ISC2▊
Organization dossier The CISSP certification body Status: still the DoD-recognized baseline
The certification body whose flagship credential a U.S. Department of Defense mandate made effectively mandatory for a generation of government security jobs — then, in the words of a recruiter who staffs those jobs, became "a warning flag to industry elite not to apply." In 2022 it gave away a million free entry-level certs while raising the annual fee on the people who already held the expensive one. In 2024 its CEO left with no reason given, and the DoD retired the mandate that built it.
Clar has led ISC2 through a period of monumental change and growth and leaves us in a much stronger position.
ISC2, in its official statement on CEO Clar Rosso's departure (October 2024) — the full stated explanation, per PR Newswire
- ENTITY
- ISC2 (formerly (ISC)²), the International Information System Security Certification Consortium — the nonprofit that issues the CISSP FACT
- CREDENTIAL
- CISSP — Certified Information Systems Security Professional; the first information-security certification accredited under ANSI/ISO/IEC Standard 17024 FACT
- THE MANDATE
- DoD Directive 8570 named the CISSP among the baseline certifications required for DoD information-assurance management roles — a market underwritten by federal policy FACT
- THE DRAMA
- A captive federal market, a "vocabulary test" reputation among practitioners, a million free certs paired with a fee hike on legacy members, a CEO who left without explanation, and the DoD retiring the mandate that built the whole thing
- RECORD
- No fraud finding, no regulator action, no adjudication appears in this record. The criticism is practitioners' and a recruiter's opinion — named and loud in the sources below, but opinion. FACT
- STATUS
- STILL OPERATING — CISSP remains recognized under DoD 8140; isc2.org is live; the CPEs still renew
This one is an institution, not a person — a nonprofit that issues a credential the U.S. government spent two decades requiring. Institutions of this species do not get charged with anything. They get quoted, invoiced, and outlived. Keep the organization distinct from the people the record happens to name; this file does.
What follows is the record in order: the mandate that made the market, the practitioners who priced the paper, the giveaway and the invoice, and the quiet exit. Every beat carries its receipt. Both sides get the microphone. You decide.
the drama timeline
ACT I — THE MANDATE (2005–)
A credential becomes valuable two ways. It can earn the field's respect, or it can be written into federal policy. Watch which one happened here.
-
2005
DoD 8570 writes the CISSP into the job description
DoD Directive 8570.01-M established baseline certification requirements for personnel in DoD information-assurance roles — military, civilian, and contractor — and named the CISSP among the approved baseline certifications for management-level positions. Any contractor staffing those roles now had to hire CISSPs or pay to make them. The demand was written into policy.
The market was not won. It was mandated.
ACT II — THE PRICE OF THE PAPER (ONGOING)
The field that actually breaks into things formed its own opinion of the credential the paperwork required. It was not the paperwork's opinion.
-
ONGOING
"A warning flag to industry elite not to apply"
Recruiter Thomas Ptacek — whose firm staffs security roles — describes the CISSP as "a joke," and says that in his experience a job description requiring a CISSP was "a warning flag to industry elite not to apply." The words are his; the credential the government required, the field priced.
-
ONGOING
"It means you know the vocabulary"
A recurring line among practitioners holds that the CISSP certifies familiarity with terminology and the ability to pass a test rather than hands-on skill — an HR prerequisite, not a competence signal. Among those who publicly walked away from the credential was industry figure Wendy Nather, who gave up her CISSP. This is the field's opinion of the paper, stated as the field's.
ACT III — THE GIVEAWAY AND THE INVOICE (2022)
A credential body facing a talent shortage has two levers: widen the front door, and raise the rent on the tenants. In one year, ISC2 pulled both.
-
2022
A million free certs
ISC2 pledged to give away one million free entry-level "Certified in Cybersecurity" (CC) exams and first-year memberships, with no experience required — a workforce-building answer to the industry's "skills gap." A CC holder becomes a full ISC2 member on passing.
-
2022
The legacy invoice goes up
In the same period, existing members' Annual Maintenance Fee rose to $125 — roughly a 50% increase over the prior $85, per members posting in ISC2's own community forum, several of whom framed it as legacy holders subsidizing the free-CC cohort. The fee increase was announced, not hidden; the framing is the members'.
A million seats free at the front. The standing members' rent up half again at the back.
ACT IV — THE QUIET EXIT AND THE RETIRED MANDATE (2024)
Institutions do not fail loudly. They announce a leadership transition with warm words, and the policy that underwrote them quietly gets rewritten.
