How to Earn CISSP CPE Credits: 40+ Ideas Organized by Category

  •   min.
  • Updated on: July 25, 2026

    • Expert review
    • Home
    • /
    • Resources
    • /
    • How to Earn CISSP CPE Credits: 40+ Ideas Organized by Category

    Most CISSP holders know that courses and conferences count toward CPE credits. Fewer realize that writing an article, mentoring a junior colleague, contributing to an open-source security project, or completing a vendor webinar also qualifies. The range of activities ISC2 recognizes is significantly broader than most professionals use, which means many people earn credits the hard way when easier, more relevant options are right in front of them.

    This guide maps out 40+ CISSP CPE ideas across every major category so you can find activities that fit your schedule, your budget, and the work you are already doing. If you want a broader view of the full CISSP renewal requirements before going further, that resource addresses every aspect of the maintenance cycle.

    Think of what follows as a standing resource. The 40+ ideas here are not just for this cycle. They are a reference you can return to at any point in your career when you need to identify what comes next. 

    How CISSP CPE Credits Work

    The CISSP requires 120 CPE credits over a three-year certification cycle, with ISC2 recommending approximately 40 credits per year to stay on track. Of those 120 credits, 90 must be Group A and 30 may be Group B.

    Group A credits come from activities directly related to the eight CISSP domains: anything that builds or reinforces your cybersecurity knowledge, from attending a security conference to publishing a research article. Group B credits come from activities that develop general professional skills rather than domain-specific security knowledge, such as leadership training, project management, or public speaking courses.

    The general rule that ISC2 applies is that one hour of activity equals one CPE credit. Some activities produce credits above that rate due to their depth or ongoing commitment. Regular job duties do not qualify, and no single activity can earn more than 40 credits toward your total. Activities are submitted through the ISC2 CPE portal, where you categorize each entry, select the relevant domain for Group A submissions, and upload supporting documentation.

    For a complete walkthrough of how to track and submit credits efficiently, the CISSP CPE maintenance guide goes into full detail on the portal process and documentation requirements.

    Group A CPE Ideas: Domain-Specific Activities

    Group A is where most of your 120 credits will come from. The activities below all relate directly to the CISSP domains and qualify for Group A submission.

    Formal Training and Courses

    Structured learning is one of the most reliable ways to earn Group A credits in volume. Each hour of instruction counts as one credit, and multi-day courses can produce a substantial portion of your annual requirement in a single commitment.

    1. Complete a CISSP domain-focused online course through an accredited provider
    2. Attend a live cybersecurity training course or workshop
    3. Complete ISC2 Express Courses through your member account
    4. Pursue an ISC2 Certificate in a specialized area such as cloud security, zero trust, or AI security
    5. Complete vendor-specific security training from providers like SANS, Coursera, or Pluralsight
    6. Enroll in a university or college course covering a security-related subject
    7. Complete a structured certification prep course for a complementary credential such as CCSP, CISM, or Security+

    Reading, Research, and Self-Study

    Reading qualifies for Group A credits when the material is directly related to CISSP domains. One hour of reading equals one credit, and this category is one of the easiest to accumulate without spending money.

    1. Read cybersecurity whitepapers from NIST, CISA, or major security vendors
    2. Read peer-reviewed security research journals
    3. Study ISC2's annual Cybersecurity Workforce Study or similar industry reports
    4. Read security-focused books aligned to CISSP domains
    5. Review security advisories and threat intelligence reports from sources like US-CERT or MITRE ATT&CK
    6. Read professional publications such as Dark Reading, CSO Online, or Infosecurity Magazine

    Webinars and Online Events

    Webinars are one of the most accessible CPE sources available, and many are free. Each hour of attendance qualifies as one Group A credit.

    1. Attend ISC2 webinars through your member portal
    2. Watch recorded security webinars from vendors such as Palo Alto, CrowdStrike, or Tenable
    3. Attend free webinars hosted by CISA, NIST, or ISACA
    4. Participate in live threat intelligence briefings or security research presentations
    5. Attend online summits and virtual security conferences

    Conferences and Industry Events

    In-person or virtual conferences are among the highest-yield CPE activities available. A two-day conference can produce 12 to 16 credits depending on session attendance, and the networking and knowledge value typically justify the investment.

    1. Attend ISC2 Security Congress
    2. Attend RSA Conference, Black Hat, or DEF CON
    3. Participate in regional cybersecurity conferences and chapter events
    4. Attend ISACA conferences, such as the GRC Conference or regional chapter events
    5. Participate in sector-specific security summits relevant to your industry

    Teaching, Presenting, and Mentoring

    Preparing and delivering security content earns credits at a higher rate than passive learning. ISC2 recognizes the additional effort involved in creating educational material, and preparation time may also qualify separately from the delivery itself.

