CISSP vs CASP: which senior security certification fits you?
CISSP vs CASP: take CASP (CompTIA Advanced Security Practitioner, now called SecurityX) if you are a senior security engineer or architect who wants a credential you hold as soon as you pass. Take the CISSP (Certified Information Systems Security Professional, from ISC2) once your work meets its five-year experience rule.
Both are senior certifications. If you have no security job yet, neither is your first exam: start with the quick answer. Jump to job ads, cost or which first.
| CISSP | CASP+ / SecurityX | |
|---|---|---|
| Issuer | ISC2 | CompTIA |
| Written for | Security work across 8 domains (topic areas), from risk management to software security | Senior security engineers (who build protections such as access rules) and security architects (who design how they fit together), CompTIA says |
| Experience | Required to hold it: 5 years of security work in 2 or more domains, or 4 with a waiver (a degree or approved credential that replaces 1 year) | Recommended only: 10 years of IT work, 5 of them in security |
| Exam | Adaptive (each question picked by your earlier answers), 100 to 150 items, 3 hours | Up to 90 questions, up to 165 minutes, pass or fail |
| Exam fee (US) | $749 | $544 voucher (prepaid exam code), US list price on the SecurityX page |
| To keep it | 120 CPE (continuing education) credits per 3 years, $135 a year | 75 CEUs (continuing education units) per 3 years, $150 per 3 years |
CompTIA CASP+ vs CISSP at a glance. Source: ISC2 and CompTIA pages listed under Sources.
Show the numbers
| Country | CISSP | CompTIA SecurityX (CASP+) |
|---|---|---|
| India | 18% | 2 of 250 |
| United Kingdom | 12% | 1 of 235 |
| United States | 4.2% | 48 of 8,110 |
| Brazil | 4 of 434 | 0 of 434 |
CISSP or CompTIA SecurityX (CASP+): which do employers name more?
Instant answer from October 2026 job ads. No email needed.
CISSP is named in more job ads in the United States.
Source: Adzuna job ads, October 2026.
Get your full report
Two optional questions shape your first step. No email needed.
On this page
- Quick answer by situation
- Are CASP+ and SecurityX the same certification?
- CompTIA CASP+ vs CISSP: which do job ads name?
- What experience does each one require?
- How do the two exams differ?
- What do the CISSP and SecurityX cost over three years?
- How do you renew each one?
- Which exam is harder, CISSP or CASP+?
- Which should you take first?
- What we did not check
- Sources
Quick answer by situation
- No IT job and no target job yet: read our cybersecurity roadmap this week and pick one entry-level title from it. Then search a job site for that title, open ten ads and write down every certification they name. For a first exam, look at CompTIA Security+, CompTIA's entry-level security exam; our CISSP vs Security+ comparison explains the order.
- Help desk or system administration, under four years in security: neither is the usual next step. Take Security+ first; CompTIA lists it among the knowledge it recommends before SecurityX.
- Security engineer or architect with about ten years in IT, five in security: SecurityX is the exam CompTIA designed for your tasks, and you hold it once you pass.
- Five years of security work in two or more CISSP domains: take the CISSP. With a relevant degree or an approved credential, four years can be enough.
- Planning both: SecurityX first can shorten the CISSP's experience rule by a year. Details are under experience.
- Moving into security management: compare the CISM, the credential from ISACA, in our CISM vs CISSP comparison.
Are CASP+ and SecurityX the same certification?
Yes: CompTIA renamed CASP+ to SecurityX, so this page compares the CISSP with one renamed CompTIA certification. CompTIA released the new exam, CAS-005 (its exam code), on December 17, 2024, and its blog announced the next day that CASP+ "is now the new CompTIA SecurityX."
The blog adds that the change "will not affect the certification status of current CASP+ certification holders or the continuing education program." An archived copy of CompTIA's former CASP+ page says unexpired CASP+ vouchers work for the SecurityX exam.
CompTIA estimates that CAS-005 will retire in 2027, about three years after launch. Check the current exam objectives before you buy study material.
CompTIA CASP+ vs CISSP: which do job ads name?
