CISSP Renewal and Continuing Education
CISSP certification is maintained on a three-year cycle.
- Members must earn and submit 120 CPE credits, including at least 90 Group A credits, pay the annual maintenance fee, and remain in good standing under the ISC2 Code of Ethics.
- The current U.S. member AMF is $135 yearly.
- Track credits and payments in the ISC2 portal throughout the cycle.
On this page9 sections
- CISSP maintenance at a glance
- What Group A and Group B mean
- Ways to earn eligible CPE credits
- Report credits while the evidence is fresh
- Pay the annual maintenance fee
- A simple three-year CPE budget
- The grace period and what can go wrong
- Does CISSP maintenance support career growth?
- A renewal routine that stays manageable
CISSP maintenance at a glance
CISSP renewal is an ongoing membership obligation. ISC2 places the certification on a three-year cycle. During each cycle, a member must earn 120 continuing professional education credits, pay the Annual Maintenance Fee (AMF) each year, and meet the applicable membership and ethics requirements. CPE credits are reported through the ISC2 member portal and can be subject to audit.
| Requirement | CISSP member requirement | How to manage it |
|---|---|---|
| Certification cycle | Three years | Use the cycle dates shown in your ISC2 account. |
| Total CPE credits | 120 each cycle | Submit eligible activities in the portal and retain supporting records. |
| Group A minimum | 90 credits directly related to the credential domains | Choose learning or professional contributions tied to information security. |
| Group B maximum | Up to 30 credits for broader professional development | Use only activities allowed under ISC2's current CPE policy. |
| Annual maintenance fee | U.S. $135 per year for a member | Pay by the anniversary date shown in your account; tax may apply by jurisdiction. |
| Late completion | A 90-day grace period applies to CPE completion and submission | Do not treat the grace period as a routine extension or ignore the AMF due date. |
The three-year CPE total is not a single end-of-cycle payment. You can earn credits across the period and report them as you go. ISC2 recommends an annual pace of 40 CPE credits, including 30 Group A and 10 Group B. That pace spreads the workload and reduces the chance that you discover a large shortfall near the end.
What Group A and Group B mean
Group A activities relate directly to one or more domains of the CISSP credential. Examples may include security-focused education, conferences, webinars, research, writing, teaching, or professional service when the activity meets ISC2's current criteria. The important point is the connection to the credential's subject matter and the evidence that you completed the activity.
Group B covers broader professional development that is not directly tied to a CISSP domain but supports professional practice. Communication, leadership, or project skills may fit when the activity meets the handbook rules. Group B is limited to 30 of the 120 credits for the CISSP cycle. A general course does not become Group A merely because a security professional took it.
When an activity could fit either category, describe what you learned and how it relates to your work. Use the category guidance in the current ISC2 Certification Maintenance Handbook. If an activity does not clearly satisfy its criteria, do not count it based only on the time spent or the name of the event.
Ways to earn eligible CPE credits
Continuing education can come from formal courses, conferences, webinars, relevant professional reading, contributions to the field, teaching, or volunteer service. ISC2's handbook defines eligible activities and how to document them. The credit value depends on the activity type and evidence. A certificate of completion, agenda, attendance record, publication, or service confirmation may be useful documentation depending on what you report.
A practical annual plan mixes activities you already do with deliberate learning. A security conference can provide domain-specific sessions. A course can deepen knowledge in a weak area. Reading can qualify when it meets the reporting conditions and you record the relevant details. Writing or speaking can count under contribution rules, but do not assume every work deliverable qualifies as continuing education.
Keep the activity tied to a learning outcome. 'Attended a meeting' is a weak record. 'Completed sessions on cloud identity risks and documented the controls discussed' is more useful if it accurately describes the event and matches the handbook's evidence requirements. Do not embellish a short session into a larger credit claim.
| Activity idea | Likely connection | Record to keep |
|---|---|---|
| Security architecture course | Group A when it addresses CISSP domain knowledge | Completion record, course outline, and date. |
| Risk or privacy conference session | Group A when the content maps to relevant security domains | Agenda, attendance confirmation, and session notes. |
| Leadership or communication workshop | Potential Group B if eligible under the handbook | Completion evidence and a brief description of the skill. |
| Security research or authored article | Potential Group A contribution | Publication details, authorship, and the applicable activity record. |
| Volunteer work for a security association | Potential Group A professional contribution | Role, dates, hours or deliverables, and organization confirmation. |
Report credits while the evidence is fresh
Log each activity in the ISC2 portal with its date, category, description, and credit amount as required. Save the supporting evidence outside the portal as well. A calendar reminder after each event is more reliable than trying to reconstruct your activity at the end of the year. Name files consistently and keep a simple ledger with the event, date, CPE category, credits requested, and evidence location.
ISC2 can audit CPE submissions. If selected, you may need to provide proof that the activity occurred and met the policy. Retain course certificates, attendance records, agendas, publication copies, and volunteer confirmation for the retention period specified by the current handbook. A CPE entry is a claim that should be supportable, not simply a number added to a dashboard.
Check the member portal periodically. Verify that activities appear under the intended cycle and category, that the total is progressing, and that the AMF payment posted. If a submission is rejected or a credit value changes, correct the plan promptly. Do not wait for a renewal notice to discover that a record did not save.
