Skip to main content
Cloud Security EngineerListed as a relevant cert for that lane. Back to pathway
Senior security governance
(ISC)² · neutral

CISSP

Certified Information Systems Security Professional. The gold standard for senior security roles, with a heavy governance and architecture focus across 8 broad domains.

DifficultyAdvanced
Study4–8 months
Exam£630
Valid3 years
FormatCAT exam, 125–175 questions
Practical weight10% practical / 90% theory & policy
Compare
POST verdict
StrongMarket-level call. Not personal advice.

A senior-bracket signal that does its work quietly over eighteen months, not the week after you pass.

Confidence: High Signal strength: High
Twenty years of consistent recruiter behaviour in UK enterprise, defence and consultancy. The slow burn is the pattern, not a bug.
Finance, defence, large consultancies and the public sector still shortlist on it. Product startups care a lot less. Geography matters.
Who this pays off for
  • People with five-plus years of security work eyeing a first management or architecture seat
  • GRC and security-management track candidates
  • Internal movers who want the next salary band to open without changing employer
Who walks away with nothing
  • Anyone with under three years in security. Associate status isn't a job.
  • Detection engineers, red teamers and AppSec people. Wrong shape, GCIH, OSEP and CSSLP do more.
  • Career changers using it as a shortcut into cyber
The named failure mode

Treating it as a shortcut into cyber. CISSP is a multiplier on existing experience, not a substitute for the five years it requires.

Recruiter signal, not marketing

Recruiter inbound goes up. Internal conversations about senior or lead roles get easier to start. The salary band on the next move opens by five to fifteen percent in the right market.

Falsifiability
  • (ISC)² changes the five-year experience requirement or the verification process
  • CCSP or a cloud-native equivalent becomes the default senior signal in product companies
  • UK enterprise hiring shifts decisively away from formal certification gating
What it actually costs
£560 (one attempt)
£100/year AMF plus 120 CPE credits every 3 years
£0 self-study with the OSG, £1,200–£3,500 for a structured bootcamp

UK figures, indicative. Exam vendors revise pricing without notice.

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert sits inside the Security Architect (after 7+ years) pathway. The pathway is where the sequencing call lives.

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • Security Manager
  • Security Architect
  • GRC Lead
  • CISO (with additional experience)
Practitioner take

CISSP is genuinely worth it for exactly one person: someone with five-plus years of real security experience aiming at GRC, security management or senior architecture. For that person it's a salary bump, a recruiter magnet, and the credential that gets them into rooms. For everyone else it's a £600 exam and 200 hours of study that produces nothing recruiters care about, because they'll see two years of experience next to a five-year-experience cert and assume something's off. The cert isn't the problem. The timing is. Wait until you've earned it, then take it seriously.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • 5+ years cumulative paid security experience (2 of the 8 domains)
  • Broad exposure across security, networking, and risk
  • Comfort with policy / governance concepts

Common misconceptions

  • CISSP is technical, it's primarily governance & architecture.
  • It's a 'first' senior cert, most pursue with 5+ yrs experience.

What this cert does NOT guarantee

  • Hands-on engineering roles
  • Management title automatically

Practical skills that matter

  • Risk management
  • Security architecture
  • Policy & governance
  • Incident response leadership
  • Stakeholder communication

Where this fits

A cert is only useful for some routes. Here's where this one earns its place.

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what people usually do. A Career Verdict judges whether it's realistic for you.

Get a judgement on your situation£39, one-off. Built for your inputs, yours to keep.

Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.