AWS
AWS Certified Security - Specialty
Popular
Cloud security
Advanced
Knowledge
Designing and implementing security solutions, data protection, identity, logging, incident response, and infrastructure security.
- Exam
- Knowledge exam
- Experience
- 5 years security and 2 years AWS recommended
- Renewal
- 3 years
ISC2
Certified in Cybersecurity
Popular
Foundations
Entry
Knowledge
Security principles, access control, network security, operations, and incident response fundamentals.
- Exam
- Knowledge exam
- Experience
- No experience required
- Renewal
- Annual maintenance
Cloud Security Alliance
Certificate of Cloud Security Knowledge
Popular
Cloud security
Entry
Knowledge
Vendor-neutral cloud security architecture, governance, risk, data, operations, and legal concerns.
- Exam
- Knowledge exam
- Experience
- Cloud fundamentals recommended
- Renewal
- Does not expire
ISC2
Certified Cloud Security Professional
Popular
Cloud security
Advanced
Knowledge
Vendor-neutral cloud architecture, data security, platform security, operations, legal, risk, and compliance.
- Exam
- Knowledge exam plus experience validation
- Experience
- 5 years IT, including cloud security
- Renewal
- Annual maintenance
ISACA
Certified Information Systems Auditor
Popular
Audit and assurance
Advanced
Knowledge
Audit, governance, acquisition, operations, resilience, and protection of information assets.
- Exam
- Knowledge exam plus experience validation
- Experience
- 5 years relevant experience
- Renewal
- Annual CPE
ISACA
Certified Information Security Manager
Popular
Leadership and architecture
Advanced
Knowledge
Security governance, program development, risk management, and incident management for leaders.
- Exam
- Knowledge exam plus experience validation
- Experience
- 5 years relevant experience
- Renewal
- Annual CPE
ISC2
Certified Information Systems Security Professional
Popular
Leadership and architecture
Advanced
Knowledge
Broad senior-level coverage of security management, architecture, engineering, operations, software, and risk.
- Exam
- Knowledge exam plus experience validation
- Experience
- 5 years across two domains
- Renewal
- Annual maintenance
ISC2
Certified Secure Software Lifecycle Professional
Popular
Application security
Advanced
Knowledge
Secure requirements, architecture, implementation, testing, deployment, and software supply chain.
- Exam
- Knowledge exam plus experience validation
- Experience
- 4 years software lifecycle experience
- Renewal
- Annual maintenance
CompTIA
CompTIA Cybersecurity Analyst+
Popular
SOC and defense
Intermediate
Knowledge
Threat detection, SIEM, vulnerability management, incident response, and security analytics.
- Exam
- Knowledge plus performance questions
- Experience
- Security operations experience recommended
- Renewal
- 3 years
INE Security
Junior Penetration Tester
Popular
Penetration testing
Entry
Practical
Entry practical exam covering network, host, and basic web application penetration testing.
- Exam
- Hands-on lab exam
- Experience
- Basic networking and systems
- Renewal
- 3 years
GIAC
GIAC Certified Forensic Analyst
Popular
Digital forensics
Advanced
Knowledge
Enterprise incident response, memory forensics, timeline analysis, threat hunting, and advanced investigations.
- Exam
- Proctored knowledge exam
- Experience
- Incident response and forensics experience
- Renewal
- 4 years
GIAC
GIAC Certified Incident Handler
Popular
Incident response
Intermediate
Knowledge
Incident handling, common attacks, network and endpoint techniques, containment, and recovery.
- Exam
- Proctored knowledge exam
- Experience
- Security operations experience helpful
- Renewal
- 4 years
Hack The Box
HTB Certified Defensive Security Analyst
Popular
SOC and defense
Intermediate
Practical
Security analysis, SOC operations, incident handling, correlation, scoping, and actionable reporting.
- Exam
- Hands-on investigation plus report
- Experience
- SOC analyst path recommended
- Renewal
- Check provider
Hack The Box
HTB Certified Penetration Testing Specialist
Popular
Penetration testing
Intermediate
Practical
Practical internal and external penetration testing with a commercial-grade report.
- Exam
- Hands-on engagement plus report
- Experience
- Pentester job-role path recommended
- Renewal
- Check provider
Hack The Box
HTB Certified Web Exploitation Specialist
Popular
Application security
Intermediate
Practical
Web application and API pentesting, bug bounty techniques, risk assessment, and reporting.
- Exam
- Hands-on engagement plus report
- Experience
- Web pentester path recommended
- Renewal
- Check provider
OffSec
OffSec Certified Professional Plus
Popular
Penetration testing
Intermediate
Practical
Widely recognized hands-on pentest credential covering enumeration, exploitation, privilege escalation, and Active Directory.
