What a cybersecurity certification should prove

Learning and certification architecture

A badge may be small. The decision behind it should be precise.

A certification can appear as one line on a résumé, a digital badge, or a PDF. Yet employers, clients, and workforce leaders may use it to make important decisions.

They may assume that the holder can perform a role, complete certain tasks, or make sound decisions in a professional setting.

That places a clear responsibility on the organization issuing the credential. It must be able to explain what the person demonstrated, how that performance was assessed, and where the recognition ends.

This becomes more difficult when the work itself is changing.

Cybersecurity work is changing

Artificial intelligence is reshaping the way many cybersecurity tasks are performed.

A junior professional may once have reviewed alerts manually. Today, an automated system may complete the first analysis. The person must then verify the output, investigate exceptions, identify errors, and decide when the system’s conclusion cannot be trusted.

The task may carry the same name, but the reasoning behind it has changed.

The required knowledge also expands. Understanding attack patterns is no longer enough. A professional may also need to understand how an automated tool reaches a conclusion, which data shaped that result, and where the system may fail.

The skill changes with it. Reading a log can now involve comparing technical evidence with a machine-generated assessment and recognizing when the two do not agree.

The 2026 Cybersecurity Workforce Research Report from SANS and GIAC reflects this shift. Among 947 respondents, 60 percent described the skills gap as a greater challenge than the shortage of people. Only 19 percent reported having no skills gap.

The same study found that certifications were the most frequently used method for validating cybersecurity skills, selected by 64 percent of respondents. Fifty-eight percent considered them very or extremely important when evaluating personnel.

These numbers do not prove that every certification is reliable. They show that organizations place considerable weight on them.

That makes the design question unavoidable:

What does the credential actually tell us about the person who holds it?

Completion and certification are different

A completion certificate records participation in a learning experience.

A professional certification makes a different statement. It indicates that a person met defined requirements within a stated area of practice.

Someone can complete a course on incident response and still need support when investigating a real alert.

A person can remember the stages of a recovery process and still struggle to choose the right action when time, risk, and business priorities compete.

Learning helps people build capability. Completion confirms that they finished an activity. Certification requires a judgment about what they demonstrated.

ISO/IEC 17024 provides an international reference for organizations that certify people. It addresses how competence is defined, how candidates are assessed, and how the certification scheme is maintained.

Many technology credentials operate outside formal accreditation under this standard. Its central principle is still useful: the requirements must be clear, and the decision must follow a controlled process.

Start with the work

A certification should not begin with a list of course modules. It should begin with the professional and the work the organization expects that person to perform.

Consider someone responsible for responding to security incidents. The person may be accountable for helping the organization understand what happened, limit the impact, and begin the appropriate response.

That responsibility includes specific tasks: examining alerts, analyzing logs, establishing priority, documenting findings, and recommending action.

Those tasks require knowledge. The person may need to understand attack patterns, system behavior, escalation procedures, and evidence-handling requirements.

They also require skills. The person must be able to interpret information, identify suspicious activity, use relevant tools, and communicate findings clearly.

These elements have different functions.

Task

Work that needs to be completed.

Knowledge

What the person must understand or recall.

Skill

An observable action the person can perform.

Competence

What appears when the person combines knowledge and skills to perform relevant tasks under real conditions.

This distinction matters because a list of subjects only describes what was taught. A professional credential should describe what the person can do with that learning.

A common language helps

The NICE Framework, published by the National Institute of Standards and Technology, gives organizations a shared language for describing cybersecurity work.

It connects tasks with the knowledge and skills needed to perform them. These elements can then be grouped into competency areas and work roles.

A simple example might look like this:

Work role

Incident response.

Task

Investigate a suspicious alert.

Knowledge

Attack indicators and incident-response procedures.

Skill

Analyze logs and identify abnormal activity.

Competence

Interpret the incident and recommend an appropriate response.

NICE does not create the entire certification. It gives the design team a structured description of the work. The team must still decide which responsibilities belong inside the credential, what level of performance is expected, and what a candidate must demonstrate.

Europe uses a related approach through the European Cybersecurity Skills Framework from ENISA. It describes cybersecurity profiles through missions, tasks, knowledge, skills, and competences.

The two frameworks are not identical, but they serve a similar purpose: helping organizations connect workforce needs with professional development.

This common language becomes especially valuable when roles evolve. A structured model can be updated one task or skill at a time. A broad job description written in free text often requires much more interpretation.

Define the scope

No credential can represent everything a professional knows or can do. A reliable certification identifies the area it covers.

It should clarify the type of professional it addresses, the responsibilities included, the expected conditions of performance, and the complexity of the work.

An entry-level credential may show that a person understands key concepts, follows established procedures, and completes guided tasks.

A more advanced credential may require independent analysis, prioritization, adaptation, and professional judgment.

The difference is not simply a harder exam. The expected performance must change.

