# Which security certifications are actually worth it

Learning something, passing a recruiter's filter and satisfying a bank's procurement department are three different problems with three different answers. What the exams really are, what they cost, and which certificates Gulf and EU regulators actually name.

- Published: 2026-07-30
- 13 min read
- Mustafa Yousry — Entrepreneur · CTO · Cyber Security
- https://mustafayousry.com/en/articles/which-security-certifications-are-worth-it

---

## Three questions wearing the same clothes

Nobody asks "is this certification worth it" and means one thing. Three questions hide in there, and the answers barely overlap.

*To learn something?* Then all that matters is whether the assessment makes you do the work.

*To get past a filter?* Then all that matters is which string a recruiter searches for.

*To satisfy somebody else's procurement or audit department?* Then my opinion is irrelevant, and so is yours: what matters is what a named instrument says.

Most advice answers the first question and sells the answer as though it settled the other two.

For the record: I hold none of the technical certificates named below — my credentials are academic — and I have no commercial or affiliate relationship with any of the providers here. I hire the people who hold them, and I fill in the procurement questionnaires that name them. That is the position from which you can say a certificate is mandatory and teaches nothing, and mean both halves.

## The ones that teach you something

One test separates these from the rest: does the exam put you in front of real systems under time pressure — breaking in or working out what already happened — and then make you write it up the way a client would receive it.

| Certification | The exam | Cost, 2026 |
|---|---|---|
| OSCP / OSCP+ | ~24 hours proctored, three machines plus an AD set, then a report | ~USD 1,750 |
| HTB CPTS | 10-day lab window, plus a separately graded client report | USD 210 |
| PNPT | Five days testing, two writing, then a 15-minute live debrief | USD 499 |
| CRTO | Red team operation in a Cobalt Strike lab | GBP 399 |
| BTL1 | 24-hour practical incident response | GBP 399 |
| CCDL2 | 48-hour practical, marked on approach | ~USD 849 |

Those are list prices checked in 2026 and they move. The OSCP figure is the course-and-exam bundle. The CPTS figure is the standalone voucher; the USD 490 you will see quoted is Hack The Box's annual Academy subscription, which bundles the training path and one voucher. CRTO is now one price for lifetime course and lab access with unlimited exam attempts; Zero-Point discounts it by purchasing power parity in some countries.

OSCP is the closest thing to an entry gate in commercial pentest hiring, which is why it costs what it costs: you are buying an assessment and a keyword, not instruction. OffSec's own exam guide gives 23 hours 45 minutes of testing and a further 24 hours to submit documentation; the marketing rounds it to 24. OSCP+ expires after three years and carries a maintenance fee; plain OSCP is for life.

CPTS is arguably the harder assessment — the report is graded separately, and HTB's rules give no second attempt unless you submitted a report on the first. PNPT is what I point junior consultants at: the live debrief examines the part of the job the client actually sees. CRTO's exam is an operation rather than a quiz, and it sits at the bottom of the red team price range, but its platform and exam mechanics both moved in 2026 — confirm the format with the vendor, not with an article. BTL1 is the defensive counterpart and the format holds up, though the issuer now trades as Centri rather than Security Blue Team.

GIAC belongs here on merit but nowhere near it on price: GCFA and GREM are respected by practitioners and hiring managers alike, but as of 2026 the SANS course runs around USD 8,800 and the GIAC attempt roughly a thousand more on top. Close to five figures. An employer-pays number.

## The gatekeeping ones you buy anyway

CEH is the clearest case. The base exam is 125 multiple-choice questions in four hours and has never required demonstrating an exploit; the separate Practical does. Practitioner regard is low. None of that reaches a procurement officer: CEH is ISO/IEC 17024 accredited, sits on the DoD 8140 qualification matrix that replaced the old 8570 baseline lists, and is named in tenders and adverts, heavily so in the Gulf. Buy it when a contract names it, not to learn to hack.

CISSP is a mile wide, an inch deep, and still the most effective single unlock for senior roles. The exam is not the substance; five years across two of eight domains plus endorsement by an existing member is. ISC2 also cut its experience-waiver list roughly in half on 1 April 2026, dropping CEH, CISA, CRISC, OSCP and most GIAC certificates — if you were told in 2024 that something waives a year, check first.

SC-200 is a cheap checkbox for a Microsoft-stack SOC: 100 minutes, free annual renewal.

## Management, governance and cloud

CISA is the strongest audit credential there is: internal audit, Big Four and examiner-facing roles name it outright. CISM is the standard security-manager filter, CRISC the weakest of ISACA's three as a hiring signal. All are knowledge exams, USD 575 for members as of 2026 — non-members pay more, and neither figure includes ISACA membership or the application fee.

