Certifications · The Landscape

CNCF certifications for platform engineers

The CNCF’s certification catalogue currently runs to fifteen exams — the same fifteen the Golden Kubestronaut programme is built from — and they are not a queue; they are a landscape. Some are ninety minutes of multiple choice about vocabulary; some drop you onto a live cluster and time you. Some map almost perfectly onto the CNPE blueprint; some are lovely badges that will not earn you a single mark on it. This page exists so you can choose deliberately instead of collecting: how the ladder is structured, every certification in one table, five recommended routes depending on where you’re starting from, an honest verdict on which ones genuinely help with the CNPE, what the Kubestronaut programmes are, how to study for the two very different exam formats, and what all of it really costs in money and evenings. (The site also covers the eleven adjacent non-CNCF certifications a platform engineer bumps into — those are gathered in their own section near the end, grouped by the provider that sells them.)

☺ Explain it like I’m 10

Imagine a big climbing wall with lots of coloured holds. Some holds are near the bottom and easy to reach — those are the associate badges, where someone asks you questions and you pick the right answer. Some holds are much higher and you have to actually climb to them — those are the professional badges, where they hand you a real wall and watch you do it. And here’s the important bit: you don’t have to touch every hold. You only need the ones on the way to where you’re going. Collecting holds you don’t need is how people spend a whole year climbing sideways.

🦉🦊Your hosts for this topic: Professor Owl & Foxy — Owl has read every published curriculum and will lay the whole map out in order; Foxy asks the question everyone is too embarrassed to ask, which today is “yes, but which of these do I actually need?”

How the certification ladder is structured

☺ Like you’re 10: There are two kinds of test. One asks “do you know it?” by giving you answers to pick from. The other says “show me” and gives you a real computer. They are completely different experiences.

The CNCF designs the curricula; The Linux Foundation runs the exams, the proctoring and the store. Everything in the master table below is one of theirs — the non-CNCF credentials a platform engineer also meets get their own section further down, because none of the rules in this section apply to them. What matters when you’re choosing is that the catalogue splits along two independent axes — tier (how senior the credential is) and format (how they test you) — and people routinely confuse the two.

The associate tier — knowledge-based, multiple choice

Associate exams are online, remote-proctored, and multiple choice. No terminal, no cluster, no documentation tab. You are tested on whether you hold a correct mental model: what a thing is, what it’s for, which component does what, which pattern applies. They are the cheapest exams, the shortest, and the ones you can genuinely prepare for by reading and drilling recall. The shape the Linux Foundation actually publishes for this tier is consistent: a 90-minute, online, proctored, multiple-choice exam, listed at US$250 exam-only, valid for two years, with a twelve-month eligibility window and one retake included — that is the wording on the KCNA and CGOA listings, and the other associates follow it. Two exceptions are worth knowing, because they are published and they matter. The Linux Foundation’s Multiple Choice Exam FAQ states that a score of 75% or above must be earned to pass any multiple-choice exam, and that the 90 minutes above applies to all of them except the CNPA, which is allowed 120. What is still not published is the question count — the exam pages no longer state one, so treat any specific “60 questions” figure you meet elsewhere, including in older versions of this page, as folklore. Read the individual exam page before you plan around any of it. KCNA, KCSA, CNPA, CGOA, CAPA, CBA, CCA, KCA, OTCA and PCA all live here.

Within the tier there’s a second, informal split worth naming. Some associate exams are broad — KCNA covers the whole cloud-native world, CNPA covers the whole platform-engineering discipline. Others are project-specific: CAPA is Argo, CBA is Backstage, CCA is Cilium, KCA is Kyverno, OTCA is OpenTelemetry, PCA is Prometheus. The project-specific ones are narrow by design, which makes them fast to prepare for and easy to over-collect.

The professional and specialist tier — performance-based

Performance-based exams put you in a remote Linux desktop with live clusters and a list of tasks, and grade the resulting state — not your method, not your reasoning. CKA, CKAD, CKS and the CNPE are the classic examples, and the Linux Foundation describes ICA as performance-based too — its listing calls the exam “performance-based and multiple-choice,” which makes it the odd entry on the shelf: hands-on in format but badged, and priced, with the associates. All five are listed as two-hour sittings; CKA, CKAD, CKS and the CNPE are listed at US$445 exam-only, while ICA sits at the associate price. Here, knowing the answer is not enough — you must be able to type it, correctly, under a clock, in the right namespace. That difference drives everything about how you prepare, and it gets its own section further down.

One structural note: only CKS has a formal prerequisite — the Linux Foundation’s wording is that you must have taken and passed the CKA exam before attempting it. Treat that as “hold a CKA in good standing and don’t let it lapse while you’re booking,” and read the current CKS page rather than this one, because the exact phrasing of that rule has been revised before. Everything else on this page can be booked cold, including the CNPE — whose own listing states plainly that there are no pre-requisites for it. “No prerequisite” is not the same as “no assumed knowledge,” though; several of these exams quietly assume Kubernetes fluency you’d normally get from CKA-level work.

