CTI certifications compared
Certifications get you past HR filters. They do not make you an analyst, and interviewers in this field are unusually good at telling the difference.
Prices, exam formats and course contents change regularly. Everything below describes what each certification signals and who it suits — always confirm current cost, validity period and syllabus directly with the provider before committing. We hold no affiliation with any body listed here.
The short version
- If an employer is paying: GCTI with the associated SANS course is the strongest single option for the discipline itself.
- If you are in the UK or much of Europe: CREST credentials carry real regional weight.
- If you are paying yourself and want the learning rather than the badge: the free and low-cost options below cover most of the same ground.
- If you already have a portfolio of public analysis: spend the money on nothing, and write more.
Intelligence-specific
| Certification | Best for | What it signals | Watch out for |
|---|---|---|---|
| GIAC GCTI SANS FOR578 |
Analysts with some experience, employer-funded | Serious grounding in tradecraft — the cycle, structured analysis, attribution discipline, reporting. The closest thing to a discipline standard. | Cost is high enough that self-funding is rarely rational. |
| CREST CPTIA Practitioner |
Entry to mid, UK/EU market | Structured knowledge of the intelligence process and threat landscape. | Recognition drops off sharply outside its home markets. |
| CREST CRTIA Registered |
Experienced analysts, UK/EU | Practical competence at a higher bar than the practitioner level. | Genuinely demanding; not a first certification. |
| EC-Council CTIA | Regions and employers that specify it | Coverage of the intelligence lifecycle at a broad level. | Mixed reputation among practitioners. Useful mainly where a job posting names it. |
| MITRE ATT&CK Defender (MAD) | Anyone doing ATT&CK mapping work | Demonstrable competence with ATT&CK specifically, including the CTI-focused modules. | Narrow by design — a complement, not a primary credential. |
| arcX CTI Foundation | Beginners, self-funded | A free, well-structured introduction to the discipline. Genuinely good value for the price. | A foundation certificate signals effort, not competence. |
Adjacent credentials that help
- GCFA / GCFE — forensics depth. Valuable for the DFIR-leaning track, where turning artefacts into intelligence is the job.
- GREM — reverse engineering. Overkill for most CTI roles, decisive for a few.
- Blue Team Level 1 / 2 — practical, affordable, and good at building the technical floor described in the roadmap.
- Security+ / CySA+ — HR filters for a first role. Close to irrelevant afterwards.
- OSCP — offensive perspective. Not a CTI credential, but genuinely improves how you read intrusion evidence.
What actually beats a certification
Every hiring manager we would trust says a variant of the same thing. In rough order of what moves a hiring decision:
- Public written analysis. One well-reasoned intrusion analysis with explicit confidence language and stated gaps outperforms any certificate. It demonstrates the actual deliverable of the job.
- Demonstrable tracking work. An intrusion set you have followed for months, with your own assessments and the questions you could not resolve.
- Relevant operational experience. SOC or IR time, and the telemetry fluency it builds.
- Community contribution. Sigma rules, YARA rules, tooling, or sustained participation in a sharing community.
- The certification.
Collecting certificates instead of producing analysis. It is visible in an interview within about five minutes, because certified candidates without practice can define the Diamond Model but cannot pivot across it on live evidence. If you have a fixed budget of hours, spend most of them writing.
Test where you actually stand with a mock interview before deciding what to buy — it is a cheaper diagnostic than a course.
Run a mock interview on this material. You get the question, a graded response against a vetted rubric, and the probing follow-up an interviewer would ask next.
Related reading
- How to become a CTI analyst Cyber threat intelligence is a writing job with a technical floor. This is what the work looks like, what hiring managers actually test, and the order to learn things in.
- MITRE ATT&CK for CTI analysts ATT&CK is a knowledge base of adversary behaviour organised by tactic and technique. Most candidates can recite that. Fewer can map an ambiguous artefact correctly, or explain what a heat map does not tell you.
- The Diamond Model of intrusion analysis The Diamond Model exists to make pivoting explicit. Its four vertices are not a taxonomy to recite — they are the four places you can be standing when you ask "what else touches this?"
- The Cyber Kill Chain A 2011 model that is still the clearest way to talk about intrusion sequence and defensive coverage — provided you can also say where its linear assumption fails.