arXiv · 2604.20389
CyberCertBench: Evaluating LLMs in Cybersecurity Certification Knowledge
Abstract
The rapid evolution and use of Large Language Models (LLMs) in professional workflows require an evaluation of their domain-specific knowledge against industry standards. We introduceCyberCertBench, a new suite of Multiple Choice Question Answering (MCQA) benchmarks derived from industry recognized certifications. CyberCertBench evaluates LLM domain knowledgeagainst the professional standards of Information Technology cybersecurity and more specializedareas such as Operational Technology and related cybersecurity standards. Concurrently, we propose and validate a novel Proposer-Verifier framework, a methodology to generate interpretable,natural language explanations for model performance. Our evaluation shows that frontier modelsachieve human expert level in general networking and IT security knowledge. However, theiraccuracy declines in questions that require vendor-specific nuances or knowledge in formalstandards, like, e.g., IEC 62443. Analysis of model scaling trend and release date demonstratesremarkable gains in parameter efficiency, while recent larger models show diminishing returns.Code and evaluation scripts are available at: https://github.com/GKeppler/CyberCertBench.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Gustav Keppler, Ghada Elbez, Veit Hagenmeyer. 2026-04-22. CyberCertBench: Evaluating LLMs in Cybersecurity Certification Knowledge. https://arxiv.org/abs/2604.20389
Cite the original work for its findings. Save a collection to share your selection of sources.