Associate of ISC2 logo
Focused certification exam prep
Start practice

What Is A Associate Of ISC2?

TL;DR
  • Associate of ISC2 is a designation you earn by passing an ISC2 exam before you have the required work experience.
  • The CISSP exam costs US$749 in the Americas and uses Computerized Adaptive Testing with 125-150 items.
  • Passing requires 700 of 1000 points; there is no experience prerequisite to sit the exam itself.
  • CISSP Associates can hold the status for up to six years while accumulating the required experience.

What Is Associate of ISC2, Exactly?

Associate of ISC2 is not a separate exam, a separate certification body, or a watered-down version of a credential. It is a formal designation awarded by ISC2 to people who have passed one of its certification exams but have not yet accumulated the professional work experience required for full certification. In plain terms: you take the exam first, prove your knowledge, and then work toward the experience requirement while holding Associate status.

This matters because ISC2 offers several certifications that carry work-experience requirements - CISSP, CCSP, CSSLP, CGRC, SSCP, ISSAP, ISSEP, and ISSMP - and the Associate pathway is available for any of them. This site focuses on the CISSP route specifically, because it is the highest-volume path into the Associate of ISC2 designation and the one most candidates mean when they ask "what is an Associate of ISC2?"

Quick Definition: Associate of ISC2 = you passed a qualifying ISC2 exam, chose the Associate pathway on your application, and are now building the experience needed to convert to full certification.

If you want the deeper mechanics of eligibility, the Associate of ISC2 Requirements guide walks through every qualifying scenario in detail. For a broader semantic breakdown of the term itself, see Associate Of ISC2 Meaning and What Does Associate Of ISC2 Stand For?.

How You Earn the Associate of ISC2 Designation

The path is more straightforward than most candidates expect:

  1. Register for and pass a qualifying ISC2 certification exam - for this site, that means the CISSP exam.
  2. During the certification application process, select the Associate of ISC2 pathway instead of waiting until you have full experience.
  3. Agree to the ISC2 Code of Ethics and pay the required Annual Maintenance Fee.
  4. Accumulate the required professional experience over the following years, then apply to upgrade to full certification.

Notice what is absent from that list: there is no experience prerequisite to sit the CISSP exam itself. You can study the material, pass the test, and become an Associate of ISC2 the same week - well before you've worked a single day in a qualifying security role.

Key Takeaway

You do not need any prior work experience to take the CISSP exam or to become an Associate of ISC2 - the experience clock only matters when you're ready to upgrade to full certification.

The CISSP Route: Exam Mechanics

Since the CISSP exam is the primary gateway to this designation, understanding its format is essential context for anyone researching "what is an Associate of ISC2."

  • Delivery: The exam is administered by Pearson VUE at ISC2 Authorized PPC and PVTC Select testing centers.
  • Cost: US$749 in the Americas, with regional pricing and applicable taxes varying by the location where the exam is administered.
  • Format: Computerized Adaptive Testing (CAT), delivering 125 to 150 items within a 3-hour window. Items include standard multiple-choice questions mixed with advanced innovative item types.
  • Passing score: You need 700 out of 1000 points to pass.
  • Current outline: The exam outline in effect took hold on April 15, 2024.
  • Languages: Available in English, German, Spanish, Japanese, and Simplified Chinese.

Because the exam is adaptive, the number of questions you see and when the test ends depends on how consistently you're answering correctly relative to the passing standard - not a fixed question count. For a full breakdown of exactly what the 700-point threshold means in practice, see the Associate of ISC2 Passing Score guide. If you're weighing the total cost of the credential - exam fee plus ongoing Associate maintenance - the Associate of ISC2 Certification Cost breakdown lays out every line item.

Retake Rule: If you don't pass on your first attempt, ISC2 enforces waiting periods before you can retake: 30 days after the first attempt, 90 days after the second, and 180 days after the third.

