Knowledge base
Cert insights, honestly written.
What works, what doesn't, what counts on the CV. Methodology, fundamentals, deep dives – fact-based and vendor-independent.
Topics
Three thematic threads through our articles – from methodology over fundamentals to deep dives on individual certifications.
Methodology
How CertMap rates certifications, calculates Total-Cost-of-Ownership, and forms clusters. Transparency on our own data basis.
3 postsFundamentals
The difference between a certification and a certificate, what ISO/IEC 17024 guarantees, how accreditation works.
3 postsDeep dive
Individual certifications and providers in detail – strengths, weaknesses, market position, German and international context.
8 posts
Methodology
How CertMap rates certifications, calculates Total-Cost-of-Ownership, and forms clusters. Transparency on our own data basis.
TCO Methodology in Portfolio Mode
How CertMap calculates the Total Cost of Ownership of a cybersecurity certification, and how bundle effects can shift a cert set's 5-year TCO by more than €5,000.
About the CertMap editorial team
CertMap is an independent platform for comparing cybersecurity certifications, built on data-journalism standards that combine editorial curation with mechanical aggregation.
How Does CertMap Rate Cybersecurity Certificates?
Scoring methodology across two axes (market strength × substance), 4 sub-criteria of 0–3 points each. Explains how the quadrant emerges.
Fundamentals
The difference between a certification and a certificate, what ISO/IEC 17024 guarantees, how accreditation works.
Was ist das NICE Framework? Wie CertMap Zertifizierungen auf Rollen abbildet
Das NICE Framework zerlegt Cybersecurity-Arbeit in benannte Rollen. CertMap mappt jede Zertifizierung dagegen, damit du siehst, welche Rolle sie wirklich trifft, statt nur einen Namen zu vergleichen.
Certification vs. Certificate: What's the Difference?
Personnel certification per ISO/IEC 17024 versus a training certificate. Why the distinction matters.
What is Personnel Certification under ISO/IEC 17024?
Accreditation standard for personnel certification, what it guarantees and which vendors comply.
Deep dive
Individual certifications and providers in detail – strengths, weaknesses, market position, German and international context.
CISSP oder TISP? Der eine baut, der andere steuert
Beide gelten als Schwergewichte für erfahrene Security-Profis, doch sie zielen auf verschiedene Tätigkeiten: Der CISSP liegt schwerpunktmäßig beim Entwurf und Bau sicherer Systeme, der T.I.S.P. bei Steuerung, Bewertung und Governance im deutschen Normenrahmen.
AAIR oder PECB LAIRM? KI-Risiko als Aufbaustufe oder als eigener Nachweis
KI-Risikomanagement ist die jüngste Disziplin im Zertifizierungsmarkt, und ISACA und PECB besetzen sie mit grundverschiedenen Modellen: hier eine Aufbaustufe für Inhaber eines ISACA-Zertifikats, die noch in der Beta-Phase läuft, dort eine eigenständige, akkreditierte Lead-Zertifizierung entlang von EU AI Act und NIST AI RMF. Der Vergleich mit den Zahlen und dem Zugangsmodell.
AAISM oder PECB 42001 Lead Implementer? Programm steuern oder Managementsystem aufbauen
Beide besetzen das Management von KI-Sicherheit, aber aus verschiedenen Richtungen: Der AAISM erweitert ein CISM- oder CISSP-Profil um die Steuerung von KI-Risiken, der PECB 42001 Lead Implementer belegt den Aufbau eines KI-Managementsystems nach ISO/IEC 42001. Der Vergleich mit Zahlen, Zugang und Prüfungsformat.
CISSP oder CISM? Zwei Karrieren, eine Entscheidung
Beide verlangen fünf Jahre Erfahrung, beide kosten auf den ersten Blick ähnlich viel. Trotzdem führen CISSP und CISM in verschiedene Berufe. Der Vergleich mit den Zahlen, die Kursanbieter nicht zeigen.
CISM oder CISA? Zwei ISACA-Wege, eine Richtungsentscheidung
Beide kommen von der ISACA, verlangen fünf Jahre Erfahrung und kosten fast dasselbe. Der Unterschied liegt nicht im Preis, sondern in der Rolle: steuern oder prüfen. Der Vergleich mit den Zahlen und der Rollen-Abbildung.
Nobody is an AI security expert yet.
Which path fits your background, and the certifications that actually count. Three ways into a field where nobody has a ten-year head start.
BSI IT-Grundschutz: Practitioners, Advisors, and the Accreditation Question
What distinguishes Practitioner from Advisor, and where does accreditation sit in the BSI path?
T.I.S.P.: Germany's Answer to the CISSP. A Missed Opportunity
How the German T.I.S.P. compares to CISSP, and why it didn't gain traction.