Keep the CISSP you earned: 120 CPE credits, one annual fee and a calendar that never lapses
CISSP follows a three-year cycle. ISC2's maintenance handbook requires 120 CPE credits in each cycle, at least 90 of them in Group A (activities directly related to the domains), with the other 30 from Group A or Group B (wider professional development). ISC2 suggests about 40 a year. The annual maintenance fee is US$135. If you fall short, a 90-day grace period follows before the credential is suspended.
Holders forget to record their continuing education until the final months of the cycle, find that some activities do not qualify, and the credential is suspended just when a contract requires it. Recording monthly takes five minutes and prevents all of it.
What does ISC2 require?
CISSP follows a three-year cycle. ISC2's maintenance handbook requires 120 continuing professional education (CPE) credits in each cycle. At least 90 of them must be in Group A, which covers activities directly related to the domains. The other 30 may be Group A or Group B, which covers wider professional development. ISC2 suggests about 40 credits a year.
You also pay an annual maintenance fee of US$135, due each year on your membership anniversary.
| Requirement | Detail |
|---|---|
| Cycle | Three years |
| CPE credits | 120 in total |
| Group A | At least 90 |
| Group A or B | The remaining 30 |
| Suggested pace | About 40 a year |
| Annual maintenance fee | US$135 |
How do you earn credits?
- Training courses, conferences and webinars on security topics
- Writing, teaching or presenting on security
- Volunteering for ISC2 or other professional bodies
- Further education, and earning other relevant credentials
Rana, in the book, recorded her credits every month: webinars, a conference and two articles for her chapter's newsletter. She reached 120 credits six months before the end of her cycle and paid each annual fee on the day it was due.
Group A is the constraint most people miss. A year of general management training might feel substantial, but it counts towards Group B, and you need 90 credits in Group A. When you plan an activity, ask which group it falls into.
What if the cycle ends?
If you have not met the CPE requirement by the end of the cycle, ISC2 gives a 90-day grace period to earn and submit credits. After that, the credential is suspended. Keep evidence of every activity, because ISC2 audits submissions.
What do Associates owe?
Associates of ISC2 follow lighter rules while they build experience: a US$50 annual fee and at least 15 Group A credits each year. Your Associate period is a good time to build the habit of recording every activity in the month you complete it.
A renewal calendar that works
| When | What to do |
|---|---|
| The week you are certified | Add your cycle end date and your annual fee date to your calendar, with reminders a month before each |
| Every month | Record each activity in the month you complete it, with its evidence |
| Every quarter | Check your total against the pace of about 40 credits a year, and check your Group A count |
| Month 24 | Plan the remaining credits, favouring Group A |
| Month 33 | If you are short, use the weeks before the cycle ends rather than the grace period |
If you plan a new credential, check how many CPE credits it earns before you commit.
Should you renew or move on?
Renewal keeps what you have. It does not decide what comes next. Choose the next step from your goal: ISC2's architecture concentration (CISSP-ISSAP) for security architecture, the engineering concentration (CISSP-ISSEP) for engineering, the management concentration (CISSP-ISSMP) or ISACA's CISM for management, ISC2 CCSP for cloud security, and ISACA's CISA for audit and assurance. For executive leadership, leadership experience and business education usually count for more than another exam.
Kareem, in the book, passed CISSP and considered three more exams at once. His goal was to lead a security team, so he took a manager role instead and later added the management concentration, which his employer funded. A year or two of leading people, budgets and programmes usually adds more than another exam.
If you are still choosing whether to start, the first guide in this series has the fit test, and the cost guide lists the fees. Chapter 15 of CredenTrek For CISSP holds the full renewal plan, and Appendix D has templates for CPE credits and the annual fee.
- Add your cycle end date and your annual fee date to your calendar, with reminders a month before each.
- Read the current ISC2 certification maintenance handbook and note the Group A and Group B rules.
- Create a folder for evidence of every activity you record.
- Write your three-year goal and decide whether it needs a new credential or more leadership experience.
Questions readers ask
How many CPE credits does CISSP need?
What is the annual maintenance fee?
What happens if I miss the CPE target?
Does ISC2 check my CPE claims?
- ISC2 CISSP certification page
- ISC2 certification maintenance handbook
- ISC2 CPE submission guidance
This guide is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.