Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Information Systems Security Engineering Professional (ISSEP)
Certification Explained.

ISSEP is the ISC2 systems security engineering certification, developed in conjunction with the U.S. National Security Agency. This guide covers the five domains, the linear 125-item exam, the two qualifying routes, career paths, DoD 8140 status, and how ISSEP compares to ISSAP and ISSMP. Start with qualifying: most candidates come in holding an active CISSP plus two years in the ISSEP domains, and there is a seven-year experience route for everyone else.

ISSEP_FAST_FACTS
Issuer: ISC2, developed with the NSA
Route A: Active CISSP plus 2 years in domain
Route B: 7 years experience, no CISSP
Exam: 125 items, 3 hours, linear
Passing Score: 700 / 1000
Approved under DoD 8140
5 ISSEP Domains 2 Ways to Qualify 125 Exam Items 3-HOUR Linear Exam NSA Co-Developed
UPDATED 2026
Overview

What Is the Information Systems Security Engineering Professional (ISSEP)?

ISSEP is one of three advanced certifications from ISC2, and it is the engineering one. ISC2 created it as a CISSP concentration and made it a standalone certification in October 2023, so today it stands on its own rather than hanging off another credential. ISC2 developed it in conjunction with the U.S. National Security Agency.

The distinction that matters: a CISSP proves you understand security across the enterprise. An ISSEP proves you can engineer it into a specific system, working the same lifecycle a systems engineer works. Requirements come first, then design, then implementation and verification, then secure operations, change management, and disposal. Five domains, weighted toward the front of that lifecycle, where the expensive mistakes get made.

That NSA origin is why the credential reads the way it does, and why it carries the most weight in defense programs, federal systems integration, and critical infrastructure engineering. It is ANAB-accredited under ISO/IEC 17024 and listed by ISC2 as meeting U.S. DoDM 8140. ISSEP is issued and maintained by ISC2.

5 Domains
125 Exam Items
2 Ways to Qualify
The ISSEP Domains

Five Domains of Security Engineering

01

Systems Security Engineering Foundations

The engineering process, technical management, and procurement. The heaviest domain at 24%.

02

Risk Management

Risk principles applied to the system and to operations. 20% of the exam.

03

Security Planning and Engineering

Environment analysis, security principles, requirements, and system security design. 22%.

04

Implementation, Verification and Validation

Integrating security solutions and proving the build matches the spec. 20% of the exam.

05

Secure Operations, Change Management and Disposal

Running the system, changing it safely, and retiring it. 14% of the exam.

Why ISSEP Matters

Why Is ISSEP So Widely Recognized?

ISSEP is a small credential compared to the CISSP. Four things give it disproportionate weight in the places it is recognized.

Developed with the NSA

ISC2 states that ISSEP was developed in conjunction with the U.S. National Security Agency. No other ISC2 credential carries that line. It is the reason the exam is built around formal engineering process rather than tooling, and the reason program offices treat it as a signal about how you work, not just what you know.

Two Ways In, Both Senior

Most people qualify with a current CISSP plus two more years in the ISSEP domains. The rest qualify on seven years of cumulative experience across two or more domains, with no CISSP involved. Either way the experience bar is high, so the credential filters for seniority before anyone sits the exam.

Named on Defense Work

Security engineering roles on defense and federal programs sit at the senior end of the pay scale, and ISSEP is frequently the credential named in the posting. Our look at the highest-paid cybersecurity jobs puts the range in context.

Approved Under DoD 8140

ISC2 lists ISSEP as meeting U.S. DoDM 8140, alongside its ANAB accreditation. With element-level qualification now mandatory across the department under DoD Manual 8140.03, an approved credential is what lets someone hold a cyber workforce role at all.

ISC2 does not publish a role-level DoD Cyber Workforce Framework mapping for ISSEP on its certification page, so we do not list work role counts here. Check the current qualification matrix at the DoD Cyber Exchange for the roles and proficiency levels a specific billet requires.

