Exampractice
Cybersecurity

Cybersecurity Certifications Explained

What cybersecurity certifications actually are, who runs them, how exams and renewal work, and how the major providers differ — a plain-language map.

Alexander Novak · 7 min read
Exploded-view diagram labelling the parts of a cybersecurity certification: provider, exam, prerequisites, renewal cycle and fees

"CISSP" appears in job advertisements more or less as a job requirement, yet it is not a qualification from any university, government or employer — it is a credential issued by a member association, earned through a three-hour adaptive exam plus five years of documented work experience, and it lapses if the holder stops paying an annual fee. That one example contains almost everything newcomers find confusing about cybersecurity certifications: private bodies, exams, experience rules and expiry dates, all bundled under a four-or-five-letter acronym.

This article is a plain-language map of how the whole system works — what a security certification actually is, who issues them, what kinds exist, and what earning and keeping one involves. It deliberately makes no recommendations; if you want a verdict on where to start, that lives in our guide to the best cybersecurity certifications for beginners.

What a cybersecurity certification actually is

A cybersecurity certification is a credential awarded by a private certification body to an individual who passes that body's proctored exam and meets its other conditions (sometimes work experience, sometimes an endorsement from an existing member, sometimes nothing at all). It certifies a person, not a course completed: you can prepare however you like — books, videos, labs, formal training — because the exam, not the study route, is the gate.

That distinguishes certifications from three neighbours they are constantly confused with:

  • Degrees are academic awards from universities; they never expire and are not tied to one vendor's exam.
  • Course certificates (the Google Cybersecurity Certificate is the best-known security example) prove you finished a programme of study, not that you passed an independent proctored exam.
  • Licences are government-issued permissions to practise. Cybersecurity has no licensing regime; certifications are voluntary industry credentials that employers have chosen to treat as signals.

The anatomy of a certification

Every security certification, whoever issues it, is built from the same five parts. Once you can read these, any acronym becomes decodable.

1. The awarding body

The organisation whose name backs the credential and whose exam you sit — CompTIA, ISC2, ISACA, and so on. The body publishes the exam objectives (the official syllabus), sets fees, and enforces the rules.

2. The exam

Usually proctored — at a test centre or online under camera supervision — and built in one of a few formats: fixed-length multiple choice (ISACA's exams are 150 questions in four hours), multiple choice mixed with hands-on performance-based questions (CompTIA), computerised adaptive testing that adjusts difficulty as you answer (ISC2's CISSP runs 100–150 items in up to three hours), or lab-heavy hands-on testing (GIAC's CyberLive components; OffSec's 24-hour practical OSCP exam). Passing standards are typically scaled scores — 750 on CompTIA's 100–900 scale, 700 out of 1,000 at ISC2, 450 on ISACA's 200–800 scale — not raw percentages.

3. Prerequisites and experience rules

Some certifications anyone may attempt (Security+, ISC2's CC, every GIAC practitioner exam). Others require documented professional experience to certify — five years for CISSP and CISM, for example — though ISC2 and ISACA both let you pass the exam first and complete the experience afterwards. A common newcomer misreading: "recommended experience" on CompTIA pages is guidance about difficulty, not an entry rule.

4. Versions and exam codes

Exam content is refreshed every few years and each revision carries a code — Security+ is SY0-701 as of 2026; its predecessor SY0-601 is retired. The credential name on your certificate never includes the code; the code matters only for matching study materials to the live exam. Retirements catch people out constantly: CASP+ no longer exists as a current exam, having been renamed CompTIA SecurityX (CAS-005) in December 2024.

5. Renewal

Nearly all security certifications expire — commonly on a three-year cycle (CompTIA, ISC2, ISACA) or four years at GIAC — and are maintained through continuing education credits (CEUs or CPEs) plus maintenance fees. This is the part newcomers most often fail to budget for: a certification is a subscription to a professional standard, not a one-off trophy.

The major providers and how they differ in kind

Five bodies issue the bulk of the certifications you will see in security job advertisements, and each has a recognisable character.

ProviderWhat it isCharacter of its certsFlagship examples
CompTIAUS-based industry associationVendor-neutral, broad, exam-only entry at every levelSecurity+, CySA+, PenTest+, SecurityX
ISC2Membership association (renamed from "(ISC)²" in 2023)Experience-gated professional credentials with member obligationsCC, SSCP, CISSP, CCSP
ISACAAssociation rooted in audit and governanceBusiness-facing: audit, risk, security managementCISA, CISM, CRISC
EC-CouncilCommercial training-and-certification companyTraining-led, offensive-security brandingCEH, ECSA lineage
GIACCertification body affiliated with the SANS InstituteDeep, hands-on, open-book technical examsGSEC, GCIH, GPEN

Two structural notes help decode the market. First, GIAC and SANS are separate organisations by design — SANS sells the (expensive, optional) training courses, GIAC runs the exams, and no GIAC practitioner exam requires the course. Second, ISC2 and ISACA are membership bodies: certifying makes you a member with annual fees and ethics obligations, which is part of why employers read their credentials as professional standing rather than just exam passes. Vendor ecosystems (Cisco, Microsoft, AWS) also run security certifications tied to their own technologies — a sixth category this cluster covers elsewhere.

