Mile2

Mile2 Certified Threat Intelligence Analyst

1 core domains$400
CCD·CyberDefenders

Certified CyberDefender

28.0/40
3 core domains$200120240 hrs
CCE·ISFCE

ISFCE Certified Computer Examiner

1 core domains$695
CCOA·ISACA

ISACA certification for SOC analysts with hybrid exam of multiple choice and performance-based questions. Focus on incident detection, response, and threat analysis. New since 2024.

21.0/40
2 core domains$575 + $45/yr60120 hrs
CFR·CertNexus

CertNexus CyberSec First Responder

27.5/40
1 core domains$250
CFSR·Council of Registered Ethical Security Testers

OpenText Certified Forensic Security Responder

1 core domains$0
Cisco COP·Cisco

Cisco Certified CyberOps Professional

27.0/40
2 core domains$300120240 hrs
CND·EC-Council

EC Council Certified Network Defender

25.0/40
2 core domains$950 + $80/yr80160 hrs
CREST CCHIA·CREST

CREST Certified Host Intrusion Analyst

31.5/40
1 core domains$700
CREST CPIA·CREST

CREST Practitioner Intrusion Analyst

27.5/40
2 core domains$700200400 hrs
CREST CRIA·CREST

CREST Registered Intrusion Analyst

27.5/40
2 core domains$700150300 hrs
CSA·EC-Council

EC Council Certified SOC Analyst

24.5/40
2 core domains$450 + $80/yr60120 hrs
CSAE·Cyber Security Forum Initiative

Cyber Struggle AEGIS

1 core domains$350
CSX-P·ISACA

ISACA Cybersecurity Practitioner

24.5/40
3 core domains$760 + $45/yr80160 hrs
DV AOPH·Dark Vortex

Dark Vortex Adversary Operations and Proactive Hunting

1 core domains$1,200
ECIH·EC-Council

EC Council Certified Incident Handler

25.0/40
2 core domains$450 + $80/yr80160 hrs
eCIR·INE/eLearnSecurity

eLearnSecurity Certified Incident Responder

25.5/40
1 core domains$200
eCTHP·INE/eLearnSecurity

eLearnSecurity Certified Threat Hunting Professional

26.0/40
1 core domains$200
Elastic Engineer·Elastic

Stands up and operates Elastic Stack clusters — search, observability, and security-analytics workloads on a real cluster.

29.0/40
2 core domains$50080160 hrs
FCP SO·Fortinet

Fortinet Certified Professional - Security Operations

27.5/40
2 core domains$40080160 hrs
FCSS SO·Fortinet

Fortinet Certified Solution Specialist - Security Operations

28.0/40
2 core domains$400120240 hrs
GCDA·GIAC

GIAC Certified Detection Analyst

26.5/40
2 core domains$979150280 hrs
GCED·GIAC

GIAC Certified Enterprise Defender

24.0/40
2 core domains$979100200 hrs
GCIA·GIAC / SANS

Packet and log analysis, detection engineering fundamentals.

27.5/40
3 core domains$979120220 hrs
GCIH·GIAC / SANS

Incident handling methodology and lifecycle.

29.5/40
2 core domains$97980150 hrs
GCTD·GIAC

GIAC Cloud Threat Detection

26.0/40
2 core domains$97980160 hrs
GEIR·GIAC

GIAC Enterprise Incident Response

28.5/40
1 core domains$979
GMON·GIAC

GIAC Continuous Monitoring

26.0/40
3 core domains$979100200 hrs
GPYC·GIAC

GIAC Python Coder

26.5/40
1 core domains$979100200 hrs
GRID·GIAC / SANS

Active defense and incident response for ICS environments.

28.0/40
3 core domains$979100180 hrs
GSNA·GIAC

GIAC Systems and Network Auditor

23.5/40
2 core domains$979100200 hrs
GSOC·GIAC / SANS

SOC operations, alert triage, metrics, SOAR.

27.0/40
3 core domains$979100180 hrs
HTB CDSA·Hack The Box

Hack the Box Certified Defensive Security Analyst

28.0/40
3 core domains$215150300 hrs
MAD SOCA·MITRE Engenuity

MAD20 track for assessing SOC capabilities using the ATT&CK framework. 17 lectures, heatmap and defensive recommendation walkthroughs. Teaches methodology for systematic assessment of detection coverage. Not a traditional certificate, but a badge upon course completion (9 CPE hours).

