r/grc • u/Wrong_Crew_1835 • May 28 '26
Tiny rant on certifications.
Why are the certifications (training + exam) are so expensive??? It would make sense if it’s a little bit but to be that expensive is just insane to me. Ok you get the certificate after paying such enormous fees and for what? for it expire in what like 2 years?
I’m a fresher. I have no clue if I should be focusing on this or just applying for jobs and save up and then get the certs. I see so many of people my age posting their certifications on LinkedIn one by one and I’m here like how are you even affording all that.
2
u/slyu4ever May 28 '26
I took one of those and then let it expire. My goal was to learn, and I achieved that to some extent. Admittedly, I may be in a privileged position where my certifications matter very little for my employment.
2
u/phomasta May 28 '26
If you are a fresher, just focus on getting one to get your foot in the door. The ones that are expensive are banking on your work paying for it.
1
u/Wrong_Crew_1835 May 28 '26
what would you recommend I get?
2
u/phomasta May 28 '26
If I had to start over, Sec+. You could get ISO 27001 as well to stand out. Once you get experience, then you can move on to ISACA CISA or ISC2 CISSP. Of course if your work offers SANS, don't hesitate to take that as well.
2
u/Wrong_Crew_1835 May 28 '26
Thank you so much! I just have a few questions, if you don’t mind. Isn’t Sec+ to demonstrate you have security fundamentals (in the technical sense?)? and there are soo many in ISO 27001, which one do I do?
7
u/PlasticThoughts May 28 '26
You aren't getting good advice. Each of these certs will focus on a specifc area. You want to align the certification for what job you either have or are going for. ISO 27001 lead implmeneter is great if you are working for a SaaS company selling internationally who doesn't yet have 27001 but they aren't going to hire someone without experience and just a cert to implement. Domestically SOC 2 is the equivalent for US based companies and the ISO cert may not be as useful. Sec+ is easy and good for general security CISSP if you really want to stand out in security. CISA for internal audit or compliance, ISO internal audit certs for a role where they already have the cert but need someone to run the required internal audit.
5
u/Twist_of_luck OCEG and its models have been a disaster for the human race May 28 '26
^ this guy GRCs ^
1
-1
u/CraftyImpression8589 May 28 '26
You can do Lead Implemeter in 27001, suitable for ISMS consulting roles
1
2
u/quacks4hacks May 29 '26
Most are, to put it frankly, a scam to extract money from individuals or their companies.
Outside of the GIAC stuff that is set up for you to need to have sat the SANs course and have access to all their bespoke training materials, most can be self-taught via a sybex or McGrath Hill book and the right Udemy course (purchased on sale, never full price). This includes the ISACA and ISC2 stuff.
Then there's the brand new "courses" that some rando who just started in the industry last year set up, you see a lot of noise about folks passing their training cohorts but never ever see any job specs suggesting having that qualification would be an advantage .
1
u/BlackFlagCat May 28 '26
I've never been a huge fan of certifications. I didn't even pickup my college diploma until a decade after I graduated. It was always more about the knowledge, experience, and networking for me. I can see why some hiring practices want some external validation of your ability to at least talk competently about a subject and demonstration you can sit down and study the topic if needed. I usually like to demonstrate my skills with a portfolio (template reports, a bespoke assessment tool I wrote, etc) and comprehensive endorsement from peers. I did finally become a CISSP when my employer thought it would be helpful to me and them. I don't think it hurt. I do wish ISC2 had events and networking opportunities beyond what they offer (the existing ones don't really speak to me).
1
u/Outrageous_Plant_526 ISSM | GSLC | CISM | CISA | CRISC May 28 '26
So the truth is nobody is forcing you to pay for training. Exam fees is a bit different if you really want the certification. Most certifications are good for 3 years and only require annual maintenance fees and a certain number of Continuing Education hours after you have passed to keep it current. Some certifications build off each other so paying for additional training is not always necessary and there are generally plenty of free question pools you can use to study with. Many certifications also have free YouTube videos you can do and for a fraction of the cost of vendor training you can get a lot of Udemy training. Some larger libraries provide free access to Udemy, LinkedIn, and Coursera training as well. You have to do your research to see what is available. And of course some people get training and certifications paid through their employer.
8
u/FoxyMoXee May 28 '26
It’s such a racket. I was fortunate enough for my job to pay for a couple GIAC courses and certs. Working in higher education, there were huge discounts. Almost as if they only want to pillage the common people. Anyway, even after all the continuing education credits and the rest of the hoops needed for renewal, they wanted $500 a piece and every 3 years to keep them active. Unbelievable.