AI and LLM Security Certifications: Extending the Security Certification Roadmap
Paul Jerimy’s Security Certification Roadmap is the chart many of us send to anyone who asks “which certification should I do next?” It lays out hundreds of credentials by domain, skill level and cost, and it is the reason a lot of people discover that certifications exist beyond the three or four they’ve heard of.
The current version is dated July 2024 and lists 481 certifications. It predates the AI security wave: apart from GIAC’s machine-learning credential (GMLE), none of the credentials in this post are on it. That isn’t a criticism. In mid-2024 there were barely any AI security certifications to list.
That has changed quickly. Sixteen credentials aimed at securing, attacking, governing or auditing AI systems now exist, most of them launched in the last year, from vendors as different as CompTIA, ISACA, OffSec, Hack The Box and GIAC. This post maps them the way the roadmap maps everything else, and tries to be honest about how much we can actually say about credentials that are mostly less than a year old.
The timeline: from nothing to a whole tier
| When | What arrived |
|---|---|
| Aug 2025 | ISACA introduces AAISM, an AI security management certification |
| Oct 2025 | Cloud Security Alliance introduces TAISE |
| 17 Feb 2026 | CompTIA launches SecAI+ |
| Spring 2026 | OffSec launches OSAI (AI-300) |
| 2 Apr 2026 | Hack The Box announces HTB COAE |
| 2026 | GIAC lists three new AI exams: GAIPS, GOAA, GASAE |
| Mid 2026 | Microsoft’s SC-500 Cloud and AI Security Engineer exam reaches general availability |
Alongside these sit ISACA’s AAIA (AI audit), IAPP’s AIGP (AI governance), EC-Council’s C|OASP, Practical DevSecOps’ CAISP, Learn Prompting’s AIRTP+, and PECB’s ISO/IEC 42001 implementer and auditor credentials.
What does “AI security certification” even mean?
Before comparing anything, it helps to notice that the phrase covers four different jobs. Many buyers’ regret comes from picking a credential for the wrong one.
- Securing AI systems. Defending LLM applications, RAG pipelines, model supply chains and AI platforms. Think prompt injection defences, guardrails, data poisoning, AI threat modelling.
- Attacking AI. AI red teaming: testing LLMs and agentic systems the way an adversary would.
- Governing and auditing AI. Risk, policy, compliance and audit: NIST AI RMF, ISO/IEC 42001, regulation.
- AI-assisted security. Using AI to do security work faster: detection, automation, SOC workflows. This is a different skill from securing AI, and some “AI security” courses are really this.
Roadmap-style domains cut across all four, so the map below uses both: the four tracks across the top, and Beginner / Intermediate / Expert bands down the side. The levels and track placements are editorial judgement, calibrated against the bands the roadmap uses (for example, AAISM requires CISSP or CISM, which the roadmap places in its Expert band, so AAISM sits there too; AAIA is placed alongside it because ISACA positions it as an advanced credential, even though the CISA it builds on is an Intermediate-band certification on the roadmap).
Two things jump out. There is almost nothing at Beginner level, and the offensive and governance tracks are much better served than AI-assisted security, where the credential landscape is still mostly courses rather than certifications.
Securing AI systems
These are for engineers who build or defend AI-enabled applications and platforms.
| Credential | Level | Assessment | Prerequisites | Cost (USD) |
|---|---|---|---|---|
| SecAI+ CompTIA SecAI+ (CY0-001) · CompTIA | Intermediate | Up to 60 multiple-choice and performance-based questions, 60 min, pass 600/900 | Recommended 3-4 years in IT, 2+ years hands-on security; Security+, CySA+ or PenTest+ | ~$359 |
| CAISP Certified AI Security Professional · Practical DevSecOps | Intermediate | Practical, 5 challenges in 6 hours, then a report within 24 hours | Basic Linux; scripting helpful | $1,099 (course + one attempt) |
| GAIPS GIAC AI Platform Security · GIAC / SANS | Intermediate | CyberLive hands-on lab exam | None listed | ~$999 |
| SC-500 Microsoft Cloud and AI Security Engineer Associate · Microsoft | Intermediate | Proctored, 120 min, may include interactive components | Practical Azure and hybrid administration; strong Microsoft Entra ID familiarity | Varies by country |
CompTIA SecAI+ is the broadest entry. Its four domains are Securing AI Systems (40%), AI-Assisted Security (24%), AI Governance, Risk and Compliance (19%) and Basic AI Concepts (17%), so it deliberately spans three of the four tracks. It’s knowledge-based (multiple choice plus performance-based questions in 60 minutes) and CompTIA recommends Security+, CySA+ or PenTest+ first. CompTIA also estimates the exam version will retire three years after launch, which is a reminder of how fast this content moves.
