ISC2
ISC2 is a non-profit membership organization that issues globally recognized cybersecurity professional certifications (CISSP, CCSP, SSCP, CC, CGRC, CSSLP, ISSAP, ISSEP, ISSMP), delivers adaptive training and continuing education, and serves individual practitioners, enterprise security teams, and government agencies including the U.S. Department of Defense.
- Company typePrivate
- Founded1996
- HeadquartersAlexandria, United States
- Headcount251–500
- GTM typeB2B and B2C
- OfferingServices
What ISC2 does
ISC2 (International Information Systems Security Certification Consortium, Inc.) is a 1996-founded, Massachusetts-incorporated non-profit membership organization that issues cybersecurity professional certifications and related training. Its core products are personnel certifications administered through Pearson VUE test centers globally, anchored by the 30-year-old CISSP credential and spanning CC, SSCP, CCSP, CGRC, CSSLP, and the ISSAP/ISSEP/ISSMP concentrations, with an AI Security Certification in development. The portfolio also includes adaptive self-paced and instructor-led training, classroom courses, certificates and express courses, the annual Security Congress and regional SECURE events, webinars, and a Peace of Mind Protection exam-retake service.
Revenue is generated through one-time exam fees, recurring Annual Maintenance Fees (AMF) for certification renewal, training and professional development subscriptions (90-365 day access tiers with member discounts), event registrations, and enterprise team training for organizations of 6+ employees. The go-to-market is community-led: a global chapter network, authorized training partners, and a member base drive demand, supplemented by an event-driven motion (Security Congress, SECURE regional events, virtual Spotlights) and thought-leadership content including the annual Cybersecurity Workforce Study (14,865 respondents).
The customer base spans individual cybersecurity professionals pursuing credentials and CPE credits, enterprise security organizations upskilling teams (995 security-leader respondents across Canada, Germany, India, Japan, the U.K., and the U.S. in ISC2's Enterprise Training Trends research), security operations teams, and government buyers including the U.S. Department of Defense under DoDM 8140. ISC2's competitive positioning rests on ANAB ISO/IEC 17024 accreditation, CISSP's brand equity, and an ecosystem of CPE partnerships with security vendors such as Palo Alto Networks, Fortinet, BlackHat, and RSA.
ISC2 firmographics
Firmographics- Name
- ISC2
- Legal name
- International Information Systems Security Certification Consortium, Inc.
- Website
- https://isc2.org
- Company type
- Private
- Founded year
- 1996
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- ISC2 is a non-profit membership organization that issues globally recognized cybersecurity professional certifications (CISSP, CCSP, SSCP, CC, CGRC, CSSLP, ISSAP, ISSEP, ISSMP), delivers adaptive training and continuing education, and serves individual practitioners, enterprise security teams, and government agencies including the U.S. Department of Defense.
- Ownership category
- akta.pro rank
ISC2 industry classification
Industry- Product category
- Cybersecurity Professional Certification
- NAICS
- Colleges, Universities, and Professional Schools (6113), Professional and Management Development Training (611430), Computer Training (61142)
- SIC
- Services-Educational Services (8200), Services-Membership Organizations (8600)
- akta.pro primary industry
- Information Technology (IT) & Cybersecurity Certifications (EDAAANAA)
- akta.pro secondary industries
- Information Technology & Cybersecurity Certification Prep (CompTIA, Cisco, Microsoft, AWS, ISC2/ISACA) (EDANAIAF), Information Security, Privacy & IT Governance (CISSP CPE, Privacy CE) (EDAAALAL), Continuing Education (CE/CPD) & Provider Accreditation Bodies (EDADACAF)
Keywords
Where ISC2 is headquartered
LocationHeadquarters
- HQ city
- Alexandria
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
ISC2 business model
Business model- GTM type
- B2B and B2C
- Offering type
- Services
- Cost components
- Personnel, Marketing or Sales, Technology or R&D, Operations, Others
Revenue model
- Certification Exam Fees: One-time exam fees for each certification exam (CC, SSCP, CISSP, CCSP, CGRC, CSSLP, ISSAP, ISSEP, ISSMP). Candidates purchase exam vouchers and schedule through Pearson VUE test centers.
- Annual Maintenance Fees (AMF): Recurring annual membership fees paid by certified members to maintain their certification and membership status. Required after passing the exam and completing endorsement.
- Training and Professional Development: Revenue from online self-paced training, online instructor-led training, classroom-based training, certificates, courses, express courses, and webinars that help professionals earn CPE credits.
