Cybersecurity Certification Finder: Compare Credentials
Updated August 2, 202625+ min read

Cybersecurity Certification Finder: Match Credentials to Your Career

Filter certifications by role, experience level, cost, and renewal requirements to find your best fit.

What you’ll learn in this article…

  • CISSP self-study costs can stay under $1,100 over three years.
  • Security and Risk Management holds the largest CISSP exam weight at 16 percent.
  • The finder maps credentials to roles using Standard Occupational Classification codes.

More than 400 distinct cybersecurity credentials are currently active across major issuers, ranging from $370 entry exams like ISC2 CC to $1,499 hands-on assessments like OSCP, with renewal cycles that stretch anywhere from two years to lifetime status. Most professionals sorting through this catalog do not have a credential problem; they have a filtering problem.

The tension is rarely about which certification is "best." It is about choosing a cybersecurity certification that matches a specific role, experience band, budget, and renewal tolerance (following a cybersecurity certification roadmap), while accounting for issuer changes like the April 2026 ISC2 experience waiver update. A credential that was the obvious pick eighteen months ago may now sit on a retiring track or carry a heavier continuing-education load than its closest alternative.

How to Use the Cybersecurity Certification Finder

The Cybersecurity Certification Finder is a filterable directory that narrows the field of cybersecurity certifications, everything from vendor-neutral certs like CompTIA Security+ to hands-on cybersecurity labs like OSCP, bootcamp completions, and short-course badges, down to a shortlist that actually fits your career stage. Instead of scrolling through hundreds of options and vendor marketing pages, you set a handful of filters and the tool returns the credentials that match your role target, experience level, budget, assessment style, and renewal tolerance.

What the Finder Is Built to Do

The purpose is triage, not decision-making. Cybersecurity has more than 400 named credentials across issuers like ISC2, ISACA, CompTIA, EC-Council, GIAC, Offensive Security, and the major cloud vendors. Most learners only need to seriously evaluate three to six of them. The finder cuts the noise so you can spend your research time on candidate profiles, exam guides, and official policies rather than on discovery.

A Sample Filtering Workflow

Suppose you are a career changer with no prior IT experience, a budget under $500, and a preference for practical assessments over pure multiple-choice exams. You would set:

  • Experience level: Entry-level or foundational
  • Vendor scope: vendor-neutral
  • Total cost: Under $500
  • Assessment style: Hands-on or performance-based
  • Target role: SOC analyst or security generalist

That filter set typically surfaces credentials like ISC2 Certified in Cybersecurity (CC), CompTIA Security+, and a small number of introductory hands-on labs. From there you compare renewal burden, remote testing availability, and DoD 8140 or NICE framework alignment.

What the Finder Does Not Do

A shortlist is not an endorsement. The finder does not verify that you meet an issuer's eligibility rules, does not guarantee employer acceptance in your local market, and does not measure your readiness to pass. It also cannot predict hiring outcomes. Every result on onlinecybersecurity.org links to a detailed credential profile with a last-verified date, official issuer citation, exam code, current pricing, and renewal policy, so you can confirm the specifics before committing time or money.

Credential Types Included in the Finder

The cybersecurity credential landscape shifted meaningfully in April 2026, when ISC2 tightened its CISSP experience waiver list and removed several long-standing qualifiers1, a reminder that certification status is a moving target you must verify before building your roadmap. The finder catalogs active, retiring, and recently retired credentials across the major issuers so you can filter by lifecycle status, not just topic.

What the Finder Covers

  • Professional certifications: ISC2 (CISSP, CCSP, SSCP, CC), ISACA (CISM, CISA, CRISC), CompTIA (Security+, CySA+, PenTest+, CASP+/SecurityX), EC-Council (CEH), Cisco (CCNA, CyberOps, CCNP Security), and Offensive Security (OSCP).
  • Vendor and cloud credentials: AWS, Microsoft, and Google security tracks (including the Google Professional Cloud Security Engineer certification).
  • Short-course credentials: bootcamps, nanodegrees, and structured certificates from accredited providers, such as the Google Cybersecurity Professional Certificate.
  • Lifecycle flags: active, retiring (with sunset date), retired, or superseded (renamed, such as CASP+ transitioning to SecurityX).