27.0/40
2 core domains$060120 hrs
OPSA·SECO

ISECOM OSSTMM Professional Security Analyst

1 core domains$295
OSDA·OffSec

Offensive Security Defense Analyst

28.5/40
3 core domains$1,649200400 hrs
OSIP·Unbekannt

IntelTechniques Open Source Intelligence Professional

1 core domains$400
PCDRA·Palo Alto

Palo Alto Networks Certified Detection and Remediation Analyst

28.5/40
2 core domains$20060120 hrs
PCSAE·Palo Alto

Palo Alto Certified Cloud Security Automation Engineer

29.0/40
1 core domains$20080160 hrs
S-TA·SECO

SECO Certified Threat Analyst

1 core domains$295
Splunk ES Admin·Splunk

Operates and tunes Splunk Enterprise Security — content, correlation searches, notable events, and risk-based alerting.

22.0/40
3 core domains$13060120 hrs
SSCP·ISC2

The SSCP is ISC2's entry-level certification below the CISSP and targets technically active security professionals with initial work experience. Since October 2025, the exam uses Computerized Adaptive Testing (CAT), which customizes the exam experience individually and increases integrity. The SSCP covers seven technical domains, from access control through cryptography to network security, and positions itself as practical proof of operational security competence. It is less well-known than Security+ or GSEC, but benefits from ISC2's strong brand and serves well as an intermediate step toward the CISSP. The effort for annual certification maintenance (AMF + CPEs) is moderate.

24.0/40
4 core domains$249 + $125/yr60150 hrs
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
A11Detection Engineering & Threat Hunting37 certs
AssociateSome security or adjacent experience assumed. Stepping stones from entry to professional.
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
AWS Security Specialty·Amazon Web Services

Deep AWS security: IAM, data protection, detection, incident response within AWS primitives.

33.5/40
5 core domains$30080150 hrs
BTL1·Security Blue Team

The BTL1 is one of the most practical entry-level certifications in the defensive area of cybersecurity. The exam is a complete 24-hour incident response scenario in a real lab environment – not a multiple-choice test. For career changers and entry-level professionals, it is a credible proof of competency that offers employers more meaningful value than many purely knowledge-based certificates. The course covers phishing analysis, SIEM, digital forensics, threat intelligence, and incident response. The certificate never expires, making it attractive long-term.

29.5/40
3 core domains$53080160 hrs
BTL2·Security Blue Team

Security Blue Team Level 2

29.0/40
3 core domains$700150300 hrs
CCD·CyberDefenders

Certified CyberDefender

28.0/40
3 core domains$200120240 hrs
CCOA·ISACA

ISACA certification for SOC analysts with hybrid exam of multiple choice and performance-based questions. Focus on incident detection, response, and threat analysis. New since 2024.

21.0/40
2 core domains$575 + $45/yr60120 hrs
Cisco COP·Cisco

Cisco Certified CyberOps Professional

27.0/40
2 core domains$300120240 hrs
CSA·EC-Council

EC Council Certified SOC Analyst

24.5/40
2 core domains$450 + $80/yr60120 hrs
CSX-P·ISACA

ISACA Cybersecurity Practitioner

24.5/40
3 core domains$760 + $45/yr80160 hrs
CTIA·EC-Council

EC Council Certified Threat Intelligence Analyst

23.0/40
2 core domains$450 + $80/yr80160 hrs
Elastic Engineer·Elastic

Stands up and operates Elastic Stack clusters — search, observability, and security-analytics workloads on a real cluster.

29.0/40
2 core domains$50080160 hrs
FCP SO·Fortinet

Fortinet Certified Professional - Security Operations

27.5/40
2 core domains$40080160 hrs
FCSS SO·Fortinet

Fortinet Certified Solution Specialist - Security Operations

28.0/40
2 core domains$400120240 hrs
GCDA·GIAC

GIAC Certified Detection Analyst

26.5/40
2 core domains$979150280 hrs
GCED·GIAC

GIAC Certified Enterprise Defender

24.0/40
2 core domains$979100200 hrs
GCIA·GIAC / SANS

Packet and log analysis, detection engineering fundamentals.

