Study offer Save 5% off your preparation plan Use codeEXAM4FUTURE5
View offer

ISC2 certification exams.

Compare current exam codes, certification paths, and preparation options in one focused ISC2 catalog.

10 current examsPublished preparation files available now.
11 certification pathsOrganized routes through the ISC2 catalog.
August 2026Latest catalog update represented in this provider view.

Choose your ISC2 preparation path.

Move between current exams, certification groups, and provider guidance without losing the context of this catalog.

CISSP Certified Information Systems Security Professional (CISSP) Updated August 14, 2026 1562 Q&A CC Certified in Cybersecurity Updated August 14, 2026 1395 Q&A SSCP Systems Security Certified Practitioner Updated August 14, 2026 1114 Q&A CCSP Certified Cloud Security Professional (CCSP) Updated August 14, 2026 891 Q&A CSSLP Certified Secure Software Lifecycle Professional Updated August 14, 2026 464 Q&A CAP Certified Authorization Professional Updated August 14, 2026 399 Q&A HCISPP HealthCare Information Security and Privacy Practitioner Updated August 14, 2026 370 Q&A ISSAP ISSAP Information Systems Security Architecture Professional Updated August 14, 2026 278 Q&A ISSEP ISSEP Information Systems Security Engineering Professional Updated August 14, 2026 266 Q&A ISSMP Information Systems Security Management Professional (ISSMP) Exam Updated August 14, 2026 202 Q&A SCF--NET Secure Software Practitioner - .NET ISC2 exam preparation Pre-order CISSP-ISSAP Information Systems Security Architecture Professional Updated August 14, 2026 Retired CISSP-ISSMP Information Systems Security Management Professional Updated August 14, 2026 Retired CISSP-ISSEP Information Systems Security Engineering Professional Updated August 14, 2026 Retired SCF-.NET Secure Software Practitioner - .NET ISC2 exam preparation Retired SCF-JAVA Secure Software Practitioner - JAVA ISC2 exam preparation Retired SCF-Mobile Secure Software Practitioner - Mobile ISC2 exam preparation Retired SCF-PHP Secure Software Practitioner - PHP ISC2 exam preparation Retired SSP-Android Secure Software Practitioner - Android ISC2 exam preparation Retired SSP-ARCH Secure Software Practitioner - Architect ISC2 exam preparation Retired SSP-C++ Secure Software Practitioner - C++ ISC2 exam preparation Retired SSP-iOS Secure Software Practitioner - iOS ISC2 exam preparation Retired SSP-PM Secure Software Practitioner - PM ISC2 exam preparation Retired SSP-QA Secure Software Practitioner - QA ISC2 exam preparation Retired

ISC2 Certification Guide: Understand the Credential Ecosystem and Choose Your Path

ISC2 offers a vendor-neutral cybersecurity certification ecosystem that spans entry-level learning, operational security, governance, risk, cloud, software, management, architecture and senior leadership. Its credentials are designed for people at different stages, from newcomers without direct IT experience to experienced professionals validating specialized or strategic responsibilities. This overview explains how the portfolio is organized, what the main progression choices involve, how experience and endorsement affect certification, and how to select a sensible next step without treating one credential as the right answer for everyone.

How the ISC2 certification ecosystem is organized

The simplest way to understand ISC2 is to view its portfolio as a set of career-aligned paths rather than a single ladder that every candidate must climb. ISC2 describes its certifications as spanning foundational knowledge through senior leadership and specialized cybersecurity roles, with credentials built around active job roles and maintained through continuing professional education.

ISC2 certifications are vendor-neutral and experience-based. That makes the portfolio relevant to professionals who work with different technologies, platforms and employers rather than only one product family. The certification pages also state that the credentials are accredited to the ISO/IEC 17024 standard through the ANSI National Accreditation Board (ANAB). Accreditation describes the structure and quality controls of the certification program; it does not by itself determine whether a particular credential fits a reader’s job target.

