AI Security Certifications Aren't Replacing CISM and CISSP. They're Stacking on Top.
August 31, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Security leaders don't need another certification for its own sake. They need to know which credential changes what their team can do, and whether the market pays for it. The honest answer: AI security certification isn't replacing your core credentials, it's stacking on top of them, which changes how you sequence training spend.
Is Demand for AI Security Skills Actually Showing Up in Budgets?
Yes, and it's showing up in two places at once: overall security spend and the shape of new credentials. Gartner projects worldwide end-user spending on information security will reach $213 billion in 2025, up from $193 billion in 2024, with the expanding use of AI by both defenders and attackers named as a key growth driver, and a further 12.5% increase forecast for 2026. That spending has to land somewhere, and certification bodies are moving fast to give it a place to land.
ISACA's new Advanced in AI Security Management (AAISM) credential is a useful signal of where the money is going. The organization built AAISM after research covered by Computer Weekly found that a majority of security professionals were highly concerned about generative AI being exploited by attackers, while also identifying a lack of concrete action on the resulting risks around misinformation, privacy, and social engineering. That's the gap budget owners are now trying to close: not general AI awareness, but people who can govern how AI actually gets used inside the business, day to day.
CompTIA read the same signal differently and moved toward practitioners rather than executives. Its new SecAI+ credential, which launched in February 2026 under exam code CY0-001, is built for security professionals who already have hands-on experience and now need to understand how AI changes their daily workflows and responsibilities. It sits as a complement to an existing security foundation such as Security+, CySA+, or PenTest+, not a replacement for any of them. Two vendors, two different bets on who needs to be certified first, and both bets assume the buyer already has a base credential in place before AI-specific training even makes sense.
Which Certification Should You Fund First: Foundation or Add-On?
Fund the foundation first, because the advanced AI credentials are built to require it. AAISM is not open to anyone with an interest in AI governance. ISACA requires that candidates already hold an active CISM or CISSP certification before they can even register to sit the exam. That is a deliberate design choice, not an accident of exam logistics.
It tells you the credential assumes a working knowledge of security governance, risk, and program management, and layers AI-specific judgment on top of it rather than teaching it from zero. If you're deciding where training dollars go this year, that prerequisite structure answers the sequencing question for you: a manager or analyst without a governance credential gets more immediate value from building that base, through a program like the CISM Certification Prep course, than from chasing an AI add-on they aren't yet eligible to sit for.
The same logic holds on the practitioner side. SecAI+ recommends three to four years of general IT experience and at least two years of hands-on security work before candidates attempt it. Nobody is meant to start their certification path with an AI security credential. It's the second purchase, not the first, and treating it otherwise wastes both training budget and the candidate's time waiting out an eligibility window they haven't earned yet.
| Path | Typical prerequisite | Who it's built for |
|---|---|---|
| CISM or CISSP | Years of practical security experience, no AI-specific requirement | Security managers and architects building governance and risk judgment |
| ISACA AAISM | Active CISM or CISSP | Governance leaders adding AI oversight to an existing management role |
| CompTIA SecAI+ | Roughly 3-4 years IT and 2+ years hands-on security | Practitioners adding AI-aware workflows to an existing technical role |
What the Hiring Data Says About Waiting Too Long
The risk of waiting isn't theoretical, it shows up directly in hiring behavior. The 2024 ISC2 Cybersecurity Workforce Study found that more than a third of cybersecurity teams report significant gaps in AI expertise, even as the overall global cybersecurity workforce gap grew to 4.76 million unfilled roles. More striking is the mismatch inside hiring decisions themselves: only 12% of hiring managers currently prioritize AI skills when filling roles, despite a third of cybersecurity professionals identifying AI as critical to their operations.
That gap between what practitioners already know matters and what hiring managers are actually screening for is an executive risk, not a talent-pool problem. If your job postings and internal promotion criteria haven't caught up to where the credentialing market already is, you're competing for the same generalist candidates as every other buyer while a smaller pool of AI-literate governance professionals gets absorbed by organizations that moved first. The compliance side of the market is moving just as fast, with industry analysis pointing to a global AI regulatory compliance market that could reach roughly $15 billion by 2026 as companies scramble to interpret AI-specific rules like the EU AI Act. Certified staff are the mechanism for meeting that demand, not a nice-to-have next to it.
Where NIST's AI Framework Fits Into the Buying Decision
The reason AI governance certification exists at all is that organizations need a defensible way to operationalize AI risk, and NIST supplied the reference model most programs now build against. The NIST AI Risk Management Framework is a voluntary framework meant to help organizations design, develop, deploy, and monitor AI systems that are trustworthy and aligned to business goals. It deliberately treats AI risk as more than a technical problem, connecting it to governance, accountability, data quality, and human oversight rather than treating it as a pure engineering exercise.
That framing matters for a budget owner because it explains why the new AI credentials sit closest to CISM and CISSP rather than to a purely technical certification track. Governance, accountability, and business alignment are exactly the domains CISM already covers. AAISM extends that lens to AI-specific policy, oversight, and safe implementation rather than introducing an entirely separate discipline. If your organization needs to show a regulator or a board that it has a defensible AI governance program, the credentialing path that maps most directly onto the NIST framework is the one built on top of a management-track certification, not a bolt-on technical badge added after the fact.
Building the Business Case for a Layered Certification Path
The practical move for a training budget is to fund in sequence rather than in parallel. Build governance and risk capability first through a core credential, confirm the team can operate a program against a recognized framework, and only then layer in the AI-specific credential once staff are eligible and the organization has a live AI governance question to point it at. A mid-size organization standing up its first AI oversight committee, for example, gets far more value sending an already-certified CISM holder through an AI-specific add-on than sending an uncertified analyst straight into AI governance training with no grounding in how the broader security program is supposed to run.
Trying to skip straight to the AI credential leaves teams with a badge but no underlying program to apply it to, which is exactly the kind of gap auditors and boards notice. Before committing a training calendar to this sequence, it helps to look at how the domains actually break down and how much study time each track realistically needs. A curriculum overview and FAQ on Forge University's resources page walks through that breakdown for teams still deciding where to start. Once you've mapped the sequence for your team, the fastest way to lock in a start date and a study plan is to sign up and get one built around the certification you're funding first.
None of this means AI credentials are optional for much longer. The regulatory and spending pressure behind them is real and growing, and the professionals who hold both the foundation and the AI-specific layer will be the ones organizations trust to run governance programs regulators actually accept. But the sequencing matters. Fund the credential that builds judgment before you fund the one that assumes it.