A naming caveat, because it trips people up: “associate”, “professional” and “specialist” are this page’s shorthand, not a formal Linux Foundation grade. What the catalogue actually publishes per exam is an experience level — the CNPE and CKA are both listed as “Intermediate,” for instance — plus the format, duration, price and validity. Where this page says “professional,” read it as “the hands-on, US$445, two-hour band,” and check the exam’s own page for the labels it really uses.

Associate tier · knowledge-based, multiple choice KCNA · KCSA · CNPA · CGOA CAPA · CBA · CCA · KCA · OTCA · PCA (project-specific) Professional & specialist · performance-based, live clusters CKA · CKAD · ICA CKS — the only one with a formal prerequisite (a passed CKA) 🦉 CNPE the platform-engineering summit · 120 min, hands-on no tier is a formal prerequisite for the next
DimensionAssociate (knowledge-based)Professional / specialist (performance-based)
How you answerPick from options; no terminalDo the task on a live cluster; graded on end state
What it provesYou hold a correct mental modelYou can execute, correctly, at speed
What kills candidatesFuzzy definitions and lookalike distractorsThe clock, and working in the wrong namespace
How you prepareRead, take notes, drill recall, take mocksRepetition at a keyboard on a throwaway cluster
Typical sitting90 minutes, multiple choice — except the CNPA, which gets 120 (question count unpublished)2 hours for CKA, CKAD, CKS, ICA and the CNPE
Cramming works?Partly — recall responds to crammingNo. Muscle memory does not cram
On this shelfKCNA, KCSA, CNPA, CGOA, CAPA, CBA, CCA, KCA, OTCA, PCACKA, CKAD, CKS, ICA, CNPE
◆ Key idea

Tier and format are different questions. “Associate” tells you how senior the credential reads on a CV; “knowledge-based” tells you how you’ll spend your study evenings. A narrow project associate like KCA can be more immediately useful to your day job than a broad one like KCNA — and neither will teach your fingers to move fast enough for the CNPE.

Every CNCF certification, in one table

☺ Like you’re 10: Here is the whole CNCF shelf on one page — what each badge is called, how hard it is, whether you type or click, and what it’s about.

Domain names and weights below are transcribed from the official CNCF curriculum PDF for each exam — all fifteen were checked against the published curricula, and every row’s weights sum to exactly 100%. If a row here ever disagrees with the curriculum, trust the curriculum and not this page; the PDFs live in the cncf/curriculum repository and are revised without ceremony. Levels and formats follow the Linux Foundation certification catalogue, which is also where you should confirm duration, format, price and validity before booking anything. Each row links to that certification’s full page on this site, where you’ll find the competencies, the substance behind each domain, an honest verdict on whether to sit it, and a study plan built from lessons already here.

