The CISSP validates that you can lead a security program across all eight domains of the common body of knowledge. What it does not validate is deep specialization in architecture, engineering, or management. That is what the three ISC2 advanced certifications are for.
ISSAP is built for security architects. ISSEP is built for systems security engineers. ISSMP is built for security program managers and executives.
Each one demands specialized experience beyond the CISSP and an exam that probes a level of depth the CISSP itself does not reach. For professionals whose careers have moved into one of those three lanes, these credentials signal something specific and credible to employers and clients.
What makes this a particularly relevant moment to understand these certifications is that ISC2 updated the exam outlines for all three in August 2025. The changes were significant. ISSAP consolidated from six domains to four, with a substantially different emphasis on infrastructure security and identity management. ISSEP added project management and international standards content that diverged noticeably from previous study materials.
ISSMP restructured its domain weights to reflect the current realities of security leadership in complex organizations. If you have been considering any of these credentials, those changes matter for how you approach preparation. If you are new to the concept, this guide gives you everything you need to understand what they are, what each one assesses, and whether any of them belong on your certification roadmap.
Think of what follows as a practical reference for CISSP holders and senior security professionals evaluating where to take their credentials next. Before getting into each certification individually, it helps to understand what all three share in terms of structure, requirements, and standing within the ISC2 ecosystem.
What the CISSP Concentrations Actually Are
ISSAP, ISSEP, and ISSMP sit at the top of the ISC2 credential hierarchy. They are the most advanced certifications ISC2 offers, and they were originally designed as CISSP specializations, meaning you had to hold the CISSP before pursuing any of them. That changed in October 2023. As confirmed in ISC2's advanced certifications update, all three are now standalone credentials. You can pursue ISSAP, ISSEP, or ISSMP without holding the CISSP first, provided you meet the higher experience threshold that applies to non-CISSP holders.
In practice, the vast majority of people who pursue these credentials are CISSP holders. The CISSP reduces the experience requirement significantly and provides the foundational security knowledge each concentration builds on. Professionals who hold CISSP and are considering what comes next will find these credentials the most direct way to signal deep specialization to employers.
All three share the same exam structure: 125 questions, three hours, a passing score of 700 out of 1,000, and an exam fee of $599. All three require CPE maintenance as part of the ISC2 Annual Maintenance Fee framework. And all three had their exam outlines updated effective August 1, 2025, based on ISC2's triennial Job Task Analysis process, which surveys working professionals to ensure the exams reflect what practitioners actually do in their specialized roles today.
For CISSP holders evaluating which direction to pursue, the CISSP career opportunities guide provides useful context on how the concentrations fit into the broader range of post-CISSP options available.
ISSAP: Information Systems Security Architecture Professional
ISSAP is the credential for security architects. If your role involves designing security solutions, translating organizational risk into architectural decisions, and providing management with guidance on how security systems should be structured to meet business objectives, ISSAP is built for that work.
The August 2025 update consolidated ISSAP from six domains down to four, with a notable shift in emphasis toward infrastructure security and identity management. According to the updated ISSAP exam outline, the four current domains are:
- Governance, Risk, and Compliance (21%)
- Security Architecture Modeling (22%)
- Infrastructure and System Security Architecture (32%)
- Identity and Access Management Architecture (25%)
The consolidation reflects how the architect role has evolved. Security architects today spend significantly more time governing infrastructure security decisions and managing identity at scale than they do on isolated application security or operations architecture in separate silos. The updated exam aligns with that reality.
The roles ISSAP targets include Chief Security Architect, Security Solutions Architect, Senior Security Analyst with an architecture focus, and consulting roles where security architecture guidance is the primary deliverable. CSO Online's security architect job description guide confirms ISSAP alongside CISSP as one of the recognized credentials for senior architecture roles, noting that at least CISSP is typically required, and ISSAP adds specialized architecture credibility on top of that foundation.
ISSAP produces its strongest value for professionals in consulting, large enterprise environments, or government roles where architecture decisions carry significant organizational and regulatory weight. For security architects whose day-to-day work is building and governing security frameworks rather than implementing controls, ISSAP validates that specialization in a way the CISSP alone does not.
ISSEP: Information Systems Security Engineering Professional
ISSEP is the credential for systems security engineers, and it carries a distinction that separates it from the other two concentrations: it was co-developed with the United States National Security Agency. That partnership reflects the credential's original focus on engineering security into complex government and defense systems, and it remains the concentration most valued in DoD and federal contracting environments.
