Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
ISSAP is ISC2's standalone security architecture certification, and there are two ways to qualify for it. Most candidates come through the CISSP: an active CISSP in good standing plus two years in the architecture domains. The other is seven years of cumulative experience and no CISSP at all. Both award the same certification. What separates them is upkeep, not standing, because holding ISSAP alongside a CISSP costs 60 CPE credits per three-year term instead of 140. This guide covers the four domains, the exam, both routes, and how CPEs work either way.
ISSAP is ISC2's security architecture credential, one of three standalone advanced certifications alongside ISSEP and ISSMP.
ISC2 describes the ISSAP holder as a security leader who specializes in designing security solutions and giving management risk-based guidance. That is a narrower job than the CISSP covers, and the exam reflects it: four domains instead of eight, with a third of the weight sitting in infrastructure and system security alone. The work it tests is target-state design, framework selection, threat modeling, and proving a design does what it claims.
Eligibility is the part people get wrong. ISC2 created the ISSAP as a CISSP concentration and made it a standalone certification on October 23, 2023, changing the postnominal at the same time, so what used to be written CISSP-ISSAP is now written ISSAP, CISSP. There are two ways to qualify, and neither is a lesser version of the other. Most candidates take the first: an active CISSP in good standing plus two years of cumulative, full-time experience in one or more of the four ISSAP domains. If your CISSP has lapsed or is suspended, that route is closed until you bring it back into good standing. The second is seven years of cumulative, full-time experience in two or more domains with no CISSP at all. Both award the same certification. The difference turns up afterward, in what it costs to keep.
The credential is ANAB-accredited under ISO/IEC 17024 and approved under DoD 8140. It is issued and maintained by ISC2.
Requirements, auditability, risk artifacts and risk treatment advice. 21% of the exam.
Frameworks, reference architectures, threat modeling, and design validation. 22% of the exam.
Platform, network, storage, cloud, endpoint and cryptographic design. The heaviest domain at 32%.
Identity lifecycle, then authentication, authorization and accounting design. 25% of the exam.
Four reasons the architecture credential carries weight with people who already know what a CISSP is.
ISSAP says something a second broad credential cannot: that you took the architecture slice of the CISSP and went deeper into it. Hiring managers who already screen for CISSP read it as a specialization signal, not as another line of the same thing. ISC2 sets the postnominal order to match, writing it ISSAP, CISSP so the specialization comes first.
Four domains, and 32 percent of the exam sits in infrastructure and system security. Nothing here is about running a SOC or managing a program. If your day is spent on target-state design, framework selection and design review, the exam is aimed at your desk.
On the CISSP route, ISC2's single annual maintenance fee of $135 already covers you no matter how many certifications you add, and ISSAP CPEs count toward the CISSP requirement instead of stacking on top. On the seven-year route the arithmetic is different: 140 CPE credits per term rather than 60, and the fee is yours to pay. Security architecture also sits near the top of the pay band; our look at the highest-paid cybersecurity jobs puts that in context.
ISC2 lists the ISSAP as approved under U.S. DoDM 8140, alongside ISSEP and ISSMP. All three carry the same approval statement on ISC2's certification pages.
ISC2 does not publish which DoD Cyber Workforce Framework work roles or proficiency levels the ISSAP satisfies, so we do not list any here. If you need the credential for a specific billet, check the current qualification matrices at the DoD Cyber Exchange against the work role you are filling.
The certification, the exam structure, and what it takes to keep ISSAP current as of 2026. Everything below traces to an ISC2 page.
ISSAP proves architecture depth. From there, people either pick up a sister certification to cover the engineering or management side of the same work, or specialize by environment. These three come up most.
The systems security engineering track. Where ISSAP designs the target state, ISSEP covers building, implementing and verifying it across five domains. Same two routes in, same 125-item exam.
The management track, and the natural move if you are heading from architecture into running the program. ISSMP covers leadership, lifecycle, risk, operations and contingency across six domains.
If most of what you architect now runs in someone else's data center, CCSP goes deep on cloud across six domains. It has its own experience rules rather than leaning on a CISSP, so it stands entirely on its own.
ISSAP is a late-career credential. Most people reach it through the CISSP, and from there either add one of the other two advanced ISC2 certifications or specialize by environment.
Either route gets you there
The architecture credential
Two questions to answer before you commit: can you certify, and should you pursue ISSAP specifically. Here's a straight answer to both.
The route most candidates take, and the cheaper one to keep.
You hold a CISSP in good standing, meaning current CPEs and a paid annual maintenance fee, and you have two years of cumulative, full-time experience in one or more of the four ISSAP domains. If your CISSP has lapsed or is suspended, this path is closed until you bring it back into good standing. Pass the exam, get endorsed, and ISSAP is added to your existing membership: 60 CPE credits per three-year term, folded into the CISSP cycle, and no second maintenance fee.
