CCISO
Certified Chief Information Security Officer
Executive leadership — governance, program mgmt, finance, and strategic planning for security.
› Quality score
Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.
› Market signals
public, citable inputs to the recognition score› Built for these roles
› Exam format
150 multiple-choice questions over 2.5 hours, English. Application essay required to qualify. Heavy emphasis on case-study scenarios drawn from real CISO programs.
30-day wait between attempts. EC-Council application + experience verification required before scheduling.
› Recertification
120 EC-Council ECE credits over three years (avg 40/yr). No annual maintenance fee.
› NICE Framework work roles
The NIST NICE work-role IDs this cert maps to. NICCS lookup.
› Core domains covered
The 2 domains this cert is centrally about. Passing the exam demonstrates working knowledge of each.
› Also touched
Present in the blueprint but not the primary focus — you’ll be introduced but shouldn’t expect depth.
Reference architectures, control frameworks (NIST SP 800-53, CIS Controls), secure-by-design patterns, threat modeling, trust-boundary design, technology standards.
EU AI Act compliance, NIST AI RMF, AI risk assessment, model cards, algorithmic auditing, AI incident response.
Data classification, encryption-at-rest/in-transit, DLP, tokenization, privacy-by-design, plus the regulatory stack (GDPR, CCPA, HIPAA) that sets the bar.
› Prerequisites
Five years in each of the CCISO domains (25 years total without waivers). Waivers available for holders of CISSP, CISM, CISA.
- Executive-level information security strategy
- Financial planning and budgeting for security
- Board-level reporting and governance
› Progression
requiredrecommendedWhere this cert fits in the typical learning path. Required edges are vendor-gated; recommended edges reflect de facto industry progression.
› Study materials
Curated starting points. Not exhaustive — vet each against your learning style and the current exam version.
- EC-Council CCISO Body of Knowledge — EC-Council
- EC-Council Sample Questions (limited free set)
› Version & lifecycle
Five domains; aligned to NIST CSF 2.0 in the 2024 update.
› Salary signal
CISO / Deputy CISO, US, 10+ years. Very wide range — depends on company size.
Robert Half Salary Guide + Glassdoor 'CISO' aggregations · 2024 · US base only · p25–p75 range
› How it compares
CISM is the security-management standard; CCISO targets the CISO seat specifically with executive-level depth.
↔ Compare side-by-sideCISSP is the prerequisite-grade senior cert; CCISO assumes you've already passed that bar.
↔ Compare side-by-side› Careers that commonly pursue this cert
Lead security strategy, communicate risk to the board, and build security programs. Executive-level cybersecurity leadership.
See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.