Certifications
The certification roadmap from beginner to specialist.
Twelve industry credentials — beginner pathway, practitioner, and specialist — each mapped to the platform's framework primers and hands-on labs. Pick a tier, scan the cards, and you will see the primer to read and the lab to run before the exam.
Where should I start?
Pick your background and get one clear first-cert recommendation.
Recommended first cert
No prerequisites, free exam option for qualifying candidates, and the broadest GRC intro available. The fastest path from zero to a recognized credential.
Beginner pathway
3 credentialsEntry-level certs with no prerequisites. Start here whether you are changing careers, a recent grad, or moving from help-desk into security.
The most employer-recognized entry cert. Covers threat analysis, cryptography, and risk — broadly maps to NIST, HIPAA, PCI, and CMMC domains.
Studying this? Start with
NIST CSF 2.0 Quick-Start·Gap Analysis — WovenCart
Certified in Cybersecurity — ISC²'s no-prerequisites entry cert. Broadest GRC intro available; free exam for qualifying candidates.
Studying this? Start with
NIST CSF 2.0 Quick-Start·Gap Analysis — WovenCart
Certified Cloud Security Professional — positioned as the practitioner-track intro to cloud security. Pairs the common body of knowledge with a NIST CSF primer for the broadest on-ramp.
Studying this? Start with
NIST CSF 2.0 Quick-Start·Gap Analysis — WovenCart
Practitioner
6 credentialsMid-career credentials that recognize years of operational GRC work — risk management, auditing, security program operation, and privacy engineering.
Systems Security Certified Practitioner — the step up from CC. One year of experience required; covers access controls, risk, and cryptography aligned to NIST and ISO frameworks.
Studying this? Start with
NIST CSF 2.0 Quick-Start·Gap Analysis — WovenCart
Certified Information Systems Auditor — the standard credential for IT audit and assurance roles. Maps directly to COBIT governance and the SOC 2 / ISO audit lifecycle.
Certified in Risk and Information Systems Control — focuses on IT risk identification, assessment, and response. Aligns to COBIT governance, NIST RMF lifecycle, and ISO 27001 risk treatment.
Studying this? Start with
NIST RMF Quick-Start·Guided Risk Register — WovenCart
Certified Information Security Manager — the management-track credential for security programs. Five years of security management experience required; covers governance, risk management, program development, and incident response aligned to COBIT and NIST RMF.
Studying this? Start with
NIST RMF Quick-Start·Guided Risk Register — WovenCart
Governance, Risk and Compliance Certification — ISC²'s risk-management credential (formerly CAP). Two years of risk / framework experience; aligns RMF Categorize → Authorize with governance and control assessment.
Studying this? Start with
NIST RMF Quick-Start·Guided Risk Register — WovenCart
Certified Data Privacy Solutions Engineer — the privacy-engineering credential. Three years of privacy / data experience required; pairs process-and-technology privacy controls across GDPR and adjacent regimes.
Specialist
3 credentialsPrincipal-architect and governance-lead credentials for the most senior security roles — the umbrella CBK cred and the dedicated IT-governance and ISMS-implementer tracks.
Certified Information Systems Security Professional — the umbrella security credential. Five years across two+ CBK domains required; the principal-architect tier cert for the most senior security roles.
Studying this? Start with
NIST CSF 2.0 Quick-Start·Gap Analysis — WovenCart
Demonstrates ability to establish and manage an ISMS under ISO 27001. Covers implementation, continual improvement, and privacy obligations that overlap GDPR and SOC 2.
Studying this? Start with
ISO 27001 Quick-Start·Draft an Information Security Policy — pick AUP / IR / AC for WovenCart
Certified in the Governance of Enterprise IT — the governance-lead credential. Five years of governance / IT experience required; the principal-architect credential for IT governance committee work aligned to COBIT.