List of computer security certifications

Last updated

In the computer security or Information security fields, there are a number of tracks a professional can take to demonstrate qualifications. [Notes 1] Four sources categorizing these, and many other credentials, licenses, and certifications, are:

Contents

  1. Schools and universities
  2. Vendor-sponsored credentials (e.g. Microsoft, Cisco)
  3. Association- and organization-sponsored credentials
  4. Governmental (or quasi-governmental) licenses, certifications, and credentials

Quality and acceptance vary worldwide for IT security credentials, from well-known and high-quality examples like a master's degree in the field from an accredited school, CISSP, and Microsoft certification, to a controversial list of many dozens of lesser-known credentials and organizations.

In addition to certification obtained by taking courses and/or passing exams (and in the case of CISSP and others noted below, demonstrating experience and/or being recommended or given a reference from an existing credential holder), award certificates also are given for winning government, university or industry-sponsored competitions, including team competitions and contests.

Certifying organizations

Vendor-neutral

Vendor-specific

List of certifications

Vendor-neutral [Notes 2]

Issuing OrganizationCredential abbreviationCertification TitleFocusValidity durationNumber issued
Altered SecurityCRTPCertified Red Team ProfessionalRed Teaming3 yearsN/A
CRTECertified Red Team ExpertRed Teaming3 yearsN/A
CRTMCertified Red Team MasterRed Teaming3 yearsN/A
CARTPCertified Azure Red Team ProfessionalRed Teaming3 yearsN/A
CAWASPCertified Azure Web Application Security ProfessionalApplication Security3 yearsN/A
SECO-Institute S-ITSFIT-Security FoundationGeneral Cyber Security3 yearsN/A
S-ITSPIT-Security PractitionerGeneral Cyber Security3 yearsN/A
S-ITSEIT-Security ExpertGeneral Cyber Security3 yearsN/A
S-CITSOCertified IT-Security OfficerGeneral Cyber Security3 yearsN/A
S-DPFData Protection FoundationPrivacyNo expiration [1] N/A
S-DPPData Protection PractitionerPrivacy1 year [2] N/A
S-CDPOCertified Data Protection OfficerPrivacy3 yearsN/A
S-EHFEthical Hacking FoundationPenetration Testing3 yearsN/A
S-EHPEthical Hacking PractitionerPenetration Testing3 yearsN/A
S-SPFSecure Programming FoundationSoftware Development3 yearsN/A
S-DWFDark Web FoundationThreat Intelligence3 yearsN/A
ISC2
CCCertified in CyberSecurityIT-Administration3 years (continuously)N/A
CISSP Certified Information Systems Security Professional Management3 years (continuously) [3] 127,734 [4]
ISSAP Information Systems Security Architecture Professional Security Architecture3 years (continuously) [5] 1,952 [6]
ISSEP Information Systems Security Engineering Professional IT-Administration3 years (continuously) [5] 1,147 [6]
ISSMP Information Systems Security Management Professional Management3 years (continuously) [5] 1,196 [6]
SSCP Systems Security Certified Practitioner IT-Administration3 years (continuously) [7] 4,319 [6]
CCSPCertified Cloud Security ProfessionalCloud Security3 years (continuously) [8] 3,549 [6]
CGRCCertified in Governance, Risk and ComplianceAuditing3 years (continuously) [9] 2,671 [6]
CSSLPCertified Secure Software Lifecycle ProfessionalSoftware Development3 years (continuously) [10] 2,214 [6]
CompTIA Security+CompTIA Security+ [11] IT-Administration3 years [12] N/A
CySA+CompTIA Cyber Security AnalystSecurity Analysis3 years [13] N/A
PenTest+CompTIA Pentest+Penetration Testing3 years [14] N/A
CASP+CompTIA Advanced Security PractitionerGeneral Cyber Security3 years [15] N/A
ISACA CISA Certified Information Systems Auditor Auditing3 years115,000 [16]
CISMCertified Information Security ManagerManagement3 years27,000 [16]
CRISC Certified In Risk and Information Systems Control Risk Management3 years18,000 [16]
CGEITCertified in the Governance of Enterprise ITManagement3 years6,000 [16]
CSX-FCyber Security FundamentalsGeneral Cyber Security3 yearsN/A
CSX-TCyber Security Technical FoundationsGeneral Cyber Security3 yearsN/A
CSX-PCyber Security PractitionerGeneral Cyber Security3 yearsN/A
CSX-ACyber Security AuditAuditing3 yearsN/A
CDPSECERTIFIED DATA PRIVACY SOLUTIONS ENGINEERData Privacy3 yearsN/A
GIAC GSESecurity ExpertGeneral Cyber Security4 years [17] N/A
GSECSecurity EssentialsGeneral Cyber Security4 years [17] N/A
GCIACertified Intrusion AnalystSecurity Analysis4 years [17] N/A
GISF GIAC Information Security Fundamentals General Cyber Security4 years [17] N/A
GCEDCertified Enterprise DefenderCyber Defense4 years [17] N/A
GCWNCertified Windows Security AdministratorIT-Administration4 years [17] N/A
GMONContinuous Monitoring CertificationThreat Intelligence4 years [17] N/A
GCCCCritical Controls CertificationCyber Defense4 years [17] N/A
GCLDCloud Security EssentialsCyber Defense4 years [17] N/A
GDSADefensible Security ArchitectureSecurity Architecture4 years [17] N/A
