- Associate of ISC2 is a designation, not its own exam - this site covers the CISSP route into it.
- The CISSP exam is CAT-based: 125-150 items, 3 hours, 700/1000 to pass, no experience needed to sit it.
- Security and Risk Management is the heaviest domain at 16% of the outline.
- Associates pay a $50 Annual Maintenance Fee and log 15 CPEs yearly; upgrading to full CISSP costs an $85 AMF.
What Associate of ISC2 Actually Is
Associate of ISC2 is governed directly by ISC2, and it isn't a test you register for by name. It's a status you receive after passing any ISC2 certification exam that has a work-experience requirement attached to it - CISSP, CCSP, CSSLP, CGRC, SSCP, ISSAP, ISSEP, or ISSMP - and then choosing the Associate pathway when you submit your certification application instead of (or before) satisfying the full experience requirement. This site focuses specifically on the CISSP route, because it's the highest-volume path candidates use to earn the designation.
One detail trips people up: the Associate badge itself only confirms that you passed an ISC2 exam and that you're part of the ISC2 community. It does not publicly disclose which exam you passed. If you want the full picture of what the badge does and doesn't communicate, the What Is Associate Of ISC2? breakdown and the Associate Of ISC2 Meaning article both dig into that distinction in more depth.
CISSP Exam Mechanics at a Glance
Since the CISSP exam is the mechanism that gets you here, know its format cold before test day:
- Delivered by Pearson VUE at ISC2 Authorized PPC and PVTC Select testing centers.
- Uses Computerized Adaptive Testing (CAT), with 125 to 150 items across a 3-hour window.
- Item types mix standard multiple-choice with advanced innovative formats - not just single-answer recall.
- Passing requires 700 out of 1000 scaled points.
- There is no experience prerequisite to sit the exam - the experience requirement only affects whether you land as Associate or full CISSP after you pass.
- The current exam outline took effect April 15, 2024, and remains the baseline for 2026 testing.
- Available in English, German, Spanish, Japanese, and Simplified Chinese.
Because it's adaptive, the exam can end anywhere between 125 and 150 items depending on how consistently you're answering correctly, which changes how you should pace yourself compared to a fixed-length test. For a deeper walkthrough of what that actually feels like under time pressure, see How Hard Is the Associate of ISC2 Exam? Complete Difficulty Guide 2026, and for the scoring mechanics specifically, Associate of ISC2 Passing Score 2026: Exactly What You Need to Pass is worth bookmarking.
The Eight Domains, One Line Each
The exam outline splits into eight domains with different weightings. Treat the percentages as your study-time budget, not just trivia.
Domain 1: Security and Risk Management (16%)
The heaviest domain. Covers governance, legal and regulatory issues, risk management frameworks, threat modeling, supply chain risk, and security awareness programs.
- Expect scenario questions on policy, risk treatment options, and third-party risk
Domain 2: Asset Security (10%)
Classification, ownership, and handling of information and assets throughout their lifecycle.
Domain 3: Security Architecture and Engineering (13%)
Secure design principles, models, and engineering processes applied to systems and facilities.
Domain 4: Communication and Network Security (13%)
Secure network architecture, components, and communication channels.
Domain 5: Identity and Access Management (IAM) (13%)
Controlling physical and logical access to assets, including identity lifecycle and authorization mechanisms.
Domain 6: Security Assessment and Testing (12%)
Designing, conducting, and analyzing security assessment and audit strategies.
Domain 7: Security Operations (13%)
Investigations, incident management, disaster recovery, and day-to-day operational security.
Domain 8: Software Development Security (10%)
Security integrated across the software development lifecycle and secure coding concepts.
For a full walkthrough of every subtopic inside each domain, the standalone Associate of ISC2 Exam Domains 2026: Complete Guide to All 8 Content Areas article is the deeper companion to this cheat sheet.
Registration and Fee Facts
Fees are one of the most commonly misquoted details across ISC2 credentials, so keep the numbers straight:
- The CISSP exam fee is US$749 in the Americas; regional pricing and taxes vary by the location of administration elsewhere.
- Once you're an Associate, you pay a US$50 Annual Maintenance Fee (AMF) each year.
- You're also expected to earn 15 CPE credits per year while holding Associate status.
- When you eventually convert to full certification, you pay an additional US$85 upgrade AMF, at which point a fresh three-year certification cycle begins.
A full breakdown of how these figures stack up over multiple years - and where most of the real cost actually sits - is covered in Associate of ISC2 Certification Cost 2026: Complete Pricing Breakdown.
Key Takeaway
Budget for the $749 exam fee, then the recurring $50 AMF while you hold Associate status, then the one-time $85 upgrade AMF when you finally convert to full certification.
