SSCP Renewal and Continuing Education
SSCP maintenance requires 60 CPE credits over three years: at least 45 Group A, with the remaining 15 from Group A or B.
- ISC2 currently suggests 15 Group A plus five A-or-B credits annually.
- Certified members pay one US $135 annual fee; complete credits by the 90-day post-cycle grace deadline.
On this page11 sections
- SSCP maintenance requirements
- Group A and Group B
- Annual maintenance fee
- When the three-year cycle ends
- A three-year credit plan
- Worked credit scenarios
- CPE activities can support real work
- Renewal planning around other certifications
- If you are behind
- A simple renewal checklist
- Frequently asked renewal questions
SSCP maintenance requirements
After ISC2 grants the SSCP credential, keeping it active requires continuing professional education (CPE) credits and payment of an annual maintenance fee (AMF). ISC2’s current Member Policies require 60 credits during each three-year SSCP cycle. The category split is 45 Group A and 15 Group A or Group B. You may earn all 60 as Group A; you cannot meet the rule with only Group B because the Group A minimum is 45.
ISC2 currently recommends an annual pace of 15 Group A credits and five additional Group A or B credits. That pace totals 20 per year, or 60 over three years. For certified members, the required amount is measured across the three-year cycle; the suggested annual pace helps avoid a last-minute shortfall. The member dashboard displays your cycle dates and credited activities.
Group A and Group B
Group A activities relate directly to the SSCP certification domains. Examples include a course on identity management, a workshop on incident evidence, a conference session on cryptographic key management, or technical research on network security. The activity should have a clear learning purpose and fit ISC2’s current CPE Handbook rules.
Group B applies to professional development that is not directly related to the certification domain but builds broader professional skills. Examples can include communication, leadership or project skills, subject to the handbook’s eligibility. Group B can contribute only up to the 15-credit portion for SSCP. It cannot replace the required 45 Group A.
Use the handbook and dashboard categories rather than guessing. Keep an activity record, completion date, duration, learning objective and evidence such as a certificate, agenda or notes if the policy requires it. ISC2 can audit CPE submissions. Accurate evidence makes an audit easier and avoids trying to reconstruct a three-year-old webinar.
Annual maintenance fee
ISC2 currently charges US $135 per year for a member holding SSCP or another professional ISC2 certification. Members pay one AMF even if they hold multiple professional certifications; the fee is due on the earliest applicable certification anniversary. Associates of ISC2 and people who hold only the foundational CC credential pay US $50 under the current policy.
The AMF is distinct from CPE. Paying $135 does not earn credits, and earning credits does not satisfy the fee. A candidate who first holds Associate status pays the Associate fee while qualifying and pays the current upgrade difference when certification is approved. When planning personal cost, use the member dashboard and current fee page for the due date and any jurisdictional tax.
When the three-year cycle ends
ISC2’s policy gives members and Associates a 90-day grace period after the cycle expiration date to earn and submit required CPE credits and pay past-due AMFs. This is a limited completion window, not an extra regular CPE year. Complete and submit activities before the credential cycle ends whenever possible, because a missing activity or rejected evidence can take time to resolve.
If required CPE and fees remain outstanding after the grace period, the certification can be suspended. ISC2’s policy permits suspension for up to two consecutive years. To reinstate, the member must submit outstanding credits and pay past-due AMFs under current policy. After two years, membership is terminated and reinstatement requires retaking and passing the exam. Avoid depending on grace or suspension remedies as a normal plan.
A three-year credit plan
At the start of the cycle, write down the exact expiration date shown in the ISC2 account. Set quarterly reminders and aim to log activity shortly after completion. A practical pattern is to earn about five Group A credits and one or two additional A-or-B credits per quarter, adjusted to the actual 15/5 annual recommendation and your opportunities. The point is steady accumulation, not a new annual minimum imposed by this example.
At the end of each year, check both totals: overall credits and Group A credits. Someone with 20 total but only 13 Group A has not met the suggested first-year pace. Someone with 60 total but only 44 Group A is still short of the three-year minimum. Keep separate running totals so Group B activity does not hide a Group A deficit.
Worked credit scenarios
Scenario 1: A member has 45 Group A credits and 15 Group B. Total is 60 and the Group A minimum is met; this meets the current category split, assuming the activities are approved and submitted on time.
