Skip to main content
Certifications in context

Not a catalogue. A context layer.

For every credential: what it actually unlocks, when it matters in your progression, what experience usually comes first, and what it won't magically solve. Anchored on the certifications hiring managers in IT, security, cloud, DevOps and GRC actually recognise.

Written by James, a UK security architect. Hiring panels, not vendor brochures.

Practitioner opinion, not vendor guidance.
Most over-claimed

CISSP at junior level

CISSP has an experience requirement for full certification, with a potential qualifying waiver. Passing the exam alone is different from holding CISSP. Check ISC2's current eligibility rules and the role you are targeting.

Read the full take on CISSP, in context
Strongest signal

Cloud associates can support relevant applications

AWS SAA and AZ-104 can support applications for work on their respective platforms. Choose according to the responsibilities you want and the platform you can practise. Neither credential guarantees a salary increase or a shortlist place.

Read the full take on AWS SAA, in context
Quietly underrated

CCNA, in a cloud-first market

Unfashionable, and that's exactly why it works. Cloud and security engineers who actually understand routing, subnets and TLS handshakes get promoted faster than those who don't. CCNA is still the cleanest way to earn that fluency.

Read the full take on CCNA, in context
Honest tradeoff

Security+ opens doors it can't hold

Useful where a vacancy names Security+ or accepts it as supporting evidence. It does not guarantee screening success. Check the current employer requirements and demonstrate relevant practical work alongside it.

Read the full take on Security+, in context

These are our calls based on what hiring panels and infra teams actually look for in 2026. They are professional opinion, not statements about exam quality or vendor conduct. Your context will vary. Treat every verdict as a starting point for your own judgement.

Hiring signal
95 shown

Foundations

Vendor-neutral baseline certs. HR-recognised, but rarely land roles alone.

8 certs

Useful as proof you can sit an exam and learn a syllabus. Treat as a starter pistol, not a finish line. Anyone hiring for them already assumes you'll need a year of supervised work after.

Networking

The base layer cloud and security stand on. Hands-on, durable.

9 certs

Cisco CCNA

Industry-respected networking certification. Heavy emphasis on labs. Routing, switching, wireless basics, and the IP fabric every other role depends on.

Intermediate

Cisco CCNP Enterprise

Two-exam track (core + concentration). Validates deep enterprise routing, switching, and increasingly automation skills.

Specialist

Network+

Vendor-neutral networking primer, pair it with CCNA, don't end with it.

Beginner

Palo Alto PCNSA (retired)

Palo Alto Networks confirms PCNSA is a retired exam. Do not plan a new sitting. Existing credentials can remain valid until their individual expiry; inspect the current role-based portfolio for a suitable exam. No precise PCNSA retirement date is asserted here.

Intermediate

Fortinet NSE 4

Fortinet's mid-tier cert. Strong in regions and verticals where Fortinet dominates.

Intermediate

Juniper JNCIA

Juniper foundation, relevant in service-provider and large-enterprise Junos networks.

Intermediate

Azure Network Engineer (AZ-700)

Azure networking credential. Most relevant when the role includes Azure network design and operations.

Intermediate

CCNP Security

CCNP Security. Deep network-security cert; respected in carrier/enterprise, less so in cloud-native shops.

Advanced

Palo Alto PCNSE (retired)

The PCNSE exam retired on 31 July 2025. Palo Alto names Next-Generation Firewall Engineer as its replacement. An existing PCNSE credential can remain valid until its individual expiry; it is not a new exam to book.

Advanced

Defensive Security

SOC, detection, SIEM. The realistic on-ramp into security.

16 certs

GIAC GCFA

SANS forensic analyst. The gold-standard DFIR credential for serious incident teams.

Specialist

CySA+

Blue-team extension of Security+. Useful for SOC promotion talks, weaker as a first cert.

Intermediate

Cloud and AI Security Engineer (SC-500)

Relevant to Azure, hybrid and AI workload security; prepare a control implementation and verification example alongside study.

Intermediate

Splunk Core Certified User

Vendor cert that proves you can drive a Splunk SIEM, narrow, but instantly useful in Splunk shops.

Intermediate

GIAC GSEC

GIAC foundational security credential. Training and exam costs are separate considerations; check current vendor pricing and demonstrate the work behind the credential.

Intermediate

GIAC GCIA

GIAC intrusion-analysis credential focused on network traffic and detection. Compare exam-only and training options using current vendor prices; course attendance is not a universal hiring requirement.

Intermediate

GIAC GCIH

GIAC incident-handling credential. Consider it for incident-response responsibilities, using the current vendor price and your own experience rather than assuming a fixed training package is required.

