Why I Didn’t Pursue ISO 27001 or ITIL Certification as a Technical Author (And Why That Matters)

Do technical authors need ISO 27001 or ITIL certification? This article challenges the assumption, explaining why real-world experience often delivers more value than foundation-level qualifications—and when certification actually makes a difference.

Introduction

Over the years, interviewers have asked me the same question. One topic that often comes up is the debate between technical author vs certification, which frequently leads to interesting discussions about their respective merits.

“You’ve worked with ISO 27001, ITIL, GDPR, PCI… why didn’t you complete the certifications?”

On the surface, it looks like a gap. Technical Authors v Compliance.

It reflects a deliberate decision about where the role of a technical author begins—and where it should not drift.


The Assumption Behind Certification

Many organisations assume that working alongside standards such as:

      • ISO/IEC 27001
      • ITIL
      • GDPR
      • PCI DSS

naturally leads to certification.

Foundation becomes Practitioner.
Practitioner becomes Expert.

This progression makes sense for:

      • Information Security Managers
      • Service Delivery Leads
      • Compliance Officers

But it does not automatically apply to technical authors.


The Role of the Technical Author in Compliance

A technical author does not own the framework.

The role is to:

      • Translate requirements into structured documentation
      • Align content with controls and governance models
      • Ensure documentation supports audit evidence
      • Create a single, coherent source of truth

In simple terms:

The framework defines what must exist.
The technical author ensures it is documented, usable, and defensible.


What Experience Delivers That Certification Does Not

After working across multiple compliance-driven projects, patterns become clear:

      • Policies that do not reflect actual operations
      • Processes that lack sequence or ownership
      • Controls that exist conceptually but not in documentation
      • Repositories with no lifecycle, governance, or consistency

These are not theoretical problems.

They are the reasons organisations fail audits.

Understanding how to fix them comes from:

      • exposure to failed documentation environments
      • Rebuilding
        The compliant Technical Author
        The complaint technical author

        structures under pressure

      • aligning documentation to real-world operations

This is applied capability, not classroom knowledge.


The Certification Trade-Off

Certifications do provide value.

They:

      • Improve credibility with recruiters and procurement
      • Help pass automated CV filtering
      • Provide standardised terminology

However, they also introduce a shift in perception.

If I had progressed to practitioner level, there is a strong likelihood:

I would no longer be seen as a technical author.

Instead, I would be positioned as:

      • a compliance specialist
      • a governance lead
      • a service manager

That is a different role, with different expectations.


The Reality in Delivery Environments

There is an uncomfortable but consistent observation across projects:

Some certified professionals struggle to produce:

      • clear policies
      • usable processes
      • audit-ready documentation

Experienced technical authors often:

      • stabilise failing documentation environments
      • restructure repositories
      • enable organisations to pass audits

without holding formal certifications.


Knowing Enough to Deliver

There is a phrase that often needs clarification:

“I know enough.”

This does not imply limited understanding.

It means:

      • understanding the intent behind standards
      • knowing how to translate that intent into documentation
      • ensuring that documentation stands up to audit scrutiny

It also means recognising boundaries.

A technical author’s strength lies in application, not ownership.


When Certification Does Make Sense

There are situations where certification adds clear value:

      • Building a consultancy offering
      • Productising compliance services
      • Working in procurement-heavy environments
      • Increasing commercial positioning for senior roles

In these cases, certification supports:

      • trust
      • marketability
      • pricing leverage

Cost vs Return

Foundation certifications typically cost:

      • £500 to £1,500 per course

Covering multiple frameworks can exceed:

      • £3,000 to £4,500

For knowledge that often overlaps with existing experience.

The return is therefore not always proportional—particularly for experienced practitioners.


The Positioning That Matters

The distinction is important:

A certified professional understands the framework.
A technical author ensures the organisation can prove it is working.

These are complementary roles—but not the same role.


Conclusion

When asked why I did not pursue certifications, the answer remains consistent:

My value does not come from owning the framework.
It comes from making it work—through structured, controlled, audit-ready documentation.

In environments where documentation determines the success or failure of an audit, that distinction matters.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.