As artificial intelligence (AI) continues to reshape cybersecurity, ISC2 has been actively evolving alongside the profession—building resources, guidance and learning pathways to help members adapt and lead.
With the recent announcement of an AI Security certification development effort, we spoke with Donna Butterbaugh, Sr. Director, Examinations and Thomas Jackson, Sr. Exam Content Development Manager, who are leading the ISC2 AI certification development program, about how this work fits into ISC2’s broader AI strategy and what it means for the profession.
There’s been a lot of discussion around AI at ISC2. How should members think about this latest announcement?
The most important thing to understand is that this isn’t a starting point—it’s the next step in an ongoing journey.
ISC2 and our members have been exploring how AI impacts cybersecurity practice for several years now. Our recent Cybersecurity Workforce Study affirmed this. Some 28% of respondents see AI-enabled security tools already being integrated into their organizations' security operations, while another 41% are actively testing or evaluating them. On top of this, nearly all of the respondents to ISC2’s 2026 AI Survey expressed concern that AI errors or failures could scale rapidly across systems if left unchecked, a point that highlights just how significant the impact of AI is on the cybersecurity workplace as well as organizations as a whole.
The certification development effort is part of a broader, coordinated strategy to help define how the profession evolves as AI becomes more integrated into everyday work.
What does that broader strategy look like?
It’s about building a continuum of support for members at every stage of learning and professional development.
ISC2 has invested across multiple areas—education, guidance, research and community engagement—to ensure members can both understand AI and apply it in their roles. The certification is a natural extension of that work, focused specifically on validating professional expertise now and as the field matures further.
Let’s talk about the ISC2 Exam Guidance for AI document. Why was that such an important initiative?
ISC2 has been incorporating emerging technologies like AI into the exam outlines for several years. This document was created for greater public awareness of our efforts.
These ongoing endeavors ensure our existing certifications continue to evolve alongside the profession and take an all-encompassing approach, rather than leaving any major technology area or skillset to just a standalone qualification.
That’s critical—it reinforces that AI is not a niche topic. It is part of modern cybersecurity practice whereby AI is already woven into most cybersecurity functions, in the same way that, for example, risk management, ethics and governance are.
How does the Exam Guidance for AI differ from what this new certification is aiming to do?
ISC2’s Exam Guidance for AI reflects how securing AI systems is increasingly incorporated into our exam content, requiring exam candidates to demonstrate their expertise addressing one of today’s most pressing security challenges.
The new certification effort is about exploring whether there is now a need to define and validate a deeper, more specialized set of capabilities on top of that cross-functional competence—particularly as new roles and responsibilities emerge.
Both are essential. One ensures consistency across the profession, and the other explores specialization where it’s needed.
Beyond certifications, how else has ISC2 been building this AI security capability for members?
There’s been a very deliberate expansion of our AI-related offerings.
ISC2 Professional Development has introduced AI-focused certificates, expanded the course catalog and express learning opportunities with AI, and created more ways for members to engage—from webinars to conference sessions and AI Spotlight events. ISC2 has also contributed research, insights and peer-driven discussions to help members stay current as technology evolves.
All of these efforts are designed to work together—not as standalone resources, but as part of a connected ecosystem.
Why is it important that this work feels connected and intentional?
Because the profession needs clear, consistent and well-defined standards for AI security.
AI is moving quickly. Without a coordinated approach you can end up with fragmented expectations—different definitions of roles, skills and expertise depending on where you look. ISC2’s role is to bring together cybersecurity professionals to help shape how AI security knowledge and skills are defined and recognized globally.
This is about ensuring that as AI reshapes cybersecurity, the profession evolves with a shared understanding of what good looks like.
How does the certification development process reflect that approach?
It starts with the profession itself.
We’re not defining this certification in isolation—we’re working with cybersecurity professionals globally to understand how their day-to-day roles and responsibilities are changing, what new responsibilities are emerging and what skills are becoming critical.
That ensures the certification, if it moves forward, is grounded in real-world practice and aligned to actual workforce needs—not assumptions.
What does this mean for members today?
It means you have multiple ways to engage, depending on where you are in your career journey.
If you’re building awareness, there are courses and learning resources. If you’re applying AI in your work, there are deeper training opportunities and insights. If you want to help define the future of AI security, this certification development effort is your opportunity to do that.
What’s the opportunity for members to shape what comes next?
This is the part we’re most excited about.
ISC2 certifications have always been built by our members, in order to support the profession. This is a moment where members can directly influence how AI security expertise is defined and validated—something that will shape hiring, career progression and professional standards for years to come.
What are you looking for from volunteers?
We are looking for volunteers to bring their everyday practical experience to the fore in shaping the certification. Leveraging professional experience to help determine what areas need to be assessed for competency and how to assess them with the right questions and knowledge testing.
Where should members go to learn more or get involved?
We’ve created two key resources to help members stay informed and engaged:
These pages bring together everything ISC2 is doing across AI—from education and guidance to certification development—so members can see the full picture and decide how they want to participate.
AI is already shaping cybersecurity. What’s exciting is that we still have the opportunity to shape how the profession responds—and that’s exactly what ISC2 and our members are doing together.
For You, By You: Join Over 5,000 Volunteers and Build ISC2's AI Security CertificationAs cybersecurity professionals evolve and adapt their skillset and job functions because of AI, ISC2 has announced the development of a new AI security certification to recognize and benchmark AI skills and competence within the cybersecurity workforce. The AI security certification development process presents an opportunity for cybersecurity professionals to input into the process and help define parameters for the certification. This is your moment to play a defining role at the foundation of this new certification:
For more information about the ISC2 AI security certification program and how to contribute to the various development activities taking place, go to https://www.isc2.org/new-ai-certification. |


