Cybersecurity Certifications: What They Say About a Candidate
CISSP, OSCP, cloud certifications: what each type of security certification proves, what it does not, and how to use certifications when hiring.
Security job ads often list required certifications. Yet a certification means very different things depending on whether it validates theoretical knowledge, a practical exam or mastery of a product. This guide helps you read a candidate's certifications correctly, verify them and use them without screening out strong people who have none.
Why certifications are misread in hiring
A certification is a signal, not proof of operational ability. It shows that someone, at a given time, passed an assessment defined by an awarding body. The useful question is therefore: what exactly did that exam assess, and does it relate to the role?
Two mistakes are common:
- Treating all certifications as equal, when a governance certification and a practical offensive exam measure unrelated things.
- Using them as an automatic knockout filter, which rules out experienced practitioners who never needed to certify.
The main families of certifications
Governance and management certifications
Examples: CISSP, CISM, ISO/IEC 27001 Lead Implementer or Lead Auditor, EBIOS Risk Manager.
They validate broad knowledge of security domains, frameworks, risk management and how to run a management system. Some, such as the CISSP, also require proof of professional experience.
What they signal: a big-picture view, a shared vocabulary with leadership and auditors, the ability to structure an approach.
What they do not signal: hands-on technical ability. A CISSP holder cannot necessarily investigate a compromise. For a CISO or GRC consultant role they are relevant; for a SOC analyst, much less so.
Practical offensive exams
Examples: OSCP and other OffSec certifications, practical exams such as CPTS, or hands-on certifications from comparable providers.
What they share: the candidate must compromise machines or applications in a live environment under time pressure, then write a report.
What they signal: demonstrated ability to exploit, persistence, method and often reporting skills.
What they do not signal: mastery of every context. An exam covers a defined scope (infrastructure rather than web or cloud, for example) and says nothing about client relationships or the quality of a report delivered to an executive committee. Our pentester job description lists the skills to check alongside.
Vendor and cloud certifications
Examples: AWS, Microsoft Azure or Google Cloud security certifications, and certifications from firewall, EDR or SIEM vendors.
What they signal: knowledge of a product or platform, its features and its configuration best practices.
What they do not signal: the ability to reason outside that ecosystem, or production experience. Some of these exams are question-based. They are useful if your environment runs on that product, provided you check real-world practice.
Entry-level certifications
Examples: CompTIA Security+, introductory certifications from various bodies, short course credentials.
What they signal: a base of vocabulary and concepts, and a commitment to learning. They are common among junior candidates and career changers.
What they do not signal: operational autonomy. They open a conversation; they do not close it. For these profiles, see our guide to hiring career changers.
Reading grid: what to check in interview
| Certification type | What it proves | What to check in interview |
|---|---|---|
| Governance (CISSP, CISM, ISO 27001 LI/LA) | Broad knowledge of domains, frameworks and risk | A programme delivered end to end, the trade-offs made, the ability to explain a risk to an executive |
| Practical offensive (OSCP and equivalents) | Demonstrated ability to compromise a given environment | Method on a case unlike the exam, the quality of a report, experience on client engagements |
| Vendor and cloud | Knowledge of a product or platform | A real configuration they built, a production issue they solved, understanding of the tool's limits |
| Entry-level | Basic vocabulary and concepts | Personal practice (labs, CTF, homelab), networking and systems fundamentals |
Using certifications without excluding good candidates
A sound practice is to separate three levels in your job ad:
- Required: only when it is a genuine requirement, for example contractual with a client, regulatory, or tied to a qualification such as the ANSSI-qualified provider schemes in France (PASSI, PRIS, PDIS), which set requirements on the skills of the people delivering the service.
- Preferred: the certification is a plus, but equivalent demonstrated experience replaces it.
- Not needed: leave it out, it only shrinks your pool.
Write the skill rather than the acronym. "Able to run an internal penetration test on an Active Directory environment" attracts better and filters more accurately than "OSCP required".
In interview, treat the certification as a starting point: ask what the candidate learned while preparing, what they found hard and how they have applied it since. Our incident response interview questions show this kind of practice-led conversation.
How to verify a certification
- Ask for the certification number or ID, and check it on the awarding body's register or verification service where one exists.
- Verify digital badges through the issuing platform rather than from a screenshot.
- Check validity: several certifications require renewal or continuing education. An expired certification is not disqualifying, but it should be presented as such.
- Tell certification from training: a course attendance certificate is not a certification earned by passing an exam.
- Get the candidate's consent for any check involving their personal data, in line with the principles set out by the CNIL on recruitment.
Certification, experience and practical proof
A certification complements experience and practical assessment; it does not replace them. The most reliable signal is still watching a candidate tackle a concrete problem close to your context. That is the purpose of our method for assessing cybersecurity skills.
A heavily certified candidate who fails a simple lab raises questions. An uncertified candidate who cleanly solves a demanding lab deserves your full attention.
Conclusion
Read each certification for what it measures: knowledge, a practical exam or mastery of a product. Keep strict requirements for cases where they are genuinely imposed, verify what is declared and always confirm through practice.
Hiring a security profile and unsure which certifications to require? Tell us about your need. A recruiter and a security practitioner scope the role with you, and our shortlisted candidates prove their skills on hands-on labs, certified or not. See how we work.