- What "Associate of ISC2" Actually Means
- How You Earn the Designation Through CISSP
- What the Badge Confirms - and What It Doesn't
- Inside the Exam: The Eight Domains You're Tested On
- Registration, Fees, and Format Mechanics
- Maintaining Associate Status Until Full Certification
- Scheduling Your Prep Around the Domain Weights
- Who Looks for Associate of ISC2 on a Resume
- Frequently Asked Questions
- Associate of ISC2 is a designation, not a separate exam - you earn it by passing an ISC2 exam like CISSP before you have the required experience.
- The CISSP route requires no experience prerequisite to sit the exam; experience is only required to convert to full certification.
- The exam is computerized adaptive, 125-150 items, 3 hours, with a passing score of 700 out of 1000.
- Associates can hold the designation for up to six years for CISSP while accumulating the required experience.
What "Associate of ISC2" Actually Means
Associate of ISC2 is not its own certification exam. It's a status granted by ISC2 to candidates who pass a qualifying ISC2 certification exam - one that normally carries a work-experience requirement - but who haven't yet accumulated that experience. Instead of walking away empty-handed after passing, the candidate selects the Associate pathway during the certification application and is recognized as an Associate of ISC2 while the clock runs on their experience requirement.
This site focuses on the CISSP route into the designation, because it is by far the highest-volume path candidates take. If you've searched "what does Associate of ISC2 mean" hoping for a definition tied to a specific exam blueprint, that's exactly why: the designation itself is generic, but the exam behind it - in this case CISSP - is very specific, with its own domains, format, and fee structure covered below.
How You Earn the Designation Through CISSP
There is no experience prerequisite to sit the CISSP exam. That's the mechanic that makes the Associate of ISC2 designation possible: you can take and pass the exam on day one of your security career, then apply as an Associate instead of a full CISSP holder. If you want the exact eligibility rules spelled out step by step, see our Associate of ISC2 requirements guide.
The exam itself uses Computerized Adaptive Testing (CAT), delivered at ISC2 Authorized PPC and PVTC Select testing centers through Pearson VUE. It runs up to 3 hours and serves between 125 and 150 items, mixing standard multiple-choice questions with advanced innovative item types. Because it's adaptive, the system adjusts question difficulty as you answer, which changes how you should approach pacing and review compared to a fixed-length exam. We break down exactly how this affects difficulty in our full difficulty guide.
To pass, you need 700 out of 1000 scaled points. Our passing score breakdown explains how that scaled score is derived and why it doesn't map to a simple percentage of correct answers.
What the Badge Confirms - and What It Doesn't
Once you've passed and enrolled as an Associate, ISC2 issues a digital badge confirming two things: that you're a member of the ISC2 community, and that you've passed a qualifying exam. Notably, the badge does not disclose which exam you passed. An Associate of ISC2 badge earned via CISSP looks the same, credential-wise, as one earned via another qualifying ISC2 exam - the distinction lives in your ISC2 profile and application record, not in the public badge itself.
This is worth understanding before you list the credential on a resume or LinkedIn profile: employers reading "Associate of ISC2" alone won't automatically know you sat the CISSP exam unless you say so explicitly. Many candidates note the underlying exam directly (e.g., "Associate of ISC2 - CISSP") for clarity.
Key Takeaway
Always specify the exam behind your Associate of ISC2 designation on your resume, since the badge itself doesn't disclose it.
Inside the Exam: The Eight Domains You're Tested On
The current CISSP exam outline took effect April 15, 2024, and is available in English, German, Spanish, Japanese, and Simplified Chinese. It's organized into eight domains, each weighted differently in terms of how much of the exam it represents:
Domain 1: Security and Risk Management (16%)
The heaviest domain on the exam. It covers governance, legal and regulatory issues, risk management, threat modeling, supply chain risk, and security awareness - foundational material that also underpins questions in other domains.
- Governance frameworks and legal/regulatory compliance
- Risk assessment, treatment, and monitoring
- Threat modeling methodologies
- Supply chain risk management
- Security awareness, education, and training programs
Domain 2: Asset Security (10%)
Focuses on classifying, handling, and protecting information and assets throughout their lifecycle.
Domain 3: Security Architecture and Engineering (13%)
Covers secure design principles, cryptography, and engineering processes applied to systems and infrastructure.
Domain 4: Communication and Network Security (13%)
Tests knowledge of secure network architecture and secure communication channels.
Domain 5: Identity and Access Management (IAM) (13%)
Covers controlling how identities are provisioned, authenticated, and authorized across systems.
Domain 6: Security Assessment and Testing (12%)
Focuses on designing and executing assessment, testing, and audit strategies.