- Exam
- 24-hour proctored practical exam
- Experience
- Strong Linux, Windows, networking, scripting
- Renewal
- 3 years for Plus designation
Important: The underlying OSCP remains valid indefinitely; the OSCP+ designation expires.
Application security
Advanced
Practical
White-box source review, authentication bypass, deserialization, and complex web exploit development.
- Exam
- 48-hour proctored practical exam
- Experience
- Strong source review and web exploitation
- Renewal
- Does not expire
Google Cloud
Professional Cloud Security Engineer
Popular
Cloud security
Advanced
Knowledge
Secure workloads and infrastructure, identity, data protection, operations, compliance, and software supply chain on Google Cloud.
- Exam
- Knowledge exam
- Experience
- 3+ years industry and 1+ year Google Cloud recommended
- Renewal
- 2 years
TCM Security
Practical Network Penetration Tester
Popular
Penetration testing
Intermediate
Practical
End-to-end external and internal network pentest with OSINT, Active Directory, reporting, and debrief.
- Exam
- 5-day engagement plus report
- Experience
- PJPT or equivalent skills recommended
- Renewal
- Does not expire
Microsoft
Microsoft Cybersecurity Architect Expert
Popular
Cloud security
Advanced
Knowledge
Zero Trust security architecture across identity, devices, data, AI, applications, infrastructure, DevOps, and GRC.
- Exam
- Knowledge exam plus prerequisite credential
- Experience
- Eligible associate credential required
- Renewal
- 1 year
Foundations
Entry
Knowledge
Broad baseline for threats, architecture, operations, identity, risk, and cryptography.
- Exam
- Knowledge plus performance questions
- Experience
- Networking knowledge recommended
- Renewal
- 3 years
ISACA
Advanced in AI Security Management
AI security
Advanced
Knowledge
Advanced credential for governing and managing AI security risk within enterprise programs.
- Exam
- Knowledge exam plus base credential
- Experience
- Active CISM required
- Renewal
- Check provider
Microsoft
Microsoft Azure Security Engineer Associate
Cloud security
Intermediate
Knowledge
Azure posture, threat protection, identity, networking, compute, storage, and compliance implementation.
- Exam
- Knowledge exam
- Experience
- Azure administration experience
- Renewal
- Retires Aug 31, 2026
Important: Scheduled to retire on August 31, 2026. Do not start without checking Microsoft's replacement path.
Hack The Box
HTB Certified Active Directory Pentesting Expert
Red teaming
Advanced
Practical
Advanced Active Directory attack paths, Kerberos, NTLM, C2, and post-exploitation.
- Exam
- Hands-on engagement plus report
- Experience
- Advanced AD pentesting skills
- Renewal
- Check provider
ISACA
Certified Cybersecurity
Foundations
Entry
Knowledge
Entry pathway covering cybersecurity concepts and practical organizational controls.
- Exam
- Knowledge exam
- Experience
- No formal prerequisite
- Renewal
- Check provider
Cisco
Cisco Certified Internetwork Expert Security
Network security
Expert
Practical
Expert design, deployment, operation, optimization, and automation of complex security solutions.
- Exam
- Core exam plus hands-on lab
- Experience
- Expert network security experience
- Renewal
- 3 years
EC-Council
Certified Chief Information Security Officer
Leadership and architecture
Expert
Knowledge
Governance, controls, audit, security program management, finance, strategy, and executive leadership.
- Exam
- Knowledge exam plus experience eligibility
- Experience
- Senior management experience
- Renewal
- 3 years
Cisco
Cisco Certified Network Professional Security
Network security
Advanced
Knowledge
Network security architecture, firewalls, VPN, identity, content security, and automation.
- Exam
- Core plus concentration exams
- Experience
- Professional network security experience
- Renewal
- 3 years
CREST
CREST Certified Red Team Specialist
Red teaming
Advanced
Knowledge
Specialist credential for planning and conducting sophisticated red-team operations.
- Exam
- Proctored exam
- Experience
- Senior red-team experience
- Renewal
- Check provider
Cisco
Cisco Certified Support Technician Cybersecurity
Foundations
Entry
Knowledge
Security principles, endpoint protection, vulnerability assessment, network defense, and incident handling.
- Exam
- Knowledge exam
- Experience
- No formal prerequisite
- Renewal
- Check provider
CREST
CREST Certified Tester - Application
Application security
Advanced
Practical
Senior benchmark for web applications, APIs, databases, containers, cloud, and macOS testing.
