SEARCH · COMPARE · CHOOSE YOUR PATH

Cybersecurity Certifications

Explore major active cybersecurity certifications by role, level, provider, exam style, experience, and renewal requirements.

80certifications
18providers
20career tracks
25practical exams
80 matching certifications
AAISM

ISACA

Advanced in AI Security Management

AI security Advanced Knowledge

Advanced credential for governing and managing AI security risk within enterprise programs.

Exam
Knowledge exam plus base credential
Experience
Active CISM required
Renewal
Check provider
AZ-500

Microsoft

Microsoft Azure Security Engineer Associate

Cloud security Intermediate Knowledge

Azure posture, threat protection, identity, networking, compute, storage, and compliance implementation.

Exam
Knowledge exam
Experience
Azure administration experience
Renewal
Retires Aug 31, 2026

Important: Scheduled to retire on August 31, 2026. Do not start without checking Microsoft's replacement path.

CAPE

Hack The Box

HTB Certified Active Directory Pentesting Expert

Red teaming Advanced Practical

Advanced Active Directory attack paths, Kerberos, NTLM, C2, and post-exploitation.

Exam
Hands-on engagement plus report
Experience
Advanced AD pentesting skills
Renewal
Check provider
CC Cybersecurity

ISACA

Certified Cybersecurity

Foundations Entry Knowledge

Entry pathway covering cybersecurity concepts and practical organizational controls.

Exam
Knowledge exam
Experience
No formal prerequisite
Renewal
Check provider
CCIE Security

Cisco

Cisco Certified Internetwork Expert Security

Network security Expert Practical

Expert design, deployment, operation, optimization, and automation of complex security solutions.

Exam
Core exam plus hands-on lab
Experience
Expert network security experience
Renewal
3 years
CCISO

EC-Council

Certified Chief Information Security Officer

Leadership and architecture Expert Knowledge

Governance, controls, audit, security program management, finance, strategy, and executive leadership.

Exam
Knowledge exam plus experience eligibility
Experience
Senior management experience
Renewal
3 years
CCNP Security

Cisco

Cisco Certified Network Professional Security

Network security Advanced Knowledge

Network security architecture, firewalls, VPN, identity, content security, and automation.

Exam
Core plus concentration exams
Experience
Professional network security experience
Renewal
3 years
CCRTS

CREST

CREST Certified Red Team Specialist

Red teaming Advanced Knowledge

Specialist credential for planning and conducting sophisticated red-team operations.

Exam
Proctored exam
Experience
Senior red-team experience
Renewal
Check provider
CCST Cybersecurity

Cisco

Cisco Certified Support Technician Cybersecurity

Foundations Entry Knowledge

Security principles, endpoint protection, vulnerability assessment, network defense, and incident handling.

Exam
Knowledge exam
Experience
No formal prerequisite
Renewal
Check provider
CCT APP

CREST

CREST Certified Tester - Application

Application security Advanced Practical

Senior benchmark for web applications, APIs, databases, containers, cloud, and macOS testing.

Exam
Proctored practical and knowledge exam
Experience
Senior application tester experience
Renewal
Check provider
CCT INF

CREST

CREST Certified Tester - Infrastructure

Penetration testing Advanced Practical

Senior infrastructure penetration-testing benchmark for networks and operating systems.

Exam
Proctored practical and knowledge exam
Experience
Senior practitioner experience
Renewal
Check provider
CDPSE

ISACA

Certified Data Privacy Solutions Engineer

Privacy Advanced Knowledge

Privacy governance, architecture, and data lifecycle implementation using privacy by design.

Exam
Knowledge exam plus experience validation
Experience
3 years relevant experience
Renewal
Annual CPE
CEH

EC-Council

Certified Ethical Hacker

Penetration testing Intermediate Knowledge

Broad ethical hacking curriculum with strong employer and government recognition.

Exam
Knowledge exam
Experience
2 years recommended or official training
Renewal
3 years
CEH Practical

EC-Council

Certified Ethical Hacker Practical

Penetration testing Intermediate Practical

Practical validation of common ethical hacking techniques and tools.

Exam
Hands-on practical exam
Experience
CEH skills recommended
Renewal
3 years
CGEIT

ISACA

Certified in the Governance of Enterprise IT

Leadership and architecture Expert Knowledge

Enterprise IT governance, benefits realization, risk optimization, and resource optimization.

