Home › AI Governance Insights › Which GRC Certification Should I Get? Take the Five Question Assessment
Which GRC Certification Should I Get? Take the Five Question Assessment
By F. Jay Hall, Founder and Chief Executive Officer, GRC Careers · September 10, 2026 · 4 min read
A woman wrote to me this week and asked a question I get more than any other. She wants into this field. She does not know which certification to start with, and every list she has found reads like a catalogue instead of an answer.
I knew exactly what to send her. We built a tool for this. Five questions, a ranked shortlist, about a minute of your time.
Then I went to find the link and I could not find it.
It was on a different site than I remembered, a third of the way down a long page, under a heading you would only spot if you already knew it was there. I built the thing and I had to hunt for it. She never would have found it at all.
So it has moved, and this is where it lives now: which GRC certification is right for you. Top of its own page. One link you can send to somebody.
Why a quiz instead of a list
Every certification roundup on the internet gives the same twelve credentials to every reader. That is not advice. That is inventory.
The honest answer to which certification should I get is that it depends, and it depends on four things nobody bothers to ask you about.
It depends on where you are coming from. If you have spent nine years in IT, the CISA and the CISSP are sitting right there waiting for you. If you are coming from paralegal work, they are the wrong door entirely and the CIPP is the right one.
It depends on your sector. Healthcare compliance runs on its own regulations and its own vocabulary, and hiring managers in hospitals screen for the CHC in a way that no general compliance credential will satisfy. If you are not in healthcare, that credential is close to irrelevant to you.
It depends on how far along you are. The CISSP wants five years. Telling a career changer to go get one is not encouragement, it is a five year delay dressed up as guidance. The AIGP and the GRCP ask for no formal experience at all, which is exactly why they are the two most useful credentials for somebody standing outside the field looking in.
And it depends on what you actually want. Getting hired for the first time and getting promoted are different problems, and they do not have the same answer.
The assessment weighs all four. Your background and your chosen discipline carry the most weight. Your sector adds the credentials that only matter inside it. Your experience level takes away anything you are not yet eligible for, because there is no kindness in recommending an exam somebody cannot sit.
What you get
Four credentials, ranked, best fit first. For each one you get what it is actually called, what the salary data says, a sentence on why it fits you specifically rather than why it is generally good, and a link to the body that issues it.
You can see all of it without giving us anything. There is a field for your email and there is a button next to it that says skip. Use whichever one you want. I mean that, and I built the page so it works that way rather than saying so and then holding your results hostage.
One thing I got wrong, and I will say it plainly
The earlier version of this tool asked for a name and an email before it showed results. It promised no spam and easy unsubscribe.
It then threw every one of those addresses away. The code wrote them to the browser console and did nothing else. No list, no database, no email, nothing. Every person who trusted that form got their results and vanished, and I did not know until I went looking this week.
That is fixed. Leads are stored and they reach a human now. But if you took that assessment at some point over the last stretch and wondered why you never heard from us, that is why, and I am sorry. Come take it again. It works.
Who this is for
I built this for the person who is standing at the edge of GRC and cannot tell whether there is a door. There is. There are several, and which one opens for you depends on what you already carry.
It is also for the person already inside who has hit a ceiling and suspects a credential is the thing between them and the next level. Sometimes it is. Sometimes it is not, and the results will tell you that too.
Take it here: which GRC certification is right for you. Then, when you know what you are aiming at, we have practice exams and study companions for most of them, and the live roles so you can see what the credential actually buys.
Five questions. One minute. Send it to whoever asked you the same question I got asked this week.
Frequently Asked Questions
Which GRC certification should I get first?
It depends on your starting point, which is why a single recommended list is close to useless. Someone entering from outside the field usually gets further with the AIGP or the GRCP, because neither requires prior experience. Someone already auditing systems is better served by the CISA. The assessment ranks all twelve against your own background rather than giving everyone the same answer.
Do I have to give my email to see the results?
No. There is a skip button next to the email field and it works. You see the full ranked roadmap either way. The email is only there if you want the roadmap sent to you along with the study companions for each credential.
How long does the assessment take?
About a minute. Five questions, five options each, and you can go back and change an answer before you finish.
Is the AIGP worth getting?
It is the first credential built specifically for AI governance work, covering the EU AI Act, the NIST AI Risk Management Framework and AI program design. It requires no formal experience, which makes it unusually accessible, and AI governance roles have grown faster than any other category on this job board.
Can I get a GRC job with no certification at all?
Yes, and plenty of people do. A certification mainly helps you get past screening when you are changing fields, and gives a hiring manager shorthand for what you know. It matters most early and matters less once you have a track record.
Which GRC certification pays the most?
The CISSP and the CISM sit highest in published salary surveys, largely because they gate senior security leadership roles rather than because the exam itself is worth more. A credential pays when it unlocks a level you could not otherwise reach.
What is the difference between the CISA and the CIA?
The CISA is an information systems audit credential aimed at technology controls. The CIA is the general internal audit credential aimed at business processes and financial reporting. People who audit systems take the CISA. People who audit the business take the CIA.
I took this assessment before and never heard back. Why?
Because the earlier version of the tool discarded every email it collected. The code logged them to the browser console and stored nothing. That is fixed and leads now reach a person, but nothing from before was recoverable. Please take it again.
Who's Hiring AI Governance Professionals?
Explore current openings in:
AI Governance · Responsible AI · AI Risk · AI Compliance · AI Audit · AI Policy · Privacy · Cybersecurity · Public Policy
Search the latest opportunities at GRC Careers › · nonprofit GRC jobs ›