AuditXYZ

Compliance Framework

ISC2 Cybersecurity Professional Certifications (ISC2)

ISC2 certifications including CISSP are the most recognized cybersecurity professional credentials globally. This guide covers certification paths, exam requirements, costs, and career value.

$500–$5,0002–6 months2024 (ongoing certification updates)
Issuing BodyInternational Information System Security Certification Consortium (ISC2)
First Published1994-01-01
Latest Version2024 (ongoing certification updates)
Typical Cost$500–$5,000
Typical Timeline2–6 months
Audit RequiredNo
Audit FrequencyContinuing Professional Education (CPE) credits required annually. Certification renewal every 3 years with CPE and AMF.
Geographyglobal

ISC2 Cybersecurity Certifications Guide

ISC2 (International Information System Security Certification Consortium) is the world's largest nonprofit association of certified cybersecurity professionals. Its certifications — most notably the CISSP (Certified Information Systems Security Professional) — are the most widely recognized and respected cybersecurity credentials globally, held by over 600,000 professionals. For organizations, ISC2 certifications serve as a benchmark for cybersecurity workforce competency.

What ISC2 Is and Its Role in Cybersecurity Workforce Standards

ISC2 was founded in 1989 by a consortium of information security organizations seeking to standardize professional competency in the emerging field of information security. It operates as a nonprofit with a mission to inspire a safe and secure cyber world. The CISSP credential was first awarded in 1994 and remains the flagship credential over three decades later — a testament to its durability and relevance as the field has evolved from mainframe security through the internet era, cloud computing, and now AI-driven threats.

ISC2 credentials are not compliance frameworks in the traditional sense — they do not define what controls an organization must implement. Rather, they define what cybersecurity professionals must know and demonstrate. This workforce-oriented focus makes ISC2 uniquely important in the compliance ecosystem: frameworks like ISO 27001, NIST CSF, and SOC 2 require skilled people to implement them. ISC2 certifications provide the credential validation that employers, clients, and regulators use to assess whether their cybersecurity teams have that skill.

ISC2 is headquartered in the United States and maintains chapters globally. It is accredited by ANSI under ISO/IEC 17024 — the international standard for personnel certification bodies — which confirms that ISC2's certification processes meet internationally recognized standards for competence assessment, examination development, and credential maintenance.

In 2022, ISC2 launched a free entry-level certification — CC (Certified in Cybersecurity) — designed to bring more people into the cybersecurity profession. This move reflects ISC2's response to the global cybersecurity workforce shortage, which the organization estimates at nearly 4 million unfilled roles as of 2025.

The ISC2 Certification Portfolio in Depth

CISSP — Certified Information Systems Security Professional

The CISSP is the gold standard for senior cybersecurity professionals. It validates broad, deep knowledge across eight domains of the Common Body of Knowledge (CBK):

  1. Security and Risk Management — governance, ethics, compliance, risk management, threat modeling
  2. Asset Security — data classification, ownership, privacy protection
  3. Security Architecture and Engineering — secure design principles, cryptography, physical security
  4. Communication and Network Security — network architectures, protocols, secure communication channels
  5. Identity and Access Management (IAM) — access control models, identity lifecycle, authentication
  6. Security Assessment and Testing — audit, testing, penetration testing, vulnerability management
  7. Security Operations — incident response, forensics, recovery, security operations center
  8. Software Development Security — secure SDLC, application vulnerabilities, DevSecOps

CISSP holders must have at least 5 years of paid work experience in at least two of the eight domains. The exam uses Computerized Adaptive Testing (CAT) with 125–175 questions over 4 hours. CAT adapts question difficulty based on performance, providing a more precise measurement of competency than fixed exams. The exam passing standard is equivalent to a knowledge level that would be expected of a 3-year experienced practitioner across the CBK domains.

CCSP — Certified Cloud Security Professional

The CCSP validates advanced technical skills and knowledge in cloud security — an area of rapidly increasing importance as organizations move workloads to cloud platforms. CCSP covers cloud concepts and architecture, cloud data security, cloud platform and infrastructure security, cloud application security, cloud security operations, and legal, risk, and compliance. Candidates must have 5 years of IT experience including 3 years in information security and 1 year in cloud security.

The CCSP is particularly valuable for security architects, cloud engineers, and compliance professionals working with cloud-native environments. Its alignment with the CSA STAR programme and the CSA Cloud Controls Matrix makes it a natural complement to cloud security assurance work.

