CredenTrek
Library / CISSP / Guide 08 of 8
CISSP · Renewal and CPE credits

Keep the CISSP you earned: 120 CPE credits, one annual fee and a calendar that never lapses

By Mustafa K. Al-Dori · Edition 2026.2, verified 9 October 2026 · 6 min read

The short answer

CISSP follows a three-year cycle. ISC2's maintenance handbook requires 120 CPE credits in each cycle, at least 90 of them in Group A (activities directly related to the domains), with the other 30 from Group A or Group B (wider professional development). ISC2 suggests about 40 a year. The annual maintenance fee is US$135. If you fall short, a 90-day grace period follows before the credential is suspended.

Holders forget to record their continuing education until the final months of the cycle, find that some activities do not qualify, and the credential is suspended just when a contract requires it. Recording monthly takes five minutes and prevents all of it.

What does ISC2 require?

CISSP follows a three-year cycle. ISC2's maintenance handbook requires 120 continuing professional education (CPE) credits in each cycle. At least 90 of them must be in Group A, which covers activities directly related to the domains. The other 30 may be Group A or Group B, which covers wider professional development. ISC2 suggests about 40 credits a year.

You also pay an annual maintenance fee of US$135, due each year on your membership anniversary.

Requirement Detail
Cycle Three years
CPE credits 120 in total
Group A At least 90
Group A or B The remaining 30
Suggested pace About 40 a year
Annual maintenance fee US$135

How do you earn credits?

  • Training courses, conferences and webinars on security topics
  • Writing, teaching or presenting on security
  • Volunteering for ISC2 or other professional bodies
  • Further education, and earning other relevant credentials

Rana, in the book, recorded her credits every month: webinars, a conference and two articles for her chapter's newsletter. She reached 120 credits six months before the end of her cycle and paid each annual fee on the day it was due.

Group A is the constraint most people miss. A year of general management training might feel substantial, but it counts towards Group B, and you need 90 credits in Group A. When you plan an activity, ask which group it falls into.

What if the cycle ends?

If you have not met the CPE requirement by the end of the cycle, ISC2 gives a 90-day grace period to earn and submit credits. After that, the credential is suspended. Keep evidence of every activity, because ISC2 audits submissions.

What do Associates owe?

Associates of ISC2 follow lighter rules while they build experience: a US$50 annual fee and at least 15 Group A credits each year. Your Associate period is a good time to build the habit of recording every activity in the month you complete it.

A renewal calendar that works

When What to do
The week you are certified Add your cycle end date and your annual fee date to your calendar, with reminders a month before each
Every month Record each activity in the month you complete it, with its evidence
Every quarter Check your total against the pace of about 40 credits a year, and check your Group A count
Month 24 Plan the remaining credits, favouring Group A
Month 33 If you are short, use the weeks before the cycle ends rather than the grace period

If you plan a new credential, check how many CPE credits it earns before you commit.

Should you renew or move on?

Renewal keeps what you have. It does not decide what comes next. Choose the next step from your goal: ISC2's architecture concentration (CISSP-ISSAP) for security architecture, the engineering concentration (CISSP-ISSEP) for engineering, the management concentration (CISSP-ISSMP) or ISACA's CISM for management, ISC2 CCSP for cloud security, and ISACA's CISA for audit and assurance. For executive leadership, leadership experience and business education usually count for more than another exam.

Kareem, in the book, passed CISSP and considered three more exams at once. His goal was to lead a security team, so he took a manager role instead and later added the management concentration, which his employer funded. A year or two of leading people, budgets and programmes usually adds more than another exam.

If you are still choosing whether to start, the first guide in this series has the fit test, and the cost guide lists the fees. Chapter 15 of CredenTrek For CISSP holds the full renewal plan, and Appendix D has templates for CPE credits and the annual fee.

Your next step
  1. Add your cycle end date and your annual fee date to your calendar, with reminders a month before each.
  2. Read the current ISC2 certification maintenance handbook and note the Group A and Group B rules.
  3. Create a folder for evidence of every activity you record.
  4. Write your three-year goal and decide whether it needs a new credential or more leadership experience.

Questions readers ask

How many CPE credits does CISSP need?
120 in each three-year cycle, with at least 90 in Group A. The other 30 may be Group A or Group B. ISC2 suggests about 40 a year.
What is the annual maintenance fee?
US$135 for members, due each year on your membership anniversary. Associates pay US$50.
What happens if I miss the CPE target?
ISC2 gives a 90-day grace period to earn and submit credits after the cycle ends. After that, the credential is suspended.
Does ISC2 check my CPE claims?
Yes. ISC2 audits submissions, so keep evidence of every activity.
Sources

This guide is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.