CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingCompare CISSP, CISM, OSCP, CCSP, SecurityX and GIAC for security professionals with five or more years of experience — by track, cost and payoff.

Five-plus years into a security career, the certification question stops being "which one is achievable?" and becomes "which one changes what I get paid to do?" At this level every serious credential is expensive in money, hours, or both — so the ranking that matters is not difficulty but fit with the next role you want. This guide ranks advanced certifications only; if you are earlier in your journey, the full cybersecurity certification roadmap sequences the entry and intermediate stages that precede these.
Short answer: for a leadership trajectory, CISSP first, then CISM if you are heading specifically into security programme management. For a deep-technical trajectory, OSCP if offensive skills are the goal, SecurityX or a GIAC specialisation if you are staying on the defensive/architecture side. CCSP earns its place when cloud is your remit — and CISSP holders get its experience requirement waived entirely.
Everything else follows from one honest question: in three years, do you want to run a security programme or remain the person who does the hardest technical work?
The management track (CISSP, CISM, CISA) rewards breadth, governance fluency and the ability to translate risk for executives. The technical track (OSCP and OffSec's higher tiers, SecurityX, GIAC specialisations) rewards demonstrated depth. Neither is a demotion of the other, but hiring managers read them differently: a CISM on a CV says "give me the programme"; an OSCP says "give me the target." Certifications signal intent as much as knowledge, so pick the signal you want broadcast.
A realistic scenario: a senior SOC lead with seven years' experience, already holding Security+ and CySA+, is choosing between CISSP and OSCP. If her goal is SOC manager, CISSP is the obvious buy — the experience requirement is behind her and the credential is what leadership job specs name. If her goal is to move into red-team work, OSCP is worth more than any management letterhead, but she should budget for months of lab time, not weeks.
The Certified Information Systems Security Professional from ISC2 remains the credential most senior job descriptions name. The exam has been computerised adaptive testing in all languages since April 2024: 100–150 items in a maximum of 3 hours, with no going back to previous questions. The fee is $749 in the Americas as of 2026 (regional prices vary), and certification requires five years of cumulative paid experience across two or more of the eight domains — one year waivable via a relevant degree or approved credential, one waiver only. Renewal runs on a 3-year cycle of 120 CPE credits plus an annual maintenance fee.
For an experienced professional the experience gate is a formality, which is exactly why CISSP is the efficient first buy on this track: maximum recognition, no wasted prerequisite-building. Also worth knowing: within nine months of passing you need endorsement by an ISC2-certified professional in good standing (or ISC2 itself), so line up your endorser early.
Where CISSP is broad, ISACA's Certified Information Security Manager is pointed: four domains, of which Information Security Program (33%) and Incident Management (30%) dominate the current outline. The exam is 150 multiple-choice questions over 4 hours, passing at a scaled 450 on a 200–800 scale, priced at US$575 for ISACA members and US$760 for non-members, plus a US$50 application fee after passing. Certification requires five or more years of information security management experience, with waivers capped at two years; you may sit the exam first and apply within five years of passing.
One timing note that matters right now: ISACA has announced the CISM exam content outline changes effective 3 November 2026. Candidates testing before that date sit the current outline; anyone planning a late-2026 attempt should match prep materials to the outline they will actually face.
CISSP or CISM? Take CISSP when you want one credential covering the whole senior market, or when your background is technical breadth. Take CISM when the destination is explicitly security management or CISO-track roles, when you already hold CISSP, or when your organisation lives in ISACA's governance world. Many professionals eventually hold both — CISSP first is the common and sensible order, and holding an active CISM can even waive a year of CISSP experience (only one waiver applies).
If your senior work runs through audit, control and assurance rather than operations, CISA shares CISM's format and price (150 questions, 4 hours, 450/800, $575/$760 plus $50 application) but tests five audit-focused domains, and requires five years of IS audit, control or assurance experience with waivers up to three years. Do not treat CISA and CISM as levels of one ladder — they aim at different jobs.
The OSCP is the advanced credential least like the others: a 24-hour proctored, hands-on penetration-testing exam against live machines, followed by a professional report, scored out of 100 with 70 to pass — 60 points from three standalone machines and 40 from an Active Directory set with partial credit. The old 10 bonus points for course exercises were removed effective November 2024, so the score now comes entirely from exam performance. Since that same change, passing awards both the lifetime OSCP and a three-year OSCP+ renewable through OffSec's CPE programme or further OffSec exams.
Pricing reflects OffSec's training-first model: the PEN-200 Course & Cert bundle is $1,749 (90 days of access, one attempt), Learn One is $2,749 per year with two attempts, and a standalone exam attempt exists at $1,699 but is rarely advisable. For experienced defenders crossing into offensive work, OSCP is the credential that survives technical interviews. Those who pass often continue to OSEP (evasion and breaching defences) or OSWE (advanced web exploitation), both 48-hour exams in the same bundle pricing structure. For a candid look at how OSCP's difficulty compares with everything else here, see the ranking of the hardest cybersecurity certification exams.
