Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 442

GIAC Certifications

What is GIAC Certifications?

GIAC CertificationsA family of role-based cybersecurity certifications issued by GIAC and aligned with SANS Institute training, covering operations, incident response, forensics, and penetration testing.


Global Information Assurance Certification (GIAC) is the certifying body affiliated with the SANS Institute and offers more than 40 role-specific certifications across defense, offense, management, cloud, ICS, and forensics. Popular entries include GSEC for security essentials, GCIH for incident handling, GPEN for penetration testing, GREM for reverse engineering malware, and GCFA for forensic analysis. Exams are proctored, open-book, and typically include 75 to 115 questions over three to four hours with passing scores between 67 and 73 percent. Candidates usually attend a corresponding SANS course; certifications must be renewed every four years through 36 Continuing Professional Experience credits.

Examples

  1. 01

    An incident responder earns GCIH after the SANS SEC504 course to lead enterprise IR engagements.

  2. 02

    A digital forensics examiner combines GCFA and GREM to investigate ransomware intrusions.

Frequently asked questions

What is GIAC Certifications?

A family of role-based cybersecurity certifications issued by GIAC and aligned with SANS Institute training, covering operations, incident response, forensics, and penetration testing. It belongs to the Compliance & Frameworks category of cybersecurity.

What does GIAC Certifications mean?

A family of role-based cybersecurity certifications issued by GIAC and aligned with SANS Institute training, covering operations, incident response, forensics, and penetration testing.

How does GIAC Certifications work?

Global Information Assurance Certification (GIAC) is the certifying body affiliated with the SANS Institute and offers more than 40 role-specific certifications across defense, offense, management, cloud, ICS, and forensics. Popular entries include GSEC for security essentials, GCIH for incident handling, GPEN for penetration testing, GREM for reverse engineering malware, and GCFA for forensic analysis. Exams are proctored, open-book, and typically include 75 to 115 questions over three to four hours with passing scores between 67 and 73 percent. Candidates usually attend a corresponding SANS course; certifications must be renewed every four years through 36 Continuing Professional Experience credits.

How do you defend against GIAC Certifications?

Defences for GIAC Certifications typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for GIAC Certifications?

Common alternative names include: Global Information Assurance Certification, SANS GIAC.

Related terms

See also