Exam
Knowledge exam plus experience validation
Experience
5 years governance experience
Renewal
Annual CPE
CHFI

EC-Council

Computer Hacking Forensic Investigator

Digital forensics Intermediate Knowledge

Forensic readiness, evidence handling, acquisition, investigation, and reporting.

Exam
Knowledge exam
Experience
Security or IT experience helpful
Renewal
3 years
CIPM

IAPP

Certified Information Privacy Manager

Privacy Intermediate Knowledge

Building, operating, measuring, and improving an organizational privacy program.

Exam
Knowledge exam
Experience
Privacy program experience helpful
Renewal
2 years
CIPP/E

IAPP

Certified Information Privacy Professional - Europe

Privacy Intermediate Knowledge

European data protection law, GDPR, regulators, cross-border data, and compliance practice.

Exam
Knowledge exam
Experience
Privacy or compliance knowledge helpful
Renewal
2 years
CIPT

IAPP

Certified Information Privacy Technologist

Privacy Intermediate Knowledge

Privacy engineering, data lifecycle, privacy-enhancing technologies, and privacy by design.

Exam
Knowledge exam
Experience
Technical privacy experience helpful
Renewal
2 years
CKS

Cloud Native Computing Foundation

Certified Kubernetes Security Specialist

Platform security Advanced Practical

Cluster hardening, system hardening, supply chain, runtime security, and incident response in Kubernetes.

Exam
Performance-based practical exam
Experience
Active CKA required
Renewal
2 years
CPENT

EC-Council

Certified Penetration Testing Professional

Penetration testing Advanced Practical

Advanced network, web, IoT, OT, evasion, pivoting, and reporting skills.

Exam
Hands-on cyber-range exam
Experience
Advanced pentest experience
Renewal
3 years
CPIA

CREST

CREST Practitioner Intrusion Analyst

Incident response Entry Knowledge

Entry pathway for intrusion analysis and incident-response work.

Exam
Proctored exam
Experience
Early-career analyst knowledge
Renewal
Check provider
CPTIA

CREST

CREST Practitioner Threat Intelligence Analyst

Threat intelligence Entry Knowledge

Entry pathway for cyber threat intelligence collection, assessment, and reporting.

Exam
Proctored exam
Experience
Early-career intelligence knowledge
Renewal
Check provider
CRIA

CREST

CREST Registered Intrusion Analyst

Incident response Intermediate Knowledge

Intermediate credential for investigating intrusions and handling incidents.

Exam
Proctored exam
Experience
Frequent relevant experience
Renewal
Check provider
CRISC

ISACA

Certified in Risk and Information Systems Control

Risk and GRC Advanced Knowledge

Enterprise IT risk identification, assessment, response, reporting, controls, and monitoring.

Exam
Knowledge exam plus experience validation
Experience
3 years relevant experience
Renewal
Annual CPE
CRT

CREST

CREST Registered Penetration Tester

Penetration testing Intermediate Practical

Government-recognized infrastructure and web penetration-testing credential.

Exam
Proctored practical and knowledge exam
Experience
Valid CPSA required
Renewal
Check provider
CTIA

EC-Council

Certified Threat Intelligence Analyst

Threat intelligence Intermediate Knowledge

Threat intelligence lifecycle, collection, analysis, reporting, and operationalization.

Exam
Knowledge exam
Experience
Security analysis experience helpful
Renewal
3 years
CyberOps Associate

Cisco

Cisco Certified CyberOps Associate

SOC and defense Entry Knowledge

Security monitoring, host analysis, network intrusion analysis, and incident response.

Exam
Knowledge exam
Experience
No formal prerequisite
Renewal
3 years
ECIH

EC-Council

EC-Council Certified Incident Handler

Incident response Intermediate Knowledge

Incident preparation, detection, triage, containment, recovery, and common attack scenarios.

Exam
Knowledge exam
Experience
Security operations experience helpful
Renewal
3 years
eCPPT

INE Security

Certified Professional Penetration Tester

Penetration testing Intermediate Practical

Professional network and web penetration testing with practical exploitation and reporting.