The portfolio includes Certified in Cybersecurity (CC), Systems Security Certified Practitioner (SSCP), Certified in Governance, Risk and Compliance (CGRC), Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Certified Secure Software Lifecycle Professional (CSSLP), HealthCare Information Security and Privacy Practitioner (HCISPP), and the advanced concentrations ISSAP, ISSEP and ISSMP. The most useful choice is therefore based on the work you want to perform and the experience you can document, not simply on choosing the most familiar acronym.

The foundation and early-career lane

CC is ISC2’s entry-level credential and does not require work experience. ISC2 positions it for people entering cybersecurity or transitioning from IT and other professions, including IT professionals, career changers, college students and recent graduates. It validates foundational knowledge rather than requiring a candidate to already have a substantial security career.

SSCP sits in a more hands-on operational direction. ISC2 describes it as suited to practitioners who monitor, administer and defend systems in active security operations roles. CGRC is oriented toward governance, risk and compliance work, making it a more natural consideration for candidates whose responsibilities involve risk management, governance or regulatory alignment.

These options can overlap in a real career. Someone moving from IT administration into security operations may find SSCP more closely related to current duties, while a newcomer without direct experience may need the broader foundation of CC first. A risk analyst or compliance professional may reasonably investigate CGRC rather than defaulting to an operations credential.

Experienced, specialist and leadership paths

CISSP is positioned for experienced practitioners, managers and executives. It covers broad security responsibilities and is often the portfolio’s most natural choice for professionals who coordinate across multiple security domains, lead programs or make organization-wide security decisions. The official experience page requires a minimum of five years of cumulative full-time experience in two or more of the eight CISSP domains.

CCSP focuses on cloud security, while CSSLP focuses on secure software lifecycle responsibilities. HCISPP is the healthcare information security and privacy specialty. The advanced concentrations provide more targeted directions: ISSAP addresses security architecture, ISSEP security engineering and ISSMP security management. ISC2 lists ISSAP as suited to architects developing, designing and analyzing security solutions.

These specialist credentials should be selected because the associated work is central to your role, not merely because the title sounds advanced. A cloud security professional may need a different body of knowledge from a security architect; a software security practitioner may benefit more from CSSLP than from a broad management credential. The best sequence can include a broad credential followed by a specialty, but ISC2 does not require every candidate to collect every certification.

Which ISC2 credential fits your starting point?

Choose the credential that matches both your current responsibilities and your evidence of readiness. A practical starting decision is whether you are entering the field, performing a hands-on security function, managing risk, working in a specialist area or leading across the security program.

The following paths are useful decision categories, not a ranking of ISC2 credentials.

Choose CC if you are building a cybersecurity foundation

CC is the clearest starting point for a newcomer because ISC2 states that no work experience is required. It is also relevant to career changers, students, graduates and IT professionals who want to establish security fundamentals before committing to a more experience-dependent credential.

The current CC exam outline covers Security Principles; Business Continuity, Disaster Recovery and Incident Response Concepts; Access Controls Concepts; Network Security; and Security Operations. Those domains give a newcomer a broad map of the field, including the language used in later study and entry-level work.

CC is not automatically the best choice for someone who already performs substantial security work. If your day-to-day responsibilities already involve administering controls, monitoring systems or responding to security events, compare the SSCP scope and requirements before registering.

Choose SSCP if your work is operational and hands-on

SSCP is a sensible path for a practitioner whose work centers on implementing, monitoring, administering or defending systems. ISC2 places it among certifications for foundational, early-career, risk management and operational roles, and lists one year of required work experience on its certification portfolio page.

Use your actual responsibilities as the test. Evidence such as security operations, system administration with security accountability, access control administration or monitoring duties may be more relevant than a general interest in cybersecurity. Review the current SSCP requirements directly before applying because the official certification page is the controlling source for eligibility.