We counted both certifications in the same security-analyst ads on Adzuna, a job-ad search site, in October 2026. An ad counted for the CISSP when it contained the word cissp, and for CASP when it contained casp, which also matches CASP+. Ads that use only the name SecurityX are missed, so the casp column undercounts. An ad can name both.
| Country | Ads containing cissp | Ads containing casp |
|---|---|---|
| United States | 338 of the 8,110 | 48 of the 8,110 |
| United Kingdom | 29 of the 235 | one of the 235 |
| India | 45 of the 250 | 2 of the 250 |
| Brazil | 4 of the 434 | none of the 434 |
Source: Adzuna API, security-analyst ads collected in October 2026; each cell gives the ads naming the word out of all security-analyst ads we counted in that country. Analysis: CertWorthIt. Method.
In the US, the word cissp appeared in 4.2% of the ads for security analysts in October 2026, and casp in 48 of the 8,110 ads (Adzuna).
Our reading: we counted both in analyst ads, but SecurityX was written for engineers and architects, whose ads are not in this sample. Our cybersecurity-analyst page lists what analyst ads name by country.
Show the numbers
| Item | Ads | Share of ads |
|---|---|---|
| SIEM | 415 | 5.1% |
| CISSP | 338 | 4.2% |
| CompTIA | 162 | 2.0% |
| CISM | 134 | 1.7% |
| CompTIA CySA+ | 119 | 1.5% |
| CompTIA Security+ | 112 | 1.4% |
| Splunk | 100 | 1.2% |
| CEH | 81 | 81 of 8,110 |
| CompTIA SecurityX (CASP+) | 48 | 48 of 8,110 |
What experience does each one require?
The CISSP requires five years of security work before you can hold it; SecurityX only recommends ten years of IT work and is yours once you pass. You can take either exam without the experience.
CISSP: a rule you must meet
ISC2 asks for "a minimum of five years cumulative, full-time experience in two or more of the eight domains" of its exam outline. A computer science or IT degree can cover one year, or one credential from ISC2's approved list can. "Only one waiver is permitted," ISC2 adds.
After passing, you complete endorsement, ISC2's review of your application and work history, within nine months of the exam date. Pass without the experience and you become an Associate of ISC2, a status for people who passed but are not yet certified. You keep it by paying $50 a year and earning 15 CPE credits a year, and you have six years to earn the five years.
SecurityX: a recommendation only
CompTIA recommends knowledge from its lower-level exams on networking, security, security analysis, cloud and penetration testing (attacking systems with permission to find weak spots). Its SecurityX page also lists "Recommended experience: minimum of 10 years of general hands-on IT experience, including 5 years of hands-on security." The page states no required prerequisite, so passing the exam is enough to hold it.
Does CASP+ shorten the CISSP experience rule?
Yes, by one year. ISC2's approved list names both "CompTIA Advanced Security Practitioner (CASP+)" and "CompTIA SecurityX," so either counts as the single waiver. The catch is the one-waiver rule: if your degree already covers that year, holding SecurityX takes nothing more off the five.
How do the two exams differ?
The CISSP is a three-hour adaptive exam scored out of 1,000; SecurityX has up to 90 questions, including hands-on tasks, and a pass-or-fail result.
| CISSP (ISC2) | SecurityX, CAS-005 (CompTIA) | |
|---|---|---|
| Questions | 100 to 150 items, multiple choice and "advanced item types" (ISC2's term for other formats) | Up to 90, multiple choice and performance-based (hands-on tasks) |
| Time | 3 hours | Up to 165 minutes |
| How questions are picked | Computerized adaptive testing | Not described as adaptive |
| Result | 700 out of 1,000 to pass | Pass or fail only, no scaled score |
| Languages | Chinese, English, German, Japanese, Spanish | English; others to be decided |
| Retakes | Waits of 30, 60, then 90 days; at most 4 attempts in 12 months | No wait before a 2nd attempt; 14 days before each later one |
Source: ISC2 CISSP exam outline and after-your-exam page; CompTIA SecurityX page and retake policy.
Adaptive means the computer chooses each next question based on how you answered so far, so the exam can end anywhere between 100 and 150 items. Performance-based questions ask you to carry out a task in a simulated system instead of choosing an answer. A scaled score is a raw result converted to a fixed scale; SecurityX gives none.
The topic weights show the difference in focus. CompTIA weights SecurityX at 31% security engineering, 27% security architecture, 22% security operations and 20% governance, risk, and compliance (the rules, risk decisions and legal duties a company must meet). ISC2 spreads the CISSP over eight domains of 10% to 16% each, with Security and Risk Management the largest and Security Architecture and Engineering one domain among eight.
