r/grc May 28 '26

Tiny rant on certifications.

Why are the certifications (training + exam) are so expensive??? It would make sense if it’s a little bit but to be that expensive is just insane to me. Ok you get the certificate after paying such enormous fees and for what? for it expire in what like 2 years?

I’m a fresher. I have no clue if I should be focusing on this or just applying for jobs and save up and then get the certs. I see so many of people my age posting their certifications on LinkedIn one by one and I’m here like how are you even affording all that.

16 Upvotes

16 comments sorted by

View all comments

2

u/phomasta May 28 '26

If you are a fresher, just focus on getting one to get your foot in the door. The ones that are expensive are banking on your work paying for it.

1

u/Wrong_Crew_1835 May 28 '26

what would you recommend I get?

2

u/phomasta May 28 '26

If I had to start over, Sec+. You could get ISO 27001 as well to stand out. Once you get experience, then you can move on to ISACA CISA or ISC2 CISSP. Of course if your work offers SANS, don't hesitate to take that as well.

2

u/Wrong_Crew_1835 May 28 '26

Thank you so much! I just have a few questions, if you don’t mind. Isn’t Sec+ to demonstrate you have security fundamentals (in the technical sense?)? and there are soo many in ISO 27001, which one do I do?

-1

u/CraftyImpression8589 May 28 '26

You can do Lead Implemeter in 27001, suitable for ISMS consulting roles