Longer to qualify for, and heavier to maintain.
Since October 23, 2023 ISC2 has accepted seven years of cumulative, full-time experience in two or more of the ISSAP domains with no CISSP at all. A bachelor's or master's in computer science or IT, or another credential from the ISC2 approved list, can cover one of those years, and only one. Two things to weigh first: maintenance runs to 140 CPE credits per three-year term rather than 60, and the annual maintenance fee is yours rather than one a CISSP you already keep would have covered. You also finish without the CISSP that most hiring filters screen for. Pass before you have the experience and you can hold the Associate of ISC2 designation for up to eight years while you earn it.
ISC2 names system architect, chief technology officer, system and network designer, business analyst and chief security officer as the roles the ISSAP is built for. These six are where the credential comes up most in practice.
Designs the security controls, patterns and reference architectures an organization builds on. This is the role the ISSAP was written around, and the one its four domains map to almost line for line.
Owns the shape of a platform end to end and has to make security part of that shape rather than a bolt-on. ISC2 names it as one of the roles the ISSAP is built for.
Sits between the C-suite and the security program. ISSAP is aimed squarely at the part of that job that is risk-based guidance to senior management rather than day-to-day operations.
Makes platform and architecture bets the whole business lives with. ISC2 lists CTO among the roles the ISSAP suits, because the credential is about design tradeoffs, not tooling.
Designs the network, platform and storage layers that Domain 3 covers, which alone carries 32 percent of the exam. The most technical of the roles ISC2 names for ISSAP.
Advises clients on target-state architecture, framework selection and control design. ISSAP is a clean way to prove architecture depth to a buyer who already knows what a CISSP is.
This is the real decision. All three are standalone ISC2 certifications, all three take the same two routes in, run the same exam and carry the same maintenance rules. The only thing that separates them is which part of the job they cover.
| ISSAP | ISSEP | ISSMP | |
|---|---|---|---|
| Focus | Designing security solutions | Building and verifying secure systems | Running the security program |
| Domains | 4 | 5 | 6 |
| Heaviest Domain | Infrastructure and System Security, 32% | Systems Security Engineering Foundations, 24% | Leadership and Organizational Management, 21% |
| Exam | 125 items, 3 hrs, fixed length | 125 items, 3 hrs, fixed length | 125 items, 3 hrs, fixed length |
| Route 1 (With CISSP) | Active CISSP + 2 yrs in 1 or more domains | Active CISSP + 2 yrs in 1 or more domains | Active CISSP + 2 yrs in 1 or more domains |
| Route 2 (No CISSP) | 7 yrs cumulative, no CISSP | 7 yrs cumulative, no CISSP | 7 yrs cumulative, no CISSP |
| CPEs per 3-Year Term | 60 with CISSP, 140 without | 60 with CISSP, 140 without | 60 with CISSP, 140 without |
| Passing Score | 700 / 1000 | 700 / 1000 | 700 / 1000 |
| Exam Outline | Effective Aug 1, 2025 | Effective Aug 1, 2025 | Effective Aug 1, 2025 |
| DoD 8140 Approved | Yes | Yes | Yes |
| Best For | Security and system architects | Security and systems engineers | Security managers and program leads |
Read more on ISSEP, ISSMP, and the CISSP. Pricing and renewal details vary by region and membership status.
Our official ISC2 ISSAP boot camp covers all four domains over four days, with your $599 exam voucher, official ISC2 courseware, and a free retake guarantee included, so experienced architects leave exam-ready.
Choosing between the three advanced certifications, what changed in the 2025 outlines, and where a CISSP leads next.
The only comparison that really matters once you hold a CISSP. Architecture, engineering or management, and how to tell which one your actual job is.
ISC2 rewrote the outlines for all three advanced certifications effective August 1, 2025. What moved, what the new domain weights mean, and why older study material is now a liability.
ISSAP, ISSEP and ISSMP are one answer, but not the only one. A look at where ISSAP sits among the credentials CISSP holders reach for next.
How to pick a follow-on credential based on the work you actually do rather than the one with the best marketing. Useful before you commit to one of the three.
Where a CISSP actually leads, including the architecture track the ISSAP formalizes. A useful map if you are deciding whether to specialize or broaden.
Most ISSAP candidates qualify through the CISSP, so that is where they start. A full walkthrough of the CISSP and what it takes to hold one.
Worth reading before you add ISSAP, because on the CISSP route its CPEs fold into the CISSP cycle rather than creating a second one to track.
The ISSAP Common Body of Knowledge is organized into four domains, each carrying its own weight on the exam. Click any domain for what it covers.
Identifying the legal, regulatory, organizational and industry requirements a design has to satisfy, then architecting for them: key assets and stakeholders, monitoring and reporting, design for auditability, risk assessment artifacts, and advising on risk treatment.