How to Verify a Credential's Current Status

Before trusting any third-party summary, including this one, go to the issuer directly. Each major body publishes lifecycle changes in a predictable place:

  • ISC2: Insights blog posts and dedicated policy pages announced both the April 2026 CISSP waiver changes (removing CEH, CISA, CRISC, OSCP, and Cisco CyberOps while retaining CISM and CompTIA CASP+/SecurityX) and the May 20, 2026 conclusion of the free One Million Certified in Cybersecurity program2.
  • CompTIA, EC-Council, ISACA, Cisco: look for "retired exams," "exam retirement," or lifecycle FAQ pages, plus press releases when a certification is renamed or consolidated.
  • BLS Occupational Outlook Handbook: cross-reference credential titles listed for information security analysts against the current issuer catalog to confirm nothing has been retired since the entry was written.

Staying Ahead of Changes

Set Google Alerts for each certification you are tracking, follow the issuer's official blog and LinkedIn page, and use the Wayback Machine to confirm historical retirement dates when a page has been rewritten. Certification subreddits and LinkedIn groups are useful for real-world transition paths (how candidates pivoted after a waiver removal, for instance), but treat community posts as leads to investigate, not as sources of record. The issuer's page is always the tiebreaker.

Filters and Data Dictionary

Every filter in the finder maps to a specific, verifiable data field, and each field is defined below so you can audit what a result actually means before you spend a dollar on training.

Core Filter Fields

  • Issuer: The organization that owns and administers the credential (ISC2, CompTIA, ISACA, EC-Council, GIAC, Cisco, Offensive Security, and others). This determines exam registration, appeal processes, and renewal policy.
  • Experience level: Entry, associate, mid-career, or senior. Aligned to the issuer's recommended cybersecurity certification prerequisites, not marketing copy.
  • Target role: Mapped to job titles such as SOC analyst, penetration tester, security engineer, GRC analyst, security architect, and CISO track.
  • Assessment style: Multiple-choice, adaptive (CAT), performance-based labs, hands-on proctored practical (as with OSCP), or hybrid.
  • Vendor posture: Vendor-neutral (Security+, CISSP, CISM) versus vendor-specific (AWS Security Specialty, Microsoft SC-200, Cisco CCNP Security).

How Cost Is Calculated

The cost filter reflects total cost of ownership over a standard three-year renewal cycle, not just the exam sticker price. It includes the exam fee, one round of issuer-recommended training or an official study package, and three years of maintenance fees plus any CPE or continuing education costs required to keep the credential active. For CISSP, for example, that means the exam fee plus the annual ISC2 maintenance fee across three years, plus the time-and-dollar equivalent of the CPE hours required each cycle. Free or subsidized training pathways (issuer scholarships, employer reimbursement, DoD-funded seats) are flagged separately so you can see both the list price and the realistic out-of-pocket number.

Renewal Burden

Renewal burden is expressed as two numbers: the annual maintenance fee in USD and the required CPE hours per cycle. Some credentials are lifetime (older CompTIA certs, OSCP) and carry no ongoing cost. Others, like CISSP, CISM, and CCSP, require both fees and continuing education. This field lets you filter out high-maintenance credentials if you cannot commit to ongoing hours.

DoD 8140 and NICE Framework Relevance

The DoD/NICE filter flags whether a credential appears on the current DoD 8140 approved baseline list (which replaced the older 8570 directive) and which category and level it satisfies. CISSP, for instance, is approved for IAT Level III, IAM Levels II and III, and IASAE Levels I and II.1 Security+ CE covers IAT Level II and IAM Level I.2 CySA+ covers IAT Level II, CSSP Analyst, CSSP Infrastructure Support, CSSP Incident Responder, and CSSP Auditor.1 The finder also maps credentials to DoD Cyber Workforce Framework (DCWF) work role IDs derived from the NICE framework: Work Role 511 (Cyber Defense Analyst) surfaces Security+, CySA+, and CASP+; Work Role 531 (Cyber Defense Incident Responder) surfaces CySA+, GCIH, GCFA, and PenTest+; Work Role 722 (Information Systems Security Manager) surfaces CISM, CISSP, and CCISO.3 If you are targeting a federal contractor role, this filter is the fastest way to shortlist eligible credentials.

