ACSskillsassessment
ACS RPL

ACS Vendor Certifications List for DevOps & Cyber Security

You passed AZ-400, you hold CISSP, and now you are looking at the ACS skills assessment form wondering whether either credential earns you anything. The…

13 min read

You passed AZ-400, you hold CISSP, and now you are looking at the ACS skills assessment form wondering whether either credential earns you anything. The published ACS vendor certifications list answers that question only halfway. It names the certificates ACS is willing to look at, but it stops short of telling you which nominated occupation each one supports, why three of the most commonly submitted certs get thrown out, and what proof ACS actually wants in the file. This guide closes those gaps for DevOps and cyber security applicants and maps each accepted certification to a specific ANZSCO code, something the ACS InfoHub itself never does.

Fix one point in place before anything else. For ACS, a vendor certification is supplementary evidence. It strengthens a borderline application. It does not replace a degree or your employment record.

How ACS weighs vendor certifications against a degree

ACS accepts vendor certifications 'only in certain circumstances', and, as the InfoHub frames it, only for DevOps and Cyber Security ANZSCO codes. The wording on the general skills pathway is deliberate: when you apply under those occupations, 'optional evidence of vendor certification may be provided'. That certificate supports the assessment; it is not the thing being assessed. If a consultancy tells you an AWS badge is 'the deciding factor' in your application, treat that as marketing, not policy. The ACS vendor certifications list is deliberately narrow, and, as the InfoHub frames it, applies only to these two occupational families. ACS updates the InfoHub periodically, so confirm the current scope and certificate list on acs.org.au before you submit. If you are still deciding which pathway fits your situation, start with our ACS skills assessment overview.

There is also no ACS point value attached to any certificate. ACS produces a suitability outcome; the Department of Home Affairs awards migration points against that outcome and your other attributes. Any blog that prints a table awarding '10 points for CISSP' has invented it. ACS publishes no such figures, so do not build your expectations on numbers that do not exist.

The two frameworks applicants keep confusing

Search this topic and you will hit two contradictory answers, because two different frameworks are in circulation. The older general pathway treated a small set of expert-tier credentials, Microsoft MCSE and MCSD, and a defined set of Cisco professional and expert credentials such as CCNP and CCIE, as equivalent to an AQF Diploma-level qualification. That is the framework that generated most of the 'CCNA is not accepted' language you read on community forums.

The newer pathway, introduced by ACS more recently, is narrower and different in kind. It applies specifically to DevOps and cyber security occupations, and it treats the certificate as optional supporting evidence rather than a diploma substitute. Older ImmiTracker threads and general guides that still list MCSE and the Cisco expert-tier certs are describing the first framework. If you nominate DevOps Engineer, that list is not your reference point.

Why no certificate carries a fixed ACS point value

No single certificate is worth a defined number of ACS points, because ACS does not score them that way. The assessment returns a suitable or not-suitable outcome for your nominated occupation, and the vendor certification either helps establish that outcome or it does not. Points enter the picture later, at the migration stage, and they are the Department of Home Affairs' domain. Any cert-to-points table you find online is fabricated.

Accepted DevOps vendor certifications: ANZSCO 261316 and 261313

For DevOps, the ACS InfoHub lists three certificates: AWS Certified DevOps Engineer Professional, Google Professional Cloud DevOps Engineer, and Microsoft DevOps Engineer Expert. Treat that as the set published at the time of writing, and confirm it against the current InfoHub before you rely on the count.

The AWS, Google, and Microsoft certs ACS actually lists

Match these three to the right occupation before you submit. The dedicated code is 261316, DevOps Engineer, a distinct occupation from 261313, Software Engineer, inside the same 2613 unit group. A practitioner whose real work is build, release, and pipeline engineering should be nominating 261316, and all three certificates sit most naturally there. If you nominate 261313 because your day-to-day is application development rather than delivery engineering, the same certs still read as relevant supporting evidence, though the occupation fit is secondary.

AWS Solutions Architect and AZ-104: cited everywhere, listed nowhere

Here is where competitor content parts company with the official source. AWS Certified Solutions Architect (Associate and Professional) and Azure Administrator Associate (AZ-104) are widely repeated as 'ACS accepted'. Neither appears on the ACS InfoHub vendor certifications page. For AWS, only the DevOps Engineer Professional credential is listed. For Microsoft, only DevOps Engineer Expert, reached through AZ-400, appears; AZ-104 is a prerequisite exam, not a separately listed certificate.

The practical takeaway is blunt. Do not lead your evidence with a certificate that is not on the published list and assume it will be counted. If you hold Solutions Architect or AZ-104, include it as background, but build your case on a certificate ACS actually names, or confirm current acceptance with ACS directly before you rely on it.

