Pillar A: CybersecurityA25

Security Architecture & Engineering

Reference architectures, control frameworks (NIST SP 800-53, CIS Controls), secure-by-design patterns, threat modeling, trust-boundary design, technology standards.

Part of Pillar A: Cybersecurity · Cybersecurity groups the disciplines that share methods, tools, and threat models with Security Architecture & Engineering.

Curated resources

Authoritative sources we ground Security Architecture & Engineering questions in — frameworks, research, guides, and tools.

Certifications that signal this domain

Credentials whose blueprint meaningfully covers this domain. Core means centrally covered; also touched means present in the blueprint but not the primary focus.

Core coverage

Apple ACSPProfessional·AppleOfficial page →

Apple Certified Support Professional

Apple Certified Support Professional

AWS CSSProfessional·AWSOfficial page →

Amazon Web Services Certified Security - Specialty

The AWS Security Specialty is AWS's most demanding security certification and requires solid practical experience with AWS workloads. It covers a broad spectrum: from IAM and data encryption to incident response, logging, and compliance. The practical relevance is high; pure textbook candidates typically fail. The certification has high market value potential, as it is regarded as proof of quality for security architects in cloud environments. Important: Version SCS-C02 was superseded in December 2025; SCS-C03 is now current.

AWS SAAAssociate·AWSOfficial page →

Amazon Web Services Certified Solutions Architect - Associate

Amazon Web Services Certified Solutions Architect - Associate

AWS SAPProfessional·AWSOfficial page →

Amazon Web Services Certified Solutions Architect - Professional

Amazon Web Services Certified Solutions Architect - Professional

AZ-305Expert·MicrosoftOfficial page →

Microsoft Azure Solutions Architect Expert

Microsoft Azure Solutions Architect Expert

CASP+Expert·CompTIAOfficial page →

CompTIA Advanced Security Practitioner+

CompTIA's SecurityX (formerly CASP+, current exam code CAS-005) is one of the few vendor-neutral advanced certifications for technical security experts without management focus. It deliberately positions itself as a technical alternative to CISSP and is recognized by DoD and US government agencies as an 8570-compliant credential, which is a real advantage in government environments. In the private sector, market perception is mixed: CISSP clearly dominates job postings, but SecurityX provides a credible signal for technically deep skills. The pass/fail format without score disclosure is unusual and criticized by some as lacking transparency. Performance-based questions increase the practical rigor.

CCDEExpert·CiscoOfficial page →

Cisco Certified Design Expert

Cisco Certified Design Expert

CCIE EntExpert·CiscoOfficial page →

Cisco Certified Internetwork Expert - Enterprise Infrastructure

Cisco Certified Internetwork Expert - Enterprise Infrastructure

CCIE SecExpert·CiscoOfficial page →

Cisco Certified Implementation Expert - Security

Cisco Certified Implementation Expert - Security

CCSEExpert·Check PointOfficial page →

Checkpoint Certified Security Expert

Checkpoint Certified Security Expert

CCSPProfessional·ISC2Official page →

Certified Cloud Security Professional

Cloud security architecture: shared responsibility, identity, data protection, crypto, and cloud-native detection.

CIOTSPProfessional·CertNexusOfficial page →

CertNexus Certified Internet of Things Security Practitioner

CertNexus Certified Internet of Things Security Practitioner

CIS LIProfessional·IBITGQOfficial page →

IBITGQ Certified ISO 27001 Information Security Management Specialist Lead Implementer

IBITGQ Certified ISO 27001 Information Security Management Specialist Lead Implementer

CISSPExpert·ISC2Official page →

Certified Information Systems Security Professional

Breadth across security engineering, architecture, operations, and governance at senior-IC / manager level. The default senior-generalist signal.

CISSP-ISSAPExpert·ISC2Official page →

CISSP Information Systems Security Architecture Professional

Architecture concentration on top of CISSP — trust boundaries, identity / crypto / network composition, defense-in-depth design.

CNDAProfessional·EC-CouncilOfficial page →

EC Council Certified Network Defense Architect

EC Council Certified Network Defense Architect

CREST CCNIAProfessional·CRESTOfficial page →

CREST Certified Network Intrusion Analyst

CREST Certified Network Intrusion Analyst

CREST CRTSAProfessional·CRESTOfficial page →

CREST Registered Technical Security Architect

CREST Registered Technical Security Architect

CREST CSAMProfessional·CRESTOfficial page →

CREST Certified Simulated Attack Manager

CREST Certified Simulated Attack Manager

CSSLPProfessional·ISC2Official page →

Certified Secure Software Lifecycle Professional

Secure SDLC, threat modelling, secure architecture across product teams.

