A certification is legitimate when a real certifying body stands behind it, a genuine assessment sits inside it, and a third party can confirm you earned it. If any of those three legs is missing — no identifiable organisation, no meaningful exam, no way for an employer to verify the credential — you are probably looking at a certificate mill, however polished the website looks.
That three-leg test is the whole article in one paragraph. The rest of this guide turns it into a practical checklist you can run in fifteen minutes, before you hand over money, plus the specific warning signs that should make you close the tab. Note the lane we are in: this is a buyer's guide to judging whether a certification programme is credible. If you are an employer trying to confirm that a candidate really holds a credential they claim, that is a different task — most major providers run verification portals for exactly that purpose, and the provider's own site is the place to start.
Why fake and weak certifications exist at all
Certification sits in a lightly regulated space. Unlike a licence — which a government grants and can revoke — anyone can register a domain, design a badge, and sell a "certification". Some of these products are honest but weak (a completion certificate for watching videos). Some are deliberately deceptive, trading on names that sound like established bodies. The financial incentive is obvious: candidates pay upfront, and the seller bears almost no cost per credential issued.
That does not mean unfamiliar equals fake. New, niche and regional certifying bodies launch legitimately all the time. It means the burden of proof is on the programme, and you are entitled to check.
The 15-minute legitimacy checklist
Work through these seven checks in order. A legitimate programme passes most of them easily; a mill usually fails several within the first five minutes.
1. Identify the certifying body — precisely
Find the full legal name of the organisation issuing the credential, not just the brand on the badge. Then answer three questions: Who runs it? How long has it existed? What else has it published — exam objectives, policies, governance documents? A credible body has a visible organisational footprint: named leadership or governance structure, a physical or registered presence, published policies on retakes, appeals and misconduct. A mill typically has a sales page, a checkout, and nothing else.
Watch for name mimicry. Deceptive programmes often adopt titles one word away from an established credential, or acronyms that collide with famous ones. If the name rings a bell, confirm you are on the organisation that made the bell ring.
2. Look for third-party accreditation — and understand what it means
Accreditation is the strongest single signal, because it means an external auditor has examined how the certification is built and maintained. The reference point for personnel certification is ISO/IEC 17024, the international standard for bodies that certify people; accreditation organisations such as ANAB (the ANSI National Accreditation Board) assess certification programmes against it. Serious credentials advertise this: ISC2's CISSP, for example, is ANAB-accredited and approved under U.S. Department of Defense Manual 8140.03 — the kind of externally checkable claim a mill cannot fake for long.
Two cautions. First, verify the accreditation claim on the accreditor's own directory, not just the certification body's marketing page — a logo is easy to copy. Second, absence of ISO/IEC 17024 accreditation is not automatic disqualification. Many respected vendor certifications (cloud platforms, networking vendors) derive their credibility from the vendor's market position and exam rigour rather than a personnel-certification accreditation. Accreditation is a strong positive signal; its absence simply moves your scrutiny to the remaining checks.
3. Examine the assessment itself
Legitimate certifications publish how they test you before you register. Look for a public exam guide or objectives document, a stated question format and duration, a defined passing standard, and — critically — proctoring. Established programmes deliver exams through supervised channels: test centres or monitored online sessions with identity checks. Pearson VUE's online-proctoring service, used by major providers, requires a system test, a private room and consent to live monitoring throughout the exam; CompTIA's online-testing rules go as far as mandating a webcam room scan, a cleared work surface and ID that exactly matches your registration name.
A programme that hands you a certificate for finishing a video course, or offers an "exam" that is untimed, unproctored and retakeable instantly until you pass, is selling a completion certificate — which has its uses, but is not a professional certification and should not be priced like one. The distinction between course certificates and proctored credentials matters enough that we cover it separately in our guide to whether online certifications are worth it.
4. Confirm a verification mechanism exists
Ask one question: if an employer wanted to confirm my credential, how would they do it? Legitimate bodies provide an answer — a verification portal, a credential ID an employer can check with the issuer, or digital badges issued through a badging platform with cryptographic backing. If the only proof of your achievement is a PDF that anyone with a graphics editor could produce, employers will treat it accordingly. Before paying, search the provider's site for "verify" or "digital badge"; if nothing surfaces, email and ask. Silence is an answer.