GCDACertified Detection AnalystThreat Intelligence4 years [17] N/A
GDATDefending Advanced ThreatsCyber Defense4 years [17] N/A
GCIHCertified Incident HandlerIncident Response4 years [17] N/A
GPENPenetration TesterPenetration Testing4 years [17] N/A
GWAPTWeb Application Penetration TesterPenetration Testing4 years [17] N/A
GXPNExploit Researcher and Advanced Penetration TesterPenetration Testing4 years [17] N/A
GMOBMobile Device Security AnalystSecurity Analysis4 years [17] N/A
GAWNAssessing and Auditing Wireless NetworksWireless Security4 years [17] N/A
GPYCPython CoderSoftware Development4 years [17] N/A
GCFACertified Forensic AnalystForensics4 years [17] N/A
GCFECertified Forensic ExaminerForensics4 years [17] N/A
GREMReverse Engineering MalwareMalware Analysis4 years [17] N/A
GNFANetwork Forensic AnalystForensics4 years [17] N/A
GCTICyber Threat IntelligenceThreat Intelligence4 years [17] N/A
GASFAdvanced Smartphone ForensicsForensics4 years [17] N/A
GSLCSecurity LeadershipManagement4 years [17] N/A
GSNASystems and Network AuditorAuditing4 years [17] N/A
GISPInformation Security ProfessionalGeneral Cyber Security4 years [17] N/A
GLEGLaw of Data Security & InvestigationsForensics4 years [17] N/A
GCPMCertified Project ManagerManagement4 years [17] N/A
GSTRTStrategic Planning, Policy, and LeadershipManagement4 years [17] N/A
GWEBCertified Web Application DefenderSoftware Development4 years [17] N/A
GICSPGlobal Industrial Cyber Security ProfessionalCritical Infrastructure Security4 years [17] N/A
GRIDResponse and Industrial DefenseCritical Infrastructure Security4 years [17] N/A
GCIPCritical Infrastructure ProtectionCritical Infrastructure Security4 years [17] N/A
GOSIOpen Source IntelligenceThreat Intelligence4 years [17] N/A
GBFABattlefield Forensics and AcquisitionForensics4 years [17] N/A
GCSACloud Security AutomationCloud Security4 years [17] N/A
GFCTFoundational Cybersecurity TechnologiesCyber Security4 years [17] N/A
GSOCSecurity Operations CertifiedSecurity Operations4 years [17] N/A
GPCSPublic Cloud SecurityCloud Security4 years [17] N/A
CyberDefendersCCDCertified CyberDefenderCyberDefense / BlueTeamNo expiration [18] N/A
EC-Council CSCUEC-Council Certified Secure Computer UserSecurity AwarenessNo expirationN/A
CNDEC-Council Certified Network DefenderNetwork Security3 years [19] N/A
CEHEC-Council Certified Ethical Hacker Penetration Testing3 years [19] N/A
CEH-Practical (Master)EC-Council Certified Ethical Hacker Practical (Master)Penetration Testing3 years [19] N/A
ECSAEC-Council Certified Security AnalystPenetration Testing3 years [19] N/A
ECSA-Master (Practical)EC-Council Certified Security Analyst (Practical)Penetration Testing3 years [19] N/A
LPT-Master (Practical)EC-Council Licensed Penetration Tester (Master)Penetration Testing1 year [Notes 3] [20] N/A
E|ISMEC-Council Information Security ManagerManagement3 years [19] N/A
CCISOEC-Council Certified Chief Information Security OfficerManagement1 year [21] N/A
ECIHEC-Council Certified Incident HandlerIncident Response3 years [19] N/A
CHFIEC-Council Computer Hacking Forensic InvestigatorForensics3 years [19] N/A
EDRPEC-Council Disaster Recovery ProfessionalDisaster Recovery3 years [19] N/A
ECESEC-Council Certified Encryption SpecialistEncryption3 years [19] N/A
CASE JavaEC-Council Certified Application Security Engineer JavaSoftware Development3 years [19] N/A
CASE .NetEC-Council Certified Application Security Engineer .NetSoftware Development3 years [19] N/A
CTIAEC-Council Certified Threat Intelligence AnalystThreat Intelligence3 years [19] N/A
CSAEC-Council Certified SOC AnalystSecurity Analysis3 years [19] N/A
ECSSEC-Council Certified Security SpecialistGeneral Cyber Security3 years [19] N/A
CCSEEC-Council Cloud Security EngineerCloud Security3 years [19] N/
OffSec OSCP OffSec Certified Professional Penetration TestingNo expiration [22] N/A
OSWPOffSec Wireless ProfessionalPenetration TestingNo expiration [22] N/A
OSWAOffSec Web AssessorPenetration TestingNo expiration [22] N/A
OSEPOffSec Experienced Penetration TesterPenetration TestingNo expiration [22] N/A
OSEDOffSec Security Exploit DeveloperExploit DevelopmentNo expiration [22] N/A
OSWEOffSec Web ExpertPenetration TestingNo expiration [22] N/A
OSCE3OffSec Certified Expert3Penetration TestingNo expiration [22] N/A
OSEEOffSec Exploitation ExpertExploit DevelopmentNo expiration [22] N/A
OSDAOffSec Defensive AnalystSecurity OperationsNo expiration [22] N/A
OSMROffSec macOS ResearcherExploit DevelopmentNo expiration [22] N/A
EITCI EITCA/IS EITCA Information Technologies Security Academy General Cyber SecurityNo expirationN/A
CSACCSKCSA Certificate of Cloud Security KnowledgeCloud SecurityNo expirationN/A
Cloud Credential CouncilPCSMCCC Professional Cloud Security ManagerCloud SecurityNo expirationN/A
IAPP CIPP Certified Information Privacy Professional Privacy2 years50,000 Total
CIPMCertified Information Privacy ManagerPrivacy2 years
