CISSP Year 5: Reflections

The practical impact of the CISSP certification.
career
Author
Published

November 6, 2025

It’s been five cycles since I first held the Certified Information Systems Security Professional (CISSP) credential, earning it back in November 2020. I’ve previously charted the demanding journey to obtaining the certification itself here 🔗. This time, however, I want to step back and reflect, not on the grueling process of getting the badge, but on the practical impact it has had on the following half-decade of my career. What does it actually mean to be “certified” after five years in Information Security? 🤔

Beyond Certifications

For me, any certification or structured learning process only holds true, enduring value if it provides actionable knowledge, a framework capable of bridging skill gaps that would otherwise be hard to cover organically.

The CISSP’s Common Body of Knowledge (CBK) does this well. Its eight domains are carefully defined, covering nearly the entire spectrum of Information Security. By internalizing this structure, you don’t just get exposed to the different areas but understand how these elements interoperate and relate to each other — a broad view that forms a solid professional foundation.

This broad knowledge is valuable because it lets you confidently work with teams of any size and complexity. And since the concepts demand understanding rather than simple recall, the certification gives you a solid introductory depth across many topics. That lets you talk to almost any Infosec professional, moving past the basics into strategic, cross-functional discussions.

Job Opportunities

It’s quite common for professionals to pursue certifications as a path to new job opportunities, and that is a perfectly rational goal. In fact, many job descriptions list the CISSP as a desirable credential. Yet, while it is often desired, I rarely recall seeing it explicitly required.

In my personal experience, the CISSP was never the deciding factor that secured a position or guaranteed a promotion, and I honestly don’t have a problem with that. In the end, the certification is just a professional badge. What actually drives success, in my view, is proven accomplishments:

  • The quantifiable impact of your actions
  • The demonstrable value you add to the business

Keeping the Badge

To maintain the certification, (ISC)² requires two things: payment of the Annual Maintenance Fee (AMF) and the collection of Continuing Professional Education (CPE) credits. Unlike some other certifications, there is no need to repeat the grueling examination. I think this approach is great because, at the end of the day, what matters is keeping the intellectual fire lit, staying up-to-date with new technologies and emerging threats.

CPEs are the required evidence of this ongoing professional development. The beauty of this system is its flexibility: we can claim credits for:

  • Applied research
  • Formalized training
  • Even relevant on-the-job experience, provided the activity maps back to the CBK domains.

This means that simply by working and developing within the Infosec area, you are continuously collecting the necessary CPEs, renewing your certificate just by being an engaged professional.

Criticism

My only point of criticism is related to the tangible benefits offered to certified professionals, or “members.” Currently, the offering seems sparse, mostly limited to discounts on (ISC)² events and access to a few foundational courses. Considering the price of the annual fee, I believe the value proposition could be substantially improved.

For instance, I struggle to comprehend the rationale behind billing members to attend virtually to the very events the organization is hosting. Even if a fee structure is deemed necessary, charging hundreds of dollars for virtual attendance is prohibitive. For professionals like myself located in emerging countries where the US Dollar is not the national currency, this is more than just “not okay”; it becomes an absolute blocker to participation.

Regarding alternative benefits, if this annual fee were translated, for example, into complimentary access to a resource library like O’Reilly’s virtual catalog, the value would be obvious. As it stands, I just pay the fee to renew, expecting no real benefits from (ISC)², which is, frankly, a pity.

Final Thoughts

I once read that “T-shaped” engineers work effectively in most areas and are experts in at least one, and the CISSP is designed to help you reach that broad, foundational knowledge. It’s a good example of finding real happiness in the journey of learning, not just in hitting the pass/fail score. The lasting value of this certification is tied to its body of knowledge. Mastering it will make you a more consistent and capable Infosec professional, and let you move across the different domains with confidence.

If this certification included clearly better benefits, such as relevant professional subscriptions or the chance to join official events for free or at genuinely competitive prices, it would add to the professional obligation it represents. This perceived lack of valuable benefits makes me consistently re-evaluate the decision to renew the certificate.

And yet, here I am, re-certified for the next cycle and with all my CPEs already filled one year in advance.

Do I recommend pursuing the CISSP after five years? Definitely, for the knowledge it imparts. Do I recommend perpetually keeping certified? Well, with the current balance of cost and benefit, I’m not entirely sure. However, with simple, member-focused adjustments, (ISC)² could easily turn that into an enthusiastic definitely yes answer.

Reuse

Citation

BibTeX citation:
@online{lopes2025,
  author = {Lopes, Joe},
  title = {CISSP {Year} 5: {Reflections}},
  date = {2025-11-06},
  url = {https://lopes.id/log/cissp-year-5-reflection/},
  langid = {en}
}
For attribution, please cite this work as:
Lopes, Joe. 2025. “CISSP Year 5: Reflections.” November 6. https://lopes.id/log/cissp-year-5-reflection/.