Associate of ISC2 logo
Focused certification exam prep
Start practice

What Does Associate Of ISC2 Mean?

TL;DR
  • Associate of ISC2 is a designation, not a separate exam - you earn it by passing an ISC2 exam like CISSP before you have the required experience.
  • The CISSP route requires no experience prerequisite to sit the exam; experience is only required to convert to full certification.
  • The exam is computerized adaptive, 125-150 items, 3 hours, with a passing score of 700 out of 1000.
  • Associates can hold the designation for up to six years for CISSP while accumulating the required experience.

What "Associate of ISC2" Actually Means

Associate of ISC2 is not its own certification exam. It's a status granted by ISC2 to candidates who pass a qualifying ISC2 certification exam - one that normally carries a work-experience requirement - but who haven't yet accumulated that experience. Instead of walking away empty-handed after passing, the candidate selects the Associate pathway during the certification application and is recognized as an Associate of ISC2 while the clock runs on their experience requirement.

This site focuses on the CISSP route into the designation, because it is by far the highest-volume path candidates take. If you've searched "what does Associate of ISC2 mean" hoping for a definition tied to a specific exam blueprint, that's exactly why: the designation itself is generic, but the exam behind it - in this case CISSP - is very specific, with its own domains, format, and fee structure covered below.

Important distinction: "Associate of ISC2" describes your membership status after passing an exam, not the exam itself. When people ask about the "Associate of ISC2 exam," they typically mean the CISSP exam taken under the Associate pathway.

How You Earn the Designation Through CISSP

There is no experience prerequisite to sit the CISSP exam. That's the mechanic that makes the Associate of ISC2 designation possible: you can take and pass the exam on day one of your security career, then apply as an Associate instead of a full CISSP holder. If you want the exact eligibility rules spelled out step by step, see our Associate of ISC2 requirements guide.

The exam itself uses Computerized Adaptive Testing (CAT), delivered at ISC2 Authorized PPC and PVTC Select testing centers through Pearson VUE. It runs up to 3 hours and serves between 125 and 150 items, mixing standard multiple-choice questions with advanced innovative item types. Because it's adaptive, the system adjusts question difficulty as you answer, which changes how you should approach pacing and review compared to a fixed-length exam. We break down exactly how this affects difficulty in our full difficulty guide.

To pass, you need 700 out of 1000 scaled points. Our passing score breakdown explains how that scaled score is derived and why it doesn't map to a simple percentage of correct answers.

What the Badge Confirms - and What It Doesn't

Once you've passed and enrolled as an Associate, ISC2 issues a digital badge confirming two things: that you're a member of the ISC2 community, and that you've passed a qualifying exam. Notably, the badge does not disclose which exam you passed. An Associate of ISC2 badge earned via CISSP looks the same, credential-wise, as one earned via another qualifying ISC2 exam - the distinction lives in your ISC2 profile and application record, not in the public badge itself.

This is worth understanding before you list the credential on a resume or LinkedIn profile: employers reading "Associate of ISC2" alone won't automatically know you sat the CISSP exam unless you say so explicitly. Many candidates note the underlying exam directly (e.g., "Associate of ISC2 - CISSP") for clarity.

Key Takeaway

Always specify the exam behind your Associate of ISC2 designation on your resume, since the badge itself doesn't disclose it.

Inside the Exam: The Eight Domains You're Tested On

The current CISSP exam outline took effect April 15, 2024, and is available in English, German, Spanish, Japanese, and Simplified Chinese. It's organized into eight domains, each weighted differently in terms of how much of the exam it represents:

Domain 1: Security and Risk Management (16%)

The heaviest domain on the exam. It covers governance, legal and regulatory issues, risk management, threat modeling, supply chain risk, and security awareness - foundational material that also underpins questions in other domains.

  • Governance frameworks and legal/regulatory compliance
  • Risk assessment, treatment, and monitoring
  • Threat modeling methodologies
  • Supply chain risk management
  • Security awareness, education, and training programs

Domain 2: Asset Security (10%)

Focuses on classifying, handling, and protecting information and assets throughout their lifecycle.

Domain 3: Security Architecture and Engineering (13%)

Covers secure design principles, cryptography, and engineering processes applied to systems and infrastructure.

Domain 4: Communication and Network Security (13%)

Tests knowledge of secure network architecture and secure communication channels.

Domain 5: Identity and Access Management (IAM) (13%)

Covers controlling how identities are provisioned, authenticated, and authorized across systems.

Domain 6: Security Assessment and Testing (12%)

Focuses on designing and executing assessment, testing, and audit strategies.

Domain 7: Security Operations (13%)

Covers day-to-day operational security, incident response, and recovery activities.

Domain 8: Software Development Security (10%)

Tests understanding of security integrated into the software development lifecycle.

For a deeper walk-through of each domain with subtopics and study priorities, see the complete domain-by-domain guide.

