Certifications in context

Not a catalogue. A context layer.

For every credential: what it actually unlocks, when it matters in your progression, what experience usually comes first, and what it won't magically solve. Anchored on the certifications hiring managers in IT, security, cloud, DevOps and GRC actually recognise.

Practitioner opinion, not vendor guidance.
Most over-claimed

CISSP at junior level

Listed as 'entry-level security' on countless job ads. It isn't. The exam is passable in months; the five years of paid security experience required for full certification are not. Use it to consolidate seniority, not to enter the field.

Read the full take on CISSP, in context
Strongest signal

Cloud associates still move salaries

AWS SAA and AZ-104 remain the clearest paid signal in the market, not because the exams are hard, but because the roles they map to are scarce and well-funded. If you only finish one cert this year and want comp to move, pick one of these.

Read the full take on AWS SAA, in context
Quietly underrated

CCNA, in a cloud-first market

Unfashionable, and that's exactly why it works. Cloud and security engineers who actually understand routing, subnets and TLS handshakes get promoted faster than those who don't. CCNA is still the cleanest way to earn that fluency.

Read the full take on CCNA, in context
Honest tradeoff

Security+ opens doors it can't hold

Good enough to clear HR filters and DoD 8570 boxes. Not good enough to carry you through a technical interview alone. Treat it as a permission slip, not a qualification. Pair it with a home lab, a SOC tool, or scripting before applying.

Read the full take on Security+, in context

These are our calls based on what hiring panels and infra teams actually look for in 2026. They are professional opinion, not statements about exam quality or vendor conduct. Your context will vary. Treat every verdict as a starting point for your own judgement.

Strong hiring signal Solid / situational Niche or vendor-specific
84 shown

Foundations

Vendor-neutral baseline certs. HR-recognised, but rarely land roles alone.

Networking

The base layer cloud and security stand on. Hands-on, durable.

Defensive Security

SOC, detection, SIEM. The realistic on-ramp into security.

GIAC GCFA

SANS forensic analyst. The gold-standard DFIR credential for serious incident teams.

Specialist

CySA+

Blue-team extension of Security+. Useful for SOC promotion talks, weaker as a first cert.

Intermediate

Splunk Core Certified User

Vendor cert that proves you can drive a Splunk SIEM, narrow, but instantly useful in Splunk shops.

Intermediate

GIAC GSEC

GIAC's foundational security cert. Respected by SANS-leaning employers, expensive relative to value.

Intermediate

GIAC GCIA

Deep packet / detection analyst cert. Narrow but highly respected for IR and detection engineering.

Intermediate

GIAC GCIH

SANS incident-handling. Operationally aligned and widely respected for IR and senior SOC.

Intermediate

Microsoft SC-200

The canonical Microsoft SOC credential, direct fit for Sentinel / Defender shops.

Intermediate

Blue Team Level 1

Security Blue Team Level 1. Most realistic hands-on cert for Tier-1/2 SOC work.

Intermediate

Certified CyberDefender (CCD)

Certified CyberDefender (HTB). Hands-on DFIR-adjacent cert, increasingly recognised in defensive teams.

Intermediate

EC-Council CHFI

EC-Council forensic investigator, common in law-enforcement-adjacent and compliance markets.

Intermediate

Microsoft SC-400

Microsoft Information Protection / Purview specialty, the compliance-coded cert in the SC series.

Advanced

GIAC GMON

SANS continuous-monitoring cert, closest SANS equivalent to a detection-engineering credential.

Advanced

GIAC GNFA

SANS network forensic analyst, narrow but credible for telemetry-heavy IR teams.

Specialist

GIAC GREM

SANS malware RE cert, the strongest mainstream credential for malware analysts.

Specialist

EC-Council CND

EC-Council Network Defender. Recognised in compliance-driven environments; practitioners typically pair it with labs or SOC work.

Intermediate

Offensive Security

Pentest, red team. Slow ramp; entered after SOC or SWE experience.

OSCP

Still the most-recognised offensive cert, but it gates on lab time, not on the exam itself.

Specialist

PNPT

Practical, AD-heavy offensive cert. Cheaper and arguably more realistic than OSCP for internal pentest work.

Intermediate

CompTIA PenTest+

Recognised in compliance-driven shops; carries far less weight than OSCP/PNPT in technical interviews.

Intermediate

CEH

Still passes HR filters in compliance-driven hiring; practitioners typically pair it with hands-on work (HTB / labs / OSCP).

Intermediate

GIAC GPEN

SANS pentest cert. Strong in gov/consulting markets, expensive vs OSCP for similar signal.