27.5/40
3 core domains$979120220 hrs
GCTD·GIAC

GIAC Cloud Threat Detection

26.0/40
2 core domains$97980160 hrs
GCTI·GIAC / SANS

Structured threat intel production, ATT&CK, analytic tradecraft.

26.5/40
2 core domains$979100180 hrs
GMON·GIAC

GIAC Continuous Monitoring

26.0/40
3 core domains$979100200 hrs
GNFA·GIAC

GIAC Network Forensic Analyst

27.5/40
3 core domains$979150280 hrs
GSOC·GIAC / SANS

SOC operations, alert triage, metrics, SOAR.

27.0/40
3 core domains$979100180 hrs
HTB CDSA·Hack The Box

Hack the Box Certified Defensive Security Analyst

28.0/40
3 core domains$215150300 hrs
MAD Purple Teaming·MITRE Engenuity

MAD20 track for Purple Teaming with ATT&CK methodology. 32 lectures, planning and execution walkthroughs. Covers coordination between red and blue teams using the ATT&CK framework. Badge upon completion (13 CPE hours).

27.5/40
2 core domains$080160 hrs
MAD SOCA·MITRE Engenuity

MAD20 track for assessing SOC capabilities using the ATT&CK framework. 17 lectures, heatmap and defensive recommendation walkthroughs. Teaches methodology for systematic assessment of detection coverage. Not a traditional certificate, but a badge upon course completion (9 CPE hours).

27.0/40
2 core domains$060120 hrs
MAD Threat Hunting·MITRE Engenuity

MAD20 track for Threat Hunting and Detection Engineering with ATT&CK. 28 lectures, complete analytics walkthroughs, 60+ range scenarios. Covers systematic development of detection rules and hunting hypotheses based on ATT&CK techniques. Badge upon completion (9 CPE hours).

27.5/40
2 core domains$080160 hrs
OSDA·OffSec

Offensive Security Defense Analyst

28.5/40
3 core domains$1,649200400 hrs
PCDRA·Palo Alto

Palo Alto Networks Certified Detection and Remediation Analyst

28.5/40
2 core domains$20060120 hrs
Splunk ES Admin·Splunk

Operates and tunes Splunk Enterprise Security — content, correlation searches, notable events, and risk-based alerting.

22.0/40
3 core domains$13060120 hrs
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
A12Data Security, Privacy & Protection21 certs
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
CCSP·ISC2

Cloud security architecture: shared responsibility, identity, data protection, crypto, and cloud-native detection.

28.0/40
6 core domains$599 + $135/yr100180 hrs
CDP·(ISC)² / Cyber Defense

IMI Certified in Data Protection

1 core domains$350
CDPSE·ISACA

ISACA certification for Privacy Engineering. Focus on technical implementation of privacy requirements: Privacy Governance, Privacy Architecture, and Data Lifecycle Management. Bridge between privacy and technology.

23.5/40
3 core domains$760 + $45/yr60120 hrs
CIPM·IAPP

Running a privacy program end-to-end.

22.0/40
2 core domains$550 + $250/yr40100 hrs
CIPP·IAPP

IAPP Certified Information Privacy Professional

25.5/40
2 core domains$55060120 hrs
CIPP/C·IAPP

Canadian privacy-law expertise — PIPEDA, provincial regimes (Quebec Law 25, Alberta/BC PIPA), and federal sectoral rules.

23.0/40
1 core domains$550 + $250/yr4080 hrs
CIPP/E·IAPP

GDPR and European privacy law expertise.

27.0/40
1 core domains$550 + $250/yr50100 hrs
CIPP/US·IAPP

US federal and state privacy-law expertise.

27.5/40
1 core domains$550 + $250/yr4080 hrs
CIPT·IAPP

Privacy engineering, privacy-by-design in products and platforms.

24.0/40
2 core domains$550 + $250/yr4080 hrs
CRFS·Council of Registered Ethical Security Testers

IMI Certified Red Flag Specialist

1 core domains$0
DCPP·DRI International

DSCI Certified Privacy Professional

1 core domains$800
EPDPP·EXIN

EXIN Privacy and Data Protection Practitioner

1 core domains$295
GCIP·GIAC

GIAC Critical Infrastructure Protection

20.0/40
2 core domains$97980160 hrs
GCP Professional Cloud Security Engineer·Google Cloud

GCP-specific security engineering: identity, VPC SC, secrets, logging, compliance.