Associate Status Timelines by Credential
Associate status isn't indefinite. ISC2 allows you to hold it for one year longer than the underlying certification's own experience requirement - the clock varies by which exam you passed.
| Certification Track | Years Associate Status Can Be Held |
|---|---|
| CISSP | 6 years |
| CCSP | 6 years |
| CSSLP | 5 years |
| CGRC | 3 years |
| SSCP | 2 years |
| ISSAP | 8 years |
| ISSEP | 8 years |
| ISSMP | 8 years |
Since this site is built around the CISSP path, the number that matters most for most readers is six years - the window you have to accumulate the required experience before your Associate status needs to convert. If you're unsure whether you currently qualify for full certification or still need Associate status, the Associate of ISC2 Requirements 2026: Eligibility, Prerequisites & How to Qualify guide walks through eligibility in detail.
Retake Waiting Periods
If you don't pass on your first attempt, ISC2 enforces escalating waiting periods before you can retake the exam:
- 30 days before your second attempt
- 90 days before your third attempt
- 180 days before any attempt after that
These waiting periods make first-attempt preparation far more valuable than treating the exam as something you can just retake quickly. For a data-informed look at how attempts play out, see Associate of ISC2 Pass Rate 2026: What the Data Shows.
From Associate to Full Certification
Converting from Associate of ISC2 to full CISSP requires:
- Five years of cumulative paid full-time work experience across two or more of the eight domains.
- Up to one year waived by an approved four-year college degree, or by an approved credential from the ISC2 waiver list.
- Endorsement by an existing ISC2 member who can attest to your professional experience.
Once endorsement and experience verification clear, you pay the $85 upgrade AMF and a new three-year certification cycle starts from that point. This is the moment your Associate badge becomes a full CISSP credential rather than a passed-exam-only status.
A Domain-by-Domain Review Cadence
Rather than a generic study calendar, structure your remaining review time around domain weight. Give Security and Risk Management (16%) the most calendar days since it's both the heaviest domain and the broadest in scope - governance, legal issues, risk frameworks, threat modeling, supply chain risk, and awareness programs all live there. Communication and Network Security, Identity and Access Management, and Security Operations (13% each) deserve roughly equal secondary blocks. Asset Security and Software Development Security (10% each) can be compressed into shorter review sessions since they're narrower in scope, provided you've already covered adjacent architecture and operations material.
Security and Risk Management
- Governance structures, legal/regulatory frameworks, risk management processes
- Threat modeling exercises and supply chain risk scenarios
Architecture, Network, and IAM
- Security Architecture and Engineering, Communication and Network Security
- Identity and Access Management lifecycle and authorization models
Assessment, Operations, and Development
- Security Assessment and Testing methodologies
- Security Operations, incident handling, and Software Development Security
Asset Security and Full Review
- Asset classification and handling
- Mixed-domain practice under timed, adaptive-style conditions
For a complete pass-first-time framework built around this same domain logic, see Associate of ISC2 Study Guide 2026: How to Pass on Your First Attempt. And if you'd rather test your readiness than just read about it, run through timed questions on the main practice test platform before committing to an exam date.
Who Looks for This Designation
Hiring managers screening for security roles increasingly recognize Associate of ISC2 as a signal that a candidate has cleared a rigorous, adaptively-scored exam even before they've hit the full experience threshold. Because the badge doesn't disclose which underlying exam was passed, employers who care about the specific domain (CISSP-level architecture and governance versus, say, a narrower operational credential) typically ask directly during interviews. If you're mapping this designation to job search strategy, Associate Of ISC2 Jobs and Associate of ISC2 Salary Guide 2026: Complete Earnings Analysis go into how the status is positioned on resumes and in postings. And if you're still deciding whether the whole path is worth pursuing given your timeline, Is the Associate of ISC2 Certification Worth It? Complete ROI Analysis 2026 weighs that decision directly.
For structured coursework rather than self-study, Associate Of ISC2 Training covers the formal training options available around the CISSP domains, and the practice test platform is the fastest way to see which of the eight domains still need work before you lock in a testing date.
Frequently Asked Questions
No. You take the underlying certification exam - CISSP on this site's focus - and the Associate pathway is selected during the application process if you haven't yet met the experience requirement.
The CISSP exam uses Computerized Adaptive Testing with 125 to 150 items delivered over a 3-hour window, mixing multiple-choice and advanced innovative item types.
You need 700 out of 1000 scaled points to pass.
Up to six years on the CISSP track - one year longer than the five-year experience requirement itself.
A US$50 Annual Maintenance Fee, plus earning 15 CPE credits annually. Converting to full certification later adds a one-time US$85 upgrade AMF.