ISC2 opened development on a new AI security certification on July 15, 2026, and is asking practitioners worldwide to help define what it tests. The CISSP itself is unaffected. What the announcement signals is where ISC2 believes the profession’s skills gap now sits, and the mechanics of how the credential gets built are the same mechanics that will eventually reshape the CISSP.
ISC2 is building a standalone, vendor-neutral AI security certification and has opened a global call for volunteers to define its content. Nothing about the CISSP changes. The exam outline effective April 15, 2024 remains in place with no refresh announced. ISC2 has said it anticipates a pilot exam by the end of 2026, while CEO Scott Beale has separately described beta testing beginning in early 2027.
What did ISC2 announce?
ISC2 announced from Alexandria, Virginia on July 15, 2026 that it has begun developing a certification covering the security of AI systems, the management of AI-related threats, and the mitigation of AI risk. The organization published a program page and volunteer interest form the same day, and is recruiting both members and non-members.
The build follows the three-phase process ISC2 uses for all its credentials. A definition phase identifies the knowledge, skills, and abilities the certification should cover. A development phase turns those into exam items. A delivery phase runs pilot exams and analyzes the results before the credential moves into the operational portfolio. Volunteers are being sought for all three, and the invitation extends past security practitioners to AI engineers, risk leaders, and policy people.
ISC2 chief operating officer Casey Marks framed the decision to Network World in terms of timing, saying AI has reached a tipping point for the profession.
Why a separate certification instead of more AI questions on existing exams?
ISC2 already took the incremental route once. The organization added AI-related items across all nine of its current certifications during the previous cycle, which means CISSP candidates sitting the exam today can already encounter AI content within the existing eight domains.
According to Beale’s account to Axios, members and employers kept asking for something standalone anyway. His stated reason is demand rather than pedagogy: the question came up constantly enough in his first months as CEO that it registered as a pattern. The organization’s public position is that the profession lacks a recognized standard for validating AI security expertise, and that expanding existing exams doesn’t produce one.
There’s a practical argument underneath it. A CISSP holder who scores well on a handful of AI-adjacent items has demonstrated nothing an employer can point to specifically. A separate credential produces a signal that can be filtered on. Whether employers actually adopt that filter is a different question, and the certification market has produced plenty of credentials that never gained hiring traction.
Does this change the CISSP exam?
No. The current CISSP exam outline took effect April 15, 2024, and ISC2 hasn’t announced a successor. The format is unchanged at 100 to 150 adaptive items across three hours, and the eight domains stay as they are.
Candidates holding a test date have no reason to move it. Candidates deciding whether to book one have no reason to wait for a refresh, because none is scheduled. ISC2 runs a Job Task Analysis on roughly a three-year cycle, and the 2024 outline already absorbed the organization’s thinking on AI and zero trust at the time.
How does this fit against the AI certifications that already exist?
The field isn’t empty. IAPP’s Artificial Intelligence Governance Professional and ISACA’s Advanced in AI Security Management and Advanced in AI Audit both launched into this space ahead of ISC2, and each approaches it from a different angle. The IAPP credential leans toward policy and regulatory frameworks. The ISACA credentials sit closer to assurance and management practice.
ISC2 hasn’t finalized domains, so a direct comparison isn’t possible yet. Reporting so far indicates the certification will span both technical AI security and governance topics, and that it’s expected to target professionals with some security background rather than veteran practitioners exclusively, with AI engineers moving the other direction as a secondary audience. That positioning would put it between the governance-focused options and a purely technical credential.
Readers weighing the current options can compare the CISSP against the AIGP and the CISSP against ISACA’s AAISM in the meantime.
When will the AI security certification launch?
The public statements don’t fully agree, which is worth naming rather than smoothing over.
ISC2’s own program materials and its July 15 announcement describe a pilot exam anticipated by the end of 2026. Six days later, Beale told Axios the organization hopes to begin beta testing in early 2027, and that scope and target audience would be settled over roughly the following five months. Both statements can be true if the pilot slips or if the terms are being used differently, but candidates planning around a date should treat early 2027 as the realistic floor and note that ISC2 has given no launch date for an operational exam at all.
The verdict
For anyone currently preparing for the CISSP, this announcement changes nothing worth acting on. Keep the study plan and the test date. The AI certification is 18 months or more from being something a hiring manager recognizes, and an unproven credential in a crowded category is a poor substitute for the one that already appears in senior security job postings.
The exception is practitioners who already do AI security work and want influence over what the standard becomes. Volunteering during the definition phase is the only window where an individual practitioner meaningfully shapes an exam’s body of knowledge, and it costs nothing but time.
Tara Kohl is a 20-year IT veteran whose career has centered on information security and risk management. She holds the CISSP and CISM along with a range of additional certifications, and she's spent most of those years consulting for major aerospace firms and government contractors, where security and compliance demands sit at the top of the priority list.
