CISSP · ● Active · Expert · ISC2
ISC2's flagship security certification — the gold standard for information security professionals globally. Required endorsement from an existing CISSP holder within 9 months of passing. The most respected credential at the expert level across all security domains.
Exam facts
| Field | Value |
|---|---|
| Cost | $749 USD |
| Duration | 3 hours |
| Questions | 100–150 (CAT format) |
| Passing | 700/1000 scaled |
| Format | Multiple choice (Computerized Adaptive Testing) |
| Delivery | Pearson VUE |
| Languages | English (primary); Japanese available |
| Valid | 3 years |
| Renewal | 120 CPE credits over 3 years + $135 annual maintenance fee |
| Prerequisites | 5 years cumulative paid work experience in 2+ of 8 CBK domains (waivable with degree or approved cert) |
| Released | 1994 (current CBK v2024 revision) |
| Retiring | N/A |
Vendor source — ISC2 CISSP Certification ↗
Official exam guide — CISSP Exam Blueprint ↗
Exam objectives — CISSP CBK Domains (2024) ↗
About
The CISSP (Certified Information Systems Security Professional) is the premier vendor-neutral security certification recognized globally by enterprises, government agencies, and Fortune 500 companies. Launched in 1994, CISSP validates mastery across eight domains of information security and is widely considered the benchmark credential for security architects, managers, and senior technical leaders. The 2024 update to the Common Body of Knowledge (CBK) reflects modern threat landscapes, cloud security, zero-trust architectures, and AI-driven security operations. Unlike entry-level certs, CISSP requires verified professional experience and endorsement, making it a lifetime achievement in the security field.
Domain context — Security
Core information security and risk management across people, processes, and technology. CISSP sits at the expert apex — a prerequisite for CISO roles and a signal of deep, multi-domain security competency.
Read full deep dive — ISC2 Ecosystem ↗
Topics covered
CISSP's eight Common Body of Knowledge (CBK) domains, weighted by exam emphasis (2024 update):
- Security & Risk Management (16%) — Risk assessment, governance, compliance frameworks (ISO 27001, NIST, COBIT), privacy regulations (GDPR, CCPA), business continuity, disaster recovery.
- Asset Security (10%) — Data classification, handling, retention, destruction. Physical security. Media sanitization.
- Security Architecture and Engineering (13%) — Cryptography, PKI, secure design principles, CIA triad, defense-in-depth, resilience.
- Communication and Network Security (13%) — OSI model, network protocols, VPNs, firewalls, intrusion detection, wireless security.
- Identity and Access Management (IAM) (13%) — Authentication, authorization, identity federation, MFA, SSO, privilege management, directory services.
- Security Assessment and Testing (12%) — Vulnerability management, penetration testing, security testing methodologies, code review.
- Security Operations (13%) — Incident response, detection and monitoring, SIEM, forensics, threat hunting, log analysis.
- Software Development Security (10%) — Secure SDLC, threat modeling, API security, supply chain security, secure coding practices.
Source: ISC2 CISSP CBK Overview ↗
Common skills at Security · Expert
Shared competencies across the security domain at expert level — not specific to CISSP, but foundational for the role.
- Risk quantification and Monte Carlo modeling — Translate threat and vulnerability data into financial risk metrics; communicate upward to executives and boards.
- Enterprise architecture and security integration — Design security into systems at scale; work with infrastructure and application teams across hybrid/multi-cloud.
- Incident response leadership — Triage, contain, remediate, and communicate major breaches; lead cross-functional war rooms.
- Compliance program design — Map regulatory frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS, FedRAMP) to business controls; coordinate audits.
- Threat intelligence synthesis — Translate open-source and proprietary threat data into prioritized defensive actions.
- Executive communication — Explain technical security to C-suite in business language; justify budget for security initiatives.
