top of page

Certifiable: The Value of IT Certifications

  • Writer: Michael Trotter-Lawson
    Michael Trotter-Lawson
  • 9 minutes ago
  • 6 min read

Burk I.T. is a company with a lot of certifications. Our engineering team holds dozens of certifications from a wide variety of organizations in many different IT-related disciplines. There are cybersecurity certs, infrastructure certs, sales and marketing certs, and hundreds more just in the field of information technology.


Why? Why so many certifications? Who creates and administers these certs? Why are certs important for IT companies like Burk? And why should people outside the industry care about them?


 

The Keepers of the Badges


The reason there are so many certifications is partially tied to the organizations that create and award these certs. Most of the certifications that we have here at Burk are from our vendors, companies like Fortinet, Kaseya, and Microsoft. All these companies have a vested interest in ensuring partners (such as Burk I.T.) are actually qualified to operate, install, and support the hardware and software that they sell.  


As massive as companies like Microsoft are, it is not practical for them to sell to and support end-users directly. Working with companies like Burk, they can leave installation and support to local providers that already know the area and the businesses. By offering certifications for their products, these vendors are also able to ensure that a level of quality-control is maintained. It’s a mutually beneficial relationship: engineers take such certifications to learn more about the vendor’s products and prove their knowledge to employers, managed services providers hire engineers with these certs (or encourage their existing staff to acquire the certs themselves) to prove their competence to both the vendor and their clients, and the vendor is motivated to make these certs as comprehensive and informative as possible (because if they aren’t, the entire system collapses).


There are a lot of technology vendors, and each of these vendors likely offer a variety of products. With so many vendors and products, one can understand how so many certifications exist, as well as why multiple qualified and experienced engineers could each have a completely different list of certifications. Of course, there is an entire category of certs we have not touched on: third-party certifications.


 

Independent Arbiters


A certification that makes an individual qualified to manage or install a given product is all well and good, but it does not make for the best resume builder. For an IT engineer to be hired by a company like Burk, they need to display a general capability in the field of information technology, and that can be achieved via third-party certifications.


There are many organizations/associations that offer certifications in the field of IT, but not every one of these entities nor every cert holds the same weight or prestige. Plus, different organizations have different specializations in terms of the certs they offer. To explore these certification specialists further, take two the most prominent and respected entities who offer certs: CompTIA and ISC2.


CompTIA is a for-profit American trade association who offers certifications on basically every aspect of information technology. They have dozens of certifications, but typically, engineers will go for three as a baseline for the IT field: A+, Network+, and Security+. A+ has long been recognized as the industry standard for establishing competence as an entry-level IT engineer. Anyone looking to work as a support desk engineer should have (or at least be studying for) their A+. Network+ is the first step towards establishing a specialization, as it serves as a starting point for developing skills as a network technician. Security+ is naturally about establishing the skills for working in IT security. Given the state of the world, with AI-powered cybercriminals and hostile nation states targeting IT infrastructure many times a day, certifications in IT security have never been more valuable.


With CompTIA (or any other organization that profits off certifications), it is important to remember that they are incentivized to offer as many certs as possible to make as much money as possible. That fact does not necessarily devalue their certifications, but some of CompTIA’s certs can be described as steppingstones to other more valuable certs. For instance, one engineer could only have their A+ and Security+, while another has Tech+, AI Help Desk Essentials, Cloud Essentials, and Project Management Essentials. The simple math shows that engineer two has twice as many certs as the first, but the sheer number of certs can be deceptive. Tech+ is not a bad cert, but it is just a steppingstone to A+. All the “essentials” certs can be achieved in a single day and are designed to be broad introductions to the topics they cover. Generally, the most valuable certs that CompTIA offers are those in the “Plus Series” (A+, Security+, Network+, etc.) and the “Xpert Series”, which is highest level of certification that CompTIA offers.


Given the importance of IT security, it is no surprise that ISC2 offers some of the most prestigious certifications in the field. The International Information System Security Certification Consortium (ISC2) is a non-profit organization that specializes in training and professional certifications for cybersecurity professionals. As a non-profit, the continued existence and success of ISC2 is entirely dependent on its members paying into the organization, either through membership fees or the fees to pay for the various certs they offer. ISC2 is significantly more specialized than CompTIA, only offering certifications related to cybersecurity, though every cert naturally requires some related IT knowledge and capabilities. The certifications offered by ISC2 include some of the most prestigious cybersecurity certs in the industry, though like CompTIA, they are not all created equally.


ISC2 only has a total of nine certifications, so I will touch on all of them. Certified in Cybersecurity (CC) is the only entry-level cert, designed to make some level of cybersecurity awareness and competence accessible to the general public. Systems Security Certified Practitioner (SSCP) requires a year of relevant industry experience and is designed for engineers and administrators who have hands-on technical security responsibilities. Certified in Governance, Risk and Compliance (CGRC) requires two years of experience and is for those individuals who, naturally, manage risk and compliance for their organizations or client organizations. Moving into slightly more niche territory, there is Certified Cloud Security Professional (CCSP) and Certified Secure Software Lifecycle Professional (CSSLP). CCSP requires over five years’ experience and is focused on cloud security, while CSSLP requires four years of experience and focuses on secure software development.


Finally, we get to ISC2’s first ever certification, as well as the industry standard for establishing general expertise in cybersecurity: Certified Information Systems Security Professional (CISSP). Requiring at least five years of paid work experience, the CISSP certification is about proving that an individual is capable of effectively designing, implementing, and managing a best-in-class cybersecurity program. There are only three ISC2 certifications beyond CISSP, and they are all specialized into different aspects of cybersecurity infrastructure: Information Systems Security Architecture, Engineering, and Management Professional (ISSAP, ISSEP, and ISSMP). Each of these certs require over seven years’ experience and represent arguably the world’s most prestigious certifications in cybersecurity.  

 


What does it all mean for you?


I have written about many certifications in this article, but they are a fraction of the hundreds of IT certifications that exist. Should someone outside of the field really care about all these certs? Or any of these certs? Yes and no.


It is impossible to keep up with every relevant certification in IT, even for those of us who work in the industry. However, you should still care about certs, because they should still prove a level of competence for the holder. What I hope this article impresses on you is that the simple quantity of certifications is not as important as the quality of certifications. An engineer with a CISSP and an A+ is probably way more competent than one with a CC and a Tech+. And if an engineer or an IT company has certifications that you have never heard of before, look them up. The organizations that offer these certs should be very candid about what it takes to receive their certs and what those certs qualify their holders to do. If they aren’t, that is a major red flag.


Certifications are a valuable tool for the IT industry, but they are only as good as the hands-on experience behind them. A badge on a website proves an engineer passed a test, but the real benefit is knowing your technology is being handled according to the highest standards in the industry.

Comments


bottom of page