CIPTCertified Information Privacy TechnologistPrivacy2 years
INE SecurityeJPTeLearnSecurity Certified Junior Penetration TesterPenetration TestingNo expirationN/A
eCPPTeLearnSecurity Certified Professional Penetration TesterPenetration TestingNo expirationN/A
eWPTeLearnSecurity Web Application Penetration TesterPenetration TestingNo expirationN/A
eMAPTeLearnSecurity Mobile Application Penetration TesterPenetration TestingNo expirationN/A
eCPTXeLearnSecurity Certified Penetration Tester eXtremePenetration TestingNo expirationN/A
eCIReLearnSecurity Certified Incident Response ProfessionalIncident ResponseNo expirationN/A
eCXDeLearnSecurity Exploit DevelopmentPenetration TestingNo expirationN/A
eNDPeLearnSecurity Network Defense ProfessionalNetwork SecurityNo expirationN/A
eCREeLearnSecurity Certified Reverse EngineerMalware AnalysisNo expirationN/A
eCTHPeLearnSecurity Certified Threat Hunting ProfessionalThreat HuntingNo expirationN/A
eCMAPeLearnSecurity Certified Malware Analysis ProfessionalMalware AnalysisNo expirationN/A
eWDPeLearnSecurity Web Defense ProfessionalWeb DefenseNo expirationN/A
eCDFPeLearnSecurity Certified Digital Forensics ProfessionalDigital ForensicsNo expirationN/A
CRESTCPSACREST Practitioner Security AnalystPenetration Testing3 YearsN/A
CRTCREST Registered Penetration TesterPenetration Testing3 YearsN/A
CCT AppCREST Certified Web Application TesterPenetration Testing3 YearsN/A
CCT InfCREST Certified Infrastructure TesterPenetration Testing3 YearsN/A
CCSASCREST Certified Simulated Attack SpecialistAttack Simulation3 YearsN/A
CCSAMCREST Certified Simulated Attack ManagerAttack Simulation3 YearsN/A
CCWSCREST Certified Wireless SpecialistWireless security3 YearsN/A
CPTIACREST Practitioner Threat Intelligence AnalystThreat Intelligence3 YearsN/A
CRTIACREST Registered Threat Intelligence AnalystThreat Intelligence3 YearsN/A
CCTIMCREST Certified Threat Intelligence ManagerThreat Intelligence3 YearsN/A
CPIACREST Practitioner Intrusion AnalystSecurity Analysis3 YearsN/A
CRIACREST Registered Intrusion AnalystSecurity Analysis3 YearsN/A
CCNIACREST Certified Network Intrusion AnalystSecurity Analysis3 YearsN/A
CCHIACREST Certified Host Intrusion AnalystSecurity Analysis3 YearsN/A
CCMRECREST Certified Malware Reverse EngineerMalware Analysis3 YearsN/A
CCIMCREST Certified Incident ManagerIncident Response3 YearsN/A
CRTSACREST Registered Technical Security ArchitectSecurity Architecture3 YearsN/A
InfoSec Institute CCFECertified Computer Forensics ExaminerForensics4 yearsN/A
CCTHPCertified Cyber Threat Hunting ProfessionalThreat Hunting4 yearsN/A
CDRPCertified Data Recovery ProfessionalDisaster Recovery4 yearsN/A
CEPTCertified Expert Penetration TesterPenetration Testing4 yearsN/A
CEREACertified Expert Reverse Engineering AnalystMalware Analysis4 yearsN/A
CMWAPTCertified Mobile and Web Application Penetration TesterPenetration Testing4 yearsN/A
CMFECertified Mobile Forensics ExaminerForensics4 yearsN/A
CPTCertified Penetration TesterPenetration Testing4 yearsN/A
CRTOPCertified Red Team Operations ProfessionalRed Teaming4 yearsN/A
CREACertified Reverse Engineering AnalystMalware Analysis4 yearsN/A
CSSACertified SCADA Security ArchitectCritical Infrastructure Security4 yearsN/A
CSAPCertified Security Awareness PractitionerSecurity Awareness4 yearsN/A
Cyber Struggle[ notability? ]CSAECyber Struggle AegisSecurity AnalysisNo expirationN/A
CSRCyber Struggle RangerRed TeamingNo expirationN/A
CSTPOCyber Struggle Tactical Pistol OperatorTactical fire gun shootingNo expirationN/A
Linux Professional Institute (LPI) SecELinux Professional Institute Security EssentialsGeneral Cyber SecurityNo expiration [23] N/A
LPIC-3 SecurityLinux Professional Institute LPIC-3 SecurityIT-Administration5 years [24] N/A
Mile2C)SA1Certified Security Awareness 1Security Awareness3 YearsN/A
C)SA2Certified Security Awareness 2Security Awareness3 YearsN/A
C)SPCertified Security PrinciplesGeneral Cyber Security3 YearsN/A
C)ISSOCertified Information Systems Security OfficerManagement3 YearsN/A
IS20Information Security 20 Security ControlsGeneral Cyber Security3 YearsN/A
C)SLOCertified Security Leadership OfficerManagement3 YearsN/A
C)VACertified Vulnerability AssessorVulnerability Management3 YearsN/A
C)PEHCertified Professional Ethical HackerPenetration Testing3 YearsN/A
C)PTECertified Penetration TesterPenetration Testing3 YearsN/A
C)PTCCertified Penetration Testing ConsultantPenetration Testing3 YearsN/A
C)PSHCertified PowerShell HackerScripting3 YearsN/A
C)IHECertified Incident Handling EngineerIncident Response3 YearsN/A
C)DFECertified Digital Forensic ExaminerForensics3 YearsN/A
C)VFECertified Virtualization Forensics EngineerForensics3 YearsN/A
C)NFECertified Network Forensics ExaminerForensics3 YearsN/A
C)DRECertified Disaster Recovery EngineerDisaster Recovery3 YearsN/A
C)HISSPCertified Healthcare Information Systems Security ProfessionalHealthcare3 YearsN/A
