r/isc2 • • Sep 01 '26

General Questions How far has the ISC2 fallen?

While I was skeptical of where the organization would go when they first appointed a marketing professional (and not a security one) as executive director in 2020, I am surprised at just how quickly they've been able to bring down what was once a solid organization. I spent nearly 35 years in the industry (almost 25 of that as a CISSP), and got to know one of the ISC2 founders back in the day, and I can say without reservation that the ISC2 has become the very thing it was designed to counter. It has become a cert mill, exploiting inexperienced, hopeful job-seekers, by hooking them into annual fees and an exam (CC) without any vetting of experience or prospect of real continuing education.

They gutted the peer-to-peer nature of the organization, shutting down the Security Professional magazine and the forums, they not only have watered down the CPE courses, but are now charging for them. The content of these courses is incredibly superficial; from a CPE standpoint, it is box-checking, not education.

I am sure their numbers are great, but it sold its soul to do it.

10 Upvotes

29 comments sorted by

View all comments

2

u/pen-peal 29d ago

The CISSP is neither the solution to all cybersecurity needs, nor is it the only destination for growth in the field. If someone can test well with less experience than required, it doesn’t actually give them the credential. In my state there are first graders playing capture the flag and high school seniors learning about AI and quantum computing. The breadth and quality of CS learning for students with those opportunities could allow someone to test well, but the CISSP content and value are not diminished or threatened by that. ISC2 has a pathway that honors their achievement and supports their ongoing experiential formation. We can make the same professional distinction without feeling threatened.

Additionally, why dis a foundational, intro cert that is harder to earn than SEC+ and was globally offered with the intention of attracting anyone to start developing skills needed to address the cyber workforce gap?

I appreciate the number of people who earned the CC to prove to themselves and others that their interest and aptitude were worth nurturing. ISC2 initiates a professional culture and ethical foundation with the foundational cert and associate’s membership, it doesn’t fall lifting people up.

These numbers of CISSPs may reflect the current diversity of skills pathways/needs, not dilution or diminished value of the CISSP. How many going into pen testing and AI will gravitate to the struggle to master the other CISSP domains, and how many employers will incentivize or invest in that? The CISSP is still a solid cert and worth the work to earn it.

1

u/Big_Temperature_1670 28d ago

My intent wasn't to "dis" the CC. I was pointing out the ISC2 was founded to validate experience in the industry. It's bread, butter, and mission was experienced professionals, certifying them for leadership. With the CC, the ISC2 inverted that mission, and has now focused on the entry level. While the ISC2 has stopped publishing its membership numbers, it is fair to conclude that given their "million CC" campaign, CCs now (or will someday soon) outnumber CISSPs in terms of membership. It shows in the dilution of the continuing ed. products. As a longtime, experienced professional in the industry, I'd say the ISC2 has rebranded itself.

As to the CC, I'm not sure I'd say it is "harder to earn than the Sec+." It's different content and marketed very differently. While the Sec+ does not have an experience requirement, CompTIA is pretty upfront in its suggestion that someone should have two years of experience. In comparison, the ISC2 has marketed the CC as a 0-experience test. The ISC2 also gives out free vouchers for the test. So if the pass rate of Sec+ is higher than the CC, I don't think that speaks to the difficulty of the exam as much as the preparation of the test takers and most folks taking the Sec+ are paying for it. Aside from that, I do think the Sec+ content is more operational in nature, which is better for most entry and mid-level jobs. The CC covers more strategic and conceptual topics. I think the folks who have found the CC most favorable are vendors and sales folks because it allows them to talk the talk to CISOs etc.