ISSEP (Information Systems Security Engineering Professional)
The ISSEP covers the application of systems engineering principles to build secure systems: defining security requirements, designing security architectures, implementing and verifying system security, and supporting assessment and authorization for government and industry. ISC2 developed it with the U.S. National Security Agency and lists roles such as senior systems engineer and information assurance systems engineer.
Exam Details
Fixed-length English exam with multiple choice and advanced item types at Pearson VUE test centers.
Standard registration in the Americas, Asia Pacific, Middle East and Africa. ISC2 also lists EUR 575.04 for EMEA and GBP 485.19 for the UK. Currency and taxes depend on the exam location.
Requirements and Renewal
Prerequisites
Either an active CISSP plus two years of cumulative, full-time experience in one or more of the five ISSEP domains, or seven years of cumulative, full-time experience in two or more of them (a degree or approved credential can waive one year). A passing candidate without the experience can hold Associate of ISC2 status for up to eight years.
Renewal
Without a CISSP, 140 Group A CPE credits per three-year cycle. Holders who also have a CISSP earn ISSEP-related Group A credits that ISC2 counts toward the CISSP requirement. A single U.S. $135 annual maintenance fee covers all ISC2 certifications held.
Current Version
ISSEP Exam Outline effective August 1, 2025, in effect since Aug 1, 2025.
Exam Domains
5 domains| Domain | Weight |
|---|---|
| Systems Security Engineering Foundations | 24% |
| Risk Management | 20% |
| Security Planning and Engineering | 22% |
| Systems Security Implementation, Verification, and Validation | 20% |
| Secure Operations, Change Management and Disposal | 14% |
DoD 8140 Work Roles
9 work rolesThe DoD 8140 Qualification Matrix V2.1 lists ISSEP as a foundational qualification option for these DoD Cyber Workforce Framework work roles, up to the proficiency level shown. Lower levels of the same work role are also covered.
Frequently Asked Questions
What does ISSEP stand for?→
ISSEP stands for Information Systems Security Engineering Professional, one of three advanced ISC2 certifications alongside the ISSAP and ISSMP.
What experience does the ISSEP require?→
A CISSP in good standing plus two years in one or more ISSEP domains, or seven years of cumulative experience in two or more domains.
How is the ISSEP exam structured?→
It has 125 items across five domains, a 3-hour limit and a passing grade of 700 out of 1000. Systems Security Engineering Foundations is the largest domain at 24%.
Sources
- ISSEP - Information Systems Security Engineering Professional
- ISSEP Certification Exam Outline
- ISC2 Updates Advanced Certifications ISSAP, ISSEP, ISSMP
- ISC2 Cybersecurity Certifications
- ISC2 Exam Pricing
- ISC2 Member Policies (CPE requirements)
- ISC2 Annual Maintenance Fees (AMF)
- Become an Associate of ISC2
- ISC2 Certification Maintenance Handbook
Exam details are checked against official ISC2 pages. Fees, exam versions, and renewal rules change; confirm with ISC2 before registering. ISSEP is a trademark of its owner. This site is not affiliated with or endorsed by ISC2.