What are GIAC certifications?
GIAC - the Global Information Assurance Certification - is the certification body associated with the SANS Institute, widely regarded as producing the most rigorous and hands-on security credentials in the industry. Unlike many other certification programmes, GIAC exams are known for testing practical, applied knowledge rather than rote memorisation.
For IT security teams, GIAC certifications carry significant weight. Many government agencies, defence contractors, and enterprise security programmes specifically require GIAC credentials for certain roles, and the certifications map directly to real-world security functions - incident response, forensics, penetration testing, cloud security, and more.
There are currently over 40 active GIAC certifications spanning every major domain of information security, from entry-level credentials like GSEC through to the prestigious GIAC Security Expert (GSE) designation held by fewer than 300 professionals worldwide.
How long do GIAC certifications last?
All GIAC practitioner certifications are valid for four years from the date of certification. This applies across the full catalogue - GSEC, GCIH, GPEN, GCFA, GCIA, and all others follow the same four-year renewal cycle.
To renew before expiry, the certification holder must accumulate 36 Continuing Professional Experience (CPE) credits through activities such as attending security conferences, completing training, publishing research, or contributing to the security community. Alternatively, they can retake and pass the exam.
There is no grace period for expired GIAC certifications. Once a cert expires, the holder's certified status is removed from the public directory immediately. Reinstatement requires retaking the full exam - CPE submission is no longer accepted after the expiry date has passed.
For a security team manager, this means that proactively tracking renewal windows is not optional - it is operational risk management. A lapsed GSEC or GCIH on your team can create gaps in compliance documentation, client-facing credential requirements, and internal capability mapping.
Using the GIAC certified professionals directory
GIAC maintains a public directory of all active certified professionals at giac.org/certified-professionals. This is an important resource for several use cases:
Verifying an analyst's certifications
When hiring a security analyst, contractor, or consultant, the GIAC directory allows you to verify their claimed certifications before making a hiring decision. Simply search by name or certification type to confirm their current status. Active certifications will appear with the holder's name and credential - expired certifications will not appear in active searches.
Finding certified professionals by specialisation
The directory can also be used to search for professionals holding specific certifications. If you need to find a qualified GCFE (forensic examiner) or GPEN (penetration tester) in your network or for a specific engagement, the directory provides a searchable pool of verified professionals. This is particularly useful for MSSPs and security consultancies evaluating potential partners or subcontractors.
Confirming team member status
For compliance purposes - particularly ISO 27001 audits, Cyber Essentials Plus assessments, and client-facing credential requirements - the GIAC directory serves as an independent verification source. Cross-referencing your team's self-reported certifications against the live directory ensures your compliance documentation is accurate.
The GIAC directory shows current active status only. If a team member's certification recently expired, it will disappear from the directory without notice. Running regular directory checks manually is time-consuming - this is one of the core problems that a GIAC certification tracker like TrackACert solves automatically.
The most common GIAC certifications to track
Security teams typically hold a mix of GIAC certifications across different domains. Here are the most commonly held credentials and their renewal requirements:
| Code | Certification name | Domain | Validity |
|---|---|---|---|
| GSEC | GIAC Security Essentials | Security fundamentals | 4 years |
| GCIH | GIAC Certified Incident Handler | Incident response | 4 years |
| GCIA | GIAC Certified Intrusion Analyst | Network monitoring | 4 years |
| GPEN | GIAC Penetration Tester | Penetration testing | 4 years |
| GCFA | GIAC Certified Forensic Analyst | Digital forensics | 4 years |
| GCFE | GIAC Certified Forensic Examiner | Digital forensics | 4 years |
| GREM | GIAC Reverse Engineering Malware | Malware analysis | 4 years |
| GWAPT | GIAC Web Application Penetration Tester | Web security | 4 years |
| GCLD | GIAC Cloud Security Essentials | Cloud security | 4 years |
| GSLC | GIAC Security Leadership Certification | Security management | 4 years |
| GCTI | GIAC Cyber Threat Intelligence | Threat intelligence | 4 years |
| GMON | GIAC Continuous Monitoring | Security operations | 4 years |
Why GIAC certification tracking matters
For individual practitioners, tracking a single certification renewal is manageable - set a calendar reminder and keep up with CPEs. But for anyone responsible for a security team, the complexity compounds quickly.
