Published September 7, 2026 · CISSP Certification Process

CISSP CPE Requirements: How to Maintain Your Certification

Passing the exam and completing endorsement gets you certified. Staying certified is a separate, ongoing obligation built around Continuing Professional Education credits and an annual fee. Here is exactly what ISC2 requires and how to meet it without much extra effort.

9 min read

Unlike a lot of professional credentials that you earn once and keep forever, the CISSP has to be actively maintained. ISC2 requires certified members to keep learning after they pass, on the theory that a security professional whose knowledge is frozen at exam day quickly falls behind a field that changes every year. That ongoing requirement takes two forms: Continuing Professional Education (CPE) credits, and the Annual Maintenance Fee (AMF).

Neither one is difficult once you understand how the system is structured. Most working security professionals earn far more CPE credits than they need just by doing their jobs and paying attention to the field. The people who run into trouble are usually the ones who ignore the requirement for two years, then panic in year three. This guide breaks down the cycle, the credit categories, the fee, and the easiest ways to stay ahead of all of it.

The Three-Year CPE Cycle

CISSP certification maintenance runs on a rolling three-year cycle that starts on the date your certification was issued (or the date of your last recertification). Within that cycle, ISC2 requires two things at once: a total credit count for the full cycle, and a minimum you must hit every single year.

The CPE requirement in one look:

The annual minimum is the part people miss. It is not enough to average 40 credits a year over three years by cramming 100 credits into year one and coasting for the next two. ISC2 checks the annual floor independently, so a light year followed by a heavy one can still leave you out of compliance even if your three-year total looks fine on paper.

Group A vs. Group B Credits

Not all continuing education counts the same way. ISC2 splits CPE activity into two categories, and understanding the difference matters more than most candidates expect.

The practical takeaway: treat Group A as your default source of credits and Group B as a supplement, not a substitute. If most of your CPE activity is domain-specific security learning, which is true for most working practitioners, the category split rarely becomes an issue. Check the current ISC2 CPE Handbook for the exact Group B cap in effect for your cycle, since ISC2 periodically revises the specifics.

The Annual Maintenance Fee (AMF)

CPE credits are only half of staying certified. ISC2 also charges an Annual Maintenance Fee to every certified member, currently around $125 per year for the CISSP. The AMF is billed annually and is due whether or not you have completed CPE activity for the year, and it applies on top of any fees you paid for the exam itself.

The AMF and CPE requirements are independent

Paying the AMF does not substitute for CPE credits, and earning CPE credits does not waive the AMF. ISC2 tracks both separately, and falling behind on either one can put your certification into suspension. Set a reminder for your renewal date so the fee never lapses by accident.

Low-Effort Ways to Earn CPE Credits

Most CISSPs who stay current in their field hit 40 annual credits without deliberately trying. If you want to be sure you are on pace, these are reliable, low-effort sources ISC2 recognizes:

The common thread: if it is professionally relevant, security-focused, and something you can describe and date, it is very likely eligible. When in doubt, submit it and let ISC2's review process make the call rather than assuming it will not qualify.

Reporting and Tracking Your Credits

CPE credits are self-reported through your ISC2 member account. For each activity, you will typically log the activity type, the sponsoring organization, the date, the number of hours or credits claimed, and a short description of what you did. Keep your own backup records, calendar invites, certificates of completion, webinar confirmation emails, for at least as long as your current cycle, since ISC2 does audit a portion of submissions and can ask for supporting documentation.

Do not wait until the end of your cycle to report everything at once. Logging credits as you earn them, even just a few minutes after a webinar or conference session, avoids the scramble of trying to reconstruct a year of activity from memory when your renewal date is approaching.

What Happens If You Fall Behind

Missing the annual minimum or letting the AMF lapse does not immediately strip your certification, but it starts a clock. ISC2 typically moves a non-compliant member into a suspended status, during which the CISSP designation cannot be used, and gives a window to resolve the shortfall by submitting outstanding credits and paying any past-due fees. If the certification remains unresolved beyond ISC2's reinstatement window, it can be revoked entirely, at which point regaining it means retaking and passing the exam again from scratch.

In practice, this outcome is avoidable with minimal effort. The people who lose their certification over CPE compliance are almost never people who tried and fell just short. They are people who stopped tracking the requirement entirely for an extended period. A once-a-year check of your ISC2 account against the 40-credit annual minimum is usually enough to stay safely ahead of any problem.

Frequently Asked Questions

How many CPE credits does a CISSP need?

120 CPE credits total across a three-year certification cycle, with a minimum of 40 credits required in each individual year of that cycle.

What is the difference between Group A and Group B CPE credits?

Group A credits come from activity directly tied to the CISSP's 8 domains and can satisfy your entire requirement. Group B credits come from broader professional development not specific to security and are capped at a minority share of your total, so they work best as a supplement to Group A activity rather than your primary source.

How much is the CISSP Annual Maintenance Fee?

Approximately $125 per year as of this writing. It is billed annually, applies regardless of your CPE progress, and is separate from any CPE reporting requirement. Confirm the current amount on your ISC2 member account, since ISC2 can adjust fees over time.

What happens if I do not earn enough CPE credits in a given year?

Your certification can move into a suspended status, during which you cannot use the CISSP designation. ISC2 provides a window to submit outstanding credits and resolve past-due fees. If the shortfall is not resolved within that window, the certification can be revoked, requiring you to retake the exam to become certified again.

Do CPE credits carry over between three-year cycles?

No. Each three-year cycle starts its own count at zero. Credits you earn beyond what a cycle requires do not roll forward into the next one.

Not Certified Yet? Start With the Exam

If you found this guide while researching what certification actually involves long-term, it is worth remembering that CPE maintenance only becomes relevant once you pass the exam and complete ISC2's endorsement process. The exam itself is scenario-based and tests managerial judgment more than raw technical recall, which is a different kind of preparation than most candidates expect going in. Our breakdown of how to think like a manager on the CISSP exam covers that reasoning shift, and our guide to how the CISSP passing score is calculated explains what the adaptive exam is actually measuring as you go.

See the Exam's Reasoning Style Before You Sit

Whether you are still preparing or already planning your first CPE cycle, understanding how CISSP questions are actually written helps. Try a free 5-question diagnostic, no account required.

Take the Free Diagnostic

No credit card required for the 7-day trial · CISSP, CCSP & CISM included

Related Resources