CISSP, CISM or CCSP: which security credential should you earn first?
Pick the credential your target job adverts name most often. As a rule of thumb, CISSP suits broad security leadership and architecture, ISACA's CISM suits management of a security programme, and ISC2's CCSP suits cloud security. Read each body's experience rule first, because the rule, not the exam, is usually what stops people.
Three famous security credentials, one limited budget. The expensive mistake is not failing an exam. It is passing the wrong one.
Start from the job, not the acronym
Security credentials are not ranked on one ladder. They answer different questions, and employers ask for them for different reasons. So begin with a role you would like in two years, then work backwards.
The CredenTrek CISSP book describes CISSP as ISC2's flagship credential. It covers eight domains and shows that you can design, implement and manage a security programme across an organisation. Its neighbours in the book's own "what comes next" chapter are:
| Credential | Issued by | Where the book places it |
|---|---|---|
| CISSP | ISC2 | Broad leadership, architecture and consulting |
| CISM | ISACA | Managing a security programme |
| CCSP | ISC2 | Cloud security |
| CISA | ISACA | Audit and assurance |
None of these replaces the others. A cloud architect and a head of risk may both hold CISSP and still need different second credentials.
Let ten adverts vote
Open a job site and search for the title you want, not the credential. Read ten advertisements and tally which letters appear under "required" and which under "preferred". Two minutes of tallying beats an evening of forum arguments.
Three patterns are common:
- Government contractors and large consultancies often name CISSP outright. ISC2 states that CISSP is approved under US DoD Manual 8140.03, which matters if you are aiming at defence work.
- Roles with "governance", "programme" or "risk management" in the title lean towards CISM or CISSP.
- Roles that mention cloud platforms by name often add CCSP or a vendor credential.
If your city shows no pattern, that is information too. In a small market, the broadest credential usually travels furthest.
Check the experience rule before the syllabus
Every one of these credentials asks for work history, and the rules differ. ISC2's rule for CISSP is at least five years of cumulative, full-time experience in two or more of the eight domains, with a possible waiver of one year for a degree or an approved credential. Without it, you can still pass and become an Associate of ISC2, with six years to earn the experience.
For CISM, CCSP and CISA, read the issuing body's current rule on its own site. Do not rely on a summary, including this one. The experience rule changes how long the whole route takes, and it is the part candidates read last.
Four questions to settle it
- Does a role you want in the next two years name one of these credentials in at least half of the adverts you read?
- Do you already have, or will you soon have, the experience the credential requires?
- Can you give the exam eight hours a week for several months?
- Does the cost, including the annual fee, fit your budget?
Four yes answers point to one credential. If you answer yes to the first question for two of them, choose the one with the lower experience barrier and plan the second for a year later.
When CISSP is the wrong first choice
It is a poor first security credential for someone with two years in IT support. They can pass and become an Associate, but the Associate period runs out in six years, and a lighter credential would often open more doors sooner. If that sounds like you, read the Associate route article in this blog before spending anything.
Your next hour
Write the role, tally ten adverts and note the three credentials that appear most. Then open the issuing body's page for the top one and read its experience rule in full.
Questions readers ask
Is CISSP harder than CISM?
Can I hold CISSP and CCSP together?
Which pays more, CISSP or CISM?
- ISC2, CISSP certification page
- US Bureau of Labor Statistics, information security analysts
- CredenTrek: Is CISSP worth it
This article is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.