Want a sequenced plan instead of a list? Join the structured learning tracks

GRC certifications

Governance, risk, compliance, audit, privacy and AI governance.

Clear

9 certifications match these filters

GRC 9

GRC certifications
Cert name Target job title Level Prerequisites Study notes Recent updates
CISA ISACA IT Auditor / IS Assurance Analyst Intermediate 5 years of IS audit, control or security experience (up to 3 years can be waived). Coming Soon Current job practice since August 2024. An active CISA unlocks ISACA's AAIA AI-audit credential.
ISC2 CGRC ISC2 GRC Analyst / Authorization Officer (RMF) Intermediate 2 years of paid experience in at least one of the CGRC domains. Coming Soon Renamed from CAP. Also listed as a qualifying credential for ISACA's AAIR.
ISO 27001 Lead Implementer PECB ISMS Implementer / GRC Consultant Intermediate ISMS fundamentals. The full credential requires professional experience (PECB: 5 years, 2 in information security management). Coming Soon Aligned to ISO/IEC 27001:2022. Certified organisations had to transition from the 2013 edition by 31 October 2025.
ISO 27001 Lead Auditor PECB ISMS Auditor / Compliance Auditor Intermediate ISMS fundamentals plus audit experience for the full credential. Coming Soon Audits now run against the 2022 edition's 93 Annex A controls; the 2013 transition window has closed.
CIPP/E IAPP Privacy Analyst / Data Protection Officer Intermediate None. Coming Soon Body of knowledge centres on GDPR. Recertify every 2 years with 20 CPE credits.
AIGP IAPP AI Governance Lead / Responsible AI Analyst Intermediate None. Coming Soon Maps AI governance to the EU AI Act, NIST AI RMF and related frameworks.
CRISC ISACA IT Risk Manager / Risk & Control Analyst Advanced 3 years of experience in IT risk management and IS control. Coming Soon Counts as a qualifying credential for ISACA's new AI-risk certification (AAIR).
AAIA ISACA AI Auditor / Senior IT Auditor Advanced Active CISA, or a qualifying audit designation (CIA, US CPA, ACCA/FCCA, Canadian, Australian or Japanese CPA). Coming Soon Eligibility was expanded beyond CISA/CIA/CPA to include ACCA and several international CPA designations.
AAIR ISACA AI Risk Manager Advanced One of about 25 qualifying credentials, including CRISC, CISA, CISM, CISSP and CGRC. Coming Soon The newest of ISACA's AI trio alongside AAIA (audit) and AAISM (security management).

Not sure which one is yours?

Coaching & cert roadmaps

One-to-one guidance and a roadmap built around your background, target role and timeline, so you stop guessing which cert comes next.

See coaching programs

Structured learning tracks

Membership with role- and cert-based learning tracks: roadmaps, cheat sheets, assessments, exclusive writeups and member pricing on notes.

Join the learning tracks

Prep resources & cheat sheets

Cheat sheets, command references and exam-day extras for when you already know the material and need it fast and in one place.

Browse prep resources