ISC2 CC Renewal and Continuing Professional Education
To maintain CC, earn 45 Group A CPE credits during each three-year certification cycle and pay the annual maintenance fee.
- ISC2 recommends earning 15 credits per year.
- The annual AMF is US $50 for holders maintaining only CC; Group B credits do not apply to CC.
- Track credits in the ISC2 portal and follow the cycle dates shown in your account.
On this page13 sections
- The CC maintenance requirement
- Annual maintenance fee
- What qualifies as relevant CPE
- Plan the three-year cycle
- Submit and retain evidence
- Deadlines and a missed cycle
- Career relevance without overclaiming
- Renewal scenarios
- A sample three-year CPE plan
- Evidence for CPE entries
- CPE and work are not always the same thing
- Annual fee scenarios
- If a cycle is ending
The CC maintenance requirement
ISC2 Certified in Cybersecurity is maintained through continuing professional education and an annual maintenance fee. A CC holder must earn 45 Group A CPE credits during the three-year certification cycle. ISC2 recommends a pace of 15 credits per year to spread the work across the cycle. The official requirement is the three-year total; the annual figure is a planning recommendation, not a separate annual quota for a CC holder.
CC holders do not use Group B professional-development credits. ISC2’s maintenance policy says Group B credits are not applicable to CC. All 45 credits should relate to the certification’s cybersecurity subject matter and meet the handbook’s rules. The cycle and due dates are shown in the member account, which should be the starting point for any renewal plan.
Annual maintenance fee
The annual AMF for a member holding only CC is US $50, due on the certification cycle start date and subsequent annual anniversaries. Candidates also pay a first AMF after passing and completing the certification application, before the credential is granted. If you hold additional ISC2 certifications, the fee can be different under the member policy; verify the amount in your account rather than assuming the single-CC amount applies to a multi-certification profile.
A CC holder who has already paid ISC2 Candidate annual dues for the same year may have those dues cover that year’s CC AMF when becoming certified. That is not a waiver of future maintenance. Keep the payment confirmation, certification date and next anniversary visible in your budget. The AMF is separate from CPE credit reporting; paying it does not satisfy the education requirement.
What qualifies as relevant CPE
Group A activities relate directly to the domains of the certification. For CC, relevant work can include cybersecurity courses, security webinars, technical conferences, reading or researching cybersecurity topics, security-related volunteering, and appropriate professional activities tied to the exam domains. A course in IAM, incident response, governance, networking or cloud security may fit if it meets the handbook criteria.
The key is the learning connection. A general management workshop may be valuable professionally, but Group B is not available to meet CC’s CPE requirement. A broad technology course should be counted only when the content connects to cybersecurity and qualifies under ISC2’s current handbook. Do not claim credit merely for routine job time or passive activity without meeting the activity rules.
| Activity example | Likely CC relevance | Recordkeeping point |
|---|---|---|
| Attend a webinar on incident response | Group A subject matter | Keep completion confirmation and topic |
| Complete a course on identity access controls | Group A subject matter | Retain completion certificate and course hours |
| Read and research cloud security guidance | Potential Group A self-study | Record the material, time spent and learning summary as required |
| Volunteer on a cybersecurity awareness event | Potential Group A security activity | Document role, date and contribution |
| Attend a general project-management class | Not Group A by subject alone; Group B does not apply to CC | Do not count unless the activity meets an eligible cybersecurity-related rule |
Plan the three-year cycle
A steady schedule reduces the risk of a last-minute credit shortfall. Set a target of about 15 credits each year, log activities as they happen, and check the dashboard periodically. A holder who earns 20 credits in the first year has useful progress but still needs the full 45 by the cycle deadline. Credits should be relevant to the CC domains and completed within the eligible period.
- At certification, note the cycle start, annual AMF dates and cycle expiration in your calendar.
- Choose a few cybersecurity learning activities for the first year, such as courses, webinars or research.
- Enter each eligible activity in the ISC2 CPE portal and retain evidence.
- Review the dashboard each quarter or after a major activity to catch missing submissions.
- Before the final year, compare submitted credits with the 45-credit total and schedule the remaining learning.
An example: a help-desk analyst earns 12 credits in the first year through security awareness and access-control learning, 18 in the second year through incident response study and a relevant conference, and 15 in the third year through cloud-security training. The total is 45. The exact credits depend on the activity and handbook rules, so use the portal’s reporting instructions rather than assigning hours informally.
Submit and retain evidence
Some ISC2 training products report CPE automatically after completion; processing may take time. Other activities require the member to submit them through the CPE portal. Keep certificates, attendance confirmation, publication details or a concise activity record in case ISC2 asks for validation. A good record identifies what you did, when, how long it took and how the subject connects to cybersecurity.
Do not rely solely on an email saying a course is complete. Check the dashboard after the expected reporting period. If a credit entry is missing, use the provider’s completion record and submit or contact support according to the CPE portal process. Avoid duplicate entries for activities already reported automatically.
Deadlines and a missed cycle
ISC2’s maintenance policy provides a 90-day grace period after the end of a cycle to earn and submit outstanding CPE credits and pay overdue AMFs. If requirements are still unmet after the grace period, the certification can move to suspended status. The account and current policy govern the exact dates and consequences. Do not plan to rely on the grace period as routine study time; it exists to address outstanding obligations.