Registration, Fees, and Format Mechanics

The CISSP exam fee is US$749 in the Americas, with regional pricing and taxes varying by the location of administration. Exams are scheduled and delivered through Pearson VUE at ISC2 Authorized PPC and PVTC Select testing centers. For a full cost breakdown, including what happens if you need to retake, read our pricing breakdown.

If you don't pass on your first attempt, retake waiting periods apply: 30 days before your second attempt, 90 days before a third, and 180 days before a fourth. That structure rewards focused, deliberate preparation over repeated quick attempts.

ItemDetail
Exam deliveryPearson VUE, ISC2 Authorized PPC / PVTC Select centers
FormatComputerized Adaptive Testing, 125-150 items, 3 hours
Passing score700 of 1000 points
Exam feeUS$749 (Americas; regional pricing varies)
Experience needed to sit examNone
LanguagesEnglish, German, Spanish, Japanese, Simplified Chinese
Retake waits30 / 90 / 180 days

Maintaining Associate Status Until Full Certification

Passing the exam and becoming an Associate is only the first milestone. Full CISSP certification requires five years of cumulative paid full-time experience in two or more of the eight domains, with up to one year waivable through an approved degree or an approved credential from the ISC2 waiver list, plus endorsement by an existing ISC2 member.

Because most Associates haven't accumulated that experience yet, ISC2 allows Associate status to be held for a defined window while experience is earned - for CISSP and CCSP, that window is six years, one year longer than the underlying five-year experience requirement. Other ISC2 credentials have their own windows: five years for CSSLP, three for CGRC, two for SSCP, and eight for ISSAP, ISSEP, and ISSMP.

Fees during Associate status: Associates pay an Annual Maintenance Fee of US$50 and are expected to earn 15 CPE credits each year. When you finally accumulate the required experience and endorsement, converting to full certification carries an US$85 upgrade AMF, after which a fresh three-year certification cycle begins.

If you're weighing whether it's worth pursuing the Associate pathway at all versus waiting until you have experience, our ROI analysis walks through the tradeoffs in more depth.

Scheduling Your Prep Around the Domain Weights

Generic study techniques - spaced repetition, timed practice blocks, active recall - work fine for CISSP prep, but they only pay off when applied against the actual domain weighting. Since Security and Risk Management carries the heaviest weight at 16%, it deserves the largest share of early study time, both because of its own weight and because its concepts (governance, risk, threat modeling) resurface inside other domains.

Weeks 1-2

Security and Risk Management + Asset Security

  • Build a strong governance and risk vocabulary first - it recurs throughout the exam
  • Cover asset classification and handling lifecycle
Weeks 3-4

Architecture, Networking, and IAM

  • Work through Security Architecture and Engineering and Communication and Network Security together, since they share technical overlap
  • Add Identity and Access Management once core network concepts are solid
Weeks 5-6

Assessment, Operations, and Development Security

  • Practice scenario-based questions for Security Assessment and Testing and Security Operations
  • Finish with Software Development Security and run full-length adaptive practice sessions

For a structured, week-by-week plan built specifically around these weights, see the full study guide. You can also pressure-test your readiness with adaptive-style practice questions on the main practice test platform before booking your real exam date.

Who Looks for Associate of ISC2 on a Resume

Because the designation confirms you've passed a rigorous exam without yet holding full field experience, it tends to appeal to employers hiring for entry- and early-career security roles - positions where foundational knowledge across governance, network security, and access management matters more than years on the job. Hiring managers scanning for this credential are often looking to backfill security operations, GRC-support, or junior analyst seats while a candidate builds toward full certification.

If you're mapping out what roles typically value this status and how it compares to holding the full certification, our jobs guide and earnings analysis go deeper on that question. And if you're still comparing certifications broadly before committing, our certification overview is a good starting point, with practice questions available anytime on our exam prep site.

Key Takeaway

List the underlying exam next to "Associate of ISC2" on your resume so hiring managers immediately understand the scope of what you've passed.

Frequently Asked Questions

Is Associate of ISC2 a real certification?

It's a formal designation from ISC2, not a certification in itself. You earn it by passing a qualifying ISC2 exam, such as CISSP, before completing the required work experience for full certification.

Do I need experience to become an Associate of ISC2?

No. There is no experience prerequisite to sit the CISSP exam. Experience is only required later, when you convert Associate status into full CISSP certification.

How long can I stay an Associate of ISC2?

For the CISSP and CCSP pathways, Associate status can be held for up to six years - one year beyond the five-year experience requirement - while you accumulate qualifying experience.

What does it cost to maintain Associate status?

Associates pay a US$50 Annual Maintenance Fee and must earn 15 CPE credits each year. Converting to full certification later adds an US$85 upgrade fee.

Does the Associate of ISC2 badge show which exam I passed?

No. The badge confirms ISC2 community membership and that you passed a qualifying exam, but it does not disclose which specific exam - you'll want to state that separately, such as on your resume.

Ready to pass your Associate of ISC2 exam?

Put this into practice with free Associate of ISC2 questions across every exam domain.