GCFAGIAC Certified Forensic Analyst
Created per CertMap methodology · Updated 12 May 2026 · About the editorial team →

▾ Jump to …4 sections
Overview
What is GCFA?
The GIAC Certified Forensic Analyst (GCFA) is a highly respected certification in digital forensics and incident response, based on the SANS course FOR508. It validates competency in Windows system analysis, memory forensics, timeline analysis, and investigation of Advanced Persistent Threats (APTs). The open-book, proctored exam with practical CyberLive exercises ensures that not only theoretical knowledge but also practical skills are tested. GCFA is highly valued by incident response teams and forensic units; in German-speaking regions it is well known but, due to high SANS course costs, primarily prevalent in larger enterprises and government agencies.
Suitable for
Quick facts
Key details
Cost, prerequisites, exam & renewal
Cost over 5 years
Prerequisites
No formal prerequisites. Associated SANS course strongly recommended.
Exam format
82 questions + CyberLive, 3 hours, open-book, proctored via Pearson VUE. Passing score: 72%.
Renewal & maintenance
Valid for 4 years. Renewal via 36 CPE credits or renewal exam (479 USD). Each GIAC cert separate.
Classification
CertMap score and matching roles
Rating
Matching NICE roles
More certifications
More certifications
From GIAC
GAIPSGIAC AI Platform SecurityGASAEGIAC AI Security Automation EngineerGCIHGIAC Certified Incident HandlerGICSPGIAC Global Industrial Security ProfessionalGOAAGIAC Offensive AI AnalystGPENGIAC Certified Penetration TesterGSEGIAC Security ExpertGSECGIAC Security Essentials CertificationGSLCGIAC Security Leadership CertificationThis page follows CertMap methodology: editorial content is curated by hand. Score, costs and NICE mapping are aggregated from official provider documents. Score methodology → · TCO methodology →
Transparency: CertMap is operated by Daniel Thomas Heessel, who is also managing director of Threat‑Informed, a company specialising in Threat‑Informed Defense. CertMap currently receives no commissions from certification providers, no affiliate links, no sponsored placements. Podcast and interview guests are not paid for appearances and receive no affiliate commissions.
From the knowledge base
View all articles →CISSP oder CISM? Zwei Karrieren, eine Entscheidung
Beide verlangen fünf Jahre Erfahrung, beide kosten auf den ersten Blick ähnlich viel. Trotzdem führen CISSP und CISM in verschiedene Berufe. Der Vergleich mit den Zahlen, die Kursanbieter nicht zeigen.
CISM oder CISA? Zwei ISACA-Wege, eine Richtungsentscheidung
Beide kommen von der ISACA, verlangen fünf Jahre Erfahrung und kosten fast dasselbe. Der Unterschied liegt nicht im Preis, sondern in der Rolle: steuern oder prüfen. Der Vergleich mit den Zahlen und der Rollen-Abbildung.
CC oder Security+? Der Gratis-Einstieg und der Arbeitsmarkt-Klassiker
Beide sind Einsteiger-Zertifikate ohne Zulassungshürde, beide decken die Grundlagen der Cybersicherheit ab, und trotzdem stehen sie für verschiedene Strategien: das eine als niedrigschwelliger, zeitweise kostenloser Start, das andere als etablierter Nachweis mit Gewicht im Arbeitsmarkt. Der Vergleich mit den Zahlen und der gegenläufigen Kostenlogik.

1:1 with the CISO
Need the full picture for your case?
Personal strategy instead of weeks of self-research. Vendor-independent, with auditable recommendations and transparent sources.