Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
ISSEP is the ISC2 systems security engineering certification, developed in conjunction with the U.S. National Security Agency. This guide covers the five domains, the linear 125-item exam, the two qualifying routes, career paths, DoD 8140 status, and how ISSEP compares to ISSAP and ISSMP. Start with qualifying: most candidates come in holding an active CISSP plus two years in the ISSEP domains, and there is a seven-year experience route for everyone else.
ISSEP is one of three advanced certifications from ISC2, and it is the engineering one. ISC2 created it as a CISSP concentration and made it a standalone certification in October 2023, so today it stands on its own rather than hanging off another credential. ISC2 developed it in conjunction with the U.S. National Security Agency.
The distinction that matters: a CISSP proves you understand security across the enterprise. An ISSEP proves you can engineer it into a specific system, working the same lifecycle a systems engineer works. Requirements come first, then design, then implementation and verification, then secure operations, change management, and disposal. Five domains, weighted toward the front of that lifecycle, where the expensive mistakes get made.
That NSA origin is why the credential reads the way it does, and why it carries the most weight in defense programs, federal systems integration, and critical infrastructure engineering. It is ANAB-accredited under ISO/IEC 17024 and listed by ISC2 as meeting U.S. DoDM 8140. ISSEP is issued and maintained by ISC2.
The engineering process, technical management, and procurement. The heaviest domain at 24%.
Risk principles applied to the system and to operations. 20% of the exam.
Environment analysis, security principles, requirements, and system security design. 22%.
Integrating security solutions and proving the build matches the spec. 20% of the exam.
Running the system, changing it safely, and retiring it. 14% of the exam.
ISSEP is a small credential compared to the CISSP. Four things give it disproportionate weight in the places it is recognized.
ISC2 states that ISSEP was developed in conjunction with the U.S. National Security Agency. No other ISC2 credential carries that line. It is the reason the exam is built around formal engineering process rather than tooling, and the reason program offices treat it as a signal about how you work, not just what you know.
Most people qualify with a current CISSP plus two more years in the ISSEP domains. The rest qualify on seven years of cumulative experience across two or more domains, with no CISSP involved. Either way the experience bar is high, so the credential filters for seniority before anyone sits the exam.
Security engineering roles on defense and federal programs sit at the senior end of the pay scale, and ISSEP is frequently the credential named in the posting. Our look at the highest-paid cybersecurity jobs puts the range in context.
ISC2 lists ISSEP as meeting U.S. DoDM 8140, alongside its ANAB accreditation. With element-level qualification now mandatory across the department under DoD Manual 8140.03, an approved credential is what lets someone hold a cyber workforce role at all.
ISC2 does not publish a role-level DoD Cyber Workforce Framework mapping for ISSEP on its certification page, so we do not list work role counts here. Check the current qualification matrix at the DoD Cyber Exchange for the roles and proficiency levels a specific billet requires.
The two qualifying routes, the exam structure, and how maintenance changes depending on whether you also hold a CISSP, as of 2026.
ISSEP proves you can engineer security into a system. From there people usually widen the aperture, either to the architecture of the whole enterprise, to running the program, or to the cloud environments the next system will live in.
The architecture certification, standalone like ISSEP and reachable by the same two routes. Same 125-item exam, four domains covering governance, security architecture modeling, infrastructure, and identity architecture. The move for engineers who start designing across systems instead of within one. Read the ISSAP guide.
The management certification, the third of the ISC2 advanced three. Six domains covering leadership, lifecycle management, risk, operations, contingency, and compliance. The move for engineers heading toward running the program rather than building the system. Read the ISSMP guide.
A different shape of ISC2 credential, with its own five-year experience requirement rather than the ISSEP routes. Worth adding when the systems you engineer stop being racks and start being someone else's data center. Six domains, adaptive exam, five years of experience. Read the CCSP guide.
ISSEP is a late-career move, not an early one. Most people arrive holding a CISSP, and from there the usual next steps are ISSAP or ISSMP.
How most candidates arrive
Engineering specialization
Two questions to answer before you commit: can you certify, and should you pick ISSEP over ISSAP or ISSMP. Here's a straight answer to both.
The CISSP route.
You hold a current CISSP in good standing and have two years of full-time experience in one or more ISSEP domains. Pass the exam and you write it as ISSEP, CISSP: two standalone certifications side by side, not one nested inside the other. Maintenance is 60 Group A CPEs per three-year term, and those credits count toward your CISSP cycle as well. This is the route almost everyone takes.