The types of certification, by role and level

Certifications sort along two axes. By level: entry (ISC2 CC, Security+), intermediate (CySA+, PenTest+, SSCP, GSEC), and advanced (CISSP, SecurityX, OSCP, CISM), where "advanced" usually means an experience requirement or a brutally practical exam. By specialism: defensive operations, offensive testing, governance/audit/risk, and niches like forensics, cloud security and industrial control systems. Which sequence suits which career is exactly the question this article does not answer — the full sequencing map is our guide to the best certifications for cybersecurity careers.

Government frameworks add a third sorting: the US NICE Workforce Framework defines 52 cyber work roles, and the Department of Defense's 8140 policy maps approved qualifications to those roles for its workforce — one reason certain certifications (Security+, CISSP among them) are near-mandatory in US defence-sector jobs.

What earning one actually involves, start to finish

  1. Choose the exam and download its official objectives from the provider's site — free in every case, and the only authoritative syllabus.
  2. Register and pay. Fees as of 2026 range from $199 (ISC2 CC) through roughly $425–$439 (Security+) to $749 (CISSP) and $999 per GIAC attempt — all varying by country, so confirm on the official pricing page.
  3. Prepare by any route you like, then verify readiness: practice questions used diagnostically — analysing which topic areas you miss, not memorising answers — followed by a timed simulation. ExamPractice's free sample questions cover many of the security exams named here, with fuller sets and a timed practice-test mode for subscribers.
  4. Sit the proctored exam at a test centre or online. Most providers show a preliminary result immediately or within days.
  5. Complete any post-exam steps — ISC2 requires an endorsement within nine months; ISACA charges a $50 application fee and requires the experience evidence within five years of passing.
  6. Maintain it: log CPE credits, pay the annual or cycle fee, or retake/upgrade before expiry.

If you fail, providers allow retakes under waiting-period rules that differ by body (CompTIA permits an immediate second attempt; ISACA imposes 30- and 90-day waits) — always at a fresh fee, which is the practical argument for benchmarking before booking.

Do cybersecurity certifications actually matter?

They matter as signals, and the signal strength varies by context. Employers use them to filter applications at volume; US defence work formally requires approved certifications for many roles under DoD 8140; and ISC2's 2024 Cybersecurity Workforce Study reported a global workforce gap of more than 4.7 million people, which is the demand backdrop against which employers lean on credentials to sort candidates quickly. What certifications cannot do is substitute for demonstrable skill in interviews or on the job — the industry's long-running consensus is that they open doors and experience keeps them open. Claims you should treat sceptically: any published "pass rate" for CISSP, CISM or similar (the major bodies do not publish them) and any single "average salary" attached to a cert without a named, dated source.

Where to go from here

You now have the grammar of the system: a certification is a renewable credential from a private body, decoded by its provider, level, specialism, exam format and maintenance rules. The natural next steps are choosing a lane — the staged sequencing in the cybersecurity certification roadmap — and getting a feel for real exam-style material, for which our sibling guide to free cybersecurity practice questions and the certification exams directory are useful first stops. Whichever acronym you eventually pursue, read its official objectives page before any third-party opinion, including ours.

Frequently asked questions

Are cybersecurity certifications the same worldwide?

The credentials themselves are — a CISSP earned in Lagos is the same credential as one earned in London. Exam pricing, available languages and local recognition vary by country, and each provider's site lists regional details.

Can a certification expire even if I keep working in security?

Yes. Work experience does not automatically renew a certification; you must log the required continuing-education credits and pay maintenance fees on the provider's cycle, or pass a current exam again.

Is training from the provider required to sit these exams?

Almost never for the bodies covered here — CompTIA, ISC2, ISACA and GIAC all allow self-study. The main exception pattern is EC-Council's CEH, where you either take official training or qualify via documented experience plus an application fee.

What is the difference between a proctored exam and an online course quiz?

Proctoring means your identity is checked and you are supervised (in person or by camera) under closed conditions, which is why employers treat proctored certifications as stronger evidence than course-completion certificates with unsupervised assessments.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like