Choose CGRC when governance, risk and compliance are the center of the role

CGRC is aimed at professionals responsible for risk management, governance and regulatory alignment. It can suit a candidate working with control frameworks, assessments, authorization activities, policy or compliance evidence more closely than a primarily technical operations credential.

ISC2 lists two years of required work experience for CGRC. Candidates should compare that requirement with their documented duties and determine whether the role involves the governance and assurance responsibilities represented by the credential. If your work is divided between technical operations and risk, consider which area you expect to own in the next role rather than selecting solely on your present job title.

Choose CISSP for broad responsibility and senior progression

CISSP is the broad experience-based option for professionals whose responsibilities span several areas of information security and may include management, program direction or executive decision-making. The requirement is at least five years of cumulative full-time experience in two or more of the eight CISSP domains.

The eight domains are Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security. A candidate should be able to explain how documented work maps to at least two of these domains before treating CISSP as an immediate exam target.

A degree in computer science, information technology or a related field may satisfy up to one year of the required experience, and an approved credential may also satisfy one year. Candidates who pass the CISSP examination without the required experience can become an Associate of ISC2 and then have six years to earn the five years of required experience. These routes make CISSP possible for developing professionals, but they do not remove the need to plan for the experience and endorsement stages.

Choose a specialist credential when your role has a clear technical or sector focus

CCSP, CSSLP and HCISPP are better considered as focused paths than as generic next steps. CCSP is the cloud security option; CSSLP is directed toward secure software lifecycle work; and HCISPP addresses healthcare information security and privacy. The advanced ISSAP, ISSEP and ISSMP concentrations are designed for architecture, engineering and management specialization.

A specialist credential is most useful when your work examples, learning plan and intended next role all point in the same direction. If your role is still broad or unsettled, a foundational or broad professional credential may provide a more coherent base. If your responsibilities already have a strong cloud, software, healthcare, architecture, engineering or security-management emphasis, a focused option may be more directly relevant.

What CC demonstrates and how to prepare for it

CC preparation should begin with the official exam outline, followed by study that addresses every listed domain rather than concentrating only on familiar technical topics. The current outline is effective October 1, 2025, and ISC2 states that a new CC outline will take effect September 1, 2026, so candidates should confirm the applicable outline before scheduling.

The current CC examination uses Computerized Adaptive Testing, lasts two hours and contains 100-125 items. ISC2 lists a passing grade of 700 out of 1000 points and exam availability in English, Chinese, Japanese, German and Spanish. Chinese-language appointments are available only during select windows. These details can change, so the official outline should be checked again when you register.

The current domain weights are Security Principles 26%, Business Continuity, Disaster Recovery and Incident Response Concepts 10%, Access Controls Concepts 22%, Network Security 24% and Security Operations 18%. Use the weights to allocate attention, but do not treat a lower-weight domain as optional. The outline describes the knowledge being assessed; it is not a substitute for understanding how security concepts connect in practice.

Use official materials as the study baseline

ISC2 provides CC preparation options that include adaptive learning, online self-paced training and instructor-led learning. Its CC page also links to an ultimate guide, a practice quiz, flash cards, career resources and other self-study material. These resources can help a candidate choose between independent preparation and structured instruction.

The CC exam-outline page encourages candidates to review supplementary references and identify areas needing additional attention. A sensible process is to download the current outline, mark each topic by confidence, study the weakest areas, and then use practice questions to test reasoning rather than memorize answer patterns.

The official CC page lists self-paced access options of 90 days and 180 days, while individual products have their own access terms. Treat those periods as product-specific and verify the terms at purchase. Paid preparation is optional; the important requirement is that your preparation covers the current blueprint and that you understand the concepts well enough to apply them in unfamiliar wording.

Extend the same preparation discipline to advanced ISC2 credentials

For an experience-based credential, preparation should combine the exam outline with workplace evidence. Start by identifying the domains or role responsibilities that apply to your target credential, then study the concepts you use less often. Broad credentials require more than recalling definitions: candidates should be able to reason about risk, controls, architecture, operations, governance and professional responsibilities as appropriate to the exam.

