What are ISC2 certifications and which one should I take?
ISC2 is a non-profit membership association for cybersecurity professionals and one of the two dominant credentialing bodies in the field. It issues several certifications rather than one. Certified in Cybersecurity is the entry-level credential aimed at people with no security experience. The Systems Security Certified Practitioner sits at the hands-on practitioner level. The Certified Information Systems Security Professional β CISSP β is the flagship, a management-oriented breadth credential covering eight domains from security and risk management through asset security, architecture, communications and network security, identity and access management, assessment and testing, operations and software development security. Further credentials address cloud security, software security and healthcare privacy. The flagship credentials share a model: pass the examination, document the required paid work experience, be endorsed by an existing ISC2 certified member, and then maintain the certification with continuing professional education and an annual maintenance fee. Candidates who pass but lack the experience become Associates of ISC2 while they accumulate it.
- ISC2 issues several credentials from an entry-level certification through practitioner and flagship management tiers.
- Certification requires the exam plus defined paid experience plus endorsement by a certified member.
- Candidates who pass without the experience hold Associate of ISC2 status while they accumulate it.
- Credentials run a three-year cycle requiring continuing professional education and an annual maintenance fee.
ISC2 at a glance
| Cost | Examination pricing varies by region and an annual maintenance fee applies per credential; both are revised periodically β check ISC2's current fee schedule for your region |
| Duration | Examinations vary by credential; the flagship uses adaptive testing with a published maximum duration |
| Issued by | ISC2 |
| Format | Proctored examination at authorised test centres, followed by an experience-verified endorsement by an ISC2 certified member |
| Expiry | Three-year certification cycle maintained by continuing professional education credits plus the annual maintenance fee |
| Who needs it | Security managers, compliance and risk professionals with security responsibility, and practitioners moving into security roles |
| Entry route | Certified in Cybersecurity, aimed at candidates with no prior security experience |
| Associate status | Candidates who pass without the required experience become an Associate of ISC2 while accumulating it |
Sources: ISC2, official site Β· ISC2 certifications. Reviewed August 2026 by the GlobalCybers team.
Exam, Experience, Endorsement
The endorsement step people forget
Passing an ISC2 examination does not certify you. You must then submit an endorsement application attesting to the required paid work experience, endorsed by an existing ISC2 certified professional in good standing, and ISC2 audits a proportion of them. Candidates who pass without the experience are granted Associate of ISC2 status and have a defined period to earn it. Budget for this step in your planning β it is the part that stalls otherwise successful candidates.
Choosing a credential
Where do ISC2 credentials matter in a non-technology organisation?
They matter most in the governance layer: compliance functions, risk teams and operations leadership carrying security accountability in regulated industries, where the flagship credential appears routinely in job specifications. BLS reports pay by occupation, not by credential.
GlobalCybers reimburses certification fees after a successful permanent placement through our network.
What the Flagship Credential Covers, Eight Domains
Breadth Over Depth
The flagship credential deliberately covers eight domains at management depth. It is not a penetration testing or engineering qualification, and candidates expecting one are surprised.
Endorsement
An existing certified member attests to your experience, and ISC2 audits a share of applications. Line up an endorser early rather than after passing.
Associate Status
Passing without the experience grants Associate status and a defined window to earn it β a legitimate route for people transitioning into security.
The Entry Credential
Certified in Cybersecurity was created for people with no experience at all, and is the sensible first step for someone moving in from operations or compliance.
Three-Year Cycle
Certifications run on a three-year cycle with continuing professional education credits and an annual maintenance fee β an ongoing cost as well as an ongoing effort.
Code of Ethics
ISC2 certification carries an enforceable code of ethics, and a breach can cost the credential.
How do you get ISC2 certified, step by step?
Pick the credential that matches where you are
Certified in Cybersecurity for no experience, the practitioner credential for hands-on operational roles, the flagship for management-oriented breadth. Attempting the flagship from a standing start is a common and expensive misjudgement.
Check the experience definition carefully
The flagship requires paid work experience across a defined number of the eight domains, with a published education waiver reducing it. What counts is defined by ISC2, so read the current requirement rather than assuming your role qualifies.
Prepare against the published outline
ISC2 publishes an exam outline per credential with domains and weightings. For the flagship, the common failure is technical depth without management-level framing β the exam asks what a risk owner should do, not what a tool operator would type.
Sit the proctored exam
Examinations run at authorised test centres. ISC2 sets pricing by region and revises it periodically, so check current pricing. The flagship uses adaptive testing with a published maximum duration.
Complete the endorsement
Submit the endorsement application with your experience, endorsed by an ISC2 certified professional in good standing. Without experience you become an Associate of ISC2 and have a defined period to complete it.
Maintain with CPE and the annual fee
Certification runs a three-year cycle requiring continuing professional education credits, recorded with ISC2, plus an annual maintenance fee for each credential held.
Where ISC2 Credentials Are Written Down
No general law requires them. The requirements come from employers and contracts: government contracting frameworks and defence-related workforce requirements have long named specific security certifications for defined roles, regulated industries expect demonstrable qualification in the people accountable for security programmes, and cyber insurance and customer security questionnaires increasingly ask about staff credentials. For organisations outside the technology sector, the flagship credential is typically the one named when a job carries accountability for security governance.
ISC2 Certifications, Frequently Asked Questions
ISC2 certified? Governance roles await.
Regulated employers need people accountable for security programmes. Tell us your credential and sector.
Join the Network βMore about ISC2
Your career research journey
Do your homework, then let the network do the rest.Get the job, then keep rising
FreeSet your intent, matching jobs come to you. No applying.
A roadmap to your next licence tier and higher pay band.
Once placed, we cover all certification, licence & career-guide fees.
Hiring trade workers?
Get a verified shortlist of 3β5 qualified candidates in 48 hours
GlobalCybers verifies active state licenses, trade certifications, Intent and right-to-work status before any candidate reaches your portal. Flat $2,999/mo RPO (Recruitment Process Outsourcing), up to 3 concurrent roles, or a free trial (pay on hire). 90-day written guarantee.