CertLevelFormatWhat it covers (official domains & weights)Page
CNPE
Certified Cloud Native Platform Engineer
ProfessionalPerformance-basedGitOps and Continuous Delivery 25% · Platform APIs and Self-Service Capabilities 25% · Observability and Operations 20% · Platform Architecture and Infrastructure 15% · Security and Policy Enforcement 15%The CNPE exam
CNPA
Certified Cloud Native Platform Engineering Associate
AssociateKnowledge-basedPlatform Engineering Core Fundamentals 36% · Platform Observability, Security, and Conformance 20% · Continuous Delivery & Platform Engineering 16% · Platform APIs and Provisioning Infrastructure 12% · IDPs and Developer Experience 8% · Measuring your Platform 8%CNPA
KCNA
Kubernetes and Cloud Native Associate
AssociateKnowledge-basedKubernetes Fundamentals 44% · Container Orchestration 28% · Cloud Native Application Delivery 16% · Cloud Native Architecture 12%KCNA
KCSA
Kubernetes and Cloud Native Security Associate
AssociateKnowledge-basedKubernetes Cluster Component Security 22% · Kubernetes Security Fundamentals 22% · Kubernetes Threat Model 16% · Platform Security 16% · Overview of Cloud Native Security 14% · Compliance and Security Frameworks 10%KCSA
CKA
Certified Kubernetes Administrator
ProfessionalPerformance-basedTroubleshooting 30% · Cluster Architecture, Installation and Configuration 25% · Services and Networking 20% · Workloads and Scheduling 15% · Storage 10%CKA
CKAD
Certified Kubernetes Application Developer
ProfessionalPerformance-basedApplication Environment, Configuration and Security 25% · Application Design and Build 20% · Application Deployment 20% · Services and Networking 20% · Application Observability and Maintenance 15%CKAD
CKS
Certified Kubernetes Security Specialist
Specialist
requires a passed CKA
Performance-basedMinimize Microservice Vulnerabilities 20% · Supply Chain Security 20% · Monitoring, Logging and Runtime Security 20% · Cluster Setup 15% · Cluster Hardening 15% · System Hardening 10%CKS
CGOA
Certified GitOps Associate
AssociateKnowledge-basedGitOps Principles 30% · GitOps Terminology 20% · GitOps Patterns 20% · Related Practices 16% · Tooling 14%CGOA
CAPA
Certified Argo Project Associate
AssociateKnowledge-basedArgo Workflows 36% · Argo CD 34% · Argo Rollouts 18% · Argo Events 12%CAPA
CBA
Certified Backstage Associate
AssociateKnowledge-basedCustomizing Backstage 32% · Backstage Development Workflow 24% · Backstage Infrastructure 22% · Backstage Catalog 22%CBA
CCA
Cilium Certified Associate
AssociateKnowledge-basedArchitecture 20% · Network Policy 18% · Service Mesh 16% · Network Observability 10% · Installation and Configuration 10% · Cluster Mesh 10% · eBPF 10% · BGP and External Networking 6%CCA
ICA
Istio Certified Associate
Associate-badged, senior in practicePerformance-based (the listing describes a mix of hands-on and multiple-choice items)Traffic Management 35% · Securing Workloads 25% · Installation, Upgrades, and Configuration 20% · Troubleshooting 20%ICA
KCA
Kyverno Certified Associate
AssociateKnowledge-basedWriting Policies 32% · Fundamentals of Kyverno 18% · Installation, Configuration, and Upgrades 18% · Kyverno CLI 12% · Applying Policies 10% · Policy Management 10%KCA
OTCA
OpenTelemetry Certified Associate
AssociateKnowledge-basedThe OpenTelemetry API and SDK 46% · The OpenTelemetry Collector 26% · Fundamentals of Observability 18% · Maintaining and Debugging Observability Pipelines 10%OTCA
PCA
Prometheus Certified Associate
AssociateKnowledge-basedPromQL 28% · Prometheus Fundamentals 20% · Observability Concepts 18% · Alerting & Dashboarding 18% · Instrumentation and Exporters 16%PCA

Two things stand out when you read that table as a whole. First, every domain weight is public — the CNCF publishes each curriculum openly, so “what’s on the test” is never a mystery; the only real question is whether you can do the work. Second, the fifteen fall naturally into three families, which is exactly how the paths below are built: the platform-engineering pair (CNPE, CNPA), the core Kubernetes line (KCNA, CKA, CKAD, KCSA, CKS), and the project-specific associates that each go deep on one tool from the tool landscape. For where those projects sit in the wider ecosystem, see the CNCF landscape. Third — and this is a useful fact to hold — those fifteen are not a selection, they are the whole CNCF catalogue at the time of writing, which is why the Golden Kubestronaut list below is exactly this table plus one Linux exam.

⌁ Note · two transcription quirks, so you can reconcile this table yourself

The CKA curriculum PDF (v1.35) prints its 20% domain as “Servicing and Networking”; the exam listing and every earlier revision call it Services and Networking, which is what this table uses — it reads as a typo in the PDF, not a rename. And the CAPA, CCA and CGOA curricula are published as image-only PDFs with no selectable text, so if you try to check them by copy-paste you will get nothing back; those three have to be read by eye.

Jump to any certification

The platform-engineering pair — the two this whole site is built around:

The core Kubernetes line — the operational bedrock everything else stands on:

The project-specific associates — one tool each, examined properly:

Recommended paths for five starting points

☺ Like you’re 10: Where you should start depends on where you already are. Here are five routes — find the one that sounds like you and follow it in order.

None of these are official; they’re the sequences that make sense given how the curricula actually overlap. In every one, the ordering principle is the same: earn the credential that makes the next one easier, and stop when you’ve reached the badge you actually wanted. If a step is already covered by your day job, skip it — a certification is a proof, not a lesson.

Path 1 · Complete beginner — new to Kubernetes and cloud native

You’ve heard of containers, you’ve maybe run docker compose, and Kubernetes is a rumour. Don’t start with a hands-on exam; you’ll spend the money learning things a cheaper exam would have taught you.

  1. KCNA — the vocabulary of the whole ecosystem. Cheap, short, and it makes every later curriculum readable instead of alien.
  2. CKA — the first real one. This is where you stop reading about clusters and start running them, and it is the single biggest step in this list.
  3. CNPA — now that clusters make sense, learn what a platform is: golden paths, self-service, the product mindset.
  4. CNPE — the destination. By now you have terminal speed from CKA and the blueprint’s vocabulary from CNPA.

Expect this route to take the better part of a year at a working pace. Start reading with What is platform engineering? and the Kubernetes substrate while you decide.

