ISC² (International Information System Security Certification Consortium) — Vendor Overview
V015 · Information Security, Risk, Compliance · 5 active certifications · SA presence: Strong
Quick pitch: ISC² is the most respected information security certification body globally; CISSP is the gold standard for enterprise security professionals and is mandatory or strongly preferred for security leadership roles across all industries.
Company Snapshot
| Field | Detail |
|---|---|
| Full name | International Information System Security Certification Consortium |
| Founded | 1989 — established standardised information security certifications |
| Headquarters | Alexandria, Virginia, USA |
| Employees | ~200 globally (2026) |
| Revenue | Private non-profit; revenue estimates ~$50–80M annually |
| Listed | Non-profit |
| Core business | Develops and administers security certifications (CISSP, CCSK, CSSLP, CAP, ISSAP); provides training materials and maintains ethical standards. 100% certification and training revenue. |
| SA office | No direct office; strong partner network including TrackitSA, Westcon-Comstech, regional training providers |
What ISC² Does
ISC² is the premier non-profit information security certification body globally. The organisation maintains exceptionally high ethical and professional standards; CISSP holders must adhere to the Code of Ethics and maintain continuing professional education. The five certifications span different specialisations: CISSP (general security professional), CCSK (cloud security), CSSLP (secure software development), CAP (access control), and ISSAP (security architect).
ISC² maintains approximately 600,000+ CISSP holders globally, making it the largest professional security certification community worldwide. The organization is vendor-neutral and highly respected by enterprise security leadership. Competitors are vendor-specific programs (Palo Alto, Check Point, Fortinet) and competing certifications (CompTIA Security+, EC-Council CEH), but CISSP remains the gold standard for enterprise security professionals.
Certification Portfolio
Active certifications (5 total)
| Level | Cert Name | Code | Domain | Cost (USD) | Valid |
|---|---|---|---|---|---|
| Associate | Associate of (ISC)² | CISSP-A | Security Fundamentals | $749 | Lifetime |
| Professional | CISSP – Certified Information Systems Security Professional | CISSP | Enterprise Security | $749 | 3 yrs |
| Professional | CCSK – Certified Cloud Security Knowledge | CCSK | Cloud Security | $395 | 3 yrs |
| Professional | CSSLP – Certified Secure Software Lifecycle Professional | CSSLP | Secure Development | $749 | 3 yrs |
| Professional | CAP – Certified Access Professional | CAP | Access Control | $395 | 3 yrs |
Additional advanced cert: ISSAP (Security Architect specialist level)
Recommended starting cert
CISSP-A (Associate of ISC²) — Prerequisite for full CISSP. Validates foundational information security knowledge across 8 domains (security architecture, asset security, security engineering, communication/network security, identity/access management, security assessment, security operations, software development security). 3-hour exam; ~100–110 questions. Lifetime credential (no expiry). Prerequisites: 5 years security professional experience (or equivalent education/military background). ~4–6 months study.
Cert ladder for new starters
CISSP-A (Associate) → CISSP (Professional after 5 years experience)
CCSK or CSSLP (specialisations, parallel tracks)
Why ISC² Matters in 2026
CISSP is the gold standard for enterprise security professionals globally. LinkedIn shows 38,000+ open CISSP-related job postings, making it the #1 security certification by employer demand. CISSP is mandatory or strongly preferred for Chief Information Security Officer (CISO), security architect, and security manager roles at Fortune 500 companies, government agencies, and financial services firms.
ISC² maintains exceptionally rigorous ethical and professional standards. CISSP holders must commit to continuing professional education (CPE) and ethical conduct, making the credential particularly valuable for regulated industries. The certification ecosystem is exceptionally healthy; ISC² invests heavily in training and community development. CISSP salaries command premium rates globally, particularly in financial services and government sectors.
Job Market Data
Global demand
| Metric | Value | Source | Date |
|---|---|---|---|
| Active job postings mentioning CISSP | 38,000+ | LinkedIn Jobs | May 2026 |
| Growth YoY | +12% | LinkedIn Salary Insights | 2025–2026 |
| Top job title hiring | Security Manager | May 2026 | |
| Top hiring countries | USA, UK, Canada, Australia, India | May 2026 |
Common job titles requiring ISC² skills
| Job Title | Seniority | Median USD Salary | Median ZAR Salary |
|---|---|---|---|
| CISSP-A / Associate | Mid | $78,000 | R71,800/month |
| CISSP – Senior Security Manager | Senior | $135,000 | R124,200/month |
| CISSP – Security Architect | Senior | $145,000 | R133,400/month |
| CISO / CISSP-Expert | Executive | $200,000+ | R184,000+/month |
South Africa Presence
Direct presence
ISC² has no direct office in South Africa but operates through a strong partner network. Primary partners include TrackitSA, Westcon-Comstech, and regional training providers. CISSP is exceptionally valued in SA enterprise security roles.