Show the numbers
| Item | CISSP | CompTIA SecurityX (CASP+) |
|---|---|---|
| Questions | 100–150 questions | 90 questions |
| Exam time | 180 minutes (3 h) | 165 minutes (2 h 45 min) |
| Passing score | 700 of 1,000 | pass/fail only |
| Format | Multiple choice, adaptive testing | Multiple choice, performance-based tasks |
| Languages | 5 languages | English |
What do the CISSP and SecurityX cost over three years?
With one exam attempt, the CISSP costs $1,154 over three years at ISC2's Americas price and SecurityX costs $694 at the US voucher price on CompTIA's SecurityX page. Neither total includes study material, courses or practice tests.
| Item | CISSP, Americas | SecurityX, US |
|---|---|---|
| Exam | $749 x 1 attempt | $544 voucher x 1 attempt |
| Upkeep | $135 yearly fee x 3 years | $150 CE fee x 1 three-year cycle |
| Three-year total | $1,154 | $694 |
Source: ISC2 exam pricing and annual-fee pages; CompTIA SecurityX page (voucher price) and CE fee page. Sums: CertWorthIt.
The upkeep fees work differently. ISC2 charges its annual maintenance fee (AMF) every year and bills the first one after your endorsement is approved, so the CISSP total assumes three full years of fees. CompTIA charges its continuing education (CE) fee once per three-year cycle, due when you renew at the end of the three years.
CompTIA's retake policy charges the full exam price for every attempt. Fail once and buy a second voucher, and SecurityX comes to $1,238 (2 x $544 + $150). Other regions have their own CISSP prices on ISC2's pricing page.
Show the numbers
| Item | Fee |
|---|---|
| CISSP: Fees to get certified: Exam | $749 |
| CISSP: Fees to get certified: Annual fee, $135 a year × 3 years | $405 |
| CompTIA SecurityX (CASP+): Fees to get certified: Exam | $544 |
| CompTIA SecurityX (CASP+): Fees to get certified: Renewal, every 3 years | $150 |
How do you renew each one?
Both run on three-year cycles, with separate credits and fees at each vendor.
- CISSP: 120 CPE (continuing professional education) credits per three-year cycle, logged with ISC2 for courses, conferences and similar learning. The $135 fee is due every year.
- SecurityX: 75 CEUs (continuing education units, credits for approved learning and work activities) within the three-year cycle, plus the $150 CE fee for the cycle.
CompTIA says that when you renew a higher-level certification, your lower-level CompTIA certifications renew without extra fees. The CE fee page also warns that fees are not waived if the higher certification does not fully renew a lower one.
Which exam is harder, CISSP or CASP+?
The exams test different skills: the CISSP spreads its weight over eight domains of 10% to 16% each, while SecurityX puts 58% on engineering and architecture (ISC2 and CompTIA weights).
On the CISSP, the adaptive format means you do not know whether the exam will end at question 100 or 150. Candidates who fail get proficiency levels by domain but no score.
On SecurityX, performance-based questions test whether you can do the work in a simulated system, and the pass-or-fail result gives no score to show how close you came.
Which should you take first?
Take the one that matches your work now. SecurityX fits engineers and architects who want a credential on passing; the CISSP fits once your security work meets ISC2's rule. If you have neither job yet, the quick answer gives a first step.
Is it worth taking SecurityX before the CISSP?
It can be, if no degree covers a CISSP year and you plan both. SecurityX then counts as your waiver, so four years of qualifying work can be enough, at the cost of a second exam ($694 over three years in our cost table). The Associate route works the other way around: pass the CISSP first and earn the years afterwards.
Do both count for US defense jobs?
ISC2's CISSP page says the CISSP is approved under DoDM 8140.03, the US Defense Department manual that sets the qualifications for its cyber staff. CompTIA's SecurityX page lists DoD 8140 work roles for SecurityX, such as security architect and security control assessor (someone who checks that protections work). The manual sets qualifications per work role, so check which credentials the role you would be hired into accepts.
Is there a hands-on alternative?