The Eight Domains You'll Be Tested On

The CISSP exam - and therefore the knowledge base behind the Associate of ISC2 designation - spans eight domains. Each is weighted differently in the exam blueprint, and that weighting should directly shape how you allocate study time.

Domain 1: Security and Risk Management (16%)

The heaviest domain on the exam. It covers governance, legal and regulatory issues, risk management, threat modeling, supply chain risk, and security awareness.

  • Highest point value of any single domain - prioritize accordingly
  • Blends legal, policy, and risk-analysis concepts rather than pure technical detail

Domain 2: Asset Security (10%)

Covers data classification, ownership, retention, and protection requirements across the asset lifecycle.

Domain 3: Security Architecture and Engineering (13%)

Focuses on secure design principles, cryptography, and engineering processes that reduce systemic vulnerability.

Domain 4: Communication and Network Security (13%)

Network architecture, secure communication channels, and the controls that protect data in transit.

Domain 5: Identity and Access Management (IAM) (13%)

Identification, authentication, authorization models, and lifecycle management of identities and access.

Domain 6: Security Assessment and Testing (12%)

Designing and executing assessment strategies, audits, and test outputs that validate control effectiveness.

Domain 7: Security Operations (13%)

Day-to-day operational controls, incident response, recovery, and investigative processes.

Domain 8: Software Development Security (10%)

Secure software development lifecycle practices and the controls that get built into applications rather than bolted on afterward.

For a domain-by-domain study plan with concrete subtopics, the Associate of ISC2 Exam Domains Guide goes deeper into each of these eight areas. And if you're still calibrating how tough this material actually is relative to your background, How Hard Is the Associate of ISC2 Exam? is worth reading before you commit to a study timeline.

Associate Status: Fees, Timeline, and Deadline

Passing the exam is only step one. Once you're designated an Associate of ISC2, a few ongoing obligations and deadlines kick in.

  • Annual Maintenance Fee (AMF): US$50 per year while you hold Associate status.
  • Continuing education: 15 CPE credits earned each year.
  • Upgrade fee: When you've met the experience requirement and are endorsed, you pay an US$85 upgrade AMF to convert to full certification - at which point a fresh three-year certification cycle begins.
  • Time limit: You can hold Associate status for one year longer than the underlying certification's experience requirement. For CISSP and CCSP, that's six years. CSSLP allows five, CGRC allows three, SSCP allows two, and ISSAP, ISSEP, and ISSMP each allow eight.
Important nuance: The Associate of ISC2 badge confirms that you're a member of the community and that you've passed a qualifying exam - but it does not disclose which exam you passed. Someone reviewing your profile knows you're an Associate, not necessarily that it was the CISSP exam specifically.

To fully convert to CISSP, you'll eventually need five years of cumulative paid full-time experience in two or more of the eight domains listed above, plus endorsement by a current ISC2 member. Up to one year of that experience requirement can be waived by an approved four-year degree or by holding an approved credential from the ISC2 waiver list. The full mechanics - including which degrees and credentials qualify - are covered in the Requirements guide.

Who Hires Associate of ISC2 Holders

Because the Associate designation signals that you've mastered CISSP-level material without yet having the years in the field, it tends to appeal to a specific hiring segment: organizations that want entry-to-mid-level security staff who already think like experienced practitioners. Common roles that Associates move into while accumulating experience include security analyst, IT auditor, junior GRC analyst, network security administrator, and SOC analyst positions - roles that touch several of the eight domains above (particularly Security Operations, IAM, and Security Assessment and Testing) without requiring five years of prior tenure.

Hiring managers in regulated industries - finance, healthcare, government contracting - often view the Associate of ISC2 credential as a credible signal of foundational knowledge even before the candidate reaches full CISSP status. For a closer look at how this plays out in job postings and title progression, see Associate Of ISC2 Jobs. If you're trying to decide whether the time and fees are worth it relative to your career stage, Is the Associate of ISC2 Certification Worth It? walks through the trade-offs without relying on inflated numbers.