Path 2 · Developer moving into platform work

You write services. You’ve deployed them. You now want to build the thing that other developers deploy through. Your advantage is that you already think in workloads; your gap is the cluster underneath and the delivery machinery around it.

  1. CKAD — start where you’re already strong. It’s hands-on, so it builds the terminal reflexes you’ll need later, and it certifies the exact experience your future users will have.
  2. CGOA — the conceptual leap from “I deploy” to “the cluster reconciles.” Cheap, fast, and it reframes how you think about delivery.
  3. CKA — the uncomfortable one, and the one that most changes how you’re seen. You cannot own a platform whose substrate you can’t debug.
  4. CBA (optional) — if your organisation is building a developer portal, this is the most developer-shaped certification on the shelf and plays directly to your existing skills.
  5. CNPE — the credential for the role you’re moving into.

Pair the reading with developer experience and platform as a product — the two lessons that explain why your instincts as a developer are an asset here.

Path 3 · Ops or SRE moving into platform engineering

You already run production. You have the cluster fluency and the incident scars. What you’re missing is the product half of the job and the declarative delivery model.

  1. CKA — if you don’t already hold it. For most SREs this is a formality with a few weeks of drilling; for everyone else it’s the fastest way to prove the fluency you already have.
  2. CGOA — the shift from push to pull. This is the single most transferable idea in the whole discipline.
  3. PCA or OTCA — pick the one that matches your stack. PCA if you live in Prometheus and PromQL; OTCA if you’re standardising instrumentation on OpenTelemetry.
  4. CNPE — the natural destination, and the one where your operations background pays the most.
  5. CKS (optional) — worth it if hardening is part of your remit; it goes far deeper than the CNPE’s 15% security domain ever will.

Your blind spot is usually not technical. Read platform as a product, team topologies and anti-patterns — the last of which is largely a catalogue of what happens when good operators build platforms nobody asked for.

Path 4 · Security-focused

You want the guardrails to be your specialism. This is the one path where the CNPE is genuinely optional — the security-and-policy world has its own deeper ladder.

  1. KCSA — the vocabulary and the threat models. Knowledge-based, so it’s a cheap way to find out whether the subject holds you.
  2. CKA — required, not optional: passing the CKA is the formal prerequisite for CKS, and you cannot harden a cluster you can’t operate.
  3. CKS — the real credential in this direction. Performance-based, deep, and respected.
  4. KCA (optional) — if your organisation runs Kyverno, this makes policy-as-code your concrete deliverable rather than a slide.
  5. CNPE (optional) — take it if you want to build the platform, not only guard it. Security is 15% of it.

The lessons that go with this route are security & policy, governance & compliance and secrets management.

Path 5 · You specifically want the CNPE, as fast as is honest

No detours, no collecting. The CNPE has no prerequisites, so in principle you can book it tomorrow — but two of its five domains are worth 25% each, and both are hands-on to the bone. This route buys the fewest badges that measurably raise your odds.

  1. CKA — or genuine equivalent fluency. The CNPE assumes kubectl speed and gives you no credit for acquiring it during the exam. If you can already clear CKA-style tasks comfortably, skip the exam and keep the skill.
  2. CGOA — maps onto the 25% GitOps & Continuous Delivery domain more directly than anything else available.
  3. CNPA (optional but cheap) — the fastest way to internalise the blueprint’s vocabulary, and it shares a lot of ground with the CNPE’s conceptual half.
  4. CAPA (optional) — worth it only if Argo is your stack; three of its four projects (CD, Rollouts, Workflows) map onto work the CNPE’s delivery domain describes.
  5. CNPE — with both simulator sessions burned before the day. The Linux Foundation’s CNPE listing includes an exam simulator with two practice attempts, provided by Killer.sh; confirm that on your own registration, because what a purchase bundles has changed before. Warm up on the lab track and the practice tasks first — the simulator is worth more when you don’t waste an attempt discovering the basics.
🦉 Professor Owl’s ten-minute exercise

Before you spend a penny, write down three things: (1) the job title you want in eighteen months; (2) the one certification that title’s job adverts actually name; (3) the skill you’d have to build to earn it honestly. Now cross out every badge on this page that isn’t on the shortest line between where you are and that answer. Most people cross out ten of the fifteen — and the five that survive are your real plan. Keep the list; re-run the exercise every six months, because the landscape moves.

Which certifications genuinely help with the CNPE

☺ Like you’re 10: Some badges teach you things the CNPE actually tests. Others are lovely but won’t win you a single mark. Here’s the honest split.

“Helps with the CNPE” means one of two specific things: it drills a skill the exam grades, or it covers a domain that carries real weight. Prestige doesn’t count. Below, every certification on the shelf, mapped against the CNPE blueprint — and note that being “optional” here is not a criticism of the certification, only of its relevance to this one exam.

