I have a CISSP tattoo. 😂
I also post the Dilbert cartoon where the guy says, “Step aside. I am certified.”
Those two things are not contradictory.
I earned my CISSP in 2008, and I have long said it opened doors for me that probably would not have opened otherwise. It mattered to my career. I am proud of it.
▶️ But I have never believed a certification makes somebody competent.
Lately I have seen more people argue that the CISSP has become “watered down” because there are more CISSPs, younger people are passing the exam, and candidates have access to dramatically better study tools than we did 15 or 20 years ago.
Maybe. But I think that claim needs evidence.
“There are more CISSPs now” tells me very little without a denominator. Cybersecurity is also vastly larger than it was when I earned mine. There are more cyber jobs, more cyber professionals, more regulated environments, more cloud systems, more attack surface, and more organizations that need people who understand risk.
I also think we need to distinguish between an exam becoming easier and preparation becoming better.
I became an MCSE in the Windows NT 4.0 days. By the Windows 2000 era, braindump sites were circulating reconstructed, and sometimes actual, exam questions. People could memorize answers instead of learning the material.
That absolutely diluted a credential.
Today, CISSP candidates have adaptive test engines, online courses, enormous question banks, YouTube, Reddit, Discord, and AI. If somebody can use AI to explain Bell-LaPadula five different ways, generate scenario questions, identify weak domains, and study more efficiently, is that evidence the CISSP was watered down?
Or did learning get better? 🤔
If ISC2 lowered the competency standard, that concerns me. If people are simply getting better at preparing for the standard, I have a hard time calling that a problem.
Passing the exam is also not the same thing as becoming a CISSP. The experience requirement still matters. At the end of the day, I do not care how many letters are after your name. You still have to be effective.
Here is what would support the dilution argument: meaningful changes in pass rates over time, evidence that the passing standard has been lowered, or employer data showing newer CISSPs lack the judgment, breadth, or risk-management ability the credential should represent. THAT would be dilution.
The industry should also look in the mirror. We put “CISSP required” on jobs that do not need it, even junior ones. Then we act surprised when younger professionals pursue it. We told them it was valuable. They believed us.
Difficulty, by itself, is not quality. A certification should not exist to preserve the exclusivity of those who already hold it.
So the question is not “Are there too many CISSPs?” It is: does the CISSP still mean what the profession needs it to mean?
If yes, growth is not dilution. If no, show me why. “There are more of them now” is not enough.
#CISSP #Cybersecurity