Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Information Systems Security Management Professional (ISSMP)
Certification Explained.

ISSMP is ISC2's standalone certification for security management and leadership, for people who run a security program rather than design or engineer the systems inside it. The route most candidates take pairs an active CISSP in good standing with two years of management experience. The other asks for seven years of experience and no CISSP at all. This guide covers the six domains, the exam, both routes, how CPEs work alongside a CISSP, and how ISSMP compares to ISSAP, ISSEP and CISM.

ISSMP_FAST_FACTS
Issuer: ISC2 (standalone certification)
Routes: CISSP plus 2 yrs, or 7 yrs
Exam: 125 questions, 3 hours
Passing Score: 700 / 1000
DoD 8140 Approved
6 ISSMP Domains TWO Qualification Routes 125 Exam Questions 3-HOUR Exam AUG 2025 Current Outline
UPDATED 2026
Overview

What Is the Information Systems Security Management Professional (ISSMP)?

ISSMP is ISC2's standalone certification for security management, one of three advanced credentials it awards alongside ISSAP and ISSEP.

ISC2 describes an ISSMP as a security leader who specializes in establishing, presenting and governing information security programs, and who aligns those programs with the organization's mission, goals and strategies. In practice that means the exam is about decisions, not configurations. Six domains cover leadership, systems lifecycle, risk, operations, contingency and compliance, and every one of them assumes you are the person accountable for the outcome.

Experience is what ISC2 checks, and it publishes two ways to show it. The first route pairs an active CISSP in good standing with two years of cumulative, full-time experience in one or more ISSMP domains, and that is how most people arrive. The second asks for seven years of cumulative experience in two or more domains and no CISSP at all. Neither route produces a lesser credential: since October 2023 ISSMP has been a standalone certification either way, written after your name as ISSMP, CISSP when you hold both. What does differ is upkeep, at 140 CPE credits a term without a CISSP against 60 with one. The credential is ANAB-accredited under ISO/IEC 17024 and approved under DoD 8140. It is issued and maintained by ISC2, the same body behind the CISSP.

6 Domains
125 Exam Items
700 Passing Score
The ISSMP Domains

Six Domains of Security Management

01

Leadership and Organizational Management

Security vision, governance alignment, policy framework, and running the team. The heaviest domain at 21%.

02

Systems Lifecycle Management

Security requirements through acquisition, development and enterprise architecture. 15% of the exam.

03

Risk Management

Assessment methods, supply chain risk, treatment decisions, and reporting. 20% of the exam.

04

Security Operations

Threat intelligence, monitoring, and incident management from the management chair. 18% of the exam.

05

Contingency Management

Continuity, disaster recovery, resilience, and testing the plans. 12% of the exam.

06

Law, Ethics, and Security Compliance Management

Legal obligations, privacy, ethics, and running the compliance program. 14% of the exam.

Why ISSMP Matters

Why Is ISSMP So Widely Recognized?

Four things that give the certification its weight, starting with the experience ISC2 asks for before it will award it.

Two Routes, One Credential

ISC2 wants proven experience before it awards ISSMP, and it accepts two forms of it: an active CISSP in good standing plus two years of management work in the domains, or seven years of that work across two or more domains with no CISSP involved. Most candidates come through the first, which is why an ISSMP after your name usually reads as a CISSP holder who then chose to specialize in running the program. The seven-year route is not a consolation prize. It awards the same standalone certification, and the only thing it changes is the CPE load.

Rebuilt for 2025 and Beyond

ISC2 rewrote the outline effective August 1, 2025 after a new Job Task Analysis. AI security now runs through all six domains: governing AI adoption, MLSecOps decision gates, the NIST AI Risk Management Framework, prompt injection response, and the EU AI Act.

Cheap to Carry

ISC2 members pay one annual maintenance fee of U.S. $135 regardless of how many certifications they hold, and if you hold a CISSP as well, the 60 CPE credits ISSMP asks for count toward the CISSP's 120. Security leadership roles also sit at the higher end of the pay range: our CISSP salary breakdown has the sourced figures.

DoD 8140 Approved

ISC2 lists ISSMP as approved by the U.S. Department of Defense under DoD Manual 8140.03, alongside its ANAB accreditation to ISO/IEC 17024. That approval is what lets an ISSMP be used as a foundational qualification for cyber workforce coding.