C)ISMS-LACertified Information Security Management Systems Lead AuditorAuditing3 YearsN/A
C)ISMS-LICertified Information Security Management Systems Lead ImplementerRisk Management3 YearsN/A
C)ISSACertified Information Security Systems AuditorAuditing3 YearsN/A
C)SWAECertified Secure Web Application EngineerApplication Security3 YearsN/A
C)VCPCertified Virtualization PrinciplesVirtualization3 YearsN/A
C)VECertified Virtualization EngineerVirtualization3 YearsN/A
C)CSOCertified Cloud Security OfficerCloud Security3 YearsN/A
C)VSECertified Virtualization Systems EngineerVirtualization3 YearsN/A
C)CSSMCertified Cybersecurity Systems ManagerManagement3 YearsN/A
C)ISRMCertified Information Systems Risk ManagerRisk Management3 YearsN/A
ISCAPInformation Systems Certification & Accreditation ProfessionalAuditing3 YearsN/A
C)SWAECertified Secure Web Application EngineerWeb Security3 YearsN/A
C)ISSCertified IPv6 Security SpecialistNetwork Security3 YearsN/A
C)CSACertified Cybersecurity AnalystSecurity Analysis3 YearsN/A
C)CTACertified Cyber Threat AnalystSecurity Analysis3 YearsN/A
C)CTIACertified Cyber Threat Intelligence AnalystThreat Intelligence3 YearsN/A
ASIS InternationalCPPCertified Protection ProfessionalManagement3 YearsN/A
APPAssociate Protection ProfessionalManagement3 YearsN/A
PCIProfessional Certified InvestigatorForensics3 YearsN/A
PSPPhysical Security ProfessionalPhysical Security3 YearsN/A
SABSASABSA-SCFSABSA Chartered Security Architect – Foundation CertificateSecurity Architecture3 YearsN/A
SABSA-SCPSABSA Chartered Security Architect – Practitioner CertificateSecurity Architecture3 YearsN/A
SABSA-SCMSABSA Chartered Security Architect – Master CertificateSecurity Architecture3 YearsN/A
APMG InternationalISO/IEC 27001-FISO/IEC 27001 FoundationStandardsNo expirationN/A
ISO/IEC 27001-P ISOISO/IEC 27001 Practitioner - Information Security OfficerStandardsNo expirationN/A
NCSP-FNIST Cyber Security Professional FoundationStandardsNo expirationN/A
NCSP-PNIST Cyber Security Professional PractiionerStandardsNo expirationN/A
EXINPDP-EEXIN Privacy & Data Protection EssentialsPrivacyNo expirationN/A
PDP-FEXIN Privacy & Data Protection FoundationPrivacyNo expirationN/A
PDP-PEXIN Privacy and Data Protection PractitionerPrivacyNo expirationN/A
CIT-FEXIN Cyber & IT Security FoundationGeneral Cyber SecurityNo expirationN/A
CEFEXIN Ethical Hacking FoundationPenetration TestingNo expirationN/A
ISO/IEC 27001-FEXIN Information Security Management ISO27001 FoundationStandardsNo expirationN/A
ISO/IEC 27001-PEXIN Information Security Management ISO27001 ProfessionalStandardsNo expirationN/A
ISO/IEC 27001-EEXIN Information Security Management ISO27001 ExpertStandardsNo expirationN/A
SP-FEXIN Secure Programming FoundationSoftware DevelopmentNo expirationN/A
IBITGQEU GDPR FCertified EU General Data Protection Regulation FoundationStandardsNo expirationN/A
EU GDPR PCertified EU General Data Protection Regulation PractitionerStandardsNo expirationN/A
C-DPOCertified Data Protection OfficerPrivacyNo expirationN/A
C BS PIMS LICertified BS 10012 PIMS Lead ImplementerStandardsNo expirationN/A
CCPA FCalifornia Consumer Privacy Act FoundationPrivacyNo expirationN/A
C IDP FCertified Introduction to Data ProtectionPrivacyNo expirationN/A
CIS FCertified ISO 27001 ISMS FoundationStandardsNo expirationN/A
CIS LICertified ISO 27001 ISMS Lead ImplementerStandardsNo expirationN/A
CIS LACertified ISO 27001 ISMS Lead AuditorStandardsNo expirationN/A
CIS IACertified ISO 27001 ISMS Internal AuditorStandardsNo expirationN/A
CISRMCertified ISO 27005 ISMS Risk ManagementStandardsNo expirationN/A
PCI IMPCI DSS ImplementationStandardsNo expirationN/A
CCRMPManaging Cyber Security RiskManagementNo expirationN/A
CIRM FCyber Incident Response Management FoundationIncident ResponseNo expirationN/A
C CR PCertified Cyber Resilience PractitionerManagementNo expirationN/A
CITGPImplementing IT Governance – Foundation & PrinciplesManagementNo expirationN/A
C CS FCertified Cyber Security FoundationGeneral Cyber SecurityNo expirationN/A
CertNexusCFRCyberSec First ResponderIncident Response3 YearsN/A
CIOTSPCertified IoT Security Practitioner (CIoTSP)IoT3 YearsN/A
IRBIZIncident Response for Business ProfessionalsIncident Response3 YearsN/A
CSCCyber Secure CoderSoftware Development3 YearsN/A
CYBERSAFECyberSAFEEnd user security1 YearN/A
LunarlineCEHTCertified Expert Hunt TeamThreat Hunting3 YearsN/A
CECSCertified Expert Cloud SecurityCloud Security3 YearsN/A
CEIACertified Expert Independent AssessorAuditing3 YearsN/A
CEPMCertified Expert Program ManagerManagement3 YearsN/A
CERPCertified Expert RMF ProfessionalManagement3 YearsN/A
CESACertified Expert Security AnalystSecurity Analysis3 YearsN/A
McAfee InstituteCECICertified Expert in Cyber InvestigationsForensics2 YearsN/A
CCIICertified Cyber Intelligence InvestigatorThreat Intelligence2 YearsN/A
CCIPCertified Cyber Intelligence ProfessionalThreat Intelligence2 YearsN/A
