Need immediate help?πŸ‡ΊπŸ‡Έ+1 (773) 729-6444
Contact Usinfo@globalcybers.com
GlobalCybers
ISC2 ISSUED Β· EXAM + EXPERIENCE Β· MEMBER ENDORSEMENT Β· ANNUAL CPE + AMF

ISC2 Certification Guide 2026

How ISC2's security credentials work and which one fits: the entry-level route for people with no experience, the practitioner and flagship tiers, the endorsement step candidates forget, and the associate status that lets you certify before you qualify.

Updated August 2026

By GlobalCybers Editorial Team Β· Reviewed by our Data Desk Β· Published Aug 2026

Direct Answer

What are ISC2 certifications and which one should I take?

ISC2 is a non-profit membership association for cybersecurity professionals and one of the two dominant credentialing bodies in the field. It issues several certifications rather than one. Certified in Cybersecurity is the entry-level credential aimed at people with no security experience. The Systems Security Certified Practitioner sits at the hands-on practitioner level. The Certified Information Systems Security Professional β€” CISSP β€” is the flagship, a management-oriented breadth credential covering eight domains from security and risk management through asset security, architecture, communications and network security, identity and access management, assessment and testing, operations and software development security. Further credentials address cloud security, software security and healthcare privacy. The flagship credentials share a model: pass the examination, document the required paid work experience, be endorsed by an existing ISC2 certified member, and then maintain the certification with continuing professional education and an annual maintenance fee. Candidates who pass but lack the experience become Associates of ISC2 while they accumulate it.

ISC2 Certifications β€” including CISSP, SSCP, CCSP and Certified in Cybersecurity β€” badge illustration. Issued by ISC2 Certifications β€” including CISSP, SSCP, CCSP and Certified in Cybersecurity. Flagship CISSP, Extra step Endorsement.
ISC2 Certifications β€” including CISSP, SSCP, CCSP and Certified in Cybersecurity β€” ISC2 ISSUED Β· EXAM + EXPERIENCE Β· MEMBER ENDORSEMENT Β· ANNUAL CPE + AMF
Key takeaways
  • ISC2 issues several credentials from an entry-level certification through practitioner and flagship management tiers.
  • Certification requires the exam plus defined paid experience plus endorsement by a certified member.
  • Candidates who pass without the experience hold Associate of ISC2 status while they accumulate it.
  • Credentials run a three-year cycle requiring continuing professional education and an annual maintenance fee.

ISC2 at a glance

CostExamination pricing varies by region and an annual maintenance fee applies per credential; both are revised periodically β€” check ISC2's current fee schedule for your region
DurationExaminations vary by credential; the flagship uses adaptive testing with a published maximum duration
Issued byISC2
FormatProctored examination at authorised test centres, followed by an experience-verified endorsement by an ISC2 certified member
ExpiryThree-year certification cycle maintained by continuing professional education credits plus the annual maintenance fee
Who needs itSecurity managers, compliance and risk professionals with security responsibility, and practitioners moving into security roles
Entry routeCertified in Cybersecurity, aimed at candidates with no prior security experience
Associate statusCandidates who pass without the required experience become an Associate of ISC2 while accumulating it

Sources: ISC2, official site Β· ISC2 certifications. Reviewed August 2026 by the GlobalCybers team.

Flagship
CISSP
Extra step
Endorsement
Upkeep
CPE + annual fee

Exam, Experience, Endorsement

The endorsement step people forget

Passing an ISC2 examination does not certify you. You must then submit an endorsement application attesting to the required paid work experience, endorsed by an existing ISC2 certified professional in good standing, and ISC2 audits a proportion of them. Candidates who pass without the experience are granted Associate of ISC2 status and have a defined period to earn it. Budget for this step in your planning β€” it is the part that stalls otherwise successful candidates.