Accepted cyber security certifications: ANZSCO 262112 and beyond

The cyber security list is longer, and it spans three issuing bodies. From ISC2: CISSP, CSSLP, and CCSP. From ISACA: CISM, CISA, CRISC, and CGEIT. From CompTIA: Security+, CySA+, PenTest+, and SecurityX, the credential formerly branded CASP+. Every one appears on the InfoHub cyber security list as published, and none carries a published weighting; check the current InfoHub for any additions or removals since.

ISC2 and ISACA: the governance-tier certificates

CISSP is the credential most cyber applicants lead with, and for good reason. Recognised as the senior generalist certification, it reads cleanly against 262112, ICT Security Specialist, and 262117, Cyber Security Architect. CISM and the wider ISACA set, covering CISA, CRISC, and CGEIT, lean toward governance, audit, and risk, which aligns them with the compliance-oriented code 262114, Cyber Governance Risk and Compliance Specialist. CSSLP is the outlier of the ISC2 group: its secure-software focus maps to 261315, Cyber Security Engineer, more convincingly than to a pure analyst role.

CompTIA: the practitioner certificates

Security+ is the entry point and maps broadly across analyst and specialist codes. CySA+ points at the analyst function under 262116, while PenTest+ is the natural fit for 261317, Penetration Tester. SecurityX reaches toward the architect end at 262117. None of these is a lesser submission. Pitched at the working practitioner, they read as exactly that.

CCSP: the certificate that bridges two streams

CCSP earns its own mention because it does something no other certificate on the list does. A cloud security credential, it speaks to a cyber security assessor under 262112, and, for an applicant whose DevOps work is security-heavy, it carries genuine relevance toward the DevOps stream as well. If your role straddles pipeline security and cloud posture, CCSP is the one certificate that documents both sides of that overlap.

One caution before you move on. EC-Council CEH appears in a great deal of widely circulated content as an accepted cyber security cert. It is not on the ACS InfoHub list. Treat it the way you treat Solutions Architect: useful background, not a certificate you can assume ACS will count.

Which certifications ACS rejects, and the reason each fails

CCNA fails on two independent grounds

CCNA is the most common rejected submission, and it fails twice over. Under the old general pathway, ACS recognised Cisco credentials at the professional and expert tier, CCNP and above, so CCNA at associate level fell one rung below the threshold. Under the newer pathway, the problem is occupational: CCNA certifies routing and switching, the networking infrastructure stream, not the software or DevOps stream the pathway was built for. Neither framework has a slot for it. Leading your evidence with CCNA signals a misread of what the pathway assesses.

MCP and MCSA: retired credentials that cannot show a current date

Microsoft retired both programs in January 2021, which creates a documentation failure before you even reach the tier argument. Neither credential can produce a certificate with a current issuance and expiry date, and a current validity date is one of ACS's hard documentation requirements. The tier problem compounds the issue: MCP was an entry-level exam, and MCSA was associate level, while the old framework only ever recognised the MCSE and MCSD expert tier. A retired associate credential fails on documentation and on level at once.

Coursera, Udemy, and LinkedIn Learning are not vendor certifications

A course completion is not a vendor certification, and ACS does not treat the two as equivalent. An accredited vendor certification (AWS, Microsoft, Google, CompTIA, ISC2, ISACA) is issued by the technology vendor or a standards body after a proctored exam, and it carries a verifiable credential number. A Coursera, Udemy, or LinkedIn Learning completion certifies attendance, not assessed competency, and it has no vendor-issued validation record ACS can check. List these under professional development if you wish, but never in the same breath as your CompTIA or ISC2 credentials.

Cert-to-ANZSCO mapping: the ACS vendor certifications list by code

This table is the artifact the current SERP lacks. The ACS vendor certifications list groups every accepted certificate under two broad category headings and never maps them to individual ANZSCO codes. The mapping below cross-references the InfoHub list against the ACS IT and cyber security occupation definitions. The acceptance column reflects the InfoHub as published; the ANZSCO column is an occupational-fit reading, not an ACS-published pairing.

Certification

Issuing body

Relevant ANZSCO code(s)

ACS acceptance status

AWS Certified DevOps Engineer Professional

Amazon Web Services

261316, 261313

Listed (DevOps)

Google Professional Cloud DevOps Engineer

Google

261316, 261313

Listed (DevOps)

Microsoft DevOps Engineer Expert (via AZ-400)

Microsoft

261316, 261313

Listed (DevOps)

CISSP

ISC2

262112, 262117

Listed (Cyber Security)

CSSLP

ISC2

261315

Listed (Cyber Security)

CCSP

ISC2

262112, 261315

Listed (Cyber Security)

CISM

ISACA

262114

Listed (Cyber Security)

CISA

ISACA

262114

Listed (Cyber Security)

CRISC

ISACA

262114

Listed (Cyber Security)

CGEIT

ISACA

262114

Listed (Cyber Security)

CompTIA Security+

CompTIA

262112, 262116

Listed (Cyber Security)

CompTIA CySA+

CompTIA

262116

Listed (Cyber Security)

