# Free Security & AI-Security Learning Library — PlayCISO > 30 hand-picked, genuinely free courses and certifications for cybersecurity and AI-security professionals. Curated by PlayCISO (https://playciso.com/learn). Every link goes directly to the provider; PlayCISO is not affiliated with them. Each entry lists: provider, level (Beginner/Intermediate/Advanced), approximate time, format, whether it earns a certificate, and how it is free. ## Fundamentals - **[Certified in Cybersecurity (CC)](https://www.isc2.org/certifications/cc)** — ISC2. Free training + free exam for an entry-level, globally recognised cyber certification. _(Beginner · ~15 hrs · Certification · Free · earns a certificate)_ - **[Google Cybersecurity Certificate](https://www.coursera.org/professional-certificates/google-cybersecurity)** — Google / Coursera. Job-ready foundation across SIEM, Linux, Python, and incident response. Audit for free. _(Beginner · 120+ hrs · Certification · Free to audit · earns a certificate)_ - **[Microsoft SC-900: Security Fundamentals](https://learn.microsoft.com/en-us/training/courses/sc-900t00)** — Microsoft Learn. Security, compliance, and identity fundamentals across the Microsoft cloud. _(Beginner · ~10 hrs · Course · Free)_ - **[Fortinet Certified Fundamentals](https://www.fortinet.com/training/cybersecurity-professionals)** — Fortinet. Free self-paced training and certification path in network security fundamentals. _(Beginner · ~30 hrs · Certification · Free · earns a certificate)_ - **[Introduction to Cybersecurity](https://www.netacad.com/courses/cybersecurity)** — Cisco Networking Academy. Threats, attacks, and how to protect yourself and organisations — with a badge. _(Beginner · ~15 hrs · Course · Free · earns a certificate)_ ## AI & LLM Security - **[OWASP Top 10 for LLM Applications](https://genai.owasp.org)** — OWASP. The definitive risk list for LLM apps: prompt injection, data leakage, and more. _(Intermediate · ~4 hrs · Reading · Free)_ - **[Hugging Face LLM Course](https://huggingface.co/learn/llm-course)** — Hugging Face. Transformers, fine-tuning, and deploying LLMs hands-on — the community standard. _(Intermediate · ~25 hrs · Course · Free)_ - **[Hugging Face AI Agents Course](https://huggingface.co/learn/agents-course)** — Hugging Face. Build and evaluate autonomous agents; earn a certificate on completion. _(Intermediate · ~20 hrs · Certification · Free · earns a certificate)_ - **[Cohere LLM University](https://cohere.com/llmu)** — Cohere. From embeddings to RAG to deployment, taught clearly from first principles. _(Beginner · ~15 hrs · Course · Free)_ - **[5-Day Gen AI Intensive](https://www.kaggle.com/learn-guide/5-day-genai)** — Google / Kaggle. Intensive on prompting, embeddings, agents, and MLOps for generative AI. _(Intermediate · ~20 hrs · Course · Free)_ - **[DeepLearning.AI Short Courses](https://www.deeplearning.ai/short-courses)** — DeepLearning.AI. Bite-size, hands-on courses on RAG, agents, evaluation, and safety. _(Beginner · ~2 hrs · Video Series · Free)_ - **[Intro to LangGraph & Deep Agents](https://academy.langchain.com)** — LangChain Academy. Build stateful, multi-step agent graphs with the LangGraph framework. _(Advanced · ~8 hrs · Course · Free)_ - **[W&B AI Academy](https://www.wandb.courses)** — Weights & Biases. LLM evaluation, MLOps, and production monitoring, with completion certificates. _(Intermediate · ~10 hrs · Course · Free · earns a certificate)_ ## Cloud Security - **[Cloud Security Academy](https://www.wiz.io/academy)** — Wiz. Deep, practical explainers on cloud attack paths, CSPM, CNAPP, and identity. _(Intermediate · ~6 hrs · Reading · Free)_ - **[AWS Security Learning Plan](https://skillbuilder.aws)** — AWS Skill Builder. Official AWS security curriculum: IAM, detection, data protection, incident response. _(Intermediate · ~20 hrs · Course · Free)_ - **[Microsoft SC-200: Security Operations](https://learn.microsoft.com/en-us/training/courses/sc-200t00)** — Microsoft Learn. Threat detection and response with Microsoft Sentinel and Defender. _(Intermediate · ~20 hrs · Course · Free)_ ## Application Security - **[Web Security Academy](https://portswigger.net/web-security)** — PortSwigger. The gold standard for web AppSec: interactive labs from the makers of Burp Suite. _(Intermediate · 40+ hrs · Hands-on Labs · Free)_ - **[OWASP Top 10](https://owasp.org/www-project-top-ten/)** — OWASP. The foundational awareness document for web application security risks. _(Beginner · ~3 hrs · Reading · Free)_ - **[Secure Code Warrior (free tier)](https://www.securecodewarrior.com)** — Secure Code Warrior. Gamified secure-coding challenges across many languages and frameworks. _(Intermediate · ~8 hrs · Hands-on Labs · Free tier)_ ## Offensive / Pentesting - **[TryHackMe (free rooms)](https://tryhackme.com)** — TryHackMe. Guided, gamified hacking rooms — one of the best on-ramps into offensive security. _(Beginner · 40+ hrs · Hands-on Labs · Free tier)_ - **[HTB Academy (free modules)](https://academy.hackthebox.com)** — Hack The Box. Structured offensive-security modules with hands-on labs and a clear skill path. _(Intermediate · ~30 hrs · Hands-on Labs · Free tier)_ - **[PentesterLab (free exercises)](https://pentesterlab.com)** — PentesterLab. Real, isolated vulnerabilities to exploit and learn web pentesting properly. _(Intermediate · ~15 hrs · Hands-on Labs · Free tier)_ ## Blue Team / IR - **[LetsDefend (free path)](https://letsdefend.io)** — LetsDefend. A hands-on SOC analyst simulator — investigate real alerts in a browser. _(Beginner · ~20 hrs · Hands-on Labs · Free tier)_ - **[Blue Team Labs Online](https://blueteamlabs.online)** — Security Blue Team. Defensive challenges and investigations: forensics, IR, and threat hunting. _(Intermediate · ~20 hrs · Hands-on Labs · Free tier)_ - **[CISA Cyber Training](https://www.cisa.gov/resources-tools/training)** — CISA. Free government-grade training across IR, ICS, and cyber defence. _(Beginner · ~10 hrs · Course · Free)_ ## GRC & Compliance - **[NIST Cybersecurity Framework](https://www.nist.gov/cyberframework)** — NIST. Learn the framework that anchors modern risk and controls programmes. _(Intermediate · ~6 hrs · Reading · Free)_ - **[PCI DSS Document Library](https://www.pcisecuritystandards.org/document_library/)** — PCI SSC. The source standards, SAQs, and guidance — pair it with PlayCISO’s PCI tools. _(Intermediate · ~8 hrs · Reading · Free)_ - **[Open Security Training 2](https://ost2.fyi)** — OpenSecurityTraining. University-depth, free courses on architecture, trusted computing, and more. _(Advanced · 40+ hrs · Course · Free)_ ## Leadership - **[SANS Free Webcasts & Resources](https://www.sans.org/webcasts/)** — SANS. Expert-led sessions on strategy, threats, and building security programmes. _(Intermediate · ~2 hrs · Video Series · Free)_ - **[Cybersecurity Leadership & Management](https://www.coursera.org/courses?query=ciso)** — Coursera. Governance, risk communication, and leading teams — audit tracks for free. _(Advanced · ~20 hrs · Course · Free to audit)_ --- PlayCISO turns this theory into practice: a War Room incident simulator, a simulated PCI DSS QSA interview, and board-report coaching. https://playciso.com