CSMIECertified Social Media Intelligence ExpertThreat Intelligence2 YearsN/A
SMIACertified Social Media Intelligence AnalystThreat Intelligence2 YearsN/A
CCTACertified Counterintelligence Threat AnalystThreat Intelligence2 YearsN/A
CPCICertified Professional Criminal InvestigatorForensics2 YearsN/A
CORCICertified Organized Retail Crime InvestigatorForensics2 YearsN/A
CELCertified Executive LeaderManagement2 YearsN/A
CHTICertified Human Trafficking InvestigatorForensics2 YearsN/A
CCFICertified Cryptocurrency Forensic InvestigatorForensics2 YearsN/A
WVTSCertified Workplace violence and threat specialistForensics2 YearsN/A
C|OSINTCertified in Open Source IntelligenceThreat Intelligence2 YearsN/A
The IIACIACertified Internal AuditorAuditing160,000+
CRMACertification in Risk Management AssuranceRisk ManagementN/A
QIALQualification in Internal Audit LeadershipAuditingN/A
GAQMCSSTCertified Software Security TesterSoftware DevelopmentNo ExpirationN/A
CASSTCertified Advanced Software Security TesterSoftware DevelopmentNo ExpirationN/A
CISPCertified Information Security ProfessionalGeneral Cyber Security5 YearsN/A
CISSMCertified Information Systems Security ManagerManagement5 YearsN/A
CISSTCertified Information Systems Security TesterSecurity TestingNo ExpirationN/A
CPTCertified Penetration TesterPenetration TesterNo ExpirationN/A
CFACertified Forensic AnalystForensicsNo ExpirationN/A
CPEHCertified Professional Ethical HackerPenetration TesterNo ExpirationN/A
ISO/IEC 27001-CIAISO 27001 ISMS Certified Internal AuditorAuditingNo ExpirationN/A
ISO/IEC 27001-27002-LAISO 27001-27002 Lead AuditorAuditingNo ExpirationN/A
ISO/IEC 27001-LAISO 27001:2013 ISMS Certified Lead AuditorAuditingNo ExpirationN/A
ISO/IEC 27001-FISO 27001:2013 ISMS FoundationStandardsNo ExpirationN/A
ISO/IEC 27002-FISO 27002 FoundationStandardsNo ExpirationN/A
ISO/IEC 27002-LIISO 27002 Lead ImplementerStandards4 YearsN/A
ISO/IEC 31000-LRMISO 31000 Certified Lead Risk ManagerStandardsNo ExpirationN/A
ISECOMOPSAOSSTMM Professional Security AnalystSecurity AnalystNo ExpirationN/A
OPSTOSSTMM Professional Security TesterPenetration TesterNo ExpirationN/A
OPSEOSSTMM Professional Security ExpertGeneral Cyber SecurityNo ExpirationN/A
OWSEOSSTMM Wireless Security ExpertPenetration TesterNo ExpirationN/A
CTAOSSTMM Certified Trust AnalystTrust ManagementNo ExpirationN/A
SAICertified Security Awareness InstructorCyber Security TrainerNo ExpirationN/A
CHACertified Hacker AnalystPenetration TesterNo ExpirationN/A
CHATCertified Hacker Analyst TrainerCyber Security TrainerNo ExpirationN/A
HISPIHISPHolistic Information Security PractitionerGeneral Cyber Security3 YearsN/A
Blockchain Training AllianceCBSPCertified Blockchain Security ProfessionalBlockchain2 YearsN/A
Crypto ConsortiumCCSSACryptoCurrency Security Standard AuditorBlockchain-N/A
The Open Group OG0-041Open FAIR FoundationRisk Management-N/A
TOGAF9-FTOGAF 9 FoundationSecurity Architecture-N/A
TOGAF9-CTOGAF 9 CertifiedSecurity Architecture-N/A
TCM SecurityPJPTPractical Junior Penetration TesterPenetration TesterNo expirationN/A
PNPTPractical Network Penetration TesterPenetration TesterNo expirationN/A
PCRPPractical Career-Ready ProfessionalPenetration TesterNo expirationN/A
PJMRPractical Junior Malware ResearcherMalware AnalysisNo expirationN/A
PJMTPractical Junior Mobile TesterPenetration TesterNo expirationN/A
PJWTPractical Junior Web TesterPenetration TesterNo expirationN/A
Star CertificationSCSUStar Cyber Secure UserSecurity Awareness3 years [25] N/A
EHEStar Certified Ethical Hacking ExpertPenetration Testing3 years [26] N/A
SESSStar Expert Security SpecialistPenetration Testing3 years [27] N/A
SMFASStar Mobile Forensic and Advance SecurityForensics3 years [28] N/A
SPTEStar Penetration Tester Experts [29] Penetration Testing3 years [30] N/A
SSCAStar Secure Cyber AnalyticsPenetration Testing3 years [31] N/A
SFICH-007Star Forensic investigator in Computer Hacking-007Forensics3 years [32] N/A
SSPE.NetStar Secure Programmer Expert- .NetSoftware Development3 years [33] N/A
SSPE-JavaStar Secure Programmer Expert- JavaSoftware Development3 years [34] N/A
SSPE-AndroidStar Secure Programmer Expert- AndroidSoftware Development3 years [35] N/A
SSPE-PHPStar Secure Programmer Expert- PHPSoftware Development3 years [36] N/A
Zero-Point SecurityCRTOCertified Red Team OperatorRed TeamingN/AN/A
CRTLCertified Red Team LeadRed TeamingN/AN/A
EC FirstCCSACertified Cyber Security ArchitectSecurity Architecture3 yearsN/A
CSCSCertified Security Compliance SpecialistRisk/Compliance3 yearsN/A
CMMPCertified CMMC ProfessionalStandards3 yearsN/A
CWNPCWSCertified Wireless SpecialistWireless Security3 yearsN/A
Hack the box (HTB)CBBHCertified Bug Bounty HunterNo expirationN/A
CPTSCertified Penetration Testing SpecialistPenetration TestingNo expirationN/A
CDSACertified Defensive Security AnalystSecurity AnalystNo expirationN/A
CWEECertified Web Exploitation ExpertPenetration TestingNo expirationN/A

