CISSP holders must earn 120 CPE credits during each three-year certification cycle, with one hour of qualifying activity typically equal to one credit. ISC2 suggests spreading the workload across a mix of Group A (domain-related) and Group B (professional development) activities rather than front-loading or delaying the work. The first practical step is logging into the ISC2 CPE portal to review your current cycle dates and start recording activities as you complete them.
TL;DR:
- Up to 40 unused Group A credits earned in the last six months of the cycle can rollover, but only if documented and within the recommended limit.
- Combining certified training, conferences, self-study, and professional activities evenly throughout the cycle helps prevent last-minute workload and audit issues.
- Supporting evidence like certificates, transcripts, or receipts is essential for manual submissions, while ISC2 automatically reports certain training hours.
- Using a simple tracking system, such as a spreadsheet, can save time and reduce errors when managing CPE credits across the three-year cycle.
- Recognizing structured ISC2 courses that align with CISSP domains simplifies earning valid Group A credits and streamlines audit compliance.
Table of Contents
- CISSP CPE requirements, groups, and rollover rules explained
- Qualifying activities that count toward your CPE total
- Submitting, tracking, and keeping audit-ready records
- A pacing plan to hit 120 CPEs without last-minute scrambling
- How structured training supports a CISSP CPE plan
- A practical checklist and the mistakes to avoid
- Total Cyber Academy: training that builds your Group A credits
- Sources
- FAQ
CISSP CPE requirements, groups, and rollover rules explained
ISC2 requires CISSP holders to earn 120 CPE credits over a three-year cycle, and while there is no strict annual minimum enforced mid-cycle, ISC2 suggests pacing efforts against a suggested annual target rather than waiting until the deadline. Credits fall into two categories, and understanding the distinction shapes how you plan your learning.

Group A credits relate directly to one of the eight CISSP domains and require you to select the relevant domain when submitting, along with a written learning summary. Group B credits cover broader professional development, such as leadership or business skills, and carry looser documentation expectations. Rollover exists, but only for unused Group A credits earned in the final six months of a cycle, and only up to the recommended annual number, which for CISSP has been illustrated at up to 40 credits in ISC2’s own example.
A few numeric rules govern how credits are counted:
- Accepted increments are 0.25, 0.50, or 0.75 of an hour, so partial sessions still count.
- Per-activity caps apply to certain categories, which is why spreading activities across multiple formats works better than relying on one source.
- Rollover credits are Group A only and must have been earned in the last six months of the expiring cycle.
- Members must also pay the Annual Maintenance Fee each year, currently $135 for CISSP, and missing this payment can affect certification standing even if CPE totals are on track.
Qualifying activities that count toward your CPE total
ISC2 accepts a wide variety of learning formats, which gives working professionals flexibility to earn credits around existing schedules rather than treating CPEs as a separate obligation.
- Group A technical learning includes ISC2 training courses, vendor certification courses, security conferences, hands-on labs, and published technical articles that map to a specific CISSP domain.
- Group B professional development includes leadership or management training, mentoring and coaching others, teaching non-technical skills, and active membership in a recognized professional association.
- Self-study and knowledge sharing such as reading technical books, listening to security podcasts, or authoring content can qualify, but self-reported entries need a short learning summary explaining the domain relevance and proof that the activity took place.
- Free and low-cost sources including ISC2 chapter meetings, recorded ISC2 community webinars, and vendor-recorded sessions offer a straightforward way to accumulate hours without added expense, though it is worth confirming eligibility before assuming a session qualifies.
Pro Tip: Before attending any free webinar or community event, check whether the host publishes a CPE certificate or attendance record, since self-reported activities without documentation are the most common audit weak point.
Submitting, tracking, and keeping audit-ready records
Not every credit requires manual entry. ISC2 automatically reports credits for training you complete directly through ISC2, including official self-paced courses, so those hours typically appear in your portal without extra steps. Everything else needs self-submission at cpe.isc2.org.
A clean submission follows a consistent pattern:
- Select the correct group, and for Group A, choose the specific CISSP domain the activity supports.
- Attach a brief learning summary describing what you studied and how it relates to that domain.
