Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2

Information Systems Security Architecture Professional

The ISSAP certification validates your expertise in developing, designing, and analyzing security solutions across an organization. Ideal for chief security architects and analysts, it proves you can provide risk-based guidance to senior management and align security architecture with organizational goals. Earning the ISSAP demonstrates elite-level knowledge and opens doors to new career opportunities.

Exam formatMultiple choice and advanced item types
Duration180 minutes
DeliveryPearson VUE
Passing score700 out of 1000
Free questions343

Content last reviewed 30 July 2026 · Up to date

The certification

What Information Systems Security Architecture Professional proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

4domains
11objectives
91concepts
US $199exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The Information Systems Security Architecture Professional (ISSAP) certification is ISC2's advanced credential for security architects. It validates your ability to develop, design, and analyze security solutions that align with organizational vision, mission, and strategy. As a security architect, you play a key role between the C-suite and the implementation of your security program, providing risk-based guidance to senior management.

The ISSAP covers four domains: Governance, Risk, and Compliance (GRC), Security Architecture Modeling, Infrastructure and System Security, and Identity and Access Management (IAM) Architecture. The credential is accredited to ISO/IEC 17024 and approved by the U.S. Department of Defense (DoD 8140), demonstrating its rigor and global recognition. Earning the ISSAP proves you have elite-level knowledge and expertise, opening doors to new career paths and opportunities.

Who it’s for

The ISSAP is ideal for chief security architects, security analysts, and professionals with similar responsibilities who design and analyze security solutions. It is also suited for system architects, chief technology officers, system and network designers, business analysts, and chief security officers who need to provide risk-based guidance to senior management. You are a great fit for the ISSAP if you are a lifelong learner who craves new challenges, want to stand out from peers, and are looking ahead in your career. The certification is designed for experienced professionals who want to be recognized as subject matter experts in security architecture.

Recommended experience

Candidates should have a strong background in information security, with experience in security architecture, risk management, and designing security solutions. While not mandatory, ISC2 recommends relevant training and study resources to prepare for the exam. Experience in developing, designing, and analyzing security solutions; Knowledge of governance, risk, and compliance (GRC) principles; Familiarity with security architecture frameworks and modeling; Understanding of infrastructure and system security, including cloud and network security; Experience with identity and access management (IAM) architecture

The syllabus

What you’ll learn

Every domain and objective ISC2 measures, with the weight they carry on the exam.

The official ISC2 exam outline · checked 30 July 2026 · See the source

Governance, Risk, and Compliance (GRC)
  • 1.1 Identify legal, regulatory, organizational, and industry requirements
  • 1.2 Architecting for governance, risk, and compliance (GRC)
2 objectives · 77 free questions · 16 pages
Security Architecture Modeling
  • 2.1 Identify security architecture approach
  • 2.2 Verify and validate design (e.g., functional acceptance testing, regression)
2 objectives · 56 free questions · 12 pages
Infrastructure and System Security Architecture
  • 3.1 Identify infrastructure and system security requirements
  • 3.2 Architect infrastructure and system security
  • 3.3 Architect infrastructure and system cryptographic solutions
3 objectives · 92 free questions · 20 pages
Identity and Access Management (IAM) Architecture
  • 4.1 Architect identity lifecycle
  • 4.2 Architect identity authentication
  • 4.3 Architect identity authorization
  • 4.4 Architect identity accounting
4 objectives · 118 free questions · 25 pages
On the day

The exam itself

Everything ISC2 publishes about sitting it, and nothing we inferred.

Prerequisites

Must hold the CISSP certification in good standing

CertificationInformation Systems Security Architecture Professional
Exam formatMultiple choice and advanced item types
Duration180 minutes
Questions125 questions
Passing score700 out of 1000
DeliveryPearson VUE
LanguagesEnglish
PricingUS $199
Certification levelProfessional
After you pass

Where this credential goes next

The path ISC2 lays out, how the credential is kept, and where to book.

Step-by-step path to Information Systems Security Architecture Professional

PrerequisiteMust hold the CISSP certification in good standing
Information Systems Security Architecture Professional badgeCredential earnedInformation Systems Security Architecture Professional Professional level certification
Renewal and maintenance

ISC2 certifications are time-limited and must be renewed on a regular three-year cycle. Certification holders maintain their credentials by earning continuing professional education (CPE) credits and complying with ISC2 policies and ethical standards. ISC2 members are also responsible for an annual maintenance fee (AMF). Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. ISC2 maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by ISC2

Exam registration

Register for the exam through Pearson VUE, ISC2’s authorized testing partner.

Schedule your exam

Visit the official ISC2 certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the ISSAP relate to the CISSP certification?

The ISSAP is an advanced concentration certification that requires the CISSP as a prerequisite. It focuses specifically on security architecture, while the CISSP covers a broad range of security topics. Earning the ISSAP demonstrates specialized expertise in designing and analyzing security solutions.

Do I need to earn the CISSP before taking the ISSAP exam?

Yes, you must be a CISSP in good standing to take the ISSAP exam. Alternatively, you can qualify with seven years of cumulative, full-time experience in two or more of the ISSAP domains, but the CISSP is the standard prerequisite path.

Is the ISSAP exam available online or only at testing centers?

The ISSAP exam is administered at Pearson VUE testing centers. ISC2 does not currently offer online proctoring for this exam.

What is the retake policy for the ISSAP exam?

If you fail the ISSAP exam, you must wait 30 days before retaking it. There is no limit on the number of attempts, but each attempt requires a new exam registration and fee.

Are there any hands-on or lab components in the ISSAP exam?

No, the ISSAP exam consists of multiple-choice and advanced item types only. There are no hands-on or lab-based components.

What job roles does the ISSAP credential map to?

The ISSAP is ideal for chief security architects, security analysts, system architects, chief technology officers, system and network designers, business analysts, and chief security officers who design and analyze security solutions.

Can I recertify the ISSAP by passing a different ISC2 exam?

No, the ISSAP must be renewed by earning CPE credits and paying the annual maintenance fee. Passing another ISC2 exam does not automatically renew the ISSAP.

Is the ISSAP exam available in languages other than English?

Currently, the ISSAP exam is only available in English. ISC2 may offer additional language options in the future, but none are announced at this time.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 343 questions, free, no account needed.