CISSP CPE Requirements: How to Maintain Your Certification
Passing the exam and completing endorsement gets you certified. Staying certified is a separate, ongoing obligation built around Continuing Professional Education credits and an annual fee. Here is exactly what ISC2 requires and how to meet it without much extra effort.
Unlike a lot of professional credentials that you earn once and keep forever, the CISSP has to be actively maintained. ISC2 requires certified members to keep learning after they pass, on the theory that a security professional whose knowledge is frozen at exam day quickly falls behind a field that changes every year. That ongoing requirement takes two forms: Continuing Professional Education (CPE) credits, and the Annual Maintenance Fee (AMF).
Neither one is difficult once you understand how the system is structured. Most working security professionals earn far more CPE credits than they need just by doing their jobs and paying attention to the field. The people who run into trouble are usually the ones who ignore the requirement for two years, then panic in year three. This guide breaks down the cycle, the credit categories, the fee, and the easiest ways to stay ahead of all of it.
The Three-Year CPE Cycle
CISSP certification maintenance runs on a rolling three-year cycle that starts on the date your certification was issued (or the date of your last recertification). Within that cycle, ISC2 requires two things at once: a total credit count for the full cycle, and a minimum you must hit every single year.
- 120 CPE credits total across each three-year certification cycle
- A minimum of 40 CPE credits per year, every year, regardless of how far ahead you are on the total
- Credits reported in one cycle do not carry over into the next; the count resets when a new cycle begins
The annual minimum is the part people miss. It is not enough to average 40 credits a year over three years by cramming 100 credits into year one and coasting for the next two. ISC2 checks the annual floor independently, so a light year followed by a heavy one can still leave you out of compliance even if your three-year total looks fine on paper.
Group A vs. Group B Credits
Not all continuing education counts the same way. ISC2 splits CPE activity into two categories, and understanding the difference matters more than most candidates expect.
- Group A credits come from activity directly related to one or more of the 8 CISSP domains: hands-on security work, security-focused training, security conferences, security certifications, and similar domain-specific learning. Group A credits satisfy the full requirement on their own with no restrictions.
- Group B credits come from broader professional development that is not security-specific but is still professionally relevant: project management, general leadership or communication training, business writing, and comparable skills. Group B credits count toward your total, but ISC2 caps how much of your requirement they can cover, historically a minority share of the three-year total rather than the majority.
The practical takeaway: treat Group A as your default source of credits and Group B as a supplement, not a substitute. If most of your CPE activity is domain-specific security learning, which is true for most working practitioners, the category split rarely becomes an issue. Check the current ISC2 CPE Handbook for the exact Group B cap in effect for your cycle, since ISC2 periodically revises the specifics.
The Annual Maintenance Fee (AMF)
CPE credits are only half of staying certified. ISC2 also charges an Annual Maintenance Fee to every certified member, currently around $125 per year for the CISSP. The AMF is billed annually and is due whether or not you have completed CPE activity for the year, and it applies on top of any fees you paid for the exam itself.
The AMF and CPE requirements are independent
Paying the AMF does not substitute for CPE credits, and earning CPE credits does not waive the AMF. ISC2 tracks both separately, and falling behind on either one can put your certification into suspension. Set a reminder for your renewal date so the fee never lapses by accident.
Low-Effort Ways to Earn CPE Credits
Most CISSPs who stay current in their field hit 40 annual credits without deliberately trying. If you want to be sure you are on pace, these are reliable, low-effort sources ISC2 recognizes:
- ISC2 chapter meetings and free webinars. ISC2 and its local chapters run regular webinars, many free, that typically earn one CPE credit per hour attended.
- Vendor and industry webinars. Security vendors, SANS, and other training organizations frequently offer free webcasts that qualify as Group A activity when the content maps to a CISSP domain.
- Conferences and industry events. Attending a security conference session, whether in person or virtual, typically earns credit hour for hour.
- Volunteering. Serving on an ISC2 chapter board, mentoring candidates, or volunteering on a security-related committee counts toward your total.
