Wikiwand AI

Certified Information Systems Security Professional

Information security certification From Wikipedia, the free encyclopedia

CISSP (Certified Information Systems Security Professional) is an independent information security certification granted by the International Information System Security Certification Consortium, also known as ISC2.

CISSP logo

As of December 2025[1], there were 191,036 ISC2 members holding the CISSP certification worldwide.

In June 2004, the CISSP designation was accredited under the ANSI ISO/IEC Standard 17024:2003.[2][3] In 2024, the CISSP certification and its associated training programs were also formally approved by the U.S. Department of Defense (DoD) under DoDD 8140[4], which details qualifications for work roles in cybersecurity, cyber enablers and Information Technology (IT). DoDD 8140 replaces DoDD 8570, which also recognized the CISSP in the Information Assurance Technical (IAT), Managerial (IAM), and System Architect and Engineer (IASAE) categories for certification requirement.[5]

In May 2020, The UK National Academic Recognition Information Centre assessed the CISSP qualification as a Level 7 award, the same level as a master's degree.[6][7] The change enables cyber security professionals to use the CISSP certification towards further higher education course credits and also opens up opportunities for roles that require or recognize other Level 7 qualifications such as postgraduate diplomas and master's degrees.[6]

History

In the mid-1980s, a need arose for a standardized, vendor-neutral certification program that provided structure and demonstrated competence. In November 1988, the Special Interest Group for Computer Security (SIG-CS), a member of the Data Processing Management Association (DPMA), brought together several organizations interested in this goal. The International Information Systems Security Certification Consortium or "ISC2" formed in mid-1989 as a non-profit organization.[8]

By 1990, the first working committee to establish a Common Body of Knowledge (CBK) had been formed. The first version of the CBK was finalized by 1992, and the CISSP credential was launched by 1994.[9]

In 2003 the CISSP was adopted as a baseline for the U.S. National Security Agency's ISSEP program.[10]

In 2024, ISC2 marked 30 years of the CISSP[11] with a series of articles about the history of the certification and cybersecurity incidents from the year it was launched, along with interviews with certification holders.

Certification subject matter

The CISSP curriculum breaks the subject matter down into a variety of Information Security topics referred to as domains.[12] The CISSP examination is based on what ISC2 terms the Common Body of Knowledge (or CBK). According to ISC2, "the CISSP CBK is a taxonomy – a collection of topics relevant to information security professionals around the world. The CISSP CBK establishes a common framework of information security terms and principles that allow information security professionals worldwide to discuss, debate and resolve matters pertaining to the profession with a common understanding."[13]

On May 1, 2021 there was a domain refresh that impacted the weighting of the domains; the domains themselves did not change.[14]

On April 15, 2024, a refreshed exam outline applies. The updates are the result of the Job Task Analysis (JTA), which is an analysis of the current content of the credential evaluated by ISC2 members on a triennial cycle.[15] The impact of the change was limited to a further revision of the weighting of the domains; the domains themselves once again did not change.[16]

From April 15, 2018, the eight domains covered are :[17]

More information Domain, Average Weight ...
CISSP Certification Exam
DomainAverage Weight
Security and risk management16%
Asset security10%
Security architecture and engineering13%
Communication and network security13%
Identity and access management (IAM)13%
Security assessment and testing12%
Security operations13%
Software development security10%
Total100%
Close

From 2015 to early 2018, the CISSP curriculum was divided into eight domains similar to the latest curriculum above. The only domain to have changed its name was "Security Engineering", which in the 2018 revision was expanded to "Security Architecture and Engineering".[18]

Before 2015, it covered ten domains:[19]

  1. Operations security
  2. Telecommunications and network security
  3. Information security governance and risk management
  4. Software development security
  5. Cryptography
  6. Security architecture and design
  7. Access control
  8. Business continuity and IT disaster recovery planning
  9. Legal, regulations, investigations and compliance
  10. Physical (environmental) security

Requirements

  • Possess a minimum of five years of direct full-time security work experience in two or more of the ISC2 information security domains (CBK). One year may be waived for having either a four-year college degree, a master's degree in Information Security, or for possessing one of a number of other certifications.[20] A candidate without the five years of experience may earn the Associate of ISC2 designation by passing the required CISSP examination, valid for a maximum of six years. During those six years a candidate will need to obtain the required experience and submit the required endorsement form for certification as a CISSP. Upon completion of the professional experience requirements the certification will be converted to CISSP status.[21]
  • Attest to the truth of their assertions regarding professional experience and accept the CISSP Code of Ethics.[22]
  • Answer questions regarding criminal history and related background.[23]
  • Pass the multiple choice CISSP exam (three hours, between 100 and 150 questions, in a computer adaptive test) with a scaled score of 700 points or greater out of 1000 possible points, you must achieve a pass in all eight domains.[23]
  • Have their qualifications endorsed by another ISC2 certification holder in good standing.[24]

