Associate of ISC2 logo
Focused certification exam prep
Start practice

Associate Of ISC2 Certification

TL;DR
  • Associate of ISC2 is a designation, not its own exam - you earn it by passing an ISC2 exam with an experience requirement, like CISSP.
  • The CISSP exam costs US$749 in the Americas and uses Computerized Adaptive Testing across 125-150 items in 3 hours.
  • You need 700 of 1000 points to pass, and there's no experience prerequisite to sit the exam itself.
  • Associates can hold the status for up to six years (CISSP) while accumulating the required experience.

What the Associate of ISC2 Designation Actually Is

Associate of ISC2 is not a separate certification exam with its own blueprint. It's a status conferred by ISC2 when a candidate passes a qualifying certification exam that carries a work-experience requirement, but hasn't yet accumulated that experience. During the application process, the candidate selects the Associate pathway instead of waiting to apply for full certification. This site focuses on the CISSP route into Associate of ISC2, since CISSP is by far the highest-volume path candidates take.

The badge itself confirms two things: that the holder passed a recognized ISC2 exam and that they're part of the ISC2 community. It intentionally does not disclose which exam was passed. If you're still mapping out exactly what the designation signals to employers, our companion piece on what Associate of ISC2 actually means goes deeper into that distinction.

Not a Standalone Test: There is no "Associate of ISC2 exam" in isolation. You sit the full CISSP exam - same content, same difficulty, same scoring - and the Associate designation is simply what you're granted while you finish qualifying for full CISSP status.

The CISSP Route: Exam Mechanics

The CISSP exam is delivered exclusively by Pearson VUE at ISC2 Authorized PPC and PVTC Select testing centers. In the Americas, the fee is US$749, with regional pricing and applicable taxes varying by the location where you sit the exam. Because there is no experience prerequisite to register and take the exam, candidates can attempt CISSP the moment they feel prepared - the experience requirement only matters for converting to full certification later.

The exam format is Computerized Adaptive Testing (CAT), meaning the system selects your next item based on how you answered the previous one. Expect 125 to 150 items across a 3-hour session, blending traditional multiple-choice questions with advanced innovative item types designed to test applied judgment rather than rote memorization. A passing result requires 700 out of 1000 scaled points.

The current exam outline took effect April 15, 2024, and remains available in English, German, Spanish, Japanese, and Simplified Chinese. If you're unsure whether your preparation matches the current outline's emphasis, the passing score breakdown is a useful sanity check on how the 700-point threshold interacts with the adaptive scoring model.

Key Takeaway

Because CAT exams adjust difficulty in real time, guessing patterns and question-count tricks don't help. Depth across all eight domains matters more than memorizing a fixed question bank.

The Eight CISSP Domains You'll Be Tested On

Every question on the exam maps to one of eight domains, each weighted differently. Understanding the weighting helps you allocate study hours proportionally instead of spreading effort evenly across topics that don't carry equal exam weight.

Domain 1: Security and Risk Management (16%)

The heaviest domain by a clear margin. It covers governance, legal and regulatory issues, risk management frameworks, threat modeling, supply chain risk, and security awareness programs.

  • Expect scenario questions on policy, compliance, and organizational risk posture
  • Supply chain risk and third-party governance appear more than candidates expect

Domain 2: Asset Security (10%)

Focuses on classification, ownership, and protection of information and assets throughout their lifecycle.

Domain 3: Security Architecture and Engineering (13%)

Covers secure design principles, cryptography, and engineering processes applied to systems and infrastructure.

Domain 4: Communication and Network Security (13%)

Tests network architecture, secure communication channels, and network attack mitigation.

Domain 5: Identity and Access Management (IAM) (13%)

Covers identity lifecycle, access control models, and authentication/authorization mechanisms.

Domain 6: Security Assessment and Testing (12%)

Focuses on designing, conducting, and analyzing security assessments and audits.

Domain 7: Security Operations (13%)

Covers incident management, investigations, disaster recovery, and day-to-day operational security.

Domain 8: Software Development Security (10%)

Covers secure SDLC practices and embedding security throughout software development.

For a full breakdown of subtopics inside each domain and how they interconnect, see the complete domain guide. If you want a condensed reference to keep open during final review, the one-page cheat sheet distills the highest-yield facts per domain.

Registration, Fees, and the Application Path

Registration happens through Pearson VUE, tied to an ISC2 account. After scheduling and paying the exam fee, you sit the CISSP exam at an authorized PPC or PVTC Select center. Passing the exam is only step one - you then complete the certification application, where you formally choose the Associate of ISC2 pathway if you haven't yet met the five-year cumulative paid full-time experience requirement across two or more of the eight domains.

Up to one year of that experience requirement can be waived by an approved four-year degree or an approved credential from the ISC2 waiver list. Full certification also requires endorsement by an existing ISC2 member, which is a formality most candidates complete after passing the exam. For a granular look at fees, waiver mechanics, and what "cumulative paid full-time experience" actually means in practice, the requirements guide and cost breakdown cover both in detail.

