For most people, the certification to take after ISC2 CC is CompTIA Security+. It is the credential entry-level security job adverts ask for by name, and it needs no work experience. The exception is if you already work in IT and have a year of hands-on security work. In that case SSCP is the better next step, because it keeps you on the ISC2 ladder and costs less.
CC gives you vocabulary and a credential, but most employers read it as proof of interest rather than proof of skill. The next certification is where you choose a direction, so this guide starts from the job you want and works back to the exam.
What ISC2 CC Does and Does Not Give You
CC proves you understand the basics across five domains: security principles, business continuity and incident response, access control, network security, and security operations. Since 1 September 2026 the outline has also covered governance and cloud topics more heavily (the new CC domains and weightings are broken down separately).
What it does not do matters more once you start planning a next step:
- It does not waive CISSP experience. ISC2 lets approved credentials count for one of CISSP's five required years. Security+ and CySA+ are on that approved list. CC is not.
- It does not appear on most job adverts as a stand-alone requirement. Security+ and SSCP show up far more often, partly because both are approved under the US DoD 8140 framework.
- It carries no hands-on component. There are no performance-based questions, so it tells an employer nothing about whether you can configure a firewall rule or read a log.
That first point is the one most "what next" advice misses. If CISSP is your long-term goal, the certification you take after CC can take a year off your wait. CC itself cannot.
Exam Tip: CC holders pay a US $50 Annual Maintenance Fee and need 45 CPE credits over each three-year cycle. Once you earn SSCP or CISSP, ISC2 charges a single AMF of US $135 covering every ISC2 certification you hold, so CC does not add a second fee.
The Next Certification After ISC2 CC, by Career Goal
| Your goal | Next certification | Exam fee (US) | Experience rule | Why |
|---|---|---|---|---|
| First security job, no IT background yet | CompTIA Security+ | $439 | None required (Network+ and two years' admin experience recommended) | Most-requested entry credential; counts toward the CISSP waiver |
| Already in IT, one year of security duties | ISC2 SSCP | $249 | One year in one of seven domains to be fully certified | Cheaper than Security+, same DoD approval, stays in ISC2 |
| SOC or threat analyst role | Security+, then CySA+ (CS0-004) | Not listed on CompTIA's exam page | About four years in a SOC or vulnerability analyst role recommended | CySA+ is the analyst credential; CC is too light to skip Security+ |
| AI security specialism | Security+, then SecAI+ (CY0-001) | Not listed on CompTIA's exam page | 3 to 4 years in IT, 2+ years hands-on security recommended | SecAI+ assumes Security+ level knowledge |
| Security management, long term | CISSP (via Associate of ISC2 if needed) | $749 | Five years in two of eight domains | The destination, not the next step, for most CC holders |
ISC2 prices are from the ISC2 exam pricing page for the Americas. The Security+ price is CompTIA's US list price. CompTIA does not show a fee on the CySA+ or SecAI+ exam pages, so check the CompTIA store before you budget.
Security+: The Default Next Step After CC
Security+ is the natural follow-on for someone who took CC as their first certification. It covers the same ground in more depth and adds performance-based questions, which is the first time you are tested on doing rather than recognising.
The current exam, SY0-701, has a maximum of 90 questions in 90 minutes, and the pass mark is 750 on a scale of 100 to 900. CompTIA has said Security+ V8 (SY0-801) is expected to launch on or around 17 November 2026. The English SY0-701 exam retires on 11 June 2027, so you have time to choose a version (the SY0-801 vs SY0-701 comparison covers what moves).
Three reasons it usually wins over the alternatives for a CC holder:
- It needs no experience to be fully certified, so you are not stuck as an Associate.
- It counts as one year of CISSP experience under ISC2's approved-credential waiver.
- Your CC study transfers directly. The security principles, access control and incident response material you just learned maps onto Security+ Domain 1 (General Security Concepts) and Domain 4 (Security Operations).
If you are still deciding between the two as a first certification, that is a different question, answered in ISC2 CC vs Security+. This guide assumes CC is already done.
Practise for it on the CompTIA Security+ course.
SSCP: The Better Choice If You Already Work in IT
SSCP is ISC2's practitioner certification, aimed at security and systems administrators. ISC2 requires a minimum of one year of full-time experience in one or more of the seven SSCP domains. A bachelor's or master's degree in computer science, IT or a related field can satisfy that year.
