Skip to content
Cybridia CISSP® exam prep

CPE and renewal · Understand

ISC2 AMF: what maintaining the CISSP actually costs

The annual fee has cost 135 US dollars since late 2024 — 125 before that — at a flat rate regardless of how many ISC2 certifications are held, according to the amounts reported by members. It is paid for the first time when endorsement is approved, the certification being valid only after that payment. Three members describe having to sit the full exam again after letting their certification expire.

Updated on 7 min de lecture Par l'équipe Cybridia

Keeping your CISSP has cost 135 US dollars a year since late 2024 — 125 before that — regardless of how many ISC2 certifications you hold. This annual fee, referred to in discussions by its acronym AMF, for annual maintenance fee, produces more irritation than confusion: the amounts are well known, and it is mainly their justification and their side effects that are debated. The figures cited here are those reported by members between 2023 and 2026; the rates in force are published by ISC2 on isc2.org.

How much is the annual fee, and since when?

The accounts date the price change to within a year. Comments up to mid-2024 mention 125 US dollars; those from late 2024 onwards uniformly cite 135 US dollars.

Item Amount reported What the accounts say
Annual fee, comments up to mid-2024 US$125 Cited in particular in the reference thread on whether it is worth paying
Annual fee, late 2024 onwards US$135 Unanimous figure in recent comments
Emeritus status Around US$405 Three years of fees, compared with a single year previously
Fee paid in another currency Up to around US$145 equivalent Effect of an exchange rate seen as unfavourable

The rate is described as flat and independent of the number of certifications held, which comes up regularly as an argument in ISC2's favour when bodies are compared:

"ISC2's fee is also flat rate, regardless of how many of their certs you hold"

The most frequent comparison sets ISC2 against a training organisation whose model is seen as forcing members to buy fresh courses to produce enough credits. The criticism directed at ISC2 concerns the amount and the value of membership, not a forced-purchase mechanism.

When is it paid for the first time?

When endorsement is approved, and that payment determines everything else. The certification is not considered valid until it is made — a point made in a thread devoted to verification timelines:

"Just make sure you're not passing out your resume because your cert technically isn't valid until you pay the AMF after they approve you."

This payment date has a second consequence, often discovered too late: it sets the starting point of the credit cycle. Nothing done before the certification date can be submitted, which includes everything accomplished while waiting for endorsement — three to six and a half weeks after the application is submitted, according to the nine dated timelines in the accounts. How the 120 CPE cycle works covers this point in detail, which cost one candidate in the accounts the benefit of a conference and three certifications taken in the interval.

Does the rate change if you hold several ISC2 certifications?

No, according to the community. A member holding both the CISSP and a second ISC2 certification describes a single fee, but separate credit counters. The same CPE can nevertheless be submitted against both certifications when the subject covers both bodies of knowledge, and events organised by ISC2 are reportedly credited automatically on both sides.

In other words, the second ISC2 certification adds submission work, not annual cost: letting a sibling certification from the same body expire for budget reasons saves nothing at all.

What happens if you do not pay?

This is the most concrete piece of information in all these accounts, and it deserves to be stated plainly: three members describe having to sit the full exam again after letting their certification expire, for want of credits, of the fee, or both.

  • A member certified in 2002 who lost his certification in 2020: "I kept the designation until 2020 when I lost it due to my failure to keep up with my CPE and pay my AMFs".
  • A member certified in 2014 who could not keep up after the Covid period, and whose conclusion is the most quoted sentence in the accounts on the subject:

"Originally passed the test in 2014 but couldn't keep up with CPE's after COVID. So I had to take the test again. […] Best option >>> make time to earn CPE credits so you don't have to retake the F'ing exam!"

  • Another member certified in 2002, expired, who regained the certification in 2025 after two months of revision.
  • A neighbouring case, outside ISC2: a member whose certification from another body was revoked after a difficult professional year with no credits, and who comments: "Won't make that mistake again".

