If you have passed the CISSP and started looking at what comes next, you have almost certainly run into three acronyms that nobody explains well: CISSP-ISSAP, ISSEP and ISSMP. Most of the advice you will find is out of date, because two things changed. ISC2 dropped the CISSP prerequisite in October 2023, and then rewrote all three exam outlines with effect from 1 August 2025.
The short answer is that these are no longer "CISSP concentrations" in any meaningful sense. They are three standalone advanced certifications aimed at three different jobs: the architect who designs the system, the engineer who builds security into it, and the manager who runs the programme. Pick the one that matches the lane your career is already in, because none of them is a general-purpose upgrade to the CISSP.
The Quick Answer: Which One Fits You
Before the detail, here is the decision in three lines.
- CISSP-ISSAP if your job title includes the word architect, or you spend your week producing reference architectures, zero trust designs, segmentation models and IAM patterns.
- ISSEP if you build security into systems under a formal engineering process, especially in defence, federal, aerospace or critical national infrastructure work where NIST systems security engineering language is the house style.
- ISSMP if you run the security function: the budget, the people, the incident response programme, the business continuity plan and the compliance reporting.
If none of those describes your day job, the honest answer is that a different certification will serve you better. These three are deep specialisms, not badges of general seniority.
Exam Tip: All three exams share the same format. You get 125 questions in 180 minutes and you need a scaled score of 700 out of 1,000 to pass. The exams are available in English only.
What Changed: They Are Not CISSP Concentrations Any More
For years these credentials were marketed as concentrations that sat on top of an active CISSP. That framing is dead, and it matters for eligibility.
There are now two routes in:
- You hold an active CISSP. You need two years of cumulative, full time paid experience in one or more of the domains of the specific certification you are chasing.
- You do not hold the CISSP. You need seven years of cumulative, full time paid experience in two or more of the relevant domains.
On the second route, a relevant degree in computer science or IT, or an ISC2 approved credential, can satisfy one year of the seven.
That second path is the genuinely new part. A security architect with a decade of design work behind them can now sit ISSAP without first grinding through the CISSP. Whether that is a good idea is a separate question, and for most people the answer is still no, because the CISSP is the credential HR filters on. If you are still weighing up the base certification, our 12 week CISSP study plan is the place to start, and the recent cut to the CISSP experience waiver list is worth reading before you plan your route.
The August 2025 rewrite was not cosmetic either. ISSAP went from six domains to four. ISSEP was restructured into five. ISSMP was rebuilt around six. Study material written before mid 2025 is describing exams that no longer exist.
CISSP-ISSAP Explained: Domains, Cost and Who It Suits
CISSP-ISSAP is the Information Systems Security Architecture Professional. It is the design credential, and the 2025 outline pushed it much harder towards modern infrastructure.
The four domains and their weights, effective 1 August 2025, are:
| ISSAP domain | Weight |
|---|---|
| Governance, Risk and Compliance (GRC) | 21% |
| Security Architecture Modeling | 22% |
| Infrastructure and System Security Architecture | 32% |
| Identity and Access Management (IAM) Architecture | 25% |
Two legacy domains disappeared. Application Security Architecture and Security Operations Architecture were absorbed into the surviving four, which is why Infrastructure and System Security Architecture now carries 32% of the exam on its own. That domain is where cloud, IoT, 5G and zero trust architecture content landed. The IAM domain also grew, with noticeably more weight on passwordless authentication and context aware access.
Who should sit it: enterprise and solution architects, cloud security architects, and senior engineers who are being pulled into design review boards. If you are already comparing cloud credentials, our CISSP vs CCSP comparison covers the layer below this one.
ISSEP Explained: The Engineering Credential
ISSEP is the Information Systems Security Engineering Professional, and it is the most specialised of the three. It applies systems security engineering discipline to the full system lifecycle, which is why it has a strong following in United States federal and defence work.
The five domains under the 1 August 2025 outline are:
- Systems Security Engineering Foundations
- Risk Management
- Security Planning and Engineering
- Systems Security Implementation, Verification and Validation
- Secure Operations, Change Management and Disposal
Notice the shape of that list. It follows a system from concept through to disposal, which is exactly how NIST systems security engineering guidance frames the work. If your organisation talks in terms of security requirements traceability, verification and validation, and formal authorisation packages, ISSEP will feel like a description of your job. If it does not, the exam will feel abstract and process heavy, and you will struggle to connect the questions to anything you have actually done.
Who should sit it: security engineers on government or defence programmes, systems engineers moving into security, and anyone working inside a formal risk management framework process.
Exam Tip: ISSEP rewards process fluency over tool knowledge. If you cannot explain how a security requirement is derived, allocated, verified and then maintained through change management, you are not ready to sit it.
ISSMP Explained: The Management Credential
ISSMP is the Information Systems Security Management Professional. It is the leadership credential, and it is aimed squarely at the person accountable for the security programme rather than any single system.
The six domains under the 1 August 2025 outline are:
- Leadership and Organizational Management
- Systems Lifecycle Management
- Risk Management
- Security Operations
- Contingency Management
- Law, Ethics and Security Compliance Management
Contingency Management is the domain candidates most often underestimate. Business continuity planning, disaster recovery and crisis management get their own dedicated space here in a way they never do on the CISSP.
