ExpertVendor-neutralISO 17024ISC2· issued from US

CISSP-ISSAP

CISSP Information Systems Security Architecture Professional

Architecture concentration on top of CISSP — trust boundaries, identity / crypto / network composition, defense-in-depth design.

Exam fee
$599
Ongoing
$0/yr AMF · 30 CPE/yr
Study time
150–300 hrs
Delivery
Test center
Validity
3 yrs (renewal cycle)

› Quality score

22.0 / 40

Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.

Blueprint rigor
How well-defined and rigorous the exam blueprint is.
Concentration blueprint inherited from the CISSP — well-defined but a thin layer on top of an already-broad credential.
8.5/10
Practical evidence
Hands-on labs / written reports vs pure MCQ.
MCQ only. No architecture exercise or design review.
1.5/10
Currency & upkeep
How aggressively content is kept current with the field.
Updates lag the parent CISSP. Last meaningful refresh ~2017.
6.5/10
Market recognition
How often this signal actually moves a hiring decision.
Recognised among architecture-track candidates but the 'CISSP' brand carries most of the weight. [Holders: 3k, 2024-12] [DoD 8140 listed]
5.5/10

› Market signals

public, citable inputs to the recognition score
Holders worldwide
3,000
as of 2024-12 · source
DoD 8140 baseline
Listed
IASAE-III

› Built for these roles

Security ArchitectSenior Security Engineer (architecture-track)Cloud Security ArchitectEnterprise Architect (security-leaning)

› Exam format

125 multiple-choice questions over 3 hours, English. Pearson VUE proctored. AMF is shared with your active CISSP — no separate fee.

Passing score
700/1000 (scaled)
Retake policy
Fee: $599 per attempt
Wait: 30d between attempts
Cap: 4 attempts/year

Standard ISC2 retake schedule: 30/60/90 day waits.

› Recertification

90 CPEs over the three-year cycle (avg 30/yr), included under your CISSP $135/yr Annual Maintenance Fee.

Recognition
GlobalUSEUUK
Exam languages
en

› Core domains covered

The 7 domains this cert is centrally about. Passing the exam demonstrates working knowledge of each.

› Also touched

Present in the blueprint but not the primary focus — you’ll be introduced but shouldn’t expect depth.

› Prerequisites

Experience

Requires an active CISSP in good standing plus two years of professional experience in the ISSAP concentration domains.

Knowledge assumed
  • Trust boundaries and identity architecture
  • Cryptographic and network composition
  • Defense-in-depth design patterns

› Progression

requiredrecommended

Where this cert fits in the typical learning path. Required edges are vendor-gated; recommended edges reflect de facto industry progression.

Required prereqs (1)
Recommended priors (0)

No de facto priors typically expected.

CISSP-ISSAP
ISC2
Required by (0)

No certs require this one.

› Study materials

Curated starting points. Not exhaustive — vet each against your learning style and the current exam version.

Official guides
  • Official (ISC)² ISSAP CBK Reference, 4th Ed.Wiley/ISC2
Practice tests
  • Boson ExSim-Max for ISSAP
Free / community

› Version & lifecycle

Current version
2017 CBK
Released
2017-04

ISSAP CBK has not been refreshed since 2017 — content gaps relative to current cloud/AI architecture practice.

› Salary signal

Security architect, US, 7+ years. Requires active CISSP.

$145K$210K
median $170K

Robert Half Salary Guide + Glassdoor 'Security Architect' aggregations · 2024 · US base only · p25–p75 range

› How it compares

vs
SC-100

Vendor-neutral architecture (ISSAP) vs Microsoft-stack architecture (SC-100).

↔ Compare side-by-side
vs
CCSP

CCSP is cloud-deep architecture; ISSAP is broader vendor-neutral architecture.

↔ Compare side-by-side

› Careers that commonly pursue this cert

Quantum Security Specialist

Prepare for the post-quantum era. Understand quantum threats and lead cryptographic migration efforts.

Security Architect

Senior design role — defines how pillar A components fit together across identity, crypto, network, cloud, and data — and, increasingly, how pillar C bolts into it.

› Common exam traps to study

Cybersecurity cert exams reuse the same 25 distractor patterns over and over — category confusion, RTO vs RPO, IDS vs IPS, MD5 vs SHA-256, and more. Once you can name the trap, you stop falling for it. Each archetype page covers what it is, the specific pairs candidates confuse, and how to avoid it.

See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.