FOUNDATIONAL
| Certification | Provider | Level | Prerequisites | Description |
|---|---|---|---|---|
| CompTIA A+ | CompTIA | Entry | No | IT fundamentals; good starting point before Security+ |
| CompTIA Network+ | CompTIA | Entry | No | Networking fundamentals underpinning all security work |
| CompTIA Security+ | CompTIA | Entry | No | General baseline for most roles; DoD 8570 required |
| Google Cybersecurity Certificate | Entry | No | Beginner-friendly intro to cybersecurity concepts | |
| CCNA | Cisco | Entry–Mid | No | Network config & security; prerequisite for advanced Cisco certs |
CLOUD SECURITY
| Certification | Provider | Level | Prerequisites | Description |
|---|---|---|---|---|
| Microsoft SC-900 | Microsoft | Entry | No | Entry-level Microsoft security, compliance & identity concepts |
| Microsoft AZ-500 | Microsoft | Mid | AZ-900 recommended | Azure security technologies; strong demand as Azure adoption grows |
| CCSK | CSA | Mid | No | Vendor-neutral cloud security knowledge; good foundation before CCSP |
| CCSP | ISC2 | Advanced | 5yr IT + 3yr infosec | Most respected cloud security cert; covers all major platforms |
| AWS Certified Security – Specialty | Amazon | Advanced | 5yr IT exp | AWS-specific; highly valued if your org runs on AWS |
DIGITAL FORENSICS INCIDENT RESPONSE [DFIR]
| Certification | Provider | Level | Prerequisites | Description |
|---|---|---|---|---|
| GCFE | SANS/GIAC | Mid | Recommended exp | Windows forensics & evidence handling |
| CHFI | EC-Council | Mid | No strict req | Covers forensic investigation methodology; law enforcement friendly |
| CCE | ISFCE | Mid | 2yr exp | Vendor-neutral computer forensics examiner credential |
| EnCE | OpenText | Mid–Advanced | 18mo exp + exam | EnCase tool certification; widely used in law enforcement & corporate IR |
| GCFA | SANS/GIAC | Advanced | GCFE or exp | Advanced forensics; memory analysis, APT investigations |
GOVERNANCE, RISK, COMPLIANCE [GRC]
| Certification | Provider | Level | Prerequisites | Description |
|---|---|---|---|---|
| CISSP | ISC2 | Advanced | 5yr exp in 2+ domains | The definitive leadership/architecture cert; required for senior roles |
| CISM | ISACA | Advanced | 5yr exp, 3yr mgmt | Best for pure security management & governance roles |
| CISA | ISACA | Advanced | 5yr audit/control exp | Top audit-focused credential; required at many consultancies & banks |
| CRISC | ISACA | Advanced | 3yr risk/IS control | Focused on IT risk management & control frameworks |
| ISO 27001 Lead Implementer | Various (PECB etc) | Advanced | Varies by body | Validates ability to implement ISMS per ISO 27001 standard |
MALWARE ANALYSIS
| Certification | Provider | Level | Prerequisites | Description |
|---|---|---|---|---|
| eCMAP | INE/eLearnSecurity | Mid–Advanced | Programming basics | Practical malware analysis cert; more affordable entry point than SANS |
| FOR610 (→ GREM) | SANS | Advanced | Programming knowledge | SANS course covering malware analysis techniques |
| GREM | SANS/GIAC | Advanced | Strong RE/malware exp | The definitive malware RE cert; covers static & dynamic analysis |
OPEN SOURCE INTELLIGENCE [OSINT]
| Certification | Provider | Level | Prerequisites | Description |
|---|---|---|---|---|
| GOSI | SANS/GIAC | Mid | Recommended exp | Validates OSINT methodology, data collection & analysis; most recognised |
| C|OSINT | McAfee Institute | Mid | Degree + 2yr exp | First globally accredited OSINT board certification |
| SEC497 (→ GOSI) | SANS | Mid | No | Practical OSINT course covering tools, sock puppets, dark web research |
| SEC587 (→ GOSINT) | SANS | Advanced | SEC497 recommended | Advanced OSINT; data mining, geolocation, advanced investigations |
OPERATIONAL TECHNOLOGY [OT]
| Certification | Provider | Level | Prerequisites | Description |
|---|---|---|---|---|
| ICS410 (→ GICSP) | SANS | Mid | IT/OT background | SANS course covering ICS/SCADA security essentials |
| GICSP | SANS/GIAC | Mid–Advanced | ICS/IT exp helpful | Most recognised OT/ICS security cert globally |
| CSSA | IACRB | Advanced | ICS security exp | Certified SCADA Security Architect; niche but valued in critical infra |
PENETRATION TESTING
| Certification | Provider | Level | Prerequisites | Description |
|---|---|---|---|---|
| CEH | EC-Council | Mid | 2 yrs exp or training | Well-known but more theory than hands-on; widely recognised by employers |
| PNPT | TCM Security | Mid | No | Practical, affordable alternative to OSCP; highly respected in community |
| CompTIA PenTest+ | CompTIA | Mid | Network+/Security+ | Vendor-neutral; covers full pentest lifecycle |
| OSCP | OffSec | Mid–Advanced | Yes (hacking exp) | Gold standard; 24hr practical exam on real machines |
| GPEN | SANS/GIAC | Advanced | Recommended exp | Covers network exploitation; pairs with SEC560 course |
| CRTO | Zero-Point Security | Advanced | Pentest exp | Focused on Cobalt Strike & red team ops; very practical |
| OSEP | OffSec | Advanced | OSCP recommended | Advanced evasion & post-exploitation techniques |
SOC ANALYST
| Certification | Provider | Level | Prerequisites | Description |
|---|---|---|---|---|
| CSA (Certified SOC Analyst) | EC-Council | Entry–Mid | No | Entry-level SOC focused; covers monitoring & triage |
| BTL1 (Blue Team Labs Level 1) | Security Blue Team | Entry–Mid | No | Affordable, hands-on blue team fundamentals |
| CompTIA CySA+ | CompTIA | Mid | Security+ recommended | Threat detection, SIEM, incident analysis; in-demand for SOC roles |
| GCIH | SANS/GIAC | Mid–Advanced | Recommended exp | Incident handling & response; covers attacker techniques |
| GCIA | SANS/GIAC | Mid–Advanced | Recommended exp | Network forensics & intrusion analysis; pairs with SEC503 |
THREAT INTELLIGENCE
| Certification | Provider | Level | Prerequisites | Description |
|---|---|---|---|---|
| CTIA | EC-Council | Mid | Cybersec background | Covers full threat intel lifecycle incl. OSINT, HUMINT, Python automation |
| eCTHP | INE/eLearnSecurity | Mid | Blue team exp | Practical threat hunting using MITRE ATT&CK; more affordable than SANS |
| GCTI | SANS/GIAC | Advanced | Exp in intel/SOC | Gold standard for threat intel; pairs with FOR578 course |
| FOR578 (→ GCTI) | SANS | Advanced | Exp recommended | SANS course covering CTI frameworks, adversary tracking |
| FOR508 (→ GCFE/GCFA) | SANS | Advanced | DFIR experience | Advanced IR & threat hunting; covers ransomware & APT hunting |
