Knowledge base
Cert insights, honestly written.
What works, what doesn't, what counts on the CV. Methodology, fundamentals, deep dives – fact-based and vendor-independent.
Topics
Three thematic threads through our articles – from methodology over fundamentals to deep dives on individual certifications.
Methodology
How CertMap rates certifications, calculates Total-Cost-of-Ownership, and forms clusters. Transparency on our own data basis.
3 postsFundamentals
The difference between a certification and a certificate, what ISO/IEC 17024 guarantees, how accreditation works.
3 postsComparisons
Certifications compared head to head: X or Y, with live figures from the comparison tool, role mapping, and clear decision guidance instead of a winner ranking.
12 postsDeep dive
Individual certifications and providers in detail – strengths, weaknesses, market position, German and international context.
5 posts
Methodology
How CertMap rates certifications, calculates Total-Cost-of-Ownership, and forms clusters. Transparency on our own data basis.
TCO Methodology in Portfolio Mode
How CertMap calculates the Total Cost of Ownership of a cybersecurity certification, and how bundle effects can shift a cert set's 5-year TCO by more than €5,000.
About the CertMap editorial team
CertMap is an independent platform for comparing cybersecurity certifications, built on data-journalism standards that combine editorial curation with mechanical aggregation.
How Does CertMap Rate Cybersecurity Certificates?
Scoring methodology across two axes (market strength × substance), 4 sub-criteria of 0–3 points each. Explains how the quadrant emerges.
Fundamentals
The difference between a certification and a certificate, what ISO/IEC 17024 guarantees, how accreditation works.
What is the NICE Framework? How CertMap maps certifications to roles
The NICE Framework breaks cybersecurity work into named roles. CertMap maps every certification against it, so you can see which role it actually covers, instead of just comparing names.
Certification vs. Certificate: What's the Difference?
Personnel certification per ISO/IEC 17024 versus a training certificate. Why the distinction matters.
What is Personnel Certification under ISO/IEC 17024?
Accreditation standard for personnel certification, what it guarantees and which vendors comply.
Comparisons
Certifications compared head to head: X or Y, with live figures from the comparison tool, role mapping, and clear decision guidance instead of a winner ranking.
CISSP or CISM? Two Careers, One Decision
Both require five years of experience, both cost roughly the same at first glance. Yet CISSP and CISM lead to different professions. The comparison with the numbers that course providers don't show.
CISM or CISA? Two ISACA paths, one directional decision
Both come from ISACA, both require five years of experience, and both cost almost the same. The difference is not the price but the role: managing or auditing. The comparison with the numbers and the role mapping.
CC or Security+? The Free Entry Point and the Job-Market Classic
Both are entry-level certifications with no admission barrier, both cover the fundamentals of cybersecurity, and yet they stand for different strategies: one as a low-threshold, temporarily free start, the other as an established credential with weight in the job market. The comparison with the numbers and the opposing cost logic.
CCSP or CCSK? Two Rungs of the Same Ladder
The two best-known vendor-neutral cloud security credentials compete less than their names suggest: on one side a knowledge certificate with no entry requirement and no expiry date, on the other the comprehensive personnel certification with an experience requirement and a maintenance regime. The comparison, with the numbers and the ladder logic behind it.
CISM or ISO 27001 Lead Implementer? Owning the programme or building the ISMS
Both often appear in the same sentence in German job postings, yet they fill different roles: the CISM attests to steering information security from the leadership perspective, the PECB ISO/IEC 27001 Lead Implementer to building and running an ISMS along the standard. The comparison with the numbers, the entry requirements, and the role question behind it.
CISM or GSLC? Two Origins, One Leadership Role
Both target the security leadership role, but they come from different worlds: the CISM is the governance standard with an experience requirement and worldwide visibility, the GSLC the technically grounded leadership credential from the SANS/GIAC system without an entry barrier. The comparison with the numbers, the entry requirements and the role mapping.
CISSP or TISP? One Builds, the Other Governs
Both are considered heavyweights for experienced security professionals, yet they target different kinds of work: the CISSP centres on designing and building secure systems, the T.I.S.P. on oversight, assessment, and governance within the German regulatory framework.
AAIR or PECB LAIRM? AI risk as an add-on tier or as a standalone credential
AI risk management is the youngest discipline in the certification market, and ISACA and PECB occupy it with fundamentally different models: on one side an add-on tier for holders of an ISACA certification that is still in its beta phase, on the other a standalone, accredited lead certification built around the EU AI Act and the NIST AI RMF. The comparison, with the numbers and the access model.
AAISM or PECB 42001 Lead Implementer? Running the programme or building the management system
Both cover the management of AI security, but from different directions: the AAISM extends a CISM or CISSP profile with the governance of AI risks, the PECB 42001 Lead Implementer certifies building an AI management system per ISO/IEC 42001. The comparison with numbers, entry requirements, and exam format.
CEH or OSCP? Knowledge Exam or 24-Hour Practical Test
Few comparisons come up as often in the security scene: on one side the accredited knowledge exam with decades of presence in tender requirements, on the other the fully hands-on exam format with a strong reputation among pentesters. The comparison with the numbers, the format contrast, and the different renewal models.
CySA+ or GCIH? Detect or Respond in the SOC
Both are among the best-known blue-team credentials, both are accredited, both target security operations, and yet almost everything practical separates them: the path to the certificate, the price behind it, the exam language, and the role each one attests. The comparison with the numbers and the role mapping.
OSCP or GPEN? Marathon versus Method
Two technical pentest credentials with a hands-on component, tied in our rating, and yet fundamentally different: on one side the continuous 24-hour practical exam with cult status in the scene, on the other the methodical GIAC exam with CyberLive tasks, accreditation and a maintenance regime. The comparison with the numbers and the surprising cost logic.
Deep dive
Individual certifications and providers in detail – strengths, weaknesses, market position, German and international context.
NIS 2 Training Obligation for Management: What § 38 BSIG Actually Requires
The training obligation for management bodies is the most heavily advertised part of NIS 2 and at the same time the easiest to fulfil. What the law literally requires, what it deliberately leaves open, and why the real liability question sits one line above the training obligation.
NIS2 Training Records for the Workforce: From Obligation to Audit-Ready Documentation
Training the executive management is an appointment. Training the workforce is a permanent state: § 30 BSIG makes it a mandatory measure, § 38 requires the management to monitor its implementation. What has to be documented for that, where spreadsheets hit their limits, and when personnel certifications are the stronger form of evidence.
Nobody is an AI security expert yet.
Which path fits your background, and the certifications that actually count. Three ways into a field where nobody has a ten-year head start.
BSI IT-Grundschutz: Practitioners, Advisors, and the Accreditation Question
What distinguishes Practitioner from Advisor, and where does accreditation sit in the BSI path?
T.I.S.P.: Germany's Answer to the CISSP. A Missed Opportunity
How the German T.I.S.P. compares to CISSP, and why it didn't gain traction.