Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Information Systems Security Architecture Professional (ISSAP)
Certification Explained.

ISSAP is ISC2's standalone security architecture certification, and there are two ways to qualify for it. Most candidates come through the CISSP: an active CISSP in good standing plus two years in the architecture domains. The other is seven years of cumulative experience and no CISSP at all. Both award the same certification. What separates them is upkeep, not standing, because holding ISSAP alongside a CISSP costs 60 CPE credits per three-year term instead of 140. This guide covers the four domains, the exam, both routes, and how CPEs work either way.

ISSAP_FAST_FACTS
Issuer: ISC2 (standalone certification)
Route 1: Active CISSP in good standing + 2 yrs
Route 2: 7 yrs experience, no CISSP
CPEs: 60 per term with a CISSP, 140 without
Exam: 125 questions, 3 hours
Passing Score: 700 / 1000
DoD 8140 Approved
4 ISSAP Domains 2 Qualifying Routes 125 Exam Questions 3-HOUR Fixed-Length Exam AUG 2025 Exam Outline
UPDATED 2026
Overview

What Is the Information Systems Security Architecture Professional (ISSAP)?

ISSAP is ISC2's security architecture credential, one of three standalone advanced certifications alongside ISSEP and ISSMP.

ISC2 describes the ISSAP holder as a security leader who specializes in designing security solutions and giving management risk-based guidance. That is a narrower job than the CISSP covers, and the exam reflects it: four domains instead of eight, with a third of the weight sitting in infrastructure and system security alone. The work it tests is target-state design, framework selection, threat modeling, and proving a design does what it claims.

Eligibility is the part people get wrong. ISC2 created the ISSAP as a CISSP concentration and made it a standalone certification on October 23, 2023, changing the postnominal at the same time, so what used to be written CISSP-ISSAP is now written ISSAP, CISSP. There are two ways to qualify, and neither is a lesser version of the other. Most candidates take the first: an active CISSP in good standing plus two years of cumulative, full-time experience in one or more of the four ISSAP domains. If your CISSP has lapsed or is suspended, that route is closed until you bring it back into good standing. The second is seven years of cumulative, full-time experience in two or more domains with no CISSP at all. Both award the same certification. The difference turns up afterward, in what it costs to keep.

The credential is ANAB-accredited under ISO/IEC 17024 and approved under DoD 8140. It is issued and maintained by ISC2.

4 Domains
125 Exam Items
700 Score to Pass
The ISSAP Domains

Four Domains of Security Architecture

01

Governance, Risk, and Compliance

Requirements, auditability, risk artifacts and risk treatment advice. 21% of the exam.

02

Security Architecture Modeling

Frameworks, reference architectures, threat modeling, and design validation. 22% of the exam.

03

Infrastructure and System Security

Platform, network, storage, cloud, endpoint and cryptographic design. The heaviest domain at 32%.

04

Identity and Access Management Architecture

Identity lifecycle, then authentication, authorization and accounting design. 25% of the exam.

Why ISSAP Matters

Why Is ISSAP So Widely Recognized?

Four reasons the architecture credential carries weight with people who already know what a CISSP is.

It Builds on the CISSP Rather Than Repeating It

ISSAP says something a second broad credential cannot: that you took the architecture slice of the CISSP and went deeper into it. Hiring managers who already screen for CISSP read it as a specialization signal, not as another line of the same thing. ISC2 sets the postnominal order to match, writing it ISSAP, CISSP so the specialization comes first.

Narrow on Purpose

Four domains, and 32 percent of the exam sits in infrastructure and system security. Nothing here is about running a SOC or managing a program. If your day is spent on target-state design, framework selection and design review, the exam is aimed at your desk.

Cheap to Keep

On the CISSP route, ISC2's single annual maintenance fee of $135 already covers you no matter how many certifications you add, and ISSAP CPEs count toward the CISSP requirement instead of stacking on top. On the seven-year route the arithmetic is different: 140 CPE credits per term rather than 60, and the fee is yours to pay. Security architecture also sits near the top of the pay band; our look at the highest-paid cybersecurity jobs puts that in context.

