1.3 Eligibility, Associate Pathway, Endorsement, and Maintenance
Key Takeaways
- SSCP certification requires at least one year of full-time experience in one or more of the seven SSCP domains; a qualifying bachelor's or master's degree in computer science, IT, or a related field may satisfy that year.
- Candidates who pass the exam without the required experience become Associates of ISC2 and have two years to earn the one year of experience.
- Endorsement must be completed within nine months of the exam by an ISC2 member in good standing (any credential) or through ISC2 endorsement assistance.
- SSCP members pay a USD $135 Annual Maintenance Fee (one AMF even with multiple non-CC-only credentials) and must earn 60 CPE credits over a three-year cycle: 45 Group A plus 15 Group A or B.
- Associates pay a USD $50 AMF and must submit 15 Group A CPE credits each year; upgrading to member after the $50 is already paid requires the USD $85 difference.
Why the post-exam path is part of the exam
A Pearson VUE printout that says "pass" does not authorize you to write SSCP after your name. ISC2 certification is a bundle: examination, qualifying experience, endorsement, first Annual Maintenance Fee (AMF), and ongoing Continuing Professional Education (CPE) plus AMF. Associates who skip the experience clock, candidates who miss the nine-month endorsement window, and members who ignore CPE all lose the credential even though the CAT session went well.
Think of this section as the identity-lifecycle chapter for you: proofing (experience), provisioning (endorsement and AMF), monitoring (CPE), and deprovisioning (suspension or termination). SSCP Domain 2 will ask you to administer that lifecycle for users. Domain 1 will ask you to follow codes of ethics. Start by applying those ideas to your own certification record.
Experience: one year in one or more domains
Candidates must have a minimum of one year of full-time experience in one or more of the seven domains of the current SSCP Exam Outline. You do not need a year in every domain. A year spent operating access reviews (Domain 2) can qualify. So can a year of network administration with security duties (Domain 6), SOC monitoring (Domain 3), or backup and recovery operations (Domain 4). The work must be information-systems-security-related or must require information-security knowledge and apply it directly. Generic retail-floor time does not count because you reset passwords once a week.
| Experience type | Official accrual rule |
|---|---|
| Full-time | Minimum 35 hours/week for four weeks = one month. Accrual is monthly. |
| Part-time | 20–34 hours/week only. 1040 hours = 6 months full-time equivalent; 2080 hours = 12 months. |
| Below 20 hours/week | Does not meet the part-time band |
| Internship | Paid or unpaid, with documentation on company or organization letterhead (registrar stationery if the internship is at a school) |
| Degree waiver | A qualifying bachelor's or master's in computer science, information technology, or related fields, or an approved cybersecurity program, may satisfy the one year. Only one year can be waived by education or an approved credential — not stacked. |
Full-time is stricter than many job titles. A "full-time" salaried role that is actually 30 hours of security work plus 10 hours of unrelated duties still has to be mapped honestly to hours that apply the SSCP domains. Part-time cannot be less than 20 hours a week and cannot be more than 34; 2080 part-time hours equal the one-year requirement.
Internships count, which matters for career-changers and students. Keep the letterhead letter. If ISC2 audits the endorsement (a random subset of applications), you will need more than a resume bullet.
Degree and approved-program pathway
ISC2 looks for a cybersecurity program that addresses cyber, information, software, and infrastructure security, or a preapproved degree such as Computer Science, Computer Engineering, Computer Systems Engineering, Management Information Systems, or Information Technology. The preapproved list can change; check the current experience-requirements page when you apply. A bachelor's in an unrelated major does not automatically burn the waiver. Conversely, a qualifying degree may satisfy the entire one-year SSCP requirement — unlike CISSP, where education typically waives only part of a longer clock.
Associate of ISC2: pass first, earn the year later
If you pass SSCP without the required experience, you may become an Associate of ISC2. That designation is not the SSCP credential. Associates have two years to earn the one year of experience and to complete the certification application. That two-year associate window is SSCP-specific (CISSP and CCSP associates have longer windows on their own programs).
Associates pay an AMF of USD $50 per year and must earn 15 Group A CPE credits annually, with a 90-day grace period after the associate-cycle expiration. They receive an Associate digital badge, not the SSCP mark. ISC2's mark rules are blunt: Associates are not certified and may not use SSCP, CISSP, or any other certification mark. The allowed description is "Associate of ISC2". Using SSCP on a business card before endorsement can jeopardize future certification.
When the year of experience is in hand, the Associate submits the certification application. After approval, ISC2 instructs the Associate to pay the USD $85 difference if the USD $50 associate AMF for the year is already paid, bringing the year in line with the USD $135 member AMF. The associate cycle ends as "Upgrade Associate," and a three-year member cycle starts on the first of the following month after that upgrade payment. The associate Credly badge is replaced with the SSCP badge.
