Cyber Defence
ISC2 · Management · Computerised adaptive test in English: between 100 and 150 items in 3 hours, with a scaled pass mark of 700 out of 1000. Longer linear versions exist in some other languages. Eight domains span security and risk management, asset security, architecture, network security, identity, assessment, operations and software development security.

CISSP — Certified Information Systems Security Professional

CISSP is ISC2’s senior credential for security managers, architects and leaders. It is broad and governance-heavy rather than technical, and it is genuinely gated: you must document five years of relevant paid work experience and be endorsed by an existing ISC2 member. It is the most widely demanded certification in senior security job advertisements.

Last updated: 6 August 2026

The facts

VendorISC2
LevelManagement
FormatComputerised adaptive test in English: between 100 and 150 items in 3 hours, with a scaled pass mark of 700 out of 1000. Longer linear versions exist in some other languages. Eight domains span security and risk management, asset security, architecture, network security, identity, assessment, operations and software development security.
CostHigh band. The exam fee alone is substantially more than a CompTIA voucher and is set in US dollars with regional variation, and there is a mandatory annual maintenance fee for as long as you hold it. Official training runs far more again, though many candidates self-study. Confirm current exam and maintenance fees directly with ISC2.
Validity / renewalThree years. You must earn 120 continuing professional education credits across the cycle, with an annual minimum, and pay the annual maintenance fee. Letting either lapse suspends the certification.
PrerequisitesFive years of cumulative, paid, full-time work experience in at least two of the eight CISSP domains. One year can be waived with an approved four-year degree or an approved credential — note that ISC2 substantially cut its approved credential list on 1 April 2026, reportedly removing several well-known certifications, so check the current list before relying on a waiver. Without the experience you can still sit the exam and become an Associate of ISC2 while you accumulate it. All candidates need endorsement by an ISC2-certified professional.

Vendors revise prices, formats and eligibility. Always confirm on the vendor's own site before you pay — including against this page.

Is it worth it?

CISSP proves managerial breadth: risk, governance, architecture and law across the whole security estate. In India it is the credential that appears in CISO, security manager, architect and consulting job specifications, and it materially affects salary bands at large IT services firms, banks and global capability centres. Because the experience requirement is verified and endorsed, it is one of the few security certifications employers genuinely treat as evidence of seniority.

The downside

It is a mile wide and an inch deep — passing proves you can reason about controls and management, not that you can configure or attack anything. For a fresher it is largely wasted: without five years of documented experience you get Associate status, and paying senior-level fees and annual maintenance for a junior job is poor economics. The CPE and fee treadmill never ends.

Compared to

VersusVerdict
CISMBoth are management-track. CISM is narrower and purely about managing an information security programme — governance, risk, incident and programme development. CISSP is broader and more technical in flavour. CISM tends to suit people already in management; CISSP suits architects and senior practitioners moving up.
CISADifferent job families. CISA is audit and assurance, CISSP is security management and architecture. Auditors, Big Four consultants and compliance teams want CISA; security leadership roles want CISSP.
OSCPNo overlap at all. OSCP proves you can break into a network; CISSP proves you can govern a security programme. Comparing them is a category error, though a senior practitioner may sensibly hold both at different career stages.
CEHCEH is technical-entry theory; CISSP is verified senior management. When Indian job listings mention both, CISSP is usually the one that actually gates the role and CEH is a nice-to-have line.

Where we fit

We do not teach CISSP and we do not prepare candidates for it. It is a management-track certification requiring years of documented professional experience, which no training institute can supply. We do not issue it, we are not an ISC2 training provider, and we do not sell exam vouchers. Amit Kumar holds CEH and CRTA — not CISSP — and our honest advice to students is to build the five years of real work first and revisit CISSP then.

We issue no vendor certification and resell no exam vouchers. Buy from the vendor.

CISSP — FAQs

Do I really need 5 years of experience for CISSP?

To hold CISSP, yes — five years cumulative paid work in at least two of the eight domains, with one year waivable by an approved degree or an approved credential. You may sit the exam without it and become an Associate of ISC2, then have a defined window to earn the experience and convert to full CISSP.

What is Associate of ISC2?

It is the status granted to someone who passes the CISSP exam but has not yet documented the required experience. You hold Associate status, pay maintenance fees and earn CPEs while you accumulate the years, then submit for endorsement and become a full CISSP.

Is CISSP worth it in India?

For managers, architects, consultants and anyone targeting CISO track roles at banks, IT services firms or global capability centres, yes — it appears in job specifications and affects salary banding. For a fresher or a hands-on tester it is not; the money and the annual fees are better spent on skills you can demonstrate now.

Kya aapki academy CISSP karati hai?

Nahi. CISSP management-level certification hai jismein paanch saal ka verified experience chahiye — koi bhi institute wo experience nahi de sakta. Hum CISSP na padhate hain, na certificate dete hain, na voucher bechte hain. Amit sir ke paas CEH aur CRTA hai, CISSP nahi.

Not sure if CISSP is the right next step?

Free call. If the honest answer is a cheaper certification, or six more months of lab work before you pay anyone, that is what you will hear.

Call +91 75175 72000