For 30 years, CSIRT work and cybersecurity have been practiced by a diverse community of technically inclined, curious problem solvers, and we have made great strides in the practice over that time. However, if we are going to tackle the tough problems that lie ahead, including the need to massively expand the number of qualified cybersecurity workers and the need to have our voices heard in policy and legislative discussions, we need to professionalize: “to make an activity into a job that requires special education, training, or skill.”It’s time for our community to adopt standards of education, training and conduct to ensure we can be trusted to do the right thing and that we can scale up our talent pool without dilution or pollution. This leads to a large number of difficult questions, such as: What are the technical and ethical standards for a CSIRT member (or any cybersecurity professional)? What should they be? How should we govern ourselves, and what kinds of “barriers to entry” should we establish?This talk will discuss some of the positive and negative impacts that might come from professionalization, some steps we need to take as a community, and why our field needs to go ahead and do it sooner rather than later.