← All certifications

Global Industrial Cyber Security Professional (GICSP)

GIAC

Validates the knowledge to secure industrial control systems (ICS), bridging IT, engineering, and cybersecurity to protect ICS/SCADA environments.

We have a course for this

Built from this exam's published objectives. The first module is free.

Baseline certification levels

This certification satisfies these DoD baseline levels — the IAT / IAM / IASAE / CSSP requirement many contracts still state. It's a separate question from the 8140 work roles above, and there is no official mapping between the two.

What this qualifies you for

Listed specifically for 11 work roles — up to Advanced proficiency. Because options cascade downward, a cert listed at Advanced also satisfies Intermediate and Basic for that role.

411Technical Support SpecialistProvides technical support to customers who need assistance utilizing client level hardware and software in accordance with established or approved organizational process components. (i.e., Master Incident Management Plan, when applicable).Advanced441Network Operations (NETOPS) SpecialistPlans, implements, and operates network services/systems, to include hardware and virtual environments.Intermediate451System Administrator (SYSADMIN)Installs, configures, troubleshoots, and maintains hardware, software, and administers system accounts.Intermediate511Cyber Defense AnalystUses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs.) to analyze events that occur within their environments for the purposes of mitigating threats.Advanced521Cyber Defense Infrastructure Support SpecialistTests, implements, deploys, maintains, and administers the infrastructure hardware and software.Advanced531Cyber Defense Incident ResponderInvestigates, analyzes, and responds to cyber incidents within the network environment or enclave.Advanced541Vulnerability Assessment AnalystPerforms assessments of systems and networks within the NE or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. Measures effectiveness of defense-in-depth architecture against known vulnerabilities.Intermediate651Enterprise ArchitectDevelops and maintains business, systems, and information processes to support enterprise mission needs; develops information technology (IT) rules and requirements that describe baseline and target architectures.Advanced652Security ArchitectDesigns enterprise and systems security throughout the development lifecycle; translates technology and environmental conditions (e.g., law and regulation) into security designs and processes.Advanced722Information Systems Security Manager (ISSM)Responsible for the cybersecurity of a program, organization, system, or enclave.Advanced723Communications Security (COMSEC) ManagerManages the Communications Security (COMSEC) resources of an organization (CNSSI No. 4009).Advanced
Also listed for 14 Cyberspace Enablers roles — but so is every other certification

The Enablers matrix isn’t role-differentiated: the same certification options are listed for all 14 roles at every proficiency level. We verified that across all 14. So this is true, and it carries no information about this credential specifically — which is why it isn’t in the count above.

Renewal

4year cycle36CPE per cycle

Certification renewal, USD 499

This is the issuer’s clock. 8140 runs a second one — 20 hours of CPD a year, at every proficiency level, which applies even if you hold no certification at all. How that works

GIAC publishes objective areas without percentage weights; all domain weights are 0 by design. GICSP is a CyberLive (hands-on) certification per GIAC's CyberLive list.

Source: GIAC - GICSP certification page · dated 2026-07-17 · checked 2026-07-17

Verifying it

GIAC publishes a lookup a third party can use without your involvement.

Name or GIAC number

GIAC publishes objective areas without percentage weights; all domain weights are 0 by design. GICSP is a CyberLive (hands-on) certification per GIAC's CyberLive list.

Source: GIAC - GICSP certification page · dated 2026-07-17 · checked 2026-07-17

Exam blueprint

Verified against GIAC’s published outline.

GICSP

Current

82 questions · 3 hours · passing score 71%

Hardening & Protecting Endpoints
ICS Components & Architecture
ICS Overview & Concepts
ICS Program & Policy Development
Intelligence Gathering & Threat Modeling
PERA Level 0 & 1 Technology Overview and Compromise
PERA Level 2 & 3 Technology Overview and Compromise
Protocols, Communications, & Compromises
Risk Based Disaster Recovery & Incident Response
Wireless Technologies & Compromises

GIAC publishes objective areas without percentage weightings, so none are shown.

GIAC publishes objective areas without percentage weights; all domain weights are 0 by design. GICSP is a CyberLive (hands-on) certification per GIAC's CyberLive list.

Source: GIAC - GICSP certification page · dated 2026-07-17 · checked 2026-07-17