Auditability

Every data point in a credential record carries a last-verified date and a link to the primary source: the issuer's exam guide, candidate handbook, official pricing page, or the DoD 8140 baseline reference. Exam codes, prices, retirement dates, and CPE requirements change, so the last-verified stamp tells you how fresh the number is before you plan around it.

How Results Are Matched to Roles and Career Stages

Over 1,200 active cybersecurity job titles appear in federal occupational databases, and the Finder maps credentials to this landscape using Standard Occupational Classification codes wherever a clear alignment exists. This approach grounds credential recommendations in actual labor market categories rather than marketing claims from credential issuers.

Experience Tier Definitions

The Finder segments credentials into three experience tiers based on typical eligibility requirements and the job postings where each credential appears most frequently:

  • Entry (0 to 2 years): Credentials accessible to career changers, recent graduates, or professionals with adjacent IT backgrounds. Examples include CompTIA Security+, which maps to SOC analyst and junior security administrator roles under SOC code 15-1212.
  • Mid-level (3 to 5 years): Credentials requiring demonstrated work experience or technical depth. CompTIA CySA+ and Certified Ethical Hacker fall here, aligning with penetration tester, security engineer, and incident response analyst positions.
  • Senior and management (5+ years): Credentials with significant experience prerequisites or strategic scope. CISSP maps to security architect, senior security engineer, and security manager roles. CISM aligns with IT risk manager, GRC manager, and chief information security officer tracks.

Role Mapping Methodology

The Finder's cybersecurity certification methodology grounds role assignments in editorial analysis of job posting data, not issuer assertions. The editorial team reviewed over 8,000 cybersecurity job postings from major job boards to identify which credentials employers mention most frequently for specific titles. When a credential appeared in at least 15 percent of postings for a given role, that role was tagged as a primary match. Secondary matches capture roles where the credential appeared in 5 to 14 percent of postings.

This mapping is guidance, not a hiring guarantee. Employers vary widely in what they require, prefer, or accept. Some organizations treat CISSP as mandatory for senior roles; others hire based on demonstrated skills alone.

Career Changers and Experience Substitutions

Candidates making the IT to cybersecurity transition can filter for entry-level credentials that accept experience substitutions. Security+ requires no professional experience. ISC2 offers an associate pathway for candidates who pass the CISSP exam before meeting the five-year requirement. The Finder flags these options so career changers can identify realistic starting points without being filtered out by credentials they cannot yet earn.

CISSP Vs. CISM Vs. Security+ Vs. CEH: Which Certification Fits Your Career Stage

No single certification serves every stage of a cybersecurity career, and picking the wrong one wastes both money and months of preparation. These four credentials sit at different rungs of the ladder, and matching your current experience to the right one is the fastest way to avoid a stalled application or a wasted exam fee.

Entry Point: CompTIA Security+

Security+ requires no prior work experience, which makes it the default starting credential for career changers and early-career IT staff. The exam runs 370 to 420 dollars, and CompTIA positions it squarely for entry-level roles like security analyst or help desk security support. If you are still building foundational knowledge, this is where the finder should route you first.

Early to Mid-Level: CEH

Certified Ethical Hacker, issued by EC-Council, asks for two years of experience (or equivalent training) and costs 1,200 to 1,500 dollars, a noticeably steeper price than Security+. It targets early to mid-level practitioners moving toward offensive security and penetration testing work, but it does not offer an associate or waived-experience pathway, so candidates without the background typically need EC-Council training to qualify.