CertificationWhat it feeds in the CNPEDomain weightVerdict for a CNPE candidate
CKACluster fluency, kubectl speed, troubleshooting under a clock, and the performance-exam format itselfUnderpins all 100%The highest-value preparation on this list. Not because of the badge — because CNPE assumes this fluency and never teaches it.
CGOAReconciliation, drift, desired state, promotion patterns, Argo CD and Flux concepts25% (GitOps and Continuous Delivery)Genuinely helps. The tightest single-domain overlap available, and cheap.
CNPAThe entire conceptual half — golden paths, self-service, platform APIs, measuring the platformSpans all five domainsGenuinely helps, especially for the “why” behind tasks. Knowledge-based, so it builds no speed.
CAPAArgo CD, Rollouts and Workflows — reconciliation, progressive delivery and pipeline authoringFeeds the 25% delivery domainHelps if Argo is your stack. Skip it if your platform runs Flux and Tekton — the CNPE is vendor-neutral and names no required tool.
PCA / OTCAMetrics, PromQL, alerting rules; the OTLP data model and Collector pipelines20% (Observability & Operations)Useful. One of the two, matched to your stack — not both, for CNPE purposes.
KCAAdmission-time policy, validate/mutate/generate, writing policy that fails usefullyPart of 15% (Security and Policy Enforcement)Nice-to-have. High value at work, modest value on this exam.
CBADeveloper portals, catalogs and templates — the front door of self-servicePart of 25% (Platform APIs and Self-Service Capabilities)Nice-to-have. Goes far deeper into one product than the CNPE asks.
ICAService mesh: mTLS, authorization policy, traffic shifting for canariesPart of 15% (Security and Policy Enforcement)Optional. Deep, hands-on and excellent — but a lot of exam for a slice of a 15% domain.
CCAeBPF data plane, identity-based network policy, HubbleBelow the stated domainsOptional. CNI internals sit under the CNPE’s five domains rather than in them. Take it for the job, not the exam.
KCNAEcosystem vocabulary and Kubernetes fundamentalsAssumed backgroundOptional. Valuable if you’re new; redundant if you already hold CKA.
KCSAThreat models, the 4Cs, Pod Security Standards, security frameworksPart of 15% (Security and Policy Enforcement)Optional. A pleasant cheap read; not a mark-mover on its own.
CKADWorkload authoring and debugging from your users’ side of the fenceAssumed backgroundOptional. Excellent empathy training, largely redundant with CKA for exam purposes.
CKSDeep hardening, supply chain, runtime detectionOvershoots 15% (Security and Policy Enforcement)Optional. Far deeper than the CNPE needs, and gated behind a CKA. A career move, not a prep move.
◆ Key idea

If you take exactly two certifications before the CNPE, take CKA and CGOA. CKA gives you the hands the exam assumes; CGOA gives you a quarter of the blueprint. Everything else on the shelf is a career decision rather than a CNPE decision — which is a perfectly good reason to take it, just not the reason people usually give.

🦆 Dot’s-eye view

“I did KCNA, then KCSA, then CCA, then CBA — four badges in a year, and I still froze the first time someone handed me a real broken cluster. Nobody had ever timed me. The badge that changed my job was the one that made me type.”

Kubestronaut & Golden Kubestronaut

☺ Like you’re 10: If you collect a whole set of badges and have them all valid at the same moment, the CNCF gives you a special title — and a jacket. Keeping the jacket means keeping the badges fresh; the bigger title, once you have it, is yours for good.

Beyond the individual certifications, the CNCF runs recognition programmes for people who hold several at once. They are not exams and you don’t register for them: you qualify automatically by holding the required certifications simultaneously and in good standing, and the CNCF then invites you into the programme.

Kubestronaut is the long-running one: it recognises individuals holding the five Kubernetes certifications — KCNA, KCSA, CKA, CKAD and CKS — all active at the same time. Recipients get a title, a digital badge, and the well-known jacket, plus community perks such as a private channel and discounts. Golden Kubestronaut is the newer, considerably harder tier: it recognises people who have passed the CNCF’s entire certification catalogue — every one of the fifteen in the table above — together with the Linux Foundation’s Linux administration credential, LFCS. Sixteen exams, in other words, of which two are the CNPE and CNPA.

The two programmes differ in one way that matters more than the badge count, and it is routinely got wrong: Kubestronaut has to be maintained, Golden Kubestronaut does not. The CNCF’s FAQ is explicit that the Kubestronaut title lapses at the end of the calendar year in which the first of your five certifications expires — so keeping it means a permanent renewal rota. Golden Kubestronaut, once earned, is described as kept for life; new certifications launching afterwards do not retroactively un-Golden you, and letting the underlying exams lapse does not either. (The one thing tied to staying current is the subscription perk, not the title.) Read the programme page for the current rules rather than trusting the summary above.