Vendor-specific [Notes 2]

Issuing OrganizationCredential AbbreviationCertification TitleFocusValidity durationNumber issued
Cisco CCNA Security Cisco Certified Network Associate - Security Network Security3 years [37]
CCNA CyberOps Cisco Certified Network Associate - CyberOps Network Security3 years [37]
CCNP Security Cisco Certified Network Professional - Security Network Security3 years [37]
CCIE SecurityCisco Certified Internetwork Expert - SecurityNetwork Security3 years [37] 2062 [38]
Check Point CCSACheck Point Certified Security AdministratorNetwork Security
CCSECheck Point Certified Security ExpertNetwork Security
Kali KLCPKali Linux Certified ProfessionalPenetration TestingNo expirationN/A
IBM -IBM Certified Deployment Professional - Security Access Manager V9.0Access Control
-IBM Certified Associate Administrator - Security Guardium Data Protection V10.1.2Data Protection
-IBM Certified Administrator - Security Guardium V10.0Data Protection
-IBM Certified Deployment Professional - Identity Governance and Intelligence V5.2Access Control
-IBM Certified Analyst - i2 Analysts Notebook V9Threat Intelligence
-IBM Certified SOC Analyst - IBM QRadar SIEM V7.3.2Threat Intelligence
-IBM Certified Associate Analyst - IBM QRadar SIEM V7.3.2Threat Intelligence
-IBM Certified Associate Administrator - IBM QRadar SIEM V7.3.2Threat Intelligence
-IBM Certified Deployment Professional - IBM QRadar SIEM V7.3.2Threat Intelligence
-IBM Certified Deployment Professional - Security Identity Governance and Intelligence V5.2.5Access Control
Microsoft AZ-500Microsoft Certified: Azure Security Engineer AssociateCloud Security1 year * [39]
MS-500Microsoft 365 Certified: Security Administrator AssociateCloud Security1 year * [39]
SC-100Microsoft Certified: Cybersecurity Architect ExpertSecurity Architect1 year * [39]
SC-200Microsoft Certified: Security Operations Analyst AssociateSIEM1 year * [39]
SC-300Microsoft Certified: Identity and Access Administrator AssociateIAM1 year * [39]
SC-400Microsoft Information Protection AdministratorRisk/Compliance1 year * [39]
SC-900Microsoft Certified: Security, Compliance, and Identity FundamentalsFundamentalsNo expiration [40]
AWS -AWS Certified Security - SpecialtyCloud Security
Google -Google Professional Cloud Security EngineerCloud Security
JamfJCESAJamf Certified Endpoint Security AdminmacOS Security
Alibaba ACAACA Cloud Security CertificationCloud Security
ACPACP Cloud Security CertificationCloud Security
ACEACE Cloud Security ExpertCloud Security
Red hat EX415Red Hat Certified Specialist in Security: LinuxIT-Administration
EX425Red Hat Certified Specialist in Security: Containers and OpenShift ContainerIT-Administration
OpenText EnCEEnCase Certified ExaminerForensics
EnCEPEnCase Certified eDiscovery PractitionerForensics
CFSREnCase Certified Forensic Security ResponderForensics
Fortinet NSE 1/2/3Network Security Professional Associatevendor-specific products2 years [41]
NSE 4Network Security Professionalfirewalls2 years [41]
NSE 5Network Security Analystadministration2 years [41]
NSE 6Network Security Specialistvendor-specific products2 years [41]
NSE 7Network Security Architectfirewalls2 years [41]
NSE 8Network Security Expertfirewalls2 years
Juniper JNCIA-SECJuniper Networks Certified AssociateNetwork Security3 years
JNCIS-SECJuniper Networks Certified SpecialistNetwork Security3 years
JNCIP-SECJuniper Networks Certified ProfessionalNetwork Security3 years
JNCIE-SECJuniper Networks Certified ExpertNetwork Security3 years
JNCDS-SECJuniper Networks Certified Design Specialist SecurityNetwork Security3 years
Palo Alto PCNSAPalo Alto Networks Certified Network Security AdministratorNetwork Security
PCNSEPalo Alto Networks Certified Network Security EngineerNetwork Security
PCCETPalo Alto Networks Certified Cybersecurity Entry-level TechnicianGeneral Cyber Security
PCDRAPalo Alto Networks Certified Detection and Remediation AnalystNetwork Security
PCCSEPalo Alto Networks Prisma Certified Cloud Security EngineerCloud Security
PCSAEPalo Alto Networks Certified Security Automation EngineerThreat Intelligence
Symantec, (since 2015 NortonLifeLock )250-215Administration of Symantec Messaging Gateway 10.6Network Security
250-420Administration of Symantec VIP (March 2017)Network Security
250-426Administration of Symantec Data Center Security - Server Advanced 6.7Network Security
250-428Administration of Symantec Endpoint Protection 14Network Security
250-430Administration of Blue Coat ProxySG 6.6Network Security
250-433Administration of Blue Coat Security Analytics 7.2Network Security
250-438Administration of Symantec Data Loss Prevention 15*Network Security
250-440Administration of Symantec PacketShaper 11.9.1*Network Security
250-441Administration of Symantec Advanced Threat Protection 3.0*Network Security
251/250-443Administration of Symantec CloudSOC - R2*Network Security
250-444Administration of Symantec Secure Sockets Layer Visibility 5.0*Network Security
250-445Administration of Symantec Email Security.cloud - v1*Network Security
251/250-446Administration of Symantec Web Security Service (WSS) - R1*Network Security
251/250-447Administration of Symantec Client Management Suite 8.5*Network Security
251/250-551Administration of Symantec Endpoint Detection and Response 4.1*Network Security
250-556Administration of Symantec ProxySG 6.7*Network Security

