Doc CC-02Rev 2026-10Class study materialRead ~9 min
CISSP certification: what it is, who it’s for, and how you earn it
The ISC2 CISSP (Certified Information Systems Security Professional) certification is a senior, vendor-neutral credential that says you can run security for an organization rather than for one product: you pass a 100–150-item adaptive exam, show five years of relevant work, get endorsed by a certified peer, and then keep it current with continuing education. Anyone can sit the exam; only people who finish all four steps can use the letters.
Exam readout
- Format
- CAT, every language
- Items
- 100–150
- Time
- 3 hours
- Pass mark
- 700 / 1000 scaled
- Outline
- 8 domains · Apr 2024
The credential in four readings
Issuer
ISC2
Vendor-neutral: no product is ever the right answer.
Scope
8 domains
Current outline, effective April 2024.
Experience
5 years
Cumulative, in at least 2 of the 8 domains.
Upkeep
120 CPE
Per three-year cycle, plus an annual fee.
What CISSP certifies
It is a credential about breadth and judgment. The exam covers eight domains — from Security and Risk Management, the heaviest at 16% of the current outline, to Software Development Security at 10% — and its scenarios are written from the chair of someone who advises the business, not the person holding the screwdriver. The full domain list and what each one asks of you is in the study guide.
Two outside reference points give the letters their weight. The certification is accredited by ANAB against ISO/IEC 17024, the international standard for bodies that certify people, and it is approved under the U.S. Department of Defense manual DoDM 8140.03 for a range of cyber work roles. Neither turns it into a license: this is a private professional certification, and no law requires it to practice security.
Vendor-neutral means the outline never names a platform. You will be asked which control fits, who owns the risk and what to do first; you will not be asked which menu holds the setting. Engineers who come from a single vendor’s world tend to find this mildly offensive for about two weeks, after which it starts to make sense.
What the letters do not mean
They do not mean “passed an exam.” Passing is step two of four. A candidate who passes without the experience becomes an Associate of ISC2 and may not use the designation until the experience is earned and the endorsement is approved.
From candidate to certified in four steps
The exam is the famous part. The other three steps are where people quietly lose months.
Step 01
Confirm your experience
Five years of cumulative work in at least two of the eight domains; a relevant degree or one approved credential can waive one of those years. Part-time hours, internships and the waiver list are covered on CISSP requirements.
Step 02
Pass the CAT exam
100–150 items, up to 3 hours, 700 out of 1000 scaled points to pass, taken at a Pearson VUE test center. How the adaptive engine decides when to stop is on the CISSP exam page.
Step 03
Get endorsed within 9 months
After the pass, an active ISC2-certified professional attests to your experience — or ISC2 itself acts as endorser if you cannot find one. The 9 months run from your exam date, so collect proof of employment before you sit, not after.
Step 04
Keep it current
Earn 120 continuing professional education (CPE) credits per three-year cycle, at least 90 of them Group A, and pay an annual maintenance fee (AMF). Current amounts and member policies are published on isc2.org.
Who holds CISSP, and who actually needs it
The typical holder sits between hands-on engineering and management: security managers and architects, consultants, analysts moving into leadership, risk and audit people who need the technical vocabulary, and the occasional developer who keeps getting pulled into threat modeling. Because of the five-year rule, it is rarely anyone’s first credential.
Need is a different question from fit. The roles that most often ask for it are senior security positions, consulting work where clients want an independent signal, and U.S. government and defense-contractor positions under the DoD 8140 framework. Elsewhere it usually appears under “preferred” rather than “required” — a filter on a job posting, not a gate in law.
Earlier in a career, this one can wait. ISC2’s entry-level Certified in Cybersecurity (CC) and the practitioner-level SSCP exist for that stage, and either is a better use of the next three months than an exam built for people who have already sat through an incident review or two.
The Associate of ISC2 route
You do not need the five years to sit the exam. If you pass without them, you become an Associate of ISC2 and have six years to earn the required experience, after which you complete endorsement like any other candidate.
The trade-off is plain. An Associate pays an annual fee and earns CPE credits each year but cannot use the title; the designation waits for the experience. In exchange, the hardest step is behind you while the material is fresh, and the rest of the wait is simply going to work.
It suits people three or four years into the field who want the exam done before a job change, and career changers whose experience will accrue on a predictable schedule. It does not suit anyone hoping the Associate status counts as the experience — the requirement is postponed, never reduced.
The vocabulary of getting certified
Half of the confusion around CISSP comes from five administrative words used loosely on forums. Here they are, used precisely.
- CBK
- The Common Body of Knowledge — ISC2’s name for the material the eight domains draw on. The exam outline, refreshed roughly every three years, is the part that tells you the weights.
- Endorsement
- The step after the pass where a certified professional in good standing confirms your experience is real. It has a 9-month deadline from the exam date and can be done by ISC2 itself when you know nobody suitable.
- Associate of ISC2
- The status of someone who passed without the five years. It carries membership obligations but not the CISSP designation; the clock to earn the experience is six years.
- CPE credits
- Continuing professional education. Holders need 120 per three-year cycle; at least 90 must be Group A, meaning activity tied to the domains, while Group B covers broader professional development. ISC2 suggests about 40 a year, but the binding number is the cycle total.
