Skip to main content
← Back to certifications
ISC2CybersecurityAdvancedVendor-neutralActive

ISC2 CISSP

An advanced cybersecurity credential spanning security leadership, architecture, engineering, operations, risk management, software security, identity, and communications security.

Last verified: 2026-09-01

Overview

ISC2 CISSP is an advanced, vendor-neutral cybersecurity certification for experienced practitioners, architects, managers, and security leaders. It validates broad technical and managerial knowledge across eight security domains, including risk management, security architecture, networking, identity and access management, assessment, operations, asset security, and software security. The certification is intended for professionals who design, implement, manage, or oversee an organization's cybersecurity program. Candidates must pass the CISSP exam and satisfy ISC2 experience and endorsement requirements to become fully certified; those who pass the exam before meeting the experience requirement may pursue the Associate of ISC2 pathway while they gain the required experience.

Recommended experience
ISC2 requires at least five years of cumulative full-time work experience in two or more of the eight CISSP domains. Up to one year of the experience requirement may be waived through an eligible post-secondary degree or an approved credential. Candidates who pass the exam without the required experience may become an Associate of ISC2 and have up to six years to earn the required experience.
Estimated study time
120–200 hours
Target job roles
Chief Information Security OfficerSecurity DirectorSecurity ManagerSecurity ArchitectSecurity EngineerSecurity ConsultantSecurity AuditorSenior Security AnalystIT Director/ManagerNetwork Architect

Exam Details

ISC2 CISSP Exam

Exam code
CISSP
Number of exams
1
Duration
180 minutes
Question count
100–150 items
Delivery method
Computerized Adaptive Testing (CAT) at authorized Pearson VUE testing centers
Price
$749 USD (standard registration in the Americas and many other regions; regional pricing and taxes may vary)

Skills and Domains

Security and Risk Management

16%

Covers security governance, risk management, compliance, legal and regulatory concepts, professional ethics, business continuity, security awareness, and security policy.

Asset Security

10%

Covers information and asset classification, ownership, handling requirements, data lifecycle management, retention, protection, and secure disposal.

Security Architecture and Engineering

13%

Covers secure design principles, security models, cryptography, physical security, system architecture, vulnerabilities, and engineering practices.

Communication and Network Security

13%

Covers secure network architecture, communication technologies, network protocols, network components, segmentation, secure channels, and network attacks.

Identity and Access Management (IAM)

13%

Covers identity lifecycle management, authentication, authorization, access control models, identity federation, provisioning, and privileged access.

Security Assessment and Testing

12%

Covers security assessment strategies, vulnerability testing, penetration testing concepts, audits, log reviews, testing methodologies, and security control validation.

Security Operations

13%

Covers investigations, incident management, disaster recovery, monitoring, vulnerability management, configuration management, change management, and operational security.

Software Development Security

10%

Covers security throughout the software development lifecycle, secure coding concepts, application security controls, software acquisition, testing, and development environment risks.

Study Resources

ISC2 CISSP Certification

Official resource

Documentation · Free

Official CISSP certification overview, eligibility information, career fit, and certification pathway.

View resource

CISSP Certification Exam Outline

Official resource

Official Guide · Free

Official ISC2 CISSP exam outline with current domains, weights, exam format, and experience requirements.

View resource

CISSP Self-Study Resources

Official resource

Documentation · Free

Official ISC2 page collecting CISSP self-study tools and preparation resources.

View resource

Official ISC2 CISSP Online Self-Paced Training

Official resource

Official Training · Paid

Official ISC2 online self-paced CISSP training option aligned to the certification.

View resource

Renewal

Validity period
3 years
Renewal method
Earn 120 Continuing Professional Education (CPE) credits during the three-year certification cycle and remain current on the ISC2 Annual Maintenance Fee (AMF).
Notes
ISC2 currently requires CISSP members to earn 120 CPE credits over each three-year cycle. The current AMF for members who hold CISSP is U.S. $135 per year; members holding multiple applicable ISC2 certifications pay a single AMF. Requirements and fees can change, so holders should verify them with ISC2.

Recommended Before

Verify with official provider.

Recommended After

Verify with official provider.

Alternatives

Verify with official provider.

Specializations

Verify with official provider.

Explore certification categories

Browse focused certification guides by technology and career domain.