The mechanism described is suspension followed by loss of the certification. The arithmetic is quick: the cost of sitting the exam again, in money and above all in weeks of revision, far exceeds several years of fees. The spending reported by candidates — 750 to 1,000 US dollars per attempt, more outside the United States — is detailed on the page devoted to the price of the exam. That is the argument of the highest-rated comment in the 2024 reference thread, addressed to a security manager who was hesitating to pay:

"Bruh it's $125. You can watch a bunch of webinars and record them for CPEs. […] Never let it lapse unless you're never go back into IT."

There are, moreover, entirely free sources of credits sufficient to cover a complete cycle, which reduces the cost of maintenance to the fee alone.

Is Emeritus status a solution for retirees?

This is the subject that draws the most anger in the accounts. Emeritus status, intended for members who stop working, previously required one year of fees; it now requires three, or around 405 US dollars.

"They're slowly but surely becoming just a money grab. I'm not paying $405 just to put "CISSP Emeritus" on my LinkedIn profile."

One retiree describes taking his complaint to the board, obtaining a five-minute phone call, and then hearing nothing more. The highest-rated comment in the thread sums up the dominant feeling: "Make no mistake, it has always been a money grab for this cert".

Practical conclusion from the accounts: for someone permanently retired, letting it expire costs less than the honorary status. The calculation changes the moment a return to work, even a part-time one, remains plausible.

How can payment and exchange-rate surprises be avoided?

Two concrete irritants are documented, along with their workarounds.

The first is a payment failure linked to the browser: a member going through endorsement cannot add the fee to his cart, getting the message "product could not be added to your cart". The problem was resolved by switching browsers, with other members in the same thread confirming the behaviour.

The second is the exchange rate applied by ISC2, seen as unfavourable. The same thread reports that a payment made in local currency came to around 145 US dollars instead of the 135 US dollars expected; the advice that follows is to pay directly in US dollars and let your bank handle the conversion.

One last habit worth keeping: check the due date and the validity of the payment method on file. The loss of certification described above takes no conscious decision, only a renewal that goes unnoticed.

Should you keep your certification when you leave the field?

The accounts rarely settle the question, but they do shed light on it. Those who give it up are mainly retirees and professionals changing career, and the argument is one of simple budgeting: "if you're retired, let it expire". The order of priority is sometimes explicit among those holding several certifications: drop the general entry-level ones, keep the high-level ones.

Three counter-arguments come up consistently.

The first is the job market. One member describes how "every position required a CISSP, and it was even one of the options on the application form — answering no led to automatic disqualification". That is exactly the filtering role certified members describe in the CISSP career assessment.

The second is unpredictability: "companies change, and you never know when you won't be renewed". A career change does not guarantee that the certification will not be needed three years later, in particular for consulting work.

The third is financial: many employers reimburse the fee, one member writing that he has "never paid this fee out of pocket". Before giving up, the first question to ask is therefore whether it will be covered.

The decision remains personal, but it should be taken with a clear view of what leaving costs: in the cases reported in the accounts, the certification was not reinstated — it was earned again by sitting the exam. The conditions for reinstatement appear on isc2.org.

Frequently asked questions

How much is the ISC2 annual fee?

135 US dollars a year since late 2024, up from 125 before that, according to the amounts reported by members; the rate in force can be checked on isc2.org.

Does the fee increase if you hold several ISC2 certifications?

No: the fee is a flat rate, independent of how many ISC2 certifications are held. It is an argument frequently made against bodies that charge a fee per certification.

When is the fee paid for the first time?

When endorsement is approved. A point emphasised in the accounts: the certification is technically not valid until this first payment is made, and the CPE counter does not start before it either.

What happens if you do not pay?

Suspension, then loss of the certification. Three members describe having to sit the full exam again after expiry, including one certified since 2002 and one certified in 2014 who could not keep up the pace after the Covid period.

Is Emeritus status worth it for a retiree?

Rarely: since it requires three years of fees, around 405 US dollars, compared with a single year previously, several retirees say they would rather let their certification expire.

Where does this information come from?

This article draws on the public reports of several thousand candidates, published over the last three years (24 July 2023 to 24 July 2026) and synthesised topic by topic. Quoted extracts are anonymised. Our method in detail.

More on this topic

Explore other topics