- Peace of Mind Protection: Exam retake protection offering two attempts within 180 days for a bundled price, providing insurance against initial exam failure.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Annual | Entry-level cybersecurity certification |
| Subscription | Annual | Online Self-Paced Training |
| Subscription | Annual | Online Instructor-Led Training |
| One time/ perpetual license | Multi-year contract | Peace of Mind Protection |
| Subscription | Annual | Certificates, Courses, and Express Courses |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels8 records
ISC2 product offering
Product offeringCore offering
ISC2 develops, owns, and administers globally recognized cybersecurity professional certifications including CISSP, SSCP, CCSP, CC, CGRC, CSSLP, ISSAP, ISSEP, and ISSMP, along with supporting training (self-paced, instructor-led, classroom), professional development certificates and courses, and continuing professional education (CPE) resources. Certifications are delivered through Pearson VUE test centers globally, with candidates required to pass exams, complete peer endorsement, and pay recurring Annual Maintenance Fees to maintain credentialed member status.
Product overview
ISC2 is a certification and professional development organization offering a portfolio of cybersecurity certifications, training programs, and continuing education resources. The core offerings include flagship certifications (CISSP, SSCP, CCSP, CC, CGRC, CSSLP) and advanced concentration certifications (ISSAP, ISSEP, ISSMP) for specialized security domains. ISC2 also provides AI-focused offerings including the AI Security Certificate, AI for Cybersecurity Course, and a new AI Security Certification under development. Training is delivered through multiple channels: adaptive online self-paced learning, instructor-led virtual training, classroom-based sessions, and workshops. The organization supports certified professionals with CPE (Continuing Professional Education) opportunities through events, webinars, certificates, courses, and volunteering programs. The flagship annual event is the ISC2 Security Congress, supplemented by regional SECURE Events. Additional services include exam preparation tools (flash cards, study questions), the Peace of Mind Protection retake program, and research publications including the annual Cybersecurity Workforce Study.
Differentiator
Problem solved
Functional benefit
Products and services
- CISSP - Certified Information Systems Security Professional
Quantifiable outcome
- ISC2 certification holders earn salaries ranging from $94,948 to $159,030 globally depending on certification level
- +3 more outcomes
Companies that use ISC2
Customer profileNamed customers2 records
Segments4 records
Ideal customer profiles3 records
ISC2 technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability1 record
Feature2 records
ISC2 partnerships and signals
Strategic signalPartnerships
20 partnerships are on record, tiered minor and core.
- 3Tree TechminorCPE Partner authorized to submit CPE activity on behalf of ISC2 members and provide professional development opportunities for earning CPE credits.
- Abnormal SecurityminorCPE Partner authorized to submit CPE activity on behalf of ISC2 members.
- AkamaiminorCPE Partner providing security-focused professional development opportunities for ISC2 members.
- Arctic WolfminorCPE Partner authorized to submit CPE activity on behalf of ISC2 members.
- AttackIQminorCPE Partner offering continuous security validation education for ISC2 members.
- BlackHatcoreMajor security industry events brand partnership providing CPE-credited activities for ISC2 members.
- FortinetcoreCPE Partner with training academy providing security certification preparation and CPE opportunities.
- Hack The BoxminorCPE Partner providing ethical hacking and cybersecurity training platforms for ISC2 members.
- LinkedIn LearningminorCPE Partner providing professional development courses eligible for CPE credit.
- Palo Alto NetworkscoreCPE Partner with comprehensive security training offerings for ISC2 members.
- Recorded FutureminorCPE Partner providing threat intelligence education for ISC2 members.
- RSAcoreCPE Partner from RSA Conference providing security industry events and education.
- SnykminorCPE Partner providing developer security training for ISC2 members.
- SophosminorCPE Partner offering cybersecurity events and training for ISC2 members.
- Trend MicrominorCPE Partner providing security training and certification preparation for ISC2 members.
- WiCyScoreStrategic partnership supporting women in cybersecurity through DEI initiatives and workforce development programs.
- Pearson VUEcoreGlobal exam delivery partner administering ISC2 certification exams through professional test centers worldwide with biometric verification.
- Cyber Leadership InstitutecorePartnership for Cyber Leadership Program workshop delivered virtually over 8 weeks, providing leadership development for cybersecurity professionals.
- ISC2 Authorized China AgencycoreOfficial authorized agency managing ISC2 certification programs and member services in China.
- ISC2 JapancoreOfficial authorized agency managing ISC2 certification programs and member services in Japan, with Japanese language website support.
