Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Careers

CPE Requirements by Certification Body: A Complete Comparison

M
Mark Sabo Training Camp
Published
Read Time 12 min read
CPE Requirements by Certification Body: A Complete Comparison

Every major certification body requires continuing education credits and an annual payment to keep a credential active. Almost everything else differs. ISC2 asks for 120 CPE credits across three years and a $135 fee. ISACA also asks for 120 hours across three years, except it enforces a hard 20 hour floor every year and runs on the calendar rather than your exam date. Microsoft charges nothing and asks for no credits at all, but expires your certification after twelve months. IAPP works on a two year cycle. CompTIA offers no grace period whatsoever.

Candidates who hold credentials from more than one body end up managing several incompatible calendars at once, and the failures almost never come from a shortage of learning hours. They come from misreading which clock applies to which credential. What follows is every maintenance requirement in one place, drawn from each body’s published policy.

The credit totals are the part people study. The cycle start dates are the part that costs them the certification.


How Many CPE Credits Do You Need for Each Certification?

The table below covers the bodies behind most security and IT credentials. Read the annual minimum column carefully, because that is where the two largest security certifications part ways. ISC2 recommends roughly 40 credits a year without mandating it. ISACA requires 20 hours every year as a separate condition on top of the three year total, so banking all 120 hours in year three fails the requirement even though the arithmetic works.

Certification Cycle Credits per cycle Annual minimum Maintenance fee Clock starts
ISC2 CISSP, CCSP, SSCP, CGRC, CSSLP 3 years 120 CPE, at least 90 from Group A 40 recommended, not mandated $135 per year Your certification anniversary
ISC2 CC 3 years 45 CPE 15 recommended $50 per year Your certification anniversary
ISACA CISA, CISM, CRISC, CGEIT 3 years 120 CPE hours 20 hours, required $45 member, $85 non member, per year January 1, calendar year
ISACA AAISM 3 years 30 CPE hours 10 hours, required $20 member, $35 non member, per year January 1, calendar year
CompTIA A+ 3 years 20 CEU None $75 per cycle The date you passed
CompTIA Network+ 3 years 30 CEU None $150 per cycle The date you passed
CompTIA Security+, Cloud+ 3 years 50 CEU None $150 per cycle The date you passed
CompTIA CySA+, PenTest+ 3 years 60 CEU None $150 per cycle The date you passed
CompTIA SecurityX 3 years 75 CEU None $150 per cycle The date you passed
IAPP CIPP, CIPM, CIPT, AIGP 2 years 20 CPE per certification None $250 per 2 year term, covers all IAPP certifications, waived with membership Your term start, credentials align
PECB ISO lead credentials 3 years CPD hours vary by credential level Annual reporting required $120 per year Your certification anniversary
Microsoft role based, associate and expert 1 year None, free online assessment instead Not applicable $0 Window opens 6 months before expiry
Cisco associate level including CCNA 3 years 30 CE credits, or retake the exam None $0 The date you passed

The CompTIA fee works differently from the others and gets described wrongly almost everywhere. CompTIA states that CE fees are not required annually. They are owed only if you renew by uploading CEUs, and they must be paid by the expiration date. Renew instead by passing a higher CompTIA certification or by completing a CertMaster CE course and the fee disappears entirely.

One detail worth pulling out of the ISC2 row. Of the 120 credits, at least 90 have to come from Group A activity tied directly to the domains of the credential you hold. Group B covers general professional development that sits outside those domains. Reaching 120 total credits while falling short of 90 in Group A leaves you out of compliance despite hitting the headline number.


Which Renewal Clocks Start on Your Exam Date and Which Start January 1?

This distinction causes more lapsed credentials than any credit shortfall. ISC2, CompTIA, PECB, and Cisco all run anniversary cycles keyed to the day you certified. ISACA runs on the calendar. Your ISACA reporting period opens January 1 and closes December 31 regardless of when you sat the exam, and the maintenance fee is due by January 1 for the year ahead.

Consider someone who passes the CISM in September. Their first full ISACA reporting year begins the following January, and from that January forward they owe 20 hours annually. A candidate who assumes the cycle tracks their exam date has already misjudged the deadline by four months. Anyone holding both a CISA and a CISM reports against a single calendar year for both, which at least keeps the ISACA side of the ledger simple.

