ISC2 CISSP

Renewal requirements for the CISSP certification

Daniel Brecht
February 14, 2025 by
Daniel Brecht

The ISC2 Certified Information Systems Security Professional (CISSP) certification is considered the gold standard in information security credentials. A person with this designation is deemed to have sufficient technical knowledge and skills to develop or enhance a security program. 

There are stringent requirements that must be met to become recognized as a CISSP: 

  1. Have five years of cumulative, paid work experience in two or more of the eight domains of the ISC2 CISSP common body of knowledge (CBK). 
  2. Pass a three-hour CISSP exam consisting of 100 to 150 questions for the computerized adaptive testing (CAT). Alternatively, answer 250 questions in a six-hour testing window if taking the linear, fixed-form test administered in all other languages. 
  3. Get endorsed by an ISC2-certified professional who is currently an active member. This endorsement must happen no later than nine months after the date of the exam; otherwise, retaking the exam is required. 
  4. Recertify every three years to maintain your CISSP-certified status. 

Here are some frequently asked questions about CISSP recertification and renewal requirements. If you're preparing for your CISSP, Infosec Institute created a free, one-hour CISSP exam tips course and ebook with an instructor whose students have a 95% pass rate.

View Free Course

How long is the CISSP certification good for? 

Your CISSP certification is valid for three years, but you can maintain it indefinitely by following certain requirements. As per ISC2’s member policies, you must earn a minimum amount of continuing professional education (CPE) credits for each of your three-year certification cycles and pay an annual maintenance fee (AMF). 

Note: ISC2 allows certified members and associates a 90-day grace period to fulfill the AMF and CPE requirements on time. 

What are CISSP CPEs? 

Part of the renewal requirements for those holding the CISSP is meeting a certain amount of CPE credits over the course of your three-year certification cycle. Failure to comply will result in the revocation of an individual’s CISSP designation, which means they’d have to retake the exam to get recertified. 

Earn your CISSP, guaranteed!

Earn your CISSP, guaranteed!

Get live, expert CISSP training from anywhere. Enroll now to claim your Exam Pass Guarantee!

To satisfy the CISSP CPE requirements, beginning the calendar year after becoming certified, members need to engage in activities that directly relate to the domains of the certification (which earn you “Group A” credits) or that are outside the domains but still part of the general professional development (which give you “Group B” credits). 

What are CISSP AMFs? 

ISC2-certified members pay a single AMF of $135 (regardless of how many certifications they earn). This is due each year upon the anniversary of your certification date. Associates of ISC2 pay an AMF of $50, which is also due each year. 

Failure to pay within 90 days will result in certification suspension. The reinstatement fee is $600, in addition to the application fee of $100 and your AMF costs. This has to be paid before you can register for an exam by creating an account with Pearson VUE. 

What is the code of ethics? 

The Code of Ethics, or “The Code,” must be adhered to by all information security professionals recognized and certified by ISC2, not just CISSPs. The Code is composed of four mandatory canons: 

  • Protect society, the common good, necessary public trust and confidence and the infrastructure 
  • Act honorably, honestly, justly, responsibly and legally 
  • Provide diligent and competent service to principles 
  • Advance and protect the profession 

Members who violate any clause of The Code, whether knowingly or unknowingly, will be subject to action, which can result in the cancellation of their certification. 

What are the CISSP CPE maintenance requirements? 

Certified members have to earn and submit the following CPE credits: 40 per year (recommended) and 120 by the end of the three-year cycle (required). 

CISSP CPE activities must be completed during the three years and no later than the expiration date stated in the certification. You can submit your CISSP CPE credits after the expiration date (but not more than 90 days after). However, those credits must have been earned before the expiration date. 

What are the various CISSP CPE activities? 

Work completed as part of the regular job of a CISSP does not qualify for CPE credits. Instead, you earn credits by attending training sessions, conferences, seminars and similar activities, where you can gain a high level of knowledge or skill. 

The activities are divided into Group A (directly related to the domain) and Group B credits (professional development skills, education, knowledge or competency outside the domain). Here are some examples of the CISSP CPEs for which a member can earn credits: 

Group A credits: 

  • Attending a conference (in-person or virtual), educational course, seminar or presentation in communication and network security 
  • Publishing a book, whitepaper or article on security operations 
  • Serving as a subject matter expert (SME) for a panel discussion on asset security 

Group B credits: 

  • Technical skill sets not in information security, such as programming languages 
  • Management-oriented events that promote development in skills like communication and teamwork 
  • Project planning activities that expand their knowledge base to perform well at the tasks given 

These are just examples, and many other activities can be claimed as CPE credits. 

Members in “good standing” need not fret about CPE activities, as ISC2 has made them simple for members to access. 

How are CPE credits calculated? 

The CPE credits are weighed by the CPE activities you attend or participate in. In general, you earn one CPE credit per hour spent on an educational activity, although some are worth more credits. Here are a few examples of CPE opportunities: 

  • Attendance at conferences (both groups): Attendees in conferences related to cybersecurity will qualify for one Group A credit per hour, while other educational conferences (not related to the domains) receive one Group B credit per hour. 
  • Attendance at vendor presentations (Group A only): Group A credit is awarded for attending vendor presentations, as long as the presentation is educational and related to a CISSP domain. 
  • Completion of self-study, computer-based training (CBT) and podcasts (both groups): Attendance and completion of any of these activities will award one credit per hour for the member. Members should keep attendance records at any of these to provide details if they get audited. 
  • Volunteering for government and charitable organizations (Group A only): Each hour of volunteer work will earn you one CPE credit. The volunteer work must be related to the member’s credential since they earn you Group A credits. 
  • Reading information security books (Group A only): One completed book equals five CISSP CPE credits. Only one book per year is allowed in this instance. After completing the book, you must submit a summary of the information gained from the book. 

What will happen if I don't meet the requirements for renewal? 

Should a member fail to meet any of the requirements stated above, they will have the CISSP certification canceled or revoked. Also, if a member allows their certification to expire without renewing it prior to the expiration date, the certification is considered canceled. However, membership can be regained even after the certification has been canceled by retaking the exam. 

There are two ways to regain membership if the certification is revoked: 

Retaking the exam or by appeal 

  • Appeal: The ISC2 board hears appeals. To formally file an appeal, you have to put it in writing and submit it to the board within 90 days of any event (such as denial of CPE credits or certification expiration). The board will convene on a decision and send out a formal written response. This decision is considered final. 
  • Retaking the exam: A member can retake the exam to re-obtain their certification. The member will have to go through the same process they did the first time regarding scheduling the exam, paying for the examination fee and taking and successfully passing the test. If a prior member successfully passes the exam, they will have to contact the member services department to reactivate their certification.

Free CISSP one-hour prep course and ebook!

Free CISSP one-hour prep course and ebook!

Get proven exam tips from an instructor whose students have a 95% exam pass rate — plus a complimentary ebook!

Renewing your CISSP certification 

CPEs are a crucial part of staying a certified information security professional and continuing to learn in an ever-changing industry. Earning CPE credits not only helps individuals maintain their certification but also helps them grow as professionals. 

The steps for obtaining and maintaining a CISSP certificate may be tedious, but it’s a necessity in order to keep up with the ever-evolving world of information. This helps the ISC2 ensure the highest standards when it comes to the cybersecurity professionals it certifies. 

Considering taking the exam for the first time? You may find these resources helpful: 

Daniel Brecht
Daniel Brecht

Daniel Brecht has been writing for the Web since 2007. His interests include computers, mobile devices and cyber security standards. He has enjoyed writing on a variety of topics ranging from cloud computing to application development, web development and e-commerce. Brecht has several years of experience as an Information Technician in the military and as an education counselor. He holds a graduate Certificate in Information Assurance and a Master of Science in Information Technology.

Earn your CISSP, guaranteed!

Get live, expert CISSP training from anywhere. Enroll now to claim your Exam Pass Guarantee!