ISC2 publishes the approval but not a role mapping, so we are not listing DCWF work roles or proficiency levels here. The DoD qualification matrix is the authoritative source for those, and it is revised periodically. Check the current version at the DoD Cyber Exchange for the role you are being coded into.

DoDM 8140.03 Approved ISO/IEC 17024 ANAB Accredited
Fast Facts

What Are the Key Facts About ISSMP?

The certification, the exam structure, and what it takes to keep ISSMP current as of 2026. Every figure below comes from ISC2.

01

The Certification

Certification Name
Information Systems Security Management Professional (ISSMP)
Issued By
ISC2
Credential Type
Standalone ISC2 certification
Exam Outline
Effective August 1, 2025
Standalone Since
October 23, 2023
Route A
Active CISSP plus 2 yrs in 1+ domain
Route B
7 yrs cumulative in 2+ domains, no CISSP
Difference Between Routes
CPE load only: 140 per term on Route B, 60 on Route A
Experience Waiver
1 year (degree or approved credential), Route B only
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Approved; ISC2 publishes no role mapping
02

Exam & Maintenance

Exam Format
Multiple choice plus advanced items
Number of Items
125 questions
Exam Duration
3 hours
Passing Score
700 out of 1000
Exam Language
English
Delivery
Pearson VUE test center
Exam Cost
$599 USD (Americas and Asia Pacific)
Validity
3 years
CPE Requirement
60 Group A CPEs over 3 years, with a CISSP
CPEs Without a CISSP
140 Group A CPEs over 3 years
Maintenance
$135 a year; one fee covers all your ISC2 certs
Going Deeper

What Comes After the ISSMP?

ISSMP proves you can govern a security program. From there people either add one of ISC2's technical certifications to cover the design side, or move toward the executive credentials that focus on the business of security.

ISSAP (Architecture)

The architecture certification, four domains across GRC, security architecture modeling, infrastructure and identity. Worth adding if you still make design calls as well as program calls. Same exam mechanics, same qualification routes.

ISSEP (Engineering)

The systems security engineering certification, five domains covering engineering fundamentals, planning, implementation and verification. The natural second credential for managers in federal and defense programs.

CCISO (Executive)

EC-Council's Certified CISO goes further into the executive side: strategic planning, finance, procurement and vendor management. A different flavor of leadership credential for people already in or near the chair.

Certification Roadmap

Where Does ISSMP Fit in Your Career?

ISSMP is not a starting point. It lands at the moment a career turns from doing security to running it, and it leads toward ISSAP and ISSEP or the executive track.

STAGE 02 You Are Here

The Certification

Prove you run the program

PRIMARY
ISSMP
ISC2 ยท Information Systems Security Management Professional
Seven-Year Route
ISC2 ยท Qualify without a CISSP
STAGE 03

Specialize

Pick your path

Sister Certifications
Executive Track
Decision Point

Is ISSMP Right For You?

Two questions to answer before you commit: can you certify, and should you pursue ISSMP rather than one of its siblings. Here's a straight answer to both.

Q1

Do You Qualify for ISSMP?

Path A

Active CISSP Plus Two Years

The route almost everyone takes.

You hold a CISSP in good standing, meaning current CPEs and a paid annual maintenance fee, and you have two years of cumulative, full-time experience in one or more of the six ISSMP domains. Pass the exam and you hold ISSMP in its own right, written after your name as ISSMP, CISSP. If your CISSP has lapsed, that is the first thing to fix, because this route depends on it being active.

Path B

Seven Years, No CISSP

Open to anyone with the years behind them.

Seven years of cumulative, full-time experience in two or more of the domains, with no CISSP required. A bachelor's or master's in computer science, IT or a related field, or another credential from the ISC2 approved list, can cover one year, and one year is the maximum waiver. Part-time work and internships can count. The certification you earn is the same one. The single thing that changes is upkeep: ISC2's maintenance table puts this case at 140 Group A CPE credits over the three-year term instead of 60, because there is no CISSP cycle for them to count toward.

ISC2 lists these two routes and no others on the ISSMP exam outline. If you pass the exam before you meet the experience requirement, you can become an Associate of ISC2 and hold that status for up to eight years while you earn it.

Q2

Is ISSMP the Right Certification for Your Goals?

ISSMP Is a Strong Fit If...

