Vendor lineage
EC-Council
The most required certification in its field, and the most argued about, which are the same fact seen twice.
The International Council of E-Commerce Consultants was founded in 2001, in response to the September 11 attacks and the question of whether the security community was equipped for an equivalent attack on commercial infrastructure. It launched the Certified Ethical Hacker in 2003, and CEH became the most widely required security certification in the world - and the most persistently criticised. Those two facts are connected.
**Start with the criticism that does not depend on anybody's opinion, because EC-Council published it themselves.** The Certified Network Defence Architect was marketed as a defensive credential. EC-Council's own frequently-asked-questions page stated that apart from the title, the content of the exam was the same as CEH. **One examination, two names, sold to two audiences as different qualifications.** Whatever one concludes about the rest, that is documented in the organisation's own words and is difficult to defend.
The wider criticism is long-running and easily found: the security researchers at attrition.org maintain a page arguing the case, allegations of comment-spam marketing that the organisation's president dismissed as a fictional theory, published advice in 2015 that women should wear a trouser suit with heels to be credible on a penetration test, and website security incidents at an organisation selling website security. **A site that records the criticism of CompTIA, of web filtering and of practical exams should record this too, and does.**
**And the accreditation is real, which is the other half of an honest account.** EC-Council holds ISO/IEC 17024 accreditation for personnel certification bodies, and CEH is recognised under United States Department of Defense Directive 8140 - previously 8570 - which means it satisfies a mandatory requirement for certain defence roles. That recognition is not marketing. **It is why the certification appears in job requirements written by people who have never heard the criticism.**
**Here is the structural explanation, and it is the reason this entry exists rather than a verdict.** A certification that becomes mandatory acquires enormous volume, because people take it who would not otherwise have chosen it. Volume produces variance: among hundreds of thousands of holders there will be excellent practitioners and people who memorised a question bank, and both hold the same credential. Variance produces the anecdote - everybody in this industry has met a certificate holder who could not do the thing - and the anecdote travels much further than the median. **Being required is what makes a certification valuable and what degrades what holding it signals, and there is no version of mandating a credential that avoids this.**
**Which lands exactly where the rest of this cluster does.** Standardised exams are scalable and memorisable. Practical exams are unfakeable and leakable. Mandated exams are universally recognised and universally diluted. **Every mechanism that makes a credential useful attacks the thing that made it worth having**, and the honest position for anyone hiring is that no certification is evidence of capability - it is evidence that somebody passed a specific test on a specific day, which is a smaller and more useful claim.
EQT Private Equity invested in September 2021. **That is the second EQT holding on this timeline**, after Prometric - a reminder that the certification industry's ownership is concentrated in a smaller number of hands than its variety of brands suggests. Reported certification totals vary widely between EC-Council's own materials and its press releases, from fifty thousand to over four hundred thousand, and this entry asserts neither.
- Wikipedia and HandWiki: founded 2001 as the International Council of E-Commerce Consultants in response to the September 11 attacks; CEH launched 2003; EQT Private Equity investing September 2021; the recorded criticisms including comment-spam allegations dismissed by the president as a fictional theory and the 2015 published advice about women's dress on penetration tests
- attrition.org: the long-running criticism page, including EC-Council's own FAQ stating that apart from the title, the CNDA exam content is the same as the CEH exam
An openly critical source maintained by security researchers, and it says so. Cited here for the CNDA/CEH identical-exam point specifically, which rests on EC-Council's own published FAQ rather than on the site's opinion - and that is why this entry leads with that point rather than the rest.
- EC-Council press materials: ISO/IEC 17024 accreditation, recognition under US Department of Defense Directive 8140/8570, operation across 145 to 170 countries, and certification totals that differ between documents
Company press release. Used for the accreditation facts, which are verifiable independently; its certification counts conflict with the company's own About page (50,000 versus over 400,000) and neither figure is asserted here.
- EC-Council's own About page: the founding account following the 9/11 attacks and the question posed by Jay Bavisi
- Secondary accounts differing on the founding: Haja Mohideen credited as creator of the CEH, CHFI and ECSA/LPT programmes, and one account stating Bavisi bought the company in 2015
A user-editable wiki whose account of the founding conflicts with EC-Council's own and with Wikipedia. Recorded because the discrepancy exists, not because it is resolved.