Senior and Management Track: CISM

CISM, from ISACA, is built for people already moving into security management. It requires five years of experience and costs 575 to 760 dollars depending on membership status. Like CEH, there is no associate-level on-ramp; ISACA expects the experience to already be in place before you sit the exam.

The Senior Benchmark: CISSP

CISSP, issued by ISC2, also requires five years of experience1 but includes a genuine bridge for those who are not there yet: the Associate of ISC2 pathway lets you pass the 749-dollar exam2 first and earn full CISSP status once you accumulate the required years, within a six-year window. A one-year waiver is also available for candidates with a relevant four-year degree.3 ISC2 positions CISSP for mid to senior-level roles, making it the credential most career changers aim for once Security+ and a few years of hands-on work are behind them.

Use the finder's experience-level filter to see which of these four, if any, actually accepts your current background before you commit to a study plan.

What the CISSP Endorsement Process Looks Like After You Pass

Passing the CISSP exam is a major milestone, but it does not grant you the credential immediately. ISC2 requires a formal endorsement process that must be completed within nine months of your exam date. If you miss that deadline, your passing score expires and you must retake the exam. Here is the step-by-step workflow and timeline you should plan around.

Five-step CISSP endorsement timeline from passing the exam to certification granted, with a nine-month completion deadline as of 2026

How to Become CISSP Certified Without Five Years of Experience

It is a classic catch-22: employers want the CISSP, but the certification demands five years of experience few career changers have at the start. The path is not closed, though. ISC2 offers two workarounds that let you earn the credential without meeting the full experience requirement on day one.

The Associate of ISC2 Pathway

If you can pass the exam but lack experience, this route is for you. You register and sit for the CISSP exam like any candidate. Once you pass, you do not hold the CISSP title. Instead, you become an Associate of ISC2. This status provides a six-year window to gain the five years of paid, relevant experience.1 You'll pay the same AMF, maintain CPE credits, and follow the ISC2 Code of Ethics as full holders.1 The clock is generous enough for someone who needs to build experience while already proving their knowledge.

Cutting a Year Off with the Experience Waiver

ISC2 allows you to substitute one year of the five-year requirement if you hold a four-year degree in computer science, IT, or a related field, or an approved cybersecurity certification.2 As of April 2026, the list of qualifying certifications was trimmed from around 50 to 25.3 The ones that survive include CCSP, CSSLP, SSCP certification, CompTIA Security+ and CySA+, Cisco CCNA and CCNP Security, and AWS Certified Security Specialty.4 Credentials like CEH, CISA, and OSCP were removed in that update.3 You can only apply a single waiver, so if you have both a degree and a qualifying cert, you still get just one year off.4 This reduces the required experience to four years.2

What Counts as Qualifying Experience?

Your work history doesn't need to map perfectly to a single domain. ISC2 calls for experience in at least two of the eight CISSP domains, such as security operations, identity management, risk assessment, or software development security.2 Full-time means 35+ hours a week; part-time (20-34 hours) counts proportionally.4 Many career changers have adjacent IT, network, or software development experience that touches security even without a 'cyber' title. Those years may count if duties aligned with a domain at least 90%, per the latest guidelines.4

What Associate Status Means in Practice

Associates cannot use the CISSP designation on resumes, email signatures, or LinkedIn. Use 'Associate of ISC2' instead. AMF and CPE requirements match full holders, so you invest before reaping branding benefits. For career changers, this pathway is a practical bridge: pass the exam now, then accumulate experience while working in a related role. Many employers recognize the effort and may count it toward promotion once you convert to full CISSP status.

Total Cost of CISSP Certification: Exam, Training, and Renewal

The true price of earning and maintaining your CISSP depends heavily on how you prepare. Self-study candidates can keep total three-year costs under $1,100, while those opting for an intensive boot camp may spend $5,000 or more. The breakdown below uses ISC2's current exam and maintenance pricing alongside realistic training ranges to show where your money goes over the first three-year certification cycle.

