Registered in the United Kingdom · Independent professional standards council
Technology · GCS-02

Prove you can defend a system under real pressure

The Cyber Security standard certifies people who can find weaknesses before an attacker does, and hold a response together when something gets through. Assessment includes incident evidence from your own work, not multiple-choice theory.

41,208 holders worldwide 6 levels +4.1% growth this year
What this standard certifies

Six capability areas, assessed on evidence

Each area is evidenced from your own work. Assessors look for what you decided and why, not for a rehearsed answer.

Threat identification
Finding the weaknesses that matter, and ranking them honestly.
Secure architecture
Designing systems where a single mistake is not fatal.
Risk management
Translating technical exposure into decisions a board can act on.
Incident response
Containment, evidence and communication while the clock is running.
Assurance & audit
Evidencing controls against recognised frameworks.
Security culture
Making safe behaviour the easy path for everyone else.
Levels in this standard

Cyber Security across the recognition ladder

The same six-level framework, expressed in the terms of this discipline. Experienced applicants can enter directly at a higher level through the portfolio route.

Level Post-nominal What it certifies Professional Experience Annual CPD
1BIPS Foundation BIPS-F Understands the threat landscape, core controls and why each one exists. 0–1 yr 10 h
2BIPS Practitioner BIPS-P Runs assessments and hardening work under the direction of a senior practitioner. 1–3 yrs 15 h
3BIPS Professional BIPS-Pro Owns the security of a system or domain and answers for its exposure. 3–6 yrs 20 h
4BIPS Specialist BIPS-S Leads a specialism — offensive testing, forensics, cloud security — with reviewed evidence. 6–10 yrs 25 h
5BIPS Expert BIPS-E Sets security strategy and is trusted on risk at executive level. 10+ yrs 30 h
6BIPS Fellow FBIPS Contributes to the profession through standards, research or public defence work. By election 30 h
Who it is for

Built for people already doing the work

Security analysts and engineers SOC and incident responders Penetration testers Infrastructure engineers moving into security Risk and compliance leads IT professionals retraining
How you are assessed

Four stages, no written exam

1

Portfolio

You submit real work against the six capability areas.

2

Evidence review

An assessor checks provenance and your role in it.

3

Professional discussion

A recorded conversation about decisions and trade-offs.

4

Award & register

Your credential is issued and listed publicly.

Where it leads

Roles this standard opens up

Security Engineer

Builds and hardens the controls that hold the line.

Incident Responder

Runs containment and recovery when something gets through.

Penetration Tester

Finds it first, on purpose, and writes it up properly.

Chief Information Security Officer

Owns organisational risk and answers for it.

Latest on cyber

What is changing in this field

Related standards

Often held alongside this one

Technology

Cloud Engineering

The Cloud Engineering standard recognises people who can build infrastructure that survives contact with real traffic, real budgets and real failure.

GCE-035 levels
View the standard →
Technology

DevOps & Reliability

The DevOps & Reliability standard recognises people who shorten the distance between an idea and production while making outages rarer and shorter.

GDO-055 levels
View the standard →
Data & AI

Artificial Intelligence

The Artificial Intelligence standard recognises people who can take a model from problem framing to production and stay accountable for what it does once it is there.

GAI-016 levels
View the standard →