- Exam
- Proctored practical and knowledge exam
- Experience
- Senior application tester experience
- Renewal
- Check provider
CREST
CREST Certified Tester - Infrastructure
Penetration testing
Advanced
Practical
Senior infrastructure penetration-testing benchmark for networks and operating systems.
- Exam
- Proctored practical and knowledge exam
- Experience
- Senior practitioner experience
- Renewal
- Check provider
ISACA
Certified Data Privacy Solutions Engineer
Privacy
Advanced
Knowledge
Privacy governance, architecture, and data lifecycle implementation using privacy by design.
- Exam
- Knowledge exam plus experience validation
- Experience
- 3 years relevant experience
- Renewal
- Annual CPE
EC-Council
Certified Ethical Hacker
Penetration testing
Intermediate
Knowledge
Broad ethical hacking curriculum with strong employer and government recognition.
- Exam
- Knowledge exam
- Experience
- 2 years recommended or official training
- Renewal
- 3 years
EC-Council
Certified Ethical Hacker Practical
Penetration testing
Intermediate
Practical
Practical validation of common ethical hacking techniques and tools.
- Exam
- Hands-on practical exam
- Experience
- CEH skills recommended
- Renewal
- 3 years
ISACA
Certified in the Governance of Enterprise IT
Leadership and architecture
Expert
Knowledge
Enterprise IT governance, benefits realization, risk optimization, and resource optimization.
- Exam
- Knowledge exam plus experience validation
- Experience
- 5 years governance experience
- Renewal
- Annual CPE
EC-Council
Computer Hacking Forensic Investigator
Digital forensics
Intermediate
Knowledge
Forensic readiness, evidence handling, acquisition, investigation, and reporting.
- Exam
- Knowledge exam
- Experience
- Security or IT experience helpful
- Renewal
- 3 years
IAPP
Certified Information Privacy Manager
Privacy
Intermediate
Knowledge
Building, operating, measuring, and improving an organizational privacy program.
- Exam
- Knowledge exam
- Experience
- Privacy program experience helpful
- Renewal
- 2 years
IAPP
Certified Information Privacy Professional - Europe
Privacy
Intermediate
Knowledge
European data protection law, GDPR, regulators, cross-border data, and compliance practice.
- Exam
- Knowledge exam
- Experience
- Privacy or compliance knowledge helpful
- Renewal
- 2 years
IAPP
Certified Information Privacy Technologist
Privacy
Intermediate
Knowledge
Privacy engineering, data lifecycle, privacy-enhancing technologies, and privacy by design.
- Exam
- Knowledge exam
- Experience
- Technical privacy experience helpful
- Renewal
- 2 years
Platform security
Advanced
Practical
Cluster hardening, system hardening, supply chain, runtime security, and incident response in Kubernetes.
- Exam
- Performance-based practical exam
- Experience
- Active CKA required
- Renewal
- 2 years
EC-Council
Certified Penetration Testing Professional
Penetration testing
Advanced
Practical
Advanced network, web, IoT, OT, evasion, pivoting, and reporting skills.
- Exam
- Hands-on cyber-range exam
- Experience
- Advanced pentest experience
- Renewal
- 3 years
CREST
CREST Practitioner Intrusion Analyst
Incident response
Entry
Knowledge
Entry pathway for intrusion analysis and incident-response work.
- Exam
- Proctored exam
- Experience
- Early-career analyst knowledge
- Renewal
- Check provider
CREST
CREST Practitioner Threat Intelligence Analyst
Threat intelligence
Entry
Knowledge
Entry pathway for cyber threat intelligence collection, assessment, and reporting.
- Exam
- Proctored exam
- Experience
- Early-career intelligence knowledge
- Renewal
- Check provider
CREST
CREST Registered Intrusion Analyst
Incident response
Intermediate
Knowledge
Intermediate credential for investigating intrusions and handling incidents.
- Exam
- Proctored exam
- Experience
- Frequent relevant experience
- Renewal
- Check provider
ISACA
Certified in Risk and Information Systems Control
Risk and GRC
Advanced
Knowledge
Enterprise IT risk identification, assessment, response, reporting, controls, and monitoring.
- Exam
- Knowledge exam plus experience validation
- Experience
- 3 years relevant experience
- Renewal
- Annual CPE
CREST
CREST Registered Penetration Tester
Penetration testing
Intermediate
Practical
Government-recognized infrastructure and web penetration-testing credential.
- Exam
- Proctored practical and knowledge exam
- Experience
- Valid CPSA required
- Renewal
- Check provider
EC-Council
Certified Threat Intelligence Analyst
Threat intelligence
Intermediate
Knowledge
Threat intelligence lifecycle, collection, analysis, reporting, and operationalization.
