What Is CISSP?
Dr. Abeer Alshammari · Published 7/29/2026
CISSP (Certified Information Systems Security Professional) is a vendor-neutral certification issued by (ISC)², aimed at people who design, implement, and manage an organization's overall security program rather than people who only configure a single tool. It is widely treated as the benchmark certification for senior security practitioners and is a common requirement for roles like security manager, security architect, and CISO-track positions.
What it certifies
CISSP tests breadth across eight domains that span governance, risk, architecture, network security, identity, and operations. It is deliberately a generalist certification: it does not certify that you can operate a specific firewall or SIEM, it certifies that you understand how all the pieces of a security program fit together and can make sound decisions across them.
(ISC)² requires a minimum of five years of paid work experience in at least two of the eight domains (four years with a relevant degree or approved credential). This is not an entry-level certification -- it assumes you have already done hands-on security work and are formalizing that experience into a recognized credential.
What CISSP is not
CISSP is not a technical deep-dive credential the way OSCP or a vendor-specific certification is. It will not teach you to write exploit code or configure a specific product. It also is not primarily a management certification the way CISM is -- CISSP sits between the two, covering technical concepts broadly enough that a hands-on practitioner will recognize them, while still being organized around governance and program management.
Why it matters professionally
Many government and enterprise security roles list CISSP as a hard requirement, particularly where compliance frameworks reference it directly (for example, U.S. federal DoD 8570/8140 requirements). Beyond specific requirements, it functions as a credible signal to employers that you have broad, verified security knowledge and five-plus years of relevant experience.
Try it yourself
An interactive CyberAbeer experience for this topic is in development.
Coming soon