Certification Exam Costs Explained
·13 min read
What certification exams actually cost across CompTIA, AWS, Cisco, Microsoft, ISC2 and PMI, why prices differ so much, and how pricing tiers work.
Continue readingWhy certification bodies audit applications and CPE claims, how candidates are selected, and what the main audit types involve across PMI, ISC2 and others.

Nobody proctors your CV. That is the quiet problem at the heart of experience-based certifications: an exam can be supervised, recorded and scored, but the claim that you led projects for 36 months, or worked five years in security domains, arrives on a form as unverified text. Audits are how certification bodies close that gap — by pulling a slice of applications and renewal claims aside and asking for proof.
If you have been selected for an audit and want the step-by-step walkthrough of what happens next, go straight to what happens during a certification audit. This article covers the layer underneath: why audit programmes exist, how selection works, and the distinct audit types you may meet across the major providers.
A certification is only worth what employers believe it verifies. Exam security handles one half of that — proctoring, identity checks, room scans. Audits handle the other half: the prerequisites and maintenance claims that no proctor ever sees.
Three claims in a typical certification lifecycle rest on the honour system until audited:
Without a credible chance of verification, every one of those claims would be an invitation to exaggerate, and the credential's value would erode for the honest majority who earned it. The audit programme is not really aimed at you as an individual; it is aimed at keeping the whole system honest. That is why audit selection is dominated by randomness rather than suspicion.
The major providers select most audits at random from the eligible pool. ISC2 states plainly that random application audits occur as part of its endorsement process. PMI likewise selects a portion of PMP applications for audit before granting exam eligibility. Neither publishes its selection rate or the full workings of its selection model, so treat any "X per cent of applications get audited" figure you see elsewhere as folklore — the honest answer is that selection odds are not published, and you should apply as if selection were certain.
Random selection has a practical implication people miss: being audited is not feedback. It does not mean your application looked weak, your experience seemed thin, or someone reported you. A flawless application and a shaky one draw from the same lottery.
Providers do not publish triggers, so nobody outside their audit teams can say definitively what — if anything — flags an application beyond the random draw. What is verifiable is what audits check: consistency between what you claimed and what your employers, supervisors and training providers can confirm. Applications with internal inconsistencies obviously fare worse once selected, whatever got them selected. The errors that commonly cause trouble at that point — overlapping dates, unreachable contacts, vague role descriptions — are catalogued in our guide to common certification application mistakes.
"Certification audit" covers three distinct checks, which land at different points in the credential lifecycle.
This is the PMP-style audit. You submit your application, PMI reviews it, and a selected subset must verify their claims — experience, education and contact hours — with supporting documentation before exam eligibility is granted. The application sits on hold until the audit is cleared. For a candidate this is the highest-stakes audit type, because it stands between you and the exam itself, and it arrives on the provider's timeline, not yours.
ISC2 inverts the order. You sit the CISSP (or CCSP, SSCP and so on) first; then, within nine months of passing, you submit an endorsement application in which an ISC2-certified professional in good standing vouches for your claimed experience — or ISC2 itself endorses you after employment verification. ISC2 audits a random selection of these endorsement applications. Passing the exam therefore proves knowledge, endorsement asserts experience, and the audit spot-checks that assertion. A candidate without the experience can still pass the exam and hold Associate of ISC2 status while earning it — the audit regime is precisely why the full credential cannot be shortcut.
