- What Is Associate of ISC2, Exactly?
- How the Designation Actually Works
- The Exam Behind the Designation
- The Eight Domains You're Tested On
- Fees, Maintenance, and Upgrading
- How Long You Can Hold Associate Status
- Who Values the Associate of ISC2 Badge
- Mapping a Study Plan to the Domain Weights
- Frequently Asked Questions
- Associate of ISC2 is a designation, not its own exam - it's earned by passing an ISC2 exam like CISSP before you have the required experience.
- The CISSP route uses Computerized Adaptive Testing: 125-150 items, 3 hours, 700/1000 needed to pass.
- Associates pay a $50 Annual Maintenance Fee and log 15 CPE credits each year while working toward full certification.
- You can hold Associate status for up to six years on the CISSP path before it expires.
What Is Associate of ISC2, Exactly?
Associate of ISC2 is a designation awarded by ISC2, the certifying body behind CISSP and several other information security credentials. It is not a certification exam in its own right. Instead, it is the status you receive when you pass the exam for a qualifying ISC2 certification - one that normally requires paid work experience - before you actually have that experience on your resume.
In practice, a candidate sits the full certification exam, passes it, and then chooses the Associate pathway during the application step instead of the full-certification pathway. This lets people who are new to the field, career switchers, or students demonstrate verified knowledge of the domain body of knowledge while they accumulate the required professional experience.
This site focuses specifically on the CISSP route into the designation, because it is the highest-volume path candidates use to earn Associate of ISC2 status. Everything below - the exam format, the fee, the domains, the maintenance requirements - reflects that CISSP-based pathway.
How the Designation Actually Works
The mechanics are straightforward once you separate the exam from the status:
- You register for and sit the CISSP exam through Pearson VUE - no work experience is required to schedule or take it.
- You pass by reaching 700 of 1000 points on the scaled scoring model.
- During the certification application, you select the Associate of ISC2 pathway rather than submitting an endorsement for full certification.
- You receive the Associate of ISC2 badge, which confirms membership in the ISC2 community and that you passed a qualifying exam - without disclosing which specific exam you passed.
- You then work toward accumulating the professional experience needed to convert to full certification later.
Because the underlying test is the CISSP exam, the requirements, question style, and domain weighting for earning the designation are identical to those covered in our Associate of ISC2 requirements breakdown, which walks through eligibility and the experience waiver rules in more depth.
The Exam Behind the Designation
The CISSP exam - the qualifying exam most Associate of ISC2 holders use - is delivered exclusively through Pearson VUE at ISC2 Authorized PPC and PVTC Select testing centers. A few concrete facts candidates should plan around:
- Format: Computerized Adaptive Testing (CAT), which adjusts question difficulty based on your responses in real time.
- Length: Between 125 and 150 items answered within a 3-hour window, mixing standard multiple-choice with advanced innovative item types.
- Passing score: 700 out of 1000 scaled points - see our dedicated passing score guide for how the scaling actually works.
- Fee: US$749 for exams administered in the Americas; pricing and applicable taxes vary by testing region. Full breakdown in our certification cost guide.
- Languages: English, German, Spanish, Japanese, and Simplified Chinese.
- Current outline: The exam content outline in effect since April 15, 2024 governs today's version of the test.
Because CAT exams end once the system is statistically confident in a pass/fail result, session length and item count vary between candidates - this is one reason difficulty perception differs so much test to test. Our difficulty guide unpacks what that adaptive format feels like in the room.
Key Takeaway
Because there's no experience prerequisite to sit the exam, you can attempt it as soon as you're prepared - the experience requirement only matters later, when converting Associate status to full certification.
The Eight Domains You're Tested On
The CISSP exam - and therefore the knowledge base behind Associate of ISC2 - is organized into eight domains. Understanding the relative weight of each helps you allocate study time correctly instead of spreading effort evenly across topics that aren't weighted evenly on the real exam.
Domain 1: Security and Risk Management (16%)
The heaviest domain on the exam. It covers governance, legal and regulatory issues, risk management, threat modeling, supply chain risk, and security awareness.
- Understand how governance frameworks connect to organizational risk appetite
- Know how threat modeling outputs feed into risk treatment decisions
- Be comfortable with supply chain risk concepts, not just internal risk
Domain 2: Asset Security (10%)
Focuses on classifying, handling, and protecting information and physical assets throughout their lifecycle.
Domain 3: Security Architecture and Engineering (13%)
Covers secure design principles, engineering processes, and architecture models candidates must apply to real systems.
Domain 4: Communication and Network Security (13%)
Tests knowledge of secure network architecture, components, and communication channels.
Domain 5: Identity and Access Management (IAM) (13%)
Covers identity lifecycle, access control models, and authentication/authorization mechanisms.
Domain 6: Security Assessment and Testing (12%)
Covers designing and executing assessment strategies, and interpreting security test results.
Domain 7: Security Operations (13%)
Focuses on day-to-day operational security, incident management, and recovery processes.