DoD 8140 Approved

ISC2 lists the ISSAP as approved under U.S. DoDM 8140, alongside ISSEP and ISSMP. All three carry the same approval statement on ISC2's certification pages.

ISC2 does not publish which DoD Cyber Workforce Framework work roles or proficiency levels the ISSAP satisfies, so we do not list any here. If you need the credential for a specific billet, check the current qualification matrices at the DoD Cyber Exchange against the work role you are filling.

DoDM 8140 Approved ANAB Accredited ISO/IEC 17024
Fast Facts

What Are the Key Facts About ISSAP?

The certification, the exam structure, and what it takes to keep ISSAP current as of 2026. Everything below traces to an ISC2 page.

01

The Certification

Certification Name
Information Systems Security Architecture Professional (ISSAP)
Issued By
ISC2
Credential Type
Standalone advanced certification (since October 23, 2023)
Exam Outline
Effective August 1, 2025
Qualifying Route 1 (With CISSP)
Active CISSP in good standing, plus 2 yrs in 1 or more domains
Qualifying Route 2 (No CISSP)
7 yrs cumulative, full-time in 2 or more domains
Difference Between Routes
Upkeep, not status: Route 2 is 140 CPEs per term instead of 60
Experience Waiver (Route 2)
1 year max (degree or approved ISC2 credential)
No-Experience Path
Associate of ISC2, held up to 8 years
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Approved (ISC2 publishes no DCWF roles)
02

Exam & Maintenance

Exam Format
Fixed length, not adaptive
Number of Items
125 questions
Item Types
Multiple choice plus advanced items
Exam Duration
3 hours
Passing Score
700 out of 1000
Delivery
Pearson Testing Center, English only
Exam Cost
$599 USD
Validity
3 years
CPE Requirement
60 per 3-yr term with CISSP; 140 without
Maintenance
$135 AMF, one fee covering all ISC2 certs held
Going Deeper

What Comes After the ISSAP?

ISSAP proves architecture depth. From there, people either pick up a sister certification to cover the engineering or management side of the same work, or specialize by environment. These three come up most.

ISSEP (Engineering)

The systems security engineering track. Where ISSAP designs the target state, ISSEP covers building, implementing and verifying it across five domains. Same two routes in, same 125-item exam.

ISSMP (Management)

The management track, and the natural move if you are heading from architecture into running the program. ISSMP covers leadership, lifecycle, risk, operations and contingency across six domains.

CCSP (Cloud Depth)

If most of what you architect now runs in someone else's data center, CCSP goes deep on cloud across six domains. It has its own experience rules rather than leaning on a CISSP, so it stands entirely on its own.

Certification Roadmap

Where Does ISSAP Fit in Your Career?

ISSAP is a late-career credential. Most people reach it through the CISSP, and from there either add one of the other two advanced ISC2 certifications or specialize by environment.

STAGE 01

Qualify

Either route gets you there

STAGE 02 You Are Here

Specialization

The architecture credential

PRIMARY
ISSAP
ISC2 ยท Security architecture credential
Associate of ISC2
ISC2 ยท Pass first, earn experience after
STAGE 03

Specialize

Pick your path

Sister Certifications
Environment Depth
Decision Point

Is ISSAP Right For You?

Two questions to answer before you commit: can you certify, and should you pursue ISSAP specifically. Here's a straight answer to both.

Q1

Do You Qualify for ISSAP?

Path A

Active CISSP Plus Two Years

The route most candidates take, and the cheaper one to keep.

You hold a CISSP in good standing, meaning current CPEs and a paid annual maintenance fee, and you have two years of cumulative, full-time experience in one or more of the four ISSAP domains. If your CISSP has lapsed or is suspended, this path is closed until you bring it back into good standing. Pass the exam, get endorsed, and ISSAP is added to your existing membership: 60 CPE credits per three-year term, folded into the CISSP cycle, and no second maintenance fee.

Path B

Seven Years, No CISSP

Longer to qualify for, and heavier to maintain.