Microsoft 1 year *: you have to do a free refresh exam within 180 days before expiration. if not done, the certificate expire otherwise it extends by 1 year.

See also

Notes

  1. This article is about the certification and credentialing of individuals. It does not include certification of organizations or classified computer systems by authorizing, accrediting, and approval bodies and authorities as meeting a prescribed set of safeguards.
  2. 1 2 In this chart, colors are used to help group certifications from the same issuer together and have no other significance.
  3. First validation period after exam is 2 years.

    Related Research Articles

    <span class="mw-page-title-main">SANS Institute</span> American security company

    The SANS Institute is a private U.S. for-profit company founded in 1989 that specializes in information security, cybersecurity training, and selling certificates. Topics available for training include cyber and network defenses, penetration testing, incident response, digital forensics, and auditing. The information security courses are developed through a consensus process involving administrators, security managers, and information security professionals. The courses cover security fundamentals and technical aspects of information security. The institute has been recognized for its training programs and certification programs. Per 2021, SANS is the world’s largest cybersecurity research and training organization. SANS is an acronym for SysAdmin, Audit, Network, and Security.

    CISSP is an independent information security certification granted by the International Information System Security Certification Consortium, also known as ISC2.

    Global Information Assurance Certification (GIAC) is an information security certification entity that specializes in technical and practical certification as well as new research in the form of its GIAC Gold program. SANS Institute founded the certification entity in 1999 and the term GIAC is trademarked by The Escal Institute of Advanced Technologies.

    ISACA is an international professional association focused on IT governance. On its IRS filings, it is known as the Information Systems Audit and Control Association, although ISACA now goes by its acronym only. ISACA currently offers 8 certification programs, as well as other micro-certificates.

    <span class="mw-page-title-main">International Association of Privacy Professionals</span> Nonprofit membership association

    The International Association of Privacy Professionals (IAPP) is a nonprofit, non-advocacy membership association founded in 2000. It provides a forum for privacy professionals to share best practices, track trends, advance privacy management issues, standardize the designations for privacy professionals, and to provide education and guidance on career opportunities in the field of information privacy. The IAPP offers a full suite of educational and professional development services, including privacy training, certification programs, publications and annual conferences. It is headquartered in Portsmouth, New Hampshire.

    <span class="mw-page-title-main">Computer repair technician</span> Person who repairs and maintains computers and servers

    A computer repair technician is a person who repairs and maintains computers and servers. The technician's responsibilities may extend to include building or configuring new hardware, installing and updating software packages, and creating and maintaining computer networks.

    The following outline is provided as an overview of and topical guide to information technology:

    The Certified Internet Web Professional (CIW) education program was created by a community of Web designers and developers in the late 1990s. The company that currently owns CIW, Certification Partners, offers books, on-line learning and high-stakes exams. Third-party companies also sell CIW preparation material.

    Corey Schou is University Professor of Informatics and Associate Dean at Idaho State University, director of the National Information Assurance Training and Education Center (NIATEC) and the Simplot Decision Support Center (SDSC), and for ten years the chair of the Colloquium for Information Systems Security Education (CISSE).

    <span class="mw-page-title-main">Robert Slade</span> Canadian information scientist

    Robert Michael Slade, also known as Robert M. Slade and Rob Slade, is a Canadian information security consultant, researcher and instructor. He is the author of Robert Slade's Guide to Computer Viruses, Software Forensics, Dictionary of Information Security and co-author of Viruses Revealed. Slade is the author of thousands of technical book reviews, today published on the techbooks mailing list and in the RISKS Digest, and archived in his Internet Review Project. An expert on computer viruses and malware, he is also the Mr. Slade of "Mr. Slade's lists".

    The Institute for the Certification of Computing Professionals (ICCP) is a non-profit institution for professional certification in the Computer engineering and Information technology industry. It was founded in 1973 by 8 professional computer societies to promote certification and professionalism in the industry, lower the cost of development and administration of certification for all of the societies and act as the central resource for job standards and performance criteria.

    Michael Gregg is an American computer security specialist, businessman, author and co-author, some of his books include; Build Your Own Network Security Lab and Inside Network Security Assessment. He has also served as an expert witness before a congressional committee on cyber security and identity theft.

    The Computing Technology Industry Association, more commonly known as CompTIA, is an American non-profit trade association that issues professional certifications for the information technology (IT) industry. It is considered one of the IT industry's top trade associations.

    Kaplan IT Training, formerly Transcender, provides IT certification practice exams, practice labs, and online learning courses. Kaplan IT Training offers test preparation solutions that are used by IT professionals to improve their technical skills and prepare for industry certification exams, including

    <span class="mw-page-title-main">Boris Loza</span> International computer security expert (born 1960)

    Boris Loza is the founder of SafePatrol Solutions and Tego Systems, as well as a Certified Information Systems Security Professional (CISSP). He was born in Krasnodar, Russia, where he attained a Master's degree at the age of 22 and a PhD at the age of 26, both in Computer Science and Cybernetics. While still living in the former USSR, Loza published more than 30 scientific articles, as well as secured one patent. Upon relocating to Canada in 1996, his PhD was confirmed by the Higher Attestation Committee of The University of Toronto.

    ISC2 Non-profit IT cybersecurity organization

    The International Information System Security Certification Consortium, or ISC2, is a non-profit organization which specializes in training and certifications for cybersecurity professionals. It has been described as the "world's largest IT security organization". The most widely known certification offered by ISC2 is the Certified Information Systems Security Professional (CISSP) certification.

    Microsoft Certified Professional was a certification program from Microsoft.

    <span class="mw-page-title-main">Stephen T. Cobb</span>

    Stephen Cobb is an expert on security, privacy, and the risks related to digital technology.

