Сертификации по киберсигурност
Пълен каталог на водещите сертификации в индустрията — от начални до напреднали. Използвайте филтрите, за да намерите правилния следващ сертификат за вашата кариера. Базиран на Paul Jerimy Security Certification Roadmap.
Броят обяви до всеки сертификат идва от актуалните обяви в каталога с обяви — само отворените, изисквани или посочени като предимство.
Validates advanced security knowledge specific to the AWS platform, including data protection, infrastructure security, identity management, and logging. Requires at least two years of…
An advanced CREST certification demonstrating expert-level infrastructure penetration testing skills. Widely considered one of the most difficult penetration testing certifications…
An advanced CREST certification demonstrating expert-level web application penetration testing skills. Required by many UK financial sector organizations and government bodies for…
An entry-level CREST qualification testing foundational knowledge in vulnerability assessment and penetration testing theory. Often used as a prerequisite for more advanced CREST…
A rigorous practical and theoretical penetration testing certification highly respected in the UK and internationally. Often a baseline requirement for penetration testers at UK government…
A performance-based certification where candidates must demonstrate cybersecurity skills in a live, proctored virtual environment. Tests the ability to identify, protect, detect, respond…
A vendor-neutral cloud security certification covering the CSA Guidance and the ENISA cloud computing risk assessment. Covers cloud architecture, data security, infrastructure security, and…
Validates advanced technical skills in cloud security design, implementation, architecture, operations, controls, and compliance. Jointly developed by (ISC)² and Cloud Security Alliance…
Validates technical privacy skills focused on implementing privacy by design in systems, applications, and infrastructure. Bridges the gap between privacy law and technical implementation.
One of the most recognized ethical hacking certifications, covering hacking tools, techniques, and methodologies used by malicious hackers. The exam covers footprinting, scanning…
An advanced credential earned by passing both the CEH theoretical exam and the CEH Practical exam in a live cyberrange environment. Validates the ability to apply ethical hacking skills in…
Validates skills in structuring and managing a data privacy program within an organization. Designed for privacy managers, DPOs, and compliance officers responsible for program…
The leading privacy certification for professionals working with European data protection law, including GDPR. Essential for data protection officers, privacy lawyers, and compliance…
Validates the ability to embed privacy practices into technical design and IT infrastructure. Covers privacy-by-design principles, identity management, encryption, and privacy-enhancing…
Designed for information security managers and aspiring managers, validating expertise in managing, designing, overseeing, and assessing an enterprise's information security program…
The globally recognized standard for IT auditors, assessing skills in auditing, controlling, and assuring information systems. Requires five years of professional experience in information…
The gold standard for senior security practitioners, covering all eight CISSP Common Body of Knowledge (CBK) domains. Requires five years of paid work experience across two or more domains…
Covers a structured methodology for conducting professional penetration tests across networks and systems. Addresses enumeration, exploitation, privilege escalation, and report writing…
A fully practical penetration testing certification conducted in a live cyberrange with multiple targets across enterprise networks, OT/SCADA, IoT, and cloud. Candidates have 24 or 48 hours…
An entry-level ethical hacking certification covering foundational penetration testing concepts, tools, and methodologies. Covers reconnaissance, scanning, exploitation, and reporting.
Validates foundational skills needed to work as a Tier 1 or Tier 2 SOC analyst, covering network security monitoring, log management, and SIEM operation. Designed as an entry point for…
Covers the entire threat intelligence lifecycle from planning and direction to dissemination. Validates skills in collecting, processing, analyzing, and acting on threat intelligence using…
Formerly known as CAP, validates the ability to authorize and maintain information systems within the Risk Management Framework. Covers information security risk management, security…
Validates expertise in identifying and managing IT and business risks through the development and maintenance of information systems controls. Requires three years of cumulative work…
Recognizes professionals who bring IT governance knowledge and application to their enterprise. Covers governance frameworks, strategic management, benefits realization, risk optimization…
Validates foundational skills needed to work in a Security Operations Center (SOC), covering security monitoring, host-based analysis, and network intrusion analysis. An entry point for…
An advanced-level certification validating the ability to design and implement threat detection, incident response, and forensics processes within a SOC. Covers advanced security…
Validates skills in securing Cisco networks, including firewall configuration, VPNs, IPS/IDS, and identity management for Cisco devices. Particularly valuable for network engineers managing…
An advanced-level certification for security architects and senior engineers who design and implement enterprise security solutions. Covers enterprise security, risk management…
Validates skills needed to deploy and automate secure cloud environments, covering multiple vendor platforms. Covers cloud architecture, security, deployment, and operations.