Since October 23, 2023 ISC2 has accepted seven years of cumulative, full-time experience in two or more of the ISSAP domains with no CISSP at all. A bachelor's or master's in computer science or IT, or another credential from the ISC2 approved list, can cover one of those years, and only one. Two things to weigh first: maintenance runs to 140 CPE credits per three-year term rather than 60, and the annual maintenance fee is yours rather than one a CISSP you already keep would have covered. You also finish without the CISSP that most hiring filters screen for. Pass before you have the experience and you can hold the Associate of ISC2 designation for up to eight years while you earn it.

Q2

Is ISSAP the Right Certification for Your Goals?

ISSAP Is a Strong Fit If...

  • You already hold a CISSP in good standing, which is the more common route in and much the cheaper one to maintain
  • Your job title has the word architect in it, or should
  • You spend your week on target-state design, framework selection, threat modeling and design review
  • Infrastructure, network, platform and cryptographic design is where you are strongest, since that is 32 percent of the exam
  • You want a second credential that adds no second maintenance fee and whose CPEs count toward your CISSP cycle
  • You need a DoD 8140 approved credential and the work role you are filling accepts ISSAP

Consider Alternatives If...

  • You do not hold a CISSP yet, where earning that first is the faster route and leaves you on 60 CPEs a term instead of 140
  • Your work is building and verifying systems rather than designing them, where ISSEP is the better match
  • You are moving into running the program rather than designing it, where ISSMP fits
  • Nearly everything you architect is cloud-native, where CCSP goes deeper on that ground
  • You need a credential a hiring filter will recognize on sight, since CISSP still has far wider name recognition than any of the three advanced certifications
  • You are early in your career, where the seven-year experience route makes this a long project
Career Paths

What Jobs Can You Get With ISSAP?

ISC2 names system architect, chief technology officer, system and network designer, business analyst and chief security officer as the roles the ISSAP is built for. These six are where the credential comes up most in practice.

Architecture

Security Architect

Designs the security controls, patterns and reference architectures an organization builds on. This is the role the ISSAP was written around, and the one its four domains map to almost line for line.

Systems Design

System Architect

Owns the shape of a platform end to end and has to make security part of that shape rather than a bolt-on. ISC2 names it as one of the roles the ISSAP is built for.

Executive

Chief Security Officer

Sits between the C-suite and the security program. ISSAP is aimed squarely at the part of that job that is risk-based guidance to senior management rather than day-to-day operations.

Executive

Chief Technology Officer

Makes platform and architecture bets the whole business lives with. ISC2 lists CTO among the roles the ISSAP suits, because the credential is about design tradeoffs, not tooling.

Infrastructure Design

System and Network Designer

Designs the network, platform and storage layers that Domain 3 covers, which alone carries 32 percent of the exam. The most technical of the roles ISC2 names for ISSAP.

Advisory

Enterprise Security Consultant

Advises clients on target-state architecture, framework selection and control design. ISSAP is a clean way to prove architecture depth to a buyer who already knows what a CISSP is.

Comparison

How Does ISSAP Compare to ISSEP and ISSMP?

This is the real decision. All three are standalone ISC2 certifications, all three take the same two routes in, run the same exam and carry the same maintenance rules. The only thing that separates them is which part of the job they cover.

  ISSAP ISSEP ISSMP
Focus Designing security solutions Building and verifying secure systems Running the security program
Domains 4 5 6
Heaviest Domain Infrastructure and System Security, 32% Systems Security Engineering Foundations, 24% Leadership and Organizational Management, 21%
Exam 125 items, 3 hrs, fixed length 125 items, 3 hrs, fixed length 125 items, 3 hrs, fixed length
Route 1 (With CISSP) Active CISSP + 2 yrs in 1 or more domains Active CISSP + 2 yrs in 1 or more domains Active CISSP + 2 yrs in 1 or more domains
Route 2 (No CISSP) 7 yrs cumulative, no CISSP 7 yrs cumulative, no CISSP 7 yrs cumulative, no CISSP
CPEs per 3-Year Term 60 with CISSP, 140 without 60 with CISSP, 140 without 60 with CISSP, 140 without
Passing Score 700 / 1000 700 / 1000 700 / 1000
Exam Outline Effective Aug 1, 2025 Effective Aug 1, 2025 Effective Aug 1, 2025
DoD 8140 Approved Yes Yes Yes
Best For Security and system architects Security and systems engineers Security managers and program leads

Read more on ISSEP, ISSMP, and the CISSP. Pricing and renewal details vary by region and membership status.