A team of ten security professionals holding an average of three GIAC certifications each means thirty separate expiry dates to track, across potentially a dozen different certification codes, each earned at different times. Add CISSP, CompTIA, ISACA, and cloud certifications into the mix and the tracking problem becomes genuinely hard to manage manually.
The consequences of getting it wrong are real:
- Compliance failures: Many client contracts, government frameworks, and audit requirements specify that team members must hold current certifications. A lapsed cert discovered during an audit can result in failed assessments and remediation costs.
- Reputational risk: For MSSPs and security consultancies, claiming staff hold certifications they no longer actively hold is a serious credibility issue.
- Missed renewal windows: Once a GIAC cert expires, CPE submission is no longer accepted. The only route back is a full exam retake - a significant time and cost burden that proactive tracking avoids entirely.
- Hidden capability gaps: When certifications lapse silently, the skill gap mapping you use for resource allocation and team development becomes inaccurate.
In conversations with security team managers, the most common answer to "how do you track your team's certifications?" is still: a shared spreadsheet. The second most common answer is: we don't really track it. Most teams find out a cert has lapsed during an audit rather than before it.
How to track GIAC certifications for your team
There are several approaches to GIAC certification tracking, ranging from manual to fully automated. Here is a realistic assessment of each:
Option 1: Manual spreadsheet
A shared spreadsheet with columns for team member name, certification code, issue date, and expiry date is how most teams start. It works for very small teams but degrades quickly as the team grows, people join and leave, and nobody remembers to update it. The fundamental problem is that spreadsheets rely on someone actively maintaining them - and cert tracking is typically not anyone's primary job.
Option 2: Calendar reminders
Individual team members setting their own calendar reminders at 90, 60, and 30 days before expiry is better than nothing but puts the burden on individuals rather than giving the manager visibility. It also provides no consolidated view of team coverage.
Option 3: Cross-referencing the GIAC directory manually
Periodically checking the GIAC certified professionals directory to confirm active status is a useful verification step but is reactive rather than proactive. The directory shows current status - it does not tell you that a certification is expiring in 45 days.
Option 4: Dedicated certification tracker
A purpose-built certification tracking platform like TrackACert gives managers a single dashboard showing every team member's certifications, expiry dates, and upcoming renewals - with automatic email alerts before anything expires. This is the only approach that scales reliably and provides both individual and team-level visibility.
Automating GIAC tracking with TrackACert
TrackACert is a certification tracking platform built specifically for IT and security teams. It was designed to solve exactly the problem described above - giving security managers a single place to track every team member's certifications across GIAC, ISC², CompTIA, OffSec, ISACA, AWS, Microsoft, and over 200 other IT credentials.
Create your organisation and invite your team
Set up your organisation in minutes. Team members receive an email invite, create their account, and add their own certifications. No manual data entry by the manager required.
Add certifications from the pre-loaded library
TrackACert includes a library of 200+ IT certifications including the full GIAC catalogue. Team members search for their cert, add their issue date, and the platform automatically calculates the expiry date.
View the team dashboard
The manager sees a consolidated dashboard showing every certification across the team - who holds what, what's expiring, and where the skill coverage gaps are across key security domains.
Receive automatic expiry alerts
TrackACert sends automated email alerts at 60 and 30 days before any certification expires - giving enough notice to complete CPEs or schedule exam retakes well in advance.
Export audit-ready reports
For compliance audits, client requirements, or internal reviews, export a clean CSV or PDF showing your team's full certification status - current, expiring, and expired.
Track your team's GIAC certifications for free
TrackACert is 100% free - unlimited members, every feature included, no credit card required.
Start tracking free → 100% free · No credit card · All features included