CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingWhat cybersecurity certifications actually are, who runs them, how exams and renewal work, and how the major providers differ — a plain-language map.

"CISSP" appears in job advertisements more or less as a job requirement, yet it is not a qualification from any university, government or employer — it is a credential issued by a member association, earned through a three-hour adaptive exam plus five years of documented work experience, and it lapses if the holder stops paying an annual fee. That one example contains almost everything newcomers find confusing about cybersecurity certifications: private bodies, exams, experience rules and expiry dates, all bundled under a four-or-five-letter acronym.
This article is a plain-language map of how the whole system works — what a security certification actually is, who issues them, what kinds exist, and what earning and keeping one involves. It deliberately makes no recommendations; if you want a verdict on where to start, that lives in our guide to the best cybersecurity certifications for beginners.
A cybersecurity certification is a credential awarded by a private certification body to an individual who passes that body's proctored exam and meets its other conditions (sometimes work experience, sometimes an endorsement from an existing member, sometimes nothing at all). It certifies a person, not a course completed: you can prepare however you like — books, videos, labs, formal training — because the exam, not the study route, is the gate.
That distinguishes certifications from three neighbours they are constantly confused with:
Every security certification, whoever issues it, is built from the same five parts. Once you can read these, any acronym becomes decodable.
The organisation whose name backs the credential and whose exam you sit — CompTIA, ISC2, ISACA, and so on. The body publishes the exam objectives (the official syllabus), sets fees, and enforces the rules.
Usually proctored — at a test centre or online under camera supervision — and built in one of a few formats: fixed-length multiple choice (ISACA's exams are 150 questions in four hours), multiple choice mixed with hands-on performance-based questions (CompTIA), computerised adaptive testing that adjusts difficulty as you answer (ISC2's CISSP runs 100–150 items in up to three hours), or lab-heavy hands-on testing (GIAC's CyberLive components; OffSec's 24-hour practical OSCP exam). Passing standards are typically scaled scores — 750 on CompTIA's 100–900 scale, 700 out of 1,000 at ISC2, 450 on ISACA's 200–800 scale — not raw percentages.
Some certifications anyone may attempt (Security+, ISC2's CC, every GIAC practitioner exam). Others require documented professional experience to certify — five years for CISSP and CISM, for example — though ISC2 and ISACA both let you pass the exam first and complete the experience afterwards. A common newcomer misreading: "recommended experience" on CompTIA pages is guidance about difficulty, not an entry rule.
Exam content is refreshed every few years and each revision carries a code — Security+ is SY0-701 as of 2026; its predecessor SY0-601 is retired. The credential name on your certificate never includes the code; the code matters only for matching study materials to the live exam. Retirements catch people out constantly: CASP+ no longer exists as a current exam, having been renamed CompTIA SecurityX (CAS-005) in December 2024.
Nearly all security certifications expire — commonly on a three-year cycle (CompTIA, ISC2, ISACA) or four years at GIAC — and are maintained through continuing education credits (CEUs or CPEs) plus maintenance fees. This is the part newcomers most often fail to budget for: a certification is a subscription to a professional standard, not a one-off trophy.
Five bodies issue the bulk of the certifications you will see in security job advertisements, and each has a recognisable character.
| Provider | What it is | Character of its certs | Flagship examples |
|---|---|---|---|
| CompTIA | US-based industry association | Vendor-neutral, broad, exam-only entry at every level | Security+, CySA+, PenTest+, SecurityX |
| ISC2 | Membership association (renamed from "(ISC)²" in 2023) | Experience-gated professional credentials with member obligations | CC, SSCP, CISSP, CCSP |
| ISACA | Association rooted in audit and governance | Business-facing: audit, risk, security management | CISA, CISM, CRISC |
| EC-Council | Commercial training-and-certification company | Training-led, offensive-security branding | CEH, ECSA lineage |
| GIAC | Certification body affiliated with the SANS Institute | Deep, hands-on, open-book technical exams | GSEC, GCIH, GPEN |
Two structural notes help decode the market. First, GIAC and SANS are separate organisations by design — SANS sells the (expensive, optional) training courses, GIAC runs the exams, and no GIAC practitioner exam requires the course. Second, ISC2 and ISACA are membership bodies: certifying makes you a member with annual fees and ethics obligations, which is part of why employers read their credentials as professional standing rather than just exam passes. Vendor ecosystems (Cisco, Microsoft, AWS) also run security certifications tied to their own technologies — a sixth category this cluster covers elsewhere.
Certifications sort along two axes. By level: entry (ISC2 CC, Security+), intermediate (CySA+, PenTest+, SSCP, GSEC), and advanced (CISSP, SecurityX, OSCP, CISM), where "advanced" usually means an experience requirement or a brutally practical exam. By specialism: defensive operations, offensive testing, governance/audit/risk, and niches like forensics, cloud security and industrial control systems. Which sequence suits which career is exactly the question this article does not answer — the full sequencing map is our guide to the best certifications for cybersecurity careers.
Government frameworks add a third sorting: the US NICE Workforce Framework defines 52 cyber work roles, and the Department of Defense's 8140 policy maps approved qualifications to those roles for its workforce — one reason certain certifications (Security+, CISSP among them) are near-mandatory in US defence-sector jobs.
If you fail, providers allow retakes under waiting-period rules that differ by body (CompTIA permits an immediate second attempt; ISACA imposes 30- and 90-day waits) — always at a fresh fee, which is the practical argument for benchmarking before booking.
They matter as signals, and the signal strength varies by context. Employers use them to filter applications at volume; US defence work formally requires approved certifications for many roles under DoD 8140; and ISC2's 2024 Cybersecurity Workforce Study reported a global workforce gap of more than 4.7 million people, which is the demand backdrop against which employers lean on credentials to sort candidates quickly. What certifications cannot do is substitute for demonstrable skill in interviews or on the job — the industry's long-running consensus is that they open doors and experience keeps them open. Claims you should treat sceptically: any published "pass rate" for CISSP, CISM or similar (the major bodies do not publish them) and any single "average salary" attached to a cert without a named, dated source.
You now have the grammar of the system: a certification is a renewable credential from a private body, decoded by its provider, level, specialism, exam format and maintenance rules. The natural next steps are choosing a lane — the staged sequencing in the cybersecurity certification roadmap — and getting a feel for real exam-style material, for which our sibling guide to free cybersecurity practice questions and the certification exams directory are useful first stops. Whichever acronym you eventually pursue, read its official objectives page before any third-party opinion, including ours.
The credentials themselves are — a CISSP earned in Lagos is the same credential as one earned in London. Exam pricing, available languages and local recognition vary by country, and each provider's site lists regional details.
Yes. Work experience does not automatically renew a certification; you must log the required continuing-education credits and pay maintenance fees on the provider's cycle, or pass a current exam again.
Almost never for the bodies covered here — CompTIA, ISC2, ISACA and GIAC all allow self-study. The main exception pattern is EC-Council's CEH, where you either take official training or qualify via documented experience plus an application fee.
Proctoring means your identity is checked and you are supervised (in person or by camera) under closed conditions, which is why employers treat proctored certifications as stronger evidence than course-completion certificates with unsupervised assessments.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading