Certification Exam Costs Explained
·13 min read
What certification exams actually cost across CompTIA, AWS, Cisco, Microsoft, ISC2 and PMI, why prices differ so much, and how pricing tiers work.
Continue readingWhy certification bodies require continuing education, how CPE, PDU and CEU systems fit into renewal, and what your obligations look like by provider.

Many newly certified professionals believe the exam was the finish line. Then, sometime in the first year, an email arrives from the certification body about "CPE requirements", "PDU reporting" or "CE fees", and it becomes clear the credential was not a trophy but a subscription — one paid partly in money and mostly in documented learning. Continuing education is the mechanism behind that: the ongoing, provider-defined learning you must complete and report to keep a certification valid.
This guide is the overview of that whole system: why it exists, which certification bodies use it (and which use something else instead), what a typical obligation looks like in numbers, and how the pieces — units, activities, reporting, fees — fit together. Where a sub-topic deserves its own deep treatment, we link down to the dedicated guide rather than compressing it here.
A certification is a claim the provider makes to employers on your behalf: this person met our standard. In fields like IT, security and project management, the standard itself moves — technologies, threats and methods change materially within a few years. A credential frozen at the moment of the exam would decay into a statement about what you knew once. Continuing education is how certification bodies keep the claim honest without forcing everyone back into an exam room: you demonstrate, through documented professional development, that your knowledge has kept moving with the field.
There is a second, less advertised function. Requiring holders to stay engaged — attending events, taking courses, remaining members — keeps the credential community active and the certification commercially alive. That is not a criticism; it simply explains why the systems include maintenance fees and provider-approved activity lists rather than a bare instruction to "keep learning".
For you as a holder, the practical consequence is a cycle: earn the credential, accumulate a defined number of learning units across a defined period, report them (with evidence available if asked), pay whatever fee applies, and the certification renews for another cycle.
Before mapping your obligations, check which maintenance model your provider actually uses, because three distinct models coexist:
The full contrast between the education-based and exam-based models — and how to tell which your provider uses — is covered in renewal versus recertification. The rest of this article concentrates on the continuing-education model, since that is where the ongoing obligations live.
Every continuing-education programme measures learning in units, but each body brands its unit differently:
The underlying idea is the same everywhere — a unit is a measured amount of qualifying professional development — but the units are not interchangeable currencies, and each body defines its own qualifying activities and record rules. In practice, this means a professional holding credentials from two bodies keeps two tallies under two rulebooks, even when a single afternoon of training feeds both. One real activity can often be claimed under more than one programme if it meets each body's definition. The terminology and rough equivalences get a full treatment in CEUs vs PDUs vs CPEs; the measurement mechanics — how units are counted, categorised and capped within a cycle — are explained in how continuing education credits work.
The table below summarises the continuing-education (or alternative) maintenance requirements of the major bodies as of 2026. Figures change; always confirm against the provider's current policy pages.
| Provider (example credential) | Cycle | Requirement per cycle | Recurring fees | Model |
|---|---|---|---|---|
| CompTIA (Security+) | 3 years | 50 CEUs (20 for A+) | Annual CE fees — $25/yr for A+, $50/yr for most other certs per CompTIA's help centre | Continuing education (or retake newest exam / pass higher cert) |
| ISC2 (CISSP) | 3 years | 120 CPE credits | US$135 annual maintenance fee, covering all your ISC2 certs | Continuing education |
| ISACA (CISA) | 3 years | 120 CPE hours, minimum 20 per year, reported annually by 31 Dec | Annual maintenance fee (secondary sources report $45 members / $85 non-members — confirm at isaca.org) | Continuing education |
| PMI (PMP) | 3 years | 60 PDUs | Renewal fee at cycle end: $60 members / $150 non-members | Continuing education |
| Cisco (CCNA / CCNP) | 3 years | 30 CE credits (CCNA) / 80 (CCNP level), from Cisco-approved activities | — | Continuing education or re-exam (or combinations) |
| AWS (all levels) | 3 years | Pass the current exam version | — (50% discount voucher after a pass) | Recertification by exam only |
| Microsoft (role-based) | 12 months | Free online renewal assessment in final 6 months | None | Renewal assessment |
Three patterns worth noticing. First, three-year cycles dominate, with Microsoft's one-year cycle the outlier — offset by its renewal being free and open-book. Second, the unit burden scales roughly with the credential's seniority: an entry-level CompTIA A+ needs 20 CEUs while a CISSP needs 120 CPEs. Third, money and learning are separate obligations: ISC2 and CompTIA bill fees annually even though the learning cycle is three years, and an unpaid fee can block a renewal that is otherwise complete on credits. The recurring-cost side has its own guide in certification renewal costs explained.
