Security+ vs CISSP: not two rungs of one ladder
Security+ and CISSP get compared as beginner and advanced, and that framing causes real mistakes — people spending $749 too early, and people sitting on Security+ for years after it has stopped telling anyone anything new. They are different instruments. One gets you considered for a job; the other gets you considered for a decision.
The two exams, as published
CompTIA publishes Security+ V7, exam code SY0-701, as a maximum of 90 questions mixing multiple-choice and performance-based items, 90 minutes long, with a passing score of 750 on a scale of 100 to 900. It is available in English, Japanese, Portuguese, Spanish and Thai.
ISC2 publishes CISSP as three hours, 100 to 150 questions, computerised adaptive testing for all exams, with a pass mark of 700 out of 1000 points, in Chinese, English, German, Japanese and Spanish.
Performance-based questions are the interesting difference in kind: Security+ asks you to do small things, CISSP asks you to judge. Neither body publishes a pass rate, so anyone telling you one is harder by the numbers is inventing the numbers.
What Security+ weighs most heavily
Security+ V7 domain weightings, CompTIA
- 28%Security Operations
- 22%Threats, Vulnerabilities, and Mitigations
- 20%Security Program Management and Oversight
- 18%Security Architecture
- 12%General Security Concepts
- 100% in total — the weightings add up, which is how we check we copied them correctly.
CompTIA's V7 objectives put Security Operations at 28%, the single heaviest domain in either exam. Threats, Vulnerabilities, and Mitigations at 22% follows, then Security Program Management and Oversight at 20%, Security Architecture at 18% and General Security Concepts at 12%. The five add to 100.
Set that against CISSP's spread — 16% at the top, 10% at the bottom, across eight domains — and the character of each exam is obvious. Security+ concentrates: half the paper is operations and threats. CISSP levels: no subject dominates, and a weak domain cannot be hidden.
The gate, which is the real difference
CompTIA recommends that Security+ candidates hold Network+ and two years of experience working in a security/systems administrator job role, and requires neither. Nothing stops you sitting it in your first month in IT.
ISC2 requires a minimum of five years cumulative, full-time experience in two or more of the eight domains before it will certify you, with up to one year waived by a relevant degree or an approved credential. You may sit the exam without the experience, but you hold Associate of ISC2 status rather than CISSP, and you may not use the CISSP marks until endorsement is complete.
That is the whole decision for most people. If you do not have five years, CISSP is not a choice you are making this year.
What they cost to keep
Security+ lasts three years from the day it is earned. You renew either with 50 continuing-education units or with a single qualifying activity — CompTIA names its own CertMaster CE course, a higher-level CompTIA certification, or an approved non-CompTIA certification. If you renew by uploading CEUs, CompTIA charges $150 for the whole three-year period, and states that the fee is only due if you are renewing that way and must be paid by the certification's expiration date.
CISSP costs $749 to sit, then a $135 annual maintenance fee, plus 120 CPE credits per three-year cycle with at least 90 in Group A. CompTIA does not publish the Security+ voucher price anywhere we could read, so we cannot give you a clean total for the CompTIA side — which is itself worth knowing before you budget.
One more date to plan around
Security+ has a version cycle, and it is public. V7 launched on 7 November 2023 and retires on 11 June 2027 for English, and 13 August 2027 for Japanese, Portuguese, Spanish and Thai. CompTIA expects Security+ V8 on 17 November 2026.
That changes the calculus for anyone studying now. If you sit V7 before it retires you hold a current certification for three years from the date you earn it regardless of the version cycle — but if you are starting study in mid-2027, you will be learning objectives that are on their way out. There is no equivalent published retirement schedule for CISSP.
So which one
Sit Security+ if you are inside your first few years of IT, if job adverts you want mention it, or if you need a credential that proves you took the subject seriously before anyone will let you near it professionally. Sit CISSP when you have the five years and your work has moved from doing to deciding.
If you are between the two, the useful next question is which layer you are defending rather than which certificate is more impressive — the comparison by career stage lays that out. And if CISSP is the target but the experience clause is what is blocking you, the five-year rule in detail is the page to read next.
The performance-based questions are the thing to practise
CompTIA's format note deserves more attention than it usually gets: Security+ is a maximum of 90 questions mixing multiple-choice with performance-based items, in 90 minutes. Those performance-based questions are simulations — configure something, interpret output, place controls correctly — and candidates who have only drilled multiple choice find them slow.
Slow is the problem, because the clock does not care. Ninety items in ninety minutes averages a minute each, and a performance-based question can absorb five. The standard advice is the right advice here: move past them on the first pass, bank the multiple-choice marks, and come back with whatever time is left.
CISSP has no equivalent. Its advanced item types are still assessment rather than simulation, and its three hours for up to 150 questions is a gentler ratio than Security+ offers.
What each one signals to a hiring manager
Security+ signals that you took the subject seriously and can be trusted with the vocabulary. In a lot of organisations it also satisfies a procurement or compliance requirement, which is why it appears in adverts for roles that have nothing obviously to do with it.
CISSP signals something different and narrower: that an independent body has checked five years of your experience against eight domains and that somebody already certified vouched for you. That verification step — the endorsement — is the part most people forget is in there, and it is the reason the credential carries weight in senior hiring that a longer exam alone would not give it.
Choosing between them
Can I skip Security+ and go straight to CISSP?
Is Security+ still worth it in 2026?
How long is Security+ valid?
Does CISSP replace Security+?
Still deciding between credentials? Work through which cybersecurity certification fits the stage you are at, or read how every figure on this site is checked. Fees, formats and eligibility rules change without warning — open the certifying body’s page before you pay for anything.