ISC2 certifications do not usually change three at a time. In 2026, they are. The CISSP experience waiver list got cut in half back in April. The CCSP moved to a new exam outline on August 1. The CC follows with its own refresh on September 1. None of this is speculation or a vendor teaser: all three dates have already passed or are locked in, and two of the three changes are already live.

If you are studying for any of these three credentials right now, or planning to start soon, the changes affect your timeline, your study materials, or your eligibility path, depending on which one you are chasing. Here is what actually changed in each case, what stayed the same, and which of the three makes sense to prioritize first.

Why Three ISC2 Credentials Are Changing in the Same Year

ISC2 runs a Job Task Analysis, or JTA, on a three-year cycle for each of its certifications. A JTA is a formal review where working professionals in the field are surveyed about what the job actually involves today, and the exam outline gets rewritten to match. CCSP and CC happened to land in the same JTA window this year, which is why both are changing within five weeks of each other rather than being spread further apart.

The connective thread across both refreshes is artificial intelligence. Neither exam is adding a standalone “AI domain.” Instead, ISC2 folded AI-related content into the existing domain structure of each exam, on the reasoning that AI is now part of how cloud and cybersecurity work gets done rather than a separate specialty. That approach lines up with where the job market already sits: ISC2’s own workforce research puts the global cybersecurity staffing gap at roughly 4.8 million unfilled roles, and AI-adjacent security work is one of the fastest-growing reasons employers cite for that gap.

ISC2 Cut Its CISSP Experience Waiver List in Half

This change has nothing to do with the CISSP exam content itself. It changes who qualifies to sit for it without the full experience requirement, and it already took effect months ago.

What Changed on April 1, 2026

The CISSP normally requires five years of paid work experience across at least two of its eight domains. For years, ISC2 let candidates waive one of those five years by holding one of roughly 50 approved certifications. As of ISC2’s own announcement, that list dropped to 26 credentials. A certification only stays on the list if it meets three specific criteria: it publishes its exam outline publicly, it carries ANAB/ISO 17024 accreditation or an equivalent from a recognized body, and its content overlaps at least 90 percent with two or more CISSP domains.

Several well-known certifications did not survive that filter, including CEH, CISA, CRISC, and OSCP.

Which Certifications Still Waive a Year of Experience

The 26 credentials that remain on the approved list span several vendors, not just ISC2’s own catalog:

  • ISC2’s own family: CCSP, CGRC, CSSLP, HCISPP, ISSAP, ISSEP, ISSMP, SSCP
  • CompTIA: CASP+, CySA+, Security+, SecurityX
  • Cisco: CCIE Security, CCNA, CCNP Security
  • AWS Certified Security – Specialty
  • ISACA’s CISM
  • Several GIAC certifications
  • Microsoft Certified: Cybersecurity Architect Expert
  • Select Zscaler credentials

Notice what is missing from that list: ISACA’s own CISA and CRISC did not make the cut, even though CISM did. That is a meaningful distinction if you hold, or were planning to earn, one of ISACA’s other credentials specifically to shortcut the CISSP timeline.

What to Do If CEH, CISA, or CRISC Was Your Plan

If you already hold one of the removed certifications, nothing retroactive happens to you. The change only affects new CISSP applications submitted after April 1, 2026. If you were mid-plan and hadn’t applied yet, you now need either the full five years of unwaived experience or one of the 26 surviving credentials. For anyone who picked up CRISC specifically as a stepping stone, it’s worth reading up on what the CRISC credential is actually good for on its own merits, since it still carries real weight in governance and risk roles even though it no longer shortcuts the CISSP application.

Having watched ISC2 run this cycle before, the practical read is simple: the waiver list isn’t a formality, it’s a real gate, and it just got narrower. Anyone leaning on a certification that didn’t survive the cut needs a new plan, not just a delayed one.

The CCSP Exam Moved to a New Outline on August 1, 2026

This is the change with the most immediate relevance, since the cutover already happened three days before this article was published.