Endorsement within nine months
All candidates who pass an ISC2 credential exam (except Certified in Cybersecurity, which has no experience requirement) must complete the certification application / endorsement process within nine months of the exam date. You cannot submit before ISC2 notifies you that you passed; early drafts stay in draft mode.
The application needs an endorser: an ISC2 certified professional in good standing who can attest that your experience assertions are true to the best of their knowledge and that you are in good standing in the industry. The endorser does not have to hold SSCP. A CISSP, CCSP, or other ISC2 member in good standing can sign. You will enter the endorser's member ID (certification number) and surname.
If you do not know a member, request ISC2 endorsement assistance. You must submit additional documentation, including proof of employment, so ISC2 staff can review qualifications and consider endorsing you. A percentage of applications are randomly audited; if selected, you provide extra verification. After approval, you pay the first AMF. If you already hold another ISC2 certification, you do not pay a second AMF for the new one.
Miss the nine-month window and you do not become SSCP on a handshake. Keep a calendar reminder the day unofficial results print.
AMF and CPE: staying certified
| Status | Annual Maintenance Fee | CPE requirement |
|---|---|---|
| SSCP member (and other non-CC-only members) | USD $135 per year, one AMF even with multiple certifications | 60 credits in a 3-year cycle: 45 Group A + 15 Group A or B (suggested 20/year) |
| Certified in Cybersecurity only | USD $50 | 45 Group A over 3 years |
| Associate of ISC2 | USD $50 per year | 15 Group A each year (no 3-year 60-credit member total) |
| Associate upgrading after $50 paid | Pay USD $85 difference | Member cycle begins after upgrade |
Group A credits relate to the domains of your credential. Group B credits are professional development outside those domains (management, communication, and similar). SSCP's 15 "A or B" credits can all be Group A if your year was all domain work; they cannot all be Group B.
ISC2 allows a 90-day grace period after cycle expiration to earn and submit CPE and to pay AMF. Miss that grace period and the credential is suspended: you may not use the mark or imply current certification. Suspension can last up to two years; then the record is terminated. Reinstatement from suspension requires outstanding CPE and past-due AMFs. Terminated members have a heavier CPE catch-up or must re-examine; terminated associates re-examine only.
AMF payments are non-refundable. Members with several certifications share one anniversary — the earliest certification date — and one USD $135 AMF (unless the only credential is CC).
Ethics and using the mark
Endorsement includes agreement to the ISC2 Code of Ethics. The four canons, in order, are:
- Protect society, the common good, necessary public trust and confidence, and the infrastructure.
- Act honorably, honestly, justly, responsibly, and legally.
- Provide diligent and competent service to principals.
- Advance and protect the profession.
The preamble puts the safety and welfare of society and the common good first, then duty to principals and to each other. Strict adherence is a condition of certification. On the exam, when two answers both look helpful to an employer, the canon order still prefers public trust and lawful behavior over a principal's convenience.
Use the mark as Your Name, SSCP in capitals without periods. Do not print SSCP on a product, domain name, or team logo. Do not imply that your employer "has three SSCPs" as if the company were certified. Those rules live in ISC2's certification-mark regulations and are easy to violate on LinkedIn the week after you pass.
Realistic candidate scenarios
Priya holds a bachelor's in Computer Science and works a help desk that already performs access provisioning, malware first response, and patch windows. The degree may satisfy the one-year SSCP experience requirement. She still gathers ticket metrics and a manager letter so an audit does not reduce her job to "password resets only." She schedules endorsement inside nine months rather than waiting until the degree waiver is "obvious."
Luis works a network operations center 25 hours a week. That is part-time in the 20–34 band. He needs 2080 hours to equal 12 months. At 25 hours per week he is looking at roughly 83 weeks, not "one calendar year." If he sits SSCP now, Associate status gives him two years to finish the hour count, with USD $50 AMF and 15 Group A CPEs each year.
Aisha passes CAT in March, works in a small shop with no ISC2 members, and assumes she can put SSCP on proposals immediately. She cannot. She files for ISC2 endorsement assistance with employment proof, watches the nine-month clock, and pays USD $135 after approval. Until then she is a passer, not a member. If she skipped experience entirely, she would apply as Associate and would write Associate of ISC2, not SSCP.
Noah earns SSCP, pays the first AMF, then ignores CPE while job-hunting. At the three-year mark plus 90 days he is suspended and must stop using the letters. The exam he passed does not freeze the credential in amber.
Section takeaways
Map your hours to domains before you claim SSCP. Use the degree waiver only when the program actually qualifies, and do not stack education plus another waiver past one year. If you pass early, Associate is the legal path — two years, $50, 15 Group A, no SSCP mark. Endorsement in nine months is a hard administrative control. Budget USD $135 and 60 CPE / 3 years (45 Group A) as the cost of keeping the credential in production.
Which statement matches official SSCP experience rules for becoming certified (not Associate)?
How do SSCP members in good standing maintain the credential after endorsement?
A candidate passes SSCP, has the required experience, but does not know an ISC2-certified colleague. What is required before using the SSCP mark?