Skip to content
Cybridia CISSP® exam prep

CPE and renewal · Understand

Where to find free CPE for your CISSP

The source most recommended by the community is BrightTALK, which credits the ISC2 account automatically when the member ID is entered there, followed by the SANS virtual summits and the quizzes on the ISC2 dashboard. Podcasts, books and videos count as self-study, submitted manually with a short summary.

Updated on 7 min de lecture Par l'équipe Cybridia

BrightTALK, the SANS virtual summits and the content in the ISC2 member dashboard: these are the three free sources the community recommends first, with remarkably stable answers over three years. The rest — podcasts, conferences, certifications — is supplementary. Whether an activity is eligible and which group it falls under is a matter for the CPE Handbook published on isc2.org — the accounts include one case of 20 hours being reclassified after the fact from group A to group B.

Which source does the community recommend most?

BrightTALK, with no serious competition. It is the reflex answer, sometimes given without further comment:

"BrightTALK. Nothing else."

The main appeal lies in automatic crediting: the ISC2-sponsored channels post CPE directly to the account when the member ID is entered there. The channels cited in the accounts are ISC2 Think Tank, Knowledge Vault, APAC Secure Webinars and Security Briefings, including an EMEA edition.

Two reservations come up. The first is the volume of marketing email that follows registration, to the point where the shared advice is to use a dedicated email address. The second is that automatic crediting is described as temperamental: it works most of the time, but not always.

Which sources credit the ISC2 account automatically?

Three families stand out: BrightTALK, the SANS virtual summits, and ISC2's own content (quizzes and webinars in the member dashboard). The SANS summits are the subject of the highest-rated comment in one of the threads:

"SANS virtual summits are my main source of CPEs. They're free, always high quality and they register your CPEs with ISC2 automatically"

Here are the free sources cited, with the orders of magnitude and the timings as reported in the accounts.

Source (free) Order of magnitude in CPE Time before it appears on the counter
BrightTALK, ISC2-sponsored channels 1 per hour of webinar Automatic, about 1 week if the address matches the account
SANS virtual summits 12 to 15 per 2-day summit Automatic, timing not specified
ISC2 dashboard webinars Enough, according to one comment, to cover the 120 15 to 45 days
ISC2 Insights quizzes 2 in group A per quiz, about 6 quizzes a year 15 to 45 days
Podcasts 1 per hour of listening Manual submission
Microsoft Learn (SC-200, SC-300 paths) About 40 for one path Manual submission
ISO 27001 Lead Auditor, free training About 11 Manual submission
FutureCon, with free access code About 10 per month Manual submission
SECON, ISC2 New Jersey chapter, online 5 Manual submission
Black Hills / Antisyphon weekly webcasts 1 per hour, certificate provided Manual submission
Vendor and trade magazine webinars 1 per hour Manual submission
Volunteering, writing, local chapter meetings Variable Manual submission

The quizzes deserve a special mention: they are credited in group A, attempts are unlimited, and half a dozen are available over a year, which is a dozen credits for no effort. Their only drawback is how long they take to register, which can be as much as 45 days.

One comment goes further on ISC2's own content:

"The webinars that are available to you in your membership dashboard are enough to earn all 120 cpes"

How many CPE does a conference yield?

Conferences are the second large family of sources. They offer the best hourly yield, but they are not all free.

Event Free or paid Order of magnitude in CPE
ISC2 Security Congress Not specified in the accounts About 70 at once
DefCon Not specified in the accounts 20 to 32
BSides Not specified in the accounts 8 to 16
SecureWorld Paid, 320 US dollars cited 12
FutureCon Free with access code About 10 per month
SECON, ISC2 New Jersey chapter Free, online 5
Local chapter meetings Generally free Variable

On the evidence side, a conference calls for nothing formal: one member audited after DefCon describes supplying screenshots of his own posts taken on site, and that the 35 credits submitted were accepted.

Do podcasts, books and videos really count?

Yes, as self-study, and the community classes them in group A. A trio of podcasts comes up regularly: Security Now, Darknet Diaries and Paul's Security Weekly.

Two practical points stand out. First, submission is episode by episode, which explains the stated preference for long formats — a two-hour weekly podcast produces more credits for the same number of entries. Second, a short written summary is enough as evidence: one audited member reports supplying "a screenshot from Spotify as supporting documentation, and it was accepted".

The same principles apply to books, articles, white papers and training videos. Paid platforms also come up regularly: courses of more than twenty hours bought for around 10 US dollars, or an online training subscription about which one member writes:

"I binged probably 80 CPEs worth of LinkedIn Learning last year"

Can another certification be turned into CPE?

This is one of the richest seams. Preparing for a certification counts as study, and obtaining it is itself submittable — provided it happens after the certification date, that is, once endorsement is approved and the fee is paid. The order of magnitude observed is around 40 CPE for an entry-level certification from a cloud provider.

"My plan is to get one new certification per year. I just recorded my AWS SAA for 40 CPEs."

Two free variants of the same mechanism are cited: the Microsoft Learn paths, which yield around forty credits for a complete path, and an ISO 27001 auditor course of about eleven hours available at no cost.

Hands-on practice platforms fall into the same category, except that a paid subscription is needed to link the ISC2 account:

"Sign up to hackthebox and link your isc2 membership #. Every machine you pwn goes towards your cpe […] I've already earned 250 out of 120 cpes during my first year"

An equivalent platform is cited with paths "worth 40 to 50 CPE each", and submissions of more than forty hours accepted without difficulty.

How can a cycle that has fallen behind be caught up quickly?

Two typical distress calls appear in the accounts: a member in the third year of his cycle with zero credits and ten months ahead of him, and another with a single credit out of the 120 expected. In both cases the replies converge on the same method.

  1. Run through automatically credited webinars, BrightTALK first, to build a base with no submission work.
  2. Slot in one or two free virtual summits, which bring 12 to 15 credits over two days each.
  3. Aim for a high-yield event if the calendar allows: the annual ISC2 congress alone provides more than half a cycle.
  4. Retroactively submit what has already been done since the certification date: reading, podcasts, internal training, professional meetings eligible for group B.
  5. Do the ISC2 dashboard quizzes as early as possible, because of how long they take to register.

The accounts show that catching up works. They also show what it costs not to: the cases of lost certifications all end with an exam to sit again — so with another attempt to pay for, at the amounts listed on the page devoted to the price of the CISSP exam, and with weeks of revision that the accounts of resitting describe as the most gruelling part of the journey.

How long do credits take to appear on the counter?

Only two timings are quantified in the accounts, and they are enough to guide planning. BrightTALK's automatic crediting arrives in about a week, provided the email address used matches the ISC2 account. ISC2 quizzes and webinars are credited within 15 to 45 days.

The consequence is simple: do not count on the last weeks of the cycle. An activity completed in late December for a cycle ending on 31 December may not appear until January. The most widely shared piece of advice in the accounts points in the same direction, and is worth more than any catch-up strategy:

"My advice to a newly minted CISSP is to try to get all the CPE out of the way as early as you can. After mine was issued, I was able to hit my 3 years' worth of CPE within the first 8 months."

For the detail of the count, groups A and B and how audits work, see the guide to the 120 credits.

Frequently asked questions

What is the most frequently cited source of free CPE?

BrightTALK, by a wide margin: it is the community's reflex answer, in particular through the ISC2-sponsored channels. The main advantage is that the account is credited automatically when the ISC2 member ID is entered there; the main drawback is the volume of marketing email that follows.

Can the 120 CPE be covered without spending anything?

Yes: one comment states that the webinars available in the ISC2 member dashboard alone are enough to earn all the credits, and several members show counters well beyond 120 without any particular effort.

How many CPE does a conference yield?

The orders of magnitude reported range from 5 credits for an online chapter event to around 70 for the annual ISC2 congress, with 8 to 16 for a BSides and 20 to 32 for DefCon. These events are not all free.

Do podcasts really count as CPE?

Yes, as self-study and in group A, provided they are submitted manually with a short summary. One audited member reports supplying a screenshot from his listening app as evidence, and that it was accepted.

How long do credits take to appear on the counter?

About a week for BrightTALK's automatic crediting when the email address matches the ISC2 account, and 15 to 45 days for ISC2 quizzes and webinars — a lag to plan for if your cycle ends soon.

Where does this information come from?

This article draws on the public reports of several thousand candidates, published over the last three years (24 July 2023 to 24 July 2026) and synthesised topic by topic. Quoted extracts are anonymised. Our method in detail.

More on this topic

Explore other topics