What’s Actually Different in the Six Domains

The CCSP keeps its familiar six-domain structure and its adaptive testing format. What changed is the content inside those domains, refreshed through ISC2’s Job Task Analysis process and covered in detail on ISC2’s official CCSP exam outline:

  • Cloud Concepts, Architecture, and Design
  • Cloud Data Security
  • Cloud Platform and Infrastructure Security
  • Cloud Application Security
  • Cloud Security Operations
  • Legal, Risk, and Compliance

This is the first CCSP refresh to weave AI and machine learning security considerations across all six domains instead of treating cloud AI as an afterthought. The most concrete addition is OWASP LLM Top 10 material inside Domain 4, Cloud Application Security, meaning candidates are now expected to understand the specific risks tied to large language model applications running in cloud environments, not just traditional application security patterns.

Cost, Format, and Eligibility (What Didn’t Change)

The parts of the CCSP that generate the most confusion are actually untouched by this update:

  • Exam fee stays at $599 through Pearson VUE
  • Eligibility still requires five years of cumulative paid IT experience, with three years in information security and one year in one or more of the six CCSP domains
  • Holding the CISSP still waives the entire CCSP experience requirement, not just part of it
  • Renewal still runs on a three-year cycle requiring 90 CPE credits, at least 60 of them from Group A activity tied directly to the six domains, plus a $135 annual maintenance fee

If your exam date falls before August 1, you were tested on the prior outline. Anything scheduled on or after that date follows the new one, regardless of when you started studying.

Who Should Care About the CCSP Refresh Right Now

Anyone who already scheduled an exam date past August 1 needs updated study material, full stop. Materials built for the old outline will still cover most of the exam correctly, since the domain structure didn’t move, but they will miss the new AI and LLM security content entirely. If cloud security is your target career path rather than a box to check, this is also a reasonable moment to look at how CCSP stacks up against the other cloud security credentials on the market before committing your study hours to one path. DirectCertify’s own CCSP practice test set is worth checking against the current outline directly if you’re deciding when to schedule.

The CC Exam Gets Its AI-Era Refresh on September 1, 2026

The CC, short for Certified in Cybersecurity, is ISC2’s entry-level credential, and it’s changing next, one month after the CCSP.

What’s New Across the Five Domains

The CC keeps its five domains intact in name and structure:

  • Security Principles
  • Business Continuity, Disaster Recovery, and Incident Response Concepts
  • Access Controls Concepts
  • Network Security
  • Security Operations

What ISC2 added is foundational AI awareness woven into each one: recognizing what counts as an AI asset inside an organization, spotting automated or AI-driven attack patterns, and understanding the basics of AI governance. None of this assumes prior AI knowledge. The point of the CC has always been to test whether someone new to the field understands core concepts, and ISC2’s own CC certification page frames the AI additions the same way, as baseline awareness rather than technical depth.

The format itself doesn’t change: 100 questions, 120 minutes, delivered as a computer adaptive test at Pearson VUE centers.

The Free Voucher Era Just Ended

For years, ISC2’s One Million Certified program let a large number of candidates sit the CC exam for free. That program stopped accepting new enrollments on May 20, 2026. Anyone who already claimed a voucher code before that date can still use it through December 31, 2026, but new candidates are now paying the standard rate: $199 for the exam plus a $50 annual maintenance fee. That’s a real shift for anyone who was counting on the free path and hadn’t registered yet.

Why CC Still Makes Sense as a Starting Point

Losing the free voucher doesn’t change what the CC is good for. At $199, it’s still one of the cheaper ways to put a recognized credential in front of a hiring manager with zero required experience, and the new AI content arguably makes it more relevant to entry-level SOC and helpdesk-adjacent roles than the previous outline was. If you’re weighing CC against other beginner-friendly paths, a broader look at where entry-level certifications fit against more advanced ones is a useful next read before you commit to a study plan.

CC vs. CCSP vs. CISSP: Which One Should You Actually Prepare For

Laid side by side, the three credentials serve different points in a career, not competing versions of the same thing.

