ctianalyst.com

CTI certifications compared

Certifications get you past HR filters. They do not make you an analyst, and interviewers in this field are unusually good at telling the difference.

Before you spend anything

Prices, exam formats and course contents change regularly. Everything below describes what each certification signals and who it suits — always confirm current cost, validity period and syllabus directly with the provider before committing. We hold no affiliation with any body listed here.

The short version

  • If an employer is paying: GCTI with the associated SANS course is the strongest single option for the discipline itself.
  • If you are in the UK or much of Europe: CREST credentials carry real regional weight.
  • If you are paying yourself and want the learning rather than the badge: the free and low-cost options below cover most of the same ground.
  • If you already have a portfolio of public analysis: spend the money on nothing, and write more.

Intelligence-specific

CertificationBest forWhat it signalsWatch out for
GIAC GCTI
SANS FOR578
Analysts with some experience, employer-funded Serious grounding in tradecraft — the cycle, structured analysis, attribution discipline, reporting. The closest thing to a discipline standard. Cost is high enough that self-funding is rarely rational.
CREST CPTIA
Practitioner
Entry to mid, UK/EU market Structured knowledge of the intelligence process and threat landscape. Recognition drops off sharply outside its home markets.
CREST CRTIA
Registered
Experienced analysts, UK/EU Practical competence at a higher bar than the practitioner level. Genuinely demanding; not a first certification.
EC-Council CTIA Regions and employers that specify it Coverage of the intelligence lifecycle at a broad level. Mixed reputation among practitioners. Useful mainly where a job posting names it.
MITRE ATT&CK Defender (MAD) Anyone doing ATT&CK mapping work Demonstrable competence with ATT&CK specifically, including the CTI-focused modules. Narrow by design — a complement, not a primary credential.
arcX CTI Foundation Beginners, self-funded A free, well-structured introduction to the discipline. Genuinely good value for the price. A foundation certificate signals effort, not competence.

Adjacent credentials that help

  • GCFA / GCFE — forensics depth. Valuable for the DFIR-leaning track, where turning artefacts into intelligence is the job.
  • GREM — reverse engineering. Overkill for most CTI roles, decisive for a few.
  • Blue Team Level 1 / 2 — practical, affordable, and good at building the technical floor described in the roadmap.
  • Security+ / CySA+ — HR filters for a first role. Close to irrelevant afterwards.
  • OSCP — offensive perspective. Not a CTI credential, but genuinely improves how you read intrusion evidence.

What actually beats a certification

Every hiring manager we would trust says a variant of the same thing. In rough order of what moves a hiring decision:

  1. Public written analysis. One well-reasoned intrusion analysis with explicit confidence language and stated gaps outperforms any certificate. It demonstrates the actual deliverable of the job.
  2. Demonstrable tracking work. An intrusion set you have followed for months, with your own assessments and the questions you could not resolve.
  3. Relevant operational experience. SOC or IR time, and the telemetry fluency it builds.
  4. Community contribution. Sigma rules, YARA rules, tooling, or sustained participation in a sharing community.
  5. The certification.
The failure mode to avoid

Collecting certificates instead of producing analysis. It is visible in an interview within about five minutes, because certified candidates without practice can define the Diamond Model but cannot pivot across it on live evidence. If you have a fixed budget of hours, spend most of them writing.

Test where you actually stand with a mock interview before deciding what to buy — it is a cheaper diagnostic than a course.

Next step

Run a mock interview on this material. You get the question, a graded response against a vetted rubric, and the probing follow-up an interviewer would ask next.

Related reading