Choosing a credential

Certified in Cybersecurity: Entry level, no experience requirement β€” the on-ramp credential
SSCP: Hands-on practitioner level for those operating security controls
CISSP: The flagship breadth credential, management-oriented across eight domains
Cloud and software: Specialist credentials for cloud security and secure software
Healthcare privacy: A credential aimed at privacy and security in healthcare settings

Where do ISC2 credentials matter in a non-technology organisation?

They matter most in the governance layer: compliance functions, risk teams and operations leadership carrying security accountability in regulated industries, where the flagship credential appears routinely in job specifications. BLS reports pay by occupation, not by credential.

$80,730
BLS OEWS May 2025 national median for compliance officers (SOC 13-1041), the occupation most holders work in
Governance layer
Utilities, healthcare systems, financial institutions and government contractors name security credentials in job specifications for the people accountable for security programmes rather than for the people operating tools
$133,720
90th-percentile pay for compliance officers β€” where the most senior credentialed practitioners concentrate

GlobalCybers reimburses certification fees after a successful permanent placement through our network.

What the Flagship Credential Covers, Eight Domains

πŸ—ΊοΈ

Breadth Over Depth

The flagship credential deliberately covers eight domains at management depth. It is not a penetration testing or engineering qualification, and candidates expecting one are surprised.

🀝

Endorsement

An existing certified member attests to your experience, and ISC2 audits a share of applications. Line up an endorser early rather than after passing.

πŸŽ“

Associate Status

Passing without the experience grants Associate status and a defined window to earn it β€” a legitimate route for people transitioning into security.

πŸšͺ

The Entry Credential

Certified in Cybersecurity was created for people with no experience at all, and is the sensible first step for someone moving in from operations or compliance.

πŸ“…

Three-Year Cycle

Certifications run on a three-year cycle with continuing professional education credits and an annual maintenance fee β€” an ongoing cost as well as an ongoing effort.

βš–οΈ

Code of Ethics

ISC2 certification carries an enforceable code of ethics, and a breach can cost the credential.

How do you get ISC2 certified, step by step?

1

Pick the credential that matches where you are

Certified in Cybersecurity for no experience, the practitioner credential for hands-on operational roles, the flagship for management-oriented breadth. Attempting the flagship from a standing start is a common and expensive misjudgement.

2

Check the experience definition carefully

The flagship requires paid work experience across a defined number of the eight domains, with a published education waiver reducing it. What counts is defined by ISC2, so read the current requirement rather than assuming your role qualifies.

3

Prepare against the published outline

ISC2 publishes an exam outline per credential with domains and weightings. For the flagship, the common failure is technical depth without management-level framing β€” the exam asks what a risk owner should do, not what a tool operator would type.

4

Sit the proctored exam

Examinations run at authorised test centres. ISC2 sets pricing by region and revises it periodically, so check current pricing. The flagship uses adaptive testing with a published maximum duration.

5

Complete the endorsement

Submit the endorsement application with your experience, endorsed by an ISC2 certified professional in good standing. Without experience you become an Associate of ISC2 and have a defined period to complete it.

6

Maintain with CPE and the annual fee

Certification runs a three-year cycle requiring continuing professional education credits, recorded with ISC2, plus an annual maintenance fee for each credential held.

Employer & Contract Requirement

Where ISC2 Credentials Are Written Down

No general law requires them. The requirements come from employers and contracts: government contracting frameworks and defence-related workforce requirements have long named specific security certifications for defined roles, regulated industries expect demonstrable qualification in the people accountable for security programmes, and cyber insurance and customer security questionnaires increasingly ask about staff credentials. For organisations outside the technology sector, the flagship credential is typically the one named when a job carries accountability for security governance.

Type
Professional certification
Named in
Contracts and job specifications
Legal status
Not a licence

ISC2 Certifications, Frequently Asked Questions

Is ISC2 one certification or several?

Several. ISC2 issues an entry-level credential for people with no security experience, a hands-on practitioner credential, the flagship management-oriented breadth credential, and specialist certifications for cloud security, secure software and healthcare privacy. Naming which one you hold matters, because they target very different levels of responsibility.

What is the endorsement requirement?