A useful readiness check is whether you can explain a security decision, its business context, the risks it addresses, the control or process selected, and how you would evaluate the result. This is a practical recommendation, not an ISC2 eligibility rule. It helps distinguish genuine understanding from familiarity with terminology.

Use official training and supplementary references where available, and confirm that third-party resources match the current exam outline. Do not rely on leaked questions or exam dumps. ISC2’s member policies state that discussing examination items, answers and responses violates the examination non-disclosure agreement.

Understand the exam, endorsement and Associate of ISC2 process

Passing an ISC2 examination is not always the end of the certification process. For credentials that require experience, the candidate must complete an endorsement process so ISC2 can verify the required professional background.

After passing, ISC2 sends official results and directions for the next steps. The endorsement application is digitally signed by an ISC2 certified professional in good standing. If a candidate does not know an eligible endorser, ISC2 can act as the endorser. The member policies state that candidates who pass an ISC2 credential examination must complete endorsement within no longer than nine months.

Candidates should prepare employment dates, role descriptions and documentation before the exam result arrives. The purpose is not to inflate a résumé but to map real work to the target credential’s requirements. ISC2 may randomly select submitted endorsements for audit and request additional information.

Use the Associate route when you have passed but still need experience

The Associate of ISC2 route is designed for candidates who pass an examination but do not yet have the experience required for full certification. For the CISSP pathway, the official experience page gives the Associate of ISC2 six years to earn the required five years of experience and submit the certification application.

Associates must continue meeting the applicable maintenance obligations. ISC2 states that Associates are required to earn and submit 15 CPE credits annually, and the Associate AMF is U.S. $50 due each year on the anniversary of achieving associate status. The specific time frame depends on the target certification; the member policy lists up to six years for CISSP and CCSP, up to five years for CSSLP, up to three years for CGRC and up to two years for SSCP.

This route can be a practical bridge, but it should be treated as a time-bound plan. Keep a record of qualifying work as it accumulates, review the target certification’s experience domains, and submit the application before the permitted period ends. Passing the exam alone does not turn an Associate into a full credential holder.

Complete the final membership step

Once the endorsement application is approved, the candidate is notified and can pay the first Annual Maintenance Fee to begin the membership cycle. ISC2’s policies also require candidates to commit to and support the ISC2 Code of Ethics.

For members holding CISSP, SSCP, CCSP, CGRC, CSSLP, ISSAP, ISSEP or ISSMP, ISC2 lists an AMF of U.S. $135. For members who hold only CC, the AMF is U.S. $50. ISC2 members pay one AMF regardless of how many ISC2 certifications they hold, with the fee due on the earliest certification anniversary when multiple certifications are held. Fees are subject to policy and should be confirmed before payment.

Plan for maintenance before you choose a credential

An ISC2 credential is an ongoing professional commitment, not only an exam purchase. Members must earn the applicable continuing professional education credits during the certification cycle and pay the annual maintenance fee to maintain certification or Associate status.

The member policy lists three-year CPE totals of 45 for CC, 120 for CISSP, 90 for CSSLP and CCSP, and 60 for SSCP and CGRC. The advanced ISSAP, ISSEP and ISSMP requirements vary depending on whether the holder also has CISSP. Review the Certification Maintenance Handbook and current policy for the exact activity rules before selecting a credential.

Build a maintenance routine that matches your work

CPE planning is easier when it is connected to ordinary professional development. Relevant learning, conferences, webinars, training, community activity and other qualifying opportunities can be recorded as they are completed, subject to ISC2’s rules. The goal is to avoid treating the end of the cycle as a deadline-driven catch-up exercise.