    <span class="mw-page-title-main">Gregory Touhill</span> American general

    Brigadier GeneralGregory (Greg) J. Touhill is Director of the world renowned Carnegie Mellon University Software Engineering Institute’s CERT Division. Previously, he was the president of AppGate Federal Group . He was previously appointed by President Barack Obama as the first Federal Chief Information Security Officer of the United States, stepping down in January, 2017. He was previously the Deputy Assistant Secretary, Office of Cybersecurity and Communications, National Programs and Protection Directorate, Department of Homeland Security. While at DHS he concurrently served as Director of the National Cybersecurity and Communications Integration Center (NCCIC) during 2014–2015.

    William "Chuck" Easttom II is an American computer scientist specializing in cyber security, cryptography, quantum computing, and systems engineering.

    References

    1. "Data Protection Foundation". SECO-Institute. Retrieved 2021-08-14.
    2. "Data Protection Practitioner". SECO-Institute. Retrieved 2021-08-14.
    3. "Certified Information Systems Security Professional (CISSP) - GoCertify". www.gocertify.com. Retrieved 2018-07-24.
    4. "Member Counts | How Many (ISC)2 Members Are There Per Certification | (ISC)2". www.isc2.org. Retrieved 2018-07-24.
    5. 1 2 3 "IT Security Architect, Engineer, and Management Certifications | CISSP Concentrations | (ISC)²". www.isc2.org. Retrieved 2018-07-24.
    6. 1 2 3 4 5 6 7 "Member Counts | How Many (ISC)² Members Are There Per Certification | (ISC)²". www.isc2.org. Retrieved 2018-07-24.
    7. "IT Security Certification | SSCP - Systems Security Certified Practitioner | (ISC)2". www.isc2.org. Retrieved 2018-07-24.
    8. "Cloud Security Certifications: CCSK vs CCSP – Confidis". www.confidis.co. 30 April 2015. Retrieved 2018-07-24.
    9. "Security Authorization Certification | CAP - Certified Authorization Professional | (ISC)2". www.isc2.org. Retrieved 2018-07-24.
    10. "Software Security Certification | CSSLP - Certified Secure Software Lifecycle Professional | (ISC)2". www.isc2.org. Retrieved 2018-07-24.
    11. "CompTIA Security+ Certification" . Retrieved 2021-09-08.
    12. "How Long Does the CompTIA Security+ Certification Last | CompTIA IT Certifications". CompTIA.org. Retrieved 2024-02-21.
    13. "How Long Does the CompTIA CySA+ Certification Last | CompTIA IT Certifications". CompTIA.org. Retrieved 2024-02-21.
    14. "How Long Does the CompTIA PenTest+ Certification Last | CompTIA IT Certifications". CompTIA.org. Retrieved 2024-02-21.
    15. "How long does the CASP+ Certification Last | CompTIA IT Certifications". CompTIA.org. Retrieved 2024-02-21.
    16. 1 2 3 4 "ISACA Certifications by Region". www.isaca.org. Retrieved 2019-11-08.
    17. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 "Renewing Your GIAC Certification". www.giac.org. Retrieved 2024-02-20.
    18. CyberDefenders. "CCD Certification FAQs". CyberDefenders. Retrieved 2024-02-25.
    19. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 "ECE Policy". cert.eccouncil.org. Retrieved 2018-07-24.
    20. "Application Process Eligibility". cert.eccouncil.org. Retrieved 2018-07-24.
    21. "CISO FAQ - EC-Council". EC-Council. Retrieved 2018-07-24.
    22. 1 2 3 4 5 6 7 8 9 10 "Digital certification FAQ".
    23. "Linux Professional Institute Security Essentials". lpi.org. Retrieved 2023-09-06.
    24. "Linux Professional Institute LPIC-3 Security". lpi.org. Retrieved 2023-09-06.
    25. "(SCSU) Star Cyber Secure User | Star Certifications" . Retrieved 2021-08-30.
    26. "(EHE) Star Certified Ethical Hacking Expert | Star Certifications" . Retrieved 2021-08-30.
    27. "(SESS) Star Expert Security Specialist | Star Certifications" . Retrieved 2021-08-30.
    28. "(SMFAS) Star Mobile Forensic and Advance Security | Star Certifications" . Retrieved 2021-08-30.
    29. "PenTest Certification" . Retrieved 2021-09-08.
    30. "(SPTE) Star Penetration Tester Experts | Star Certifications" . Retrieved 2021-08-30.
    31. "(SSCA) Star Secure Cyber Analytics | Star Certifications" . Retrieved 2021-08-30.
    32. "(SFICH-007) Star Forensic investigator in Computer Hacking-007 | Star Certifications" . Retrieved 2021-08-30.
    33. "(SSPE.Net) Star Secure Programmer Expert- .Net | Star Certifications" . Retrieved 2021-08-30.
    34. "(SSPE-Java) Star Secure Programmer Expert- Java | Star Certifications" . Retrieved 2021-08-30.
    35. "(Android) Star Secure Programmer Expert- Android | Star Certifications" . Retrieved 2021-08-30.
    36. "(SSPE-PHP) Star Secure Programmer Expert- PHP | Star Certifications" . Retrieved 2021-08-30.
    37. 1 2 3 4 "Recertification - Training & Certifications". Cisco. Retrieved 2024-02-19.
    38. "CCIE". CCIE Hall of Fame. Retrieved 2024-02-19.
    39. 1 2 3 4 5 6 Micsullivan (2023-10-25). "Credential expiration policies". learn.microsoft.com. Retrieved 2024-02-21.
    40. Micsullivan (2023-10-25). "Credential expiration policies". learn.microsoft.com. Retrieved 2024-02-21.
    41. 1 2 3 4 5 "Network Security Expert". NSE Institute. Fortinet via egnyte.com.