Scale indicators8 records
Recent moves6 records
Expansion highlights5 records
ISC2 competitors and assessment
Company assessmentDirect peers
- ISACA: Non-profit professional association offering information security, governance, and audit certifications (CISA, CISM, CRISC, CGEIT) with similar membership-and-maintenance-fee model. Direct competitor for cybersecurity leadership credentials and continuing education wallet.
- SANS Institute: Leading provider of cybersecurity training and GIAC certifications, with deep technical curriculum and a global faculty. Competes directly with ISC2 for technical cybersecurity certification and enterprise training budgets.
- GIAC (SANS): Closest substitute for ISC2's technical certifications (SSCP, CSSLP), offering 30+ granular cybersecurity credentials. Frequently chosen by practitioners for hands-on technical depth versus ISC2's leadership-oriented portfolio.
- CompTIA: Vendor-neutral IT certification body offering Security+, CySA+, CASP+, and PenTest+ that compete with ISC2's entry-level CC and mid-tier certifications. Strong adoption in DoD 8140 and enterprise hiring pipelines.
- EC-Council: Cybersecurity certification body known for Certified Ethical Hacker (CEH), ECSA, and LPT credentials. Competes with ISC2 in ethical hacking and security engineering categories, particularly in emerging markets.
Emerging players
- OffSec: Issuer of OSCP, OSWE, and other hands-on offensive security certifications that emphasize practical skills verification. Emerging alternative to ISC2's exam-based model, gaining traction among technical practitioners and employers.
- Coursera: Online learning platform partnering with universities and companies to deliver professional certificates (including Google Cybersecurity Certificate, IBM Cybersecurity Analyst). Competes at entry-level and career-changer segments where ISC2's CC certification operates.
Broad incumbents
- Cisco (Certifications): Vendor certifications (CCNA Security, CCNP Security, Cisco Certified CyberOps Associate) bundled with Cisco's networking and security platform adoption. Complements but also competes with ISC2's network security credentials.
- Microsoft (Certifications): Issuer of Azure Security Engineer Associate, Cybersecurity Architect Expert, and SC-200 Security Operations Analyst credentials. Increasingly relevant as enterprises consolidate on Microsoft security stack.
- AWS (Certifications): AWS Certified Security - Specialty and related cloud/security credentials are widely adopted by cloud-first enterprises. Competes with ISC2's CCSP for cloud security certification wallet.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
ISC2 social profiles
Digital presenceISC2 compliance and trust
Trust signalCompliance2 records
ISC2 financial estimates
Financial estimateRevenue estimate
Valuation estimate
ISC2 leadership team
Management profileNumber of profiles
ISC2 subsidiaries and ownership
Company hierarchySubsidiaries1 record
ISC2 funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ISC2 M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ISC2
What does ISC2 do?
ISC2 develops, owns, and administers globally recognized cybersecurity professional certifications including CISSP, SSCP, CCSP, CC, CGRC, CSSLP, ISSAP, ISSEP, and ISSMP, along with supporting training (self-paced, instructor-led, classroom), professional development certificates and courses, and continuing professional education (CPE) resources. Certifications are delivered through Pearson VUE test centers globally, with candidates required to pass exams, complete peer endorsement, and pay recurring Annual Maintenance Fees to maintain credentialed member status.
Is ISC2 a public or private company?
ISC2 is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was ISC2 founded?
ISC2 was founded in 1996. It employs 251 to 500 people.
Where is ISC2 based?
ISC2 is headquartered in Alexandria, United States, in the North America region.
How does ISC2 make money?
Four revenue lines are on record. Certification Exam Fees are the primary driver. The others are annual Maintenance Fees (AMF), training and Professional Development and peace of Mind Protection.
Who are ISC2's main competitors?
Direct peers on record are ISACA, SANS Institute, GIAC (SANS), CompTIA and EC-Council. Emerging players are OffSec and Coursera. Broad incumbents are Cisco (Certifications), Microsoft (Certifications) and AWS (Certifications).
Does ISC2 have an API?
No public API is recorded for ISC2.
What industry is ISC2 in?
ISC2's product category is Cybersecurity Professional Certification. Its primary akta.pro industry code is EDAAANAA, Information Technology (IT) & Cybersecurity Certifications, with a secondary code of EDANAIAF, Information Technology & Cybersecurity Certification Prep (CompTIA, Cisco, Microsoft, AWS, ISC2/ISACA). Its NAICS code is 6113 and its SIC code is 8200.