Member counts

Number of CISSP members as of December, 2025 is 191,036[1]. The organization no longer publishes breakdowns of individual certification holders by country, with the last publicly available data released in 2022.[25]

More information #, Country (Top 15) ...
Top 15 countries by CISSP Member Counts as at July 2022
# Country (Top 15) Count
1 United States 95,243
2 United Kingdom 8,486
3 Canada 6,842
4 China 4,136
5 Japan 3,699
6 India 3,364
7 Australia 3,305
8 The Netherlands 2,983
9 Singapore 2,963
10 Germany 2,856
11 Korea 2,090
12 Hong Kong 1,968
13 France 1,277
14 Switzerland 1,127
15 Spain 847
Close

Further specializations

Holders of CISSP certifications can earn additional certifications in areas of speciality. These specializations used to be known as CISSP concentrations, but have been made accessible for every applicant who meets the requirements. There are three possibilities as listed below.[26]

Information Systems Security Architecture Professional (ISSAP)

It is an advanced information security certification issued by ISC2 that focuses on the architecture aspects of information security. The certification exam consists of 125 questions covering six domain areas:

  1. Identity and Access Management Architecture
  2. Security Operations Architecture
  3. Infrastructure Security
  4. Architect for Governance, Compliance, and Risk Management
  5. Security Architecture Modeling
  6. Architect for Application Security

As of December, 2025, there were 2,649 ISC2 members holding the ISSAP certification worldwide.[1]

Information Systems Security Engineering Professional (ISSEP)

It is an advanced information security certification issued by ISC2 that focuses on the engineering aspects of information security across the systems development life cycle.[27] In October 2014 it was announced that some of its curricula would be made available to the public by the United States Department of Homeland Security through its National Initiative for Cybersecurity Careers and Studies program.[28] Both ZDNet and Network World have named ISSEP one of tech's most valuable certifications.[29][30] The certification exam consists of 125 questions covering 5 domain area:

  1. Security Engineering Principles
  2. Risk Management
  3. Security Planning, Design, and Implementation
  4. Secure Operations, Maintenance, and Disposal
  5. Secure Engineering Technical Management

As of December, 2025, there were 1,526 ISC2 members holding the ISSEP certification worldwide.[1]

Information Systems Security Management Professional (ISSMP)

It is an advanced information security certification issued by ISC2[31] that focuses on the management aspects of information security.[27] In September 2014, Computerworld rated ISSMP one of the top ten most valuable certifications in all of tech.[32] The certification exam consists of 125 questions covering 6 domain areas:

  1. Leadership and Business Management
  2. Systems Lifecycle Management
  3. Risk Management
  4. Threat Intelligence and Incident Management
  5. Contingency Management
  6. Law, Ethics, and Security Compliance Management

As of December, 2025, there were 1,803 ISC2 members holding the ISSMP certification worldwide.[1]

Fees and ongoing certification

As of June 2026, the standard exam costs US$749.[33] On completion of the exam, to gain certification you need to complete an endorsement process to evidence at least five years experience within a mix of the domains. A dispensation can be claimed for one year with the relevant academic qualification. The final step is payment of the annual maintenance fee of US$135 (as of 2026[34]).

The CISSP credential is valid for three years; holders renew either by submitting 40 Continuing Professional Education (CPE) credits per year over three years or re-taking the exam.

CPE credits are gained by completing relevant professional education.

Value

In 2005, Certification Magazine surveyed 35,167 IT professionals in 170 countries on compensation and found that CISSPs led their list of certificates ranked by salary. A 2006 Certification Magazine salary survey also ranked the CISSP credential highly, and ranked CISSP concentration certifications as the top best-paid credentials in IT.[35][36]

In 2008, another study came to the conclusion that IT professionals in the Americas holding the CISSP (or other major security certifications) and at least 5 years of experience had salaries of up to 26% higher than IT professionals with similar experience levels who did not have such certificates.[37] Note that any actual cause-and-effect relationship between the certificate and salaries remains unproven.[citation needed]

In September 2025, the National Cybersecurity Alliance included the CISSP as one of six cybersecurity certifications it considered to be worth exploring[38].

ANSI certifies that CISSP meets the requirements of ANSI/ISO/IEC Standard 17024, a personnel certification accreditation program.[2]

See also

  • CISM (Certified Information Security Manager)

References

Related Articles

Timelines

Top Qs

Fact Checks