This pages makes recommendations for learners seeking to understand which ISC2 certifications will help them acquire the knowledge and skills required for roles under ENISA’s European Cybersecurity Skills Framework (ECSF). The recommendations are based on the coverage of knowledge and skills topics for each role, rather than coverage of tasks, and limited to roles where ISC2 certifications provide a high level of coverage.
| ECSF Profile Title | Recommended Certification | Other Relevant Certifications |
|---|---|---|
| Chief Information Security Officer | ||
| Cyber Legal Policy and Compliance Officer | ||
| Cybersecurity Architect | ||
| Cybersecurity Auditor | ||
| Cybersecurity Educator | ||
| Cybersecurity Implementer | ||
| Cybersecurity Risk Manager |
Certified in Cybersecurity
Designed as a starting point for students, young professionals and career-changers, this entry-level cybersecurity certification demonstrates knowledge in the key foundational concepts in information security and requires no work experience – just a passion for cybersecurity and the desire to dive into an exciting field that protects the world from cyber threats.
There are no specific prerequisites to take the exam. No work experience in cybersecurity or formal educational diploma/degree is required.
Systems Security Certified Practitioner
The SSCP is ideal for IT administrators, managers, directors and network security professionals responsible for the hands-on operational security of their organization’s critical assets. It demonstrates advanced technical skills and knowledge to implement, monitor and administer IT infrastructure using security best practices, policies and procedures.
To qualify for the SSCP, candidates must pass the exam and have at least one year of cumulative, paid work experience in one or more of the seven domains of the ISC2 SSCP Common Body of Knowledge (CBK®).
Governance, Risk and Compliance Certification
The CGRC is ideal for IT, information security and information assurance practitioners who work in Governance, Risk and Compliance (GRC) roles and have a need to understand, apply and implement a risk management program for IT systems within an organization. It demonstrates advanced knowledge and technical skills to formalize processes to assess risk and establish security documentation.
To qualify for the CGRC, candidates must pass the exam and have at least two years of cumulative, paid work experience in one or more of the seven domains of the ISC2 CGRC Common Body of Knowledge (CBK®).
Certified Secure Software Lifecycle Professional
The CSSLP is ideal for software development and security professionals responsible for applying best practices to each phase of the software development lifecycle (SDLC). It demonstrates advanced knowledge and technical skills to effectively design, develop and implement security practices within each phase of the software lifecycle.
To qualify for the CSSLP, candidates must pass the exam and have at least four years of cumulative, paid work experience as a software development lifecycle professional in one or more of the eight domains of the ISC2 CSSLP Common Body of Knowledge (CBK®).
Certified Cloud Security Professional
The CCSP is ideal for IT and information security leaders seeking to prove their understanding of cybersecurity and securing critical assets in the cloud. It demonstrates advanced technical skills and knowledge to design, manage and secure data, applications and infrastructure in the cloud.
To qualify for the CCSP, candidates must pass the exam and have at least five years of cumulative, paid work experience in information technology, of which three years must be in information security, and one year in one or more of the six domains of the ISC2 CCSP Common Body of Knowledge (CBK®).
Certified Information Systems Security Professional
The CISSP is ideal for information security leaders seeking to prove their understanding of cybersecurity strategy and hands-on implementation. It demonstrates advanced knowledge and technical skills to design, develop and manage an organization’s overall security posture.
To qualify for the CISSP, candidates must pass the exam and have at least five years of cumulative, paid work experience in two or more of the eight domains of the ISC2 CISSP Common Body of Knowledge (CBK®).
Information Systems Security Management Professional
The Information Systems Security Management Professional (ISSMP) recognizes cybersecurity leaders with expertise in information systems security management. It demonstrates deep management and leadership skills and the advanced knowledge to establish, present and govern information security programs.
There are two ways to earn the ISSMP. Path 1: CISSPs in good standing must have a minimum of two years of cumulative fulltime experience in one or more of the six domains in the current ISSMP exam outline. Path 2: All other candidates must have a minimum of seven years of cumulative full-time experience in two or more of the six domains in the current ISSMP exam outline.
Information Systems Security Architecture Professional
The Information Systems Security Architecture Professional (ISSAP) recognizes cybersecurity leaders with expertise in information systems security architecture. It demonstrates the knowledge and skills to develop, design and analyze security solutions and provide risk-based guidance to meet organizational goals.
There are two ways to earn the ISSAP. Path 1: CISSPs in good standing must have a minimum of two years of cumulative full-time experience in one or more of the six domains in the current ISSAP exam outline. Path 2: All other candidates must have a minimum of seven years of cumulative full-time experience in two or more of the six domains in the current ISSAP exam outline.
Information Systems Security Engineering Professional
The Information Systems Security Engineering Professional (ISSEP) recognizes cybersecurity leaders with expertise in information systems security engineering. It demonstrates the knowledge and skills to incorporate security into projects, applications, business processes and information systems.
There are two ways to earn the ISSEP. Path 1: CISSPs in good standing must have a minimum of two years of cumulative fulltime experience in one or more of the five domains in the current ISSEP exam outline. Path 2: All other candidates must have a minimum of seven years of cumulative full-time experience in two or more of the five domains in the current ISSEP exam outline.