For offensive testing, look at the OSCP, a hands-on penetration-testing exam, in our CISSP vs OSCP comparison, or the CEH (Certified Ethical Hacker). For IT audit (checking a company's controls), see ISACA's CISA in CISA vs CISSP; for networking, Cisco's CCNA in CCNA vs CISSP.
What we did not check
- Salary. We found no dated official source that compares pay for CISSP and SecurityX holders.
- Pass rates. Neither ISC2 nor CompTIA publishes one on the pages we read.
- Engineer and architect ads. Our counts cover security-analyst ads in four countries only.
- CISSP retake price and online testing. ISC2's outline lists test centers only, and we did not confirm a retake fee.
- Visible SecurityX price. The $544 sits in the SecurityX page's embedded data, not its visible text; check the store before you buy.
- Which CompTIA certifications SecurityX renews. The CE fee page does not list them.
Sources
All pages below were read October 8, 2026. An archived copy is a saved copy of a page from the date given.
- ISC2: CISSP page, experience requirements, exam outline, exam pricing, AMF overview, member policies, Associate of ISC2, endorsement, after your exam.
- CompTIA: SecurityX page (exam details, domains, voucher prices), blog: Introducing CompTIA SecurityX, retake policy, earn CEUs, CE renewal fees, former CASP+ page (archived copy from 2024).
- Job ads: Adzuna API, October 2026, security-analyst ads in the US, UK, India and Brazil. Analysis: CertWorthIt. Method.
Questions people ask
Is CASP+ the same certification as CompTIA SecurityX?
Yes. CompTIA renamed the CASP+ (CompTIA Advanced Security Practitioner) to CompTIA SecurityX in December 2024, when it released the new exam version, CAS-005 (the exam code). CompTIA says the name change does not affect the status of people who already hold CASP+ or their continuing education, the credits they earn to renew it. CASP is the short form of the old name, so CASP, CASP+ and SecurityX are one certification.
CompTIA CASP+ vs CISSP: which exam is harder?
The exams test in different ways. The CISSP (Certified Information Systems Security Professional, from ISC2) is adaptive, meaning each question is chosen based on your earlier answers, with 100 to 150 items in three hours across eight topic areas called domains. CompTIA SecurityX, formerly CASP+, has up to 90 questions in up to 165 minutes, including performance-based questions, tasks you carry out in a simulated system, across four domains. SecurityX gives only pass or fail; the CISSP needs 700 out of 1,000.
Is the SecurityX (CASP+) exam adaptive like the CISSP?
ISC2 says the CISSP (Certified Information Systems Security Professional) uses computerized adaptive testing for all exams: the computer picks each question based on your earlier answers and stops somewhere between 100 and 150 items. CompTIA's SecurityX page, for the exam formerly called CASP+, lists a maximum of 90 questions and does not describe the exam as adaptive.
Does CASP+ count toward the CISSP experience requirement?
Yes, for one year. The CISSP (Certified Information Systems Security Professional) requires five years of full-time security work. ISC2's list of approved credentials, each of which can replace one of those years, names both CASP+ and CompTIA SecurityX, its current name. ISC2 allows only one such waiver: a degree and a credential cannot be combined, so if a computer science degree already covers your year, CASP+ shortens nothing further.
How much do the CISSP and SecurityX cost over three years?
With one exam attempt and no study material, the CISSP (Certified Information Systems Security Professional) costs $1,154 over three years at ISC2's Americas price: the $749 exam plus three yearly fees of $135. CompTIA SecurityX, formerly CASP+, costs $694: a $544 exam voucher (a prepaid code you use to book the exam) in CompTIA's US store (listed on CompTIA's SecurityX page) plus one $150 continuing education fee, which covers a three-year renewal cycle.
Which do job ads name, the CISSP or CASP?
In October 2026, we counted 8,110 US security-analyst ads on Adzuna, a job-ad search site. Of those, 338 contained the word cissp and 48 contained the word casp. Ads that use only the new name, SecurityX, are not in the casp count.
How do you renew the CISSP and SecurityX?
The CISSP (Certified Information Systems Security Professional) needs 120 CPE credits every three years, logged learning such as courses and conferences, plus ISC2's $135 yearly fee. CompTIA SecurityX, formerly CASP+, needs 75 continuing education units (CEUs, credits for approved learning and work) and a $150 fee per three-year cycle. The two systems are separate, so holding both means renewing with each vendor.