⚠ The qualifying list moves — check it, don’t assume it

These programmes are defined by a list of certifications, and that list grows every time the CNCF launches a new exam — CNPA and CNPE are recent additions to the catalogue, and newer project associates keep arriving. That means the entry requirement for Golden Kubestronaut is a moving target: the target you are chasing today may be one exam longer by the time you get there. What is not a moving target, per the CNCF’s own FAQ, is what happens to people who have already qualified — a new certification launching afterwards does not revoke Golden status. Either way, do not plan a year of study from any third-party summary, including this one. Read the official CNCF programme page for the current qualifying list, the “all certifications must be active” rule, and how renewals are handled.

↗ CNCF Kubestronaut programme ◆ CNCF certification catalogue ◆ Official curriculum repository

⌁ Note · the renewal maths nobody mentions

Qualifying for either programme requires the relevant certifications to be active at the same time. CNCF certifications generally run for two years and they don’t all expire together, so assembling a large collection means racing your own earliest expiry — pass CKA first and take three years over the rest, and you will be re-sitting CKA before you finish. Retaining is where the two programmes part company: Kubestronaut lapses at the end of the calendar year your first certification expires, which makes it a genuine recurring commitment rather than a one-off achievement, whereas Golden Kubestronaut is kept for life once earned. So the honest reading is: Golden is an expensive sprint with a permanent trophy; plain Kubestronaut is a subscription. Both are fine goals if the recognition motivates you; neither is a shortcut to the CNPE.

Beyond the CNCF shelf — the certifications next door, by provider

☺ Like you’re 10: The CNCF badges aren’t the only ones. Other companies make their own, and some of them matter a lot for a platform job — especially if your platform runs on one particular cloud. They’re sorted below by who makes them, because each company has its own rules.

Everything above is CNCF-and-Linux-Foundation. But job adverts for platform roles routinely name credentials from outside that catalogue, and pretending otherwise would give you a misleading map. These are different programmes with different rules — different vendors, different validity periods, different renewal mechanics, different pricing, and in several cases exams that are neither knowledge-based multiple choice nor CNCF-style performance tasks. Nothing on this page’s tier-and-format model transfers to them automatically; each has its own page here with its own logistics.

They matter for two distinct reasons. First, your platform runs on something — a cloud, an infrastructure-as-code tool, a secrets manager, a Git host — and the vendor certification for that thing is often what a hiring manager recognises. Second, LFCS is the one non-CNCF exam that appears inside a CNCF programme: it is the sixteenth requirement for Golden Kubestronaut.

These eleven pages are grouped by the organisation that sells them — ten providers — and the sidebar is grouped identically, so you can move between the map and the menu without translating. Grouping by provider rather than by topic is deliberate: the provider is what sets the price, the format, the validity period, the retake policy and the renewal mechanics, and those are the things that actually differ. Two exams from the same vendor almost always share those rules; two exams about the same subject from different vendors almost never do.

PlatformEngineering.org — the other vendor-neutral line

HashiCorp — infrastructure as code and secrets

AWS · Microsoft · Google Cloud — one per cloud

Red Hat & the Linux Foundation — the substrate underneath

GitHub & GitLab — where your pipelines actually live

PeopleCert & DASA — the practice credentials

Read each one alongside the lesson it maps onto: IaC and control planes for Terraform and Crossplane, secrets management for Vault and External Secrets, CI/CD and progressive delivery for the two Git-host programmes, and reliability and incidents for the SRE practice ones. As ever, the lesson is the learning and the certificate is only the receipt. One note on the Git hosts specifically: they were a single page here until recently, and separating them was not cosmetic. The two programmes now differ in almost every mechanic that matters — where you sit the exam, who proctors it, what it costs, and how often the content is rebuilt — so a merged page could only describe them at a level of generality that helped nobody.

⚠ Don’t import the rules from one programme into another

Validity periods, retake policies, recertification mechanics and “does this expire?” are set by each vendor independently, and they differ sharply — some vendor certifications expire in two years, some in three, some effectively never, and some are retired outright when the product changes. The two-year, one-retake, twelve-month-eligibility shape described earlier on this page is a Linux Foundation pattern and nothing more. Read each programme’s own terms.

Studying for a knowledge exam vs a performance exam

☺ Like you’re 10: For a “pick the answer” test you read and quiz yourself. For a “show me” test you practise with your hands until you stop thinking. Doing the first kind of study for the second kind of test is how people fail.

This is the most common preparation mistake on the whole shelf: candidates who passed three associate exams by reading assume the same method will carry them through a performance exam. It will not. The two formats punish different weaknesses and reward different habits, and you should switch modes deliberately depending on which you’ve booked.