Focuses on behavioral analytics applied to networks and devices to prevent, detect, and combat cybersecurity threats. Covers threat and vulnerability management, security operations…
Validates foundational networking skills including infrastructure, operations, security, and troubleshooting. Covers TCP/IP, network protocols, and basic network security concepts. A widely…
Validates skills for planning, scoping, and performing penetration testing and vulnerability management across various environments. Includes performance-based questions alongside multiple…
The industry-standard baseline certification for cybersecurity roles, covering threats, vulnerabilities, architecture, implementation, and governance. Widely required by US federal…
Validates skills in detecting hacking attacks and properly extracting evidence for legal proceedings. Covers digital forensics investigation processes, forensic tools, dark web forensics…
Validates skills in handling and responding to various types of cybersecurity incidents using a structured methodology. Covers post-incident activities, forensics basics, and how to…
Validates proficiency in the FAIR (Factor Analysis of Information Risk) quantitative risk analysis model. Covers risk scoping, Monte Carlo simulation, and communicating cyber risk in…
Validates advanced skills in designing, implementing, and troubleshooting complex Fortinet enterprise security solutions. Available in multiple specializations including SD-WAN, OT…
The highest level Fortinet certification, combining a multiple-choice written exam with a complex eight-hour practical lab exam. One of the most challenging vendor certifications in the…
Validates the ability to install and configure FortiGate firewalls to protect networks at the enterprise level. One of the most popular vendor-specific network security certifications…
Validates advanced skills in forensic analysis of compromised systems, covering memory forensics, timeline analysis, and anti-forensics detection. Highly regarded for DFIR (Digital…
Validates skills in conducting formal incident investigations and using forensic techniques to analyze Windows systems. Covers browser forensics, file system analysis, registry analysis…
Validates skills in detecting, responding to, and resolving computer security incidents. Covers attack techniques, incident handling steps, and the tools used by both attackers and…
Validates skills in configuring and monitoring intrusion detection systems (IDS), analyzing network traffic, and identifying malicious activity. Highly valued for SOC network analyst roles.
Validates skills in implementing and running a continuous security monitoring program aligned with the CIS Critical Security Controls. Suited for network security monitoring roles.
Validates the ability to apply structured threat intelligence methods to support an organization's defense posture. Covers intelligence frameworks (ATT&CK, STIX/TAXII), threat modeling, and…
Validates skills in advanced exploitation techniques including network-based exploitation, shellcode development, and advanced fuzzing. One of the most technically challenging GIAC…
Validates skills in conducting penetration tests using best-practice techniques and methodologies. Covers password attacks, exploitation, reconnaissance, and scanning.
Validates skills in reverse-engineering malicious code including Windows malware, malicious web scripts, and obfuscated code. One of the most respected certifications for malware analysts…
Validates a broad understanding of information security fundamentals beyond simple terminology and concepts. Covers active defense, network security, cryptography, incident handling, and…
Validates technical and managerial knowledge required for IT security leadership roles. Designed for security managers who need to bridge technical and business domains.