SSCP — Systems Security Certified Practitioner

The SSCP is positioned as the hands-on technical practitioner credential, covering access controls, security operations, risk identification and monitoring, incident response, cryptography, network communications security, and systems and application security. It requires 1 year of experience in one or more SSCP CBK domains, making it accessible to earlier-career professionals. Many CISSP candidates hold SSCP as a precursor, building toward the experience and knowledge requirements of CISSP.

CSSLP — Certified Secure Software Lifecycle Professional

The CSSLP addresses the integration of security throughout the software development lifecycle. Coverage includes secure software concepts, requirements, architecture and design, implementation and coding, testing, supply chain management, and deployment, operations, and maintenance. With software vulnerabilities remaining a primary attack vector, CSSLP-certified developers and architects provide organizations with documented competence in building security in rather than bolting it on.

CGRC — Governance, Risk, and Compliance

Formerly known as CAP (Certified Authorization Professional), the CGRC credential was rebranded in 2022 to reflect its broader applicability beyond the US government's authorization framework. CGRC validates competency in information security risk management and governance frameworks — aligning with RMF, NIST CSF, ISO 27001, and similar frameworks. It is particularly valued for compliance professionals working in regulated industries or government contexts.

CC — Certified in Cybersecurity (Entry Level)

ISC2's free entry-level certification launched in 2022. CC covers basic cybersecurity concepts: network security, security principles, access controls, incident response, and business continuity. No experience is required. The CC is designed to open the cybersecurity pathway for people transitioning from other fields, students, and early career professionals. Exam fee is currently waived for qualifying candidates; maintenance requires 45 CPE credits per 3-year cycle.

ISSAP, ISSEP, ISSMP — CISSP Concentrations

Experienced CISSP holders can pursue advanced concentrations. ISSAP (Information Systems Security Architecture Professional) focuses on security architecture at the enterprise level. ISSEP (Information Systems Security Engineering Professional) addresses systems engineering and the application of security in complex technical environments. ISSMP (Information Systems Security Management Professional) covers leadership, compliance, and management of security programs. These concentrations require active CISSP status and 2 years of relevant concentration-domain experience.

Who Benefits from ISC2 Certifications

Individual professionals use ISC2 certifications to validate expertise, advance careers, and command premium compensation. CISSP-certified professionals earn an average of 20–25% more than non-certified peers with similar experience, reflecting the market value of the credential. In many cybersecurity roles — particularly at senior levels — CISSP is a hiring prerequisite.

Organizations building cybersecurity teams use ISC2 certifications as a screening and development tool. Requiring CISSP for senior security roles, CCSP for cloud security positions, and CSSLP for security architects provides a standardized competency baseline. This is especially valuable for organizations that find it difficult to assess cybersecurity expertise through conventional interview processes.

Government agencies and defense contractors are subject to DoD Directive 8140 (formerly 8570), which maps specific cybersecurity roles to required certification levels. CISSP satisfies IA Management Level II and III requirements. SSCP satisfies IA Technical Level I and II requirements. Organizations contracting with the US Department of Defense must ensure relevant personnel hold required certifications.

Compliance programme managers overseeing ISO 27001, SOC 2, HIPAA, or similar frameworks benefit from having certified professionals leading or involved in compliance implementation. Regulatory frameworks increasingly expect evidence of qualified security professionals, and ISC2 certifications provide that evidence.

The Certification Process in Depth

Exam preparation

ISC2 provides official study materials including the Official Study Guide, practice exams, and self-paced online training. Third-party training providers offer bootcamps ranging from intensive 5-day residential courses to extended self-study programmes. Self-study time varies widely — CISSP candidates typically invest 100–200 hours of study time, though candidates with broad security experience may require less.

Sitting the exam

All ISC2 exams are administered at Pearson VUE testing centers worldwide. CISSP uses Computer Adaptive Testing: the exam adapts to the candidate's performance level, asking progressively harder or easier questions based on responses. The minimum is 125 questions; the maximum is 175 questions. If the system can determine pass or fail before 175 questions, the exam ends early. Candidates with 3–4 years of experience in relevant domains pass at approximately 70% rate on first attempt.

Experience endorsement

After passing the exam, candidates must have their experience endorsed by an active ISC2 member in good standing. The endorser verifies that the candidate has the claimed professional experience. Candidates who cannot find an endorser within the ISC2 network can request ISC2 to act as endorser, subject to additional verification.

Associate of ISC2 pathway

Candidates who pass the exam but do not yet have sufficient professional experience become Associates of ISC2. They have six years to accumulate the required experience, after which they transition to full certification. This pathway is particularly valuable for students and recent graduates who want to demonstrate knowledge while building experience.

