Security Certification Roadmap

For years I used Paul Jerimy’s framework to decide, among hundreds of acronyms and certifications, which ones were worth pursuing — considering their contribution, the expertise gained in earning them, and their usefulness, in order to build capabilities that add value for our clients and for ONESEC and Twin Fact.

The framework splits domains into columns, and specifies, from bottom to top, the level of expertise required for each credential — higher up means more expertise. Each certification lists its prerequisites and cost.
However, maintaining a framework like that took enormous effort across nearly 500 certifications, which is why it had gone almost 2 years without an update.

So I decided not to keep waiting, and picked up Paul’s work, updating it as of July 2026, with these changes and improvements:
– Removed retired or renamed certifications — for example Palo Alto Networks, which replaced its entire catalog with 14 certifications in July 2025.
– Added relevant certifications released in the last two years, verifying each one against its official source.
– Split out certifications that used to live in a single domain but whose CBK actually spans several in depth. Example: CISSP no longer lives only in GRC — it’s now mapped across all 8 domains of its CBK.
– For certifications spanning more than one domain, depth of expertise was estimated separately per domain, since the same certification can be expert-level in one domain and beginner-level in another. Example: see CISSP.
– Recalibrated the level of several certifications. For example: PMP and PgMP moved from «expert» to «intermediate,» benchmarked against certifications below them that actually require a higher level of expertise to earn.
– The roadmap is now maintained with monthly updates, so it doesn’t go stale again.

My purpose:
I’m sharing it with the community with the same purpose Paul started with, and as a tribute to his effort. Hoping it keeps answering questions that matter to every professional in our industry:
– For clients: «When everyone claims to be an expert, how do I determine a business partner’s real level of capability? What do their certifications actually say?»
– For every organization: «Given finite time and resources, which certifications should my team pursue for the greatest return?»
– For ONESEC Twin Fact: «What capabilities must we develop to bring more value to our clients?»
– For me: «Which one is next?»
The updated framework will be shared on our website for reference.
Comments and suggestions are welcome.
hashtag#Onesec hashtag#TwinFact hashtag#AlwaysSecureNeverAtRisk hashtag#Certification

License note: this roadmap is derived from Paul Jerimy’s Security Certification Roadmap (https://lnkd.in/gxJXTar7), used and distributed under a Creative Commons BY-SA 4.0 license (https://lnkd.in/gpZ9T-qA) — anyone can take it, adapt it, and redistribute it, as long as they preserve attribution and keep the same license.

Scroll al inicio