Intermediate

Microsoft SC-200

The canonical Microsoft SOC credential, direct fit for Sentinel / Defender shops.

Intermediate

Blue Team Level 1

Security Blue Team Level 1. A practical option for developing junior SOC investigation skills.

Intermediate

Certified CyberDefender Level 2 (CCDL2)

CyberDefenders CCDL2, formerly CCD. A practical threat-hunting and forensic-investigation credential; employer recognition depends on the vacancy.

Intermediate

EC-Council CHFI

EC-Council forensic investigator, common in law-enforcement-adjacent and compliance markets.

Intermediate

Microsoft SC-401 (formerly SC-400)

Microsoft Information Protection / Purview specialty, the compliance-coded cert in the SC series.

Advanced

GIAC GMON

SANS continuous-monitoring cert, closest SANS equivalent to a detection-engineering credential.

Advanced

GIAC GNFA

SANS network forensic analyst, narrow but credible for telemetry-heavy IR teams.

Specialist

GIAC GREM

SANS malware RE cert, the strongest mainstream credential for malware analysts.

Specialist

EC-Council CND

EC-Council Network Defender. Recognised in compliance-driven environments; practitioners typically pair it with labs or SOC work.

Intermediate

Offensive Security

Pentest, red team. Slow ramp; entered after SOC or SWE experience.

12 certs

OSCP

Offensive Security Certified Professional. A 24-hour practical exam that remains the industry's most respected entry-to-mid penetration testing credential.

Specialist

PNPT

Practical, AD-heavy offensive cert. Cheaper and arguably more realistic than OSCP for internal pentest work.

Intermediate

CompTIA PenTest+

Recognised in compliance-driven shops; carries far less weight than OSCP/PNPT in technical interviews.

Intermediate

CEH

Still passes HR filters in compliance-driven hiring; practitioners typically pair it with hands-on work (HTB / labs / OSCP).

Intermediate

GIAC GPEN

SANS pentest cert. Strong in gov/consulting markets, expensive vs OSCP for similar signal.

Intermediate

GIAC GWAPT

SANS web app pentest cert. Credible in SANS-funded shops; OSWE is the deeper alternative.

Advanced

CPTS

HTB's modern offensive benchmark, respected by practitioners, still building HR recognition.

Specialist

CRTO

Zero-Point Security red-team cert. Modern Cobalt Strike tradecraft, increasingly the de-facto red-team cert.

Specialist

OSEP

OffSec's evasion / advanced AD cert, only meaningful after OSCP and red-team exposure.

Specialist

OSWE

OffSec's web-exploitation cert. The deepest hands-on AppSec credential for source-aware testers.

Specialist

GIAC GXPN

SANS exploit-dev cert. Narrow, expensive, only meaningful in vuln-research-adjacent roles.

Specialist

eJPT

Cheap, hands-on entry to offensive security, great warm-up, not a hiring credential by itself.

Beginner

Data / AI

Data platforms, pipelines and applied AI. Match the credential to the work and platform.

6 certs

Cloud

AWS / Azure / GCP. Strongest senior salary ladder in tech.

19 certs

AWS Solutions Architect. Associate

The most popular AWS certification. Broad coverage of core services, the Well-Architected Framework, and basic design tradeoffs.

Intermediate

AWS Cloud Practitioner

AWS vocabulary primer. Useful for first cloud roles, transparent at any senior level.

Beginner

AWS CloudOps Associate

Useful for AWS operations work when paired with a documented incident, recovery or monitoring example.

Intermediate

Windows Server Admin (AZ-802)

A Windows Server administration route for people who can explain identity, recovery and hybrid operations in practice.

Intermediate

AWS SysOps (superseded)

AWS states the last day to take the SysOps Administrator - Associate exam was 29 September 2025, and that the updated exam is now known as AWS Certified CloudOps Engineer - Associate. Anyone planning this exam should register for CloudOps instead. A SysOps certification already held stays valid for its three year term.

Intermediate

AWS Developer

Developer-flavoured AWS cert. Most useful if you actually ship code on Lambda/DynamoDB/CDK.

Intermediate

Azure Administrator (AZ-104)

Practical Azure administrator cert. The closest equivalent to AWS SysOps in the Microsoft world.

Intermediate

Google Cloud Associate

GCP's associate cert, niche but premium-paid where Google Cloud lands.

Intermediate

CSA CCSK

Vendor-neutral cloud-security primer. Cheap, broad, lighter than CCSP.

