Cybersecurity professional certification historical data
Description
This table includes data on the cybersecurity professional certification industry from the 1970s through 2025. Each of 466 certifications is listed with the certifying organization, year in which the organization was founded, year in which the certification was founded (both earliest and latest possible), year in which the certification retired (if applicable) and total lifetime of the certification, and hyperlinks to current or historical webpages that form the basis for the data shown.
Files
Steps to reproduce
We began with two published lists of information security certifications: a survey published in Certification Magazine, which identifies 36 vendor-neutral and 22 vendor-specific information security certifications (Tittel 2004); and a “roadmap” of certifications maintained by Paul Jerimy, a self-identified cybersecurity professional (Jerimy 2024). Jerimy’s roadmap is linked to a GitHub repository, which shows that it began in 2014 with a chart produced by a user of techexams.net , and has been updated every few years since then. As of 2024, it included 481 certifications. We gathered data on all certifications included in these two lists, including: certification title; year the certification was founded; year the certification was retired or merged; certifying organization; year the certifying organization was founded; and nation in which the certifying organization was first founded (its international headquarters). We also compiled notes on the content of the certification, price, and other relevant details. As we gathered historical data, we discovered additional training courses and certifications that never made it into either of the two lists noted above. We added them only when they were described as a “certification,” even though the difference between a course and a certification could be largely a matter of semantics. After close review of the certifications’ subject matter, we also eliminated some certifications as insufficiently focused on information security. For example, Jerimy’s roadmap includes certifications for programming languages, project management, and risk management; we determined most of these to be insufficiently focused on cybersecurity. The 2003 list also included the Physical Security Specialist offered by the American Society for Industrial Security; while physical security is part of information security, we did not see sufficient focus on information security in the current materials for the certification. Our final dataset includes 466 cybersecurity-focused certifications from 12 different nations. We regard this as a minimal rather than maximal list of cybersecurity certifications. It is likely that we missed some short-lived certifications. Additionally, as discussed further below, the lists with which we started were oriented towards U.S. markets, leading to a dataset with no certifications from Central or East Asia, and only a few from the global South. All were marketed in English (a few were also marketed in other languages). Nonetheless, our dataset is likely a reasonably thorough accounting of cybersecurity professional certifications that are available in the United States, Britain, and other regions where English is commonly spoken.