DoDM 8140 Approved ANAB Accredited ISO/IEC 17024
Fast Facts

What Are the Key Facts About ISSEP?

The two qualifying routes, the exam structure, and how maintenance changes depending on whether you also hold a CISSP, as of 2026.

01

The Certification

Certification Name
Information Systems Security Engineering Professional (ISSEP)
Issued By
ISC2, developed with the U.S. NSA
Type
Standalone ISC2 certification, advanced level
Postnominal
ISSEP, CISSP (or ISSEP alone, without a CISSP)
Route A
Active CISSP plus 2 yrs in one or more ISSEP domains
Route B
7 yrs cumulative across 2+ domains, no CISSP
Experience Waiver
1 yr (degree or approved ISC2 credential), Route B only
Exam Outline
Effective August 1, 2025
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Approved (ISC2 lists U.S. DoDM 8140)
02

Exam & Maintenance

Exam Format
Linear (not adaptive)
Number of Items
125 questions
Item Types
Multiple choice plus advanced items
Exam Duration
3 hours
Passing Score
700 out of 1000
Exam Cost
~$599 USD
Validity
3 years
CPEs With a CISSP
60 Group A per 3-year term, also count toward CISSP
CPEs Without a CISSP
140 Group A per 3-year term
Maintenance Fee
Single AMF of U.S. $135, however many certs you hold
Going Deeper

What Comes After the ISSEP?

ISSEP proves you can engineer security into a system. From there people usually widen the aperture, either to the architecture of the whole enterprise, to running the program, or to the cloud environments the next system will live in.

ISSAP (Architecture)

The architecture certification, standalone like ISSEP and reachable by the same two routes. Same 125-item exam, four domains covering governance, security architecture modeling, infrastructure, and identity architecture. The move for engineers who start designing across systems instead of within one. Read the ISSAP guide.

ISSMP (Management)

The management certification, the third of the ISC2 advanced three. Six domains covering leadership, lifecycle management, risk, operations, contingency, and compliance. The move for engineers heading toward running the program rather than building the system. Read the ISSMP guide.

CCSP (Cloud)

A different shape of ISC2 credential, with its own five-year experience requirement rather than the ISSEP routes. Worth adding when the systems you engineer stop being racks and start being someone else's data center. Six domains, adaptive exam, five years of experience. Read the CCSP guide.

Certification Roadmap

Where Does ISSEP Fit in Your Career?

ISSEP is a late-career move, not an early one. Most people arrive holding a CISSP, and from there the usual next steps are ISSAP or ISSMP.

STAGE 02 You Are Here

The Certification

Engineering specialization

PRIMARY
ISSEP
ISC2 ยท Systems security engineering
7-Year Route
ISC2 ยท Qualify on experience, no CISSP
STAGE 03

Widen

Pick your direction

Other Advanced Certs
Cloud Systems
Decision Point

Is ISSEP Right For You?

Two questions to answer before you commit: can you certify, and should you pick ISSEP over ISSAP or ISSMP. Here's a straight answer to both.

Q1

Do You Qualify for ISSEP?

Path A

Active CISSP Plus 2 Years

The CISSP route.

You hold a current CISSP in good standing and have two years of full-time experience in one or more ISSEP domains. Pass the exam and you write it as ISSEP, CISSP: two standalone certifications side by side, not one nested inside the other. Maintenance is 60 Group A CPEs per three-year term, and those credits count toward your CISSP cycle as well. This is the route almost everyone takes.

Path B

7 Years, No CISSP

The experience route.

ISC2 also lists a route for candidates without a CISSP: seven years of cumulative full-time experience across two or more ISSEP domains. A relevant bachelor's or master's degree, or an approved ISC2 credential, covers one of those years. You earn exactly the same certification this way, and the only real difference is the maintenance load: 140 Group A CPEs per three-year term instead of 60. ISC2 members pay a single annual maintenance fee of U.S. $135 regardless of how many certifications they hold, so on the CISSP route your existing fee already covers it, while on this route the fee is your own. If you pass before you meet the experience requirement, you can hold Associate of ISC2 status for up to eight years while you earn it.

