Certifications

The certification roadmap from beginner to specialist.

Twelve industry credentials — beginner pathway, practitioner, and specialist — each mapped to the platform's framework primers and hands-on labs. Pick a tier, scan the cards, and you will see the primer to read and the lab to run before the exam.

Where should I start?

Pick your background and get one clear first-cert recommendation.

Recommended first cert

ISC² CC

No prerequisites, free exam option for qualifying candidates, and the broadest GRC intro available. The fastest path from zero to a recognized credential.

Beginner pathway

3 credentials

Entry-level certs with no prerequisites. Start here whether you are changing careers, a recent grad, or moving from help-desk into security.

CompTIA
Beginner pathway
Entry
CompTIA Security+

The most employer-recognized entry cert. Covers threat analysis, cryptography, and risk — broadly maps to NIST, HIPAA, PCI, and CMMC domains.

Studying this? Start with

NIST CSF 2.0 Quick-Start·Gap Analysis — WovenCart

ISC²
Beginner pathway
Entry
ISC² CC

Certified in Cybersecurity — ISC²'s no-prerequisites entry cert. Broadest GRC intro available; free exam for qualifying candidates.

Studying this? Start with

NIST CSF 2.0 Quick-Start·Gap Analysis — WovenCart

ISC²
Beginner pathway
Entry
ISC² CCSP

Certified Cloud Security Professional — positioned as the practitioner-track intro to cloud security. Pairs the common body of knowledge with a NIST CSF primer for the broadest on-ramp.

Studying this? Start with

NIST CSF 2.0 Quick-Start·Gap Analysis — WovenCart

Practitioner

6 credentials

Mid-career credentials that recognize years of operational GRC work — risk management, auditing, security program operation, and privacy engineering.

ISC²
Practitioner pathway
Entry–Mid
ISC² SSCP

Systems Security Certified Practitioner — the step up from CC. One year of experience required; covers access controls, risk, and cryptography aligned to NIST and ISO frameworks.

Studying this? Start with

NIST CSF 2.0 Quick-Start·Gap Analysis — WovenCart

ISACA
Practitioner pathway
Entry–Mid
ISACA CISA

Certified Information Systems Auditor — the standard credential for IT audit and assurance roles. Maps directly to COBIT governance and the SOC 2 / ISO audit lifecycle.

Studying this? Start with

SOC 2 Quick-Start·Review a Vendor SOC 2 Report

ISACA
Practitioner pathway
Entry–Mid
ISACA CRISC

Certified in Risk and Information Systems Control — focuses on IT risk identification, assessment, and response. Aligns to COBIT governance, NIST RMF lifecycle, and ISO 27001 risk treatment.

Studying this? Start with

NIST RMF Quick-Start·Guided Risk Register — WovenCart

ISACA
Practitioner pathway
Mid
ISACA CISM

Certified Information Security Manager — the management-track credential for security programs. Five years of security management experience required; covers governance, risk management, program development, and incident response aligned to COBIT and NIST RMF.

Studying this? Start with

NIST RMF Quick-Start·Guided Risk Register — WovenCart

ISC²
Practitioner pathway
Mid
ISC² CGRC

Governance, Risk and Compliance Certification — ISC²'s risk-management credential (formerly CAP). Two years of risk / framework experience; aligns RMF Categorize → Authorize with governance and control assessment.

Studying this? Start with

NIST RMF Quick-Start·Guided Risk Register — WovenCart

ISACA
Practitioner pathway
Entry–Mid
ISACA CDPSE

Certified Data Privacy Solutions Engineer — the privacy-engineering credential. Three years of privacy / data experience required; pairs process-and-technology privacy controls across GDPR and adjacent regimes.

Studying this? Start with

GDPR Quick-Start·GDPR DPIA Outline

Specialist

3 credentials

Principal-architect and governance-lead credentials for the most senior security roles — the umbrella CBK cred and the dedicated IT-governance and ISMS-implementer tracks.

ISC²
Specialist pathway
Mid
ISC² CISSP

Certified Information Systems Security Professional — the umbrella security credential. Five years across two+ CBK domains required; the principal-architect tier cert for the most senior security roles.

Studying this? Start with

NIST CSF 2.0 Quick-Start·Gap Analysis — WovenCart

PECB / BSI
Specialist pathway
Mid
ISO 27001 Lead Implementer

Demonstrates ability to establish and manage an ISMS under ISO 27001. Covers implementation, continual improvement, and privacy obligations that overlap GDPR and SOC 2.

Studying this? Start with

ISO 27001 Quick-Start·Draft an Information Security Policy — pick AUP / IR / AC for WovenCart

ISACA
Specialist pathway
Mid
ISACA CGEIT

Certified in the Governance of Enterprise IT — the governance-lead credential. Five years of governance / IT experience required; the principal-architect credential for IT governance committee work aligned to COBIT.

Studying this? Start with

ISO 27001 Quick-Start·ISO 27001 Gap Analysis