Microsoft operates on a different model entirely. Role based associate, expert, and specialty certifications expire twelve months after you earn them, and the renewal window opens only six months before that date. Taking the assessment early is impossible. The assessment itself is free, unproctored, open book, and shorter than the original exam, but missing the window means sitting the full paid exam again. Fundamentals credentials including AZ-900, AI-900, and DP-900 carry no expiration and require nothing.

The practical consequence. A working professional holding a CISSP, a Security+, a CISM, and an AZ-104 is tracking four separate deadlines governed by four different rules. Three anniversary dates and one calendar year, one of which recurs every twelve months rather than every thirty six. No single reminder date covers all of them.


Do CPE Credits Count Toward More Than One Certification?

Within a single body, usually yes, and this changes the arithmetic considerably for anyone stacking credentials.

ISC2 applies credits added to your account across every certification you hold that is inside an active cycle, so a CISSP and CCSP holder does not earn two separate sets of 120. ISACA permits the same hours to satisfy multiple certifications when the activity relates directly to each job practice,. IAPP goes furthest here, stating outright that a single qualifying activity can count toward several credentials and that holders of multiple certifications rarely need 20 unique credits for each one. Its $250 maintenance fee also covers every active IAPP certification you hold rather than being charged per credential. One IAPP webinar can move the needle on a CIPP, a CIPM, and an AIGP simultaneously.

Across bodies there is no such reciprocity. Hours you report to ISACA do not appear in your ISC2 record, and nothing transfers automatically. Every submission happens separately in each portal. The learning overlaps, the paperwork does not.

CompTIA handles multi credential holders through a different mechanism called the certification hierarchy, sometimes described as the renewal pyramid. Passing a higher level CompTIA exam renews the qualifying certifications beneath it. Pass SecurityX and it renews Security+, Network+, and A+ underneath it with fees waived. A Security+ pass does the same for A+ and Network+. For candidates early in a stack this converts renewal from an administrative chore into progress, which is why passing the next exam often beats grinding out CEUs. Certifications outside that hierarchy, including Server+, Project+, Data+, and DataSys+, still renew on their own.


What Happens If You Miss the Deadline?

The consequences vary far more than most candidates expect, and the range runs from a generous grace window to immediate loss.

What Lapsing Costs You, by Body
ISC2

A 90 day grace period after expiration for both credits and the maintenance fee. Credits earned during that window still count. Beyond it, status moves to suspended and eventually revoked, at which point the exam is the only way back.

ISACA

Failure to comply results in revocation of the designation, and because ISACA owns the certificate, a revoked certificate must be destroyed. A reinstatement process exists with an additional fee, but the window is finite.

COMPTIA

No grace period. The certification expires on its date and the only recovery is passing the current version of the exam, which for Security+ means whichever objectives are live at that moment rather than the ones you originally studied.

PECB

Missing CPD or the maintenance fee downgrades the credential rather than removing it, so a Lead Auditor can drop to a lower tier. Two schemes are exceptions and get revoked outright, the ISO/IEC 27005 Risk Manager and Lead Risk Manager and the CNIL credential. Master certifications are also revoked rather than downgraded.

MICROSOFT

The certification drops off your profile at expiration with no grace period and no alternative path. Passing a different exam or retaking the original proctored exam early does not renew it. Only the renewal assessment does.

PECB stands alone in that list for a reason worth understanding. Downgrade rather than revocation means an ISO/IEC 27001 Lead Auditor who neglects maintenance keeps a credential, just a weaker one, and the drop may go unnoticed until a client or employer checks the registry. The two revocation exceptions matter because 27005 risk credentials are frequently held alongside 27001 audit credentials, and the two behave differently under identical neglect.


What Does It Actually Cost to Keep a Certification Active?

Over a full three year cycle, a CISSP costs $405 in maintenance fees. An ISACA certification costs $135 for members or $255 for non members, and ISACA membership dues sit on top of that. Security+ costs $150. A+ costs $75. PECB costs $360. Microsoft costs nothing. IAPP costs $250 per two year term unless membership covers it, which is why most privacy professionals hold membership rather than paying the fee directly.

The credits themselves can cost nothing. Vendor webinars, chapter meetings, conference sessions, reading, and teaching all qualify at roughly one credit per hour across most schemes, and each body runs free programming that auto submits to your record. Anyone budgeting for a first credential should treat maintenance as a recurring line separate from the upfront exam and training spend, because the second cycle arrives with no reminder that the first one was ever paid for.