The August 2025 update restructured ISSEP around five domains, with notable additions in project management and international standards content that expanded the exam's scope beyond what previous study materials emphasized. The five current domains are:
- Systems Security Engineering Foundations (25%)
- Risk Management (14%)
- Security Planning and Design (30%)
- Systems Implementation, Verification, and Validation (14%)
- Secure Operations, Change Management, and Disposal (17%)
The heaviest weighting falls on Security Planning and Design, which reflects the core of what a systems security engineer does: building security into projects, applications, and information systems from the design phase rather than retrofitting it afterward. The risk management domain reinforces this with an emphasis on how engineering decisions are evaluated against organizational and mission risk.
The roles ISSEP targets include Senior Systems Security Engineer, Information Assurance Engineer, Information Assurance Officer, Security Systems Engineer, and senior technical roles in government agencies and defense contractors. In the DoD and federal space, ISSEP carries recognition that goes beyond a career differentiator. For certain roles and clearance levels, it satisfies specific DoD 8140 requirements that make it a practical requirement rather than an optional credential.
For engineers in commercial environments, ISSEP is less commonly recognized than in government contexts. The credential produces its strongest ROI for professionals whose work involves engineering security into large-scale systems, particularly in regulated or mission-critical environments where the rigor of the NSA-developed framework carries institutional weight.
ISSMP: Information Systems Security Management Professional
ISSMP is the credential for security program leaders, executives, and CISOs. Where ISSAP and ISSEP validate technical specialization in architecture and engineering, ISSMP validates the management and leadership competencies that running a security program at an organizational level requires.
The August 2025 update restructured ISSMP around six domains that reflect the full scope of what senior security leaders are accountable for. The six current domains are:
- Leadership and Organizational Management (21%)
- Systems Lifecycle Management (15%)=
- Risk Management (20%)
- Security Operations (18%)
- Contingency Management (12%)
- Law, Ethics, and Security Compliance Management (14%)
The domain structure reflects the reality of senior security leadership: budget management, organizational governance, business continuity, legal and regulatory compliance, and the operational oversight of security programs that span complex, multi-unit organizations. The weighting toward leadership and risk management reinforces that ISSMP tests how you govern and direct a program, not how you implement individual controls.
The roles ISSMP targets include CISO, Chief Information Officer, Chief Technology Officer, Security Program Director, and senior security executives responsible for organizational strategy rather than day-to-day technical operations.
For professionals on the CISO track who want a credential that specifically validates security management depth, ISSMP is one of the options worth evaluating alongside CISM. The CISSP vs CISM comparison addresses how those two credentials position differently for management-focused careers, which provides useful context for evaluating where ISSMP fits relative to both.
Looking for some exam prep guidance and mentoring?
Learn about our personal mentoring

Experience Requirements and Exam Details
The experience and exam requirements are consistent across all three credentials, with one important variable: whether you hold an active CISSP.
With a CISSP in good standing:
- Two years of cumulative, full-time experience in one or more of the target certification's domains
- Exam: 125 questions, three hours, passing score of 700 out of 1,000
- Exam fee: $599
- CPE: 60 credits over three years, all related to the relevant specialization domain, covered under the existing ISC2 AMF
Without a CISSP:
- Seven years of cumulative, full-time experience in two or more of the target certification's domains
- One year may be substituted with a qualifying four-year degree or an ISC2-approved credential
- Exam structure, fee, and passing score are the same
- AMF: $135 per year if ISSAP, ISSEP, or ISSMP is your first or only ISC2 certification
For CISSP holders, the two-year experience requirement is the practical threshold. Most professionals who are seriously considering a concentration already have that experience accumulated in their specialization. The question is rarely whether they qualify. It is whether the credential produces enough return in their specific career context to justify the preparation investment.
If you are still working toward your CISSP and want a strong foundation before considering which concentration fits your direction, the free CISSP MindMaps from Destination Certification give you 30 visual mindmap videos across all eight domains, downloadable audio files, and a printable PDF to reinforce domain knowledge efficiently.