  • You already hold a CISSP and your job has shifted from doing security to running the program
  • You own a security budget, a team, a policy framework, or a board reporting line
  • You want a certification that adds no separate annual fee and folds its CPEs into your CISSP cycle
  • You work in defense or federal contracting and need a DoD 8140 approved management credential
  • Continuity, disaster recovery and compliance are your problems, not somebody else's
  • You are aiming at CISO, senior security executive, or security program manager work

Consider Alternatives If...

  • You do not hold a CISSP and want a shorter experience requirement, where CISM asks five years rather than seven
  • You still design systems for a living, where ISSAP matches the work better
  • You engineer security into systems under a formal process, where ISSEP is the closer match
  • You are early in your career and do not yet have the years behind you, start with CISSP
  • You need a credential a non-specialist recruiter recognizes instantly, where CISSP or CISM travel further
  • You want executive finance and procurement content rather than security program mechanics, where CCISO fits
Career Paths

What Jobs Can You Get With ISSMP?

ISSMP points at leadership roles rather than practitioner ones. ISC2 names the first four of these on its own ISSMP page as the roles the credential is built for.

Executive

Chief Information Security Officer

The role ISSMP is pointed at. Owns the security program end to end: strategy, budget, risk posture, and the conversation with the board. ISC2 names CISO as one of the roles the credential is built for.

Executive

Senior Security Executive

Security leadership below or alongside the CISO, running large parts of the program. The domain mix, heavy on leadership, risk and contingency, maps closely to what the job actually involves.

Executive

Chief Information Officer

IT leadership with security accountability. ISSMP is the credential that shows a CIO can govern a security program rather than only sponsor one, which matters in regulated industries.

Executive

Chief Technology Officer

Technology leadership where security is a standing agenda item. ISC2 lists CTO among the roles ISSMP suits, because the systems lifecycle domain sits squarely in CTO territory.

Program Management

Information Systems Security Manager

Runs security for a system, program or agency component. This is the day-to-day version of the ISSMP domains: policy, risk, operations and continuity, all at once.

Program Management

Security Program Manager

Owns the delivery of the security program: the roadmap, the metrics, the vendor relationships, and the reporting line into governance. Leadership and Organizational Management is the largest domain for a reason.

Comparison

How Does ISSMP Compare to ISSAP, ISSEP and CISM?

The real decision is between the three advanced ISC2 certifications, which share their mechanics and differ only in subject. CISM is the fourth column because it chases the same security manager from outside the ISC2 family.

  ISSMP ISSAP ISSEP CISM
Issuer ISC2 ISC2 ISC2 ISACA
Focus Security program leadership Security architecture Systems security engineering Security management and governance
Domains 6 (21/15/20/18/12/14) 4 (21/22/32/25) 5 (24/20/22/20/14) 4
Exam Linear, 125 items, 3 hrs Linear, 125 items, 3 hrs Linear, 125 items, 3 hrs 150 items, 4 hrs
Credential Type Standalone ISC2 cert Standalone ISC2 cert Standalone ISC2 cert Standalone ISACA cert
Experience CISSP + 2 yrs, or 7 yrs without one CISSP + 2 yrs, or 7 yrs without one CISSP + 2 yrs, or 7 yrs without one 5 yrs infosec, 3 in management
Passing Score 700 / 1000 700 / 1000 700 / 1000 450 / 800
Exam Cost $599 $599 $599 $575 member / $760 non-member
Renewal 60 CPEs with a CISSP, 140 standalone 60 CPEs with a CISSP, 140 standalone 60 CPEs with a CISSP, 140 standalone 120 CPEs over 3 yrs
DoD 8140 Approved Yes Yes Yes Yes
Best For People running the program People designing the systems People engineering the systems Managers outside the ISC2 track

All three share the same two routes. The seven-year route asks for more experience up front and more CPEs afterward, 140 a term instead of 60, but it awards the same standalone certification, and ISC2 charges the same single annual maintenance fee either way. Exam pricing varies by region. For the credential most candidates pair these with, see what the CISSP covers.

Ready to Get Certified?

Train for ISSMP with Training Camp.

Our official ISC2 ISSMP boot camp covers all six domains over four days, with your exam voucher, official ISC2 courseware, and a free retake guarantee included, so working security leaders can get in and out in a week.

View Boot Camp
Dive Deeper

ISSMP Articles and Guides.

Choosing between ISSAP, ISSEP and ISSMP, what the 2025 outlines changed, and how the management track pays.

