Hardenstep
Menu

A desk that reads the source, then writes

Hardenstep is a small independent publication about security certifications and the training that leads to them. It is written for people spending their own money.

What this is

Hardenstep covers vendor-neutral security certifications — CISSP, CISM, CCSP, Security+, and the hands-on training people use to get ready for them. We do not cover cloud-provider exams, general IT certifications or degree programmes, and we do not publish study materials of our own.

The organising idea is the one on the home page: certifications are not a ladder, they are layers of a system, and the question is always which layer you are defending.

Who writes it

A two-person editorial desk with a background in security operations and technical writing, working to a published method. We are not an ISC2, CompTIA, ISACA, OffSec or EC-Council partner, affiliate or authorised training organisation, and we award no credential of any kind. Nothing on this site is a qualification, a course, or advice about a specific employer's requirements.

We deliberately do not use a badge, shield or seal anywhere in the design, because a publication about credentials should not be dressed as one.

How the money works

Some links to training providers are paid: if you subscribe after following one, the provider pays us a share. The certifying bodies are never paid links, because their pages are the source for every fee, weighting and rule on this site, and a source we were paid by would not be a source. The full arrangement, including what we refuse, is on the disclosure page.

No provider has ever seen a page before publication, and none has any input into what is recommended. Several things we recommend — TryHackMe's free tier, OffSec, reading the exam outline on the body's own site — earn us nothing at all.

Corrections

Fees and rules change. When we find something out of date, we re-read the source, change the figure and change the date on the page. When you find it first, write to the desk and we will do the same. The method we hold ourselves to is written out in full on how we check exam facts.