Intermediate

Hybrid Server Admin (AZ-800)

Hybrid Windows Server on Azure. The cert ex-sysadmins use to translate into the cloud.

Intermediate

Hybrid Server Services (AZ-801)

AZ-800's senior sibling, hybrid security, monitoring, recovery.

Intermediate

Microsoft MS-102

Microsoft 365 Administrator, tenants, Exchange Online, Entra, Teams, compliance.

Intermediate

AWS Security Specialty

Strong signal for cloud-security-leaning roles. Assumes you already speak AWS fluently.

Advanced

Azure Security Engineer (AZ-500) (retired)

The certification, its exam and its renewal assessment were retired on 31 August 2026. Microsoft's replacement is SC-500, and there is no transition path from a held AZ-500; the new credential has to be earned on its own.

Advanced

AWS SA Pro

Advanced AWS architecture study is most useful after you have real design trade-offs to analyse.

Specialist

Azure Architect Expert

Azure solutions architect. The senior design cert, only credible with production scars.

Specialist

GCP Pro Cloud Security Engineer

GCP's senior cloud-security credential, narrow market, strong signal inside GCP shops.

Specialist

(ISC)² CCSP

(ISC)²'s senior cloud-security cert. CISSP-adjacent, weighted toward architecture and program work.

Leadership

AZ-900

Azure vocabulary primer. The knowledge can support AZ-104 preparation; passing AZ-900 is not a formal prerequisite for AZ-104.

Beginner

Identity Security

IAM, PAM, SSO, Zero Trust. Often entered from AD or cloud.

3 certs

Governance & Risk

Audit, risk and compliance. Senior management lane.

11 certs

ISACA CISA

ISACA's audit cert. The credential of choice for internal/external IT audit and audit-adjacent GRC.

Advanced

CISSP

Certified Information Systems Security Professional. The gold standard for senior security roles, with a heavy governance and architecture focus across 8 broad domains.

Leadership

CISM

ISACA's management-coded cert. The CISSP alternative for governance and program leads.

Leadership

CRISC

ISACA's risk credential. The dedicated counterpart to CISM for risk-coded governance lanes.

Intermediate

(ISC)² CGRC

ISC2 governance / risk / compliance cert (formerly CAP). Narrow but credible in federal / regulated markets.

Intermediate

SecurityX (formerly CASP+)

Hands-on senior security generalist cert, quietly respected, mostly in defence/contractor space.

Advanced

ISO 27001 Lead Implementer

ISO 27001 Lead Implementer. The cert that gets you on certification programs, not running them.

Advanced

ISO 27001 Lead Auditor

ISO 27001 Lead Auditor, for the audit side of the same standard.

Advanced

TOGAF 10

TOGAF is a certification family, not one exam. Consider the specific credential where architecture methods and governance match the work.

Leadership

Microsoft SC-100

Microsoft security architect. The senior design cert for the Microsoft security stack.

Leadership

EC-Council C|CISO

EC-Council's CISO-prep cert. Narrower employer recognition than CISM/CISSP in most markets.

Leadership

Platform / DevSecOps

Kubernetes, IaC, pipelines. Code fluency required.

11 certs

HashiCorp Terraform Associate

Validates working knowledge of Terraform: state, modules, providers, and core workflow. Cheap, practical, and useful across every cloud.

Beginner

Certified Kubernetes Administrator

A fully hands-on, performance-based exam. You're given real clusters and a task list. Speed and command-line fluency matter as much as concepts.

Intermediate

RHCSA

Hands-on Linux signal that infra and platform interviewers actually trust.

Intermediate

LFCS

Distro-neutral counterpart to RHCSA, slightly less prestige, equally hands-on.

Intermediate

AWS DevOps Engineer Professional

Supports experienced AWS delivery and operations work; exam success is not a substitute for a tested deployment and rollback.

Intermediate

CKAD

Developer-side counterpart to CKA. Useful for engineers shipping to k8s, less so for operators.

Intermediate

VCP-VCF Administrator (VMware)

VMware professional cert, narrowing market, still meaningful in regulated enterprise.

Intermediate

CCNA Automation (formerly DevNet Associate)

Cisco's network-automation cert. Useful proof that a network engineer actually codes.

Intermediate

Azure DevOps Engineer (AZ-400)

DevOps engineer on the Microsoft stack. Azure DevOps, GitHub, pipelines, IaC.

Intermediate

RHCE

Practical Ansible automation makes this relevant to Linux operations; confirm the EX294 version and credential requirements before booking.

Advanced

CKS

k8s security depth cert. Only meaningful if you already hold CKA and ship clusters.

Specialist