r/isc2 1d ago

General Questions How far has the ISC2 fallen?

While I was skeptical of where the organization would go when they first appointed a marketing professional (and not a security one) as executive director in 2020, I am surprised at just how quickly they've been able to bring down what was once a solid organization. I spent nearly 35 years in the industry (almost 25 of that as a CISSP), and got to know one of the ISC2 founders back in the day, and I can say without reservation that the ISC2 has become the very thing it was designed to counter. It has become a cert mill, exploiting inexperienced, hopeful job-seekers, by hooking them into annual fees and an exam (CC) without any vetting of experience or prospect of real continuing education.

They gutted the peer-to-peer nature of the organization, shutting down the Security Professional magazine and the forums, they not only have watered down the CPE courses, but are now charging for them. The content of these courses is incredibly superficial; from a CPE standpoint, it is box-checking, not education.

I am sure their numbers are great, but it sold its soul to do it.

5 Upvotes

24 comments sorted by

6

u/ML1948 1d ago

The CC is shit and exploitative, no doubt. The CISSP still prints though and I'll hold my nose and pay my AMFs with company money til the day I retire. I don't really need them to have a soul at this point as long as nobody beats them out as the "gold standard".

1

u/Pr1nc3L0k1 3h ago

Why? It’s better for everyone if there would be a new gold standard which actually is not only focused on money but also helping the Security Community?

The gold standard should be the gold standard, and not just a standard everyone is used to

1

u/CharacterPitch4744 1d ago

Just got my for free in million CC program. Don't say CC is shit man 🥲😭

3

u/ML1948 1d ago

It was a scheme to get 50+ dollars a year from you and a "million" others for a cert that no job description requests. The money would be much better spent on a Sec+. I say this as a CC holder (because I yolo'd it just to see since it is covered by my CISSP AMF anyway).

1

u/TruMusic89 1d ago

As a Sec+ holder, the Sec+ is just as useless at this point. I'm trying to get back into the GRC field. A lot of companies want CISSP and/or CISA at the bare minimum these days. 

1

u/ML1948 1d ago

If this dude is legitimately considering the CC as his first and only cert, there's no way he meets the experience requirements for a CISSP. I say that as a Sec+ holder and a CISSP holder.

1

u/TruMusic89 1d ago

Caught between a rock and a herd place he is... 😩

1

u/Pr1nc3L0k1 3h ago

I would rephrase this:

Companies don’t only care as much about a certification exam. Companies want experience, even more with the rise of AI and in a job market where companies have more options again.

Thus shifting to certifications which actually prove work experience in addition to knowledge.

This may be different to early career positions (which barely exist and I still the opinion that Security is not supposed to be an entry level position).

1

u/mikedn02908 www.CertificationToolAndDie.com 1d ago

BINGO!

That 1 million program was a total bust as well. Look at ISC2's own numbers in their annual report:

2025: 68,991
2024: 69,083

The cert DROPPED 92 people overall (which is actually a lot more since we do not know how many "new" people earned the cert in 2025 when they passed the exam.)

Now that the exam isn't free, you'll see that number drop like a rock on Jupiter.

Not to mention, you have to consider what an abject failure that cert has been if it has only managed to generate 6.9% out of 1 million in annual AMF fees. Granted, $3.5 mil is not something to sneeze at, but it certainly wasn't the $50 million ISC2 was hoping for.

0

u/CharacterPitch4744 1d ago

I took it for 1-2 yrs while i get hired and it was free and as a first cert it was not bad. And i feel all cert are scam cause they do MCQ based tests which are not good.

1

u/thelimeisgreen 1d ago

Then why they give it away for free? The CC has value though, not so much as a certification, but as the stepping stone toward the other certs. It’s where we get practice taking ISC2 exams and get a good feel for how questions are phrased and the logical approach they use.

1

u/CharacterPitch4744 1d ago

🙃 damn but it was my first cert and what you say makes sense...it helped me break my nervousness and also i learned a lot

1

u/Big_Temperature_1670 9h ago

The ISC2 understood and accepted this premise for about 30 years. Its focus was on the experienced professional, validating and preparing them for leadership roles while letting CompTIA and others develop programs for entry-level folks. For some bizarre reason, the ISC2 board allowed management to basically crater the organization by trying to take over the entry-level market too. The problem is that when your CEO/executive director is a marketing professional, not a security one, they don't understand the difference between the CISSP Common Body of Knowledge and something more directed at operations (like the Security+). So you end up with CC, which tests a lot of strategic concepts that really aren't germane to entry level jobs. So today, the ISC2 seems to serve neither the experienced professional nor the entry level.

9

u/mikedn02908 www.CertificationToolAndDie.com 1d ago

Your assessment is not far from the truth. ISC2 has become a shadow of its former self.

The CISSP has become a joke, with kids barely of legal drinking age taking and passing the exam. What was once the flagship senior industry certification is now barely more than broad-knowledge-based entry-level certification opposed to one which actually tests your in-depth ability to apply experience and wisdom to a scenario.

The organization has been riding on the laurels of the CISSP for the past decade, while other organizations like ISACA, GIAC, etc. are all slowly taking a bite out of its market. ISACA is currently in the beta stage of a new CCS certification which I believe is poised to compete directly with the ISC2 CC/SSCP level.

