All vendors

Vendor lineage

EC-Council

The most required certification in its field, and the most argued about, which are the same fact seen twice.

The International Council of E-Commerce Consultants was founded in 2001, in response to the September 11 attacks and the question of whether the security community was equipped for an equivalent attack on commercial infrastructure. It launched the Certified Ethical Hacker in 2003, and CEH became the most widely required security certification in the world - and the most persistently criticised. Those two facts are connected.

**Start with the criticism that does not depend on anybody's opinion, because EC-Council published it themselves.** The Certified Network Defence Architect was marketed as a defensive credential. EC-Council's own frequently-asked-questions page stated that apart from the title, the content of the exam was the same as CEH. **One examination, two names, sold to two audiences as different qualifications.** Whatever one concludes about the rest, that is documented in the organisation's own words and is difficult to defend.

The wider criticism is long-running and easily found: the security researchers at attrition.org maintain a page arguing the case, allegations of comment-spam marketing that the organisation's president dismissed as a fictional theory, published advice in 2015 that women should wear a trouser suit with heels to be credible on a penetration test, and website security incidents at an organisation selling website security. **A site that records the criticism of CompTIA, of web filtering and of practical exams should record this too, and does.**

**And the accreditation is real, which is the other half of an honest account.** EC-Council holds ISO/IEC 17024 accreditation for personnel certification bodies, and CEH is recognised under United States Department of Defense Directive 8140 - previously 8570 - which means it satisfies a mandatory requirement for certain defence roles. That recognition is not marketing. **It is why the certification appears in job requirements written by people who have never heard the criticism.**

**Here is the structural explanation, and it is the reason this entry exists rather than a verdict.** A certification that becomes mandatory acquires enormous volume, because people take it who would not otherwise have chosen it. Volume produces variance: among hundreds of thousands of holders there will be excellent practitioners and people who memorised a question bank, and both hold the same credential. Variance produces the anecdote - everybody in this industry has met a certificate holder who could not do the thing - and the anecdote travels much further than the median. **Being required is what makes a certification valuable and what degrades what holding it signals, and there is no version of mandating a credential that avoids this.**

**Which lands exactly where the rest of this cluster does.** Standardised exams are scalable and memorisable. Practical exams are unfakeable and leakable. Mandated exams are universally recognised and universally diluted. **Every mechanism that makes a credential useful attacks the thing that made it worth having**, and the honest position for anyone hiring is that no certification is evidence of capability - it is evidence that somebody passed a specific test on a specific day, which is a smaller and more useful claim.

EQT Private Equity invested in September 2021. **That is the second EQT holding on this timeline**, after Prometric - a reminder that the certification industry's ownership is concentrated in a smaller number of hands than its variety of brands suggests. Reported certification totals vary widely between EC-Council's own materials and its press releases, from fifty thousand to over four hundred thousand, and this entry asserts neither.

Sources