CAISP (Practical DevSecOps) is the practical option for application security and platform engineers: five challenges in six hours, then a written report within 24 hours. The syllabus covers the OWASP Top 10 for LLM Applications, MITRE ATLAS, STRIDE-based threat modelling for AI, supply chain security, and NIST AI RMF and ISO 42001. It’s described as a lifetime credential.
GIAC GAIPS targets people who audit and secure GenAI applications and LLM development pipelines, and maps to SANS SEC545. Like GIAC’s other new AI exams it uses the CyberLive format: hands-on tasks in a live lab instead of multiple choice.
Microsoft SC-500 (Cloud and AI Security Engineer Associate) is different in kind. It’s an Azure and hybrid security exam where securing AI solutions is one responsibility among several, next to identity, storage, networking and compute. If your job is Azure security, it’s the sensible pick. If your job is LLM security specifically, it’s not what it looks like from the title.
Attacking AI
This is where the credentials are most hands-on, and where practitioners with a penetration testing background will feel at home.
| Credential | Level | Assessment | Prerequisites | Cost (USD) |
|---|---|---|---|---|
| OSAI OffSec AI Red Teamer (AI-300) · OffSec | Expert | 24-hour proctored practical red-team engagement | Pentesting, networking, Linux/Windows, scripting; OSCP or equivalent recommended | $1,749 (course + cert bundle, 90 days access, one attempt) |
| HTB COAE HTB Certified Offensive AI Expert · Hack The Box | Expert | 7-day practical assessment plus a commercial-grade report | Complete the AI Red Teamer job-role path (12 modules, built with Google, aligned to SAIF) | $490 Silver Annual subscription incl. voucher (two attempts) |
| GOAA GIAC Offensive AI Analyst · GIAC / SANS | Intermediate | CyberLive hands-on lab exam | None listed | ~$999 |
| C|OASP Certified Offensive AI Security Professional · EC-Council | Intermediate | Exam included in the course; format not published on the pages checked | None specified | $2,199 (course, labs and exam) |
| AIRTP+ AI Red Teaming Professional · Learn Prompting | Intermediate | Hands-on 24-hour online exam | Familiarity with LLMs, prompt injection and jailbreaking recommended | $299 exam only, $1,199 with course |
OffSec OSAI (AI-300) is the offensive-security heavyweight: a 24-hour practical red team engagement against an AI-enabled enterprise environment. It covers offensive testing of LLMs and multi-agent systems, RAG compromise, and AI supply chain and infrastructure attacks. OffSec recommends OSCP or equivalent experience. OSAI itself doesn’t expire; the OSAI+ designation lasts three years.
HTB COAE requires completing Hack The Box’s AI Red Teamer job-role path first (12 modules, rated Hard, developed with Google and aligned to its Secure AI Framework), then a seven-day assessment with a commercial-grade report. That’s a very different experience from a 24-hour sprint, and closer to how real engagements are scoped.
GIAC GOAA maps to SANS SEC535, Offensive AI: Attack Tools and Techniques, and is again a CyberLive lab exam.
EC-Council C|OASP has a ten-module curriculum that includes agentic AI and model-to-model attacks, OWASP LLM Top 10 and MITRE ATLAS. At $2,199 for the course, labs and exam it’s the priciest option here, and the pages we checked don’t publish the exam format, so ask before you buy.
Learn Prompting AIRTP+ is the low-cost entry: a 24-hour hands-on exam for $299 on its own. It comes from a training company rather than a long-standing certification body, so weigh the price against the unproven track record.
Governing and auditing AI
Most of these are knowledge exams, and several are gated by an existing certification, which matters when you add up what the route really costs.
| Credential | Level | Assessment | Prerequisites | Cost (USD) |
|---|---|---|---|---|
| TAISE Trusted AI Safety Expert · Cloud Security Alliance | Beginner | 60 multiple-choice questions, 120 min, 80% to pass | None required; basic AI, cloud and security familiarity recommended | $795 (training + exam, two attempts) |
| AAISM ISACA Advanced in AI Security Management · ISACA | Expert | Computer-based exam | Active CISM or CISSP | $459 member / $599 non-member + $50 application |
| AAIA ISACA Advanced in AI Audit · ISACA | Expert | Computer-based exam | CISA, or CIA / CPA / ACCA and similar with an IT audit focus | $459 member / $599 non-member + $50 application |
| AIGP Artificial Intelligence Governance Professional · IAPP | Intermediate | 100 questions, 2.75 hours with a 15-minute break | None listed | $649 member / $799 non-member |
| ISO 42001 LI ISO/IEC 42001 Lead Implementer · PECB | Intermediate | Exam on day 5 of a 5-day course | General knowledge of AI management systems and ISO/IEC 42001 | Exam included in the course fee |
| ISO 42001 LA ISO/IEC 42001 Lead Auditor · PECB | Intermediate | Course plus exam | See PECB requirements | Exam included in the course fee |
ISACA AAISM requires an active CISM or CISSP. Its three practice areas are AI governance and program management, AI risk management, and AI technologies and controls. AAIA, the audit sibling, requires CISA (or another audit or accounting designation with an IT audit focus). Both cost $459 for members or $599 for non-members, plus a $50 application fee after you pass.