CWSPProfessional·CWNPOfficial page →

CWNP Certified Wireless Security Professional

CWNP Certified Wireless Security Professional

DCAAssociate·DRI InternationalOfficial page →

Docker Certified Associate

Docker Certified Associate

DevNet ProProfessional·CiscoOfficial page →

Cisco DevNet Professional

Cisco DevNet Professional

eNDPProfessional·INE/eLearnSecurityOfficial page →

eLearnSecurity Network Defense Professional

eLearnSecurity Network Defense Professional

F5 CTS DNSProfessional·F5Official page →

F5 Big-IP Certified Technical Specialist - Domain Name Services

F5 Big-IP Certified Technical Specialist - Domain Name Services

FCXExpert·FortinetOfficial page →

Fortinet Certified Expert

Fortinet Certified Expert

GCCCProfessional·GIACOfficial page →

GIAC Critical Controls Certification

GIAC Critical Controls Certification

GDSAProfessional·GIACOfficial page →

GIAC Defensible Security Architecture

GIAC Defensible Security Architecture

GMONProfessional·GIACOfficial page →

GIAC Continuous Monitoring

GIAC Continuous Monitoring

ISA CDSProfessional·ISAOfficial page →

ISA Certified Design Specialist

ISA Certified Design Specialist

ISA CFSAssociate·ISAOfficial page →

ISA Certified Fundamentals Specialist

ISA Certified Fundamentals Specialist

ISA CRASProfessional·ISAOfficial page →

ISA Certified Risk Assesment Specialist

ISA Certified Risk Assessment Specialist

ISSAPExpert·ISC2Official page →

Information Systems Security Architecture Professional

ISC2 specialization for security architecture. Requires an active CISSP. Focus on GRC, Security Architecture Modeling, Infrastructure Security, and IAM architecture. For senior security architects in enterprise environments.

ISSEPExpert·ISC2Official page →

Information Systems Security Engineering Professional

ISC2 specialization for security engineering, developed in cooperation with NSA. Focus on Systems Security Engineering, Risk Management, and Security Planning. Particularly relevant in US Government/Defense context.

