Are certifications required for cybersecurity analysts? Under ECC – 2 : 2024 control 1-10-4, organizations must make essential, job-tailored cybersecurity training and access to relevant professional skillsets available to personnel performing cybersecurity work. The control does not name one mandatory external certification for every analyst, but it expects approved training plans, completed training, and training certificates or equivalent completion evidence for applicable personnel.
What does ECC 1-10-4 officially require?
The stated requirement for ECC – 2 : 2024 practice 1-10-4 is:
“Essential and customized (i.e., tailored to job functions as it relates to cybersecurity) training and access to professional skillsets must be made available to personnel working directly on tasks related to cybersecurity including:”
For a compliance officer, the important point is that this is a workforce capability control, not merely an awareness-training requirement. It requires the organization to identify cybersecurity-related roles, determine the competencies each role needs, provide relevant development opportunities, and retain evidence that the program has been approved and delivered.
- “Essential” means the training must cover the capabilities employees genuinely need to perform their assigned duties safely and effectively. A generic annual security-awareness module alone will not demonstrate competence for a SOC analyst, cloud administrator, or application developer.
- “Customized” means training must be tailored to job functions. Incident responders need investigation and containment skills; developers need secure coding instruction; executives need decision-making, risk, and targeted-phishing awareness.
- “Training and access to professional skillsets” means the organization should provide more than a policy document. It can include instructor-led courses, recognized industry training, labs, mentoring, subscriptions, internal workshops, professional communities, and access to qualified specialists.
- “Must be made available” means management must provide the opportunity, budget, time, and approval path for relevant personnel to complete the training. A training catalogue that employees cannot access because of budget or workload constraints is weak evidence.
- “Personnel working directly on tasks related to cybersecurity” includes the cybersecurity function and, under the related requirements, personnel who develop applications, operate technology assets, or hold supervisory and executive responsibilities.
The control’s expected deliverables reinforce this interpretation: an approved document identifying the control requirements, approved training plans or programs, and cybersecurity training certificates. Certificates are therefore important evidence of completion, but the ECC does not prescribe a universal certification name such as CISSP, Security+, CISM, or CEH.
Are certifications required for cybersecurity analysts under ECC 1-10-4?
Cybersecurity analysts should receive role-relevant training, and the organization should retain certificates where the selected course or program issues them. However, compliance does not depend on forcing every analyst to hold the same professional credential. The defensible approach is to document why a selected course, certification, lab, or internal program fits the analyst’s duties and to retain objective evidence that the person completed it.
For example, a junior analyst monitoring Microsoft Sentinel alerts may need training in SIEM query development, alert triage, phishing investigation, and incident escalation. A senior analyst leading investigations may instead need digital forensics, threat hunting, incident coordination, and cloud-log analysis. Requiring both employees to earn the same credential without regard to their duties would not demonstrate the customization that 1-10-4 expects.
A professional certification can be strong evidence, particularly where it is relevant to the role and includes assessment. It is not the only acceptable evidence. An assessor may also accept vendor training certificates, course completion records, practical lab assessments, internal training attendance records, and competency sign-off by a qualified manager, provided the evidence maps clearly to documented job requirements.
Who does ECC 1-10-4 apply to, and when is it triggered?
The control applies whenever personnel perform work that can affect the organization’s cybersecurity posture. It is not limited to staff whose job titles contain “cybersecurity” or “information security.” The training population should be determined through roles, responsibilities, system access, and assigned activities.
| Population under 1-10-4 | Typical roles | Training focus | Relevant evidence |
|---|---|---|---|
| Cybersecurity function personnel | SOC analysts, security engineers, GRC specialists, incident responders | Monitoring, response, risk, vulnerability management, security tooling | Approved annual plan, certificates, lab or assessment results |
| Development and IT operations personnel | Developers, DevOps engineers, system administrators, cloud administrators | Secure development, code review, patching, privileged access, safe asset operations | Secure coding certificates, LMS records, workshop attendance, role matrix |
| Executive and supervisory positions | CIO, IT manager, security manager, business-unit leaders | Cybersecurity risk, governance, crisis decisions, whale phishing, resource oversight | Executive training program, attendance records, completion certificates |
The requirement is triggered at onboarding into a covered role, when responsibilities change, when a new technology or threat materially changes required skills, and when the annual training plan is refreshed. A transfer from infrastructure operations to cloud operations, for example, should prompt a review of training needs rather than relying solely on the employee’s prior completion record.