    1. Deliver a security presentation at a conference, company event, or professional association
    2. Teach a cybersecurity course or workshop as an instructor
    3. Mentor a junior security professional or associate member of ISC2
    4. Lead an internal security awareness training session for your organization
    5. Create and publish an online security course or tutorial

    Professional Contributions and Volunteering

    Contributing to the security profession beyond your regular job duties qualifies for Group A credits and often produces some of the most meaningful learning experiences.

    1. Author an article, blog post, or whitepaper on a security topic
    2. Contribute to or peer-review security publications or research
    3. Volunteer with ISC2's charitable foundation or chapter activities
    4. Participate in bug bounty programs or responsible disclosure initiatives
    5. Contribute to open-source security tools or projects
    6. Serve on a security advisory board, working group, or standards committee
    7. Participate in ISC2 Job Task Analysis surveys

    Group B CPE Ideas: Professional Development Activities

    Group B credits build the professional skills that make you more effective as a security leader, even when the content is not directly tied to CISSP domains. You can earn up to 30 Group B credits toward your 120-credit total.

    • Complete a project management course or PMP certification training
    • Attend a leadership or executive development program
    • Complete a public speaking or professional communication course
    • Take a business writing or technical writing workshop
    • Attend a management or organizational behavior seminar
    • Complete training in data analysis, financial literacy, or business strategy
    • Study a foreign language relevant to your professional environment
    • Participate in general professional development webinars not tied to security domains
    • Complete a course in ethics or professional responsibility
    • Attend a cross-functional industry event focused on business rather than security

    Any professional development activity that builds skills applicable to your role in a security organization qualifies, provided it falls outside the direct scope of the CISSP domains.

    Looking for some exam prep guidance and mentoring?


    Learn about our personal mentoring

    Image of Lou Hablas mentor - Destination Certification

    Free CISSP CPE Ideas

    Budget should not be a barrier to meeting your CPE requirements. A significant portion of your annual 40 credits can come from free sources without compromising quality. Not every idea here will suit your role or schedule. Pick the ones that align with where you are in your career and build from there.
     

    • ISC2 member webinars available through your member portal at no additional cost
    • CISA free training catalog, including courses on critical infrastructure security, incident response, and risk management
    • NIST publications, special publications, and cybersecurity framework guidance documents
    • MITRE ATT&CK framework documentation and threat intelligence research
    • Dark Reading, CSO Online, and Infosecurity Magazine articles and feature reports
    • ISC2 community forums and chapter event participation
    • Free vendor webinars from major security providers
    • YouTube security research presentations from DEF CON and Black Hat were published after the event
    • Open courseware from universities such as MIT OpenCourseWare covering relevant security topics

    If you want a concrete, free Group A CPE activity you can start immediately, the free Cryptography Mini MasterClass from Destination Certification builds foundational cryptographic knowledge that maps directly to Domain 3 of the CISSP. It is free, self-paced, and directly relevant to one of the most consistently tested concept areas across the exam and beyond.

    Fast Ways to Earn CISSP CPE Credits

    If you are behind on your annual target or entering the final year of your cycle with a gap to close, certain activity types produce the highest credit yield per unit of time invested.

    • Multi-day conferences: A three-day conference with full session attendance can produce 18 to 24 credits in a single commitment. ISC2 Security Congress, RSA Conference, and Black Hat all qualify.
    • Structured online courses: A 20-hour security course earns 20 Group A credits. Platforms like SANS OnDemand and Coursera offer security courses in this range that you can complete on your own schedule.
    • ISC2 Certificates: These multi-course learning pathways are designed to build deep expertise in a focused area and typically produce 15 to 40 credits, depending on the certificate. ISC2 submits these credits to your account automatically.
    • Authoring content: Writing a security article or whitepaper earns credits for preparation time plus publication. A substantive published piece can qualify for up to 40 credits depending on depth and ISC2's assessment of the contribution.
    • Teaching a course: Instructors earn credits for preparation time in addition to delivery time. If you teach a security course or deliver a multi-session internal training program, the total credit count can be substantial.

    How to Track and Submit Your CPE Activities

    Consistent documentation prevents end-of-cycle scrambles and protects you if ISC2 audits your submission. According to ISC2's guidance on managing CPE credits, activities submitted directly through ISC2 programs are logged automatically, while all other activities require manual submission through the CPE portal at cpe.isc2.org.