The experience route.
ISC2 also lists a route for candidates without a CISSP: seven years of cumulative full-time experience across two or more ISSEP domains. A relevant bachelor's or master's degree, or an approved ISC2 credential, covers one of those years. You earn exactly the same certification this way, and the only real difference is the maintenance load: 140 Group A CPEs per three-year term instead of 60. ISC2 members pay a single annual maintenance fee of U.S. $135 regardless of how many certifications they hold, so on the CISSP route your existing fee already covers it, while on this route the fee is your own. If you pass before you meet the experience requirement, you can hold Associate of ISC2 status for up to eight years while you earn it.
ISSEP lines up with the engineering side of security work, concentrated in defense programs, federal systems integrators, and critical infrastructure.
The role the credential is named for. Sits inside a program team and owns security requirements, design, and verification from concept through disposal. The most common title on ISSEP job postings.
Works security into the wider systems engineering process rather than bolting it on at the end. Trades requirements, interfaces, and constraints with the rest of the engineering team.
Evaluates whether the controls a system claims are actually implemented and effective. The ISSEP risk management and verification domains map onto this work almost directly.
Turns policy, mission need, and threat into testable system security requirements, then defends them through design reviews. Domain 3 is largely about this job.
Works on classified or controlled systems for a prime or an integrator, where a DoD 8140 approved credential is often a contract condition rather than a preference.
Designs the security of a system rather than an enterprise. Overlaps with ISSAP, but stays closer to the build than to the reference architecture.
This is the real decision. All three are standalone ISC2 certifications with identical exam mechanics and the same two qualifying routes. What separates them is the job they describe: engineering, architecture, or management.
| ISSEP | ISSAP | ISSMP | |
|---|---|---|---|
| Discipline | Systems security engineering | Security architecture | Security management |
| Scope of Work | One system, whole lifecycle | The enterprise structure | The program and the people |
| Domains | 5 | 4 | 6 |
| Heaviest Domain | Engineering Foundations, 24% | Infrastructure and System Security, 32% | Leadership and Org Management, 21% |
| Exam Format | Linear, 125 items, 3 hrs | Linear, 125 items, 3 hrs | Linear, 125 items, 3 hrs |
| Passing Score | 700 / 1000 | 700 / 1000 | 700 / 1000 |
| Qualifying Routes | CISSP + 2 yrs, or 7 yrs cumulative | CISSP + 2 yrs, or 7 yrs cumulative | CISSP + 2 yrs, or 7 yrs cumulative |
| Exam Outline | Effective Aug 1, 2025 | Effective Aug 1, 2025 | Effective Aug 1, 2025 |
| NSA Co-Developed | Yes | Not stated by ISC2 | Not stated by ISC2 |
| Best For | Engineers on defense and federal systems | Architects designing across systems | Managers running security programs |
All three open on the same two routes, and the CISSP one is the route most people take, so start with the CISSP if you do not hold it. If you do, read the ISSAP and ISSMP guides before you commit, and pick the one that matches the work already on your calendar.
Our official ISC2 ISSEP boot camp covers all five domains over four days, aligned to the exam outline effective August 1, 2025, with your exam voucher, official ISC2 courseware, and a free retake guarantee included.
Choosing between the three advanced ISC2 certifications, what changed in the 2025 outlines, and the engineering background behind the exam.
The only comparison that matters once you hold a CISSP. Architecture, engineering, or management, and how to tell which of the three your actual job looks like.
ISC2 rewrote all three exam outlines. What moved, what got dropped, and why study material bought before the change no longer matches the exam.
The CISSP is a starting point, not the destination. Where the three advanced ISC2 certifications sit among the credentials people add next, and who each one actually suits.
A systems engineering concept that turns up throughout the ISSEP material. Useful background if you came to engineering from the security side rather than the other way around.
How the DoD 8140 qualification matrix works, which credentials map where, and what element-level qualification means for people in defense engineering roles.
Most ISSEP candidates qualify through the CISSP, so that credential is worth understanding first. A full walkthrough of what CISSP covers and requires.
Adding a second ISC2 certification changes your CPE picture. How the CISSP renewal cycle works, and what the single annual maintenance fee does and does not cover.
The ISSEP Common Body of Knowledge is organized into five domains that follow the system lifecycle in order, each carrying its own weight on the exam. Click any domain for what it covers.
The heaviest domain. Systems security engineering fundamentals, executing the engineering process, integrating security into the system development methodology, technical management, technology procurement management, and resource analysis.