Each body publishes its own catalogue of qualifying activities, but the categories rhyme across programmes. ISACA, for example, lists conferences, courses, self-study, teaching and publishing, and mentoring among CPE-eligible activities for the CISA — with caps on some categories. Cisco requires that CE credits come from Cisco-approved activities completed before the certification expires. Broadly, qualifying activity falls into a few families:
Two cautions. Categories are frequently capped — a body may limit how much of a cycle can come from self-study, which is why "I'll just read for three years" is not a plan. And approval matters: an activity that would obviously educate you can still earn nothing if it is not recognised under the programme's rules. Check before you spend the time. For a concrete, cost-ranked menu of qualifying activities, see how to earn continuing education units.
Earning is only half the obligation; the programme only knows about learning you report. Each body has a submission process — typically a portal where you log the activity, date and unit value — and reporting rhythms differ: ISACA requires annual CPE reporting by 31 December, ISC2 ties its annual maintenance fee to your certification anniversary, and others reconcile at cycle end.
Keep evidence for everything you claim: certificates of completion, attendance confirmations, records of what you did and when. Certification bodies can ask holders to substantiate reported credits, and a claim you cannot evidence is a claim you may lose. The safest habit is to treat reporting and evidencing as one action performed the day the activity finishes — log the units in the portal, save the proof in a named folder, and note both in your own records. Reconstructing a cycle's worth of learning from memory in the final month is the single most common way otherwise-diligent professionals end up short. Practical record-keeping systems — what to save, where, and in what format — are covered in how to track professional development credits.
Consider a security analyst who passed CompTIA Security+ in January. Her obligation: 50 CEUs and roughly $150 in annual CE fees across three years, everything completed before the expiry date.
Nothing in that walkthrough was heroic. Continuing education punishes only two behaviours: forgetting, and leaving everything to the final months. The day-to-day habits that prevent both — pacing units, calendar alarms, immediate evidence capture — are the subject of our companion guide on keeping your certifications current.
Honest answer: both, in proportions you control. The burden is real — fees recur, evidence must be kept, and a three-year cycle arrives faster than it sounds. But the professionals who resent continuing education most are usually those doing it worst: paying for last-minute courses chosen for credit value rather than usefulness.
Approached deliberately, the requirement becomes a free planning discipline. Sixty PDUs or 120 CPEs is, in effect, a mandate to spend a predictable slice of every year learning — a slice many professionals intend to spend anyway and never quite do. Choosing activities that serve your actual career direction, and letting the credits fall out as a side effect, turns a compliance exercise into subsidised professional development. Some holders even sequence their next credential so it doubles as renewal for the current one — a strategy worth checking against your provider's rules before relying on it.
No. Continuing education is one of three maintenance models. AWS renews only by re-examination, Microsoft role-based certifications use a free annual online assessment, and Microsoft Fundamentals certifications never expire. CompTIA, ISC2, ISACA, PMI and Cisco all offer continuing-education renewal, with Cisco and CompTIA also allowing renewal by exam.
Often, yes — if it meets each programme's definition of a qualifying activity and you report it under each. A security conference might reasonably be claimed for both an ISC2 and an ISACA credential. Always check each body's rules; approved-activity lists and category caps differ.
The certification is at risk of expiring, and what follows — grace periods, suspension, reinstatement — varies by provider and is not uniform. Check your body's current policy pages, and see our article on what happens when a certification expires for the general landscape.
The units themselves need not be — free webinars, employer-funded training and community events all commonly qualify. The unavoidable costs are the programme fees: for example, ISC2's US$135 annual maintenance fee, CompTIA's annual CE fees, and PMI's $60/$150 end-of-cycle renewal fee, each subject to change on the provider's site.
Continuing education is the price of a credential that stays meaningful — a structured obligation to keep learning, measured in units, reported on a schedule, and paid for with modest recurring fees. Your immediate moves: confirm which maintenance model each of your certifications uses, note its cycle length, unit requirement and fees, and start logging qualifying activity now rather than in year three. From here, the deep dives are: how the credits are measured, where to earn them, what the unit names mean across bodies, and how to keep audit-ready records. If you are still choosing the credential itself, ExamPractice's certification exam directory lets you scope providers — and their maintenance systems — before you commit.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·13 min read
What certification exams actually cost across CompTIA, AWS, Cisco, Microsoft, ISC2 and PMI, why prices differ so much, and how pricing tiers work.
Continue reading·7 min read
The real end-to-end cost of earning a professional certification — exam fees, training, materials and the extras most first-time candidates forget.
Continue reading·5 min read
When paid certification training earns its price and when self-study wins — a decision framework comparing courses, bootcamps and self-study by candidate situation.
Continue reading