31.0/40
4 core domains$20080160 hrs
HCISPP·ISC2

ISC2 certification for healthcare security and privacy. Will be retired in December 2026. Focus on data protection, compliance, and risk management in healthcare. Relevant in the US (HIPAA), less so in Europe.

21.0/40
2 core domains$599 + $125/yr80160 hrs
PCI QSA·PCI Security Standards Council

PCI Qualified Security Assessor

30.5/40
2 core domains$080160 hrs
A13Supply Chain Security2 certs
A14OT/ICS Security15 certs
A15Cryptography11 certs
AssociateSome security or adjacent experience assumed. Stepping stones from entry to professional.
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
AWS Security Specialty·Amazon Web Services

Deep AWS security: IAM, data protection, detection, incident response within AWS primitives.

33.5/40
5 core domains$30080150 hrs
CCSP·ISC2

Cloud security architecture: shared responsibility, identity, data protection, crypto, and cloud-native detection.

28.0/40
6 core domains$599 + $135/yr100180 hrs
ECES·EC-Council

EC Council Certified Encryption Specialist

20.0/40
1 core domains$450 + $80/yr60120 hrs
GCP Professional Cloud Security Engineer·Google Cloud

GCP-specific security engineering: identity, VPC SC, secrets, logging, compliance.

31.0/40
4 core domains$20080160 hrs
NIST PQC migration training·NIST / vendors

Crypto inventory, algorithm selection (ML-KEM/ML-DSA/SLH-DSA), migration planning.

21.0/40
4 core domains$040120 hrs
SSCP·ISC2

The SSCP is ISC2's entry-level certification below the CISSP and targets technically active security professionals with initial work experience. Since October 2025, the exam uses Computerized Adaptive Testing (CAT), which customizes the exam experience individually and increases integrity. The SSCP covers seven technical domains, from access control through cryptography to network security, and positions itself as practical proof of operational security competence. It is less well-known than Security+ or GSEC, but benefits from ISC2's strong brand and serves well as an intermediate step toward the CISSP. The effort for annual certification maintenance (AMF + CPEs) is moderate.

24.0/40
4 core domains$249 + $125/yr60150 hrs
A16Mobile & IoT Security4 certs
A18Security Leadership40 certs
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
ASIS CPP·ASIS

ASIS Certified Protection Professional

28.0/40
1 core domains$425100200 hrs
ASIS PCI·ASIS

ASIS Professional Certified Investigator

28.0/40
2 core domains$425100200 hrs
CLCSM·PECB

PECB Lead Cloud Security Manager

24.0/40
2 core domains$1,10080160 hrs
CRISC·ISACA

Enterprise risk identification, assessment, and response + IT controls.

24.0/40
2 core domains$760 + $45/yr100200 hrs
EISM·EC-Council

EC Council Information Security Manager

13.5/40
2 core domains$450 + $80/yr80160 hrs
GCPM·GIAC

GIAC Certified Project Manager

21.0/40
1 core domains$979
GISP·GIAC

GIAC Information Security Professional

22.0/40
2 core domains$979100200 hrs
GSP·GIAC

GIAC Security Professional

25.0/40
1 core domains$979
ITIL MP·Axelos

ITIL Managing Professional

24.0/40
1 core domains$41080200 hrs
NCSC CCPLP·NCSC

NCSC Certified Cybersecurity Professional - Lead Practitioner

27.5/40
2 core domains$0120240 hrs
PECB 27032CM·PECB

PECB ISO/IEC 27032 Lead Cybersecurity Manager

24.5/40
2 core domains$1,10080160 hrs
PEXIN ISM·EXIN

EXIN Information Security Management Professional

1 core domains$295
PgMP·PMI

PMI Program Management Professional

27.5/40
1 core domains$405150300 hrs
PMI ACP·PMI

PMI Agile Certified Practitioner

28.0/40
1 core domains$40560120 hrs
PMP·PMI

The Project Management Professional (PMP) certificate from PMI is the world's most recognized and widely adopted project management certification – cross-industry and internationally acknowledged. It covers both traditional (Waterfall) and agile methodologies, addressing a broad professional field. For cybersecurity professionals, the PMP is particularly relevant when transitioning into project leadership or program management roles or managing security projects. Critics note that the certificate is general in nature and offers no technical depth; it does not replace specialized security credentials. Starting July 2026, a new exam format with 185 questions and updated domains (including AI, sustainability) takes effect.

