International Information System Security Certification Consortium
Security credentials with documented experience requirements, headlined by CISSP and CCSP and anchored by a shared common body of knowledge.
ISC2 certifications are built on a common body of knowledge that is revised on a three-year cycle. Most of them require documented professional experience in addition to a passing exam result, and candidates who pass without the experience are recorded as an Associate of ISC2 until they accrue it.
CISSP is the best known of the set and is deliberately broad rather than deep: it spans risk management, architecture, network security, identity, testing, operations and software security. The exam is delivered adaptively, so item count varies with performance.
Every credential is maintained through continuing professional education credits and an annual maintenance fee rather than by re-sitting the exam.
Foundational1
Entry-level credentials that validate core concepts and vocabulary.
Associate1
Role-based credentials for practitioners with hands-on experience.
Professional3
Advanced credentials covering design, scale and trade-off decisions.
Expert1
The highest tier, usually requiring a prerequisite certification.
Filter by practice availability, category, level or exam code. Retired exams are hidden by default.
6 exams
5 with practice · 1 guide only
The most widely recognised senior security certification: eight domains spanning risk management, asset and architecture security, networks, identity, testing, operations and software security.
Vendor-neutral cloud security: cloud architecture and design, data security, platform and infrastructure security, application security, operations, and legal and compliance obligations.
A practitioner-level credential for hands-on security roles: access controls, risk monitoring, incident response, cryptography, network security and systems and application security.
The authorisation and risk management credential, formerly CAP: building a risk management programme, selecting and implementing controls, assessment, authorisation and continuous monitoring.
Security across the software lifecycle: secure requirements, architecture and design, implementation, testing, deployment and operations, and securing the software supply chain.
An entry-level security certification with no experience requirement: security principles, business continuity and incident response, access control, network security and security operations.
How the ISC2 ladder is structured, from entry point to the top tier.
Entry-level credentials that validate core concepts and vocabulary.
Role-based credentials for practitioners with hands-on experience.
Advanced credentials covering design, scale and trade-off decisions.
The highest tier, usually requiring a prerequisite certification.
ISC2 exams with an available question bank. Each bank shows its source, licence and answer-support coverage.
Categories and topics that run through the ISC2 catalog.
This directory currently lists 6 ISC2 exams across 4 levels (Foundational, Associate, Expert and Professional). ISC2 adds and retires exams regularly, so treat this as a working map rather than a permanent one.
ISC2 Certified in Cybersecurity is the usual starting point — it is the most widely taken foundational-level exam in the ISC2 programme. An entry-level security certification with no experience requirement: security principles, business continuity and incident response, access control, network security and security operations.
The best-known active options in this directory include ISC2 Certified Information Systems Security Professional, ISC2 Certified Cloud Security Professional and ISC2 Certified in Cybersecurity. Compare their levels, syllabus domains and role focus before choosing one.
Yes — 5 ISC2 exams have 1,377 practice questions in total. 820 questions currently carry an explanation. Every bank is labelled with its source and licence; 5 community-contributed banks are available.
15 categories · browse by technology · all providers