IAPP AIGP is aimed at governance and privacy professionals: 100 questions over 2.75 hours, covering responsible AI principles, applicable laws and frameworks, and risk management across the AI lifecycle. It’s about governing AI, not securing it technically.
CSA TAISE is the only credential here with no formal prerequisites, which makes it the gentlest starting point, and it comes only as a training and exam bundle at $795 (60 multiple-choice questions, 80% to pass).
PECB ISO/IEC 42001 Lead Implementer and Lead Auditor are for people building or auditing an AI management system to the ISO standard. Both are five-day courses with the exam on the last day and fees included. PECB gates the level of credential by experience, from Provisional (none required) up to Senior Lead (ten years, seven in AI).
AI-assisted security
| Credential | Level | Assessment | Prerequisites | Cost (USD) |
|---|---|---|---|---|
| GASAE GIAC AI Security Automation Engineer · GIAC / SANS | Intermediate | CyberLive hands-on lab exam | None listed | ~$999 |
GIAC GASAE covers applying automation and AI across offensive, defensive and cloud security operations, mapped to SANS SEC598. It’s the only dedicated AI-assisted credential we found. The existing GMLE (GIAC Machine Learning Engineer, already on the original roadmap) covers applied machine learning for security and is the natural companion, and SecAI+ spends about a quarter of its exam here too.
What the data actually shows
Looking across all sixteen, a few patterns stand out.
- Offense is practical, governance is multiple choice. Every attacking-AI credential with a published format is hands-on: OSAI (24 hours), HTB COAE (seven days), AIRTP+ (24 hours) and GIAC’s CyberLive labs. The governance track is almost entirely knowledge exams. If you value being able to demonstrate skill, that’s a genuine difference.
- The price range is wide, and the sticker price isn’t the cost. Exams run from $299 (AIRTP+ exam only) to $2,199 (C|OASP bundle). But AAISM and AAIA require you to already hold CISSP, CISM or CISA, and HTB COAE requires finishing a full learning path. Budget for the whole route.
- Almost nothing is entry-level. Only TAISE has no prerequisites. SecAI+, OSAI, AAISM and others all assume a security background. Newcomers should build foundations first (the roadmap’s beginner tier is the right place to start) and treat AI security as a specialisation.
- Everything is young. Most of these launched within the last year or so; a few, such as IAPP’s AIGP and the ISO/IEC 42001 credentials, have been around a little longer. Syllabi are moving fast, especially around agents and tool use, so check that the one you’re considering actually covers what you’ll defend or attack: OffSec’s and EC-Council’s material explicitly includes agentic or multi-agent systems.
- Hiring signal is unproven. We found no reliable evidence yet on how employers weigh these credentials. Salary figures quoted by training vendors are marketing, not data. Treat these as validation of skills, and check job postings for the roles you want before spending money.
Choosing by role
- Penetration tester or red teamer: OSCP or equivalent, then OSAI or HTB COAE. AIRTP+ is a cheap way to test whether you enjoy the work first.
- Application security or ML engineer: CAISP or GAIPS.
- SOC and detection engineer: SecAI+ for breadth, then GASAE.
- Azure security engineer: SC-500.
- CISO, security manager or GRC lead: CISM or CISSP, then AAISM. Add AIGP if you’re also responsible for privacy and regulation.
- Auditor: CISA, then AAIA, or ISO/IEC 42001 Lead Auditor if you audit against the standard.
- Just starting out: Security+ (or similar) first. TAISE is a low-friction way to learn the vocabulary.
You can learn most of this for free first
The credentials above keep pointing at the same handful of public frameworks. They’re free, they’re what the syllabi are built from, and reading them first will tell you whether a paid course is worth it:
- OWASP Top 10 for LLM Applications
- MITRE ATLAS, the adversarial threat landscape for AI systems
- NIST AI Risk Management Framework
- Google’s Secure AI Framework (SAIF)
Method and caveats
Costs, formats and prerequisites were checked against vendor pages on 21 September 2026. A few figures, including CompTIA’s SecAI+ price, GIAC’s exam prices and HTB’s subscription price, came from third-party sites rather than the vendor’s own page and could be off. Things I could not verify: the exam format for C|OASP, the exact question count for ISACA’s exams, and the launch date for OffSec’s OSAI beyond “spring 2026”. Prices and requirements change, so confirm on the vendor page before you buy.
Levels, tracks and domain placements are my own editorial judgement, not the issuers’. The credentials were found through searches and vendor pages, so the list may be missing newer or smaller offerings. If you know of one, or spot something out of date, get in touch.
Roadmap credit: Paul Jerimy’s Security Certification Roadmap.