Building a Maintenance System That Survives a Busy Year

Record every deadline in one place with its governing rule attached, since the date alone is insufficient when the rules differ. Note whether each credential runs on an anniversary or the calendar, whether it carries an annual floor, and what the fee is. That single document does more work than any reminder app.

Submit credits as you earn them rather than batching at cycle end. Reconstructing two years of activity under deadline pressure produces exactly the thin documentation that fails an audit, and every body here audits a sample of submissions. Keep the certificate of completion, the agenda, or the confirmation email at the moment you finish something. Bodies that let you claim credit on the honor system still ask for evidence when your name comes up, and a credit you cannot document is a credit you did not earn. For anyone holding a single ISC2 credential and wondering where the mechanics sit relative to the exam itself, the step by step CISSP renewal process covers the portal side in detail.

Where a hierarchy exists, use it. A CompTIA holder who is planning to move from Security+ toward CySA+ or SecurityX anyway should time that exam to land inside the renewal window and clear the whole stack at once. The same logic applies to anyone weighing whether to add a credential above their current one, since the maintenance saved is real money and real hours.

🎯 The Short Version

Three years and 120 credits is the pattern for ISC2 and ISACA, but ISACA enforces a 20 hour annual floor and starts its clock on January 1. CompTIA scales credits to the level of the certification and offers no grace period at all. IAPP runs two year terms. PECB downgrades instead of revoking, with two exceptions. Microsoft asks for a free assessment every twelve months inside a six month window. Verify your own dates in each portal rather than assuming the rules travel with you from one body to the next, because they do not.


Frequently Asked Questions About Certification Maintenance

How many CPE credits does the CISSP require?

The CISSP requires 120 CPE credits across a three year cycle, with at least 90 of those coming from Group A activities tied directly to the eight CISSP domains. ISC2 recommends roughly 40 credits per year to stay on pace, and charges a $135 annual maintenance fee alongside the credit requirement.

Can I earn all my ISACA CPE hours in the final year of the cycle?

No. ISACA requires a minimum of 20 CPE hours reported every year in addition to the 120 hour three year total, so hitting 120 hours entirely in year three fails the annual requirement even though the cumulative number is met.

Does CompTIA offer a grace period after a certification expires?

No. CompTIA certifications expire on their date with no grace period, and the only route back is passing the current version of the exam. This differs from ISC2, which allows a 90 day window after expiration to submit credits and pay the maintenance fee.

Do Microsoft certifications expire and does renewal cost anything?

Role based associate, expert, and specialty certifications expire after one year and renew through a free, unproctored, open book assessment on Microsoft Learn, available only in the six months before expiration. Fundamentals certifications including AZ-900, AI-900, and DP-900 do not expire and require no renewal.

Can the same CPE credit count toward two certifications?

Within one certification body, generally yes. ISC2 applies credits across all your active certifications automatically, ISACA permits shared hours where the activity relates to each job practice, and IAPP explicitly allows one activity to count toward multiple credentials. Credits do not transfer between different bodies, so hours reported to ISACA do nothing for an ISC2 cycle.

What happens if I let a PECB certification lapse?

Most PECB credentials are downgraded to a lower tier rather than revoked when CPD or the annual maintenance fee goes unmet. The exceptions are the ISO/IEC 27005 Risk Manager and Lead Risk Manager credentials and the CNIL credential, which are revoked, along with Master certifications.

Which certification bodies audit CPE submissions?

All of the major ones run audits on a sample of submissions, including ISC2, ISACA, CompTIA, and IAPP. Keep certificates of completion, conference agendas, or confirmation emails for every activity you claim, since a credit you cannot document will be removed and has to be replaced before the cycle closes.

Requirements and fees change. Confirm current figures against each body’s published policy: ISC2 member policies, ISACA certification maintenance, PECB maintenance policy, IAPP CPE policy, Microsoft certification renewal, and Cisco continuing education policies.

Mark Sabo

Director, Educational Services | Training Camp

Mark Sabo is the Director of Educational Services at Training Camp, where he oversees the training team, course design, and certification program development. He holds a B.S. in Information Sciences and Technology from Penn State University and more than 50 industry certifications. Mark joined Training Camp in 2005, became a Technical Trainer in 2007, and assumed his current leadership role in 2015. His specialty is practice exam development and exam preparation strategy, built from years of teaching students in the classroom and studying how certification exams are constructed. His writing focuses on the technical details that matter most to professionals preparing for high stakes exams.