31.5/40
1 core domains$40580200 hrs
Project+·CompTIA

CompTIA Project+

24.5/40
1 core domains$3584080 hrs
Scrum PSD·Scrum.org

Scrum Professional Scrum Developer

1 core domains$200
Scrum SPS·Scrum.org

Scrum Scaled Professional Scrum

1 core domains$200
TOGAF·The Open Group

TOGAF is the world's leading standard for Enterprise Architecture and is considered a de-facto mandatory qualification for EA roles in many large enterprises. The certification provides a structured framework (ADM) for developing and maintaining enterprise architectures, but is more methodological than technically deep. Critics note that the framework appears abstract and process-heavy and is often applied only selectively in practice. Nevertheless, market acceptance is high: TOGAF knowledge is frequently explicitly required in job postings for EA roles. The certificate does not expire, making it a one-time investment without recertification effort.

26.5/40
2 core domains$47080160 hrs
Zach EAP·Zachman

Zachman Enterprise Architect Practitioner (Level 2)

1 core domains$1,500
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
LeadershipExecutive / CISO / governance credentials. Years of management experience.
A19Cyber Deception & Active Defense1 cert
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
A20Security Awareness & Human Factors1 cert
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
A21Malware Analysis & Reverse Engineering9 certs
A23Recovery, Resilience & Cyber Recovery3 certs
A25Security Architecture & Engineering63 certs
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
Apple ACSP·Apple

Apple Certified Support Professional

1 core domains$250
AWS CSS·AWS

The AWS Security Specialty is AWS's most demanding security certification and requires solid practical experience with AWS workloads. It covers a broad spectrum: from IAM and data encryption to incident response, logging, and compliance. The practical relevance is high; pure textbook candidates typically fail. The certification has high market value potential, as it is regarded as proof of quality for security architects in cloud environments. Important: Version SCS-C02 was superseded in December 2025; SCS-C03 is now current.

32.0/40
2 core domains$300100200 hrs
AWS SAP·AWS

Amazon Web Services Certified Solutions Architect - Professional

32.5/40
3 core domains$300120240 hrs
CCSP·ISC2

Cloud security architecture: shared responsibility, identity, data protection, crypto, and cloud-native detection.

28.0/40
6 core domains$599 + $135/yr100180 hrs
CIOTSP·CertNexus

CertNexus Certified Internet of Things Security Practitioner

1 core domains$250
CIS LI·IBITGQ

IBITGQ Certified ISO 27001 Information Security Management Specialist Lead Implementer

1 core domains$695
CNDA·EC-Council

EC Council Certified Network Defense Architect

22.0/40
2 core domains$450 + $80/yr80160 hrs
CREST CCNIA·CREST

CREST Certified Network Intrusion Analyst

31.5/40
1 core domains$700
CREST CRTSA·CREST

CREST Registered Technical Security Architect

27.0/40
2 core domains$700150300 hrs
CREST CSAM·CREST

CREST Certified Simulated Attack Manager

26.5/40
2 core domains$700120240 hrs
CSSLP·ISC2

Secure SDLC, threat modelling, secure architecture across product teams.