Credential 2026 Change Exam Cost Experience Required Renewal Best For
CC New outline, Sept 1 $199 + $50/yr AMF None 3-year cycle, AMF-based Career starters, no prior experience
CCSP New outline, Aug 1 $599 5 yrs (3 infosec, 1 in a CCSP domain) 3 yrs, 90 CPE + $135/yr AMF Cloud-focused security roles
CISSP Waiver list cut, Apr 1 $699 5 yrs across 2+ domains 3 yrs, 120 CPE + $135/yr AMF Senior/leadership security roles

How the Three Credentials Stack Into One Career Path

ISC2 markets these as a deliberate progression, and for once the marketing matches reality reasonably well. CC works as a first credential for someone with no security background. CCSP fits once you’ve accumulated real cloud security experience and want a specialization that pays a premium over general security roles. CISSP sits at the top as the broad, leadership-track credential once you clear five years of qualifying work. If you’re already eyeing the top of that path, DirectCertify’s CISSP practice test set covers all eight current domains at the exam’s existing 360-minute, 1,487-question scale.

If You Only Have Time to Prepare for One Right Now

A few concrete factors should decide which one you prioritize this year:

  1. If you have zero professional security experience, start with CC. Nothing about the CCSP or CISSP eligibility rules changes that math.
  2. If you already work in cloud infrastructure or cloud-adjacent security and meet the experience bar, CCSP’s new outline is worth tackling now rather than waiting, since the content only gets more AI-heavy from here, not less.
  3. If CISSP is your target but you were relying on a waived year of experience, check the new 26-credential list immediately rather than assuming your existing certification still qualifies.
  4. If you hold the CISSP already, none of this changes your standing. The credential itself isn’t being re-tested or revoked.

What Cybersecurity Certification Is Actually Worth in 2026

The dollar figures behind these credentials are part of why ISC2’s changes get this much attention every cycle. ISC2 itself lists CCSP among the top-paying certifications in the field, with average earnings around $137,100 in the United States and $115,150 globally. CISSP tracks even higher: Glassdoor’s current salary data puts the median total pay for CISSP holders in the US at roughly $164,000.

Demand is the other half of the story. ISC2’s most recent Cybersecurity Workforce Study puts the global staffing shortfall at about 4.8 million unfilled positions, with roughly 522,000 of those in the United States alone and the largest single regional gap, 3.4 million, in Asia-Pacific. That gap is exactly why AI security skills are showing up across CC, CCSP, and eventually CISSP: employers are already asking for people who can secure AI-integrated systems, and the credentialing bodies are playing catch-up. CompTIA made a similar bet this year with its own dedicated AI security credential, and how that certification is structured is a useful comparison point if you’re trying to figure out where AI security specialization is heading industry-wide.

DirectCertify is an independent certification prep provider. We are not ISC2, and we do not administer the CC, CCSP, or CISSP exams or set their pricing, eligibility rules, or outlines. Treat ISC2’s own certification pages as the authoritative source for current exam codes, fees, and policy details, since those can and do change between updates to this article.

Frequently Asked Questions

Do I need to retake the CISSP because of the waiver list change?
No. The April 2026 change only affects new applicants trying to waive a year of experience with another certification. If you already hold an active CISSP, your credential is unaffected.
Will my CCSP study materials still work after August 1, 2026?
Mostly, since the six domains didn’t change names or order. What older materials will miss is the new AI and machine learning content, including the OWASP LLM Top 10 material added to Domain 4. Anyone testing on or after August 1 should confirm their materials were updated for the new outline.
How much does the CC exam cost now that the free vouchers are gone?
$199 for the exam plus a $50 annual maintenance fee. The One Million Certified free-voucher program closed to new enrollments on May 20, 2026, though anyone with an unexpired code can still use it through December 31, 2026.
Can I still use CEH or CISA to waive a year of CISSP experience?
No. Neither made the cut when ISC2 trimmed the waiver list from roughly 50 certifications to 26 on April 1, 2026. CCSP, CySA+, Security+, CISM, and CCNA are among the credentials that did survive.
Is the CISSP exam content itself changing in 2026?
Not directly. The waiver list update changes eligibility, not exam content. CISSP follows the same three-year Job Task Analysis cycle as CCSP and CC, so a content-level update is expected eventually, just not yet scheduled or dated.
Which ISC2 certification should I start with?
CC if you have no security experience yet and want an entry point. CCSP once you have real cloud security experience and want a specialization that commands a pay premium. CISSP once you’ve cleared five years of qualifying experience across at least two of its domains, either directly or through one of the 26 remaining waiver credentials.