Continuing education and renewal

Certified professionals must earn Continuing Professional Education (CPE) credits annually — 40 CPEs per year for CISSP, totaling 120 over a 3-year renewal cycle. CPEs are earned through professional development activities: attending conferences, completing training courses, writing articles, mentoring, volunteering in security communities, and similar activities. Annual Maintenance Fees (AMF) are $125 for most certifications. Failure to maintain CPE requirements or pay AMF results in certification lapsing.

Costs and Timeline

ActivityTypical CostTimeline
CISSP exam fee$7494 hours (exam)
Official study guide and materials$100 – $300Self-study
Self-study preparation$500 – $1,500 (materials + courses)3–6 months
Instructor-led bootcamp$2,000 – $5,0005 days + self-study
Annual Maintenance Fee$125/yearAnnual
CPE maintenance costs$0 – $500/yearOngoing
CCSP exam fee$599Separate exam
CC certification (entry level)Currently free1–2 hours (exam)

ISO 27001 Lead Auditor / Lead Implementer: These certifications focus on implementing or auditing ISO 27001 management systems. They are narrower in scope than CISSP but more directly relevant for professionals focused specifically on ISO 27001 compliance programmes. Many security professionals hold both CISSP and ISO 27001 credentials.

NIST CSF alignment (55% overlap): The CISSP CBK domains overlap significantly with NIST CSF's five functions — Identify, Protect, Detect, Respond, Recover. Organizations implementing NIST CSF benefit from having CISSP-certified professionals who understand the breadth of security domains the framework addresses.

CSA STAR / CCSP: The CCSP credential is specifically aligned with cloud security requirements including those addressed by CSA STAR and the CSA Cloud Controls Matrix. For cloud security roles, CCSP is more targeted than CISSP, though CISSP is still required at senior management levels.

See our best compliance automation platforms comparison for tools that help compliance-certified professionals manage framework programmes efficiently.

How Automation Helps Certified Professionals

Compliance automation platforms amplify the impact of certified security professionals by eliminating manual evidence collection, status tracking, and reporting — allowing skilled professionals to focus on governance, risk analysis, and control design rather than administrative compliance tasks. LowerPlane supports 50+ frameworks and is designed for use by compliance professionals regardless of specific framework expertise. Starting at $4,000 per year with a free tier, it is rated 9.4/10 by AuditXYZ users.

Frequently Asked Questions

Is CISSP still relevant given how much the security landscape has changed? Yes. CISSP's 2021 refresh updated domain content to address cloud security, DevSecOps, zero trust architecture, IoT security, and modern threat landscapes. The breadth of CISSP — covering management, technical, and operational domains — remains valuable precisely because senior security professionals need a broad foundation. Specialist credentials (CCSP, CSSLP) complement CISSP for depth in specific areas.

How does CISSP compare to CISM (ISACA's Certified Information Security Manager)? Both are senior cybersecurity credentials, but they emphasize different aspects. CISSP is broader, covering both technical and management domains. CISM (offered by ISACA, not ISC2) focuses specifically on security management and governance. Many organizations value both — some prefer CISM for CISOs and governance-focused roles, CISSP for technical security architects. Professionals often pursue both over time.

Can CISSP satisfy requirements under the EU's NIS2 Directive? NIS2 requires organizations to take "appropriate and proportionate technical and organisational measures" for cybersecurity risk management and requires evidence of staff security awareness and competence. CISSP-certified security professionals provide evidence of security competence that supports NIS2 compliance demonstration. CISSP is not itself a NIS2 certification scheme, but holding certified professionals on your security team is a recognized indicator of security programme maturity.

Is the Associate of ISC2 pathway worthwhile for early-career professionals? Yes. Passing the CISSP exam as an Associate demonstrates a high level of knowledge and commitment. Many employers treat CISSP Associates positively in hiring, understanding that the candidate has passed a demanding knowledge test while accumulating experience. The pathway gives early-career professionals a recognized credential and a clear path to full certification as they build experience.

How do employers verify ISC2 certification status? ISC2 provides a public certification verification service at isc2.org. Employers can verify current certification status, expiration date, and the credentials held by any named candidate. ISC2's active enforcement of CPE and AMF requirements means that lapsed certifications are quickly identified — making active certification a meaningful credential rather than a credential that can be claimed indefinitely after passing an exam.

Request a ISC2 consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

Related frameworks

Get matched with a ISC2 auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.