23.5/40
3 core domains$59980150 hrs
CWSP·CWNP

CWNP Certified Wireless Security Professional

27.5/40
1 core domains$400
DevNet Pro·Cisco

Cisco DevNet Professional

29.0/40
2 core domains$300150300 hrs
eNDP·INE/eLearnSecurity

eLearnSecurity Network Defense Professional

24.0/40
1 core domains$200
F5 CTS DNS·F5

F5 Big-IP Certified Technical Specialist - Domain Name Services

1 core domains$135
GCCC·GIAC

GIAC Critical Controls Certification

24.5/40
2 core domains$979100200 hrs
GDSA·GIAC

GIAC Defensible Security Architecture

25.5/40
2 core domains$979100200 hrs
GMON·GIAC

GIAC Continuous Monitoring

26.0/40
3 core domains$979100200 hrs
ISA CDS·ISA

ISA Certified Design Specialist

1 core domains$750
ISA CRAS·ISA

ISA Certified Risk Assessment Specialist

1 core domains$750
ITS-NS·TestOut / Pearson

Certiport IT Specialist - Network Security

1 core domains$130
JNCIP Sec·Juniper

Juniper Networks Certified Internet Professional, Security

29.5/40
2 core domains$300200400 hrs
LPIC-1·LPI

Linux Professional Institute Certified: Linux Administrator

27.0/40
1 core domains$400
LPIC-2·LPI

Linux Professional Institute Certified: Linux Engineer

26.5/40
1 core domains$400
LPIC-3·LPI

Linux Professional Institute Certified: 303 Security

27.5/40
1 core domains$200
PCCSE·INE/eLearnSecurity

Prisma Certified Cloud Security Engineer

29.0/40
1 core domains$200
PDSO CDP·SECO

PDSO Certified DevSecOps Professional

1 core domains$295
RHCA·Red Hat

Red Hat Certified Architect

33.0/40
2 core domains$4006001200 hrs
SABSA SCP·SABSA

The SABSA Chartered Practitioner (SCP) certification is the most internationally recognized qualification for risk-based security architecture at enterprise level. The SABSA framework pursues a consistently business-driven, attribute-based approach to security architecture, clearly distinguishing itself from technology-heavy frameworks. The market for SABSA is niche but highly specialized: the certification is known and valued particularly in large enterprises, the financial sector, and critical infrastructure. The assignment-based exam requires real practical application and cannot be passed through mere memorization – this increases the credibility of the credential. Limited adoption and lengthy training paths are the main limitations.

24.0/40
2 core domains$2,200120240 hrs
SC-100·Microsoft

The Microsoft Certified: Cybersecurity Architect Expert (SC-100) is Microsoft's highest security certification and targets experienced professionals who design security architectures for hybrid and cloud-native environments based on the Microsoft platform. It requires at least one associate-level security certification (e.g., AZ-500, SC-200, or SC-300) and builds on that knowledge. The certification addresses zero-trust architectures, compliance requirements, identity governance, and infrastructure protection from a strategic perspective. For organizations heavily invested in Microsoft 365 and Azure, SC-100 is valuable proof of expertise; outside the Microsoft ecosystem, its relevance is more limited. The exam will be updated in April 2026.

31.0/40
3 core domains$165100200 hrs
SCA·SUSE

SUSE Certified Administrator

1 core domains$125
SCE·SUSE

SUSE Certified Engineer

1 core domains$195
SFCTA·Tigerscheme

Salesforce Certified Technical Architect

1 core domains$1,500
SOG NSP·Mile2

SecOps Group Certified Network Security Practitioner

1 core domains$400
SSAP·SANS/GIAC

SANS Security Awareness Professional

26.5/40
2 core domains$979150280 hrs
TOGAF·The Open Group

TOGAF is the world's leading standard for Enterprise Architecture and is considered a de-facto mandatory qualification for EA roles in many large enterprises. The certification provides a structured framework (ADM) for developing and maintaining enterprise architectures, but is more methodological than technically deep. Critics note that the framework appears abstract and process-heavy and is often applied only selectively in practice. Nevertheless, market acceptance is high: TOGAF knowledge is frequently explicitly required in job postings for EA roles. The certificate does not expire, making it a one-time investment without recertification effort.

26.5/40
2 core domains$47080160 hrs
VCP DCV·VMware

VMware Certified Professional in Datacenter Virtualization

28.0/40
2 core domains$25080160 hrs
WCNA·Protocol Analysis Institute

Protocol Analysis Institute Wireshark Certified Network Analyst

1 core domains$295
Zach EAPro·Zachman

Zachman Enterprise Architect Professional (Level 3)

20.0/40
1 core domains$1,50060120 hrs
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
AZ-305·Microsoft

Microsoft Azure Solutions Architect Expert

31.0/40
2 core domains$16580160 hrs
CASP+·CompTIA

CompTIA's SecurityX (formerly CASP+, current exam code CAS-005) is one of the few vendor-neutral advanced certifications for technical security experts without management focus. It deliberately positions itself as a technical alternative to CISSP and is recognized by DoD and US government agencies as an 8570-compliant credential, which is a real advantage in government environments. In the private sector, market perception is mixed: CISSP clearly dominates job postings, but SecurityX provides a credible signal for technically deep skills. The pass/fail format without score disclosure is unusual and criticized by some as lacking transparency. Performance-based questions increase the practical rigor.

