Exampractice
Cybersecurity

ISC2 Certifications Explained

A complete map of ISC2's certifications — CC, SSCP, CISSP, CCSP, CSSLP and the concentrations — with experience requirements, formats, costs and renewal.

Alexander Novak · 9 min read
Route-map diagram showing ISC2 certifications from CC through SSCP and CISSP with branches to CCSP, CSSLP and CISSP concentrations

ISC2's certification portfolio is best read as a single system built around one variable: verified work experience. Every credential in the line-up — from the entry-level Certified in Cybersecurity (CC), which requires none, to the CISSP concentrations, which stack years on top of the CISSP's own five — occupies a rung defined by how much professional experience ISC2 will make you prove before it certifies you. Understand that, and a portfolio that looks like alphabet soup (CC, SSCP, CISSP, CCSP, CSSLP, ISSAP, ISSEP, ISSMP, CGRC) resolves into a coherent map. This article is that map: what each credential is, what it demands, what it costs, and how the shared membership machinery behind all of them works.

One housekeeping note first: the organisation renamed itself from "(ISC)²" to simply "ISC2" in 2023, so both spellings refer to the same body — a non-profit membership association for cybersecurity professionals whose exams are delivered at Pearson VUE test centres worldwide.

How the portfolio is organised

ISC2 credentials fall into three layers:

  1. Entry and practitioner level — CC (no experience) and SSCP (one year). These certify foundational knowledge and hands-on operational skill.
  2. Professional level — CISSP (five years, managerial breadth), CCSP (five years, cloud specialism) and CSSLP (four years, secure software development). These are the career-defining credentials.
  3. Post-CISSP concentrations — ISSAP (architecture), ISSEP (engineering) and ISSMP (management), which deepen a CISSP in one direction. ISC2 also offers CGRC for governance, risk and compliance specialists.

Every certification shares the same scaffolding: a 700/1000 passing standard, an endorsement step after the exam, a three-year renewal cycle with continuing professional education (CPE) credits, and an annual maintenance fee (AMF). We will return to that shared machinery after the credential-by-credential tour. Note also that prices below are Americas/USD as listed in 2026 — ISC2 prices regionally, so confirm your local fee before booking.

Certified in Cybersecurity (CC) — the open door

  • Experience required: none. No work history, no endorser needed to sit the exam.
  • Exam: adaptive (CAT) since 1 October 2025; 100–125 items, maximum 2 hours; $199 USD.
  • Domains (current outline): Security Principles (26%), Network Security (24%), Access Controls Concepts (22%), Security Operations (18%), and Business Continuity, Disaster Recovery and Incident Response Concepts (10%). A new outline takes effect on 1 September 2026, so check ISC2's CC exam outline page if you are booking beyond that date.
  • Renewal: 45 CPEs per three-year cycle and a $50 annual fee — lower than the $135 attached to ISC2's other certifications.

The CC exists to get newcomers onto the ladder. One caution for 2026 readers: the "One Million Certified in Cybersecurity" programme that made the CC's training and exam free closed to new participants on 20 May 2026, after passing one million enrolees. Codes already issued can be used through 31 December 2026, but new candidates should budget for the standard $199 exam fee.

Systems Security Certified Practitioner (SSCP) — hands-on operations

  • Experience required: one year of cumulative paid work in one or more of its seven domains (an Associate pathway exists if you lack it).
  • Exam: CAT since 1 October 2025; 100–125 items, maximum 2 hours; $249 USD; offered in English, Japanese and Spanish.
  • Domains (October 2025 outline): Security Concepts and Practices (16%), Network and Communications Security (16%), Access Controls (15%), Risk Identification, Monitoring and Analysis (15%), Systems and Application Security (15%), Incident Response and Recovery (14%), Cryptography (9%).
  • Renewal: 60 CPEs per cycle (minimum 45 "Group A" — directly security-related), $135 AMF.

The SSCP certifies the person who operates security: administering access controls, monitoring, responding to incidents, hardening systems. Full detail on the credential lives in our SSCP certification guide, and how it stacks against ISC2's flagship is a big enough question that it has its own article: SSCP vs CISSP.