    Follow these steps to keep your CPE record clean:

    1. Log each activity as soon as it is complete rather than batching submissions at the end of the year.
    2. Retain documentation for every activity: certificates of completion, conference registration confirmations, webinar attendance records, or copies of published articles.
    3. When submitting Group A activities, select the relevant CISSP domain from the portal dropdown. Leaving this field blank holds the entry in draft status and prevents the credit from posting.
    4. Report time in quarter-hour increments (0.25, 0.50, 0.75) where applicable.
    5. If an activity spans multiple days, use the end date to determine which certification cycle receives the credits.
    6. Check your CPE dashboard regularly to confirm credits are posting correctly and to monitor your Group A and Group B balances separately.

    ISC2 audits a percentage of CPE submissions. Professionals who document activities thoroughly and submit promptly move through any audit review without disruption.

    Certification in 3 Days 


    Study everything you need to know for the AAISM exam in a 3-day bootcamp!

    Frequently Asked Questions 

    Does my regular job count toward CISSP CPE credits?

    No. Standard on-the-job activities that form part of your normal employment do not qualify for CPE credits. CPE is intended to reflect learning and professional development beyond your existing responsibilities. Special projects, new skills you develop outside your core role, or activities where you take on an educational or contributory function may qualify depending on the specifics.

    Can I use the same CPE activity for both CISSP and CCSP requirements?

    Yes. ISC2 allows the same activity to count toward multiple certifications simultaneously, provided the content is relevant to each credential's domains. A cloud security course, for example, can qualify as Group A for both CISSP and CCSP in the same submission.

    How many credits can a single activity earn?

    The standard rate is one credit per hour of activity. However, no single activity can earn more than 40 credits regardless of time invested. Some activity types, particularly authoring and teaching, may be valued above the standard hourly rate depending on the depth of contribution.

    Do vendor training courses and webinars qualify for CISSP CPE?

    Yes, provided the content is relevant to at least one of the eight CISSP domains. Vendor-delivered training on topics such as network security, identity management, cloud security, or incident response qualifies as Group A. Purely promotional content without educational substance does not qualify.

    What happens if I fall short of my CPE requirement at the end of my cycle?

    ISC2 provides a 90-day grace period after your cycle ends. If you complete the outstanding credits within that window and submit them before the grace period expires, your certification remains active. If you do not, your CISSP moves to suspended status and eventually to revocation if the gap is not resolved.

    120 Credits. Three Years. Make Every One Count with Destination Certification

    The 120 CPE credits ISC2 requires over three years are achievable for any active security professional. The difference between those who meet requirements comfortably and those who scramble at renewal is not the number of credits. It is whether they treat continuing education as something they plan for or something they react to.

    If you want structured, high-quality Group A CPE that builds real skills alongside your credits, the CISSP Bootcamp at Destination Certification runs Monday through Friday with ten hours of live instruction per day from Rob Witcher, John Berti, Kelly Handerhan, and Nick Mitropoulos. It is a substantial CPE activity in its own right and includes full access to the CISSP MasterClass for ongoing review.

    If your schedule calls for something more flexible, the CISSP MasterClass delivers the same expert instruction in a self-paced format, with an adaptive learning system that identifies your knowledge gaps and adjusts your study plan around your schedule. Every hour you spend in the MasterClass qualifies as Group A CPE time.

    Start with the free CISSP MindMaps from Destination Certification if you want an immediate, no-cost way to reinforce domain knowledge and log reading and self-study credits at the same time. Thirty visual mindmap videos across all eight domains, plus downloadable audio files and a printable PDF, qualify as Group A self-study time under ISC2's CPE framework.

    CPE credits are proof that your CISSP still reflects who you are as a security professional. Destination Certification helps you earn them the right way.

    Image of Rob Witcher - Destination Certification

    Rob is the driving force behind the success of the Destination Certification CISSP program, leveraging over 15 years of security, privacy, and cloud assurance expertise. As a seasoned leader, he has guided numerous companies through high-profile security breaches and managed the development of multi-year security strategies. With a passion for education, Rob has delivered hundreds of globally acclaimed CCSP, CISSP, and ISACA classes, combining entertaining delivery with profound insights for exam success. You can reach out to Rob on LinkedIn.

    Free Class:
    Crack Cryptography for the CISSP Exam

    A free 3-part class that makes one of the CISSP's hardest topics click.

    • Why cryptography questions confuse even experienced security professionals on exam day
    • How symmetric and asymmetric encryption actually differ the way the CISSP tests it
    • What digital signatures are really doing and why the exam frames questions around them the way it does
    • A practice test at the end so you leave knowing exactly where your understanding holds up

    The easiest way to get your CISSP Certification 


    Learn about our CISSP MasterClass

    Image of masterclass video - Destination Certification