Domain 8: Software Development Security (10%)
Covers integrating security into the software development lifecycle.
For a domain-by-domain study breakdown with subtopics and sample question angles, see the full exam domains guide.
| Domain | Weight |
|---|---|
| Security and Risk Management | 16% |
| Security Architecture and Engineering | 13% |
| Communication and Network Security | 13% |
| Identity and Access Management (IAM) | 13% |
| Security Operations | 13% |
| Security Assessment and Testing | 12% |
| Asset Security | 10% |
| Software Development Security | 10% |
Fees, Maintenance, and Upgrading
Earning the Associate of ISC2 designation isn't a one-time event - it comes with ongoing obligations that differ from full certification maintenance:
- Annual Maintenance Fee (AMF): US$50 per year while holding Associate status.
- Continuing education: 15 CPE credits earned each year to stay in good standing.
- Upgrade fee: When you accumulate the required experience and convert Associate status to full certification, you pay an US$85 upgrade AMF, which starts a fresh three-year certification cycle.
These figures are separate from the initial exam fee itself, so your total cost of the pathway spans the exam, the annual maintenance while you're an Associate, and the eventual upgrade fee. The cost breakdown article lays out the full timeline of charges in one place.
How Long You Can Hold Associate Status
Associate status isn't indefinite. ISC2 allows you to hold it for one year longer than the experience requirement of the underlying certification you passed. On the CISSP route, that means:
- CISSP and CCSP: up to six years as an Associate
- CSSLP: up to five years
- CGRC: up to three years
- SSCP: up to two years
- ISSAP, ISSEP, ISSMP: up to eight years
For the CISSP path, full certification requires five years of cumulative paid full-time experience across two or more of the eight domains listed above. Up to one year of that requirement can be waived with an approved degree or an approved credential from the ISC2 waiver list, and every candidate needs endorsement from an existing ISC2 member before the full certification is granted. If you retake the exam along the way, note the mandated waiting periods: 30 days after a first attempt, 90 days after a second, and 180 days after a third.
Who Values the Associate of ISC2 Badge
Because the badge confirms that you passed a qualifying ISC2 exam and are an active member of the ISC2 community - without revealing which specific exam - employers generally read it as verified foundational knowledge from someone still building hands-on experience. It's commonly seen on resumes and LinkedIn profiles for:
- Entry-level security analysts and SOC tier-1 staff
- IT professionals transitioning into dedicated security roles
- Students and recent graduates targeting security operations, GRC, or IAM teams
- Career changers who passed the CISSP exam early to signal serious intent before accruing experience
Because the designation itself doesn't disclose the underlying exam, hiring managers familiar with ISC2 credentials typically ask candidates directly which exam they passed and what timeline they're on for full certification. See our Associate of ISC2 jobs overview and salary guide for how this plays into early-career security roles, and the ROI analysis if you're deciding whether the pathway fits your timeline.
Mapping a Study Plan to the Domain Weights
Because Security and Risk Management carries the heaviest weight at 16%, it deserves the earliest and longest block in any study plan - not because it's hardest, but because it touches concepts (governance, risk management, legal and regulatory issues) that reappear inside other domains later. A reasonable sequencing approach:
Security and Risk Management
- Governance structures and legal/regulatory frameworks
- Risk management methodologies and threat modeling
- Supply chain risk and security awareness programs
Architecture, Network Security, and IAM (13% each)
- Secure design principles and engineering models
- Network architecture and communication security
- Identity lifecycle and access control models
Security Operations and Assessment/Testing
- Incident management and operational controls
- Assessment strategy design and interpreting results
Asset Security and Software Development Security
- Classification and asset lifecycle handling
- Security integration across the development lifecycle
Rotate in short daily review sessions using spaced repetition on weak domains rather than re-reading material you've already mastered - this matters more on a CAT-format exam, where consistent competence across domains counts more than deep expertise in just one or two. For a full week-by-week plan built around this structure, see the Associate of ISC2 study guide, and practice under timed, adaptive-style conditions using the question sets on our practice test platform before exam day.
Key Takeaway
Study Security and Risk Management first - its concepts (risk, governance, legal issues) underpin material tested in nearly every other domain.
Frequently Asked Questions
No. It's a designation you receive after passing a qualifying ISC2 exam - most commonly the CISSP exam - and choosing the Associate pathway during the application process instead of submitting for full certification immediately.
No experience is required to sit the CISSP exam or to earn Associate status. Experience only becomes relevant later, when you're ready to convert Associate status into full CISSP certification.
It depends on the underlying exam. On the CISSP path, you can hold Associate status for up to six years - one year longer than CISSP's five-year experience requirement.
Associates pay a US$50 Annual Maintenance Fee and must earn 15 CPE credits each year. Converting to full certification later adds an US$85 upgrade AMF and starts a new three-year certification cycle.
No. The badge confirms ISC2 community membership and that you passed a qualifying exam, but it does not disclose which specific certification exam that was.