CISSP is not the start of a security career and it is not the finish. It is the hinge in the middle: ISC2 requires five years of cumulative, paid experience in at least two of its eight domains before you can hold the certification, and most people earn it precisely at the point where their career is about to fork — towards deep architecture, towards management, or towards advisory work. Understanding that hinge position is the whole trick to planning around it.
This article maps the trajectory: the roles that typically come before the Certified Information Systems Security Professional, the two ways to earn it, the three branches that open afterwards, and the additional steps between CISSP and Chief Information Security Officer (CISO). It is a roadmap, not a job board — if you want the concrete catalogue of titles and what each involves day to day, that lives in what jobs you can get with CISSP, and this article won't repeat it. Salary tables are likewise out of scope here; treat any figure you see quoted online as survey-specific, not a promise.
Stage one: the years before CISSP (years 0–5)
Because of the experience requirement, the road to CISSP runs through ordinary security-adjacent jobs. Common feeder roles include:
- Security analyst / SOC analyst — monitoring, triage and incident handling, which maps to the Security Operations domain.
- Systems or network administrator — infrastructure work counts when it touches domains such as Communication and Network Security or Identity and Access Management.
- Security engineer — implementing controls, hardening systems, running vulnerability management.
- IT auditor or GRC analyst — governance and risk work maps to Security and Risk Management, the most heavily weighted domain.
Two accelerators are worth knowing. First, ISC2 allows a one-year experience waiver for a relevant degree or an approved credential such as CompTIA Security+ or CISM — but only one waiver applies, so a degree plus Security+ still only removes one year. Second, part-time work and documented internships count towards the total under ISC2's rules. During this stage, many people take Security+ or ISC2's own SSCP (which needs just one year of experience) as staging credentials; if you're comparing early options, our guide to the best certifications for experienced professionals covers how experience-gated credentials stack.
Stage two: two doors into CISSP
The standard route
With five years banked, you sit the exam, then complete endorsement — an ISC2-certified professional in good standing (or ISC2 itself, with employment verification) vouches for your experience within nine months of passing. Random audits happen, so the experience you claim needs to be real and documentable.
The Associate of ISC2 route
You can sit the CISSP exam before you have the experience. Pass it, and you become an Associate of ISC2, with six years to accumulate the five years of qualifying work. This route is underused and genuinely strategic: an ambitious analyst two years into their career can pass the exam, carry the Associate designation on their CV, and convert automatically as the experience accrues. What you must not do is call yourself a CISSP before certification — ISC2 treats that as a violation.
The exam itself, briefly
As of the April 2024 refresh, the CISSP exam is Computerised Adaptive Testing in all languages: 100–150 items with a maximum of three hours, no returning to previous questions, and results reported as pass/fail against a 700/1000 standard rather than a numeric score. The fee is US$749 in the Americas as of 2026 (it varies by region — confirm on isc2.org). ISC2 publishes no pass rate, so ignore anyone quoting one. Because the CAT format punishes uneven knowledge — you cannot skip a weak domain and come back — timed, full-length rehearsal matters more than for linear exams; a CISSP-style timed practice test that breaks results down by domain will show you which of the eight domains would sink an adaptive exam before you book it.
Stage three: the fork after CISSP (years 5–10)
CISSP certifies breadth across all eight domains. The next move is choosing depth, and there are three well-trodden branches.
Branch one: the architecture track
Security architects design the control landscape — deciding how identity, network segmentation, cloud services and data protection fit together — rather than operating it. This branch suits people who liked the engineering side and want its most senior expression. ISC2's concentration for this track is the ISSAP (Information Systems Security Architecture Professional): a 125-question, three-hour linear exam (outline refreshed 1 August 2025) priced at US$599, requiring either a CISSP in good standing plus two years of architecture-domain experience, or seven years of cumulative relevant experience without CISSP. Cloud-heavy environments often pair CISSP with CCSP (Certified Cloud Security Professional) instead — and usefully, an active CISSP satisfies the entire CCSP experience requirement, making it the lowest-friction post-CISSP credential there is.
Branch two: the management track
Security managers own programmes, budgets, teams and incident accountability. CISSP's managerial breadth sets this up well, and two credentials deepen it. ISC2's own ISSMP (Information Systems Security Management Professional) concentration targets leaders overseeing incident response, governance and security programme management, with the same prerequisite structure as ISSAP (CISSP plus two years, or seven years cumulative) at US$599 — check the current exam format on ISC2's site, and try the CISSP-ISSMP practice questions to gauge how management-flavoured the material is compared with the CISSP itself. The other common pairing is ISACA's CISM; the roles and ladder on that side are mapped in our CISM career path guide, so here it's enough to say many future CISOs hold both.