Validates skills in assessing and exploiting web application vulnerabilities using both manual and tool-assisted techniques. Covers SQL injection, cross-site scripting, authentication…
Validates the ability to design and implement a secure infrastructure on Google Cloud, covering IAM, data protection, network security, and logging. The most respected cloud security…
Advanced hands-on certification for identifying and exploiting Active Directory vulnerabilities. Covers complex attack paths, Kerberos and NTLM abuse, ADCS/WSUS/Exchange misconfigurations…
Hands-on certification assessing security analysis, SOC operations, and incident handling skills. Validates the ability to spot incidents, correlate data, determine impact, and create…
Hands-on certification assessing foundational competency across offensive and defensive cybersecurity. Covers identifying common vulnerabilities, basic exploitation, SIEM-assisted…
Hands-on certification co-developed with Google assessing skills in identifying and exploiting AI/ML vulnerabilities. Covers adversarial ML, LLM prompt injection, jailbreaking, AI…
Hands-on certification validating penetration testing skills at an intermediate level. Covers ethical hacking, infrastructure risk assessment, and the ability to compose commercial-grade…
Advanced hands-on certification for identifying hard-to-find web vulnerabilities using black box and white box techniques. Covers application debugging, source code review, custom exploit…
Hands-on certification assessing web application pentesting and bug bounty hunting skills. Validates the ability to assess risk in web applications, services, and APIs, and compose…
Advanced hands-on certification for real-world Wi-Fi exploitation across all major protocols including WPA3 and WPA-Enterprise. Covers rogue APs, credential harvesting, captive portal…
Validates the ability to plan and conduct audits of Information Security Management Systems (ISMS) based on the ISO/IEC 27001 standard. Widely required for third-party auditors and internal…
Validates the ability to implement an Information Security Management System (ISMS) based on ISO/IEC 27001. Designed for security managers and consultants implementing organizational…
A CISSP concentration for security architects, validating expertise in designing and implementing security architectures aligned with business requirements. Requires an active CISSP and two…
A CISSP concentration focusing on integrating security into all facets of business operations, projects, and systems. Developed in partnership with the US NSA. Requires active CISSP plus…
A CISSP concentration for security managers and CISOs, covering leadership and business management skills alongside security program management. Requires active CISSP plus two years of…
Validates expertise in designing and evolving cybersecurity strategy for all aspects of an enterprise architecture using Microsoft technologies. Covers Zero Trust, governance, risk…
Validates skills in designing, implementing, and operating identity and access management solutions using Microsoft Entra ID (formerly Azure AD). Covers authentication, authorization…
Validates skills in using Microsoft Sentinel, Defender XDR, and Defender for Cloud to investigate and respond to cybersecurity threats. Covers threat hunting, alert management, and…
The most respected hands-on penetration testing certification in the industry, requiring candidates to compromise multiple machines in a 24-hour live exam. Tests enumeration, exploitation…
Focuses on advanced evasion techniques, Active Directory attacks, and bypassing modern endpoint defenses. Requires candidates to compromise an entire Active Directory lab in a 48-hour exam.
Covers Windows exploit development including custom shellcode creation, format string attacks, DEP bypass, and ASLR bypass techniques. The 48-hour exam requires candidates to develop…
Validates foundational to intermediate web application penetration testing skills using a black-box methodology. The 24-hour exam requires compromising multiple web application targets in a…
Focuses on white-box web application penetration testing by reviewing source code to identify and exploit vulnerabilities. The 48-hour exam requires writing custom exploit code to attack…
Covers macOS-specific offensive security techniques including Objective-C and Swift exploitation, macOS memory corruption, and bypassing macOS security mitigations. Unique in the market for…
Validates expertise in securing cloud environments using the Prisma Cloud platform across AWS, Azure, and GCP. Covers cloud security posture management (CSPM), workload protection, and…
Validates deep knowledge of designing, deploying, configuring, maintaining, and troubleshooting Palo Alto Networks Next-Generation Firewalls. The premier certification for Palo Alto…
A fully practical, five-day penetration testing exam with an additional two days to write a professional report. Covers external and internal network penetration testing, Active Directory…
Validates mastery of the SABSA enterprise security architecture framework used by large organizations worldwide. Covers the full SABSA lifecycle from business requirements through…
An intermediate practitioner-level credential validating technical skills in implementing, monitoring, and administering IT infrastructure using security best practices. Requires one year…
A professional-level practical certification covering network penetration testing, web application testing, and basic exploit development. Candidates must complete a full penetration test…
An entry-level practical penetration testing certification requiring candidates to attack a real network in a browser-based lab environment. An affordable and accessible starting point for…
A practical web application penetration testing certification where candidates must test a real multi-tier web application and write a penetration test report. Covers OWASP Top 10…