Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CCSP Renewal and Continuing Education

Updated 9 min read
Key takeaway

CCSP maintenance requires 90 CPE credits over each three-year cycle, including at least 60 Group A; the remaining 30 may be Group A or B.

  • The current annual maintenance fee is US $135.
  • ISC2 recommends a 30-credit yearly pace, but certified members have a three-year CPE total rather than an annual CPE minimum.
On this page10 sections
  1. CCSP maintenance has two requirements
  2. Know the difference between Group A and Group B
  3. Plan the cycle without creating a year-end rush
  4. Choose qualifying activities by content
  5. Use the suggested pace as a planning tool
  6. Record evidence as you earn credits
  7. Pay the AMF on the certification cycle
  8. Check your balance against the actual minimums
  9. Understand the 90-day grace period
  10. Make CPE relevant to the work you want to do

CCSP maintenance has two requirements

To keep CCSP active, ISC2 members must earn and submit continuing professional education (CPE) credits and pay the annual maintenance fee (AMF). The current CCSP cycle requires 90 CPE credits over three years: at least 60 Group A credits, with the remaining 30 allowed from Group A or Group B. The annual AMF is currently US $135 for certified members who hold a credential other than CC alone.

The two obligations are separate. Paying the AMF does not create CPE credits, and completing CPE does not satisfy an unpaid fee. ISC2 recommends a yearly pace of 20 Group A plus 10 Group A or B credits, or 30 total, to spread the workload. For certified members, that annual pace is a planning recommendation; the requirement is measured across the three-year cycle.

RequirementCCSP rulePractical reading
CPE total90 credits per three-year cycleEarn and submit the cycle total
Group A minimumAt least 60 creditsThese activities relate directly to CCSP domains
Remaining credits30 may be Group A or Group BYou may also earn all 90 as Group A
Suggested annual pace20 Group A plus 10 Group A or BRecommended distribution, not a certified-member annual minimum
Annual Maintenance FeeUS $135 per year under current policyDue at cycle start and annual anniversaries

Know the difference between Group A and Group B

Group A credits come from activities directly related to the domains of the certification. For CCSP, that can include learning about cloud architecture, data security, infrastructure, secure applications, operations, audit, privacy, risk and compliance. ISC2 lists courses, events, certification training, cybersecurity webinars, podcasts, articles, books, research and security-related volunteering as examples.

Group B credits cover professional development outside the certification domains, such as general management or professional speaking training. CCSP holders can use Group B for up to 30 of the 90 required credits. If a course is about security leadership in cloud operations, it may relate directly to a domain; a general presentation-skills course is more likely Group B. Categorize based on the activity’s content and ISC2 policy.

A simple example: a cloud security webinar about key management is Group A because it directly develops a CCSP-domain skill. A general course on giving presentations is Group B. A professional conference may include both kinds of sessions, so record the specific session and learning rather than labeling the whole event from its title.

Plan the cycle without creating a year-end rush

At a recommended pace, a holder can aim for 20 Group A credits and 10 Group A or B credits each year. Over three years, that produces the required 60 Group A and 30 flexible credits. You can earn more Group A instead of using Group B. If a year is unusually busy, the policy does not impose the same annual CPE quota on certified members, but delaying all credits until the last months leaves less room for an audit or a missed record.

  1. At the start of the cycle, note the deadline and plan a mix of domain-specific and professional-development activities.
  2. After a course, webinar or project, record the date, provider, subject, hours and relevant CCSP domain.
  3. Submit qualifying activities in the ISC2 CPE portal regularly and keep supporting evidence.
  4. Review the dashboard periodically for the total and the Group A minimum.
  5. Before the cycle ends, fill any gap and confirm the annual AMF is current.

The plan should follow genuine professional learning. A member who manages cloud incidents can use relevant exercises and training for Group A. A member in audit may choose cloud assurance or data-governance learning. General leadership training can contribute Group B, but it cannot replace the 60-credit Group A minimum.

Choose qualifying activities by content

Activity exampleLikely groupRecord to keep
Cloud data-protection courseGroup ACompletion record, date, duration and domain
Webinar on cloud incident responseGroup AProvider, session title, date and notes
Article or book on provider audit scopeGroup ATitle, author or URL, date and learning summary
General management courseGroup BCourse record, date and professional-development topic
Public-speaking instructionGroup BProvider, date and completed training record

The examples describe likely categories based on ISC2’s definitions. The activity itself must meet the current CPE policy, and the member should be able to explain its connection. A broad conference may contain both domain-specific sessions and general professional development. Log individual qualifying sessions when that reflects the learning more accurately.

Suppose you attend a cloud incident exercise, read a technical article on data deletion and complete general leadership training. The exercise and article relate directly to CCSP domains, so they can support Group A claims. The leadership course may fit Group B. You still need to meet the 60-credit Group A minimum; a large number of general-development credits cannot replace it.

