Analysis / September 2, 2026 / 4 min read

Is a CISSP Domain Refresh Coming in 2027? What the JTA Cycle Tells Us

ISC2 has not announced the next CISSP exam update. But the certification runs on a predictable rhythm, and that rhythm points to 2027 as the likely window. Here’s the pattern the schedule is built on, what actually changed last time, and why none of it is a reason to delay your exam.

When was the CISSP exam last updated?

The current exam outline took effect on April 15, 2024. That update refreshed the content across all eight domains and adjusted the domain weights based on ISC2’s latest Job Task Analysis (JTA) — the survey of working practitioners that decides what the credential should test.

How often does ISC2 update the CISSP?

On a roughly three-year cycle. ISC2 describes the JTA as a triennial process, and the recent history backs that up:

  • April 2018 — exam outline refresh
  • May 2021 — exam outline refresh
  • April 2024 — current outline, all languages moved to CAT

Three years between each. Follow that spacing forward and the next refresh lands somewhere in 2027, most plausibly in the spring. To be clear, that’s a projection from the pattern, not a date ISC2 has published.

What changed in the April 2024 refresh?

The 2024 update was an evolution, not a teardown. The eight domains stayed the same. The weights shifted only slightly — Domain 1 (Security and Risk Management) rose from 15% to 16%, and Domain 8 (Software Development Security) dropped from 11% to 10%. The more meaningful changes were in the content itself, with newer topics folded in, including quantum key distribution, secure access service edge (SASE), and updated privacy regulations.

That’s the useful precedent: ISC2 tends to modernize the topic list and nudge the weights rather than reinvent the exam. Someone studying the current outline isn’t going to wake up to a completely different test.

So when is the next CISSP update likely?

If the triennial cadence holds, expect the next outline around spring 2027. ISC2 gives notice ahead of a change and publishes the new exam outline before it takes effect — it did exactly that in 2024, announcing the weighting changes months before the April date. So candidates won’t be caught off guard as long as they check the outline before scheduling.

Treat 2027 as a planning estimate, not a countdown. ISC2 could move earlier or later, and nothing is official until they say so.

What might a future refresh emphasize?

This part is informed speculation, not fact — ISC2 has announced no content for a future exam. That said, if you look at where the field is moving and what the 2024 update already started pulling in, a few themes are reasonable bets for more coverage next time:

  • AI and machine learning security — securing models, data pipelines, and the risks AI introduces into existing controls. ISC2 has already signaled a broader push into AI security across its portfolio.
  • Post-quantum cryptography — the migration toward quantum-resistant algorithms, building on the quantum key distribution content added in 2024.
  • Cloud-native and zero-trust architecture — as more organizations operate this way by default.
  • Evolving privacy and AI regulation — the compliance landscape keeps shifting, and Domain 1 tends to absorb it.

None of that is confirmed. It’s the kind of content that fits the direction of travel, and it’s worth being conversant in regardless of what the exam does.

Should you wait for the new version to certify?

No. Waiting for a future outline is almost always the wrong move. You’d be trading a certification you could hold now for a hypothetical exam that may be more than a year out, isn’t dramatically different, and still demands the same months of preparation. The knowledge carries over, and a CISSP earned under the 2024 outline doesn’t expire or lose value when the next one arrives.

Study the current outline, sit the exam while you’re prepared, and keep your knowledge current afterward through CPE credits — which is exactly how the certification is designed to stay relevant between refreshes. If you’re mapping out a timeline, our study plan guide and complete CISSP guide are the place to start.

Frequently asked questions

Is the CISSP exam changing in 2027?
ISC2 has not announced a 2027 update. A refresh around that time is a reasonable projection based on the three-year JTA cycle (2018, 2021, 2024), but it is not official.

Will my CISSP still be valid after the next exam update?
Yes. A CISSP earned under the current outline stays valid. You maintain it through annual CPE credits and the maintenance fee, not by re-sitting the exam.

How much notice does ISC2 give before an exam change?
ISC2 publishes the new exam outline and announces the effective date in advance — for the 2024 update, the weighting changes were shared several months ahead — so candidates can plan which version they’ll sit.

Sources: ISC2 CISSP Certification Exam Outline and ISC2 guidance on the April 15, 2024 exam update. Update timing beyond 2024 is an estimate based on ISC2’s historical three-year cycle and has not been announced.

Tara Kohl

Tara Kohl is a 20-year IT veteran whose career has centered on information security and risk management. She holds the CISSP and CISM along with a range of additional certifications, and she's spent most of those years consulting for major aerospace firms and government contractors, where security and compliance demands sit at the top of the priority list.