Pay the annual maintenance fee
ISC2 currently lists a U.S. $135 annual maintenance fee for members holding CISSP and several other advanced certifications. It is due on the certification anniversary. ISC2 charges a single member AMF when a person holds multiple ISC2 certifications, rather than a separate member AMF for each one. Taxes may apply in some jurisdictions, and fees can change, so the account's current amount and due date control payment.
An Associate of ISC2 has a different status and fee. The current Associate AMF is U.S. $50, with 15 Group A CPE credits required annually. When an Associate completes the experience requirement and advances to certification, ISC2 describes an upgrade AMF of U.S. $85, assuming the Associate AMF has been paid for that year. That is a pathway-specific amount, not the standard annual fee for a certified CISSP.
Set reminders well before the anniversary. Confirm payment in the portal rather than relying only on a bank statement or a scheduled card charge. If your payment method expires or your billing address changes, update it early. The AMF supports membership administration, and keeping current is part of maintaining the active designation.
A simple three-year CPE budget
An even annual pace is 40 credits per year: 30 Group A and 10 Group B. For example, a member might complete a security-focused course and conference sessions for Group A, then use an eligible broader professional development course for Group B. The activity details and credit amount must still meet ISC2 policy; the arithmetic alone does not make a course eligible.
At the end of the first year, check that you have reported roughly 40 credits and paid the AMF. Repeat that review annually. Mid-cycle, compare the actual record with the 120 total and 90 Group A minimum. If you have plenty of Group B but too few Group A credits, prioritize domain-related learning. If your schedule gets disrupted, look for eligible activities that fit real learning needs rather than buying a course solely for its advertised credit number.
Members who meet the 120-credit requirement early should verify the cycle rules before assuming every additional credit can roll forward. ISC2 permits rollover only for qualifying excess Group A credits earned within the final six months of the cycle, up to 40 credits. The credits must exceed the current cycle's required total. Plan around the rule; do not use rollover as the primary maintenance strategy.
The grace period and what can go wrong
ISC2 policies provide a 90-day grace period after cycle expiration for completing and submitting required CPE credits. A grace period is a safety margin, not an extension to plan around. An unpaid AMF can still affect membership status under the fee policy. Check both requirements separately and contact ISC2 promptly if a medical or military circumstance prevents timely completion.
If a member misses requirements, the credential may be suspended. A suspended member may not represent themselves as currently certified or display the active designation. Reinstatement can require outstanding AMFs and CPE credits. After termination, additional reinstatement rules apply and can be more demanding. Prevention is simpler: track activities, save evidence, and pay each annual fee on time.
If your status changes, verify the exact designation and permitted use in the ISC2 portal before updating a résumé or profile. Employers and clients may check the credential. A lapsed or suspended badge can create a credibility problem even when the holder intends to fix it.
Does CISSP maintenance support career growth?
CPE requirements can help keep security knowledge current, especially when you choose activities that match the work you want to do. A cloud security course may deepen architecture knowledge; an incident response exercise can sharpen operational judgment; a privacy seminar can broaden risk discussions. The value comes from what you learn and apply, not from collecting credits alone.
CISSP does not guarantee a role, salary, promotion, or authority to practice. Employers set their own requirements, and regulated activities may need a separate license or qualification. The certification is a professional credential maintained under ISC2's experience, exam, ethics, and ongoing education rules. Keep those limits clear when describing its value.
Choose CPE activities that help with actual work or a deliberate skills gap. This gives the maintenance cycle practical value and makes the evidence easier to explain. A collection of relevant learning is more useful than a last-minute rush through unrelated material.
A renewal routine that stays manageable
- At the start of each cycle, note the cycle end date and annual AMF anniversary from your ISC2 account.
- Plan toward 30 Group A and 10 Group B credits each year, while checking activity eligibility in the current handbook.
- Submit credits after each activity and save evidence in a folder organized by cycle and date.
- Review the portal quarterly for category, credit, and payment accuracy.
- Six months before the cycle ends, compare totals with 120 overall and at least 90 Group A; fill genuine gaps early.
- After renewal, verify the new cycle dates and carry forward only credits ISC2 confirms as eligible.
CISSP renewal is straightforward when handled as a steady professional routine. Keep learning relevant, report accurately, pay the annual fee, and verify your status. Waiting until the deadline turns ordinary documentation into a rushed search.
Common questions
How many CPE credits does a CISSP need?
A CISSP needs 120 CPE credits in a three-year certification cycle. At least 90 must be Group A, directly related to the credential domains, and up to 30 can be Group B professional development under ISC2's policy.
What is the CISSP annual maintenance fee?
ISC2 currently lists a U.S. $135 annual maintenance fee for certified members holding CISSP. The fee is due on the membership anniversary; taxes may apply in some locations, and the amount can change.
Can unused CISSP CPE credits roll over?
ISC2 permits up to 40 qualifying excess Group A credits to roll over when earned in the final six months of a cycle. The credits must be above the current cycle's requirement. Check the current handbook and portal for eligibility.
What happens if I miss my CISSP CPE deadline?
ISC2 provides a 90-day grace period after cycle expiration for completing and submitting required CPEs. Missing maintenance requirements can lead to suspension, and reinstatement may require outstanding CPE credits and fees.
Do multiple ISC2 certifications mean multiple AMFs?
ISC2 says members pay one annual maintenance fee regardless of how many ISC2 certifications they hold. Each credential can still have its own CPE requirements, so review the rules for every certification in your account.