- Exam
- Knowledge exam
- Experience
- Security analysis experience helpful
- Renewal
- 3 years
Cisco
Cisco Certified CyberOps Associate
SOC and defense
Entry
Knowledge
Security monitoring, host analysis, network intrusion analysis, and incident response.
- Exam
- Knowledge exam
- Experience
- No formal prerequisite
- Renewal
- 3 years
EC-Council
EC-Council Certified Incident Handler
Incident response
Intermediate
Knowledge
Incident preparation, detection, triage, containment, recovery, and common attack scenarios.
- Exam
- Knowledge exam
- Experience
- Security operations experience helpful
- Renewal
- 3 years
INE Security
Certified Professional Penetration Tester
Penetration testing
Intermediate
Practical
Professional network and web penetration testing with practical exploitation and reporting.
- Exam
- Hands-on lab exam
- Experience
- 2+ years offensive security recommended
- Renewal
- 3 years
INE Security
Web Application Penetration Tester
Application security
Intermediate
Practical
Professional web testing methodology, analysis, exploitation, and reporting.
- Exam
- Hands-on lab exam
- Experience
- Basic web pentest experience
- Renewal
- 3 years
INE Security
Web Application Penetration Tester eXtreme
Application security
Advanced
Practical
Advanced practical testing of modern web applications and complex exploit chains.
- Exam
- Hands-on lab exam
- Experience
- Advanced web pentest experience
- Renewal
- 3 years
GIAC
GIAC Certified Forensic Examiner
Digital forensics
Intermediate
Knowledge
Windows forensic acquisition, browser artifacts, email, filesystems, registry, and user activity.
- Exam
- Proctored knowledge exam
- Experience
- Windows administration helpful
- Renewal
- 4 years
GIAC
GIAC Certified Intrusion Analyst
SOC and defense
Advanced
Knowledge
Traffic analysis, intrusion detection, protocol analysis, and network-based threat detection.
- Exam
- Proctored knowledge exam
- Experience
- Packet analysis and IDS experience
- Renewal
- 4 years
GIAC
GIAC Cloud Security Automation
Cloud security
Advanced
Knowledge
Secure DevOps, infrastructure as code, CI/CD, cloud automation, containers, and security testing.
- Exam
- Proctored knowledge exam
- Experience
- Cloud and DevOps experience
- Renewal
- 4 years
GIAC
GIAC Cyber Threat Intelligence
Threat intelligence
Advanced
Knowledge
Intelligence requirements, collection, analysis, attribution, campaigns, and intelligence products.
- Exam
- Proctored knowledge exam
- Experience
- Threat intelligence experience helpful
- Renewal
- 4 years
GIAC
GIAC Public Cloud Security
Cloud security
Intermediate
Knowledge
Security controls across AWS, Azure, and Google Cloud, including identity, networking, data, and logging.
- Exam
- Proctored knowledge exam
- Experience
- Public cloud experience helpful
- Renewal
- 4 years
GIAC
GIAC Penetration Tester
Penetration testing
Intermediate
Knowledge
Planning, reconnaissance, exploitation, password attacks, web testing, and penetration-test process.
- Exam
- Proctored knowledge exam
- Experience
- Pentest experience helpful
- Renewal
- 4 years
GIAC
GIAC Reverse Engineering Malware
Malware analysis
Advanced
Knowledge
Static and dynamic malware analysis, reverse engineering, document malware, and behavioral analysis.
- Exam
- Proctored knowledge exam
- Experience
- Assembly and debugging fundamentals
- Renewal
- 4 years
GIAC
GIAC Security Essentials
Foundations
Intermediate
Knowledge
Applied security across defense, networking, Linux, Windows, cryptography, cloud, and incident handling.
- Exam
- Proctored knowledge exam
- Experience
- Practical IT experience helpful
- Renewal
- 4 years
GIAC
GIAC Web Application Penetration Tester
Application security
Intermediate
Knowledge
Web architecture, reconnaissance, authentication, injection, client-side attacks, and testing process.
- Exam
- Proctored knowledge exam
- Experience
- Web testing experience helpful
- Renewal
- 4 years
GIAC
GIAC Certified Web Application Defender
Application security
Intermediate
Knowledge
Secure coding and defensive controls for authentication, sessions, input, APIs, and modern web stacks.
- Exam
- Proctored knowledge exam
- Experience
- Developer or AppSec experience helpful
- Renewal
- 4 years
GIAC
GIAC Exploit Researcher and Advanced Penetration Tester
Red teaming
Advanced
Knowledge
Advanced exploitation, fuzzing, network attacks, crypto attacks, and custom tooling.