Applying security risk management principles, managing risk to the system, and managing risk to operations. This is where engineering meets the assessment and authorization work that federal programs run on.
Analyzing the organizational and operational environment, applying system security principles, developing system requirements, and creating the system security design. The second heaviest domain.
Implementing and integrating security solutions into the system, then verifying that what got built matches what was specified. The part of the job where designs meet real hardware, software, and schedules.
Developing the secure operations plan, supporting secure operations, participating in change management, and taking a system through disposal at end of life. The smallest domain, and the one candidates most often underestimate.
Domains and weights reflect the ISC2 ISSEP Exam Outline effective August 1, 2025, the version ISC2 administers today.
The questions candidates ask most often when researching the Information Systems Security Engineering Professional certification.
ISSEP is the systems security engineering certification from ISC2, developed in conjunction with the U.S. National Security Agency. It is a standalone credential at the advanced level, earned either by people who already hold a CISSP or by people who qualify on experience alone. It covers five domains and proves you can build security into a system through requirements, design, implementation, verification, operations, and disposal rather than assess it after the fact.
No. ISSEP is a standalone certification with two qualifying routes, and neither one is a lesser path. Most people take the CISSP route: a current CISSP in good standing plus two years of full-time experience in one or more ISSEP domains. The other route is seven years of cumulative full-time experience across two or more domains with no CISSP, where a relevant degree or an approved ISC2 credential covers one of those years. What actually differs between the two is the CPE load, not the standing of the certification you end up holding.
The ISSEP exam costs approximately $599 USD as of 2026, set by ISC2 and varying slightly by region. That covers the exam only, not training or courseware. Boot camps often include the voucher in the course price, so check before you buy one separately.
ISSEP is a linear exam, not an adaptive one. It runs 125 items over three hours, using multiple choice plus advanced item types, and you need a scaled score of 700 out of 1000 to pass. Because it is linear, every candidate sees the same number of questions and you can move through the form at your own pace.
The five domains are Systems Security Engineering Foundations at 24 percent, Risk Management at 20 percent, Security Planning and Engineering at 22 percent, Systems Security Implementation, Verification and Validation at 20 percent, and Secure Operations, Change Management and Disposal at 14 percent. Foundations is the heaviest, and Planning and Engineering is close behind.
The outline in force took effect August 1, 2025, following ISC2's Job Task Analysis for the advanced certifications. It restructured the credential into the current five domains with new weights. Any study material written against the older outline is out of date, so check the publication date before you buy.
Held alongside a CISSP, ISSEP carries 60 Group A CPE credits per three-year term, and those credits count toward your CISSP cycle as well. Held on its own it carries 140 Group A CPEs per three-year term. Either way ISC2 charges a single annual maintenance fee of U.S. $135 regardless of how many certifications you hold, so the standalone route does not add a second fee. It means the fee is yours to pay rather than one an existing CISSP already covers.
Yes. ISC2 states on its ISSEP certification page that the credential was developed in conjunction with the U.S. National Security Agency. That origin is why the exam leans on formal systems engineering process and why the credential carries more weight in defense and federal program work than in commercial security.
Yes. ISC2 lists ISSEP as meeting U.S. DoDM 8140. ISC2 does not publish the role-level DoD Cyber Workforce Framework mapping on its certification page, so check the current qualification matrix at the DoD Cyber Exchange for the specific work roles and proficiency levels a given position requires.
All three are standalone ISC2 certifications at the advanced level, and they share the same two qualifying routes and the same exam mechanics: 125 items, three hours, 700 out of 1000 to pass, and outlines effective August 1, 2025. ISSEP is engineering, building security into a system across its lifecycle. ISSAP is architecture, designing the security structure of an enterprise. ISSMP is management, running the program and the people. Pick the one that matches what you already do.
ISSEP fits people who sit inside an engineering team rather than a security operations team: systems security engineers, security control assessors, requirements engineers, and defense contractors working to formal process. It is the narrowest of the three advanced ISC2 certifications and the least useful if your work is commercial, cloud-first, or operations-led.
It depends entirely on where you work. In defense programs, federal systems integration, and critical infrastructure engineering, ISSEP is the credential that names your job and it is approved under DoD 8140. Outside that world it is far less recognized than the CISSP itself, and ISSAP or CCSP will usually open more doors.
Whether you're picking between ISSEP, ISSAP and ISSMP, working out funding, or planning training for an engineering team, tell us where you are and we'll help you map out the right path.