ISO 27001 Lead Implementer and Lead Auditor are course credentials, not licences — only a certification body accredited to ISO/IEC 17021-1 can issue an accredited ISMS certificate. Lead Implementer is the practical one, and the one Gulf and EU compliance specs name. Auditing for a certification body usually means CQI/IRCA registration, earned in audit days, but that is convention rather than rule: ISO/IEC 17021-1 puts the competence obligation on the certification body, and some accept Exemplar Global or their own internal scheme. CCSK's value is the document behind it — the CSA guidance is the reference everyone actually cites. TOGAF and SABSA are inverses: recruiters search for one, architects respect the other.

## What the region actually requires

Most certification writing assumes a US or UK reader. Here is what I have had to satisfy.

**The UAE.** "NESA compliance" is legacy branding; the word appears nowhere in the instrument, which is the UAE Information Assurance Regulation. Its only binding words on the point are sub-control M5.4.1, which asks that compliance checking be performed by "authorized personnel with adequate technical capabilities"; the two lines usually quoted at testers — that a technical compliance check "should only be carried out by competent, authorized persons, or under the supervision of such persons", and that application security is helped by manual testing from people with programming and application penetration testing expertise — sit in the implementation and automation guidance, which the Regulation itself says is "provided for information purposes only". No certificate anywhere. The Central Bank rulebook names none either, but it is not the same shape: exchange houses must run internal and external vulnerability scanning and penetration tests at least annually, with information security and IT security controls audited by "external experts", while stored value facility licensees and larger payment service providers are asked only to "regularly assess the necessity to perform" penetration and cyber-attack simulation testing — an assessment obligation, not a testing one. Search that rulebook for CREST and you get nothing.

Dubai goes furthest. DESC launched Dubai Cyber Force in 2023 with CREST International, and for Dubai government, semi-government and critical infrastructure the gate is stacked: a trade licence covering cyber security, CREST company accreditation, DESC listing, consultants who can obtain Dubai Police clearance. Named certificates are a condition of being listed, which in the Gulf is rare but not unique — Oman's MTCIT accreditation for security assessment providers names CREST, OSCP, GPEN, GWAPT, OSWE and CEH for its own register. Dubai's list is longer — CRT, OSCP, GPEN and GWAPT for team members, CCT INF, OSEP, OSWE and GXPN for leaders, among others. Abu Dhabi is different again, and sector-specific: for the larger healthcare entities — hospitals of 21 beds and above, payers, the health information exchange, and healthcare technology and service providers, the categories ADHICS calls Advanced and Service Provider — it wants periodic independent assessment on yearly schedules, and names nobody.

**Saudi Arabia.** Any entity selling cybersecurity services in the Kingdom has had to register on NCA's Haseen platform since August 2022, and for some activities registration is no longer the whole gate: NCA licenses Managed Security Operations Centre services in two tiers. Its draft Regulatory Framework for Licensing Cybersecurity Services, Products and Solutions (RFCS-1:2026) would make penetration testing and red teaming separate specialised-licence activities, but it went out for public consultation in February 2026 and has not been issued. For testing work, Haseen registration is still the whole gate. Check whether that has changed before you bid.

Then read the controls, because the market misquotes them. ECC-2:2024's penetration testing control says nothing about who performs the test. The Critical Systems controls say far more: testing at least every six months by "a qualified team" that is nowhere defined, remote access from outside the Kingdom prohibited, outsourced and managed services restricted to "national companies and entities". That pair, not any certificate, is what ends fly-in-fly-out testing. And the most misquoted line in Saudi procurement is narrower than people repeat: control 1-5-1-2 requires technical support and technical development positions for critical systems to be filled with highly competent citizens — "experienced Saudi professionals" in NCA's own English rendering. Not cybersecurity posts generally. Whether it reaches an external test team is genuinely arguable — the section it sits under scopes personnel to employees and contractors — so do not tell a client it plainly excludes you.

SAMA prints a suggested certification table, and only for red teaming: CISA, CISM, CISSP and SSCP for managers, GPEN, GWAPT, GXPN and the OffSec set for testers, CREST's red team credentials under their old names. Suggested, not a condition of anything — that is the difference between it and Dubai's list. The rest of that appendix matters more: references, anonymised prior reports, a code of conduct, every activity logged.