Branch three: the consulting track
Security consultants sell judgement: assessments, programme builds, incident retainers, compliance readiness. CISSP functions as the table-stakes credential clients and firms expect. Progression here is less about further certificates and more about a niche (cloud migration security, regulated industries, incident response) plus a track record — though consultants working governance engagements often add ISO/IEC 27001 credentials, since so much advisory work is framed around that standard.
Choosing a branch: a quick self-test
Ask which failure would embarrass you most: a badly designed control landscape (architecture), a team that misses an incident (management), or advice a client regrets paying for (consulting). Then look at your last performance review — the strengths named there usually point at one branch. Switching later is possible; architecture-to-management is the most common mid-course correction, usually via a "lead architect with direct reports" hybrid role.
Stage four: the run at CISO (years 10+)
No certification makes you a CISO. What the final stage actually requires, on top of a credential stack, is evidence you can do four things:
- Translate risk into business language. Boards fund risk reduction they understand. Practise writing for executives — one page, money and likelihood, no acronyms.
- Own a P&L-shaped budget. Deputy CISO, head of security, or security director roles exist largely to give you this evidence.
- Run an incident in public. Leading a significant incident response end to end — including regulator and customer communication — is the experience CISO interviews probe hardest.
- Build and retain a team. ISACA's State of Cybersecurity 2025 research found 55% of cybersecurity teams understaffed and 65% carrying unfilled positions, so demonstrated ability to hire and keep people is a differentiator, not a soft skill.
Typical stepping-stone titles between the fork and the top job: senior security architect or security manager (years 5–8), head of security / deputy CISO (years 8–12), then CISO — first often at a smaller organisation, where the title comes with a broader, hands-on remit. Some CISOs add an MBA or executive education at this stage; treat that as optional polish, valuable mainly where you lack other evidence of business fluency.
Maintaining the credential while you climb
CISSP runs on a three-year cycle requiring 120 CPE credits (at least 90 in Group A) and a US$135 annual maintenance fee. This is not just admin: CPE activity is a free progression tool. Conference talks, published articles and mentoring all earn credits and build the public profile that senior roles increasingly demand. Concentrations like ISSAP and ISSMP renew alongside the base credential — confirm concentration-specific CPE rules on isc2.org, as they weren't verified for this article.
A worked example of the whole arc
A network administrator starts logging security-relevant work at year zero and passes Security+ at year one (later using it as her single one-year CISSP waiver). At year three she moves to a security engineer role and passes the CISSP exam as an Associate of ISC2; at year four her experience total clears the bar and she converts to full CISSP after endorsement. At year six she chooses the management branch, takes a security team-lead role, and adds ISSMP at year eight. Year ten: head of security at a mid-sized firm, running her first major incident. Year thirteen: CISO at a smaller company, trading organisation size for scope. Nothing in that arc is exotic — it is the standard shape, compressed or stretched by market and luck.
Frequently asked questions
Can you become a CISO without CISSP?
Yes — no law or universal policy requires it. But CISSP (often alongside CISM) appears so frequently in senior security job requirements that skipping it usually means compensating with an unusually strong track record. For most people it is the cheaper signal.
Should I take CCSP or a concentration first after CISSP?
Follow your environment: if your organisation is mid-cloud-migration, CCSP's zero-additional-experience path (an active CISSP fully covers its requirement) makes it the natural next exam. Choose ISSAP or ISSMP once you have committed to the architecture or management branch and have the two years of concentration-domain experience.
How long does the whole path take?
The experience requirement puts a hard floor of five years under certification (six years' grace as an Associate). Realistic full arcs from first IT job to CISO commonly span twelve to fifteen years, though smaller organisations shorten it. No study plan compresses the experience component.
Is the market strong enough to justify the climb?
ISC2's 2025 Cybersecurity Workforce Study deliberately published no new workforce-gap headcount, but 59% of its 16,029 respondents rated skills gaps on their teams critical or significant — demand has shifted from raw headcount to experienced, skilled people, which is exactly what this path builds.
Plotting your position on the map
Find your stage, not your title. If you are pre-experience, choose feeder work that touches two or more CISSP domains and decide whether the Associate route fits your appetite. If you are exam-ready, benchmark with timed, domain-scored practice before paying the US$749 fee. If you are newly certified, pick your branch deliberately within a year or two rather than drifting — the fork is where careers stall. And if you are eyeing CISO, start collecting the four kinds of evidence above now, because none of them can be crammed. Browse the certification exams directory when you're ready to plan the next exam on your branch.