- AMF
- The annual maintenance fee every certified member pays, separately from the exam. The current figure is on isc2.org; what it buys is staying in good standing.
Where CISSP sits among neighboring credentials
Which credential comes first depends on where you are, not on which acronym is longest.
| Credential | Issuer | Level and focus | Relation to CISSP |
|---|---|---|---|
| CC — Certified in Cybersecurity | ISC2 | Entry level; no experience required | A starting point, years before CISSP |
| SSCP | ISC2 | Practitioner; hands-on security administration | On ISC2’s experience-waiver list as of October 2026 |
| Security+ | CompTIA | Entry-level, vendor-neutral foundation | A common step before CISSP; also on the waiver list |
| CISM | ISACA | Security management and governance, 4 domains | Narrower and more managerial — see CISSP vs CISM |
| CCSP | ISC2 | Cloud security | Often taken after CISSP; an active CISSP covers its entire experience requirement |
Three identity questions, for calibration
Domain 5, Identity and Access Management, is 13% of the current outline and the place where everyday words — roles, factors, federation — turn out to have exam-specific meanings. Three original practice items with the reasoning behind every option. A calibration check, not a forecast of your result; the full set is on the CISSP practice test.
Domain drill
Item 01 / 03
Answer, then read why each option is right or wrong. Keys 1–4 pick, N goes next.
A high-security Single Page Application (SPA) processes sensitive healthcare data. To minimize the risk of Cross-Site Scripting (XSS) attacks leading to complete account compromise, how should the application store session tokens?
Rationale
Pick an answer. The reasoning for every option lands here — including why the wrong ones looked right.
Is CISSP worth it in 2026?
For someone with the experience and a move into senior, advisory or government-adjacent work in view, usually yes. It is widely named in senior security job descriptions and procurement requirements, it travels between employers and countries because it is vendor-neutral, and the DoDM 8140.03 approval keeps it relevant for U.S. defense work.
The case is weaker if your work lives deep inside one platform, if you are two years into the field, or if your next step is pure audit, where ISACA’s CISA is the conventional signal. The credential also costs time: a few months of study, an endorsement application, and 120 CPE credits every three years for as long as you hold it.
You will not find salary figures on this page. Surveys disagree with each other by region, year and sample, and any number printed here would be out of date before the page was indexed. A more useful test takes ten minutes: open five postings for the role you want next and count how many mention it.
- You have, or will soon have, five years across at least two of the eight domains.
- Your next role involves advising management, owning a security program, or consulting.
- You work, or want to work, on U.S. defense contracts where 8140 qualifications are checked.
- You are at peace with a three-year CPE cycle becoming a permanent feature of your calendar.
Three or more of those and the answer is probably yes. One or none, and an entry or practitioner credential will likely pay off sooner.
Questions people ask
Q01Is CISSP still worth it in 2026?
For people with the experience and a senior or advisory role in view, generally yes: it is vendor-neutral, ANAB-accredited to ISO/IEC 17024, approved under DoDM 8140.03 and widely named in senior job descriptions. For early-career or single-platform roles, an entry or practitioner credential usually pays off sooner.
Q02Can I use the CISSP letters as soon as I pass?
No. Passing the exam does not make you a CISSP; the title starts when ISC2 approves your endorsement. If you passed without the full experience, you are an Associate of ISC2, which is its own designation and may not use the CISSP mark. The experience rules are on CISSP requirements.
Q03Is CISSP equivalent to a Masters?
No. It is a professional certification, not an academic degree, and whether an employer or university treats it as comparable is their own call. The relationship runs the other way in ISC2’s rules: a relevant bachelor’s or master’s degree can waive one year of the experience requirement.
Q04How long does it take to get a CISSP?
Count it in stages. Study time is a planning assumption, not a rule: the study plan assumes 8 to 12 weeks at about 10 hours a week for someone already working in security. Then the exam, then an endorsement application within 9 months of the exam date; the review itself usually takes a few weeks. Starting from zero, the real limiter is the five years of experience, not the exam.
Q05Who issues CISSP certification?
ISC2, Inc. issues the certification and maintains the exam outline; Pearson VUE delivers the exam at its test centers. ISC2 also issues SSCP, CCSP, CC and other credentials, each with its own requirements.
Q06Is CISSP a license?
No. It is a private professional certification with an experience requirement and an endorsement step. Some employers and U.S. Department of Defense roles list it as an accepted qualification, but no law requires it to work in security.
The short version
Debrief · key takeaways
- CISSP is ISC2’s senior, vendor-neutral security credential, covering 8 domains.
- Four steps: experience, the CAT exam, endorsement within 9 months, then 120 CPE per three years plus an annual fee.
- No experience yet? Pass anyway and you are an Associate of ISC2 with six years to earn it.
- DoDM 8140.03 approves it for many roles; it does not make it mandatory or a license.
- Worth it when your next role is senior, advisory or defense-related; premature two years into the field.
Where to go next
Field kit
Drill the domains between meetings
The CISSP prep app carries a larger bank of original practice items, with a note on every option, on iPhone and Android.