29.5/40
3 core domains$494100200 hrs
CCDE·Cisco

Cisco Certified Design Expert

31.5/40
2 core domains$1,7508001600 hrs
CCIE Ent·Cisco

Cisco Certified Internetwork Expert - Enterprise Infrastructure

35.0/40
2 core domains$1,75012002400 hrs
CCIE Sec·Cisco

Cisco Certified Implementation Expert - Security

35.0/40
3 core domains$1,75012002400 hrs
CCSE·Check Point

Checkpoint Certified Security Expert

29.0/40
1 core domains$350
CISSP·ISC2

Breadth across security engineering, architecture, operations, and governance at senior-IC / manager level. The default senior-generalist signal.

28.0/40
10 core domains$749 + $135/yr150300 hrs
CISSP-ISSAP·ISC2

Architecture concentration on top of CISSP — trust boundaries, identity / crypto / network composition, defense-in-depth design.

22.0/40
7 core domains$599150300 hrs
FCX·Fortinet

Fortinet Certified Expert

31.0/40
1 core domains$400
ISSAP·ISC2

ISC2 specialization for security architecture. Requires an active CISSP. Focus on GRC, Security Architecture Modeling, Infrastructure Security, and IAM architecture. For senior security architects in enterprise environments.

20.5/40
4 core domains$599 + $125/yr150300 hrs
ISSEP·ISC2

ISC2 specialization for security engineering, developed in cooperation with NSA. Focus on Systems Security Engineering, Risk Management, and Security Planning. Particularly relevant in US Government/Defense context.

18.5/40
3 core domains$599 + $125/yr150300 hrs
JNCIE Sec·Juniper

Juniper Networks Certified Internet Expert, Security

31.0/40
2 core domains$3008001600 hrs
OWSE·SECO

ISECOM OSSTMM Wireless Security Expert

1 core domains$295
PDSO CDE·SECO

PDSO Certified DevSecOps Expert

1 core domains$295
SABSA SCM·SABSA

SABSA Chartered Security Architect - Master Certificate

25.5/40
2 core domains$3,500300600 hrs
VCDX DCV·VMware

VMware Certified Design Expert in Datacenter Virtualization

30.0/40
2 core domains$2508001500 hrs
VCIX DCV·VMware

VMware Certified Implementation Expert in Datacenter Virtualization

28.0/40
1 core domains$250200400 hrs
VCIX NV·VMware

VMware Certified Implementation Expert in Network Virtualization

28.5/40
2 core domains$250200400 hrs

C · Cybersecurity of AI Systems

7 domains
C1Adversarial Machine Learning5 certs
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
COASP·EC-Council

EC-Council certification for offensive AI security. Focus on Prompt Injection, Model Extraction, Training Data Poisoning, Agent Hijacking, LLM Jailbreaking. Aligned with OWASP LLM Top 10, NIST AI RMF, ISO 42001. Brand new since February 2026.

14.5/40
2 core domains$450 + $80/yr40100 hrs
GASAE·GIAC

GIAC certification for AI Security Automation. Focus on agentic workflows, automated adversary emulation, AI-enabled response playbooks. Launched April 2026 — brand new.

26.5/40
2 core domains$979
GMLE·GIAC

GIAC Machine Learning Engineer

25.5/40
3 core domains$979150300 hrs
OSAI·OffSec

Offensive AI security — adversarial ML, LLM attacks, agent abuse.

23.5/40
4 core domains$1,499250400 hrs
SecAI+·CompTIA

SecAI+ is CompTIA's answer to the need for certified professionals who combine classic cybersecurity skills with AI-specific security knowledge – officially launched in February 2026. As an 'Expansion Cert,' it is explicitly designed as a complement to existing credentials such as Security+, CySA+, or PenTest+ and targets practitioners who must secure AI systems and defend against AI-enabled attacks. Its strength lies in the practice-oriented domain structure (40% Securing AI Systems) and strong regulatory alignment story around EU AI Act and US Executive Order on AI. Weakness: The certification is only a few weeks old; job postings rarely demand it explicitly, and the market for learning materials is still thin. No hands-on labs in the exam – adversarial ML topics are tested conceptually, not practically.