If you pass without the experience, you become an Associate of ISC2 and have two years to earn the one year required. Part-time work counts: 1,040 hours at 20 to 34 hours a week gives you six months, and paid or unpaid internships are accepted with documentation.
SSCP makes sense after CC when:
- You are a help desk, systems or network administrator who already handles patching, account management or firewall changes.
- Your employer uses ISC2 credentials, or your budget matters. At US $249, SSCP costs $190 less than Security+.
- You want one ISC2 membership. Your CC and SSCP sit under a single US $135 AMF.
It makes less sense if you have no IT job yet. You will hold "Associate of ISC2" rather than SSCP on your CV until you log the year, and a hiring manager scanning for Security+ may not know what that means. The SSCP explained guide covers the seven domains, and the ISC2 SSCP course has practice questions for each.
CySA+ and SecAI+: Specialist Routes That Come After Security+
Both are good second or third certifications and poor second ones straight after CC.
CySA+ (CS0-004) launched on 23 June 2026. It has a maximum of 85 questions in 165 minutes and needs 750 on a scale of 100 to 900. CompTIA recommends about four years in a SOC or vulnerability analyst role. The exam expects you to read logs, triage alerts and prioritise vulnerabilities, none of which CC tests. See the CySA+ CS0-004 study plan and the CySA+ course.
SecAI+ (CY0-001) is CompTIA's AI security certification, with a maximum of 60 questions in 60 minutes and a pass mark of 600 on a scale of 100 to 900. CompTIA recommends three to four years in IT, two or more of them in hands-on cybersecurity, and names Security+, CySA+ or PenTest+ as the expected background. A CC holder who is interested in AI security should treat SecAI+ as a target for a year or two out. CompTIA SecAI+ explained sets out the four domains, and the SecAI+ course is there when you are ready.
CISSP: Where CC Is Pointing, Not Where to Go Next
ISC2 describes CC as a way to become familiar with the exam formats of advanced certifications such as CISSP. That is accurate. The CC exam's adaptive format and question style resemble CISSP's, just at a much lower depth.
CISSP requires five years of cumulative, full-time experience in two or more of its eight domains. A degree or an approved credential can cover one of those years. If you pass without the experience, you become an Associate of ISC2 and have six years to earn the five.
Sitting CISSP straight after CC is possible and rarely sensible. The exam fee is US $749, the content assumes management-level judgement, and an Associate title with no job to match does little on a CV. The practical sequence for most CC holders is:
- CC (done).
- Security+ or SSCP, depending on whether you already work in IT.
- Two to four years in a security role, adding CySA+ or a cloud or vendor certification that matches the job.
- CISSP once you have four years logged. Security+ covers the fifth.
The CISSP worth-it analysis covers salary and ROI, and the CISSP course is the place to start once you are within reach of the experience requirement.
Frequently Asked Questions
What certification should I get after ISC2 CC?
For most people it is CompTIA Security+, because it needs no experience, appears on more job adverts and counts toward the CISSP experience waiver. If you already work in IT with a year of security duties, ISC2 SSCP is the cheaper alternative at US $249.
Is CC from ISC2 worth it?
It is worth it as a structured first step if you have no security background, since it costs US $199 and needs no experience. It is not enough on its own to get most security jobs, which is why the next certification matters. The free exam through ISC2's One Million Certified in Cybersecurity programme closed to new enrolments on 20 May 2026.
How long does ISC2 CC certification last?
CC runs on a three-year cycle. To keep it you need 45 CPE credits across the three years and must pay the US $50 Annual Maintenance Fee each year.
Does ISC2 CC count toward CISSP experience?
No. ISC2's list of approved credentials that satisfy one year of CISSP experience includes CompTIA Security+ and CySA+, but not CC.
Ready to Start Practising?
If you are going for Security+ next, start with the domains that overlap least with CC: threats and vulnerabilities, and security architecture. Keep your CC knowledge current in the ISC2 CC course until you have logged your CPEs, and use the cybersecurity certification roadmap for the longer view.
Create a free CertCrush account and take your first Security+ or SSCP practice quiz today.