Recommended courses at Security · Expert
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISC2 Official | CISSP Training Bootcamp (5 days) | $1,995 | ↗ |
| Destination Certification | CISSP MasterClass (Rob Witcher) | $695–$995 | ↗ |
| Cybrary | CISSP (Official ISC2 Content) | Free / $99/month premium | ↗ |
| Kelly Handerhan (Cybrary) | CISSP Deep Dive (Domain-by-domain) | Free / Premium | ↗ |
| Andrew Ramdayal (Udemy) | CISSP - Complete Package (8+ hours) | $12–$99 | ↗ |
| INE (Information Security) | CISSP Bootcamp (OnDemand) | $199–$399 | ↗ |
Course-selection rule: Rob Witcher's Destination Cert MasterClass and Kelly Handerhan's Cybrary series are widely regarded as the gold standard for CISSP prep. The official ISC2 bootcamp is expensive but direct; Cybrary's free content is comprehensive for budget-conscious learners.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| Boson | ExSim-Max CISSP (200+ questions, adaptive) | $99–$149 | ↗ |
| Destination Certification | CISSP Practice Exams (250+ questions) | $69–$99 | ↗ |
| Whizlabs | CISSP Practice Tests (2000+ questions) | $99 | ↗ |
| ISC2 Official | Official CISSP Practice Exams | $50–$100 | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| CISSP Study Guide (8th Edition) | Mike Chapple, James Stewart, Darril Gibson | Sybex | 2023 | 978-1119790280 | ↗ |
| CISSP All-in-One Exam Guide (8th Edition) | Shon Harris, Fernando Maymí | McGraw-Hill | 2023 | 978-1260474572 | ↗ |
| The CISSP Prep Guide (3rd Edition) | Ronald Krutz, Russell Dean Vines | Wiley | 2022 | 978-1119679981 | ↗ |
| CISSP For Dummies (5th Edition) | Lawrence C. Miller, Peter Gregory | For Dummies | 2021 | 978-1119696339 | ↗ |
Book rule: All titles are current (2023–2023) and reflect the 2024 CBK update or are explicitly compatible with it. The Sybex and McGraw-Hill guides are industry standards; Whizlabs and INE also publish companion study materials.
Typical job titles at Security · Expert
Security Architect · Chief Information Security Officer (CISO) · Information Security Manager · Senior Security Engineer · Risk Manager · Compliance Officer · Security Operations Center (SOC) Director · Incident Response Manager · Enterprise Security Manager
(Job titles drawn from current job-board postings (LinkedIn, Indeed, Glassdoor) that list CISSP as required or strongly preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $120,000–$200,000+ | Glassdoor CISSP Salary ↗ · Robert Half 2024 Salary Guide ↗ · Levels.fyi Security ↗ |
| ZAR | R2,200,000–R3,600,000 (annualized) | Pnet Security Roles ↗ · PayScale South Africa ↗ |
| GBP | £90,000–£160,000 | IT Jobs Watch Security ↗ · Hays Salary Report ↗ |
| EUR | €95,000–€180,000 (DE/FR/NL) | Robert Half Europe ↗ · Salary.com Europe ↗ |
| AUD | A$150,000–A$250,000 | SEEK Australia ↗ · PageUp IT Salary Report ↗ |
Salary note: CISSP holders command significant premiums over non-certified peers in the same role. The credential is a hard requirement for many C-suite and director-level positions, especially in regulated industries (finance, healthcare, government). Regional data reflects 2024–2025 surveys; ZAR data is drawn from South African job boards and adjusted for PPP.
Skills validated
Concrete technologies, frameworks, and practices tested by the CISSP exam — distinct from general domain competencies.
- Cryptography fundamentals — Symmetric/asymmetric encryption, hashing, digital signatures, PKI, certificate lifecycle management.
- Access control models — RBAC, ABAC, DAC, threat actors with varying privilege levels, identity federation (SAML, OAuth 2.0).
- Secure development lifecycle (SDLC) — Threat modeling (STRIDE, PASTA), code review, static/dynamic analysis, secure coding standards (OWASP Top 10).
- Incident response process — Detection, containment, eradication, recovery, post-incident review; chain of custody and evidence handling.
- Risk management frameworks — NIST RMF, ISO 31000, quantitative/qualitative risk analysis, risk tolerance thresholds.
- Network security architectures — Firewalls, VPNs, IDS/IPS, DMZ design, network segmentation, zero-trust principles.
- Compliance and governance — SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS, FedRAMP, audit planning and execution.
- Business continuity and disaster recovery (BC/DR) — RTO, RPO, backup strategies, failover, recovery testing.
- Vulnerability and penetration testing methodologies — Scope, methodology, reporting, remediation tracking.
- Threat intelligence and malware analysis — TTPs, indicators of compromise (IOCs), threat feeds, tactical/strategic/operational intelligence.