Certified Information Systems Security Professional (CISSP) — the flagship

  • Experience required: five years of cumulative paid work in at least two of its eight domains. A relevant degree or an approved credential (CompTIA Security+, CCSP and others on ISC2's list) waives at most one year, and only one waiver applies. Part-time work and documented internships count under published formulas. Candidates without the experience can pass the exam and become an Associate of ISC2, with six years to earn the remaining experience.
  • Exam: CAT in all languages since 15 April 2024; 100–150 items, maximum 3 hours; $749 USD. Results are pass/fail — CAT candidates receive no numeric score, only below/near/above-proficiency domain feedback on a fail. You cannot return to earlier questions.
  • Domains (2024 outline): Security and Risk Management (16%), Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security (10%). The April 2024 refresh nudged two weightings (Domain 1 up one point, Domain 8 down one) and shortened the exam from its previous format.
  • Renewal: 120 CPEs per cycle (minimum 90 Group A), $135 AMF.

The CISSP is ISC2's broadest and most senior mainstream credential, aimed at people who design and run security programmes rather than individual controls. Everything about it — process, domains, costs — is unpacked in the CISSP certification guide; eligibility fine print is in CISSP experience requirements.

Certified Cloud Security Professional (CCSP) — the cloud specialist

  • Experience required: five years of cumulative full-time IT experience, of which three must be in information security and one in a CCSP domain. Two shortcuts exist: the Cloud Security Alliance's CCSK can substitute for one year, a relevant degree can waive one year (one waiver total) — and, notably, an active CISSP satisfies the entire CCSP experience requirement.
  • Exam: CAT since 1 October 2025 (the old 125-question linear format is retired); 100–150 items, maximum 3 hours; $599 USD; available in English, Chinese, Japanese and German.
  • Domains (outline listed effective 1 August 2026): Cloud Data Security (20%), Cloud Concepts, Architecture and Design (17%), Cloud Platform and Infrastructure Security (17%), Cloud Security Operations (17%), Cloud Application Security (16%), and Legal, Risk and Compliance (13%).
  • Renewal: 90 CPEs per cycle (minimum 60 Group A), $135 AMF.

The CCSP applies security discipline to cloud architecture, data and operations. It is the natural second ISC2 credential for CISSP holders moving into cloud-heavy roles — the overlap question is handled in CCSP vs CISSP: do you need both? — and the full run-down is in the CCSP certification guide. For market context: Skillsoft's 2025 Top-Paying IT Certifications list put the CCSP's US average at $171,524, a figure worth reading as one dataset's snapshot rather than a promise — pay varies enormously by location, role and experience.

Certified Secure Software Lifecycle Professional (CSSLP) — security for software teams

  • Experience required: four years of cumulative full-time experience in one or more of its eight domains; Associate pathway available.
  • Exam: still linear (it was not part of the October 2025 CAT migration): 125 items, 3 hours, $599 USD.
  • Domains (September 2023 outline): eight domains spanning the software lifecycle — secure concepts, lifecycle management, requirements, architecture and design (15%, the heaviest), implementation, testing, deployment and operations, and supply chain security.
  • Renewal: 90 CPEs per cycle (minimum 60 Group A), $135 AMF.

The CSSLP is for developers, DevSecOps engineers, application security specialists and architects who need to prove they can build security into software rather than bolt it on afterwards.

The CISSP concentrations — ISSAP, ISSEP and ISSMP

Three credentials extend the CISSP into specialisms. Eligibility is the same for all three: a CISSP in good standing plus two years of cumulative experience in the concentration's domains — or, in an alternative pathway many overlook, seven years of cumulative relevant experience without the CISSP. Each exam costs $599 USD, and all three are approved under the US Department of Defense's 8140.03 framework.

  • ISSAP (Architecture): a linear 125-item, 3-hour exam refreshed to four domains effective August 2025, weighted towards Infrastructure and System Security (32%) and IAM Architecture (25%). For security architects designing enterprise-scale solutions.
  • ISSEP (Engineering): also linear, 125 items over 3 hours, with a five-domain August 2025 outline led by Systems Security Engineering Foundations (24%). For engineers embedding security into systems engineering processes, often in government and defence contexts.
  • ISSMP (Management): aimed at leaders running security programmes, incident response and governance. ISC2 lists it alongside the other concentrations at $599; check the official ISSMP outline page for current exam format details before booking.