-
OCT 2024
The CEO leaves, no reason given
ISC2 announced that CEO Clar Rosso had stepped down. The board's statement praised her tenure — "a period of monumental change and growth" — and gave no reason for the departure. CFO Debra Taylor was named acting CEO. Nothing in the record suggests wrongdoing; the record simply contains no stated cause.
-
2024
The DoD retires 8570
DoD 8140 superseded the 8570 framework, shifting toward work-role mapping and hands-on skills assessment. Critics read the move as an implicit acknowledgment that certification alone had not reliably produced capable people. ISC2, for its part, states that CISSP remains recognized under 8140 and maps to the most work roles in the DoD's manual — continuity, in its telling, not repudiation.
-
EPILOGUE
Still the baseline
CISSP remains a DoD-recognized credential under 8140. isc2.org is live; the free CC program shipped; the Annual Maintenance Fee renews on schedule. No investigation was published. Everyone just renewed their CPEs.
both sides, on the record
The market was federal, not earned: DoD 8570 wrote the CISSP into government job requirements, underwriting demand by regulation rather than by the field's own valuation of the credential [7] [2].
Practitioners priced the paper low (theirs, not ours): a recruiter who staffs the roles calls it "a joke" and "a warning flag"; a recurring line in the field is that it certifies vocabulary and test-taking, not skill [8] [9].
The economics cut toward revenue: a million free entry-level certs at the front door, and a roughly 50% Annual Maintenance Fee increase on legacy members at the back — both in the same window, per ISC2's own program pages and its own member forum [3] [5] [6].
The institution turned opaque at the top: the CEO left with no stated reason, and the DoD retired the very mandate that built the market [1] [4].
The credential is genuinely accredited: the CISSP was the first information-security certification accredited under ANSI/ISO/IEC Standard 17024, an independent conformity standard — recognition the government paperwork did not manufacture [7].
The free-CC program is defensible on its face: the cyber-workforce shortage is real and widely documented, and a free entry-level credential lowers the barrier into a field that needs people. ISC2 frames the giveaway as workforce-building, not brand dilution [3] [6].
Fee changes are ordinary: maintenance fees rise across professional bodies; the AMF is small against the salary premium CISSP holders report, and the increase was announced in the open, not concealed [5] [7].
Nothing improper is on the record: Rosso's departure came with board praise and an orderly CFO succession; no regulator, court, or investigation has found wrongdoing by ISC2, and none is alleged here. CISSP remains recognized under DoD 8140 — ISC2 notes its certifications map to the most 8140 work roles, so the new framework reads, in its account, as continuity rather than a verdict against the credential [1] [2] [4].
YOU DECIDE
Scoped to the claims, never the institution. The claim "the CISSP is the field's gold standard" meets a split record: it is ISO-accredited and federally recognized, and it is also, in the words of a recruiter who staffs the jobs, "a warning flag." Accreditation and reputation point opposite ways, both on the record. The claim "ISC2 put revenue ahead of members" rests on a real pairing — a million free certs and a higher legacy fee in the same window — but a pairing is documented conduct, not a proven motive, and this page asserts none. Nothing here is adjudicated. Nothing here is a fraud finding.
Weigh the costly signals: the government made the credential mandatory, and the field reproduced its verdict for free. A recruiter's shrug costs nothing to give and everything to ignore. The one thing that would settle it — evidence the paper reliably produces capable defenders — is exactly what the DoD stopped betting on when it retired 8570.
The archive does not judge. The archive keeps the invoices.
evidence locker
PRIMARY RECORD
ISC2 — the "1 Million Certified in Cybersecurity" (1MCC) program page SELF-PUBLISHED — the free entry-level exam-and-membership giveaway, on ISC2's own site.
isc2.org/landing/1MCC
public.cyber.mil — DoD Cyber Workforce Framework (DCWF / DoD 8140) FACT — the 8140 framework that superseded 8570, shifting toward work-role mapping and hands-on assessment.
public.cyber.mil/wid/dcwf/
PRESS & CRITICISM
CROSS-REFERENCE — THE SIBLINGS
isc2.org SELF-PUBLISHED — the organization, still operating, still recognized.
isc2.org
The standard. Everything above is sourced to a DoD workforce framework, the organization's own program pages and press release, independent reporting, and named practitioner criticism. Facts are stated as facts; the criticism is stated as criticism and wears its critic. The organization is distinguished from the individuals the record names, the free-cert program and the fee increase are stated as the documented conduct they are without a claimed motive, and the defense — ISO accreditation, workforce-building, ordinary fee changes, orderly succession, and continued DoD recognition — is presented at full strength. No fraud is alleged, no regulator finding exists, no private character is diagnosed. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.