After passing an examination you must submit an endorsement application attesting to your paid work experience, endorsed by an existing ISC2 certified professional in good standing, and ISC2 audits a proportion of applications. This step is separate from the exam and is where candidates most often stall, so identify a potential endorser before you test rather than afterwards.

Can I get certified without the required experience?

You can pass the examination and become an Associate of ISC2, which recognises the exam result and gives you a defined period to accumulate the required experience and complete endorsement. It is a legitimate and commonly used route for people moving into security from operations, audit or compliance backgrounds.

Is the flagship credential a technical certification?

It is broad rather than deep, and management-oriented. It spans eight domains from governance and risk through architecture, network security, identity, testing, operations and software security, at the depth a security leader needs rather than the depth a specialist practitioner needs. Candidates looking for hands-on engineering or testing depth generally need a different credential alongside it.

What does maintaining an ISC2 certification involve?

A three-year cycle requiring continuing professional education credits recorded with ISC2, plus an annual maintenance fee payable for each credential held. Holding multiple credentials increases both the credit requirement and the fees, though ISC2 publishes rules on how activity can count across credentials.

Intent Network

ISC2 certified? Governance roles await.

Regulated employers need people accountable for security programmes. Tell us your credential and sector.

Join the Network β†’
Quick Reference
Issued byISC2
FlagshipCISSP
EntryCertified in Cybersecurity
Extra stepEndorsement
Cycle3 years + AMF
Related Certifications
Roles that need ISC2

More about ISC2

Why does the flagship credential emphasise breadth?

Because the role it targets is accountability rather than execution. A person responsible for a security programme has to make defensible decisions across governance, architecture, operations, testing and continuity without being the deepest expert in any of them, and has to recognise when a specialist is needed. Testing eight domains at management depth models that job; testing one domain deeply would model a different one.

How do candidates from non-security backgrounds use the entry credential?

As a structured on-ramp. It was created for people with no experience and no prerequisite, covering security principles, access controls, network security, security operations and incident response at foundational level. Auditors, compliance staff, operations managers and technicians moving toward security responsibility use it to establish vocabulary before deciding whether to pursue a practitioner or management credential.

What happens in an experience audit?

ISC2 audits a proportion of endorsement applications, asking for evidence supporting the claimed paid work experience and its mapping to the credential's domains. Applications that overstate scope β€” describing incidental exposure as domain experience β€” are the ones that fail. The practical protection is to document roles and responsibilities accurately at the point of application rather than to describe them aspirationally.

How do ISC2 and ISACA credentials fit together?

They overlap at the governance layer but come from different traditions. ISACA's portfolio grew from information systems audit and remains strongest in audit, risk and control functions; ISC2's grew from security practice and is strongest in security programme roles. Professionals in regulated industries frequently hold one from each β€” an audit or risk credential alongside a security credential β€” because their role sits at the intersection.

Your career research journey

Do your homework, then let the network do the rest.
πŸ’°
1. Know your salary
πŸͺͺ
2. Know your licences & certifications
🧭
3. Career guide
🎀
4. Interview preparation

Get the job, then keep rising

Free
Get Job β€” Join Network β†’
πŸš€
Step 5
Get matching jobs

Set your intent, matching jobs come to you. No applying.

πŸ“ˆ
Step 6
Career advancement plan

A roadmap to your next licence tier and higher pay band.

πŸŽ“
Step 7
We fund your fees

Once placed, we cover all certification, licence & career-guide fees.

⚑

Hiring trade workers?

Get a verified shortlist of 3–5 qualified candidates in 48 hours

GlobalCybers verifies active state licenses, trade certifications, Intent and right-to-work status before any candidate reaches your portal. Flat $2,999/mo RPO (Recruitment Process Outsourcing), up to 3 concurrent roles, or a free trial (pay on hire). 90-day written guarantee.

βœ“ Licenses verifiedβœ“ Intent & availability verified⚑ 48-hr shortlistπŸ›‘ 90-day guarantee
Hire Talent β†’See how staffing works β†’