Clear scope protects everyone involved. Candidates understand what they are preparing for. Employers know what they can reasonably infer. The provider avoids suggesting that one assessment proves an entire professional identity.

A credential becomes more trustworthy when it says precisely what it covers and avoids promising more than it can support.

Match the proof to the performance

Once the expected competence is clear, the design team must decide what proof would demonstrate it. The answer depends on the type of performance.

An examination can assess knowledge, interpretation, and judgment across many situations. A laboratory can assess technical execution. A simulation can observe decisions under realistic constraints. A work product can show whether the candidate can organize findings, document a process, or communicate a recommendation.

No method is automatically better than the others. The method must fit the performance being recognized.

A multiple-choice assessment may work well when the goal is to examine reasoning across a broad range of scenarios. It becomes less convincing when the badge states that the holder can configure a system, investigate an incident, or recover an environment. Those statements require proof of observable action.

The design sequence should therefore remain simple:

Describe the work. Define the expected competence. Select the proof. Build the assessment. Then organize the learning.

This order prevents the exam from becoming a final quiz attached to content that was never designed around the intended professional outcome.

A passing score must mean something

After selecting the assessment method, the team must determine how much performance is sufficient.

A passing score should not exist simply because 70 percent feels familiar. It should come from a documented process.

Experienced practitioners may review the assessment and judge what a minimally qualified candidate should be able to answer or perform. Other approaches may combine expert judgment with candidate-performance data.

The method can vary. The need to justify the decision remains constant.

The team should also review whether the assessment covers the intended competence, produces sufficiently consistent decisions, treats candidates fairly, and protects the integrity of the examination.

The score is only one part of the process. The real decision is whether the collected proof supports the professional recognition being awarded.

Keep the credential current

A certification can be well designed at launch and gradually lose relevance.

Tools change. Threats evolve. Products are updated. Regulations create new responsibilities. Artificial intelligence continues to redistribute work between people and systems.

A maintained credential needs a defined owner, regular review, controlled versions, documented changes, and clear triggers for revision.

NIST SP 800-50 Revision 1 treats cybersecurity and privacy learning as a managed lifecycle. It includes planning, development, delivery, evaluation, and continuous improvement.

Learning and certification do not follow exactly the same lifecycle, but they must remain connected.

When a task changes, the required knowledge and skills may need revision. When those requirements change, the competence being assessed may also change. That can affect the assessment, the passing standard, the preparation materials, and the meaning of existing credentials.

Keeping the recognition current is part of maintaining trust.

Who makes the decision?

No single framework decides what a certification proves.

Organizations and industry leaders identify the work that matters. Workforce frameworks help describe that work. Practitioners confirm that the description reflects reality. Learning architects organize the progression toward capable performance. Assessment specialists determine how performance will be observed and interpreted. The certification owner approves the scope, requirements, standard, and maintenance process.

Together, these decisions form the structure behind the badge.

The credential states that a person met a defined standard because the work was analyzed, the expected competence was described, suitable proof was collected, and a controlled decision was made.

Four questions worth asking

An employer, learner, or partner does not need access to protected exam material to understand whether a certification has been designed responsibly. Four questions reveal most of what matters.

What work does it represent?

The answer should identify the role, responsibilities, tasks, level, and scope.

What must the candidate demonstrate?

The answer should describe performance or proof, not only completed modules.

How is the decision made?

The provider should explain the assessment structure and the process used to establish the passing standard.

How is it kept current?

The answer should identify ownership, review cycles, version control, and the conditions that trigger revision.

A mature certification system should be able to answer these questions clearly.

Behind the badge

The visible credential may be small. Its value comes from the structure behind it.

A strong certification connects current professional work with a defined level of performance. It collects suitable proof, applies a defensible standard, and remains aligned as the field changes.

Its purpose is not to confirm that someone encountered information. Its purpose is to recognize that the person demonstrated something specific, useful, and professionally relevant.

Source footprint

SANS and GIAC, 2026 Cybersecurity Workforce Research Report. Current market context on artificial intelligence, workforce frameworks, skills gaps, and the use of certifications.
sans.org · giac.org/reports

ISO/IEC 17024. International reference for bodies operating certification schemes for persons.
iso.org/standard/17024

NIST SP 800-181 Revision 1, NICE Framework. Common language for cybersecurity tasks, knowledge, skills, competency areas, and work roles.
csrc.nist.gov · NICE Framework Resource Center

NIST SP 800-50 Revision 1. Lifecycle guidance for cybersecurity and privacy learning programs.
csrc.nist.gov

NIST Cybersecurity Framework 2.0. Cybersecurity risk-management outcomes, including workforce awareness, training, responsibilities, and governance.
nist.gov/cyberframework

European Cybersecurity Skills Framework, ENISA. European reference for cybersecurity role profiles, tasks, skills, knowledge, and competences.
enisa.europa.eu

Alejandra. Learning Architect. Open to the world. LinkedInGitHubYouTube