ISC2 also offers CGRC (Certified in Governance, Risk and Compliance) for professionals who authorise and maintain information systems within risk-management frameworks; it shares the standard $135 AMF and three-year cycle.

The machinery every ISC2 certification shares

Endorsement

Passing the exam does not make you certified. Within nine months of passing, you submit an endorsement application vouched for by an ISC2-certified professional in good standing — or by ISC2 itself, with employment verification, if you know no member. ISC2 audits a random sample of applications, so experience claims need to be documentable.

The Associate of ISC2 route

For SSCP, CISSP, CCSP and CSSLP, candidates who pass the exam without the required experience become Associates of ISC2 and get six years to earn it (Associates pay a $50 annual fee and complete 15 CPEs a year). This inverts the usual assumption that ISC2 credentials are closed to early-career professionals: the exam can come first.

Renewal, CPEs and fees

Certifications run on three-year cycles. CPE totals scale with the credential — 120 for CISSP, 90 for CCSP and CSSLP, 60 for SSCP, 45 for CC — with a 90-day grace period after each cycle to finish submissions. Members pay an annual maintenance fee of $135 (CC-only members pay $50). Exam logistics are uniform too: rescheduling costs $50, cancellation $100, and retakes are charged at full exam price.

What ISC2 does not publish

ISC2 releases no pass-rate statistics for any exam — any percentage you encounter online is unofficial. Results for the CAT exams are strictly pass/fail. And if you are researching the retake policy, go directly to ISC2's current policy page; the waiting-period rules quoted around the web are frequently out of date.

The portfolio in one table

CredentialExperience requiredExam formatCost (Americas, 2026)CPEs / 3-year cycle
CCNoneCAT, 100–125 items, 2 h$19945
SSCP1 yearCAT, 100–125 items, 2 h$24960
CISSP5 years (2+ domains)CAT, 100–150 items, 3 h$749120
CCSP5 years IT (3 in security; CISSP waives all)CAT, 100–150 items, 3 h$59990
CSSLP4 yearsLinear, 125 items, 3 h$59990
ISSAP / ISSEPCISSP + 2 years, or 7 yearsLinear, 125 items, 3 h$599See ISC2
ISSMPCISSP + 2 years, or 7 yearsLinear (see ISC2 for details)$599See ISC2

What certification actually costs over three years

A budgeting note the credential pages do not spell out: the exam fee is the smallest recurring line. A CISSP holder, for example, pays $749 once, then $135 every year, and must log 120 CPE credits per cycle — time that is free if your employer funds conference attendance and training, and very much not free otherwise. Add $50 if you reschedule an exam, $100 if you cancel, and a full-price resit if you fail. None of this is an argument against certifying; it is an argument for certifying deliberately, at the level your career can immediately use, rather than collecting badges whose maintenance you will resent.

Reading the map: common misconceptions worth clearing

  • "The CISSP is 250 questions over six hours" — or 175 over four, depending on the vintage of the forum post. Since April 2024 it is 100–150 adaptive questions in at most three hours.
  • "SSCP, CC and CCSP are fixed-length linear exams." All three moved to CAT-only on 1 October 2025; you cannot skip or revisit questions.
  • "CC is free." The free programme closed to new entrants in May 2026.
  • "You must hold CISSP before any concentration." The seven-year alternative pathway says otherwise.
  • "An SSCP is required before the CISSP." No ISC2 credential is a prerequisite for any other, except the CISSP's role in the concentrations' primary pathway.

Which one belongs in your plan?

This article has deliberately stayed descriptive — a gazetteer rather than a recommendation engine. If you want the opinionated version, our companion piece on the best ISC2 certifications for cybersecurity careers ranks these credentials by career stage and role. When you have picked a target, ExamPractice hosts free sample questions for the major ISC2 exams — start from the ISC2 exams hub — with fuller question sets and a timed practice-test simulation available to subscribers, useful for checking your grasp of each domain in the official outlines before you book.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like