Skip to content
Cybridia CISSP® exam prep

CPE and renewal · Understand

120 CPE in three years: how CISSP renewal works

You need 120 CPE per three-year cycle, with no annual minimum since 2022 for certified members — the figure of 40 per year that is often quoted is now only a suggestion. The counter does not start until the certification date, one hour of activity is worth one credit, and audits, seen as random, accept informal evidence; the CPE Handbook published by ISC2 remains the reference in case of doubt.

Updated on 7 min de lecture Par l'équipe Cybridia

You need 120 CPE per three-year cycle — and that is all: the annual minimum of 40 has not existed since 2022 for certified members. The question nevertheless keeps coming back, in barely different forms: 40 a year or 120 over three years? When does the counter start? Does a podcast count? The community's answers largely converge, but they sit alongside memories of old rules that no longer apply. This article sets out what certified members understand; the CPE Handbook published by ISC2 on isc2.org remains the reference document in the event of a dispute or an audit.

How many CPE are required, and over what period?

The consistent answer in the accounts: 120 CPE per three-year cycle. The cycle behaves as a single block, not as three annual instalments to be met separately.

The unit of account is simple, and is restated every time a member gets it wrong: one hour of activity is worth one credit. A 2025 thread is explicit on this point, after a member announced 30 to 40 CPE for an eleven-hour course:

"1 hour = 1 CPE so not entirely sure where the 30-40 comes from"

The original poster acknowledged that his estimate came from a conversational assistant and corrected his submission. It is a useful reminder: the figures that circulate need to be checked against the time actually spent.

The volume looks intimidating, but the accounts do not describe it as an obstacle: several members show counters at 250, 400, 467 or even 490 credits without any particular effort, and one of them sums up the winning routine in a single sentence:

"I tend to watch a one-hour webinar on my spare monitor most Fridays, as I finish up my workweek on the primary monitor."

Does the 40 CPE per year minimum still exist?

No, not for certified members — and this is probably the most widespread confusion in the accounts. One comment settles the debate by quoting the handbook:

"ISC2 has a suggested annual minimum to help balance maintaining your certification, however, there is no annual requirement unless you hold the associate status."

The history of this rule is told by a member who describes himself as an ISC2 exam writer and a CISSP of thirteen years:

Period Rule as reported
Before 2020 40 CPE per year mandatory, 120 per three-year cycle
2020 Annual minimum lowered to 20 CPE
Since 2022 Annual minimum removed — only the 120 per cycle remain

"Prior to 2020, you had to do 40 per year, with 120 per 3yr cycle. In 2020 they dropped it to 20/yr and then in 2022, they did away with it all together."

The same person sees this as a risk rather than a gift, and predicts that the disappearance of the annual safeguard will make certified members complacent until "a first batch" loses their certification. The confusion does persist in practice: as recently as May 2026, a newly certified member wrote that he was looking for how to maintain his certification "with 40 CPE per year OR 120 over three years".

What is the difference between group A and group B?

The split is straightforward: group A covers activities directly related to the information security domains, group B covers more general professional development. The typical strategy shared in a thread devoted to accumulating credits quickly:

"Category A: a combination of podcasts, CBTs, and reading white papers / articles. […] Category B: mostly work related stuff like leadership meetings"

The classification is not set in stone, however. A case from January 2026 reports a reclassification of 20 hours from group A to group B decided by ISC2 without warning — including two hours of webinars that ISC2 itself had sent the member by email. Another member describes getting a rejection overturned by rewriting the description of his activity to tie it explicitly to security. The advice that emerges from these threads: challenge the decision, but come with evidence.

"If you can show why they should count they will likely accept them."

Practical consequence: write your activity descriptions with someone in mind who will have to judge, later and without context, whether the hour submitted really belongs to security.

When can you start accumulating credits?

Only from the certification date, that is, once endorsement is approved and the annual fee is paid.