CompTIA PenTest+

CompTIA

261317

Listed (Cyber Security)

CompTIA SecurityX (formerly CASP+)

CompTIA

262117

Listed (Cyber Security)

AWS Solutions Architect (Associate/Professional)

Amazon Web Services

261316, 261313

Not on InfoHub list

Azure Administrator Associate (AZ-104)

Microsoft

261316

Not on InfoHub list

EC-Council CEH

EC-Council

262116, 261317

Not on InfoHub list

CCNA

Cisco

n/a

Rejected

MCP

Microsoft

n/a

Rejected (retired Jan 2021)

MCSA

Microsoft

n/a

Rejected (retired Jan 2021)

Read the table as a shortlist test, not a guarantee. A 'listed' status means ACS will accept the certificate as optional supporting evidence for the relevant category. It does not promise a score, and it never overrides the degree and employment core of your application.

What ACS accepts as proof of a vendor certification

Passing the exam is one thing. Documenting it to ACS's standard is another, and this is where otherwise strong files stumble.

The details every certificate must show

The InfoHub's documentation guidance calls for a certificate to show, clearly, the name of the issuing authority, the validation or certificate number, your full name exactly as it appears on your application, the issuance and expiry dates, and renewal or maintenance proof where the credential requires it. Confirm the current requirements on the InfoHub, since ACS can revise them. A document missing the validation number, or with a name that does not match, is the most common failure. Fix a name mismatch before you submit, not after ACS queries it.

Screenshots are the other trap. A screenshot of your badge carries no live verification path, so it is not evidence. Supply the credential through the vendor's own verification channel instead: AWS through Certmetrics, Microsoft through a Microsoft Learn transcript or a Credly badge link, Google Cloud through its credential management portal, CompTIA through CertMetrics, and ISC2 and ISACA through their member verification portals. An official PDF certificate that names the issuing body works too. A phone snapshot of a wall certificate does not. For the full picture of accepted formats, the ACS skills assessment document checklist sets out what each evidence type needs to include.

ACS policy on vendor certifications that expired before you applied

Be careful with expired certificates. The InfoHub requires an issuance date and an expiry date, which reads as a requirement that the credential be valid, and it asks for renewal proof where applicable. What ACS does not publish is an explicit rule covering a certificate that lapsed after the employment period you are claiming. Do not assume either outcome. Renew before you submit where feasible, and where renewal is not possible, ask ACS directly rather than relying on a forum answer. The ACS skills assessment eligibility documents guide covers how supporting evidence interacts with your employment claim.

Vendor certification questions from DevOps and security applicants

Can an AWS or Azure certification substitute for a formal degree in an ACS skills assessment?

No. Under the current DevOps and cyber security pathway, a vendor certification is optional supplementary evidence, not a qualification substitute. It supports an application built on your degree and employment record; it does not stand in for a degree. The older pathway that let expert-tier certs substitute for an AQF Diploma is a separate framework and does not apply to these occupations. The ACS skills assessment pathways explained guide sets out how the pathways differ.

Does ACS accept expired vendor certifications if they were current during the period of relevant employment?

ACS does not publish a clear yes or no on this. The InfoHub requires a certificate to show issuance and expiry dates and asks for renewal proof where applicable, which points toward validity at submission. It does not state a policy on a credential that was valid during your employment but has since lapsed. Renew before submitting if you can, and confirm with ACS directly if you cannot.

I hold both CISSP and an AWS certification. Does ACS award additional credit for holding multiple vendor certifications?

There is no published ACS position on cumulative credit for multiple certificates, and no ACS point value for any single one. Holding CISSP and an AWS DevOps credential documents breadth across both streams, which can only help a borderline file, but do not expect a defined score to stack. Submit the certificate that best matches your nominated code as the lead, and treat the second as reinforcing evidence.

Which DevOps or cloud ANZSCO codes benefit most from vendor certifications in an ACS application?

261316, DevOps Engineer, is the code the DevOps certificates fit most directly, with 261313, Software Engineer, as a secondary fit for application-focused roles. Because vendor certifications are only accepted for DevOps and cyber security occupations, nominating one of those codes is a precondition for the evidence to count.

Are Coursera and LinkedIn Learning completions treated the same as CompTIA or AWS vendor certifications by ACS?

No. Coursera, Udemy, and LinkedIn Learning issue completion records for attending a course, not vendor-issued credentials earned through a proctored exam, and they carry no validation number ACS can verify. CompTIA, AWS, and the other listed vendors issue verifiable certifications through their own portals. ACS does not treat the two as equivalent.

Three steps before you lodge your ACS application file

Match your strongest listed certificate to your nominated ANZSCO code, verify it through the vendor's own portal rather than a screenshot, and keep the vendor certification in its proper place as evidence that reinforces your degree and employment case rather than replacing it. Work through the full ACS vendor certifications list against your nominated code, then review the ACS skills assessment document checklist to confirm the exact format ACS accepts for each item before you lodge.