ISC2 CPE Requirements – 3 Things You Must Know
If you hold an ISC2 certification, you must earn CPE credits every three years to keep your certification in good standing. ISC2 has specific CPE requirements for each activity, and rules you should follow to ensure you earn the required credits to maintain your ISC2 certification. In this article, we have listed all the details about the ISC2 CPE requirements and how you can complete the required CPE credits to renew your ISC2 certification.
In this article
📌 Hint: Do not skip this article; you will find FREE ISC2 CPE resources throughout the article.
Note that this article is related to all ISC2 CPE requirements. If you hold a CISSP certification, you may be interested in reading our CISSP Renewal article.
3 Things You Must Know About ISC2 CPE Requirements
There are three crucial aspects of the ISC2 CPE requirements, and we will be exploring each of them in this article.
- ISC2 CPE Credit Requirements for each certification track
- Difference between Group A and Group B activities, and the maximum cap for Group B Activities
- Paying the AMF
We’ve summarized it in the following infographic.

ISC2 CPE Requirements #1 – Each Track Requires a Different Number of CPE Credits
The first thing you should know about the ISC2 CPE requirements is that there are several different types of ISC2 certification tracks. You must fulfill the requirements for the certification you are holding. The following table provides a clear view of the ISC2 CPE requirements.
| Certification | Type | Suggested Annual | 3-year Total |
|
CC
|
Group A | 15 | 45 |
| Group A or B | – | – | |
| Total Required | 15 | 45 | |
|
CISSP
|
Group A | 30 | 90 |
| Group A or B | 10 | 30 | |
| Total Required | 40 | 120 | |
|
CCSP, CSSLP
|
Group A | 20 | 60 |
| Group A or B | 10 | 30 | |
| Total Required | 30 | 90 | |
|
CGRC, HCISPP, SSCP
|
Group A | 15 | 45 |
| Group A or B | 5 | 15 | |
| Total Required | 20 | 60 | |
|
CISSP-ISSAP, ISSEP, ISSMP
|
Group A | – | 20 |
| Total Required | 20 | 20 |
In this table, you can see, for each certification track, the type of CPE credits that must be earned (we will describe the difference between Group A and Group B credits in our next heading), the suggested annual CPE amount, and the three-year total CPE credits. One CPE Credit typically counts for one hour of professional activity or education. Let’s go through a specific certification track to you give you insight into how these ISC2 CPE requirements work.
For instance, if you hold CCSP certification, you must earn a total of 90 ISC2 CPE credits to renew your certification. However, there are further requirements as well. You can see that the table shows the 3-year total:
- Group A: 60 Credits
- Group A or B: 30 Credits
This means that a CCSP certification holder must earn at least 60 CPE credits from Group A activities. You can earn all required 90 CPE credits from Group A activities as well. However, there is a maximum limit for earning CPE credits from Group B activities. For CCSP, the maximum CPE credits you can earn from Group B activities is 30.
Can I Earn All Required CPE Credits from Group A Activities?
Yes, there is no maximum cap in ISC2 CPE requirements for Group A activities. You can earn all the required CPE credits for your certification track from Group A activities. The maximum cap is only for Group B activities. For instance, for CCSP certification, you cannot submit more than 30 CPEs for Group B activities.
What Happens If I Cannot Earn the Suggested Annual CPE Credits?
You can earn all required CPEs in one year, or over three years. It does not make any problem for earning or reporting the CPE credits as long as you keep paying the Annual Management Fee (AMF), which we will be explaining further in this article.
ISC2 divides the total three-year CPE requirement into three and suggests an annual CPE credit amount that each certification holder should earn every year. However, this is just a suggested amount. Typically, one CPE is earned if you perform or attend a one-hour professional activity or education. If you consider the total CPE credit amount, it requires a significant amount of time to invest.
For instance, if you hold a CISSP certification, you need to earn 120 CISSP CPE credits to renew your CISSP certification. This roughly means 120 hours of activity to satisfy ISC2 CPE requirements. If you can spend roughly 6 hours a day, it makes 20 days for a three-year cycle- a month, actually. Considering a full-time professional, it is not easy to spare a month to complete these CPE credits in a year. That is why ISC2 recommends earning CPE credits every year instead of leaving it to the end of the cycle. However, as long as you can earn and report within the three-year cycle, there is no problem with that.
What Happens If I Earn More Than Required CPE Credits?
If you earn more than required CPE credits, you can use them for your next three-year cycle. For instance, if you already completed required CPE credits to renew your ISC2 certification, you can keep that activity or training for your next three-year cycle and submit it when the new cycle begins.
If I Hold More Than One ISC2 Certification, How Many CPEs Should I Earn?