Featured Comparison

ISSAP vs ISSEP vs ISSMP: A Straight Answer on Which One You Should Pursue

The real decision for a CISSP holder. Architecture, engineering or management, and how to tell which of the three ISC2 advanced certifications matches the job you actually do.

Read Article โ†’
Exam Update

What Changed with ISSEP, ISSAP, and ISSMP

ISC2 rebuilt all three exam outlines in 2025. What moved, what was added, and why study material written for the old outlines will steer you wrong.

Read Article โ†’
Career Path

What Comes After CISSP?

ISSAP, ISSEP and ISSMP are one answer, and for people moving into program leadership ISSMP is the one that fits. A look at where each option leads.

Read Article โ†’
Decision Guide

CISSP vs CISM: Which One Should I Get First?

ISSMP and CISM chase the same security manager. This walks the CISSP and CISM decision that sits underneath it, which is usually the first fork in the road.

Read Article โ†’
DoD 8140

Which Certifications Qualify for DoD 8140 Work Roles? A DCWF Map

How credentials map to work roles and proficiency levels under DoD 8140, and where the management track credentials tend to land in the matrix.

Read Article โ†’
Salary and Demand

CISSP Salary in 2026: Median Pay by Role, Region, and Sector

Sourced pay data for the CISSP population ISSMP candidates come from, broken out by role and sector, with the management track called out separately.

Read Article โ†’
Maintenance

CPE Requirements by Certification Body: A Complete Comparison

How CPE cycles differ between ISC2, ISACA and the rest, which matters when you hold a CISSP and an ISSMP on the same three-year clock.

Read Article โ†’
Curriculum

Inside the Six ISSMP Domains.

The ISSMP exam outline is organized into six domains, each carrying its own weight. Leadership and Risk Management together make up 41 percent. Click any domain for what it covers.

Domains 01-03

Leadership to Risk
01 Leadership and Organizational Management 21%

The heaviest domain. Establishing security's role in organizational culture, vision and mission, aligning the program with governance structures, defining and maintaining a security policy framework, and managing the security team, budget and awareness programs.

02 Systems Lifecycle Management 15%

Managing security across the system lifecycle: integrating security requirements into acquisition and development, overseeing enterprise architecture, and applying the same discipline to machine learning pipelines and the models running in production.

03 Risk Management 20%

Building and running the risk program: risk identification and assessment methodologies, supply chain and third-party risk, risk treatment decisions, control effectiveness, and reporting risk coverage to people who hold the budget.

Domains 04-06

Operations to Compliance
04 Security Operations 18%

Directing the operational side of the program: threat intelligence, monitoring and detection, incident management, and the management questions that come with AI in the SOC, including adversarial attacks against the organization's own models.

05 Contingency Management 12%

Business continuity, disaster recovery and resilience. Planning for disruption, defining recovery objectives, testing the plans, and restoring the data pipelines and services the business actually depends on.

06 Law, Ethics, and Security Compliance Management 14%

Legal and regulatory obligations, privacy and trans-border data flow, ethics, and running a compliance program against a shifting set of rules that now includes AI-specific regulation.

Domains and weights reflect the ISC2 ISSMP Certification Exam Outline effective August 1, 2025, the version ISC2 administers today.

Frequently Asked Questions

Common Questions About ISSMP.

The questions candidates ask most often when researching the Information Systems Security Management Professional certification.

What is the ISSMP certification?

ISSMP is the Information Systems Security Management Professional, one of ISC2's three advanced security certifications alongside ISSAP and ISSEP. It is the management and leadership credential, built for people who establish, present and govern a security program rather than design or engineer the systems inside it. ISC2 created it as a CISSP concentration and made it a standalone certification in October 2023, so there are now two ways to qualify: an active CISSP plus two years in the domains, or seven years of experience without one. The exam covers six domains, from organizational leadership through risk, operations, contingency and compliance.

Do you need a CISSP to earn the ISSMP?

No. ISSMP has been a standalone certification since October 2023, and ISC2 publishes two routes to it. The first, and the one most candidates use, is an active CISSP in good standing, meaning current CPEs and a paid annual maintenance fee, plus two years of cumulative, full-time experience in one or more of the six ISSMP domains. The second is seven years of cumulative, full-time experience in two or more of the domains, with no CISSP involved. Neither route awards a lesser credential. What differs is the upkeep: 140 Group A CPE credits over the three-year term without a CISSP, against 60 when you hold one.