"You can't collect CPE until after your certification date which is when it is fully endorsed"

The trap is real. One candidate describes "losing" an RSA conference and three certifications taken while waiting for his endorsement: none of it could be submitted. With the endorsement timelines reported running between three and six and a half weeks after the application is submitted — and longer where the experience is reviewed in depth — that is a window during which training effort does not count. Since payment of the fee is part of the trigger, how the AMF works directly determines when the counter starts.

For those holding several ISC2 certifications, the accounts describe separate counters, but the same CPE can be submitted against both as long as the subject covers both bodies of knowledge; events organised by ISC2 reportedly apply to both automatically.

Can surplus CPE be carried over to the next cycle?

Partly. The carry-over described by the community only concerns credits earned during the last six months of the cycle, with a cap of 40 mentioned — a figure to be confirmed in the CPE Handbook before building a plan on it.

Everyone agrees on the practical implication: do not stop submitting your activities once the 120 are reached, if the end of the cycle is approaching. What is earned in that final window is not lost.

How does an audit work and what evidence is accepted?

CPE audits are described as random, and not fussy about the form the evidence takes. One member describes being audited for the first time in several years over a half-credit on an online course, and concludes that the selection is in no way targeted.

Evidence reported in the accounts Outcome described
Screenshot from a podcast listening app Accepted
Screenshots of posts taken during a conference Accepted, 35 credits validated
Certificates of completion, receipts Accepted
Plain statement of what was done Sometimes sufficient

"'proof' doesn't have to be formal… sometimes (gasp) they'll take whatever you tell them you did"

The good practice described is consistent: keep a spreadsheet with date, title, number of hours and link; download certificates when the platform offers them; write two or three lines of summary for podcasts and reading. "No need to be more detailed than that, unless your submission is audited." This audit should not be confused with the endorsement audit, which covers professional experience at the time of application.

What is the risk of letting a cycle slip?

Suspension, then loss of the certification. And the accounts are unambiguous about what follows: among the members who lost their CISSP and needed it again, all had to sit the full exam once more. Four accounts report this, including one member certified in 2002 who let it lapse in 2020 and one certified in 2014 who could not keep up the pace after the Covid period. Sitting the exam again means paying for another attempt: the amounts reported appear on the page devoted to the price of the CISSP exam, and the reasons seasoned professionals fail it in why people fail the CISSP.

The two most frequent catch-up situations in the accounts — "I'm in year 3 with 0 CPE and ten months ahead of me" and "I have 1 credit out of 120" — end well: the replies set out fast catch-up options, essentially back-to-back webinars and conferences. The free sources listed by the community are enough on their own to cover an entire cycle. The most repeated piece of advice remains the simplest, though: start early, even if it means wrapping up the 120 credits in eight months and spending the rest of the cycle without pressure.

Frequently asked questions

Do you really need 40 CPE a year to keep your CISSP?

No: the annual minimum was removed in 2022 for certified members, and only the 120 CPE over the three-year cycle remain, the 40 per year being an ISC2 suggestion to spread the effort. Associate status, on the other hand, is still subject to an annual requirement, detailed in the CPE Handbook on isc2.org.

How many CPE is one hour of training worth?

One credit per hour: that is the rule restated every time a member gets it wrong. A submission of 30 to 40 CPE for an eleven-hour course was corrected publicly — the figure came from a conversational assistant, and the author revised it.

Do CPE earned while waiting for endorsement count?

No. The counter only starts on the certification date, that is, once endorsement is approved and the annual fee is paid. One candidate in the accounts describes losing the benefit of certifications and a conference taken during the four to six weeks of waiting.

Can CPE be carried over from one cycle to the next?

Yes, partly: only credits earned during the last six months of the cycle carry over, with a cap of 40 mentioned — a figure reported second-hand, to be confirmed in the CPE Handbook.

What happens if the cycle ends without the 120 CPE?

Suspension, then loss of the certification. Every member who lost it and needed it again had to sit the full exam once more — four accounts report this.

Where does this information come from?

This article draws on the public reports of several thousand candidates, published over the last three years (24 July 2023 to 24 July 2026) and synthesised topic by topic. Quoted extracts are anonymised. Our method in detail.

More on this topic

Explore other topics