Preparing for a knowledge-based exam

Your enemy is fuzzy recall. You will meet four plausible options where three are almost right, and “I basically know this” collapses under that pressure. So the work is: read the official curriculum first and turn every competency into a question; read the primary documentation rather than blog summaries; and then drill active recall — closing the page and reciting the answer — rather than re-reading, which feels productive and isn’t. Take mock exams under time, and treat every wrong answer as a note to write, not a fact to reread. On this site: the flashcards, the quiz, the glossary, and the CNPA mock exam are built for exactly this mode.

Preparing for a performance-based exam

Your enemy is the clock, and the antidote is repetition at a keyboard. Reading about kubectl builds no speed at all. You need a throwaway cluster (kind, minikube, k3d), the same tasks done until your hands go on autopilot, and a habit of setting context and namespace before touching anything. Practise the patterns and look up the syntax — but know which documentation you’re actually allowed to open, because it is published per exam and it is narrower than most candidates assume. At the time of writing the Linux Foundation’s exam resources allowed page gives the CNPE only kubernetes.io/docs and kubernetes.io/blog, plus whatever task-specific links appear in a question’s Quick Reference box — no Argo CD docs, no Helm docs, no Backstage docs, nothing for the very tools the delivery and self-service domains are about. CKA and CKAD get Helm’s documentation on top of that (and CKA the Gateway API site); CKS gets a much longer list including Falco, etcd, Cilium and Istio. Check the page for your exam and your date, then practise inside exactly that boundary — discovering it on the day is a very expensive way to learn it. On this site: the lab track, the practice tasks, the speed reference, Know It Cold, the triage playbook, the delivery triage drills, and the timed mock exams are the performance-mode kit.

Study dimensionKnowledge-based examPerformance-based exam
Primary activityRead, condense, recallType, break, fix, repeat
Best single resourceThe official curriculum, turned into questionsA throwaway cluster you rebuild constantly
What “ready” feels likeYou can define every term without hedgingYou can do the task without stopping to think
Mock strategyTimed question sets; log every wrong answerTimed task drills; verify every result before moving on
DocumentationNot available in the exam — memoriseAvailable but limited; practise navigating it fast
Classic failureRecognising an answer you can’t reproducePerfect work in the wrong cluster or namespace
Last week beforeRecall drills and a full mock paperSimulator sessions and full timed runs
Site kitFlashcards, quiz, glossary, CNPA mockLab track, practice tasks, speed reference, mock exams
🦫 Benny’s format-switch drill · 20 min

Prove to yourself which mode you’re in. Pick one small task — “create a Deployment with a resource limit and expose it” — and do it twice. First, write down the manifest from memory on paper; that’s knowledge mode, and it should feel comfortable if you’ve been reading. Then, on a throwaway cluster with a 4-minute timer, actually create it, expose it, and curl it; that’s performance mode. Most people discover a startling gap between the two. Whichever side is weaker is where your next five evenings go. If you’re headed for the CNPE, run this drill weekly with tasks pulled from the GitOps, platform API and security practice sets.

Cost, time and honest expectations

☺ Like you’re 10: Each badge costs real money and real evenings. It’s worth doing the sums before you start, because the total surprises people.

Two costs matter and only one of them shows up on the invoice. The money is straightforward, and the Linux Foundation’s published list prices cluster into two clean bands: the associate exams are listed at US$250 exam-only, and the two-hour performance-based exams — CKA, CKAD, CKS and the CNPE — at US$445. Every one of them is listed as including a retake, twelve months of eligibility to schedule, and a certification valid for two years. ICA is the anomaly again: hands-on in format, US$250 in price. But the Linux Foundation runs frequent promotions, bundles (an exam-plus-subscription option is usually offered alongside each exam) and regional pricing, so the number at checkout is often not the number on the page. Never budget from a third-party figure, including this one.

The time is the cost that actually hurts, and nobody invoices you for it. The figures below are honest planning estimates from how these curricula are built and how candidates describe their preparation — they are not official, and your own background moves them enormously in both directions.

Kind of examTypical sittingRealistic preparationWhat dominates the effort
Broad associate (KCNA, KCSA)Around 90 minutes2–5 weeks part-timeBreadth of vocabulary; nothing is deep, but there’s a lot of it
CNPA120 minutes — the one published exception to the 903–5 weeks part-timeBreadth again, but weighted: Core Fundamentals alone is 36% of the paper
Project associate (CGOA, CAPA, CBA, CCA, KCA, OTCA, PCA)Around 90 minutes1–4 weeks part-time if you use the tool; longer if you don’tOne product’s specifics — cheap when it’s your daily tool, expensive when it isn’t
Performance-based professional (CKA, CKAD)Typically 2 hours6–12 weeks with regular lab timeSpeed. The knowledge arrives long before the hands do
Performance-based specialist / senior (CKS, ICA, CNPE)Typically 2 hours8–16 weeks, assuming prior cluster fluencyBreadth plus speed, across tools you may not use daily

Run the maths across a whole plan before you commit. Four associate exams plus two performance exams is not “six certifications” — it’s the better part of a year of evenings, several hundred dollars, and a renewal schedule that starts ticking the day you pass the first one. That’s a perfectly reasonable investment if the certifications are on the line to where you’re going. It’s a genuinely bad one if you’re collecting. For a cost-conscious way to think about this, FinOps makes the same argument about cloud spend that Sol makes about certification spend: the cheapest resource is the one you never provisioned.