Who should sit it: security managers, heads of information security, and CISOs in mid sized organisations. Be aware that ISSMP competes directly with ISACA's CISM for attention in this space, and CISM has far broader employer recognition. Our CISSP vs CISM breakdown is a useful sanity check before you commit.
ISSAP vs ISSEP vs ISSMP: The Full Comparison
| CISSP-ISSAP | ISSEP | ISSMP | |
|---|---|---|---|
| Focus | Designing secure architecture | Engineering security into systems | Running the security programme |
| Domains | 4 | 5 | 6 |
| Questions | 125 | 125 | 125 |
| Duration | 3 hours | 3 hours | 3 hours |
| Pass mark | 700/1,000 | 700/1,000 | 700/1,000 |
| Exam fee (US) | $599 | $599 | $599 |
| Best for | Security and cloud architects | Defence, federal and CNI engineers | Security managers and CISOs |
| Global average salary | $118,973 | $109,035 | $106,946 |
| North America average | $146,169 | $159,030 | $146,352 |
Salary figures are from ISC2's global certification salary research. Treat them as directional rather than a promise, and note the pattern: ISSEP leads in North America because of the government and defence premium, while ISSAP leads globally.
Cost, Renewal and the Fine Print
The exam fee is $599 in the United States for all three, and pricing varies by region. That is not the whole cost.
- Annual Maintenance Fee: $135 per year. Critically, if you hold multiple ISC2 certifications you pay a single AMF that covers all of them, so adding ISSAP to an existing CISSP does not add a second annual fee.
- CPEs: if you hold the CISSP alongside one of these credentials, 20 of the Group A CPE credits in your three year CISSP cycle must relate directly to the advanced certification. Hold more than one of the three and you owe 20 CPE credits for each.
- Training: ISC2 has moved to self paced adaptive courses for all three, which brought the entry price of official training down substantially compared with the old instructor led packages.
The renewal maths is the quietly attractive part. Because one AMF covers your whole ISC2 portfolio, the ongoing cost of a second credential is measured in CPE effort rather than money.
Which ISC2 Advanced Certification Is Worth It in 2026?
Here is the blunt assessment.
ISSAP is the safest bet for most people. Security architecture is a role that exists in almost every large organisation, private or public, and the 2025 rewrite made the exam much more relevant to cloud and zero trust work. It also has the highest global average salary of the three.
ISSEP is the highest ceiling but the narrowest door. The North America average salary is the best of the three, driven almost entirely by cleared defence and federal work. If you are in that world, it is arguably the most valuable credential on this page. If you are not, it will not open doors that ISSAP would not open more easily.
ISSMP is the hardest to justify on its own. Not because the content is weak, but because CISM occupies the same ground with more employer recognition and a larger candidate community. ISSMP makes sense if you are already deep in the ISC2 ecosystem and want to stay there, or if your employer specifically asks for it.
And the honest fourth option: if you are a recently qualified CISSP without a settled specialism, none of these three is your next move. Breadth beats depth at that stage. Look at the CCSP for cloud depth or a hands on credential instead, and come back to ISSAP or ISSEP once your job title has stabilised.
Exam Tip: Whichever you pick, download the current detailed content outline from ISC2 before you buy a single book. Anything published before August 2025 is mapped to the retired domain structure.
Frequently Asked Questions
What does ISSAP stand for?
ISSAP stands for Information Systems Security Architecture Professional. It is one of ISC2's three advanced security certifications, alongside ISSEP and ISSMP. It was previously branded as a CISSP concentration, which is why you will still see it written as CISSP-ISSAP.
How hard is ISSAP?
ISSAP is harder than the CISSP in depth but narrower in breadth. You face 125 questions in three hours and need 700 out of 1,000 to pass. The difficulty comes from the level of design judgement required rather than the volume of material, because the exam expects you to choose between several technically valid architectures based on business and risk context.
Is CISSP ISSEP worth it?
ISSEP is worth it if you work in United States federal, defence or critical infrastructure programmes where systems security engineering is the formal method. ISC2 salary research puts the North America average for ISSEP holders at $159,030, the highest of the three advanced certifications. Outside that sector, its recognition drops sharply and ISSAP is usually the better investment.
How much does an ISSAP certified professional make?
ISC2's global salary research puts the average ISSAP salary at $118,973 globally and $146,169 in North America. Advertised roles requiring CISSP-ISSAP in the United States commonly span roughly $121,000 to $216,000, with the top of that range reserved for principal and enterprise architect positions.
Do I still need the CISSP first?
No. Since October 2023 all three are standalone certifications. You can qualify with an active CISSP plus two years in the relevant domains, or with seven years of experience across two or more domains and no CISSP at all. In practice most candidates still take the CISSP first, because it is the credential that gets past recruitment filters.
Ready to Start Practising?
Advanced ISC2 exams punish candidates who revise by reading. All three use scenario driven questions where several answers are technically defensible and only one fits the context, and the only reliable way to build that judgement is repeated exposure to realistic questions with explanations that tell you why the runner up was wrong.
CertCrush gives you exam style practice questions with full explanations for CISSP, CCSP, CISM, CISA and the rest of the certification catalogue, so you can build the reasoning habits these advanced exams test before you pay $599 to find out whether you have them.
Create your free CertCrush account and start practising today.