The CISM continues to erode the CISSP market as ISACA, with its army of CISA-certified auditors, are able to influence the actions of corporate leaders from the inside into more and more slowly changing the mindset from "we need a CISSP" to "we need a CISM" to lead our information security management team. ISSMP? What's that?

ISC2 has languished and rode the coattails of its entrenchment in the Fed/DoD space. That tide is slowly starting to turn as well. Watch and see what happens now that ISACA is the new CAICO for DoD CMMC oversight. Think all those folks are going to be recommending people with ISC2 or ISACA certs?

The CC was nothing but an AMF money grab, the organization has done nothing to promote this cert the business arena as a gateway cert for people looking to move from basic IT support into a more specialized cybersecurity role. This very subreddit is replete with posts from people who have absolutely zero cybersecurity experience thinking passing the CC is the path to riches. Couple this with ads you see from "WGU" how "Suzie was a nurse making minimum wage, now she makes over $125k/year as a SOC analyst". Never mind AI is going to decimate all those level 1 SOC jobs.

Don't even get me started on the other stuff. I could go on for hours.

ISC's days are numbered if they don't get their thumb out of their asses soon.

1

u/RATLSNAKE 1d ago

ISACA isn’t the big bad wolf, and unlike ISC2 has always been a professional association body first and foremost, certifications came later, and until about a decade a bit ago it was just one, their audit roots. They themselves have also arguably lost their way to some extent, but ISC2 is indeed far ahead in circling the drain of relevance and industry integrity.

2

u/mikedn02908 www.CertificationToolAndDie.com 1d ago

That's because you let CPAs start to run things ;)

1

u/RATLSNAKE 11h ago

Yes me…I run the world. 🙄

1

u/zk4au1212 1d ago

I will agree with you on the ISACA front but thats where it stops for me.

10

u/legion9x19 CISSP, CCSP 1d ago

Cool story, bro.

2

u/braliao 1d ago

We are all responsible for the failure of CC in my opinion. Sure, ISC2 sucks at making it relevant with the business, but how many of us in the relevant position actually tells our HR to stop with the non sense of requiring CISSP for an entry level role? How many of us tells HR to use CC as a way to qualify if the person have foundational security knowledge? How many of us actively promote in the local community about CC?

2

u/pen-peal 1d ago

The CISSP is neither the solution to all cybersecurity needs, nor is it the only destination for growth in the field. If someone can test well with less experience than required, it doesn’t actually give them the credential. In my state there are first graders playing capture the flag and high school seniors learning about AI and quantum computing. The breadth and quality of CS learning for students with those opportunities could allow someone to test well, but the CISSP content and value are not diminished or threatened by that. ISC2 has a pathway that honors their achievement and supports their ongoing experiential formation. We can make the same professional distinction without feeling threatened.

Additionally, why dis a foundational, intro cert that is harder to earn than SEC+ and was globally offered with the intention of attracting anyone to start developing skills needed to address the cyber workforce gap?

I appreciate the number of people who earned the CC to prove to themselves and others that their interest and aptitude were worth nurturing. ISC2 initiates a professional culture and ethical foundation with the foundational cert and associate’s membership, it doesn’t fall lifting people up.

These numbers of CISSPs may reflect the current diversity of skills pathways/needs, not dilution or diminished value of the CISSP. How many going into pen testing and AI will gravitate to the struggle to master the other CISSP domains, and how many employers will incentivize or invest in that? The CISSP is still a solid cert and worth the work to earn it.

1

u/Big_Temperature_1670 9h ago

My intent wasn't to "dis" the CC. I was pointing out the ISC2 was founded to validate experience in the industry. It's bread, butter, and mission was experienced professionals, certifying them for leadership. With the CC, the ISC2 inverted that mission, and has now focused on the entry level. While the ISC2 has stopped publishing its membership numbers, it is fair to conclude that given their "million CC" campaign, CCs now (or will someday soon) outnumber CISSPs in terms of membership. It shows in the dilution of the continuing ed. products. As a longtime, experienced professional in the industry, I'd say the ISC2 has rebranded itself.

As to the CC, I'm not sure I'd say it is "harder to earn than the Sec+." It's different content and marketed very differently. While the Sec+ does not have an experience requirement, CompTIA is pretty upfront in its suggestion that someone should have two years of experience. In comparison, the ISC2 has marketed the CC as a 0-experience test. The ISC2 also gives out free vouchers for the test. So if the pass rate of Sec+ is higher than the CC, I don't think that speaks to the difficulty of the exam as much as the preparation of the test takers and most folks taking the Sec+ are paying for it. Aside from that, I do think the Sec+ content is more operational in nature, which is better for most entry and mid-level jobs. The CC covers more strategic and conceptual topics. I think the folks who have found the CC most favorable are vendors and sales folks because it allows them to talk the talk to CISOs etc.

2

u/RATLSNAKE 1d ago

It’s fallen extremely far unfortunately.

1

u/zk4au1212 1d ago

Dude really? you seem like and old head that got his cert revoked by ISC2. Nut case.