If you are short on credits near expiration, first determine which eligible activities can be completed and submitted in time. Do not enter work that did not occur or claim a general course as cybersecurity Group A without justification. If the certification is suspended, use ISC2’s reinstatement instructions and resolve both outstanding credits and fees. A holder should not advertise a suspended credential as active.
Career relevance without overclaiming
CPE can help a newcomer maintain foundational knowledge, especially as tools and threats change. A CC holder in user support might study access control and incident reporting; a business analyst could learn data protection and governance; a student may attend a local security chapter event. These activities support professional growth, but CPE completion alone does not prove job performance or guarantee an employment outcome.
A renewal plan should reflect actual work goals. If your role moves toward cloud operations, select relevant cloud security learning. If you are no longer using the credential, decide whether the maintenance cost and effort remain worthwhile. Allowing a certification to expire does not erase that it was earned, but you must label it as inactive or previously held rather than current.
Renewal scenarios
A holder with 45 relevant credits and all annual AMFs paid has met the stated maintenance quantities for the cycle, subject to ISC2 review and record acceptance. A holder with 45 credits but an unpaid AMF has not completed both parts. A holder who paid every year but has only 30 credits still has a CPE shortfall. Credits and fee are independent requirements.
A professional with both CC and another ISC2 certification should check the member policy and account because multi-certification fee rules differ. CPE can sometimes support more than one credential when the activity is relevant, but a member should follow current reporting instructions and not assume one credit automatically satisfies unrelated domain requirements. CC itself does not accept Group B credits.
Earn 45 Group A credits during each three-year cycle. ISC2 recommends a pace of 15 credits per year.
The AMF is US $50 annually for someone holding only CC. Multiple certifications may use different fee rules.
No. Group B credits are not applicable to CC; the credits must be relevant Group A activities.
ISC2 provides a 90-day grace period after the cycle ends to complete outstanding CPE and AMF requirements. Unresolved maintenance can lead to suspension.
A sample three-year CPE plan
A holder could plan 15 Group A credits in each year: in year one, complete a course on access controls and attend a security webinar; in year two, study incident response and document research into cloud security; in year three, attend a conference and complete a governance course. The exact number of credits depends on activity rules and evidence. The example illustrates a steady route to 45, not a required list.
| Year | Possible relevant activities | Planning target |
|---|---|---|
| 1 | IAM course and security webinar | About 15 Group A credits |
| 2 | Incident response training and cloud security research | About 15 Group A credits |
| 3 | Security conference and governance course | About 15 Group A credits |
A CC holder may complete more than 15 in one year and fewer in another as long as the required total and deadlines are met. ISC2 recommends 15 annually to avoid a final-cycle rush. Keep the dashboard current rather than waiting until the end to enter three years of activities.
Evidence for CPE entries
For an online course, retain the completion certificate, provider, date, topic and duration. For a webinar, keep registration or attendance evidence and the subject. For self-study, record the publication or material, time spent and a concise explanation of what was learned. For volunteering, note the organization, dates, role and cybersecurity connection. ISC2’s handbook determines what documentation is accepted if an entry is audited.
A good description is specific: “Completed a two-hour course on incident handling, covering preparation, containment, evidence and recovery.” A vague entry such as “read about security” makes it difficult to connect the activity to Group A. Do not inflate time or claim an activity that did not occur. If uncertain whether the material qualifies, consult the handbook before submitting it.
CPE and work are not always the same thing
Some unique work activities can qualify when they are directly related to the certification and meet ISC2’s rules, but ordinary routine job duties are not automatically CPE. A special assignment to develop an incident playbook may differ from performing the same daily support tasks. Describe what was unique, what was learned and how it connects to security. The handbook contains specific caps and evidence requirements; follow those instead of assuming every work hour earns credit.
The same distinction applies to training products. A course may list CPE credit, and some ISC2 offerings automatically report completion after a monthly processing cycle. Keep the validation of completion and check the portal. For outside providers, determine whether the activity qualifies and submit it yourself if required.
Annual fee scenarios
A member holding only CC owes the $50 AMF annually on the certification anniversary under current policy. A member with multiple ISC2 credentials may be subject to a different fee. A Candidate whose dues covered the first CC AMF for the same year still owes future annual maintenance. Always check the account for the member category, certification set and due date.
Suppose your CPE total is complete but the AMF payment is overdue. The maintenance requirements are independent, so the fee still needs attention. Conversely, paying three years of AMFs does not replace the 45 CPE credits. Keep a separate checklist line for each obligation.
If a cycle is ending
Check the exact end date in your ISC2 dashboard. The policy allows a 90-day grace period after cycle expiration to earn and submit outstanding CPE credits and pay due AMFs. Do not treat that period as extra planned time; a late submission can cause status complications. If you discover a shortfall, use eligible Group A activities and ask Member Services if the account status or deadline is unclear.
If the credential becomes suspended, follow ISC2’s reinstatement requirements and do not represent the certification as active while its status is suspended. Resolve missing credits and unpaid fees through the proper channel. Keep all confirmations until the account reflects good standing.
Common questions
How many CPE credits does ISC2 CC require?
CC requires 45 Group A CPE credits in a three-year cycle. ISC2 suggests 15 credits each year.
How much is the CC annual maintenance fee?
US $50 per year for holders maintaining only CC; check the account if you hold additional certifications.
Can CC holders use Group B CPE credits?
No. Group B credits do not apply to CC.
What happens if I miss the maintenance deadline?
ISC2 provides a 90-day grace period after cycle expiration. Unresolved requirements may result in suspension.