5. Check the requirements structure
Oddly, entry barriers are a legitimacy signal. Real certification programmes publish eligibility rules and retake policies because they are protecting the credential's meaning — CISSP requires five years of cumulative paid work experience, for instance, and many providers that require nothing still publish recommended experience levels. A mill has no reason to gate anything; every barrier costs a sale. Zero prerequisites alone proves nothing (excellent entry-level exams have none either), but a complete absence of published policies — eligibility, retakes, appeals, renewal — is a tell. If you want to understand what requirement types exist and why providers impose them, see our overview of certification requirements.
6. Test the market signal
A certification's ultimate legitimacy is whether the people you want to impress recognise it. Search job listings in your target role for the credential's name. Search professional forums and communities for practitioner discussion. Look for the credential appearing in third-party contexts the seller does not control: employer job descriptions, government or defence approval frameworks, industry association references. A legitimate mid-tier certification generates at least some independent chatter; a mill generates only its own marketing and affiliate reviews.
7. Scrutinise the price and the pitch
Legitimate exam fees are published, fixed and boring: AWS lists its Cloud Practitioner exam at $100 USD and ISC2 lists CISSP at $749 in most regions, on stable pricing pages, with no countdown timers. Mills behave like discount retailers — perpetual "70% off ends tonight" pricing, bundles of five certifications for one fee, lifetime deals. Real certifying bodies also never guarantee you will pass, because a guaranteed pass would make the assessment meaningless. Any programme promising certification with "no exam needed" based on your "life experience" — a classic diploma-mill pitch that migrated to certifications — fails the legitimacy test outright.
Most of the checklist involves judgement. These signs do not:
- Pay-for-credential offers. Any route to the certificate that skips assessment entirely.
- Pass guarantees. "100% pass rate" or "money back if you fail on the first attempt, guaranteed" from the certifying body itself.
- Unverifiable accreditation claims. Logos of accreditors or partners that do not list the programme in their own directories.
- Name mimicry. A title engineered to be mistaken for an established credential.
- No governance surface. No retake policy, no appeals process, no code of conduct, no named organisation behind the checkout page.
- Instant everything. Register, "test", and receive your certificate inside an hour.
One adjacent trap worth naming: even around fully legitimate exams, an ecosystem of illegitimate preparation sellers exists — sites offering what they claim are leaked live exam questions ("dumps"). Using them violates provider policies and can void a credential you honestly need. Legitimate practice materials are study aids built from published exam objectives, used to test your understanding and expose weak domains — not to memorise answers. If you want to see what that looks like in practice, browse the free sample questions format ExamPractice publishes for the exams in its certification exam directory.
A worked example: vetting an unfamiliar credential
Suppose a colleague mentions a project-delivery certification you have never heard of. Applying the checklist: within five minutes you have found the certifying body's site, an exam-objectives PDF, a published fee, and a proctored, timed exam format — good signs. The accreditation page claims an ANAB relationship, so you spend two minutes on the accreditor's directory and find the programme listed — a strong sign. Job-board searches show the credential appearing in a modest number of listings in your region — enough to confirm real-world currency for a niche credential. Total time: about fifteen minutes, and you now know more than the seller's marketing would ever have told you.
Run the same routine on a mill and the wheels come off at step one or two: no identifiable organisation, an "accreditation" from a body that itself has no footprint, and a checkout page doing the work of a governance structure.
Legitimate but weak: the middle category
Not every credential that passes the fraud checks is worth your money. A programme can be honestly run, genuinely assessed and still carry little market weight — because the exam is shallow, the body is unknown in your industry, or the skills tested are trivially easy to acquire. Legitimacy is the floor, not the ceiling. Once a certification clears this article's checklist, the next question is whether it is worth pursuing at all, which our guide to what a professional certification is and whether it's worth getting tackles with a full cost-benefit framework — and choosing between several legitimate options is a separate decision process again.
Your pre-payment vetting routine
Before paying for any unfamiliar certification, confirm: (1) a named, findable certifying body; (2) an accreditation claim you verified at the source, or credibility earned another way; (3) a published, proctored, time-limited assessment with a defined passing standard; (4) a verification mechanism an employer could actually use; (5) published eligibility, retake and renewal policies; (6) independent evidence of market recognition; (7) stable, published pricing with no pass guarantees. Seven yeses and you are dealing with a legitimate credential — and can move on to the more interesting question of whether it deserves a place in your plan.