⚠ Everything on this page has a shelf life — the official pages are the only authority

Prices, exam durations, question counts, cut scores, retake and renewal policies, proctoring rules, the domain weights themselves, which exams are performance-based, and even which certifications exist all change — sometimes several times a year. New exams launch, curricula are revised to new Kubernetes versions, and programme requirements are re-scoped. This page reflects the landscape in 2026 and the curricula as published. Before you spend anything, read the current Linux Foundation certification catalogue, the CNCF certification page and the candidate handbook for the specific exam, end to end. If anything here disagrees with them, they are right and this page is stale. Verify, then pay.

🎬 At the Platform Guild
🦊

Foxy: Right. Fifteen certifications. I’ve made a spreadsheet. I’m going to get all of them.

🦉

Professor Owl: To what end? Name the job you want. Then name the badge its advert asks for.

🦊

Foxy: …Platform engineer. And the advert says CKA, and “CNPE a plus.”

🦉

Professor Owl: Then you have two, not fifteen. Add CGOA if you want a quarter of the CNPE blueprint for very little money. Everything else is a hobby.

👺

Gizmo: But the jacket, Foxy. Collect all fifteen and you get a jacket. 🧥✨

🦉

Professor Owl: Five, Gizmo. The jacket is Kubestronaut, and Kubestronaut is the five Kubernetes exams — KCNA, KCSA, CKA, CKAD, CKS — held active at once. All fifteen plus LFCS is Golden, which is a different animal entirely.

🦥

Sol: And the jacket one has to be re-earned. Let any of the five lapse and the title goes at the end of that year — a renewal bill in a rolling schedule you’ll never finish. Golden you keep forever, mind. That’s the only one you can actually finish.

🐿️

Nutty: Ooh — I checked, and the associate exams are ninety minutes of multiple choice with no terminal at all! So the one I was dreading is actually the cheap one?

🦉

Professor Owl: Mostly. Watch ICA — it wears an associate badge and an associate price, but the listing calls it performance-based and multiple-choice. Read the format, never the name.

🐼

Master Panda: Yes. And the one you weren’t dreading is the one that needs your hands, three months in advance. Pick the order on purpose, Foxy. One at a time. The wall isn’t going anywhere.

So: choose the shortest honest line between where you are and the role you want, and let the badges be evidence of that journey rather than a substitute for it. If the CNPE is your destination, your next stop is the exam guide for the logistics and the ten-week plan, then field notes to hear from people who’ve already sat in that chair. If you’re earlier on the path, start with CNPA or KCNA and come back to this page in six months — by then, both you and the landscape will have moved.

🐢 Timmy’s checkpoint

1. What are the two axes this page uses to sort the certifications, and why do people confuse them? 2. Which certification on this shelf is the only one with a formal prerequisite, and what is it? 3. If you could take only two certifications before the CNPE, which two and why? 4. Which CNPE domain does CGOA map onto, and what is it worth? 5. Name two things that make studying for a performance-based exam different from a knowledge-based one. 6. What is the recurring, easily-forgotten cost of a Kubestronaut-style collection?

Check your answers
  1. Tier (associate vs professional/specialist — how senior the credential reads) and format (knowledge-based multiple choice vs performance-based on live clusters — how you’ll study). They’re confused because the tiers mostly line up with the formats — but not always, which is why the format column exists in the master table.
  2. CKS — you must have taken and passed the CKA exam before attempting it. Everything else, including the CNPE, can be booked with no prior certification.
  3. CKA and CGOA. CKA builds the kubectl fluency and clock-pressure habits the CNPE assumes but never teaches; CGOA maps almost directly onto a full 25% domain.
  4. The GitOps & Continuous Delivery domain, worth 25% — one of the CNPE’s two joint-largest.
  5. Any two of: performance prep is repetition at a keyboard rather than reading; the enemy is the clock rather than fuzzy recall; documentation is available (but restricted) rather than absent, so navigation speed matters; the classic failure is doing perfect work in the wrong cluster or namespace; and cramming works a little for recall but not at all for muscle memory.
  6. To qualify, every required certification must be active simultaneously — and since CNCF certifications generally run two years and expire on different dates, assembling the set means racing your own earliest expiry. To keep Kubestronaut you must then keep renewing: the title lapses at the end of the calendar year in which the first of the five expires, so it behaves like a subscription. Golden Kubestronaut is the exception — once earned it is kept for life, and later exams launching does not revoke it.