ISC2 (International Information System Security Certification Consortium) created CISSP in 1994 — the first credential in information security to meet the ANSI/ISO/IEC Standard 17024 requirements. ISC2 certifications are recognized by the US Department of Defense and governments worldwide. Their free CC (Certified in Cybersecurity) program has introduced over 400,000 new professionals to the security field since its launch in 2022.
CISSP is consistently one of the highest-paying IT certifications globally and is widely considered the gold standard for senior security leadership. ISC2 certifications are DoD 8570/8140 approved and are frequently listed as required or preferred for CISO, Security Architect, and senior security engineer positions at large organizations.
ISC2 runs one of the most recognized certification ladders in cybersecurity. It starts with Certified in Cybersecurity (CC), the entry-level exam that over 1 million people enrolled for under the free One Million Certified in Cybersecurity program before ISC2 closed it on May 20, 2026 (remaining exam vouchers stay valid through December 31, 2026). Above CC sit SSCP for hands-on security administration, the flagship CISSP for security leadership, and specialist credentials: CCSP for cloud security, CSSLP for secure software, and CGRC for governance, risk and compliance. CISSP holders can add three concentrations, ISSAP (architecture), ISSEP (engineering), and ISSMP (management).
Order matters because each exam pairs a price with an experience requirement. CC costs 199 dollars with no experience needed. SSCP is 249 dollars and asks for 1 year, CCSP, CSSLP and CGRC are 599 dollars with 5, 4 and 2 years respectively, and CISSP is 749 dollars with 5 years across two of its eight domains. Pass any exam before you have the years and you become an Associate of ISC2, keeping the result while you accrue experience (up to 6 years for CISSP). Full members pay a 135 dollar annual maintenance fee on a 3-year CPE renewal cycle, while Associates and CC-only holders pay 50 dollars per year.
CertCompanion carries practice banks for all nine ISC2 exams: CC, SSCP, CISSP, CCSP, CGRC, CSSLP, ISSAP, ISSEP and ISSMP. Each bank holds 830 to 850 questions, over 7,600 in total, with explanations tied to the current exam outlines. Every exam includes 30 free questions, so you can gauge where you stand on CISSP domains or CC fundamentals before paying for anything.
Worth watching in 2026: ISC2 is developing a dedicated AI security certification, announced in July 2026 with a pilot exam targeted for late 2026, and it has already published guidance adding AI security concepts across its existing certification exams. If you are choosing between CISSP and CCSP now, expect AI-related content to keep growing in both outlines.
ISC2 · CCSP
Validates advanced competency in cloud security architecture, design, operations, and service orchestration, covering cloud concepts, data security, platform and infrastructure security, application security, operations, and legal and compliance.
ISC2 · CC
The ISC2 Certified in Cybersecurity (CC) validates foundational knowledge and skills required for entry- or junior-level cybersecurity roles. It covers security principles, access controls, network security, and incident response concepts.
ISC2 · CGRC
Validates expertise in information security governance, risk management, and compliance, covering security and privacy governance, risk management, compliance and audit, information system authorization, and continuous monitoring.
ISC2 · CISSP
Validates technical and managerial security knowledge across eight domains, from risk and architecture through identity, assessment, operations, and software development security.
ISC2 · CSSLP
The CSSLP validates that software professionals have the expertise to incorporate security practices—authentication, authorization, and auditing—into each phase of the software development lifecycle (SDLC). It is designed for software developers, engineers, architects, and security professionals with at least four years of SDLC experience.
ISC2 · ISSAP
The ISSAP is a CISSP concentration that validates advanced expertise in designing security solutions and providing risk-based architectural guidance. It demonstrates specialized knowledge across security architecture modeling, infrastructure security, IAM, and governance.
ISC2 · ISSEP
An advanced ISC2 security-engineering credential covering engineering foundations, risk, security planning, implementation and verification, and secure lifecycle operations.
ISC2 · ISSMP
The ISSMP validates advanced expertise in establishing, presenting, and governing information security programs. It demonstrates deep management and leadership skills across security governance, risk management, incident management, and compliance.
ISC2 · SSCP
The SSCP validates advanced technical skills and practical knowledge to implement, monitor, and administer IT infrastructure using security best practices. It demonstrates a practitioner's ability to ensure data confidentiality, integrity, and availability across operational IT roles.