**Europe.** Two sales-meeting claims are false: NIS2 does not require CREST, and GDPR does not require certified testers. NIS2 lets authorities order "regular and targeted security audits carried out by an independent body or a competent authority", and separately demand evidence of audits "carried out by a qualified auditor" — a term the directive never defines. GDPR names no method or qualification at all.

DORA is the real instrument, and deliberately brand-neutral: threat-led testing at least every three years for entities in scope, external testers at least every third test where internal ones are used, and testers "certified by an accreditation body in a Member State **or** adhere to formal codes of conduct or ethical frameworks". That "or" keeps non-CREST firms procurable in the EU. Its hard bars go unadvertised: independent assurance over how you manage the risk of the test, and indemnity insurance for misconduct and negligence. The ECB's 2025 TIBER-EU procurement guidance goes further — and note the year, because the 2018 predecessor said the opposite:

> Therefore, this guide does not provide a list of recommended certifications, but provides guidance on how to review the different certifications.

It specifies experience instead: a test manager with at least five years, other members two each, five company references, insurance, and separation from blue team or threat intelligence work for the same client.

Germany publishes the list nobody else will. BSI's competence assessment for penetration testers names CRT, GPEN, GXPN, the OffSec family, CEH Practical, CPENT, PenTest+, HTB CPTS and CRTO, requires one awarded within the last three years and still valid at application, and considers others case by case where the certificate carries a demonstrable practical component of at least 60% plus a final exam with a high practical content. It is a voluntary personnel scheme feeding BSI's certified-service-provider listing, not a legal requirement on anyone testing in Germany — but it is the most explicit government-published list I have seen.

**Egypt.** NTRA began accrediting cybersecurity providers in tiers in 2025: the higher tier may serve government, telecoms and critical infrastructure, the lower private clients only, and government buyers may contract accredited providers only. None of it travels to the Gulf. And whatever anybody holds, Law 175/2018 criminalises unauthorised access — what protects a tester here is a signed authorisation with a documented scope.

| Market | Gate on the firm | Gate on the person |
|---|---|---|
| Dubai government, CII | Licence, CREST accreditation, DESC listing | Named certificates, clearance |
| UAE exchange house | Annual scanning and testing, no names | "External experts", independent |
| Saudi critical systems | Saudi company, no remote access | "A qualified team", undefined |
| EU financial sector | Accreditation or code of conduct, insurance | Experience, not certificates |

## What a certificate does not prove

I have hired people holding certificates I could not pass who could not run an engagement, and people with nothing on paper who could. That is not an argument against certification, but about what an exam measures in twenty-four hours. Nothing here examines whether you can scope work with a client who does not know what they want, notice that the box in front of you is production and stop, write a finding a finance director will fund a fix for, or say "I don't know" in a boardroom. PNPT's debrief and the graded reports brush against it; everything else grades the middle of the job. Certificates also age badly in both directions: one issuer in my table has changed its name since I first wrote it down, and Dubai's published list still carries an EC-Council credential that was retired years ago. The ECB again:

> The entity should not rely on qualifications and certifications alone.

From a central bank, that is as close as you get to permission to judge the person, not the paper.

## If I had to pick a path

**Starting out.** Get employed, then spend money. ISC2's entry certification is around USD 199; the Google certificate is a course completion, not a certification, and a fine on-ramp to Security+. Take one, get a job, let an employer fund the next. The worst pattern I see is a career changer with four certificates, no job and no money left.

**Mid-career, going offensive.** CPTS or PNPT first, for the skill and the report discipline; OSCP when a filter demands the keyword; CRTO for red team credibility. Add CREST when the work requires it, knowing CRT through OSCP equivalency is a hiring credential, not a route into UK CHECK work, which now also wants a Cyber Security Council title. In the Gulf your certificate is the second gate; the first is whether the entity billing the work is locally licensed and, in Dubai, CREST-accredited.

**Architecture or leadership.** CISSP for the filter, because the filter is real and has no substitute. CCSK for cloud substance, CISA if you are going near audit, SABSA if you actually do risk-driven architecture, TOGAF when a bid names it. At that level what gets you the role is whether you can defend a design decision to the people paying for it.

## Closing

"Worth it" has no answer until you say who you are trying to convince. The hands-on exams are the cheap end of this article, and every one of them puts you in front of real systems and makes you produce a real deliverable. They buy skill and peer credibility, and nothing at a procurement desk. The gates are sold separately, cost more and teach less. Both are true at once, and anyone who says otherwise is selling training or has never answered a bank's vendor questionnaire.

---

Source: https://mustafayousry.com/en/articles/which-security-certifications-are-worth-it · Site: https://mustafayousry.com