Retake Waiting Periods: If you don't pass on your first attempt, ISC2 enforces a 30-day wait before your second attempt, 90 days before a third, and 180 days before a fourth. Plan your study runway accordingly rather than assuming an immediate retake.

Maintaining Associate Status and Upgrading

Holding Associate of ISC2 status isn't passive. Associates pay an Annual Maintenance Fee (AMF) of US$50 and are expected to earn 15 CPE credits each year to stay in good standing. This keeps your knowledge current while you accumulate the professional experience needed for full certification.

Once you've documented the required experience and secured member endorsement, you convert from Associate to full CISSP by paying an US$85 upgrade AMF. At that point, a fresh three-year certification cycle begins under full CISSP status, with its own CPE and maintenance obligations going forward.

Associate status has a shelf life that's tied to the underlying certification's experience requirement, plus one extra year of buffer. For CISSP and CCSP, that means Associate status can be held for up to six years. The table below shows how this varies across other ISC2 credentials.

Who Hires Associates of ISC2

Because the Associate badge confirms a passed exam and community membership without naming the exam, employers generally evaluate candidates on the underlying skill set implied by the CISSP route: security governance, risk management, architecture, and operations knowledge. In practice, organizations hiring for security analyst, risk analyst, GRC coordinator, and junior security engineering roles frequently list Associate of ISC2 (via CISSP) as a preferred or accelerating credential, since it signals the candidate has already cleared the exam bar and is actively working toward full certification.

If you're evaluating whether pursuing this path fits your career stage, the ROI analysis and jobs overview both look at how the designation is actually used in hiring pipelines, separate from full CISSP requirements.

A Domain-Weighted Study Approach

Generic study techniques - spaced repetition, active recall, timed practice blocks - only help if they're applied against the right domain weighting. Given that Security and Risk Management carries the heaviest weight at 16%, it deserves a proportionally larger share of early study time, since concepts from that domain (governance, risk frameworks, threat modeling) also resurface as context in scenario questions from other domains.

Weeks 1-2

Security and Risk Management + Asset Security

  • Build governance and risk-framework vocabulary first since it recurs across scenario questions
  • Practice classification and lifecycle questions for Asset Security
Weeks 3-4

Architecture, Networking, and IAM

  • Work through cryptography and secure design principles
  • Drill access control models until they're automatic, not memorized
Weeks 5-6

Assessment, Operations, and Software Development Security

  • Practice full-length adaptive-style question sets under time pressure
  • Review weak domains identified from practice test scoring

For a fuller walkthrough of pacing, resource selection, and how to sequence review before test day, the study guide lays out a complete plan. And if you're still calibrating how tough the adaptive format really feels compared to a fixed-form exam, the difficulty guide addresses that directly, while our practice test platform lets you rehearse under conditions closer to the real CAT experience than static question banks can offer.

Associate Timelines by Certification

Associate status duration is tied to how long the underlying certification's experience requirement typically takes to satisfy, plus a one-year buffer. Here's how the CISSP route compares to other ISC2 credentials that also offer the Associate pathway.

CertificationExperience RequirementMax Years as Associate
CISSP5 years6 years
CCSP5 years6 years
CSSLP4 years5 years
CGRC2 years3 years
SSCP1 year2 years
ISSAP / ISSEP / ISSMP7 years8 years

Since this site is built around the CISSP path specifically, the six-year Associate window gives most candidates ample runway to accumulate the required two-or-more-domain professional experience while paying the modest US$50 AMF and logging 15 CPE credits annually. For a deeper look at how these numbers stack up against total cost of certification over time, see the cost breakdown, and if compensation trends are part of your decision-making, the salary guide covers what the designation tends to signal in job postings.

Frequently Asked Questions

Is Associate of ISC2 its own exam?

No. It's a designation you receive after passing a qualifying ISC2 exam - such as CISSP - and choosing the Associate pathway during the certification application because you haven't yet met the experience requirement.

How much does the CISSP exam cost under this pathway?

The exam fee is US$749 in the Americas. Pricing and applicable taxes vary by the region where the exam is administered, since it's delivered through Pearson VUE at authorized testing centers worldwide.

How long can I stay an Associate of ISC2 before upgrading?

For the CISSP route, up to six years - one year longer than the five-year experience requirement itself, giving you a buffer to accumulate qualifying work experience.

What happens if I fail the CISSP exam?

You must wait 30 days before your second attempt, 90 days before a third, and 180 days before a fourth. Each retake requires paying the exam fee again.

Does the Associate badge reveal which exam I passed?

No. The badge confirms you passed a qualifying ISC2 exam and are part of the ISC2 community, but it does not disclose which specific exam you completed.

Ready to pass your Associate of ISC2 exam?

Put this into practice with free Associate of ISC2 questions across every exam domain.