Exam
Hands-on lab exam
Experience
2+ years offensive security recommended
Renewal
3 years
eWPT

INE Security

Web Application Penetration Tester

Application security Intermediate Practical

Professional web testing methodology, analysis, exploitation, and reporting.

Exam
Hands-on lab exam
Experience
Basic web pentest experience
Renewal
3 years
eWPTX

INE Security

Web Application Penetration Tester eXtreme

Application security Advanced Practical

Advanced practical testing of modern web applications and complex exploit chains.

Exam
Hands-on lab exam
Experience
Advanced web pentest experience
Renewal
3 years
GCFE

GIAC

GIAC Certified Forensic Examiner

Digital forensics Intermediate Knowledge

Windows forensic acquisition, browser artifacts, email, filesystems, registry, and user activity.

Exam
Proctored knowledge exam
Experience
Windows administration helpful
Renewal
4 years
GCIA

GIAC

GIAC Certified Intrusion Analyst

SOC and defense Advanced Knowledge

Traffic analysis, intrusion detection, protocol analysis, and network-based threat detection.

Exam
Proctored knowledge exam
Experience
Packet analysis and IDS experience
Renewal
4 years
GCSA

GIAC

GIAC Cloud Security Automation

Cloud security Advanced Knowledge

Secure DevOps, infrastructure as code, CI/CD, cloud automation, containers, and security testing.

Exam
Proctored knowledge exam
Experience
Cloud and DevOps experience
Renewal
4 years
GCTI

GIAC

GIAC Cyber Threat Intelligence

Threat intelligence Advanced Knowledge

Intelligence requirements, collection, analysis, attribution, campaigns, and intelligence products.

Exam
Proctored knowledge exam
Experience
Threat intelligence experience helpful
Renewal
4 years
GPCS

GIAC

GIAC Public Cloud Security

Cloud security Intermediate Knowledge

Security controls across AWS, Azure, and Google Cloud, including identity, networking, data, and logging.

Exam
Proctored knowledge exam
Experience
Public cloud experience helpful
Renewal
4 years
GPEN

GIAC

GIAC Penetration Tester

Penetration testing Intermediate Knowledge

Planning, reconnaissance, exploitation, password attacks, web testing, and penetration-test process.

Exam
Proctored knowledge exam
Experience
Pentest experience helpful
Renewal
4 years
GREM

GIAC

GIAC Reverse Engineering Malware

Malware analysis Advanced Knowledge

Static and dynamic malware analysis, reverse engineering, document malware, and behavioral analysis.

Exam
Proctored knowledge exam
Experience
Assembly and debugging fundamentals
Renewal
4 years
GSEC

GIAC

GIAC Security Essentials

Foundations Intermediate Knowledge

Applied security across defense, networking, Linux, Windows, cryptography, cloud, and incident handling.

Exam
Proctored knowledge exam
Experience
Practical IT experience helpful
Renewal
4 years
GWAPT

GIAC

GIAC Web Application Penetration Tester

Application security Intermediate Knowledge

Web architecture, reconnaissance, authentication, injection, client-side attacks, and testing process.

Exam
Proctored knowledge exam
Experience
Web testing experience helpful
Renewal
4 years
GWEB

GIAC

GIAC Certified Web Application Defender

Application security Intermediate Knowledge

Secure coding and defensive controls for authentication, sessions, input, APIs, and modern web stacks.

Exam
Proctored knowledge exam
Experience
Developer or AppSec experience helpful
Renewal
4 years
GXPN

GIAC

GIAC Exploit Researcher and Advanced Penetration Tester

Red teaming Advanced Knowledge

Advanced exploitation, fuzzing, network attacks, crypto attacks, and custom tooling.

Exam
Proctored knowledge exam
Experience
Advanced offensive experience
Renewal
4 years
KLCP

OffSec

Kali Linux Certified Professional

Foundations Entry Knowledge

Kali Linux administration, package management, networking, security, and enterprise use.

Exam
Knowledge exam
Experience
Linux fundamentals
Renewal
Does not expire
OSAI+

OffSec

OffSec AI Security Professional Plus

AI security Advanced Practical

Hands-on assessment of AI systems, models, agents, and AI-enabled applications.

Exam
Proctored practical exam
Experience
AI and offensive security experience
Renewal
3 years
OSEP

OffSec

OffSec Experienced Penetration Tester

Red teaming Advanced Practical

Advanced client-side attacks, defense evasion, Active Directory tradecraft, and network compromise.