SecurityX is CompTIA's expert-level cert — and if you last looked years ago, note it is the renamed CASP+: the December 2024 release moved the code from CAS-004 (retired June 2025) to CAS-005. It targets practitioners who want architect-and-engineer seniority without moving into management: roughly 90 questions over 165 minutes, graded pass/fail with no scaled score, with recommended experience of ten years in IT including five hands-on in security. CAS-005 pushed AI/ML threat modelling, post-quantum cryptography and zero trust up the objectives. Third-party trackers listed the voucher around $525 before CompTIA's June 2026 price rise — check store.comptia.org for the current figure. Its DoD pedigree (CASP+ sat on the legacy 8570 advanced baselines, carried forward under 8140) keeps it valuable in government-adjacent roles.
GIAC's catalogue lets experienced professionals certify in precisely their niche — forensics, detection, industrial control systems and more. The exams are open-book (printed notes allowed), proctored, and priced at a premium: expect roughly $999 per attempt at 2026 pricing, with the affiliated SANS courses a separate multi-thousand-dollar decision that is not required. The honest framing: GIAC certs are excellent when an employer funds them or when your niche is rare enough that the credential is scarce; they are hard to justify fully self-funded when SecurityX or OSCP covers the same career move.
The Certified Cloud Security Professional is the strongest pure cloud-security credential for senior staff. Since October 2025 it is a CAT exam of 100–150 items in up to 3 hours, priced at $599 in the Americas. The usual requirement is five years of IT experience including three in security and one in a CCSP domain — but an active CISSP satisfies the entire requirement, making CISSP-then-CCSP one of the most efficient pairings on this page. On pay: Skillsoft's 2025 Top-Paying IT Certifications data (US figures) listed CCSP at an average of $171,524 — one dated US source, not a promise; pay varies widely by location, role and experience.
| Factor | CISSP | CISM | OSCP | SecurityX | CCSP |
|---|---|---|---|---|---|
| Track | Management/broad | Management | Offensive technical | Defensive technical | Cloud |
| Format | CAT, 100–150 q, ≤3 h | 150 q, 4 h | 24 h hands-on + report | ~90 q, 165 min | CAT, 100–150 q, ≤3 h |
| Experience required | 5 yrs (1 waivable) | 5 yrs mgmt (2 waivable) | None enforced | 10 yrs recommended | 5 yrs (CISSP waives all) |
| Cost (2026, USD) | $749 | $575/$760 + $50 | $1,749 bundle | ~$525, verify | $599 |
| Renewal | 3-yr, 120 CPEs + AMF | 20 CPE/yr, 120/3 yrs + AMF | OSCP lifetime; OSCP+ 3 yrs | 3-yr CE cycle | 3-yr, 90 CPEs + AMF |
| Best for | Broad senior roles | Security programme leads | Red team, pentest | Senior technical defenders | Cloud security leads |
Three constraint-based rules of thumb:
Whichever you choose, benchmark before you book. At this career stage the risk is not ignorance but unevenness — fifteen years of operations experience can coexist with a rusty cryptography domain. Timed practice runs mapped to the official objectives expose exactly that; ExamPractice's certification exams directory carries free sample questions across security exams, with fuller sets and a timed simulation mode for subscribers.
Advanced certs are subscriptions, not trophies. CISSP demands 120 CPEs per 3-year cycle plus an annual fee; ISACA certifications require 20 CPE hours annually and 120 per cycle plus annual maintenance fees (US$45 members / US$85 non-members per ISACA's published maintenance schedule); CompTIA's CE cycle renews SecurityX every three years and automatically renews lower CompTIA certs beneath it. Only OffSec's classic credentials (plain OSCP, OSEP, OSWE) sit outside renewal economics entirely. If you plan to hold three or four of these simultaneously, sketch the decade's CPE and fee load before buying the third.
At this level the traffic runs one way: experience unlocks credentials, and some credentials unlock others. An active CISSP satisfies CCSP's entire experience requirement; an approved credential such as CISM or Security+ can waive one year of CISSP's five (a degree can do the same, but only one waiver applies); ISACA allows a maximum two-year waiver against CISM's five. None of these exams will waive its exam — only the experience ledger moves.
EC-Council's Certified Ethical Hacker is a 125-question multiple-choice exam that remains heavily recognised by HR filters and government-adjacent hiring, but for a practitioner who already has years of experience it proves less than OSCP's hands-on format and costs a similar order of money ($950–$1,199 voucher depending on delivery, plus a $100 eligibility fee for self-study candidates). Add it when a specific contract or employer names it; choose OSCP when the goal is technical credibility.
Plain OSCP, OSEP and OSWE are lifetime credentials. Everything else on this page lapses without maintenance: ISC2 and ISACA certifications suspend if CPE reporting or fees stop, and CompTIA certs expire three years from the pass date unless renewed. Losing a senior credential to unlogged CPEs is an unforced error — put the reporting deadlines in your calendar the week you pass.
For architects in Microsoft-centric enterprises, the SC-100 Cybersecurity Architect expert certification is the ecosystem-specific counterpart to the vendor-neutral options here; the SC-100 Microsoft Cybersecurity Architect exam page outlines its scope. Treat it as a complement to, not a substitute for, CISSP-tier recognition.
Buy CISSP when you want the broadest senior door-opener and your five years are in the bank. Add CISM when security management is the named destination, timed against the November 2026 outline change. Choose OSCP when you need to prove hands-on capability, SecurityX when you are staying deeply technical on the defensive side, and CCSP when cloud is your mandate — especially as a CISSP follow-on. There is no universal best at this level; there is only the certification that matches the job you are actually trying to get, and at senior pay grades, precision beats prestige.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading