Cybersecurity certifications can help employers screen for defined knowledge, but a credential alone does not establish that someone can perform a particular job. The often-cited finding that 49% of IT leaders rarely or never verified employees’ certifications comes from a 2016 survey—not a current estimate of employer behavior. Verification and job-relevant skills assessment address different questions, so a sound hiring process uses both.
What the 2016 survey found—and what it did not
A TEKsystems survey reported by Dark Reading in 2016 polled more than 300 IT leaders and 900 IT managers. In that survey:
- 49% of IT leaders said they rarely or never verified employees’ certifications; 26% said they always or often did.
- 52% of surveyed IT professionals said they always or often accurately presented certifications on resumes. The report also said some respondents embellished or self-certified.
- 45% named cybersecurity certifications as the most valuable technology-certification area in the survey, compared with 22% for programming and development. That is a respondent opinion, not an objective ranking of credentials.
These figures describe that survey’s respondents in 2016. They do not establish how often employers verify claims today or represent all employers. The survey report’s Jason Hayman, then a TEKsystems market research manager, observed that employers may face friction in a fast hiring process: “The employer has to move quickly, and taking the steps back to verify will slow the process.”
What newer studies say about certification value and hiring
Later studies provide evidence that credentials remain valued by people in cybersecurity and considered by hiring managers, but neither updates the 2016 verification rate.
#1 Best Overall
| Study | Finding | How to interpret it |
|---|---|---|
| ISC2 Value of Cybersecurity Certifications survey, 2026 | 1,533 cybersecurity professionals in Canada, Germany, India, Japan, the U.K. and the U.S. responded between December 2025 and January 2026; participants held at least one vendor-neutral certification. 67% rated vendor-neutral certifications very impactful, 65% did so for vendor-specific certifications, and 71% held both types. | These are credential-holder views, not employer verification rates or proof that a certification caused a career outcome. See ISC2’s survey report. |
| ISC2 early-career hiring study, 2025 | 929 hiring managers in Canada, Germany, India, Japan, the U.K. and the U.S. participated. They had entry- and junior-level cybersecurity personnel and had recruited for such roles in the prior two years. 90% would consider a candidate with only previous IT work experience, and 89% would consider one with only an entry-level cybersecurity certification. 84% said their organization used skills-based assessments and/or tests for entry- and junior-level applicants. | These are stated willingness and reported practices, not hiring outcomes. See ISC2’s hiring study. |
What a certification establishes—and what it cannot establish
A certification attests to meeting the issuer’s requirements for that credential. Requirements differ: a credential may be designed for people entering the field, while another may require documented professional experience. Issuers may also set renewal and continuing-education requirements. Check the specific issuer and credential rather than assuming that every certification has the same scope or maintenance rules.
For example, ISC2 describes its Certified in Cybersecurity (CC) credential as intended for people entering cybersecurity, while it describes advanced certifications as experience-based. ISC2 also describes a three-year renewal cycle with continuing professional education requirements for its certifications. Those are ISC2’s own requirements and do not apply universally to other issuers.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
A credential can be evidence of knowledge or of meeting a defined standard; it is not a guarantee of practical performance in every role. Hayman put the distinction simply: “A certification might prove knowledge, but it doesn’t necessarily prove competency.” ISACA likewise advises treating certification as one part of a broader evaluation, not as proof that a candidate can carry out every duty in a specific job. See ISACA’s discussion of certification’s value.
How employers can verify credentials and assess role fit
Verification checks whether a claimed credential is genuine and current. Assessment checks whether a candidate can apply relevant skills. Neither replaces the other.
Recommended Free Tools
Rank #3
- Specify the credential. Record the issuer and exact credential name rather than asking for a vague “cybersecurity certification.”
- Check the issuer’s process. Find out whether the issuer offers a way to confirm the credential and its current status. Procedures vary, so there is no single verification method established for every issuer or credential.
- Record the result consistently. Apply the same process to candidates for the same role and document what was checked.
- Test the work that matters. Use a role-relevant skills assessment, work sample, structured interview or reference check to evaluate capabilities the job actually requires. ISC2’s 2025 study found that 84% of surveyed organizations used skills-based assessments and/or tests for entry- and junior-level applicants.
This approach treats credentials as one useful signal while separately examining experience and applied ability. The evidence cited here does not establish that unverified certifications cause a particular share of security incidents.
Match credential requirements to the role and career stage
Job descriptions can set unrealistic barriers when they require an experienced credential for an entry-level position. In ISC2’s 2025 hiring study, 38% of surveyed hiring managers said they required CISA for entry-level positions, although the study notes that CISA requires at least five years of relevant experience. Roughly one-third said they required CISSP for entry- or junior-level roles, although CISSP requires five years of cumulative paid cybersecurity experience. These are reported hiring requirements, not recommended standards.
Rank #4
Before making a credential a must-have, compare its eligibility rules with the experience level of the job. Distinguish a genuine requirement from a preference, and consider whether relevant work experience or an entry-level credential could meet the role’s needs. The same principle helps candidates interpret listings: a credential’s value depends on whether its level, subject matter and requirements fit the work and employer.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to compare certifications without assuming a universal ranking
The cited surveys do not rank credentials universally. When comparing options, examine the credential on the criteria that affect its usefulness for a specific role:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
- Intended role and seniority: Is it aimed at newcomers, practitioners in a specialty or experienced professionals?
- Eligibility: Does the issuer require work experience, education or other prerequisites?
- Assessment: What examination or other assessment does the issuer document?
- Maintenance: Does the credential expire or require renewal, continuing education or another status check?
- Recognition: Is it relevant to the employer’s sector and geography?
- Job alignment: Does its scope match the work the person will actually do?
A survey finding that respondents value a credential area does not show that every certification in that area is equally useful, or that holding one predicts success in a particular role.
What the evidence can support
The historical 2016 survey supports a dated finding about verification practices among its respondents. ISC2’s newer studies support the narrower conclusions that surveyed credential holders report perceived value and that surveyed hiring managers consider both experience and entry-level certification while many use skills assessments. Because these studies ask different questions of different samples, the newer results cannot be used to calculate a current employer verification rate or a causal return on certification.
A 2024 NIST-hosted commentary described credentials as “the currency for employment – and advancement in one’s career,” but that passage is the author’s commentary, not an institutional NIST finding. It offers context for the perceived importance of credentials, not a measurement of verification practices. See the NIST commentary.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →




