← All certifications

Certified Information Systems Security Professional (CISSP)

ISC2

The senior management-track credential. An Advanced qualification option for System Administrator (451), ISSM (722), Cyber Defense Incident Responder (531) and the sole listed option for Control Systems Security Specialist (462).

We have a course for this

Built from this exam's published objectives. The first module is free.

Baseline certification levels

This certification satisfies these DoD baseline levels — the IAT / IAM / IASAE / CSSP requirement many contracts still state. It's a separate question from the 8140 work roles above, and there is no official mapping between the two.

What this qualifies you for

Listed specifically for 17 work roles — up to Advanced proficiency. Because options cascade downward, a cert listed at Advanced also satisfies Intermediate and Basic for that role.

421Database AdministratorAdministers databases and/or data management systems that allow for the storage, query, and utilization of data.Advanced431Knowledge ManagerResponsible for the management and administration of processes and tools that enable the organization to identify, document, and access intellectual capital and information content.Advanced451System Administrator (SYSADMIN)Installs, configures, troubleshoots, and maintains hardware, software, and administers system accounts.Advanced462Control Systems Security SpecialistResponsible for device, equipment, and system-level cybersecurity configuration and day-to-day security operations of control systems, including security monitoring and maintenance along with stakeholder coordination to ensure the system and its interconnections are secure in support of mission operations.Advanced521Cyber Defense Infrastructure Support SpecialistTests, implements, deploys, maintains, and administers the infrastructure hardware and software.Advanced531Cyber Defense Incident ResponderInvestigates, analyzes, and responds to cyber incidents within the network environment or enclave.Advanced541Vulnerability Assessment AnalystPerforms assessments of systems and networks within the NE or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. Measures effectiveness of defense-in-depth architecture against known vulnerabilities.Advanced611Authorizing Official/Designated Representative (AO/DR)Senior official or executive with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation (CNSSI 4009).Advanced612Security Control AssessorConducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37).Advanced622Secure Software AssessorAnalyzes the security of new or existing computer applications, software, or specialized utility programs and provides actionable results.Advanced631Information Systems Security DeveloperDesigns, develops, tests, and evaluates information system security throughout the systems development lifecycle.Advanced641Systems Requirements PlannerConsults with customers to evaluate functional requirements and translate functional requirements into technical solutions.Advanced651Enterprise ArchitectDevelops and maintains business, systems, and information processes to support enterprise mission needs; develops information technology (IT) rules and requirements that describe baseline and target architectures.Advanced652Security ArchitectDesigns enterprise and systems security throughout the development lifecycle; translates technology and environmental conditions (e.g., law and regulation) into security designs and processes.Advanced661Research & Development (R&D) SpecialistConducts software and systems engineering and software systems research in order to develop new capabilities, ensuring cybersecurity is fully integrated. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems.Advanced722Information Systems Security Manager (ISSM)Responsible for the cybersecurity of a program, organization, system, or enclave.Advanced723Communications Security (COMSEC) ManagerManages the Communications Security (COMSEC) resources of an organization (CNSSI No. 4009).Advanced
Also listed for 14 Cyberspace Enablers roles — but so is every other certification

The Enablers matrix isn’t role-differentiated: the same certification options are listed for all 14 roles at every proficiency level. We verified that across all 14. So this is true, and it carries no information about this credential specifically — which is why it isn’t in the count above.

Renewal

3year cycle120CPE per cycle40minimum per year

Annual Maintenance Fee, USD 135/year

This is the issuer’s clock. 8140 runs a second one — 20 hours of CPD a year, at every proficiency level, which applies even if you hold no certification at all. How that works

The 40 CPE annual minimum matters: 120 CPE over three years cannot be left to year three.

Source: ISC2 CPE Handbook · checked 2026-07-16

Verifying it

ISC2 has no public lookup a third party can use on their own — verification depends on a badge URL you share.

A badge URL the holder shares. Credly proves a badge exists, not who holds it.

Source: ISC2 — Credly digital badges · checked 2026-07-16

Exam blueprint

Verified against ISC2’s published outline.

CISSP

Current

100–150 items · 3 hours · passing score 700 of 1000

Security and risk management16%
Asset security10%
Security architecture and engineering13%
Communication and network security13%
Identity and access management (IAM)13%
Security assessment and testing12%
Security operations13%
Software development security10%

Domains 1 and 8 were re-weighted on 2024-04-15. Training material citing 15% and 11% is built on the superseded outline.

Source: ISC2 CISSP exam outline · dated 2024-04-15 · checked 2026-07-16