The least discussed and, across a long career, the most likely to reach you. Renewal by continuing education runs on self-reported activity logs: ISC2 members log CPE credits (120 per three-year cycle for CISSP), ISACA requires 120 CPE hours per cycle with a 20-hour annual minimum reported each year, and PMI members log 60 PDUs per cycle. Providers audit samples of these submissions, asking for evidence that claimed activities — courses, conference attendance, self-study, teaching — actually happened. Because a CPE audit can look back across a full cycle, it rewards people who kept records as they went. Building that habit is the subject of how to prepare for a certification audit.
| Application audit (e.g. PMP) | Endorsement audit (e.g. ISC2) | CE/CPE audit (ISC2, ISACA, PMI) | |
|---|---|---|---|
| When it lands | After submission, before exam eligibility | After passing, during endorsement | During or after a renewal cycle |
| What is verified | Experience, education, contact hours | Claimed domain experience backed by an endorser | Logged CPE/PDU activities |
| Who confirms your claims | Supervisors, employers, training providers | Your endorser and/or employment verification | Certificates, records, activity evidence you retained |
| What is at stake | Exam eligibility | The credential being issued | The credential staying active |
| Best defence | Accurate application, warned contacts | Honest experience claims, a reachable endorser | Evidence filed at the moment each activity happens |
Two of the standard pieces of application advice exist purely because audits do.
First, write your application as if it will be audited — because it may be, and you will not know in advance. Practically, that means: only claim experience your named contacts would recognise and confirm; keep dates consistent with what an employer's records would show; and tell your listed supervisors they might be contacted, so an audit email does not catch them cold. A candidate who does this loses nothing if no audit comes and loses no sleep if one does.
Second, keep the documents behind every claim. Degree certificates, training completion certificates, and — once certified — evidence for every CPE or PDU you log. The renewal-side habit matters most, because a continuing-education audit can ask about an activity you completed years earlier. If you are building a system for staying current across one or more credentials, our guide to keeping your certifications current covers tracking CE efficiently; the audit-proofing angle is simply "file the certificate the day you earn it".
A realistic sketch: an IT programme manager applies for the PMP, listing three projects across two employers over four years. Her application is selected for audit. Because her listed supervisors already knew they were named and her contact-hours certificate was saved alongside the application, the audit is an administrative errand rather than a crisis. Her colleague, audited on an application naming a supervisor who left the company with no forwarding contact, faces a genuinely harder problem — not because he lied, but because he treated the application as a formality.
No — and the pattern is logical. Programmes with no experience prerequisite have nothing to audit at application time. Microsoft role-based certifications, CompTIA certifications and AWS certifications are earned by examination alone, so there is no application audit; identity and exam integrity are enforced at the test itself through proctoring. ISC2's entry-level Certified in Cybersecurity (CC) similarly has no experience requirement or endorsement. The audit burden tracks the prerequisite burden: the more a credential asserts about your career, the more its issuer must be able to verify.
The major providers do not publish selection rates, and third-party percentages are guesses. Plan on the assumption that any application can be selected.
No. Selection is predominantly random. It is quality control on the certification system, not a judgement about your application.
Yes — continuing-education audits verify the CPE or PDU activity you log to renew, and they can arrive during or after a renewal cycle. This is the main reason to retain CE evidence throughout each cycle.
Outcomes depend on the provider and on whether the issue is an error or a misrepresentation — consequences range from clarification requests to denial. The process and its possible endings are covered in what happens during a certification audit; for a failed application outright, see what to do if your certification application is rejected.
Every audited claim — experience, education, continuing education — is something the provider agreed to take your word for instead of making you prove it up front. Audits are the mechanism that makes that trust affordable, and random selection is what makes it fair. Apply accurately, warn your references, file your evidence as you earn it, and an audit becomes what it is designed to be: a routine check that the system, and your credential's value, are working. While an application audit holds your file, the study clock need not stop — the certification exams directory links to practice material for the exam waiting on the other side of approval.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·13 min read
What certification exams actually cost across CompTIA, AWS, Cisco, Microsoft, ISC2 and PMI, why prices differ so much, and how pricing tiers work.
Continue reading·7 min read
The real end-to-end cost of earning a professional certification — exam fees, training, materials and the extras most first-time candidates forget.
Continue reading·5 min read
When paid certification training earns its price and when self-study wins — a decision framework comparing courses, bootcamps and self-study by candidate situation.
Continue reading