Use the suggested pace as a planning tool

ISC2’s suggested 20 Group A and 10 Group A or B each year can be placed around normal work. For example, a holder might complete one relevant course and several webinars or technical readings during the first year, then use incident exercises and cloud audit learning in the next. The activities need not be evenly divided by month, but a regular record makes it easier to notice a missing Group A total early.

If your cycle is nearing its end, calculate two numbers separately: all credits earned and Group A credits earned. A total of 90 does not meet the rule if fewer than 60 are Group A. If the Group A minimum is met, the final 30 may be additional Group A or Group B. Keep the activity evidence available until the cycle and any audit review are complete.

Record evidence as you earn credits

Keep a calendar or spreadsheet with activity name, date, subject, duration, credit category, domain connection and proof. Receipts, completion confirmations, agendas, notes or publication copies can help substantiate the activity if ISC2 asks for an audit. A short note about what you learned makes the record easier to assess later than an unexplained course title.

Use the ISC2 CPE portal to submit credits and the member dashboard to monitor the current total. Do not wait for the cycle anniversary to upload a pile of old records. If an activity spans both technical and management subjects, describe the relevant content and claim it under the applicable policy. Avoid counting the same learning twice unless the rules explicitly permit it.

Pay the AMF on the certification cycle

The current annual AMF for CCSP holders is US $135. It is due on the certification cycle start date and subsequent annual anniversaries. A member with multiple ISC2 certifications pays one AMF, not a separate fee for each credential. The first AMF is due after the certification application is approved and before ISC2 grants the credential.

At today’s rate, three annual payments amount to US $405 across a three-year cycle. This is a calculation from the current fee, not a promise that the price will remain unchanged. Payment timing follows the member’s cycle. Budget the AMF separately from the exam price, optional training and any paid CPE activity.

Check your balance against the actual minimums

Three-year balanceGroup AGroup BOutcome
Candidate A5733Short: total is 90, but Group A is below 60
Candidate B6030Meets the stated 90-credit mix
Candidate C900Meets the total with all credits in Group A

A candidate with 90 credits can still miss the rule if too many are Group B. Check both the total and the Group A floor. If you have 57 Group A and 33 Group B, you have the total but need at least three more Group A credits; additional Group B learning cannot solve that gap. The dashboard and your evidence log should agree before the cycle deadline.

The annual fee follows a different clock. A member pays US $135 on the certification cycle start date and each annual anniversary. The CPE requirement covers the three-year certification cycle. A candidate should therefore track three fee due dates and one CPE total, not assume that one payment at the three-year mark renews everything.

At the current rate, a three-year budget includes three annual payments, or US $405. A member holding multiple ISC2 credentials pays one AMF under the current policy, but still needs to satisfy each certification’s CPE rules. Include this recurring cost when comparing certification maintenance with optional training and conference expenses.

Understand the 90-day grace period

ISC2 provides a 90-day grace period after a certification cycle expires to earn and submit required CPE credits. The member must also pay any past-due AMF. Treat the grace period as time to resolve an unexpected shortfall, not as a normal extension of the learning cycle. The member policy says a credential can be suspended if required credits or fees remain outstanding after the grace period.

While suspended, a member may not represent themselves as currently certified or use the credential designation. Suspension can continue for up to two consecutive years; after that, the membership can be terminated and reinstatement rules apply. Keep enough buffer to correct rejected or incomplete CPE records before a cycle closes.

Make CPE relevant to the work you want to do

CPE is most useful when it strengthens a current skill gap. A cloud architect might study data protection, privacy and vendor exit design. An operations professional might focus on incident evidence, resilience and service monitoring. An auditor could deepen knowledge of cloud report scope, customer controls and jurisdictional risk. The credit total is a maintenance rule; selecting relevant activities is how the time can also improve practice.

ISC2 offers webinars, courses, events and volunteer opportunities, and some member activities are complimentary. A paid course is not automatically required. Before enrolling in an expensive event, confirm that its content qualifies, fits the relevant group and can be documented. A free domain-related webinar may be more useful than an unrelated paid conference.

Do not confuse CPE maintenance with the experience requirement for initial certification. CPE credits keep an awarded credential in good standing. They do not replace the five years of IT experience, three years in cybersecurity and one year in a CCSP domain that the credential requires, unless a permitted initial experience substitution applies.

Common questions

How many CPE credits does CCSP require?

CCSP requires 90 credits over a three-year cycle, including at least 60 Group A credits. The remaining 30 may be Group A or Group B. You can earn all 90 as Group A.

Does CCSP require 30 CPE credits every year?

No annual CPE minimum applies to certified members. ISC2 recommends 30 per year, including 20 Group A and 10 Group A or B, as a way to meet the three-year total steadily.

What is the CCSP annual maintenance fee?

The current AMF is US $135 per year for members who hold CCSP. It is due at the start of the certification cycle and each annual anniversary. Members with multiple ISC2 credentials pay one AMF.

What happens if I miss my CPE deadline?

ISC2 provides a 90-day grace period after the cycle expires to earn and submit required CPE credits and pay past-due AMFs. If obligations remain incomplete after that period, the certification may be suspended.