The Cybersecurity Cert Racket

Published on Sep 29 2026

Pay to Win

I wish we could all stop pretending the cybersecurity certification game is about competence. It isn't. It's about money.

The premise behind recertification sounds noble enough on paper: the threat landscape moves fast, technology evolves, and practitioners need to stay sharp. Nobody wants an analyst defending enterprise networks using knowledge from 1999, right? Then you actually look at how the system functions in practice, and in my opinion, the story falls apart.

Every three years, the certifying bodies demand two things: your money and your Continuing Professional Education (CPE) credits. The maintenance fee is non-negotiable. Pay the toll or lose the cute digital badge. But the credit system is where the insult turns from bad to worse. You can spend over forty hours a week doing your job. Inside production environments. Dissecting live ransomware, reverse engineering attack vectors, writing complex detection logic, hardening identity infrastructure, talking to end-users and VP's about cyber threats alike, and responding to adversaries actively attempting to penetrate your network. You live and breathe the actual work. You solve problems that haven't made it into any textbook or exam blueprint yet. You do things you can't discuss publicly for legal or national security reasons. According to the credentialing bodies, that doesn't count.

Your day job, the literal real-time application of the domain knowledge you were tested on, is capped at a fraction of what you need, if it's credited at all. The very thing proving your continued competence is dismissed as irrelevant to your maintenance requirements. It's stupid.

Worse, this recurring toll gate heavily penalizes the people who can least afford it. If you are an entry-level analyst or someone breaking into the field from a non-traditional background, you likely do not have spare cash lying around. You sacrificed money you barely had just to buy study guides and pay the $400 to $1,000 exam voucher.

Piling annual maintenance fees on top of that is predatory. Meanwhile, senior engineers and entrenched practitioners might barely blink at it. That may be because they make enough money to not care, or perhaps they work for mature enterprises that pay the dues on a corporate card without a second thought. The system acts as an unnecessary moat and a financial roadblock for newcomers trying to get their foot in the door.

And we need people at the door. Historically, talent in the cyber industry has been hard to come by.

This certificate ecosystem does not survive on merit alone. It thrives because government mandates keep it artificially alive. Frameworks like the Department of Defense's DoD 8570 and DoD 8140 have codified this nonsense. By legally requiring specific commercial certifications for every cleared contractor and military personnel touching an IT system, the government guaranteed an endless, captive revenue stream for a handful of testing vendors. It is a government-subsidized racket. Human resources departments blindly inherit these matrices, building automated filters that reject capable applicants simply because they didn't pay their dues to a for-profit 3rd party certificate printing company.

The entire system exists to manufacture artificial scarcity and recurring revenue. It is an industry tax. We don't treat any other form of technical credential this way.

Nobody calls up their university to pay an annual subscription fee to keep their bachelor's degree active. You don't have to submit proof to an alumni committee every thirty-six months showing you still remember the differential equations or computer architecture you learned in undergraduate school. An engineering degree from 2012 simply reads: B.S. in Computer Science, 2012.

The world understands how that works. You achieved the standard. You learned the fundamentals. The date tells everyone when the baseline was established, and your subsequent career history demonstrates what you've done with it since.

Certs should function the exact same way: Certification Name (Year Acquired). End of story. If an employer wants to know whether your knowledge of cloud security or network fundamentals is current, they don't need a rubber stamp from an association that charges you $135 a year just to keep your name in a database. They can look at your resume. They can look at what you’ve built, what you’ve engineered, and what you’ve protected over the last five years. If they're insistent, they could ask you to re-take the cert, and you could then list: Certification Name (Year 1, Year 2).

A certificate proves you passed a difficult, standardized filter at a specific moment in time. Everything after that is demonstrated on a resume. Your continued employment with a relevant cyber security related job title.

Turning that milestone into an eternal recurring debt doesn't elevate the profession. It just turns professional development into a dumb business scheme. You should not be required to pay rent on your own accomplishments.

My Cyber Certs

I personally reject all renewals and CPE. Everything in this list is expired / set to expire within +3 years from achievement date. The only certification I keep "alive" is my CISSP from (ISC)² and frankly, every year I consider letting that one drop.

I have degrees, lots (expired) certs, and over ten years of experience.

Who really cares about an active CISSP?

List Updated 09/2026