- Self-directed study. Reading security publications, completing vendor training, or working through structured courses can earn credit, usually with documentation requirements and a per-activity cap.
- Publishing or presenting. Writing an article, giving a talk, or teaching a course on a security topic earns credit, often more per hour than passive attendance because of the preparation involved.
- Earning another certification. A new, relevant certification can be submitted for a batch of CPE credit in the year it was earned.
The common thread: if it is professionally relevant, security-focused, and something you can describe and date, it is very likely eligible. When in doubt, submit it and let ISC2's review process make the call rather than assuming it will not qualify.
Reporting and Tracking Your Credits
CPE credits are self-reported through your ISC2 member account. For each activity, you will typically log the activity type, the sponsoring organization, the date, the number of hours or credits claimed, and a short description of what you did. Keep your own backup records, calendar invites, certificates of completion, webinar confirmation emails, for at least as long as your current cycle, since ISC2 does audit a portion of submissions and can ask for supporting documentation.
Do not wait until the end of your cycle to report everything at once. Logging credits as you earn them, even just a few minutes after a webinar or conference session, avoids the scramble of trying to reconstruct a year of activity from memory when your renewal date is approaching.
What Happens If You Fall Behind
Missing the annual minimum or letting the AMF lapse does not immediately strip your certification, but it starts a clock. ISC2 typically moves a non-compliant member into a suspended status, during which the CISSP designation cannot be used, and gives a window to resolve the shortfall by submitting outstanding credits and paying any past-due fees. If the certification remains unresolved beyond ISC2's reinstatement window, it can be revoked entirely, at which point regaining it means retaking and passing the exam again from scratch.
In practice, this outcome is avoidable with minimal effort. The people who lose their certification over CPE compliance are almost never people who tried and fell just short. They are people who stopped tracking the requirement entirely for an extended period. A once-a-year check of your ISC2 account against the 40-credit annual minimum is usually enough to stay safely ahead of any problem.
Frequently Asked Questions
How many CPE credits does a CISSP need?
120 CPE credits total across a three-year certification cycle, with a minimum of 40 credits required in each individual year of that cycle.
What is the difference between Group A and Group B CPE credits?
Group A credits come from activity directly tied to the CISSP's 8 domains and can satisfy your entire requirement. Group B credits come from broader professional development not specific to security and are capped at a minority share of your total, so they work best as a supplement to Group A activity rather than your primary source.
How much is the CISSP Annual Maintenance Fee?
Approximately $125 per year as of this writing. It is billed annually, applies regardless of your CPE progress, and is separate from any CPE reporting requirement. Confirm the current amount on your ISC2 member account, since ISC2 can adjust fees over time.
What happens if I do not earn enough CPE credits in a given year?
Your certification can move into a suspended status, during which you cannot use the CISSP designation. ISC2 provides a window to submit outstanding credits and resolve past-due fees. If the shortfall is not resolved within that window, the certification can be revoked, requiring you to retake the exam to become certified again.
Do CPE credits carry over between three-year cycles?
No. Each three-year cycle starts its own count at zero. Credits you earn beyond what a cycle requires do not roll forward into the next one.
Not Certified Yet? Start With the Exam
If you found this guide while researching what certification actually involves long-term, it is worth remembering that CPE maintenance only becomes relevant once you pass the exam and complete ISC2's endorsement process. The exam itself is scenario-based and tests managerial judgment more than raw technical recall, which is a different kind of preparation than most candidates expect going in. Our breakdown of how to think like a manager on the CISSP exam covers that reasoning shift, and our guide to how the CISSP passing score is calculated explains what the adaptive exam is actually measuring as you go.
See the Exam's Reasoning Style Before You Sit
Whether you are still preparing or already planning your first CPE cycle, understanding how CISSP questions are actually written helps. Try a free 5-question diagnostic, no account required.
Take the Free DiagnosticNo credit card required for the 7-day trial · CISSP, CCSP & CISM included
CISSP.app