Experience prerequisites and Associate path
Standard path (5-year experience required):
- 5 years cumulative paid professional work experience in 2 or more of the 8 CBK domains.
- Experience can span multiple roles and employers; military, government, and contracting work counts if full-time equivalent.
- Once you pass the exam, you have 9 months to secure endorsement from an active CISSP holder. Without endorsement, you hold "Associate of ISC2" status until endorsed.
Faster path (with degree or approved cert):
- Bachelor's degree in relevant field (Computer Science, Information Security, etc.) + 4 years experience in 2+ CBK domains.
- Or: GIAC (GPEN, GCIH, GCIA, GSEC), CompTIA (Security+), (ISC)² CAP, or other approved credentials waive 1 year of experience.
Associate of ISC2 status:
- Pass the exam without the required experience.
- Hold "Associate" badge for 5 years while building experience.
- Once you reach 5 years in 2+ CBK domains, you can be endorsed to full CISSP.
Endorsement process
After passing the exam, you must secure endorsement from an active CISSP (or CCSK, CCEP, CISSP-ISSAP holder) within 9 months:
- Contact an eligible endorser (can be a colleague, former manager, or mentor with active CISSP).
- Endorser reviews your experience and verifies your work history.
- ISC2 sends endorsement form to both you and the endorser for digital signature.
- Once signed, ISC2 grants you full CISSP status.
- Endorsement does not confer approval or liability on the endorser — it confirms you've met the experience requirement.
Finding an endorser: ISC2 maintains a limited endorser directory, but many CISSPs participate in local chapters or security communities. LinkedIn and industry conferences are also valuable resources.
Related certifications
- Stacks with: SSCP (ISC2) ↗ — complement at associate/professional level, covers narrower scope
- Prerequisite for: CISSP-ISSAP (ISC2) ↗ — specialized architecture track (requires active CISSP)
- Prerequisite for: CAP (ISC2) ↗ — certification and accreditation (requires active CISSP)
- Equivalents at this level: GIAC GSLC (GIAC) ↗ — vendor-neutral alternative at expert scope
- Alternative at this level: ECIH (EC-Council) ↗ — ethical hacking specialist (narrower scope, overlapping domains)
- Vendor overview: ISC2 Overview ↗
Renewal and maintenance
After certification:
- Valid for 3 years from the date ISC2 grants your active CISSP status.
- 120 CPE credits required over the 3-year cycle (average 40 CPEs/year).
- $135 annual maintenance fee (AMF) due each year to maintain active status.
- CPE sources: Training courses, conference attendance, published articles, volunteer work in security organizations, university teaching, advanced degrees, or ISC2-approved webinars.
- Renewal process: At year 3, submit CPE transcript and renew AMF; ISC2 grants a new 3-year certificate.
Without renewal, your credential lapses to "lapsed CISSP" and you lose the title — though many employers honor lapsed status if you maintain currency.
Career impact and trajectory
Pre-CISSP: Security roles typically max out at Senior Security Engineer or Manager without CISSP. Advancement to CISO, Chief Risk Officer (CRO), or director-level positions often requires CISSP or equivalent pedigree.
At CISSP: Opens doors to executive-track roles, C-level advisor positions, board opportunities, and high-stakes consulting. Government and regulated-industry (financial, healthcare) roles frequently mandate CISSP.
Post-CISSP: Many professionals pursue specialized paths:
- CISSP-ISSAP (Architecture) — for security architects and infrastructure leaders.
- CAP (Certification & Accreditation) — for government/federal security compliance roles (especially FedRAMP, NIST).
- CCSK (Cloud) — for cloud security specialization (often taken alongside CISSP).
- GIAC certifications — for deeper technical specialization (GPEN for pentest, GCIH for incident response, GCIA for defensive).
Sources
- ISC2 CISSP Certification Page
- ISC2 CISSP CBK Domains (2024)
- CISSP Exam Blueprint
- Destination Certification CISSP MasterClass
- Cybrary CISSP Free Course
- Boson ExSim-Max CISSP
- Sybex CISSP Study Guide (8E)
- McGraw-Hill CISSP All-in-One (8E)
- Glassdoor CISSP Salary
- Robert Half 2024 IT Salary Guide
- IT Jobs Watch UK Security Salary
Last verified: 2026-05-01
Parent ecosystem: ISC2 Ecosystem
Parent domain: Security Domain
Vendor overview: ISC2 Vendor Overview