ISC2 CISSP
An advanced cybersecurity credential spanning security leadership, architecture, engineering, operations, risk management, software security, identity, and communications security.
Last verified: 2026-09-01
Overview
ISC2 CISSP is an advanced, vendor-neutral cybersecurity certification for experienced practitioners, architects, managers, and security leaders. It validates broad technical and managerial knowledge across eight security domains, including risk management, security architecture, networking, identity and access management, assessment, operations, asset security, and software security. The certification is intended for professionals who design, implement, manage, or oversee an organization's cybersecurity program. Candidates must pass the CISSP exam and satisfy ISC2 experience and endorsement requirements to become fully certified; those who pass the exam before meeting the experience requirement may pursue the Associate of ISC2 pathway while they gain the required experience.
- Recommended experience
- ISC2 requires at least five years of cumulative full-time work experience in two or more of the eight CISSP domains. Up to one year of the experience requirement may be waived through an eligible post-secondary degree or an approved credential. Candidates who pass the exam without the required experience may become an Associate of ISC2 and have up to six years to earn the required experience.
- Estimated study time
- 120–200 hours
- Target job roles
- Chief Information Security OfficerSecurity DirectorSecurity ManagerSecurity ArchitectSecurity EngineerSecurity ConsultantSecurity AuditorSenior Security AnalystIT Director/ManagerNetwork Architect
Exam Details
ISC2 CISSP Exam
- Exam code
- CISSP
- Number of exams
- 1
- Duration
- 180 minutes
- Question count
- 100–150 items
- Delivery method
- Computerized Adaptive Testing (CAT) at authorized Pearson VUE testing centers
- Price
- $749 USD (standard registration in the Americas and many other regions; regional pricing and taxes may vary)
Skills and Domains
Security and Risk Management
16%Covers security governance, risk management, compliance, legal and regulatory concepts, professional ethics, business continuity, security awareness, and security policy.
Asset Security
10%Covers information and asset classification, ownership, handling requirements, data lifecycle management, retention, protection, and secure disposal.
Security Architecture and Engineering
13%Covers secure design principles, security models, cryptography, physical security, system architecture, vulnerabilities, and engineering practices.
Communication and Network Security
13%Covers secure network architecture, communication technologies, network protocols, network components, segmentation, secure channels, and network attacks.
Identity and Access Management (IAM)
13%Covers identity lifecycle management, authentication, authorization, access control models, identity federation, provisioning, and privileged access.
Security Assessment and Testing
12%Covers security assessment strategies, vulnerability testing, penetration testing concepts, audits, log reviews, testing methodologies, and security control validation.
Security Operations
13%Covers investigations, incident management, disaster recovery, monitoring, vulnerability management, configuration management, change management, and operational security.
Software Development Security
10%Covers security throughout the software development lifecycle, secure coding concepts, application security controls, software acquisition, testing, and development environment risks.
Study Resources
ISC2 CISSP Certification
Official resourceDocumentation · Free
Official CISSP certification overview, eligibility information, career fit, and certification pathway.
View resourceCISSP Certification Exam Outline
Official resourceOfficial Guide · Free
Official ISC2 CISSP exam outline with current domains, weights, exam format, and experience requirements.
View resourceCISSP Self-Study Resources
Official resourceDocumentation · Free
Official ISC2 page collecting CISSP self-study tools and preparation resources.
View resourceOfficial ISC2 CISSP Online Self-Paced Training
Official resourceOfficial Training · Paid
Official ISC2 online self-paced CISSP training option aligned to the certification.
View resourceRenewal
- Validity period
- 3 years
- Renewal method
- Earn 120 Continuing Professional Education (CPE) credits during the three-year certification cycle and remain current on the ISC2 Annual Maintenance Fee (AMF).
- Notes
- ISC2 currently requires CISSP members to earn 120 CPE credits over each three-year cycle. The current AMF for members who hold CISSP is U.S. $135 per year; members holding multiple applicable ISC2 certifications pay a single AMF. Requirements and fees can change, so holders should verify them with ISC2.
Related Certifications
Recommended Before
Verify with official provider.
Recommended After
Verify with official provider.
Alternatives
Verify with official provider.
Specializations
Verify with official provider.
Keep exploring on ThirdBadge
Connect this certification to its broader technology area, career roadmaps, training, and study resources.
Explore certification categories
Browse focused certification guides by technology and career domain.