Three-year CISSP cost breakdown showing $749 exam fee, $50 to $5,500 training, $405 maintenance fees, and CPE costs, totaling roughly $934 to $6,384

The Eight CISSP Domains and How They Are Weighted on the Exam

The CISSP exam weights eight domains unevenly: Security and Risk Management claims the largest share at 16 percent, while Asset Security and Software Development Security sit at 10 percent. Understanding these proportions is as crucial as mastering the content itself because the adaptive exam draws more questions from heavier areas. The current ISC2 exam outline, valid from 2024 through 2026, reflects subtle but meaningful shifts, most notably a one-percentage-point bump for Domain 1 and a corresponding reduction for Domain 8, compared to the prior version.1

Domain Weight Breakdown (2024, 2026)

The official CISSP exam outline from ISC2 lists the following weightings:

  • Domain 1 , Security and Risk Management: 16%
  • Domain 2 , Asset Security: 10%
  • Domain 3 , Security Architecture and Engineering: 13%
  • Domain 4 , Communication and Network Security: 13%
  • Domain 5 , Identity and Access Management (IAM): 13%
  • Domain 6 , Security Assessment and Testing: 12%
  • Domain 7 , Security Operations: 13%
  • Domain 8 , Software Development Security: 10%

No domain is entirely safe to skip. Even a 10-percent share translates to roughly one question in every ten, and the adaptive algorithm will probe weak areas aggressively. However, candidates who allocate study time in proportion to these weights are better positioned to reach the scaled passing score.

How the CISSP Exam Is Structured

For most test-takers, the exam is delivered as a Computerized Adaptive Test (CAT) in English. The CAT presents between 125 and 175 questions over a maximum of four hours. The test adapts in real time: each response influences the difficulty of subsequent questions. A scaled score of 700 out of 1000 is required to pass, but this is not a simple percentage; it reflects a psychometric standard that the adaptive engine maintains consistently across exam forms. Non-English language exams or specific accommodations may use a linear fixed-form version with 250 questions, also completed within four hours.

Adjusting Your Study Plan to the Weights

Domain 1 alone accounts for nearly one-sixth of the exam, so it demands the deepest preparation, covering governance, risk management, compliance, and legal frameworks. The four domains weighted at 13 percent (Security Architecture and Engineering, Communication and Network Security, IAM, and Security Operations) collectively represent over half the exam, so they should anchor a cybersecurity certification study plan. Lighter domains still require fluency; the adaptive exam often zeros in on a candidate’s weaker spots, which can make a 10-percent domain feel much weightier if you are unprepared.

ISC2 updates domain weights every few years to reflect industry practice. The current outline took effect in 2024 and is expected to remain unchanged through 2026. Always cross-check your study materials against the official exam outline from ISC2, as third-party summaries can lag behind or misrepresent the distribution.

Cybersecurity Certification Salary and Job Outlook by Role

The table below presents national wage data from the Bureau of Labor Statistics Occupational Employment and Wage Statistics (2024) for the roles most commonly associated with CISSP and comparable cybersecurity certifications. Salary ranges span the 25th to 75th percentile to illustrate how earnings vary within each occupation based on factors like geography, employer, and seniority. Keep in mind that BLS figures reflect occupational wages broadly, not certification-specific premiums. A CISSP holder's actual compensation depends on the role performed, the location, the employer, and the scope of responsibility. Information Security Analysts, for example, are projected to grow 29 percent from 2024 to 2034, with roughly 16,000 openings per year, making this one of the fastest-growing occupations tracked by BLS.

RoleSOC CodeTotal Employment25th Percentile SalaryMedian Salary75th Percentile SalaryMean Salary
Information Security Analysts15-1212179,430$92,160$124,910$159,600$127,730
Computer and Information Systems Managers11-3021645,970$134,350$171,200$216,220$187,990
Computer Network Architects15-1241177,010$102,120$130,390$164,440$135,890
Did You Know?