Exam
48-hour proctored practical exam
Experience
OSCP-level skills
Renewal
Does not expire
OSWA

OffSec

OffSec Web Assessor

Application security Entry Practical

Foundational hands-on web vulnerability discovery and exploitation.

Exam
24-hour proctored practical exam
Experience
Basic web testing knowledge
Renewal
Does not expire
OSWP

OffSec

OffSec Wireless Professional

Wireless security Intermediate Practical

802.11 reconnaissance, attacks, encryption weaknesses, and wireless network exploitation.

Exam
Proctored practical exam
Experience
Wireless and Linux fundamentals
Renewal
Does not expire
PCNSE

Palo Alto Networks

Palo Alto Networks Certified Network Security Engineer

Network security Advanced Knowledge

Design, deployment, configuration, maintenance, and troubleshooting of Palo Alto Networks security platforms.

Exam
Knowledge exam
Experience
Firewall deployment experience
Renewal
2 years
PenTest+

CompTIA

CompTIA PenTest+

Penetration testing Intermediate Knowledge

Scoping, vulnerability discovery, attacks, lateral movement, reporting, cloud, APIs, and AI attack concepts.

Exam
Knowledge plus performance questions
Experience
3-4 years recommended
Renewal
3 years
PJPT

TCM Security

Practical Junior Penetration Tester

Penetration testing Entry Practical

Internal Active Directory penetration test with a professional reporting component.

Exam
Practical engagement plus report
Experience
Beginner-friendly
Renewal
Does not expire
PWPA

TCM Security

Practical Web Pentest Associate

Application security Entry Practical

Associate-level web application penetration test with professional reporting.

Exam
2-day practical plus report
Experience
Basic web and networking knowledge
Renewal
Check provider
PWPP

TCM Security

Practical Web Pentest Professional

Application security Advanced Practical

Professional-level web application assessment with realistic reporting.

Exam
Practical engagement plus report
Experience
Professional web pentest skills
Renewal
Check provider
SC-200

Microsoft

Microsoft Security Operations Analyst Associate

SOC and defense Intermediate Knowledge

Microsoft Sentinel, Defender XDR, threat hunting, incident response, and security operations.

Exam
Knowledge exam
Experience
Microsoft security operations experience
Renewal
1 year
SC-300

Microsoft

Microsoft Identity and Access Administrator Associate

Identity security Intermediate Knowledge

Identity lifecycle, authentication, access management, workload identities, and identity governance.

Exam
Knowledge exam
Experience
Microsoft Entra experience
Renewal
1 year
SC-900

Microsoft

Microsoft Security, Compliance, and Identity Fundamentals

Cloud security Entry Knowledge

Microsoft security, compliance, identity, Zero Trust, Entra, Defender, and Purview fundamentals.

Exam
Knowledge exam
Experience
No formal prerequisite
Renewal
Does not expire
SecAI+

CompTIA

CompTIA SecAI+

AI security Intermediate Knowledge

Securing AI systems and using AI in cybersecurity operations across governance, threats, and controls.

Exam
Knowledge plus performance questions
Experience
Security+ level knowledge recommended
Renewal
Check provider
SecurityX

CompTIA

CompTIA SecurityX

Security engineering Advanced Knowledge

Enterprise architecture, engineering, operations, governance, and advanced technical integration.

Exam
Knowledge plus performance questions
Experience
Senior security experience recommended
Renewal
3 years
SSCP

ISC2

Systems Security Certified Practitioner

Security engineering Intermediate Knowledge

Hands-on administration, monitoring, incident response, access controls, and systems security.

Exam
Knowledge exam
Experience
1 year relevant experience
Renewal
Annual maintenance

CHOOSE FOR THE JOB

Do not collect certifications without a target role

  1. 01
    Read job descriptions

    Note which credentials appear repeatedly in your region and target companies.

  2. 02
    Match the exam style

    Use practical exams to prove execution. Use broad credentials when employers need governance or architecture coverage.

  3. 03
    Build public proof

    Pair the certification with reports, labs, detections, code, or threat models that demonstrate judgment.

Last reviewed: 2026-08-03. Certification names, availability, pricing, and renewal rules change. Confirm current requirements with the official provider before purchasing.