SA job market
South African banks (ABSA, Nedbank, FirstRand, Standard Bank, Investec), government agencies, and large enterprises mandate CISSP or equivalent for security leadership roles. CISSP is the gold standard credential for SA enterprise security professionals. Demand is exceptionally strong; CISSP holders command premium salaries in SA security market.
Median salary for CISSP-certified Security Manager in SA is R124,200/month (approximately $6,700 USD), among the highest for technical certifications. CISO roles command R184,000+/month.
SA training providers
| Provider | Cert(s) offered | URL |
|---|---|---|
| TrackitSA | CISSP, CCSK | trackitsa.co.za |
| Westcon-Comstech Academy | CISSP, CCSK, CSSLP | westcon.co.za |
| ISC² Learning Hub | All ISC² certs | isc2.org |
| Linux Academy / A Cloud Guru | CISSP | acloudguru.com |
Vendor Ecosystem
Key technologies and platforms
- Security architecture frameworks (NIST, ISO 27001, CIS Controls)
- Risk management (RISKR framework)
- Identity and access management (IAM)
- Cryptography and encryption standards
- Secure software development lifecycle (SDLC)
- Cloud security frameworks
- Incident response and forensics
Complementary vendors and certs
| Complementary Vendor | Why they pair well |
|---|---|
| ISACA (CISA) | Risk and governance specialist complements security professional |
| CompTIA Security+ | Entry-level cert before CISSP |
| Palo Alto, Check Point | Vendor certifications complement CISSP career |
| Cloud vendors (AWS, Azure) | Cloud architects often pursue CISSP for security foundation |
Community and resources
| Resource | Type | URL |
|---|---|---|
| ISC² Learning Hub | Official | isc2.org/learning |
| ISC² Community Forum | Community | isc2.org/community |
| r/cissp | Community | reddit.com/r/cissp |
| ISC² YouTube | Learning | youtube.com/c/ISC2 |
Vendor History & Roadmap
Key milestones
| Year | Event |
|---|---|
| 1989 | Founded; established CISSP certification |
| 2000 | CISSP became gold standard for security professionals |
| 2008 | Launched CCSK (cloud security) |
| 2015 | Introduced CSSLP (secure software development) |
| 2020 | Expanded CPE requirements; emphasised ethical conduct |
| 2024 | Introduced advanced specialisation certs (ISSAP) |
| 2025–2026 | Focus on AI security, cloud-native security, zero-trust |
| 2026 | CISSP remains gold standard; AI security specialisation growing |
Outlook
ISC² is firmly positioned as the premier information security certification authority globally. The organisation's non-profit status and ethical commitment ensure long-term credibility. For certification professionals, CISSP remains secure and in exceptionally high demand, particularly for career progression to management and leadership roles. Exam content will evolve to include AI security, supply chain risk, and zero-trust architecture over the next 12–24 months.
Frequently Asked Questions
Q: Is CISSP worth investing in for my career? Yes, absolutely—if you want a security career trajectory to management and leadership. CISSP is the gold standard for enterprise security professionals.
Q: How often do CISSP certs expire? CISSP expires after 3 years. Renewal requires earning 120 Continuing Professional Education (CPE) points or passing the CISSP renewal exam.
Q: Are CISSP certs recognised in South Africa? Absolutely. CISSP is the gold standard credential for SA enterprise security professionals and is mandatory for CISO roles.
Q: What's the best cert to start with from ISC²? CISSP-A (Associate), which requires 5 years security experience or equivalent. Expect 4–6 months study with extensive hands-on knowledge requirements.
Related Content
- Cert Roadmap → — Full progression diagram
- Ecosystem Deep Dive → — Technology landscape, tools, job market
- Individual Cert Files → — Per-exam breakdowns
Sources
| # | Source | URL | Used for |
|---|---|---|---|
| 1 | ISC² Certifications | isc2.org/certifications | Company data, cert portfolio |
| 2 | ISC² About | isc2.org/about | History, mission, ethics |
| 3 | LinkedIn Jobs – CISSP | linkedin.com/jobs | Job market data |
| 4 | TrackitSA (SA Partner) | trackitsa.co.za | SA presence, training |
Template version: 2026-05-03 | Maintained by IT Career Roadmap