Maintaining the CISSP certification requires ongoing professional development. Certified Information Systems Security Professionals must earn and submit 120 Continuing Professional Education (CPE) credits during their three-year certification cycle. The goal of CPE is to ensure that cybersecurity professionals continue developing their knowledge and skills as technologies, threats, regulations, and security practices evolve.
CISSP holders do not have to wait until the end of the three-year cycle to complete their credits. In fact, spreading CPE activities throughout the certification period can make renewal much easier. ISC2 currently recommends an annual target of 40 credits for CISSP holders, although the requirement is based on the three-year total rather than a mandatory annual quota.
Understanding CISSP CPE Requirements and Ways to Earn Credits
The 120 CISSP CPE credits are divided between Group A and Group B activities. CISSP holders need 90 Group A credits during the three-year cycle, while up to 30 credits can come from Group B professional development activities. Group A activities are directly related to cybersecurity and the domains covered by the certification. Group B activities focus on broader professional skills that support career development.
There are many ways to earn CPE credits. Cybersecurity courses, certification training, conferences, webinars, workshops, reading security-related books or articles, volunteering in security-related activities, and other educational opportunities can qualify as CPE activities. Professional development such as management or communication training may also contribute toward the Group B portion.
One effective approach is to choose activities that support both certification renewal and career objectives. For example, a cybersecurity professional interested in cloud security can focus learning on cloud architecture and security practices. Someone working in governance may benefit from activities related to risk management, compliance, privacy, and security frameworks.
Keeping a balanced learning schedule is also important. Instead of trying to complete all 120 credits near the end of the certification cycle, professionals can establish a yearly learning plan and regularly record completed activities. This reduces last-minute pressure and makes it easier to maintain continuous professional development.
How to Report and Manage Your CISSP CPE Credits
After completing eligible professional development activities, CISSP holders need to submit their CPE credits through the ISC2 CPE portal. ISC2 recommends recording activities regularly so that professionals can monitor their progress through their dashboard and avoid a rush toward the end of the certification cycle.
Documentation is an important part of managing CPE records. Depending on the activity, supporting evidence may include course certificates, transcripts, attendance records, receipts, research notes, or other relevant documentation. ISC2 recommends retaining supporting documentation for at least 12 months beyond the end of the current certification cycle in case of an audit.
CISSP professionals should regularly check their CPE balance and ensure that their activities are categorized correctly as Group A or Group B. This helps prevent an imbalance when approaching the renewal deadline. The ISC2 dashboard can be used to monitor the current CPE count and certification status.
If a professional reaches the end of the certification cycle without completing the required CPEs, ISC2 provides a 90-day grace period in which outstanding CPE credits can be earned and submitted. However, planning ahead is preferable to relying on the grace period.
CISSP renewal is therefore more than a compliance requirement. Regular CPE activities help cybersecurity professionals stay informed, strengthen their expertise, and remain prepared for changing security challenges. By planning learning activities, recording credits consistently, maintaining proper documentation, and monitoring progress through the ISC2 portal, professionals can make the 120-credit renewal process much more manageable.
Tromenz Learning provides the best certification programs regarding CISSP and other professional certifications, helping learners develop relevant skills and prepare for successful cybersecurity careers.

