Skip to content
Getting Digital
All certifications

ISC2 certifications

ISC2 is the association behind CISSP, the credential that senior security adverts name by reflex, which is precisely why so many people book it at the wrong point in their careers. Two questions settle whether sitting it now is sensible, and neither of them is about your revision timetable: does your work history satisfy what ISC2 requires before it will issue the certificate, and do you want breadth or depth out of the coming year?

Exam delivery: Pearson VUE (test centres only, no online proctoring); membership after passing and having the experience endorsed

Take the second question first, because getting it wrong wastes months. This is a management-leaning breadth credential. Eight domains run from governance and risk through architecture, networking, identity, testing and operations to software security, and each is surveyed to the depth someone accountable for a security programme needs, not the depth a specialist works at daily. Candidates who expect a proof of technical mastery prepare for the wrong paper. They drill cryptographic internals and protocol minutiae, then drop marks on items where the correct move is to escalate to the risk owner, revise the policy, or stop a process until it can be done properly. The exam wants the answer given by a person answerable for a whole organisation, not by the best engineer in the room. None of that is a criticism. Breadth is a real qualification, and rarer among experienced engineers than depth. But it does mean the certificate is a poor way to demonstrate hands-on ability, and readers who want that should take a defensive-operations or platform credential instead, which proves it sooner. The CISSP earns its keep once your responsibility has spread past a single technology and people start asking you to reason about the estate as a whole.

Your employment record, not your study plan, decides whether to book

Where you stand todayWhat passing gives youWhat still stands between you and the letters
Five years of paid security work spanning at least two of the eight domainsThe full credential, once an existing member endorses your recordThe endorsement itself, then continuing education and an annual fee every year you keep it
Four years, plus a relevant degree or an approved credentialThe same route: the waiver covers your missing yearEvidence for the waiver, claimed when you apply rather than when you book
Less than that, or experience in only one domainAssociate of ISC2 status on the identical exam paperSix years at most to finish the record and convert
A career change still in its early stagesAssociate status, with the conversion window opening before your relevant work doesA judgement call: the window is generous, but it starts running the day you pass

The sitting is the straightforward part. Holding the credential is the commitment, and it is where the real arithmetic lives. ISC2 runs three-year cycles built on continuing-education credits that you are expected to spread across the cycle rather than hoard for the final months, and a fee for maintaining it comes due each year whether or not you learned anything. Nothing is ever re-examined, which sounds like mercy until you notice the consequence: let the credits slip or the fee go unpaid and the credential lapses into a reinstatement process, not a quiet grace period. So the honest picture is one exam followed by an obligation that repeats indefinitely. Reasonable if security remains your field; wasted effort if you wanted a CV trophy. My position on timing is blunt. Sit it when you already have the record, or when you can see the finish of it from where you stand and want the material fresh while you work. Do not sit it as a way around the experience, because Associate status is not the same thing and fools nobody who reads security CVs for a living. Anyone earlier than that is better served by Security+ now and this exam later, and anyone heading for governance work should weigh CISM in the same breath. Fees and current exam facts, each dated, sit on the CISSP page.

Expert

Frequently asked

Can I write CISSP after my name once I pass as an Associate?
No. Until your experience is documented and endorsed you hold Associate of ISC2, which is a different designation with its own name. Claiming the full credential early is a quick way to lose a recruiter's trust.
Is this a technical certificate?
Not really, and that is the most common misreading on this page. It covers technical ground across eight domains, but it tests how a person responsible for the whole programme would judge a situation, which is a different skill from configuring anything.
How is the certificate kept alive?
Through continuing-education credits earned across each three-year cycle and a fee paid annually. You never sit the paper again. The trade is one hard day at the start for a standing obligation afterwards.
Should I do a hands-on security certificate first?
Early in the field, yes. Practical credentials build the experience that this one requires, and they demonstrate ability you can be hired for now. Come back when your remit has widened beyond a single system.

Official certification portal: www.isc2.org/certifications

Other vendors

Last reviewed 12 September 2026 · Getting Digital