Scenario 2: A member has 42 Group A and 18 Group B. The total is also 60, but Group A is three short and Group B exceeds the permitted 15. The member needs at least three additional Group A credits; more Group B cannot repair the deficit.
Scenario 3: A member completes 60 Group A credits. The requirement is met because Group A exceeds the 45-credit floor and Group B is optional.
Scenario 4: A member has 57 Group A plus five Group B with four months left. The member has 62 total but needs no more total credits; the missing action is to complete at least three additional eligible Group A credits and submit them before the deadline.
CPE activities can support real work
Choose learning that strengthens the security tasks you perform. A systems administrator might study endpoint hardening, cloud configuration or incident response. A network practitioner might study segmentation, wireless authentication or secure device management. A security analyst might study log integrity, threat analysis or forensic evidence. These can be Group A when directly related to SSCP domains and accepted under the handbook.
CPE need not be a paid course. ISC2’s handbook lists eligible educational and professional activities; member webinars, structured reading or research, publishing and volunteer contributions may qualify under their specific rules. Check credit calculations, reporting limits and evidence requirements for each category. Do not claim attendance for a session you did not complete or report the same activity in a way the policy forbids.
Maintain an evidence folder with course confirmations, dates, duration, title and learning notes. For an audit, a certificate alone may not show how an activity maps to the credential, so save the agenda or a short summary where appropriate. Keep the account log and your own evidence aligned.
Renewal planning around other certifications
If you hold more than one professional ISC2 certification, a single $135 AMF covers the member rather than each credential. CPE requirements may also overlap when an activity applies to more than one certification, subject to the current handbook. Record which domains an activity supports and follow the submission rules. Do not add a second $135 AMF simply because you earned another professional badge.
If you hold SSCP with CISSP, CCSP or another credential, use the account’s earliest anniversary and check the CPE dashboard for each certification requirement. A shared activity can be relevant to multiple domains, but the number of credits reported and accepted depends on the policies. Plan the stricter category or larger total first.
If you are behind
Open the ISC2 dashboard and identify the exact deficit: total CPE, Group A, fee or missing evidence. Check the remaining cycle time and choose eligible activities that directly address the gap. If the cycle is already expired, determine whether you are still inside the 90-day grace period and follow the current account instructions.
Contact Member Support early if an activity was rejected, an account date appears wrong, or a payment was not recorded. Keep the case number and copies of proof. Do not assume an email inquiry stops the deadline. If a medical or military issue affects completion, the policy describes case-by-case review of a grace-period extension; submit the request through the official process with supporting facts.
A simple renewal checklist
At cycle start, confirm your SSCP cycle dates, AMF anniversary, current annual fee and CPE category requirements. Each quarter, complete or document activities, log them and check the Group A balance. At each anniversary, pay the AMF and verify the transaction posts. Six months before expiry, compare total and Group A credits with 60 and 45. Resolve gaps before the final quarter.
By the cycle end, submit every activity, keep proof and confirm the dashboard reflects 60 total and 45 Group A. If a credit is pending, retain the evidence and contact ISC2 promptly. Paying the fee or being generally active in cybersecurity does not automatically update the CPE ledger.
Frequently asked renewal questions
How many CPE credits does SSCP require? 60 in three years, at least 45 Group A; up to 15 may be Group B.
Is there an annual minimum? Certified members have a three-year total. ISC2’s suggested pace is 15 Group A plus five A-or-B credits per year.
How much is the SSCP AMF? The current professional member amount is US $135 annually, one fee for multiple ISC2 certifications.
What if I miss the cycle deadline? A 90-day grace period applies. After that, the credential may be suspended under ISC2 policy.
Common questions
How many CPE credits does SSCP require?
60 over three years, including at least 45 Group A. The other 15 may be Group A or Group B.
How much is the SSCP annual maintenance fee?
ISC2 currently lists a US $135 annual fee for certified professional members; one AMF covers multiple professional certifications.
Does SSCP have an annual CPE minimum?
The certified member requirement is a three-year total. ISC2 suggests a pace of 15 Group A and five A-or-B credits each year.
What happens if I miss the renewal deadline?
ISC2 provides a 90-day grace period after cycle expiration. A credential may be suspended if requirements remain incomplete.