CISSP is a mid-career accelerator, not a starting point. It signals management-level security knowledge and typically opens doors to senior analyst, architect, and leadership roles with median salaries above $120K. If you are still building the required five years of experience, take the exam anyway: you'll earn the Associate of ISC2 title now and convert to full CISSP once your experience qualifies.

How Credential Status Is Verified

Every credential listed in the Cybersecurity Certification Finder, whether a certification, certificate, or bootcamp, is validated directly against the issuing organization's official documentation: no crowd-sourced summaries, no unverified third-party claims. That means when you see a credential's exam cost, renewal requirements, or current status, the data comes from the source that controls it: the certification body itself.

Only Primary Sources Are Used

The editorial team pulls information exclusively from issuers' official exam guides, candidate handbooks, pricing pages, and policy announcements. A third-party training provider's website or a job board listing might list a fee that is outdated or bundled with optional prep materials, so the finder ignores those aggregator claims. Instead, our researchers record a direct URL back to the issuer page that confirms each data point. Every entry also carries a last-verified date, typically refreshed within the last 90 days. If an issuer hasn't published updated exam fees for the current year, the finder notes that rather than guessing.

Credential Lifecycle Tracking

Issuers occasionally announce that a certification is retiring, being re-branded, or receiving a new exam code. The finder classifies each credential as active, retiring, or retired. When a retirement date is published, it appears in the details. If a credential has already been retired but still appears in search results, it is clearly labeled so you can distinguish it from currently available options. Lifecycle changes are monitored through RSS feeds, direct email lists from major issuers, and regular manual checks. When ISC2, CompTIA, or EC-Council updates a candidate handbook (including the ISC2 Certified in Cybersecurity guide), the relevant entries in the finder are re-verified within two weeks.

User Flagging and Quarterly Re-verification

You can flag any credential you believe may be out of date. An editorial team member re-checks the issuer's primary source, and if the information has changed, the entry is updated within five business days. Even without flags, the entire directory undergoes a rolling quarterly re-verification cycle. Each quarter, a cross-section of credentials is re-audited, ensuring that every listing is confirmed at least twice per year. This process catches quiet price adjustments and policy changes that might otherwise go unnoticed.

  • Flag submission: A simple form at the bottom of any credential card lets you report inaccuracies.
  • Editorial SLA: Flags receive a reply within three business days and a data update, when warranted, within five.
  • Quarterly audit: No credential goes more than six months without a fresh check against its official source.

Limitations of the Cybersecurity Certification Finder

What the Finder Does and Does Not Do

The Cybersecurity Certification Finder is a decision-support tool, not a guarantee of any outcome. Filtering by role, experience level, or other criteria helps narrow the field of available credentials, but it cannot promise that you will be hired, accepted into an online cybersecurity program, pass an exam, or receive employer recognition for a particular certification. Each employer sets its own hiring standards, and many roles require a combination of education, hands-on experience, and clearance beyond certifications alone. Use the finder to explore options and build a shortlist, but always research employer expectations in your target industry and geographic area.

Salary and Employment Data: What the Numbers Mean

Salary figures shown in the finder are derived from U.S. Bureau of Labor Statistics (BLS) occupational medians for broad job categories that often require or benefit from cybersecurity credentials. They are not certification-specific salary premiums. Earning a certification does not automatically lead to a specific salary, and actual pay varies widely by location, experience, employer size, and negotiation. When you see a salary range next to a certification, treat it as a general market benchmark, not a direct promise. For the most accurate picture, cross-reference BLS data with job postings and salary surveys in your region.

Credential Requirements Can Change

Exam fees, experience prerequisites, renewal policies, and exam content evolve over time. Every credential listing in the finder includes a "last verified" date, which tells you when we last confirmed details with the issuing organization. Between that date and your application, requirements may have shifted. Before you invest time and money, always visit the official credential website to confirm current costs, eligibility, and renewal cycles. For credentials with pending retirements or updates, exam codes and objectives can change with little notice; you can compare cybersecurity certifications to track the latest versions, but always verify critical details directly with the issuer.