Intermediate

GIAC GWAPT

SANS web app pentest cert. Credible in SANS-funded shops; OSWE is the deeper alternative.

Advanced

CPTS

HTB's modern offensive benchmark, respected by practitioners, still building HR recognition.

Specialist

CRTO

Zero-Point Security red-team cert. Modern Cobalt Strike tradecraft, increasingly the de-facto red-team cert.

Specialist

OSEP

OffSec's evasion / advanced AD cert, only meaningful after OSCP and red-team exposure.

Specialist

OSWE

OffSec's web-exploitation cert. The deepest hands-on AppSec credential for source-aware testers.

Specialist

GIAC GXPN

SANS exploit-dev cert. Narrow, expensive, only meaningful in vuln-research-adjacent roles.

Specialist

eJPT

Cheap, hands-on entry to offensive security, great warm-up, not a hiring credential by itself.

Beginner

Cloud

AWS / Azure / GCP. Strongest senior salary ladder in tech.

AWS Solutions Architect. Associate

The cloud cert that actually moves resumes; treat it as a baseline, not a finish line.

Intermediate

AWS Cloud Practitioner

AWS vocabulary primer. Useful for first cloud roles, transparent at any senior level.

Beginner

AWS SysOps

Operations-focused counterpart to SAA, heavier on monitoring, automation, and incident response.

Intermediate

AWS Developer

Developer-flavoured AWS cert. Most useful if you actually ship code on Lambda/DynamoDB/CDK.

Intermediate

Azure Administrator (AZ-104)

Practical Azure administrator cert. The closest equivalent to AWS SysOps in the Microsoft world.

Intermediate

Google Cloud Associate

GCP's associate cert, niche but premium-paid where Google Cloud lands.

Intermediate

CSA CCSK

Vendor-neutral cloud-security primer. Cheap, broad, lighter than CCSP.

Intermediate

Hybrid Server Admin (AZ-800)

Hybrid Windows Server on Azure. The cert ex-sysadmins use to translate into the cloud.

Intermediate

Hybrid Server Services (AZ-801)

AZ-800's senior sibling, hybrid security, monitoring, recovery.

Intermediate

Microsoft MS-102

Microsoft 365 Administrator, tenants, Exchange Online, Entra, Teams, compliance.

Intermediate

AWS Security Specialty

Strong signal for cloud-security-leaning roles. Assumes you already speak AWS fluently.

Advanced

Azure Security Engineer (AZ-500)

Azure security engineer cert. Practical and recognised in enterprise EU / regulated industries.

Advanced

Azure Architect Expert

Azure solutions architect. The senior design cert, only credible with production scars.

Specialist

GCP Pro Cloud Security Engineer

GCP's senior cloud-security credential, narrow market, strong signal inside GCP shops.

Specialist

(ISC)² CCSP

(ISC)²'s senior cloud-security cert. CISSP-adjacent, weighted toward architecture and program work.

Leadership

AZ-900

Azure vocabulary primer. Required to make AZ-104 stick, not a hiring signal on its own.

Beginner

AWS SA Pro

AWS SA Pro. See the relationship graph for context.

Specialist

Identity Security

IAM, PAM, SSO, Zero Trust. Often entered from AD or cloud.

Governance & Risk

Audit, risk and compliance. Senior management lane.

ISACA CISA

ISACA's audit cert. The credential of choice for internal/external IT audit and audit-adjacent GRC.

Advanced

CISSP

Senior governance signalling cert. Useful for management lanes, not for hands-on engineering.

Leadership

CISM

ISACA's management-coded cert. The CISSP alternative for governance and program leads.

Leadership

CRISC

ISACA's risk credential. The dedicated counterpart to CISM for risk-coded governance lanes.

Intermediate

(ISC)² CGRC

ISC2 governance / risk / compliance cert (formerly CAP). Narrow but credible in federal / regulated markets.

Intermediate

CASP+

Hands-on senior security generalist cert, quietly respected, mostly in defence/contractor space.

Advanced

ISO 27001 Lead Implementer

ISO 27001 Lead Implementer. The cert that gets you on certification programs, not running them.

Advanced

ISO 27001 Lead Auditor

ISO 27001 Lead Auditor, for the audit side of the same standard.

Advanced

TOGAF 10

Enterprise architecture framework cert. Meaningful only at enterprise scale, almost irrelevant elsewhere.

Leadership

Microsoft SC-100

Microsoft security architect. The senior design cert for the Microsoft security stack.

Leadership

EC-Council C|CISO

EC-Council's CISO-prep cert. Narrower employer recognition than CISM/CISSP in most markets.

Leadership

Platform / DevSecOps

Kubernetes, IaC, pipelines. Code fluency required.