What does compliant evidence look like in practice?
An assessor will normally look for a coherent chain from requirement to approval, delivery, completion, and review. The following examples show evidence that would be credible in practice.
- Approved cybersecurity capability plan. A 120-person managed service provider maintains a “Cybersecurity Training and Professional Skills Procedure” approved by its CEO. The procedure maps SOC analysts, network administrators, cloud engineers, and service-delivery managers to required competencies. Its annual plan identifies Microsoft Sentinel investigation training for analysts, Fortinet NSE training for network staff, and phishing-risk training for managers.
- Role-based analyst records. The MSP’s four-person SOC team has individual learning records in Microsoft SharePoint. Each record links the employee’s job description to courses completed, including Microsoft SC-200 training, KQL workshops, phishing-analysis labs, and incident-response tabletop exercises. Certificates and completion reports are attached, with expiry or refresh dates where applicable.
- Secure development training for relevant staff. A Riyadh-based GRC consultancy with 75 employees develops a client evidence-management portal. Its eight developers complete secure application development training covering OWASP Top 10, authentication controls, secrets management, and secure code review. The organization retains course certificates, GitHub pull-request review samples, and a manager sign-off confirming that developers applied the training in the development workflow.
- Training for technology asset operators. The same consultancy operates Microsoft 365, Azure, Intune, and a managed firewall environment. The IT operations lead maintains a plan showing administrator training on privileged identity management, conditional access, backup restoration, patch management, and secure configuration baselines. Evidence includes Microsoft Learn completion transcripts, internal configuration workshops, and attendance records for quarterly recovery tests.
- Executive and supervisory training. Senior managers attend an annual two-hour program on cybersecurity risk, incident escalation, regulatory obligations, supplier risk, and whale-phishing scenarios. The organization retains the approved agenda, attendee list, quiz results, and certificates. This demonstrates compliance with 1-10-4-3 without pretending that executives need the same technical curriculum as analysts.
In each example, the evidence is stronger because it shows coordination with the training or employee development function, management approval, adequate funding, and a repeatable process. A collection of unrelated certificates without a role mapping or approved plan is less persuasive because it does not prove that training was essential and customized.
How should a compliance officer document training requirements?
Document the requirement in the cybersecurity requirements document, policy, or procedure and obtain approval from the organization’s representative. The document should identify covered populations; define role-specific competencies; assign accountability to cybersecurity, HR or training, and line managers; establish frequency and trigger events; define acceptable completion evidence; and state how records will be reviewed.
A practical record can link each person to a role, required subject, delivery method, target date, completion status, evidence location, and renewal date. For instance, an entry may state: SOC Analyst | Sentinel incident investigation | Microsoft SC-200 course and internal lab | annual | certificate and lab score stored in SharePoint/Training/SOC/2026. This level of detail makes sampling straightforward during an ECC assessment.
FAQ
Do cybersecurity analysts need CISSP certification for ECC compliance?
No. ECC 1-10-4 does not mandate CISSP or any other named certification. Select training and credentials based on the analyst’s duties, skill level, and technologies, then retain evidence of completion.
What certificates should we keep for ECC 1-10-4?
Keep certificates issued by external courses, vendors, professional bodies, or internal training programs where available. Also retain approved plans, attendance records, assessment results, course content, and role-to-training mappings.
Does ECC 1-10-4 apply to developers and system administrators?
Yes. Requirement 1-10-4-2 specifically addresses personnel working on software and application development and employees operating information and technology assets. Their training should address secure development or safe asset management as relevant.
How often should cybersecurity training be renewed?
ECC 1-10-4 does not set one fixed renewal period. Set a documented frequency based on role, technology changes, threats, certification validity, and organizational risk; annual review is a practical baseline for most covered roles.
Next step: Ask your cybersecurity and training owners to produce a role-based training matrix and sample completion evidence for each 1-10-4 population before your next ECC readiness review.