The annual requirement differs by credential. For example, ISC2 lists 15 CPE credits annually for CC, 40 annually for CISSP, 30 annually for CSSLP and CCSP, and 20 annually for SSCP and CGRC when using the suggested distribution shown in its policy. Those figures are maintenance requirements for the named credentials, not a general study-time recommendation.

Members must also track the AMF anniversary. ISC2 provides a 90-day grace period after the certification cycle expires to earn and submit required CPE credits, but failure to meet the applicable requirements can lead to suspension. A hardship extension may be considered case by case for circumstances such as medical issues, military deployment, natural disaster or other listed hardships; candidates should contact ISC2 rather than assume an extension is automatic.

Know the consequences of falling out of good standing

If a certification or Associate designation is suspended, ISC2 requires outstanding CPE credits and past-due AMFs to be submitted or paid before reinstatement. Suspension status may be maintained for up to two consecutive years. If a member does not recertify after that period, the status may be terminated under the member policy.

While suspended, an individual may not use the certification or Associate designation, display the certificate or imply that they are currently certified or an Associate. The policy provides appeal and hardship procedures, but an appeal must be submitted before the end of the two-year suspension period. If an appeal or extension is disapproved, retesting may be required to regain the certification or designation.

These rules matter when comparing paths because maintenance workload and cost are part of the credential decision. A credential that aligns with your work is easier to maintain meaningfully than one chosen only for its title.

Schedule and take an ISC2 exam with the administrative details in mind

ISC2 exams are delivered at Pearson VUE testing centers worldwide. After purchasing an exam, candidates use their ISC2 account, open Courses and Exams, select Schedule and then complete the exam-account information before being redirected to Pearson VUE.

Enter your name and other details exactly as they appear on the identification you will present. ISC2 warns that an exact mismatch can prevent you from taking the exam without reimbursement of fees. Confirm the testing location, appointment time, identification requirements and current exam policies before the appointment.

An exam purchase provides up to 365 days to schedule and sit for the exam. ISC2 states that an exam cannot be rescheduled within 24-hours of the appointment; Pearson VUE charges a rescheduling fee of U.S. $50 and a cancellation fee of U.S. $100. If you do not sit within 365 days, the exam fee is not refunded. These rules are administrative rather than study requirements, but overlooking them can create avoidable cost and scheduling problems.

Understand retakes and result reporting

ISC2 permits up to 4 attempts within a 12-month period for each certification program, subject to the retake waiting rules. After the first attempt, the waiting period is 30 test-free days; after the second, it is 60 test-free days; after the third and subsequent attempts, it is 90 test-free days.

The test center may provide an unofficial result at checkout, while ISC2 emails the official result after statistical and psychometric analysis. No scores are provided. If a candidate fails, the testing center may provide proficiency levels by domain, which can help direct the next study cycle. Results can occasionally be delayed while ISC2 completes its analysis.

A retake should be based on a revised preparation plan, not simply a rapid repeat of the same attempt. Review the domain feedback, identify knowledge gaps, revisit the official outline and allow the applicable waiting period.

Use digital badges and the ISC2 community as part of the credential experience

ISC2 issues digital badges for certifications earned, and the badges are linked to information hosted on the Credly platform. Each certification and profile has a unique URL that can be embedded on a résumé or website, while the earner controls the information they choose to make public.

Badges can provide a convenient way to verify an achievement, but they do not replace the underlying requirements, active status or accurate use of the credential mark. Follow ISC2’s guidance on how credentials are represented to employers and clients, especially when a designation is suspended or has expired.

Membership also provides access to professional development and community resources identified by ISC2, including webinars, a CPE partner network, chapters and the ISC2 Community. These are useful for maintaining knowledge and learning about the profession, but participation should complement—not replace—role-specific experience and preparation.

A practical decision process for selecting your ISC2 path

Start with the job you want to perform, then test that goal against experience, subject matter and maintenance capacity. The following sequence keeps the decision grounded in the structure of the ISC2 ecosystem.