ITS-NSProfessional·TestOut / PearsonOfficial page →

Certiport IT Specialist - Network Security

Certiport IT Specialist - Network Security

JNCIE SecExpert·JuniperOfficial page →

Juniper Networks Certified Internet Expert, Security

Juniper Networks Certified Internet Expert, Security

JNCIP SecProfessional·JuniperOfficial page →

Juniper Networks Certified Internet Professional, Security

Juniper Networks Certified Internet Professional, Security

LFCAAssociate·Linux FoundationOfficial page →

Linux Foundation Certified IT Associate

Linux Foundation Certified IT Associate

LFCSAssociate·Linux FoundationOfficial page →

Linux Foundation Certified System Administrator

Linux Foundation Certified System Administrator

LPIC-1Professional·LPIOfficial page →

Linux Professional Institute Certified: Linux Administrator

Linux Professional Institute Certified: Linux Administrator

LPIC-2Professional·LPIOfficial page →

Linux Professional Institute Certified: Linux Engineer

Linux Professional Institute Certified: Linux Engineer

LPIC-3Professional·LPIOfficial page →

Linux Professional Institute Certified: 303 Security

Linux Professional Institute Certified: 303 Security

OWSEExpert·SECOOfficial page →

ISECOM OSSTMM Wireless Security Expert

ISECOM OSSTMM Wireless Security Expert

PCCSEProfessional·INE/eLearnSecurityOfficial page →

Prisma Certified Cloud Security Engineer

Prisma Certified Cloud Security Engineer

PDSO CDEExpert·SECOOfficial page →

PDSO Certified DevSecOps Expert

PDSO Certified DevSecOps Expert

PDSO CDPProfessional·SECOOfficial page →

PDSO Certified DevSecOps Professional

PDSO Certified DevSecOps Professional

RHCAProfessional·Red HatOfficial page →

Red Hat Certified Architect

Red Hat Certified Architect

SABSA SCFAssociate·SABSAOfficial page →

SABSA Chartered Security Architect - Foundation Certificate

SABSA Chartered Security Architect - Foundation Certificate

SABSA SCMExpert·SABSAOfficial page →

SABSA Chartered Security Architect - Master Certificate

SABSA Chartered Security Architect - Master Certificate

SABSA SCPProfessional·SABSAOfficial page →

SABSA Chartered Security Architect - Practitioner Certificate

The SABSA Chartered Practitioner (SCP) certification is the most internationally recognized qualification for risk-based security architecture at enterprise level. The SABSA framework pursues a consistently business-driven, attribute-based approach to security architecture, clearly distinguishing itself from technology-heavy frameworks. The market for SABSA is niche but highly specialized: the certification is known and valued particularly in large enterprises, the financial sector, and critical infrastructure. The assignment-based exam requires real practical application and cannot be passed through mere memorization – this increases the credibility of the credential. Limited adoption and lengthy training paths are the main limitations.

SC-100Professional·MicrosoftOfficial page →

Microsoft Cybersecurity Architect

The Microsoft Certified: Cybersecurity Architect Expert (SC-100) is Microsoft's highest security certification and targets experienced professionals who design security architectures for hybrid and cloud-native environments based on the Microsoft platform. It requires at least one associate-level security certification (e.g., AZ-500, SC-200, or SC-300) and builds on that knowledge. The certification addresses zero-trust architectures, compliance requirements, identity governance, and infrastructure protection from a strategic perspective. For organizations heavily invested in Microsoft 365 and Azure, SC-100 is valuable proof of expertise; outside the Microsoft ecosystem, its relevance is more limited. The exam will be updated in April 2026.

SCAProfessional·SUSEOfficial page →

SUSE Certified Administrator

SUSE Certified Administrator

SCEProfessional·SUSEOfficial page →

SUSE Certified Engineer

SUSE Certified Engineer

SFCTAProfessional·TigerschemeOfficial page →

Salesforce Certified Technical Architect

Salesforce Certified Technical Architect

SOG NSPProfessional·Mile2Official page →

SecOps Group Certified Network Security Practitioner

SecOps Group Certified Network Security Practitioner

SSAPProfessional·SANS/GIACOfficial page →

SANS Security Awareness Professional

SANS Security Awareness Professional

TOGAFProfessional·The Open GroupOfficial page →

OpenGroup TOGAF Certified

TOGAF is the world's leading standard for Enterprise Architecture and is considered a de-facto mandatory qualification for EA roles in many large enterprises. The certification provides a structured framework (ADM) for developing and maintaining enterprise architectures, but is more methodological than technically deep. Critics note that the framework appears abstract and process-heavy and is often applied only selectively in practice. Nevertheless, market acceptance is high: TOGAF knowledge is frequently explicitly required in job postings for EA roles. The certificate does not expire, making it a one-time investment without recertification effort.

VCDX DCVExpert·VMwareOfficial page →

VMware Certified Design Expert in Datacenter Virtualization

VMware Certified Design Expert in Datacenter Virtualization

VCIX DCVExpert·VMwareOfficial page →

VMware Certified Implementation Expert in Datacenter Virtualization

VMware Certified Implementation Expert in Datacenter Virtualization

VCIX NVExpert·VMwareOfficial page →

VMware Certified Implementation Expert in Network Virtualization

VMware Certified Implementation Expert in Network Virtualization

VCP DCVProfessional·VMwareOfficial page →

VMware Certified Professional in Datacenter Virtualization

VMware Certified Professional in Datacenter Virtualization

WCNAProfessional·Protocol Analysis InstituteOfficial page →

Protocol Analysis Institute Wireshark Certified Network Analyst

Protocol Analysis Institute Wireshark Certified Network Analyst

Zach EAProProfessional·ZachmanOfficial page →

Zachman Enterprise Architect Professional (Level 3)

Zachman Enterprise Architect Professional (Level 3)

Also touched

CCISOLeadership·EC-CouncilOfficial page →

Certified Chief Information Security Officer

Executive leadership — governance, program mgmt, finance, and strategic planning for security.

CISMLeadership·ISACAOfficial page →

Certified Information Security Manager

Security program management, risk, governance, and incident governance. The manager / CISO-track signal.

Browse all certifications → — pick a cert on the interactive map to highlight every domain it covers.

More in Cybersecurity

Test what you know about Security Architecture & Engineering

40 questions available. Beginner to expert questions, scored against the global leaderboard.