File 015 | What Do Bob Morales’s “Certifications” Actually Certify?
- July 15, 2026
Editorial illustration. This image is a satirical depiction and is not a photograph.
Bob Morales prominently identifies three credentials as “Certifications” in his professional email signature: CNSS-4016A, NIST 800-30 and NIST 800-39. But what exactly do those designations represent—and what does it mean to be “certified” in them?
Ordinarily, there would be little reason to examine the credentials someone chooses to include in an email signature.
In this case, however, Morales himself made those credentials relevant.
During a recorded discussion concerning the use of ChatGPT in research and analysis, Morales dismissed the technology in unusually direct terms:
“Well, whatever ChatGPT says, you know that we have to abide by that bullshit, right?”
He subsequently invoked his own credentials while distinguishing his analysis from that produced with the assistance of ChatGPT:
“I guarantee you whoever uses ChatGPT does not have my certifications. They don’t have them.”
Morales acknowledged that he also uses ChatGPT, describing his use as being for “organizational value” and “deep research.” But he distinguished his substantive writing by referring to his experience in risk mitigation and “the certification.”
That raises a straightforward question.
What exactly are the certifications Morales so prominently displays—and what do they actually certify?
The Credentials Morales Identifies
Morales identifies three:
CNSS-4016A
NIST 800-30
NIST 800-39
The distinction between training in a standard and professional certification by the organization responsible for that standard becomes important here.
Two of the three designations are publications of the National Institute of Standards and Technology.
And NIST itself is quite clear about what they are.
NIST SP 800-30: A Guide for Conducting Risk Assessments
Morales displays NIST 800-30 as one of his certifications.
NIST, however, identifies SP 800-30 Revision 1 as:
“Guide for Conducting Risk Assessments.”
According to NIST, the purpose of the Special Publication is to provide guidance for conducting risk assessments of federal information systems and organizations.
NIST also categorizes SP 800-30 as a “Guideline/Tool.”
In other words, SP 800-30 is a publication.
It establishes risk-assessment guidance and methodology. It is not itself the name of an individual professional credential awarded by NIST.
There is another potentially important detail.
The original NIST SP 800-30 was published in July 2002. NIST records show that version was withdrawn on September 1, 2012 and superseded by SP 800-30 Revision 1.
The current Revision 1 remains guidance for conducting risk assessments.
This does not mean that training based upon SP 800-30 is meaningless. Quite the opposite: learning to apply NIST risk-assessment methodology can plainly constitute substantive professional training.
But that is a different proposition from saying that NIST SP 800-30 itself is a professional certification held by an individual.
NIST SP 800-39: Organization-Wide Risk Management Guidance
The same distinction appears with NIST SP 800-39.
Its full title is:
Managing Information Security Risk: Organization, Mission, and Information System View.
NIST describes the purpose of SP 800-39 as providing guidance for an integrated, organization-wide program for managing information-security risk.
NIST separately categorizes SP 800-39 as a “Guideline/Tool.”
Again, this is significant risk-management material. NIST describes SP 800-39 as establishing a structured approach to managing information-security risk across an organization, and the publication forms part of NIST’s broader Risk Management Framework.
But once again, the designation refers to the publication and its guidance—not an individual professional certification called “NIST 800-39.”
A person can study it.
A training organization can teach material based upon it.
A person can complete that training.
Those facts do not transform the underlying NIST Special Publication into an individual certification issued by NIST.
What Morales’s Certificates Actually Say
This is where Morales’s own documentation becomes particularly useful.
The certificates do not need to be dismissed, disparaged or characterized as worthless.
They simply need to be read.
The certificates document that Morales “successfully completed” specified training associated with the identified standards or publications.
That is an accomplishment.
It is also a much more precise description of what occurred.
Morales completed training.
The question is whether presenting the resulting documents under the professional heading “Certifications” reasonably communicates the same thing.
CNSS-4016A: A Historical Training Credential
The third credential Morales identifies is CNSS-4016A.
Unlike the two NIST designations discussed above, Morales possesses a certificate stating that he successfully completed the National Information Assurance Training Standard CNSS-4016A “for Certification as a Risk Analyst.”
The certificate is dated December 6, 2013.
For purposes of this examination, there is no reason to dispute that Morales completed the training reflected on the certificate or that Auburn University issued it.
The more relevant question is what that credential represents today.
CNSS-4016A belongs to an earlier generation of federal information-assurance workforce training standards. Since Morales received the certificate, the federal cybersecurity workforce structure has evolved substantially.
In 2017, NIST published the NICE Cybersecurity Workforce Framework, establishing a common framework for describing cybersecurity work and the knowledge, skills and abilities associated with that work. That framework was revised in 2020 and continues to be updated today.
The current NICE Framework organizes cybersecurity work through work roles, competency areas, tasks, knowledge and skills.
Accordingly, Morales’s 2013 CNSS-4016A certificate is evidence of training completed under a historical federal training standard. It should not be confused with evidence that the underlying 2013 standard represents the current federal cybersecurity workforce framework.
Expertise Does Not Eliminate the Need for Scrutiny
Professional training and experience deserve appropriate weight. They do not, however, place someone’s conclusions beyond examination.
That distinction becomes particularly important when credentials are invoked not simply as evidence of one’s own training, but as a basis for dismissing research or analysis produced by others.
Morales did exactly that when he stated:
“I guarantee you whoever uses ChatGPT does not have my certifications. They don’t have them.”
Morales continued by characterizing those credentials more specifically:
“…because these are government-issued certifications.”
That characterization makes the nature and source of the credentials independently relevant. A credential involving a government standard or publication is not necessarily the same thing as a credential issued by the government.
The significance of that statement is not that Morales believed his own analysis was superior. Professionals routinely disagree.
The significance is that Morales himself made his credentials part of the argument.
Once a credential is offered as a reason that one person’s analysis should carry greater authority than another’s, it is entirely reasonable to ask what that credential is, who issued it, what was required to obtain it, and what the designation actually represents.
That examination is not a dismissal of expertise.
It is due diligence.
“Annual Certification Continuing Education”
There is one additional piece of evidence.
In a May 28, 2024 text message, Morales wrote:
“Okay, I’m in my annual certification continuing education. I’ll call after class.”
That statement should not be attributed to any of the three credentials discussed above without further evidence.
Morales does not identify the certification in the message.
He may have been referring to another credential entirely.
Accordingly, the message establishes only that Morales represented himself as participating in annual continuing education associated with a certification. It does not establish that NIST SP 800-30, NIST SP 800-39 or CNSS-4016A was the credential he meant.
That distinction is worth preserving.
So What Do the “Certifications” Actually Represent?
Based upon the documentation examined, at least two answers are straightforward.
NIST SP 800-30 is a NIST Special Publication providing guidance for conducting risk assessments.
NIST SP 800-39 is a NIST Special Publication providing organization-wide information-security risk-management guidance.
Morales’s certificates document that he “successfully completed” Federal Information Services Modernization Act training associated with Special Publications 800-30 and 800-39.
That does not make the training insignificant. But completing training associated with a NIST Special Publication and holding an individual professional certification issued by NIST are not the same thing.
And that is ultimately why the terminology matters.
Morales did not merely list courses he had taken. He placed these designations under the heading “Certifications.” He then expressly invoked his “certifications” when contrasting his expertise with research and analysis produced using ChatGPT.
Once he chose to make that distinction, examining precisely what those credentials represent became fair—and necessary.
The documentation should speak for itself.