- Upload or reference supporting evidence, since ISC2 accepts transcripts, certificates, attendance receipts, meeting minutes, and research notes as proof.
- Confirm the credit posts to your portal total rather than assuming submission alone finalizes it.
Retain your own copies of certificates, screenshots, and receipts rather than relying solely on the portal record, and keep them for the full cycle plus a reasonable buffer in case of audit. The most frequent mistakes are submitting Group A credits without a learning summary, misjudging which domain an activity supports, and waiting until the final months to reconcile a cycle’s worth of scattered activity.
A pacing plan to hit 120 CPEs without last-minute scrambling
Three approaches tend to work, each with different trade-offs. A steady pace of roughly 40 credits a year matches ISC2’s suggested annual rhythm and avoids year-three panic. A front-loaded approach knocks out large blocks of Group A credit early, useful if you know a busy stretch is coming later in the cycle. A rollover-focused strategy leans on the final six months of the prior cycle to bank up to the recommended annual number of unused Group A credits, though members who have tried this note it requires careful timing to avoid missing the rollover window entirely.
- Set a quarterly target, such as 10 credits, and treat it like any other recurring professional obligation.
- Log each activity the same week you complete it, attaching evidence immediately rather than reconstructing it later.
- Pair activities where possible: teaching a short session, then writing a summary of it, then taking a related course can generate both Group A and Group B credit from a single topic.
- Revisit free sources regularly, including ISC2 chapter events and recorded webinars, and verify eligibility before counting on the hours.
Pro Tip: Build a simple spreadsheet with columns for date, activity, group, domain, and evidence link. It takes ten minutes to set up and saves hours if ISC2 ever requests documentation.
How structured training supports a CISSP CPE plan
Instructor-led and on-demand courses aligned to ISC2 domains often qualify as Group A credit, and completing training through recognized ISC2 partners typically comes with the documentation an audit would ask for. Total Cyber Academy is one such provider, having formally partnered with ISC2 to deliver domain-aligned training.
- Courses built around specific CISSP domains give you the material for a learning summary without extra research.
- Structured programs typically issue completion certificates, which double as audit evidence.
- Reviewing course syllabi against the eight CISSP domains before enrolling helps confirm the training maps cleanly to Group A rather than a broader category.
A practical checklist and the mistakes to avoid
Start by logging into your CPE portal today, confirm your cycle dates, and begin recording activities as you complete them rather than in batches. The three mistakes that cause the most trouble are misclassifying an activity between Group A and Group B, submitting technical learning without the required learning summary, and delaying documentation until an audit notice or the final months of a cycle force a rushed reconstruction.
— Alden
Total Cyber Academy: training that builds your Group A credits
Training that maps directly to CISSP domains does double duty: it sharpens practical skills and generates documented Group A credit at the same time. Total Cyber Academy’s ISC2 CISSP on-demand course is built around the certification’s domain structure, and completion comes with a certificate you can attach directly to a CPE submission.

Beyond the CISSP course, the academy’s full course catalog covers vendor certifications across cybersecurity and IT operations, each structured around real domain content rather than generic filler. If you want a straightforward way to accumulate Group A hours while building a skill you will actually use, browse the catalog and find a course that fits your current cycle.
FAQ
How many CPE credits do I need for CISSP?
CISSP requires 120 CPE credits every three years, split between Group A domain-related learning and Group B professional development. ISC2 suggests pacing this against an annual target rather than waiting until the cycle ends.
How do I earn 120 CPE credits before my cycle ends?
Combine ISC2 training, vendor courses, conferences, and self-study, logging each activity through the CPE portal as you complete it. Spreading roughly 40 credits per year across a mix of Group A and Group B activities avoids a last-minute scramble.
Is CISSP still worth it in 2026?
The certification remains a widely recognized benchmark for senior security roles, and its value largely depends on the career path a professional is pursuing. It requires ongoing investment through the CPE and AMF requirements, which reflects its emphasis on continuous, current skill maintenance rather than a one-time exam.
Is there a way to earn free CPE credits through ISC2?
Yes, ISC2 chapter meetings and recorded community webinars are recurring no-cost sources of CPE opportunities. It is worth confirming that a specific event or recording carries CPE eligibility before counting on the hours.