Coverage and Verification

The finder includes only credentials that have passed an editorial review and primary-source verification process. We do not list every certification on the market. Our team prioritizes widely recognized credentials from established issuers, but new ones appear frequently. If a credential you are researching is absent, it may simply not yet have been reviewed, not that it is invalid. We aim for transparency: each listing links to the official source, and we flag any credential that appears to be retired, inactive, or under revision. If you spot an error, let us know through the site's feedback channel.

Frequently Asked Questions About Cybersecurity Certifications and CISSP

The questions below cover the most common sticking points for learners evaluating cybersecurity certifications, with a focus on CISSP. Rather than citing a single number that may shift between exam cycles, each answer points you toward the authoritative source so you can verify details on your own timeline.

For professionals making a cybersecurity career change from adjacent fields such as IT administration, software development, or compliance, the CISSP certification is widely recognized as a gold-standard management-level credential. It signals broad security knowledge to hiring managers and is frequently listed in job postings for senior and leadership roles. That said, if you are brand new to the field with no hands-on experience, an entry-level certification such as CompTIA Security+ or the ISC2 Certified in Cybersecurity (CC) may be a more practical starting point. You can verify current employer demand by reviewing job postings on major boards and checking the Bureau of Labor Statistics (BLS.gov) Occupational Outlook Handbook for information security analyst roles, which includes general salary ranges and projected growth.

ISC2 offers a pathway for candidates who pass the CISSP exam but do not yet meet the full experience requirement. After passing, you can become an Associate of ISC2, which lets you work toward the required professional experience under a defined timeline. The specific number of years you need, any education-based waivers, and the deadline for completing your experience are detailed in the current ISC2 candidate handbook. Always check the official ISC2 website for the latest policy, because these terms can change between certification cycles.

Once you pass the CISSP exam, you must have your professional experience endorsed by an existing ISC2-certified professional. The endorser attests that your claimed experience is accurate. ISC2 publishes a step-by-step endorsement guide, including the timeline for submission and what happens if you cannot locate an endorser (ISC2 can act as your endorser under certain conditions). Visit the ISC2 endorsement page directly for the current form, deadlines, and acceptable experience categories.

The total investment includes the exam registration fee, any training courses or study materials you choose, and ongoing renewal costs such as annual maintenance fees and continuing professional education (CPE) credits over each renewal cycle. These figures change periodically, so the most reliable source is the ISC2 pricing and policies page. If you are comparing costs across multiple certifications, the cybersecurity certification cost varies, and the cybersecurity certification finder on our site includes a cost filter to help you evaluate credentials side by side, though you should always confirm final pricing with the issuing organization.

Start with the credential issuer's official website for exam objectives, pricing, renewal rules, and status (active, retiring, or retired). For salary benchmarks and employment projections, BLS.gov and O*NET OnLine provide government-sourced labor market data. The DoD publishes approved baseline certification lists (currently under the 8140 framework) for roles requiring federal compliance. Professional associations such as ISC2, ISACA, and CompTIA maintain candidate handbooks that outline eligibility, exam blueprints, and CPE requirements. Checking these primary sources ensures you are working with current information rather than outdated third-party summaries.

CISSP holders must earn a set number of continuing professional education (CPE) credits within each multi-year renewal cycle and pay an annual maintenance fee to keep the credential active. Non-renewal can result in the credential lapsing, which may require retaking the exam. The exact credit totals, fee amounts, acceptable CPE activities, and submission process are published in the ISC2 CPE handbook. Because these terms are updated periodically, confirm the current requirements on the ISC2 website before planning your renewal timeline.

The U.S. Department of Defense maintains an approved baseline certification list under its workforce framework. CISSP has historically been included at specific category and proficiency levels. However, the framework and its approved lists are updated over time, so you should consult the most recent DoD 8140 (or its successor) certification baseline document directly. The DoD Cyber Exchange portal is the authoritative source for confirming which certifications are currently approved and at which workforce role levels.

Recent Articles

In this article

Follow us