CISSP — Certified Information Systems Security Professional
CISSP is ISC2’s senior credential for security managers, architects and leaders. It is broad and governance-heavy rather than technical, and it is genuinely gated: you must document five years of relevant paid work experience and be endorsed by an existing ISC2 member. It is the most widely demanded certification in senior security job advertisements.
Last updated: 6 August 2026
The facts
| Vendor | ISC2 |
|---|---|
| Level | Management |
| Format | Computerised adaptive test in English: between 100 and 150 items in 3 hours, with a scaled pass mark of 700 out of 1000. Longer linear versions exist in some other languages. Eight domains span security and risk management, asset security, architecture, network security, identity, assessment, operations and software development security. |
| Cost | High band. The exam fee alone is substantially more than a CompTIA voucher and is set in US dollars with regional variation, and there is a mandatory annual maintenance fee for as long as you hold it. Official training runs far more again, though many candidates self-study. Confirm current exam and maintenance fees directly with ISC2. |
| Validity / renewal | Three years. You must earn 120 continuing professional education credits across the cycle, with an annual minimum, and pay the annual maintenance fee. Letting either lapse suspends the certification. |
| Prerequisites | Five years of cumulative, paid, full-time work experience in at least two of the eight CISSP domains. One year can be waived with an approved four-year degree or an approved credential — note that ISC2 substantially cut its approved credential list on 1 April 2026, reportedly removing several well-known certifications, so check the current list before relying on a waiver. Without the experience you can still sit the exam and become an Associate of ISC2 while you accumulate it. All candidates need endorsement by an ISC2-certified professional. |
Vendors revise prices, formats and eligibility. Always confirm on the vendor's own site before you pay — including against this page.
Is it worth it?
CISSP proves managerial breadth: risk, governance, architecture and law across the whole security estate. In India it is the credential that appears in CISO, security manager, architect and consulting job specifications, and it materially affects salary bands at large IT services firms, banks and global capability centres. Because the experience requirement is verified and endorsed, it is one of the few security certifications employers genuinely treat as evidence of seniority.
The downside
It is a mile wide and an inch deep — passing proves you can reason about controls and management, not that you can configure or attack anything. For a fresher it is largely wasted: without five years of documented experience you get Associate status, and paying senior-level fees and annual maintenance for a junior job is poor economics. The CPE and fee treadmill never ends.
Compared to
| Versus | Verdict |
|---|---|
| CISM | Both are management-track. CISM is narrower and purely about managing an information security programme — governance, risk, incident and programme development. CISSP is broader and more technical in flavour. CISM tends to suit people already in management; CISSP suits architects and senior practitioners moving up. |
| CISA | Different job families. CISA is audit and assurance, CISSP is security management and architecture. Auditors, Big Four consultants and compliance teams want CISA; security leadership roles want CISSP. |
| OSCP | No overlap at all. OSCP proves you can break into a network; CISSP proves you can govern a security programme. Comparing them is a category error, though a senior practitioner may sensibly hold both at different career stages. |
| CEH | CEH is technical-entry theory; CISSP is verified senior management. When Indian job listings mention both, CISSP is usually the one that actually gates the role and CEH is a nice-to-have line. |
Where we fit
We do not teach CISSP and we do not prepare candidates for it. It is a management-track certification requiring years of documented professional experience, which no training institute can supply. We do not issue it, we are not an ISC2 training provider, and we do not sell exam vouchers. Amit Kumar holds CEH and CRTA — not CISSP — and our honest advice to students is to build the five years of real work first and revisit CISSP then.
We issue no vendor certification and resell no exam vouchers. Buy from the vendor.
CISSP — FAQs
Do I really need 5 years of experience for CISSP?
▾
What is Associate of ISC2?
▾
Is CISSP worth it in India?
▾
Kya aapki academy CISSP karati hai?
▾
Not sure if CISSP is the right next step?
Free call. If the honest answer is a cheaper certification, or six more months of lab work before you pay anyone, that is what you will hear.
Call +91 75175 72000