Ready to Get Certified?

Train for ISSAP with Training Camp.

Our official ISC2 ISSAP boot camp covers all four domains over four days, with your $599 exam voucher, official ISC2 courseware, and a free retake guarantee included, so experienced architects leave exam-ready.

View Boot Camp
Dive Deeper

ISSAP Articles and Guides.

Choosing between the three advanced certifications, what changed in the 2025 outlines, and where a CISSP leads next.

Featured Comparison

ISSAP vs ISSEP vs ISSMP: A Straight Answer on Which One You Should Pursue

The only comparison that really matters once you hold a CISSP. Architecture, engineering or management, and how to tell which one your actual job is.

Read Article โ†’
Exam Update

What Changed With ISSEP, ISSAP and ISSMP

ISC2 rewrote the outlines for all three advanced certifications effective August 1, 2025. What moved, what the new domain weights mean, and why older study material is now a liability.

Read Article โ†’
Career Path

What Comes After CISSP?

ISSAP, ISSEP and ISSMP are one answer, but not the only one. A look at where ISSAP sits among the credentials CISSP holders reach for next.

Read Article โ†’
Decision Guide

Beyond CISSP: Choosing Your Next Certification

How to pick a follow-on credential based on the work you actually do rather than the one with the best marketing. Useful before you commit to one of the three.

Read Article โ†’
Careers

Career Opportunities After CISSP Certification

Where a CISSP actually leads, including the architecture track the ISSAP formalizes. A useful map if you are deciding whether to specialize or broaden.

Read Article โ†’
ISC2 Foundation

The Complete CISSP Guide

Most ISSAP candidates qualify through the CISSP, so that is where they start. A full walkthrough of the CISSP and what it takes to hold one.

Read Article โ†’
Maintenance

How to Renew Your CISSP Certification

Worth reading before you add ISSAP, because on the CISSP route its CPEs fold into the CISSP cycle rather than creating a second one to track.

Read Article โ†’
Curriculum

Inside the Four ISSAP Domains.

The ISSAP Common Body of Knowledge is organized into four domains, each carrying its own weight on the exam. Click any domain for what it covers.

Domains 01-02

Governance to Modeling
01 Governance, Risk, and Compliance (GRC) 21%

Identifying the legal, regulatory, organizational and industry requirements a design has to satisfy, then architecting for them: key assets and stakeholders, monitoring and reporting, design for auditability, risk assessment artifacts, and advising on risk treatment.

02 Security Architecture Modeling 22%

Choosing the architecture approach and scope, working with frameworks such as TOGAF and SABSA, using reference architectures and threat modeling frameworks like STRIDE, then verifying and validating the design through testing, gap analysis, peer review and code review.

Domains 03-04

Infrastructure to Identity
03 Infrastructure and System Security 32%

The heaviest domain by a wide margin. Physical, platform, network, storage, data repository, cloud, operational technology and endpoint security, plus shared services, third-party integrations, monitoring, out-of-band communications, and cryptographic design and key management.

04 Identity and Access Management (IAM) Architecture 25%

Architecting the identity lifecycle from establishing and verifying identity through provisioning and de-provisioning, then the authentication, authorization and accounting design that sits on top of it.

Domains and weights reflect the ISC2 ISSAP Exam Outline effective August 1, 2025, the version ISC2 administers today.

Frequently Asked Questions

Common Questions About ISSAP.

The questions candidates ask most often when researching the Information Systems Security Architecture Professional certification.

What is the ISSAP certification?

ISSAP is ISC2's security architecture credential, one of three standalone advanced certifications alongside ISSEP and ISSMP. It validates the ability to develop, design and analyze security solutions and to give risk-based guidance to senior management. There are two ways to qualify: an active CISSP in good standing plus two years of domain experience, which is the route most candidates take, or seven years of experience with no CISSP. Both award the same certification, and what separates them is CPE load rather than status. The current exam outline took effect August 1, 2025 and covers four domains.

Do you need a CISSP to earn the ISSAP?

