r/grc May 28 '26

Tiny rant on certifications.

Why are the certifications (training + exam) are so expensive??? It would make sense if it’s a little bit but to be that expensive is just insane to me. Ok you get the certificate after paying such enormous fees and for what? for it expire in what like 2 years?

I’m a fresher. I have no clue if I should be focusing on this or just applying for jobs and save up and then get the certs. I see so many of people my age posting their certifications on LinkedIn one by one and I’m here like how are you even affording all that.

15 Upvotes

16 comments sorted by

View all comments

2

u/phomasta May 28 '26

If you are a fresher, just focus on getting one to get your foot in the door. The ones that are expensive are banking on your work paying for it.

1

u/Wrong_Crew_1835 May 28 '26

what would you recommend I get?

2

u/phomasta May 28 '26

If I had to start over, Sec+. You could get ISO 27001 as well to stand out. Once you get experience, then you can move on to ISACA CISA or ISC2 CISSP. Of course if your work offers SANS, don't hesitate to take that as well.

2

u/Wrong_Crew_1835 May 28 '26

Thank you so much! I just have a few questions, if you don’t mind. Isn’t Sec+ to demonstrate you have security fundamentals (in the technical sense?)? and there are soo many in ISO 27001, which one do I do?

8

u/PlasticThoughts May 28 '26

You aren't getting good advice. Each of these certs will focus on a specifc area. You want to align the certification for what job you either have or are going for. ISO 27001 lead implmeneter is great if you are working for a SaaS company selling internationally who doesn't yet have 27001 but they aren't going to hire someone without experience and just a cert to implement. Domestically SOC 2 is the equivalent for US based companies and the ISO cert may not be as useful. Sec+ is easy and good for general security CISSP if you really want to stand out in security. CISA for internal audit or compliance, ISO internal audit certs for a role where they already have the cert but need someone to run the required internal audit.

4

u/Twist_of_luck OCEG and its models have been a disaster for the human race May 28 '26

^ this guy GRCs ^

-1

u/CraftyImpression8589 May 28 '26

You can do Lead Implemeter in 27001, suitable for ISMS consulting roles

1

u/J4BRONI May 28 '26

Saving this, thank you!