Associate of ISC2 vs. Full CISSP

AspectAssociate of ISC2Full CISSP Certification
Experience requiredNone to hold the status5 years cumulative paid experience in 2+ domains (up to 1 year waivable)
Annual feeUS$50 AMFStandard AMF after US$85 upgrade fee
CPE requirement15 credits per yearOngoing CPE cycle tied to 3-year certification period
Endorsement neededNoYes, by an existing ISC2 member
Time limitUp to 6 years for CISSP pathNot applicable once converted
Badge disclosureConfirms exam passed, not which oneConfirms full CISSP status

Building a Study Plan Around the Domain Weights

Generic study advice - spaced repetition, timed practice blocks, active recall - works fine, but only when it's mapped to the actual domain weighting above. Since Security and Risk Management carries the largest share of exam points at 16%, it deserves the first and most sustained study block, not a footnote.

Weeks 1-2

Security and Risk Management (16%)

  • Governance frameworks, legal and regulatory concepts, risk management methodology
  • Threat modeling and supply chain risk fundamentals
Weeks 3-4

Architecture, Network, and IAM (13% each)

  • Security Architecture and Engineering, Communication and Network Security
  • Identity and Access Management models and lifecycle controls
Weeks 5-6

Operations and Assessment (13% and 12%)

  • Security Operations processes and incident handling
  • Security Assessment and Testing methodology
Weeks 7-8

Asset Security and Software Development (10% each)

  • Data classification and lifecycle protection
  • Secure development lifecycle concepts, then full-length adaptive practice runs

A structured, week-by-week plan like this one is expanded in full in the Associate of ISC2 Study Guide 2026, and you can pressure-test your readiness using timed practice questions on our practice test platform before booking your Pearson VUE appointment. Once you know roughly when you'll be ready, check the Associate of ISC2 Exam Dates guide for scheduling logistics.

Key Takeaway

Study the domains in order of weight, not in the order they're listed - Security and Risk Management first, Asset Security and Software Development last.

Where to Go From Here

Understanding what Associate of ISC2 actually is - a designation, not an exam, earned through the CISSP pathway and held while you build experience - clears up most of the confusion candidates run into. From here, the practical next steps are deciding when to sit the exam, mapping your study time against the eight domains, and getting comfortable with the adaptive question format before test day. A quick pass through our Associate of ISC2 Cheat Sheet is a useful way to sanity-check your recall of the fee structure, domain weights, and retake rules covered here. You can also run full-length timed simulations on our practice test platform to see how the adaptive format actually feels under time pressure.

Frequently Asked Questions

Is Associate of ISC2 a certification or something else?

It's a designation, not a standalone certification. You earn it by passing a qualifying ISC2 exam - most commonly CISSP - and choosing the Associate pathway before you've met the full work-experience requirement.

Do I need work experience to take the CISSP exam and become an Associate?

No. There is no experience prerequisite to sit the exam. Experience only becomes relevant when you're ready to upgrade from Associate status to full CISSP certification.

How long can I stay an Associate of ISC2 before I need to upgrade?

For the CISSP and CCSP pathways, you can hold Associate status for up to six years. Other ISC2 credentials have different limits: five years for CSSLP, three for CGRC, two for SSCP, and eight for ISSAP, ISSEP, and ISSMP.

What does the Associate of ISC2 badge tell an employer?

It confirms that you're part of the ISC2 community and that you've passed a qualifying exam, but it does not specify which exam you passed.

What does it cost to maintain Associate of ISC2 status?

You pay a US$50 Annual Maintenance Fee and must earn 15 CPE credits each year. When you're ready to convert to full certification, there's an additional US$85 upgrade AMF.

Ready to pass your Associate of ISC2 exam?

Put this into practice with free Associate of ISC2 questions across every exam domain.