Jaded Security

INDUSTRY · 2026-05-16The CISSP Is Still a Membership Fee, Not a Skill Test

– Boris Sverdlik

An editorial revisit by Jaded Security of the 2011 ISC2 coverage on this site, fifteen years on. The original posts argued the CISSP was functioning as a membership fee rather than a competency test. The argument has aged better than ISC2 has.

In 2011 this site ran a short series of posts on the CISSP and the organisation behind it. The earliest of the three, Certifications Do Not Necessarily Make You a Security Professional, set the frame. Why I Lost All Respect for ISC2 made the structural argument: the credential exists primarily as a recurring-revenue product, and the exam content tests the candidate’s ability to memorise a Common Body of Knowledge document rather than the candidate’s ability to defend a network. Hey ISC2, Where is the Opt Out Button closed the trilogy with a specific privacy complaint about the public member directory.

Fifteen years is enough time to ask whether the analysis held. This post is an editorial revisit, not a continuation of authorship. The 2011 commentary on this site predicted a set of outcomes for the certification market. Most of those predictions were confirmed by the path the organisation actually took.

What the 2011 coverage predicted

Three claims were made in that 2011 series, in approximately these words:

  1. The CISSP is functionally a paid affiliation with the security industry’s hiring pipeline. The exam content is a barrier-to-entry mechanism, not a competency assessment.
  2. ISC2’s governance is designed to make membership-level accountability theoretical rather than operational. The membership cannot effectively recall the board, change the fee structure, or alter the CBK process.
  3. The continuing-education programme exists to convert a one-time exam fee into a perpetual revenue stream, with limited apparent connection to maintaining actual defensive competence in the field.

None of those three claims required defending in 2011. The 2011 critique was: someone should defend them, because the credential’s market share will keep growing on the strength of the hiring-pipeline lock-in, not on the strength of the underlying assessment.

What actually happened

The credential market grew. ISC2’s own published material places the certified-membership base at well over half a million worldwide. The CISSP exam fee, US$549 in 2011, has been raised in steps to the current published figure. Annual maintenance fees, US$85 in 2011, are now US$135 for the CISSP-tier credentials and a smaller figure for the entry-level credential the organisation introduced under the “CC” name during the 2022-2023 rebrand. None of those changes are surprising. All of them were on the trajectory the 2011 commentary projected.

The credential portfolio expanded. ISC2 in 2011 offered the CISSP, the SSCP, and the early-stage CSSLP and CAP credentials. In 2026 the same organisation also issues the CCSP (cloud), the HCISPP (healthcare), the ISSAP / ISSEP / ISSMP concentrations on top of the CISSP base, and the entry-level CC introduced under the rebrand. Each of these is a separately-priced credential with its own continuing-education obligation. The expansion is not by itself evidence of bad faith. It is also not evidence of any of the credentials being a stronger competency assessment than the original CISSP. They are additional products in a product line.

The organisation’s published governance structure remains, in operational terms, what it was. The board is elected, but the candidate slate is curated, the petition route is procedurally onerous, and the membership has no recall mechanism that has been exercised in the credential’s full history. The 2011 prediction was that this would not change. That prediction held.

The continuing-education programme grew into the third-party industry the 2011 critique foresaw. There is now a marketplace of CPE-generating products, conferences, webinars, and on-demand course catalogues whose primary commercial logic is supplying credits to credential-holders renewing their certifications. Some of the content is good. Most of the content is structurally indistinguishable from the conference circuit it replaced. The CPE total a credential-holder accumulates per year is a function of how much time they spend filling out forms, not how much new defensive capability they acquired.

The CISSP did not become a competency test

The exam content has been refreshed. The CBK is on its current revision. New domains have been added (cloud, supply-chain considerations, modern identity). The exam-delivery mechanism moved to computer-adaptive testing. None of these revisions, taken in isolation, are objectionable.

The structural critique from 2011 does not turn on the exam being out-of-date in any specific year. It turns on whether the exam content has a measurable correlation with the candidate’s ability to do the work the credential is widely treated as evidence for. There has been no public ISC2-funded study, in fifteen years, demonstrating such a correlation. There has also been no independent peer-reviewed study demonstrating one. The industry has continued to treat the credential as if such a correlation existed, because the hiring market needs a filter and a filter that is widely held is more useful than a filter that is well-validated.

A credential whose primary function is being a widely-held hiring filter is a membership badge. That is the 2011 argument, restated in 2026 terms. The argument has not been refuted; it has been confirmed by the operational behaviour of every actor in the system.

The privacy complaint, briefly revisited

The 2011 post on the member directory remains a useful artefact in 2026 because it shows the credential body could not, in 2011, follow the privacy principles its own credential tested candidates on. The current directory configuration has changed in detail. The structural issue has not. The credential body still publishes member-status information by default; opting out remains a non-trivial process; the membership has not collectively pushed for a stronger default.

The 2011 prediction here was modest: that the privacy treatment would change in small ways but the default posture would not. That prediction held.

What the 2011 coverage missed

Two things, in the interest of being honest about a fifteen-year retrospective.

First, the workforce-gap discourse. ISC2 has, throughout the 2010s and 2020s, published a recurring workforce study reporting a multi-million-position cybersecurity workforce gap. The 2011 critique did not anticipate how durably that framing would justify continued credential growth. The argument “we need more credential-holders because there is a workforce gap” became, over fifteen years, the dominant framing for the credential body’s expansion. The framing has been criticised in adjacent literature for selection-bias issues and definitional looseness. It has nonetheless been load-bearing for ISC2’s institutional growth in a way the 2011 commentary did not foresee.

Second, the speed of competing-credential commodification. By 2026, vendor-specific certifications (AWS, Microsoft, the major cloud-security catalogues) and offensive-security certifications (OSCP and its successors, the CRTO line, the various adversary-emulation credentials) have absorbed a large share of the hiring-filter function that CISSP held a near-monopoly on in 2011. The CISSP is now one credential among several rather than the unambiguous default for senior security roles. The 2011 commentary expected this to happen over a longer timeline than it actually did. Whether that is good or bad for defenders depends on whether the competing credentials are themselves competency tests or whether the hiring market is now filtering on multiple membership badges instead of one. The evidence is mixed.

Closing

The 2011 series argued, in a sharper tone, that the CISSP was a membership fee dressed as a competency test. Fifteen years later, the operational evidence supports the argument and the credential body’s published positioning is, if anything, more candid about treating the credential as a community-membership marker than it was in 2011. The credential is what it was claimed to be. The industry is what it was claimed to be. The hiring-pipeline lock-in is what it was claimed to be.

None of that obligates a working defender to hold the credential, decline to hold the credential, or have any particular opinion about people who hold or do not hold it. It is a paid affiliation with a professional body. That is what it has always been. The 2011 critique on this site was that the rest of the industry should be honest about it. Fifteen years on, parts of the industry have become honest about it. ISC2 has not. The 2011 prediction here was that ISC2 would not, because there is no operational pressure on ISC2 to do so.

That prediction also held.


Jaded Security