In CPE reporting, one activity can fulfill multiple ISC2 certifications if you have more than one certification. For instance, if you hold CISSP and CCSP certifications, when you submit a CPE activity (or when ISC2 automatically adds credits from official webinars/events), you select all applicable credentials. For example, attending a 2-hour information security webinar counts as 2 CPEs toward your CISSP and 2 CPEs toward your CCSP at the exact same time. Once you complete the required CPE credits for each track, you can renew them.
What Is The Easiest Way to Earn ISC2 CPE Requirements Credits?
As we’ve mentioned above, earning one CPE credit requires a one-hour activity. For full-time professionals, it is not easy to find time to attend professional activities, conferences, or seminars. Even if you can find time to attend, they might be in other cities or expensive to attend. ISC2 CPE webinars can be easy to attend from home or work; however, typically they count for one CPE credit. So, it will be very hard to find tens, if not hundreds, of webinars to attend and earn CPE credits. Also, you must arrange your time to attend the webinar as well.
Earning ISC2 CPE credits through the online ISC2 CPE courses category is the most popular way for professionals. We’ve summarized the “why” in the following figure.

While there are several benefits of earning ISC2 CPE credits through ISC2 CPE courses, here are the top five reasons:
- No Caps: There is no maximum limit for the Education category, so you can earn all ISC2 CPE needs in one program, satisfy the ISC2 CPE requirements and renew your certification. You do not need to go elsewhere to find additional CPEs to renew ISC2 certification.
- Self-Paced: You do not need to attend an event, conference, or seminar. You can follow the courses at your place, at your pace.
- Affordable: Depending on the program content, you can enroll in a self-paced ISC2 CPE Online Training for ~$200-300. However, seminars or conferences start at $1,000; not only that, you may not earn all the CPEs needed in one event.
- Requires less effort: When you enroll in CPE Courses, all you have to do is follow the curriculum, earn CPEs, and renew your ISC2 certification. However, other CPE credit-earning ways require significant effort from the ISC2 certification holder, such as creating content, sharing a presentation, authoring, etc.
- Less prone to ISC2® audit: Since the ISC2 CPE training programs are used by many certified professionals, ISC2 already has a track record of the activities. However, for other categories, CPE submissions are more unique and may be more likely to hit an audit.
ISC2 CPE Online Courses to Renew ISC2 Certification
San Francisco Business School offers ISC2 Certification Renewal Course programs. The ISC2 CPE Training Programs by SFBS come with six self-paced cybersecurity and business training programs: AI & Cybersecurity, Machine Learning Principles for Secure Systems, Cybersecurity Best Practices for AI Systems, Executive Leadership, Strategy Creation & Execution, and Marketing Strategy. For each course in the programs, SFBS awards a certificate of graduation. While earning CPEs, you will earn reputable business merits to highlight in your resume and LinkedIn.

There is a CPE rule for Education CPE credits. You can submit a maximum of 40 CPE credits per entry. While you can earn all required CPEs through the education category, you must submit separate CPE entries for each course.
ISC2 CPE Requirements #2 – Group A and Group B Difference
We have seen the Group A and Group B difference in the ISC2 CPE Requirements table above in the beginning of the article. Let’s explain the difference between Group A and Group B activities now. ISC2 classifies continuing education activities in two main groups: Group A or Group B.
Group A activities must be directly related to the certification track’s main focus.
For instance, if you are a CC certified professional (Certified in Cybersecurity), only cybersecurity or information security-related activities will count as Group A activity. You can earn Group A ISC2 CPE Credits through the following example activities:
- Education: Taking an online course such as ISC2 CPE Courses (*Most Popular)
- Reading (a cybersecurity or information security paper or article)
- Publishing (if you are authoring a blog or writing a book)
- Attending ISC2 Security Congress
- Presentation (if you are preparing a presentation about information or cybersecurity or teaching)
- Performing a unique work-related project that is not part of your normal work duties (for instance, if you are invited for a research project)
- Self-study related to research for a project or preparing for a certification examination (if you are working for another cybersecurity certification)
- Volunteering for government, public sector, and other charitable organizations (for instance, if you are helping a charity to improve their cybersecurity applications)
- Taking a higher education course
Group B activities may be related to professional or soft skill development.
For instance, if you attended a leadership course or a communication course, this is not directly related to cybersecurity; however, it counts as professional development, and you can satisfy the ISC2 CPE requirements from these activities as well. You can earn Group B ISC2 CPE Credits through the following example activities:
- Attending non-security events, such as leadership conferences
- Participating in non-security education courses such as Business Strategy Training.