- Exam
- Proctored knowledge exam
- Experience
- Advanced offensive experience
- Renewal
- 4 years
OffSec
Kali Linux Certified Professional
Foundations
Entry
Knowledge
Kali Linux administration, package management, networking, security, and enterprise use.
- Exam
- Knowledge exam
- Experience
- Linux fundamentals
- Renewal
- Does not expire
OffSec
OffSec AI Security Professional Plus
AI security
Advanced
Practical
Hands-on assessment of AI systems, models, agents, and AI-enabled applications.
- Exam
- Proctored practical exam
- Experience
- AI and offensive security experience
- Renewal
- 3 years
OffSec
OffSec Experienced Penetration Tester
Red teaming
Advanced
Practical
Advanced client-side attacks, defense evasion, Active Directory tradecraft, and network compromise.
- Exam
- 48-hour proctored practical exam
- Experience
- OSCP-level skills
- Renewal
- Does not expire
OffSec
OffSec Web Assessor
Application security
Entry
Practical
Foundational hands-on web vulnerability discovery and exploitation.
- Exam
- 24-hour proctored practical exam
- Experience
- Basic web testing knowledge
- Renewal
- Does not expire
OffSec
OffSec Wireless Professional
Wireless security
Intermediate
Practical
802.11 reconnaissance, attacks, encryption weaknesses, and wireless network exploitation.
- Exam
- Proctored practical exam
- Experience
- Wireless and Linux fundamentals
- Renewal
- Does not expire
Palo Alto Networks
Palo Alto Networks Certified Network Security Engineer
Network security
Advanced
Knowledge
Design, deployment, configuration, maintenance, and troubleshooting of Palo Alto Networks security platforms.
- Exam
- Knowledge exam
- Experience
- Firewall deployment experience
- Renewal
- 2 years
Penetration testing
Intermediate
Knowledge
Scoping, vulnerability discovery, attacks, lateral movement, reporting, cloud, APIs, and AI attack concepts.
- Exam
- Knowledge plus performance questions
- Experience
- 3-4 years recommended
- Renewal
- 3 years
TCM Security
Practical Junior Penetration Tester
Penetration testing
Entry
Practical
Internal Active Directory penetration test with a professional reporting component.
- Exam
- Practical engagement plus report
- Experience
- Beginner-friendly
- Renewal
- Does not expire
TCM Security
Practical Web Pentest Associate
Application security
Entry
Practical
Associate-level web application penetration test with professional reporting.
- Exam
- 2-day practical plus report
- Experience
- Basic web and networking knowledge
- Renewal
- Check provider
TCM Security
Practical Web Pentest Professional
Application security
Advanced
Practical
Professional-level web application assessment with realistic reporting.
- Exam
- Practical engagement plus report
- Experience
- Professional web pentest skills
- Renewal
- Check provider
Microsoft
Microsoft Security Operations Analyst Associate
SOC and defense
Intermediate
Knowledge
Microsoft Sentinel, Defender XDR, threat hunting, incident response, and security operations.
- Exam
- Knowledge exam
- Experience
- Microsoft security operations experience
- Renewal
- 1 year
Microsoft
Microsoft Identity and Access Administrator Associate
Identity security
Intermediate
Knowledge
Identity lifecycle, authentication, access management, workload identities, and identity governance.
- Exam
- Knowledge exam
- Experience
- Microsoft Entra experience
- Renewal
- 1 year
Microsoft
Microsoft Security, Compliance, and Identity Fundamentals
Cloud security
Entry
Knowledge
Microsoft security, compliance, identity, Zero Trust, Entra, Defender, and Purview fundamentals.
- Exam
- Knowledge exam
- Experience
- No formal prerequisite
- Renewal
- Does not expire
AI security
Intermediate
Knowledge
Securing AI systems and using AI in cybersecurity operations across governance, threats, and controls.
- Exam
- Knowledge plus performance questions
- Experience
- Security+ level knowledge recommended
- Renewal
- Check provider
Security engineering
Advanced
Knowledge
Enterprise architecture, engineering, operations, governance, and advanced technical integration.
- Exam
- Knowledge plus performance questions
- Experience
- Senior security experience recommended
- Renewal
- 3 years
ISC2
Systems Security Certified Practitioner
Security engineering
Intermediate
Knowledge
Hands-on administration, monitoring, incident response, access controls, and systems security.
- Exam
- Knowledge exam
- Experience
- 1 year relevant experience
- Renewal
- Annual maintenance