Q2

Is ISSEP the Right Certification for Your Goals?

ISSEP Is a Strong Fit If...

  • You already hold a CISSP and your day job is engineering, not operations or audit
  • You work on defense, intelligence, or federal programs where formal systems engineering process governs the work
  • You write or defend system security requirements, and sit in design reviews rather than incident bridges
  • You need a DoD 8140 approved credential and want the one that names the engineering side of the job
  • Your work covers the whole lifecycle, from concept through verification to disposal
  • You keep seeing ISSEP listed as required or preferred on the contracts you want to work

Consider Alternatives If...

  • You do not hold a CISSP and are short of seven years in the domains, get the CISSP first, since it is both the faster way in and the credential employers actually screen for
  • You design across the enterprise rather than inside one system, where ISSAP is the closer match
  • You run the security program, the budget, and the people, where ISSMP fits better
  • Your work is commercial, cloud-first, or product security, where CCSP or a vendor credential travels further
  • You want broader employer recognition, since ISSEP is far less known outside defense and federal work
  • You are early in your career, the experience gate makes this a poor first or second certification
Career Paths

What Jobs Can You Get With ISSEP?

ISSEP lines up with the engineering side of security work, concentrated in defense programs, federal systems integrators, and critical infrastructure.

Security Engineering

Information Systems Security Engineer

The role the credential is named for. Sits inside a program team and owns security requirements, design, and verification from concept through disposal. The most common title on ISSEP job postings.

Systems Engineering

Systems Security Engineer

Works security into the wider systems engineering process rather than bolting it on at the end. Trades requirements, interfaces, and constraints with the rest of the engineering team.

Assessment and Authorization

Security Control Assessor

Evaluates whether the controls a system claims are actually implemented and effective. The ISSEP risk management and verification domains map onto this work almost directly.

Requirements

Security Requirements Engineer

Turns policy, mission need, and threat into testable system security requirements, then defends them through design reviews. Domain 3 is largely about this job.

Defense Contracting

Cybersecurity Engineer, Defense Programs

Works on classified or controlled systems for a prime or an integrator, where a DoD 8140 approved credential is often a contract condition rather than a preference.

Architecture

Security Architect, Engineering Track

Designs the security of a system rather than an enterprise. Overlaps with ISSAP, but stays closer to the build than to the reference architecture.

Comparison

How Does ISSEP Compare to ISSAP and ISSMP?

This is the real decision. All three are standalone ISC2 certifications with identical exam mechanics and the same two qualifying routes. What separates them is the job they describe: engineering, architecture, or management.

  ISSEP ISSAP ISSMP
Discipline Systems security engineering Security architecture Security management
Scope of Work One system, whole lifecycle The enterprise structure The program and the people
Domains 5 4 6
Heaviest Domain Engineering Foundations, 24% Infrastructure and System Security, 32% Leadership and Org Management, 21%
Exam Format Linear, 125 items, 3 hrs Linear, 125 items, 3 hrs Linear, 125 items, 3 hrs
Passing Score 700 / 1000 700 / 1000 700 / 1000
Qualifying Routes CISSP + 2 yrs, or 7 yrs cumulative CISSP + 2 yrs, or 7 yrs cumulative CISSP + 2 yrs, or 7 yrs cumulative
Exam Outline Effective Aug 1, 2025 Effective Aug 1, 2025 Effective Aug 1, 2025
NSA Co-Developed Yes Not stated by ISC2 Not stated by ISC2
Best For Engineers on defense and federal systems Architects designing across systems Managers running security programs

All three open on the same two routes, and the CISSP one is the route most people take, so start with the CISSP if you do not hold it. If you do, read the ISSAP and ISSMP guides before you commit, and pick the one that matches the work already on your calendar.