No. ISSAP has been a standalone certification since October 23, 2023, and ISC2 publishes two qualifying routes. One asks for an active CISSP in good standing plus two years of cumulative, full-time experience in one or more of the four ISSAP domains, and that is the route most candidates take. The other asks for seven years of cumulative, full-time experience in two or more of the domains with no CISSP at all. Both award the same certification. Holding ISSAP without a CISSP does cost more: 140 CPE credits per three-year term instead of 60, and the annual maintenance fee is your own rather than one your CISSP already covers. It also leaves you without the CISSP that most hiring filters screen for first.

What are the four ISSAP domains?

Governance, Risk, and Compliance (GRC) at 21 percent, Security Architecture Modeling at 22 percent, Infrastructure and System Security at 32 percent, and Identity and Access Management (IAM) Architecture at 25 percent. Infrastructure and System Security is the heaviest domain by a wide margin.

What is the ISSAP exam like?

The ISSAP exam is 125 items over three hours, delivered in English at a Pearson Testing Center. Item types are multiple choice plus advanced item types, and you need a scaled score of 700 out of 1000 to pass. The item count is fixed, so unlike CISSP and CCSP this exam is not adaptive.

How much does the ISSAP exam cost in 2026?

The ISSAP exam costs $599 USD as of 2026, set by ISC2 and varying by region. That fee covers the exam only, not training or study materials. Many boot camps fold the voucher into the course price, so check what is included before you pay for one separately.

Can you take the ISSAP exam before you have the experience?

Yes. If you pass the exam before you meet the experience requirement, you can become an Associate of ISC2 while you earn it. ISC2 allows the Associate designation to be held for up to eight years on the ISSAP path, which is one year longer than the seven-year experience route.

How do CPEs work for ISSAP if you already hold a CISSP?

They overlap rather than stack. ISC2's certification maintenance policy lists 20 CPE credits suggested annually and 60 over the three-year term for an ISSAP held alongside a CISSP, and states that CPE requirements for ISSAP are automatically counted toward the CISSP requirement. The footnote is specific: 20 of the Group A credits in your CISSP cycle must be directly related to the ISSAP. Earn the ISSAP on the seven-year route with no CISSP and there is nothing to fold it into, so the requirement is 140 credits per three-year term.

How much does it cost to maintain the ISSAP?

ISC2 members pay a single annual maintenance fee of $135 no matter how many certifications they hold. If you took the CISSP route you are already paying it, so ISSAP adds no second fee. If ISSAP is your only ISC2 certification, that $135 is yours to cover, on top of the heavier 140-credit CPE requirement. Certification runs on a three-year cycle either way.

Is ISSAP approved for DoD 8140?

Yes. ISC2 lists the ISSAP as approved under U.S. DoDM 8140. ISC2 does not publish which DoD Cyber Workforce Framework work roles or proficiency levels the ISSAP satisfies, so check the current qualification matrices on the DoD Cyber Exchange for the specific role you need to fill.

What is the difference between ISSAP, ISSEP and ISSMP?

All three are standalone ISC2 certifications sharing the same two routes in, the same 125-item, three-hour exam and the same maintenance rules. ISSAP is the architecture track, covering how security solutions get designed. ISSEP is the systems security engineering track, aimed at building and verifying secure systems. ISSMP is the management track, covering program leadership, risk and contingency planning.

Which ISSAP exam outline is current?

The outline in force took effect August 1, 2025, following ISC2's latest Job Task Analysis. It keeps four domains and revises the weights and subdomains across all of them. Make sure any study material you buy matches this outline rather than an older one.

Is ISSAP worth it in 2026?

If you hold a CISSP and architecture is what you actually do, ISSAP is a focused way to prove that specialization without repeating CISSP breadth. It costs $599, adds no second maintenance fee, and its CPEs count toward the CISSP cycle. Without a CISSP it is a much bigger commitment: seven years of experience to qualify, 140 CPE credits per term to keep, and no CISSP alongside it.

Get In Touch

Have Questions About ISSAP?

Whether you're weighing ISSAP against ISSEP and ISSMP, checking whether your CISSP is in good standing, or planning training for a team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    ISC2 ISSAP Boot Camp 4-Day Boot Camp ยท Exam Voucher Included
    View Boot Camp