Choosing the architecture approach and scope, working with frameworks such as TOGAF and SABSA, using reference architectures and threat modeling frameworks like STRIDE, then verifying and validating the design through testing, gap analysis, peer review and code review.
The heaviest domain by a wide margin. Physical, platform, network, storage, data repository, cloud, operational technology and endpoint security, plus shared services, third-party integrations, monitoring, out-of-band communications, and cryptographic design and key management.
Architecting the identity lifecycle from establishing and verifying identity through provisioning and de-provisioning, then the authentication, authorization and accounting design that sits on top of it.
Domains and weights reflect the ISC2 ISSAP Exam Outline effective August 1, 2025, the version ISC2 administers today.
The questions candidates ask most often when researching the Information Systems Security Architecture Professional certification.
ISSAP is ISC2's security architecture credential, one of three standalone advanced certifications alongside ISSEP and ISSMP. It validates the ability to develop, design and analyze security solutions and to give risk-based guidance to senior management. There are two ways to qualify: an active CISSP in good standing plus two years of domain experience, which is the route most candidates take, or seven years of experience with no CISSP. Both award the same certification, and what separates them is CPE load rather than status. The current exam outline took effect August 1, 2025 and covers four domains.
No. ISSAP has been a standalone certification since October 23, 2023, and ISC2 publishes two qualifying routes. One asks for an active CISSP in good standing plus two years of cumulative, full-time experience in one or more of the four ISSAP domains, and that is the route most candidates take. The other asks for seven years of cumulative, full-time experience in two or more of the domains with no CISSP at all. Both award the same certification. Holding ISSAP without a CISSP does cost more: 140 CPE credits per three-year term instead of 60, and the annual maintenance fee is your own rather than one your CISSP already covers. It also leaves you without the CISSP that most hiring filters screen for first.
Governance, Risk, and Compliance (GRC) at 21 percent, Security Architecture Modeling at 22 percent, Infrastructure and System Security at 32 percent, and Identity and Access Management (IAM) Architecture at 25 percent. Infrastructure and System Security is the heaviest domain by a wide margin.
The ISSAP exam is 125 items over three hours, delivered in English at a Pearson Testing Center. Item types are multiple choice plus advanced item types, and you need a scaled score of 700 out of 1000 to pass. The item count is fixed, so unlike CISSP and CCSP this exam is not adaptive.
The ISSAP exam costs $599 USD as of 2026, set by ISC2 and varying by region. That fee covers the exam only, not training or study materials. Many boot camps fold the voucher into the course price, so check what is included before you pay for one separately.
Yes. If you pass the exam before you meet the experience requirement, you can become an Associate of ISC2 while you earn it. ISC2 allows the Associate designation to be held for up to eight years on the ISSAP path, which is one year longer than the seven-year experience route.
They overlap rather than stack. ISC2's certification maintenance policy lists 20 CPE credits suggested annually and 60 over the three-year term for an ISSAP held alongside a CISSP, and states that CPE requirements for ISSAP are automatically counted toward the CISSP requirement. The footnote is specific: 20 of the Group A credits in your CISSP cycle must be directly related to the ISSAP. Earn the ISSAP on the seven-year route with no CISSP and there is nothing to fold it into, so the requirement is 140 credits per three-year term.
ISC2 members pay a single annual maintenance fee of $135 no matter how many certifications they hold. If you took the CISSP route you are already paying it, so ISSAP adds no second fee. If ISSAP is your only ISC2 certification, that $135 is yours to cover, on top of the heavier 140-credit CPE requirement. Certification runs on a three-year cycle either way.
Yes. ISC2 lists the ISSAP as approved under U.S. DoDM 8140. ISC2 does not publish which DoD Cyber Workforce Framework work roles or proficiency levels the ISSAP satisfies, so check the current qualification matrices on the DoD Cyber Exchange for the specific role you need to fill.
All three are standalone ISC2 certifications sharing the same two routes in, the same 125-item, three-hour exam and the same maintenance rules. ISSAP is the architecture track, covering how security solutions get designed. ISSEP is the systems security engineering track, aimed at building and verifying secure systems. ISSMP is the management track, covering program leadership, risk and contingency planning.
The outline in force took effect August 1, 2025, following ISC2's latest Job Task Analysis. It keeps four domains and revises the weights and subdomains across all of them. Make sure any study material you buy matches this outline rather than an older one.
If you hold a CISSP and architecture is what you actually do, ISSAP is a focused way to prove that specialization without repeating CISSP breadth. It costs $599, adds no second maintenance fee, and its CPEs count toward the CISSP cycle. Without a CISSP it is a much bigger commitment: seven years of experience to qualify, 140 CPE credits per term to keep, and no CISSP alongside it.
Whether you're weighing ISSAP against ISSEP and ISSMP, checking whether your CISSP is in good standing, or planning training for a team, tell us where you are and we'll help you map out the right path.