Domain 7: Security Operations (13%)
Covers day-to-day operational security, incident response, and recovery activities.
Domain 8: Software Development Security (10%)
Tests understanding of security integrated into the software development lifecycle.
For a deeper walk-through of each domain with subtopics and study priorities, see the complete domain-by-domain guide.
Registration, Fees, and Format Mechanics
The CISSP exam fee is US$749 in the Americas, with regional pricing and taxes varying by the location of administration. Exams are scheduled and delivered through Pearson VUE at ISC2 Authorized PPC and PVTC Select testing centers. For a full cost breakdown, including what happens if you need to retake, read our pricing breakdown.
If you don't pass on your first attempt, retake waiting periods apply: 30 days before your second attempt, 90 days before a third, and 180 days before a fourth. That structure rewards focused, deliberate preparation over repeated quick attempts.
| Item | Detail |
|---|---|
| Exam delivery | Pearson VUE, ISC2 Authorized PPC / PVTC Select centers |
| Format | Computerized Adaptive Testing, 125-150 items, 3 hours |
| Passing score | 700 of 1000 points |
| Exam fee | US$749 (Americas; regional pricing varies) |
| Experience needed to sit exam | None |
| Languages | English, German, Spanish, Japanese, Simplified Chinese |
| Retake waits | 30 / 90 / 180 days |
Maintaining Associate Status Until Full Certification
Passing the exam and becoming an Associate is only the first milestone. Full CISSP certification requires five years of cumulative paid full-time experience in two or more of the eight domains, with up to one year waivable through an approved degree or an approved credential from the ISC2 waiver list, plus endorsement by an existing ISC2 member.
Because most Associates haven't accumulated that experience yet, ISC2 allows Associate status to be held for a defined window while experience is earned - for CISSP and CCSP, that window is six years, one year longer than the underlying five-year experience requirement. Other ISC2 credentials have their own windows: five years for CSSLP, three for CGRC, two for SSCP, and eight for ISSAP, ISSEP, and ISSMP.
If you're weighing whether it's worth pursuing the Associate pathway at all versus waiting until you have experience, our ROI analysis walks through the tradeoffs in more depth.
Scheduling Your Prep Around the Domain Weights
Generic study techniques - spaced repetition, timed practice blocks, active recall - work fine for CISSP prep, but they only pay off when applied against the actual domain weighting. Since Security and Risk Management carries the heaviest weight at 16%, it deserves the largest share of early study time, both because of its own weight and because its concepts (governance, risk, threat modeling) resurface inside other domains.
Security and Risk Management + Asset Security
- Build a strong governance and risk vocabulary first - it recurs throughout the exam
- Cover asset classification and handling lifecycle
Architecture, Networking, and IAM
- Work through Security Architecture and Engineering and Communication and Network Security together, since they share technical overlap
- Add Identity and Access Management once core network concepts are solid
Assessment, Operations, and Development Security
- Practice scenario-based questions for Security Assessment and Testing and Security Operations
- Finish with Software Development Security and run full-length adaptive practice sessions
For a structured, week-by-week plan built specifically around these weights, see the full study guide. You can also pressure-test your readiness with adaptive-style practice questions on the main practice test platform before booking your real exam date.
Who Looks for Associate of ISC2 on a Resume
Because the designation confirms you've passed a rigorous exam without yet holding full field experience, it tends to appeal to employers hiring for entry- and early-career security roles - positions where foundational knowledge across governance, network security, and access management matters more than years on the job. Hiring managers scanning for this credential are often looking to backfill security operations, GRC-support, or junior analyst seats while a candidate builds toward full certification.
If you're mapping out what roles typically value this status and how it compares to holding the full certification, our jobs guide and earnings analysis go deeper on that question. And if you're still comparing certifications broadly before committing, our certification overview is a good starting point, with practice questions available anytime on our exam prep site.
Key Takeaway
List the underlying exam next to "Associate of ISC2" on your resume so hiring managers immediately understand the scope of what you've passed.
Frequently Asked Questions
It's a formal designation from ISC2, not a certification in itself. You earn it by passing a qualifying ISC2 exam, such as CISSP, before completing the required work experience for full certification.
No. There is no experience prerequisite to sit the CISSP exam. Experience is only required later, when you convert Associate status into full CISSP certification.
For the CISSP and CCSP pathways, Associate status can be held for up to six years - one year beyond the five-year experience requirement - while you accumulate qualifying experience.
Associates pay a US$50 Annual Maintenance Fee and must earn 15 CPE credits each year. Converting to full certification later adds an US$85 upgrade fee.
No. The badge confirms ISC2 community membership and that you passed a qualifying exam, but it does not disclose which specific exam - you'll want to state that separately, such as on your resume.