Ready to Get Certified?

Train for ISSEP with Training Camp.

Our official ISC2 ISSEP boot camp covers all five domains over four days, aligned to the exam outline effective August 1, 2025, with your exam voucher, official ISC2 courseware, and a free retake guarantee included.

View Boot Camp
Dive Deeper

ISSEP Articles and Guides.

Choosing between the three advanced ISC2 certifications, what changed in the 2025 outlines, and the engineering background behind the exam.

Featured Comparison

ISSAP vs ISSEP vs ISSMP: A Straight Answer on Which One You Should Pursue

The only comparison that matters once you hold a CISSP. Architecture, engineering, or management, and how to tell which of the three your actual job looks like.

Read Article โ†’
Exam Update

What Changed with ISSEP, ISSAP, and ISSMP

ISC2 rewrote all three exam outlines. What moved, what got dropped, and why study material bought before the change no longer matches the exam.

Read Article โ†’
Career Path

What Comes After CISSP?

The CISSP is a starting point, not the destination. Where the three advanced ISC2 certifications sit among the credentials people add next, and who each one actually suits.

Read Article โ†’
Systems Engineering

What Is IPPD? Integrated Process and Product Development Explained

A systems engineering concept that turns up throughout the ISSEP material. Useful background if you came to engineering from the security side rather than the other way around.

Read Article โ†’
Federal and DoD

Which Certifications Qualify for DoD 8140 Work Roles? A DCWF Map

How the DoD 8140 qualification matrix works, which credentials map where, and what element-level qualification means for people in defense engineering roles.

Read Article โ†’
ISC2 Foundation

The Complete CISSP Guide

Most ISSEP candidates qualify through the CISSP, so that credential is worth understanding first. A full walkthrough of what CISSP covers and requires.

Read Article โ†’
Maintenance

How to Renew CISSP Certification

Adding a second ISC2 certification changes your CPE picture. How the CISSP renewal cycle works, and what the single annual maintenance fee does and does not cover.

Read Article โ†’
Curriculum

Inside the Five ISSEP Domains.

The ISSEP Common Body of Knowledge is organized into five domains that follow the system lifecycle in order, each carrying its own weight on the exam. Click any domain for what it covers.

Domains 01-03

Foundations to Design
01 Systems Security Engineering Foundations 24%

The heaviest domain. Systems security engineering fundamentals, executing the engineering process, integrating security into the system development methodology, technical management, technology procurement management, and resource analysis.

02 Risk Management 20%

Applying security risk management principles, managing risk to the system, and managing risk to operations. This is where engineering meets the assessment and authorization work that federal programs run on.

03 Security Planning and Engineering 22%

Analyzing the organizational and operational environment, applying system security principles, developing system requirements, and creating the system security design. The second heaviest domain.

Domains 04-05

Build to Disposal
04 Systems Security Implementation, Verification and Validation 20%

Implementing and integrating security solutions into the system, then verifying that what got built matches what was specified. The part of the job where designs meet real hardware, software, and schedules.

05 Secure Operations, Change Management and Disposal 14%

Developing the secure operations plan, supporting secure operations, participating in change management, and taking a system through disposal at end of life. The smallest domain, and the one candidates most often underestimate.

Domains and weights reflect the ISC2 ISSEP Exam Outline effective August 1, 2025, the version ISC2 administers today.

Frequently Asked Questions

Common Questions About ISSEP.

The questions candidates ask most often when researching the Information Systems Security Engineering Professional certification.

What is the ISSEP certification?

ISSEP is the systems security engineering certification from ISC2, developed in conjunction with the U.S. National Security Agency. It is a standalone credential at the advanced level, earned either by people who already hold a CISSP or by people who qualify on experience alone. It covers five domains and proves you can build security into a system through requirements, design, implementation, verification, operations, and disposal rather than assess it after the fact.

Do you need a CISSP to get the ISSEP?