23.5/40
3 core domains$40480160 hrs
C2LLM-Specific Attacks4 certs
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
COASP·EC-Council

EC-Council certification for offensive AI security. Focus on Prompt Injection, Model Extraction, Training Data Poisoning, Agent Hijacking, LLM Jailbreaking. Aligned with OWASP LLM Top 10, NIST AI RMF, ISO 42001. Brand new since February 2026.

14.5/40
2 core domains$450 + $80/yr40100 hrs
GASAE·GIAC

GIAC certification for AI Security Automation. Focus on agentic workflows, automated adversary emulation, AI-enabled response playbooks. Launched April 2026 — brand new.

26.5/40
2 core domains$979
OSAI·OffSec

Offensive AI security — adversarial ML, LLM attacks, agent abuse.

23.5/40
4 core domains$1,499250400 hrs
SecAI+·CompTIA

SecAI+ is CompTIA's answer to the need for certified professionals who combine classic cybersecurity skills with AI-specific security knowledge – officially launched in February 2026. As an 'Expansion Cert,' it is explicitly designed as a complement to existing credentials such as Security+, CySA+, or PenTest+ and targets practitioners who must secure AI systems and defend against AI-enabled attacks. Its strength lies in the practice-oriented domain structure (40% Securing AI Systems) and strong regulatory alignment story around EU AI Act and US Executive Order on AI. Weakness: The certification is only a few weeks old; job postings rarely demand it explicitly, and the market for learning materials is still thin. No hands-on labs in the exam – adversarial ML topics are tested conceptually, not practically.

23.5/40
3 core domains$40480160 hrs
C4AI Data Security1 cert
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
C5AI Red Teaming2 certs
C7AI Governance & Risk9 certs
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.
AIGP·IAPP

AI risk, governance, and regulatory literacy (EU AI Act, NIST AI RMF).

20.5/40
3 core domains$550 + $250/yr4080 hrs
CAIP·CertNexus

CertNexus certification for AI/ML practitioners. First AI certification with ANAB/ISO 17024 accreditation. Vendor-neutral, focused on ML engineering (Supervised/Unsupervised Learning, Deep Learning, NLP). Not security-specific, but AI literacy foundation for security professionals.

21.0/40
2 core domains$25060120 hrs
CRAGE·EC-Council

EC-Council certification for responsible AI governance and ethics. Focus on oversight, risk management, regulatory alignment (NIST AI RMF, ISO 42001), accountability across the AI lifecycle. Brand new since February 2026.

13.5/40
2 core domains$450 + $80/yr4080 hrs
CRAI·ISACA

AI risk management and governance — emerging blueprint, expect revisions.

18.0/40
3 core domains$575 + $45/yr4080 hrs
ISO 42001 LA·PECB

PECB certification for auditing AI Management Systems according to ISO/IEC 42001. Complementary to Lead Implementer. Growing demand through third-party AI audits and regulatory requirements.

27.0/40
2 core domains$1,10080160 hrs
ISO 42001 LI·PECB

The PECB ISO/IEC 42001 Lead Implementer certificate qualifies professionals to establish and lead an AI Management System (AIMS) according to the international standard ISO/IEC 42001 within an organization—analogous to the well-known ISO 27001 Lead Implementer in the ISMS domain. It is the implementation-oriented counterpart to the Lead Auditor and targets individuals responsible for AIMS rollout. Strength: Strong anchoring in the ISO framework, internationally recognized as a compliance reference for AI governance; practical focus on project management and implementation. Weakness: PECB is a commercial provider with less market recognition than IAPP or CompTIA; the certificate requires substantial professional experience and is therefore not an entry-level certification. The market for ISO-42001-compliant AIMS implementations is still young, which currently limits demand for the certificate.

27.0/40
2 core domains$1,10080160 hrs
ExpertSenior-level credentials — practical pentest rigor or advanced specialization.
C8AI Safety & Alignment2 certs
C11Agentic AI Security1 cert
ProfessionalThree to five years of domain experience typically required. The working-practitioner tier.

D · Quantum Technologies & Cybersecurity

3 domains
D2Post-Quantum Cryptography1 cert
D3Quantum Threats to Existing Systems1 cert
D6Quantum Security Engineering1 cert

Not sure which cert fits a role? Open the interactive domain map and pivot by career path to see the community-recommended cert progression.

Explore the domain map