First, define the work target

Write down the responsibilities you want in the next role: foundational security support, system defense, governance and compliance, broad security leadership, cloud security, software security, healthcare privacy, architecture or engineering. If the target is vague, begin with the area of work you can realistically explore rather than choosing the most advanced-sounding credential.

Ask whether the role is primarily operational, assurance-oriented, technical-specialist or strategic. This distinction often narrows the portfolio more effectively than years of general IT experience.

Second, check the official eligibility requirement

Compare your documented experience with the current official requirement for the credential. CC has no work-experience requirement. CISSP requires five years of cumulative full-time experience in two or more domains, with specified alternatives and an Associate route. ISC2’s certification portfolio identifies experience requirements for other credentials, but requirements can change, so verify the target page before purchasing an exam.

Do not count responsibilities merely because their job title sounds relevant. Build a short evidence list showing the work performed, the dates, the environment and the security domain or role it supports. If the evidence is insufficient, choose CC, pursue the Associate route where available or gain the relevant experience before applying.

Third, compare the learning burden with your maintenance plan

Review the exam outline and official preparation resources, then estimate how you will keep the credential current after passing. Consider annual AMFs, CPE recording, professional development time and the relevance of available learning opportunities to your role.

If the credential does not connect to your current or intended work, maintenance can become a recurring administrative task with limited professional value. A more focused or foundational option may be the better next step even if another title appears more prestigious.

Finally, confirm the current policy before payment

Before registering, check the official certification page, exam outline, scheduling instructions, after-exam process, AMF information and member policies. Confirm the exam version, experience rule, language and delivery details, purchase window, retake policy, fees and endorsement deadline applicable to your situation.

This final review is especially important for CC candidates because ISC2 has announced a new exam outline effective September 1, 2026. Time-sensitive information should always be checked at the official source immediately before registration.

What to ask before committing to an ISC2 certification

A good certification decision should survive practical questions about fit, eligibility and follow-through. Ask yourself:

Does this credential match the work I perform or the role I am actively preparing to pursue?

Can I document the required experience in the relevant domains, or do I need an Associate route or additional work first?

Have I read the current official exam outline rather than relying on an older course or discussion?

What preparation format fits my schedule: self-study, adaptive learning, live virtual instruction or a combination?

Can I budget for the exam, endorsement-related steps, AMF and any learning resources without assuming a particular career outcome?

How will I earn and record CPE credits during the certification cycle?

Do I understand the endorsement deadline, examination confidentiality rules, retake waiting periods and scheduling restrictions?

Would a focused credential such as CCSP, CSSLP, HCISPP, ISSAP, ISSEP or ISSMP better represent my actual responsibilities than a broad credential?

If my circumstances change, have I reviewed the current suspension, hardship, appeal and reinstatement policies?

These questions do not produce one universal answer. They help distinguish a credential chosen for a defined professional purpose from one selected only because it is widely recognized.

Conclusion

ISC2’s ecosystem is broad enough to support several legitimate starting points. CC is the accessible foundation for newcomers without work experience; SSCP and CGRC suit different operational and governance directions; CISSP addresses broad, experience-based responsibility; and CCSP, CSSLP, HCISPP, ISSAP, ISSEP and ISSMP provide focused or advanced options. The strongest next step is the credential whose exam scope, eligibility evidence, intended role and maintenance obligations all line up. Review the current official pages before registering, prepare from the applicable outline, and treat endorsement, CPE and AMF requirements as part of the certification decision rather than as afterthoughts.

Related exams

Official sources

Build a focused ISC2 study route.

Use the live catalog data to move from provider research to a preparation format that fits your exam date and routine.

Choose the exact exam code

Match the certification objective to the currently published exam before starting practice.

Check recency and availability

Review question totals, update dates, retirement status, and pre-order availability directly in the catalog.

Choose the study format

Continue to the exam page to compare PDF review, test-engine practice, and supported bundle options.