No. ISSEP is a standalone certification with two qualifying routes, and neither one is a lesser path. Most people take the CISSP route: a current CISSP in good standing plus two years of full-time experience in one or more ISSEP domains. The other route is seven years of cumulative full-time experience across two or more domains with no CISSP, where a relevant degree or an approved ISC2 credential covers one of those years. What actually differs between the two is the CPE load, not the standing of the certification you end up holding.

How much does the ISSEP exam cost in 2026?

The ISSEP exam costs approximately $599 USD as of 2026, set by ISC2 and varying slightly by region. That covers the exam only, not training or courseware. Boot camps often include the voucher in the course price, so check before you buy one separately.

What is the ISSEP exam like?

ISSEP is a linear exam, not an adaptive one. It runs 125 items over three hours, using multiple choice plus advanced item types, and you need a scaled score of 700 out of 1000 to pass. Because it is linear, every candidate sees the same number of questions and you can move through the form at your own pace.

What are the five ISSEP domains?

The five domains are Systems Security Engineering Foundations at 24 percent, Risk Management at 20 percent, Security Planning and Engineering at 22 percent, Systems Security Implementation, Verification and Validation at 20 percent, and Secure Operations, Change Management and Disposal at 14 percent. Foundations is the heaviest, and Planning and Engineering is close behind.

Which ISSEP exam outline is current?

The outline in force took effect August 1, 2025, following ISC2's Job Task Analysis for the advanced certifications. It restructured the credential into the current five domains with new weights. Any study material written against the older outline is out of date, so check the publication date before you buy.

How do CPEs work for ISSEP if you already hold a CISSP?

Held alongside a CISSP, ISSEP carries 60 Group A CPE credits per three-year term, and those credits count toward your CISSP cycle as well. Held on its own it carries 140 Group A CPEs per three-year term. Either way ISC2 charges a single annual maintenance fee of U.S. $135 regardless of how many certifications you hold, so the standalone route does not add a second fee. It means the fee is yours to pay rather than one an existing CISSP already covers.

Was ISSEP developed with the NSA?

Yes. ISC2 states on its ISSEP certification page that the credential was developed in conjunction with the U.S. National Security Agency. That origin is why the exam leans on formal systems engineering process and why the credential carries more weight in defense and federal program work than in commercial security.

Is ISSEP approved for DoD 8140?

Yes. ISC2 lists ISSEP as meeting U.S. DoDM 8140. ISC2 does not publish the role-level DoD Cyber Workforce Framework mapping on its certification page, so check the current qualification matrix at the DoD Cyber Exchange for the specific work roles and proficiency levels a given position requires.

What is the difference between ISSEP, ISSAP and ISSMP?

All three are standalone ISC2 certifications at the advanced level, and they share the same two qualifying routes and the same exam mechanics: 125 items, three hours, 700 out of 1000 to pass, and outlines effective August 1, 2025. ISSEP is engineering, building security into a system across its lifecycle. ISSAP is architecture, designing the security structure of an enterprise. ISSMP is management, running the program and the people. Pick the one that matches what you already do.

Who should get the ISSEP?

ISSEP fits people who sit inside an engineering team rather than a security operations team: systems security engineers, security control assessors, requirements engineers, and defense contractors working to formal process. It is the narrowest of the three advanced ISC2 certifications and the least useful if your work is commercial, cloud-first, or operations-led.

Is ISSEP worth it in 2026?

It depends entirely on where you work. In defense programs, federal systems integration, and critical infrastructure engineering, ISSEP is the credential that names your job and it is approved under DoD 8140. Outside that world it is far less recognized than the CISSP itself, and ISSAP or CCSP will usually open more doors.

Get In Touch

Have Questions About ISSEP?

Whether you're picking between ISSEP, ISSAP and ISSMP, working out funding, or planning training for an engineering team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    ISC2 ISSEP Boot Camp 4-Day Boot Camp ยท Exam Voucher Included
    View Boot Camp