CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingA complete map of ISC2's certifications — CC, SSCP, CISSP, CCSP, CSSLP and the concentrations — with experience requirements, formats, costs and renewal.

ISC2's certification portfolio is best read as a single system built around one variable: verified work experience. Every credential in the line-up — from the entry-level Certified in Cybersecurity (CC), which requires none, to the CISSP concentrations, which stack years on top of the CISSP's own five — occupies a rung defined by how much professional experience ISC2 will make you prove before it certifies you. Understand that, and a portfolio that looks like alphabet soup (CC, SSCP, CISSP, CCSP, CSSLP, ISSAP, ISSEP, ISSMP, CGRC) resolves into a coherent map. This article is that map: what each credential is, what it demands, what it costs, and how the shared membership machinery behind all of them works.
One housekeeping note first: the organisation renamed itself from "(ISC)²" to simply "ISC2" in 2023, so both spellings refer to the same body — a non-profit membership association for cybersecurity professionals whose exams are delivered at Pearson VUE test centres worldwide.
ISC2 credentials fall into three layers:
Every certification shares the same scaffolding: a 700/1000 passing standard, an endorsement step after the exam, a three-year renewal cycle with continuing professional education (CPE) credits, and an annual maintenance fee (AMF). We will return to that shared machinery after the credential-by-credential tour. Note also that prices below are Americas/USD as listed in 2026 — ISC2 prices regionally, so confirm your local fee before booking.
The CC exists to get newcomers onto the ladder. One caution for 2026 readers: the "One Million Certified in Cybersecurity" programme that made the CC's training and exam free closed to new participants on 20 May 2026, after passing one million enrolees. Codes already issued can be used through 31 December 2026, but new candidates should budget for the standard $199 exam fee.
The SSCP certifies the person who operates security: administering access controls, monitoring, responding to incidents, hardening systems. Full detail on the credential lives in our SSCP certification guide, and how it stacks against ISC2's flagship is a big enough question that it has its own article: SSCP vs CISSP.
The CISSP is ISC2's broadest and most senior mainstream credential, aimed at people who design and run security programmes rather than individual controls. Everything about it — process, domains, costs — is unpacked in the CISSP certification guide; eligibility fine print is in CISSP experience requirements.
The CCSP applies security discipline to cloud architecture, data and operations. It is the natural second ISC2 credential for CISSP holders moving into cloud-heavy roles — the overlap question is handled in CCSP vs CISSP: do you need both? — and the full run-down is in the CCSP certification guide. For market context: Skillsoft's 2025 Top-Paying IT Certifications list put the CCSP's US average at $171,524, a figure worth reading as one dataset's snapshot rather than a promise — pay varies enormously by location, role and experience.
The CSSLP is for developers, DevSecOps engineers, application security specialists and architects who need to prove they can build security into software rather than bolt it on afterwards.
Three credentials extend the CISSP into specialisms. Eligibility is the same for all three: a CISSP in good standing plus two years of cumulative experience in the concentration's domains — or, in an alternative pathway many overlook, seven years of cumulative relevant experience without the CISSP. Each exam costs $599 USD, and all three are approved under the US Department of Defense's 8140.03 framework.
ISC2 also offers CGRC (Certified in Governance, Risk and Compliance) for professionals who authorise and maintain information systems within risk-management frameworks; it shares the standard $135 AMF and three-year cycle.
Passing the exam does not make you certified. Within nine months of passing, you submit an endorsement application vouched for by an ISC2-certified professional in good standing — or by ISC2 itself, with employment verification, if you know no member. ISC2 audits a random sample of applications, so experience claims need to be documentable.
For SSCP, CISSP, CCSP and CSSLP, candidates who pass the exam without the required experience become Associates of ISC2 and get six years to earn it (Associates pay a $50 annual fee and complete 15 CPEs a year). This inverts the usual assumption that ISC2 credentials are closed to early-career professionals: the exam can come first.
Certifications run on three-year cycles. CPE totals scale with the credential — 120 for CISSP, 90 for CCSP and CSSLP, 60 for SSCP, 45 for CC — with a 90-day grace period after each cycle to finish submissions. Members pay an annual maintenance fee of $135 (CC-only members pay $50). Exam logistics are uniform too: rescheduling costs $50, cancellation $100, and retakes are charged at full exam price.
ISC2 releases no pass-rate statistics for any exam — any percentage you encounter online is unofficial. Results for the CAT exams are strictly pass/fail. And if you are researching the retake policy, go directly to ISC2's current policy page; the waiting-period rules quoted around the web are frequently out of date.
| Credential | Experience required | Exam format | Cost (Americas, 2026) | CPEs / 3-year cycle |
|---|---|---|---|---|
| CC | None | CAT, 100–125 items, 2 h | $199 | 45 |
| SSCP | 1 year | CAT, 100–125 items, 2 h | $249 | 60 |
| CISSP | 5 years (2+ domains) | CAT, 100–150 items, 3 h | $749 | 120 |
| CCSP | 5 years IT (3 in security; CISSP waives all) | CAT, 100–150 items, 3 h | $599 | 90 |
| CSSLP | 4 years | Linear, 125 items, 3 h | $599 | 90 |
| ISSAP / ISSEP | CISSP + 2 years, or 7 years | Linear, 125 items, 3 h | $599 | See ISC2 |
| ISSMP | CISSP + 2 years, or 7 years | Linear (see ISC2 for details) | $599 | See ISC2 |
A budgeting note the credential pages do not spell out: the exam fee is the smallest recurring line. A CISSP holder, for example, pays $749 once, then $135 every year, and must log 120 CPE credits per cycle — time that is free if your employer funds conference attendance and training, and very much not free otherwise. Add $50 if you reschedule an exam, $100 if you cancel, and a full-price resit if you fail. None of this is an argument against certifying; it is an argument for certifying deliberately, at the level your career can immediately use, rather than collecting badges whose maintenance you will resent.
This article has deliberately stayed descriptive — a gazetteer rather than a recommendation engine. If you want the opinionated version, our companion piece on the best ISC2 certifications for cybersecurity careers ranks these credentials by career stage and role. When you have picked a target, ExamPractice hosts free sample questions for the major ISC2 exams — start from the ISC2 exams hub — with fuller question sets and a timed practice-test simulation available to subscribers, useful for checking your grasp of each domain in the official outlines before you book.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading