Skip to content
CertMapCertMap

METHODIK

About the CertMap editorial team

CertMap is an independent platform for comparing cybersecurity certifications, built on data-journalism standards that combine editorial curation with mechanical aggregation.

Last updated: 2026-05-12

Who is behind CertMap

Daniel Thomas Heessel is the editor of CertMap and author of its scoring methodology. He is responsible for the platform's editorial direction and methodological framework. Heessel has more than a decade of experience in information security and holds recognised certifications including CISSP, CISM, ISO 27001 Lead Auditor and T.I.S.P. In 2026 he received the CISO of the Year (DACH) award from CISO Alliance and secIT.

CertMap is not a personal-brand site; it operates as a data-journalism comparison platform for hundreds of cybersecurity certifications. The editor's credentials can be verified via his LinkedIn profile. The platform provides orientation in a fragmented market by presenting facts side by side and making them comparable. Daniel Thomas Heessel acts as the accountable person for the platform stance and compliance with editorial standards.

Data collection and editorial process

CertMap content is created through a strict separation of editorial work and mechanical data aggregation. This hybrid approach ensures that both qualitative classifications and comparable facts are available.

Manual editorial curation

The editorial team writes texts for the areas summary, audience, insight and provider context. The score narrative, which explains the numerical evaluation, is also written manually. These contents go through a weekly review process. The date of the last editorial review is transparently visible on every certification detail page.

Mechanical data aggregation

Quantitative data points are aggregated directly from official provider documentation, ISO/IEC 17024 accreditation data and the NIST NICE Framework SP 800-181. This includes:

  • Scores: a rating across four sub-axes of 0 to 3 points each. Details in the scoring methodology.
  • Costs (TCO): aggregation of acquisition costs, annual maintenance fees (AMF), continuing professional education effort (CPE) and recertification fees. Calculation follows the TCO methodology.
  • NICE mapping: certifications are mapped to specific NICE Framework roles based on factual curriculum criteria.

CertMap pursues explicit anti-goals to safeguard quality. AI tools are used in the editorial process as writing assistance for first drafts; every published text subsequently goes through human review by the editor. What is avoided: unchecked mass-generation of certification descriptions, marketing speak and automated content inflation. There are no affiliate buttons and no paid "top-10" lists. The platform avoids subjective ratings via thumb icons or classic strengths-weaknesses lists in favour of data-driven presentation.

Transparency and conflict of interest

Editorial independence is the central element of CertMap. Daniel Thomas Heessel operates this platform independently from his role as managing director of Threat‑Informed, a company specialising in Threat‑Informed Defense. He additionally offers consulting services on CertMap. There is a clear separation between content and recommendations across the different activities.

The following transparency rules apply to CertMap operations:

  • The platform receives no commissions from certification providers for listing or curating content.
  • No affiliate links are used. Provider links serve user information only.
  • CertMap does not sell placements. The sorting and display of certifications follows only the selected filter logic or alphabetical order.

Guests in experience reports, podcasts or interviews receive no compensation from CertMap for their appearance. Likewise, no affiliate commissions are paid to these individuals. Should the platform's funding model change in the future, this page and the corresponding disclosure block on every certification page will be updated immediately. CertMap is currently funded entirely self-sustained, without external funders from the certification industry.