How to Decide Which Concentration Is Right for You
Most CISSP holders who pursue a concentration do so because their role has specialized deeply enough that the CISSP alone no longer fully reflects what they do or what they can offer. Use the scenarios below to identify which credential aligns with your current trajectory:
- Pursue ISSAP if your role centers on designing security architectures, translating business and risk requirements into security solutions, and advising management on how security systems should be structured. If your title includes architect or if most of your work involves security design rather than implementation or governance, ISSAP validates that specialization directly.
- Pursue ISSEP if your role involves engineering security into systems from the ground up, particularly in government, defense contracting, or mission-critical infrastructure environments. If your work requires you to satisfy DoD 8140 requirements or if you spend significant time on security planning and design for complex technical systems, ISSEP is the credential built for that work.
- Pursue ISSMP if you are in or moving toward a CISO, security director, or senior security executive role where your primary accountability is governing a security program rather than building or architecting its components. If your work involves budget management, organizational governance, regulatory compliance strategy, and security leadership at the program level, ISSMP validates that management depth.
- Hold off on all three if your CISSP is recent and you have not yet accumulated two years of experience in a specialized domain. The concentrations produce their strongest value when your experience genuinely matches the domain depth they assess. Pursuing one before that alignment exists produces a weaker ROI than deepening the specialized experience first.
Certification in 1 Week
Study everything you need to know for the CISSP exam in a 1-week bootcamp!
Frequently Asked Questions
Yes. ISC2 allows professionals to hold multiple advanced certifications simultaneously under the same account. The AMF covers all credentials under a single annual payment, so adding a second concentration does not increase your maintenance cost if you already pay the $135 AMF.
Holding a concentration does not change your CISSP CPE requirements. You still need 120 CPE credits over three years for the CISSP. The concentration adds 60 CPE credits specific to its domain area, but these credits are managed under the same ISC2 account and AMF payment. Many CPE activities that qualify for the CISSP also qualify for the concentration, which reduces the incremental effort involved in maintaining both.
They serve overlapping but distinct audiences. CISM is an ISACA credential that is widely recognized in management and governance roles across industries. ISSMP is an ISC2 credential that builds on the CISSP foundation and focuses specifically on security program management at a senior level. For professionals who already hold CISSP, ISSMP is a natural extension within the same ISC2 ecosystem. For professionals without a CISSP who want a management credential, CISM is often the more accessible and broadly recognized option.
Recognition varies significantly by sector. ISSEP is the most recognized in government and DoD contracting environments, where it satisfies specific DoD 8140 requirements. ISSAP carries recognition in senior architecture roles, particularly in large enterprises and consulting. ISSMP has some recognition in CISO-track roles but is less universally required than CISM in most commercial markets. None of the three carries the same broad employer recognition as the CISSP itself, which is why they function best as specialization signals for professionals already established at the senior level.
Choose the CISSP Concentration That Works Best for Your Career with Destination Certification
ISSAP, ISSEP, and ISSMP each address a different dimension of senior security expertise. ISSAP validates the depth of a security architect. ISSEP validates the rigor of a systems security engineer. ISSMP validates the leadership capability of a security program executive. Choosing the right one depends on where your career has already specialized and where you are heading next. But every path to a concentration runs through the same foundation: a solid, well-prepared CISSP.
If you want the most structured and intensive path to passing the CISSP before pursuing a concentration, the CISSP Bootcamp at Destination Certification delivers ten hours of live instruction per day, Monday through Friday, from Rob Witcher, John Berti, Kelly Handerhan, and Nick Mitropoulos, with full access to the CISSP MasterClass and all study materials included.
If your schedule calls for flexibility, the CISSP MasterClass adapts to your knowledge gaps and study calendar so you can build the foundation the concentrations demand on your own timeline without sacrificing depth or accountability.
Start with the free Cryptography Mini MasterClass from Destination Certification if you want an immediate, no-cost way to sharpen one of the most consistently tested concept areas across both the CISSP and the concentrations that follow it.
Architecture, engineering, or management. The path splits at the top. Make sure the foundation underneath it is solid. Destination Certification builds that foundation.
John is a major force behind the Destination Certification CISSP program's success, with over 25 years of global cybersecurity experience. He simplifies complex topics, and he utilizes innovative teaching methods that contribute to the program's industry-high exam success rates. As a leading Information Security professional in Canada, John co-authored a bestselling CISSP exam preparation guide and helped develop official CISSP curriculum materials. You can reach out to John on LinkedIn.










