In the mid-1980s, a need for a standardized, vendor-neutral certification program for information security professionals was identified. In November 1988, the Data Processing Management Association's Special Interest Group for Computer Security (SIG-CS) brought together several organizations to form a consortium to address this need. This led to the formation of ISC2 in mid-1989 as a non-profit organization.
The first working committee to establish a Common Body of Knowledge (CBK) was formed in 1990, and the first version of the CBK was finalized in 1992. This work laid the foundation for the organization's first certification, the Certified Information Systems Security Professional (CISSP), which was launched in 1994.2
The organization continued to expand its certification offerings over the years:
ISC2 also expanded its global presence, opening a regional office for Europe, the Middle East, and Africa (EMEA) in London in 2001, and an Asia-Pacific office in Hong Kong in 2002.6 The first ISC2 Security Congress conference was held in 2011, the same year its charitable arm, the ISC2 Foundation (now the Center for Cyber Safety and Education), was launched.
In 2022, ISC2 announced a major initiative to address the cybersecurity workforce gap, including the “One Million Certified in Cybersecurity” program, which provides free entry-level Certified in Cybersecurity (CC) certification education and exams.7 In 2023, the organization underwent a rebrand, changing its preferred abbreviation from ISC2 to ISC2.8
ISC2 offers a range of certifications aimed at different levels of experience and specializations within the information security field.
ISC2 is governed by a Board of Directors, which is composed of 13 members elected by the ISC2 membership. The Board provides strategic direction and oversight for the organization. Elections are held annually to fill open seats, and members vote to select from a slate of qualified candidates. The Board is led by a Chairperson, who is elected by the directors to preside over meetings and guide the Board's activities. The day-to-day operations of the organization are managed by a Chief Executive Officer (CEO), who is appointed by and reports to the Board of Directors.18
The organization's structure and procedures are defined in its official Bylaws. All ISC2 members, associates, and candidates must adhere to the ISC2 Code of Ethics. The code mandates that individuals act honorably, honestly, justly, responsibly, and legally. It serves as a framework for professional conduct, and violations can lead to an investigation and potential sanctions, including the revocation of certifications.
ISC2 is involved in advocacy efforts and regularly publishes research on the state of the cybersecurity workforce. Key publications include:
The organization actively engages with governments and policymakers to shape cybersecurity-related laws, regulations, and frameworks globally, with specific advocacy efforts in the United States, United Kingdom, Canada, and the European Union. It partners with government agencies, such as the U.S. Department of Defense, to align its certifications with governmental workforce requirements like the DoD 8140 Directive.21
Through its Global Academic Program, ISC2 partners with universities and colleges to integrate professional certifications into academic curricula, providing institutions with research support and curriculum development resources to prepare students for cybersecurity careers.22 Its charitable arm, the Center for Cyber Safety and Education, focuses on public outreach and educational programs to improve cyber safety for the general public.
"Why is the CISSP Considered the Gold Standard in Cybersecurity?". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/Insights/2024/11/why-cissp-is-the-gold-standard ↩
"Celebrating 30 Years of CISSP". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/Insights/2024/02/Celebrating-30-Years-of-CISSP ↩
"CAP is Now Certified in Governance, Risk and Compliance (CGRC)". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/Insights/2023/02/CAP-is-Now-Certified-in-Governance-Risk-and-Compliance ↩
"What is CSSLP (Certified Secure Software Lifecycle Professional)? | Definition from TechTarget". Search Security. Retrieved June 12, 2025. https://www.techtarget.com/searchsecurity/definition/CSSLP-certified-secure-software-lifecycle-professional ↩
"What is Certified Cloud Security Professional (CCSP)? | Definition from TechTarget". Search Security. Retrieved June 12, 2025. https://www.techtarget.com/searchsecurity/definition/Certified-Cloud-Security-Professional-CCSP ↩
"Contact Us | ISC2". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/contact-us ↩
"ISC2 Continues Investment in One Million Certified in Cybersecurity Pledge with New AI-Based Training". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/Insights/2024/03/ISC2-Continues-Investment-in-One-Million-Certified-in-Cybersecurity-Pledge ↩
"Cybersecurity Is Evolving. So Are We". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/Insights/2023/08/cybersecurity-is-evolving-so-are-we ↩
"CC Certified in Cybersecurity Certification | ISC2". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/certifications/cc ↩
"CISSP Certified Information Systems Security Professional | ISC2". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/certifications/cissp ↩
"ISSAP Information Systems Security Architecture | ISC2". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/certifications/issap ↩
"ISSEP Systems Security Engineering Certification | ISC2". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/certifications/issep ↩
"ISSMP Information Systems Security Management | ISC2". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/certifications/issmp ↩
"SSCP Systems Security Certified Practitioner Certification | ISC2". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/certifications/sscp ↩
"CCSP Certified Cloud Security Professional | ISC2". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/certifications/ccsp ↩
"CGRC Governance, Risk & Compliance Certification | ISC2". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/certifications/cgrc ↩
"CSSLP Certified Secure Software Lifecycle Professional | ISC2". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/certifications/csslp ↩
"ISC2 Govarnance and Bylaws". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/about/governance ↩
"Cybersecurity Workforce Study". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/research ↩
"ISC2 Events". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/professional-development/events ↩
"Certifications Key to Unlocking DoD8140 Compliance". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/Insights/2025/01/certifications-key-to-unlocking-dod-8140-compliance ↩
"Global Academic Program". www.isc2.org. Retrieved June 12, 2025. https://www.isc2.org/landing/global-academic-program ↩