Who should get the ISSMP?

ISSMP fits people who have moved into running a security program: security managers, directors, senior security executives, CISOs and the CIOs and CTOs who carry security accountability. Most candidates already hold a CISSP, and the seven-year route is there for those who do not. If your work is still hands-on architecture or engineering, ISSAP or ISSEP is the better match.

How much does the ISSMP exam cost in 2026?

ISC2 lists the ISSMP exam at U.S. $599 for the Americas and Asia Pacific, with EMEA priced in euros. That covers the exam only, not training or courseware. Boot camps often include the voucher in the course price, so check before you buy one separately.

What is the ISSMP exam like?

The ISSMP exam is 125 items over three hours, using multiple choice plus advanced item types. You need a scaled score of 700 out of 1000 to pass. It is delivered in English only, at Pearson VUE test centers. Note that ISC2's outline states a set 125 items rather than the adaptive item range used for the CISSP exam.

What are the six ISSMP domains?

The six domains are Leadership and Organizational Management at 21 percent, Systems Lifecycle Management at 15 percent, Risk Management at 20 percent, Security Operations at 18 percent, Contingency Management at 12 percent, and Law, Ethics, and Security Compliance Management at 14 percent. Leadership and Risk Management together account for 41 percent of the exam.

Which ISSMP exam outline is current?

The outline in force took effect August 1, 2025, when ISC2 updated all three of its advanced certifications, ISSAP, ISSEP and ISSMP, following a new Job Task Analysis. It reorganized the domains and folded AI security into every one of them, from governing AI adoption in Domain 1 to adversarial attacks in Domain 4 and the EU AI Act in Domain 6. Study material written for the previous outline will not match it.

How do CPEs work for ISSMP if you already hold a CISSP?

You do not run a separate cycle. ISC2 requires 60 Group A CPE credits over the three-year term when ISSMP is held alongside a CISSP, suggested as 20 a year, and those credits count toward the CISSP's own 120-credit requirement rather than sitting on top of it. There is also no extra annual fee: ISC2 members pay a single annual maintenance fee of U.S. $135 no matter how many certifications they hold, so adding ISSMP to a CISSP costs nothing more each year. Someone who holds ISSMP without a CISSP needs 140 Group A credits over the term instead, and pays that same single $135 fee.

Is ISSMP approved for DoD 8140?

Yes. ISC2 lists ISSMP as approved by the U.S. Department of Defense under DoD Manual 8140.03. ISC2 publishes the approval but not a role mapping, so this page claims no DCWF work roles and no proficiency levels. The DoD qualification matrix is the authoritative source for those and it is revised periodically. Check the current version at the DoD Cyber Exchange for the role you are being coded into.

What is the difference between ISSMP, ISSAP and ISSEP?

All three are standalone ISC2 certifications with the same exam mechanics and the same two qualification routes. ISSMP is the management credential, six domains covering leadership, risk, operations, continuity and compliance. ISSAP is the architecture credential, four domains covering security architecture modeling, infrastructure and identity. ISSEP is the engineering credential, five domains covering systems security engineering across the lifecycle. Pick the one that matches the work you do, not the one that sounds most senior.

Is ISSMP or CISM better for a security manager?

They compete for the same person, and the honest answer depends on what you already hold. CISM from ISACA has wider name recognition with recruiters and asks for five years of experience rather than seven. ISSMP goes deeper on contingency and lifecycle management, and if you already hold a CISSP it is the cheaper credential to keep, because its CPEs fold into the cycle you are already running. If you have a CISSP, ISSMP is the lower-friction addition. If you have neither, CISM is usually the more portable first credential.

Is ISSMP worth it in 2026?

For a CISSP holder who runs a security program, ISSMP is a low-cost, low-maintenance way to make that specialization explicit: one exam, no extra annual fee, and CPEs that fold into the CISSP cycle you are already keeping. Without a CISSP it is still open to you through the seven-year route, though the CPE load more than doubles. It is a poor fit if your work is technical rather than managerial, or if you need one credential that a non-specialist recruiter will recognize on sight.

Get In Touch

Have Questions About ISSMP?

Whether you're picking between ISSAP, ISSEP and ISSMP, checking whether your CISSP is still in good standing, or planning training for a leadership team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    ISC2 ISSMP Boot Camp 4-Day Boot Camp ยท Exam Voucher Included
    View Boot Camp