- Preparing for non-security presentations/lectures/trainings
- Non-security government/private sector/charitable organization committees
How Can I Know If a CPE Activity Belongs to Group A or Group B?
There are certain criteria to understand if an activity belongs to Group A or Group B.
- Look at the definition: Group A activities are related to information security or cybersecurity, which is actually the core of ISC2. Group B activities are more soft-skill courses such as leadership, strategy, communication skills, etc.
- Ask the question: Does this activity help to improve my technical skills or soft skills? Typically, technical activities belong to Group A, and soft skill activities belong to Group B.
When you are fulfilling your ISC2 CPE requirements, you can use the following matrix to identify if an activity belongs to Group A or Group B.
| Feature | Group A: Directly Related / Technical | Group B: General Professional Development |
| Definition | Activities directly related to the specific domains and skills covered by your certification. | Activities that enhance your general professional, managerial, or soft skills, but are outside your certification’s core domain. |
| Focus Area | Core technical domain, industry standards, threat modeling, security architecture, audit, hands-on labs. | Leadership, communication, project management, non-security IT skills, foreign languages, interpersonal skills. |
| Relevance Test | “Does this directly build or maintain knowledge in my certification’s official syllabus/domains?” | “Does this make me a more capable professional, manager, or leader overall?” |
| Contribution Cap | No cap. You can fulfill 100% of your required CPE credits using Group A alone. | Capped. Usually maximum 25–30% of total required CPEs (e.g., max 30 out of 120 CPEs over a 3-year CISSP cycle). |
Can I Satisfy ISC2 CPE Requirements for Free?
While you can earn a few ISC2 CPE credits for free from webinars and free activities, it is practically not easy to complete all required CPE credits through free activities. Besides, entering several CPE reports may trigger an audit by ISC2, as you will enter several 1-2 CPE credit activities in your reporting. We also offer a Free ISC2 CPE Credit Course Online. You can attend and earn three CPE credits for free. No credit card is required.
San Francisco Business School offers a self-paced Free ISC2 CPE Course Online Program as well. If you attend this program, you can earn 3 Free ISC2 CPE credits and submit them in the education category. Considering you are a full-time working professional and looking to earn ISC2 CPE credits in one step, look into our ISC2 CPE Online Courses.
You can read more about earning Free CISSP CPE credits.
ISC2 CPE Requirements #3 – Pay Annual Management Fee (AMF)
ISC2 requires certification holders to pay an annual management fee (AMF) to keep their certification status active. We’ve created the following table to summarize the ISC2 Annual Management Fee (AMF) structure.
| Category | Applicable Certifications | AMF Rate | Payment Due Date |
| Standard Member Fee for Single Certification Holders | CISSP, CCSP, SSCP, CGRC, CSSLP, ISSAP, ISSEP, ISSMP | 135 USD / year | Earliest certification anniversary |
| Entry-Level Fee for CC Certification Holder | Certified in Cybersecurity (CC) only | 50 USD / year | CC certification anniversary |
| Multiple Certification Holder | Any combination of ISC2 credentials | 135 USD total (Single fee covers all) |
Earliest certification anniversary |
If you hold a CC (Certified in Cybersecurity) certification, the AMF is 50 USD per year. For all other ISC2 certifications, members must pay 135 USD per year. The payment due date is the anniversary of the certification you earned. For instance, if you earned CISSP certification on 15th of April, you will pay the AMF until 15th of April every year. If you hold more than one ISC2 certification, you pay only one AMF, which is 135 USD per year, and it will cover all your certifications.
Why Do We Pay AMF?
ISC2 reinvests its revenue – including AMF – back into the association. AMF ensures the long-term viability of the association and its certifications, while also enabling ISC2 to provide benefits and value to members. Members and Associates of ISC2 also gain access to a wide array of valuable, rewarding professional development opportunities and membership benefits that deliver a robust return on this annual investment.
Summary
We’ve gone through the ISC2 CPE requirements in this article. Basically, there are three important aspects that you must be aware of when satisfying the ISC2 CPE requirements.
First, know the CPE credit requirements. There are different ISC2 CPE requirements for different types of ISC2 certification tracks. You must be aware of the CPE credits you need to earn to renew your certification, report as you earn CPE credits, and follow up the deadline for the three-year cycle.
Second, be aware of the Group A and Group B difference. Group A activities are core domain activities typically related to information security or cybersecurity. However, Group B activities are more related to soft skills such as leadership, business, communication, etc.
Third and last, pay AMF to keep your membership active. The AMF fee is 135 USD per year for all ISC2 certifications except CC. CC certification holders only pay 50 USD per year. Make sure you keep on paying the AMF to ISC2 until your certification anniversary to keep your CPE credits and ISC2 certification active.

