CISSP and AI in 2026: What Actually Changed?

CISSP and AI in 2026: What Actually Changed?


Clearing the confusion around AI, the CISSP examination, and ISC2’s new AI Security certification

If you are preparing for the CISSP examination in 2026, you may have recently encountered a new concern:

“Has AI been added to the CISSP?”

Then comes the next question:

“Do I need completely new AI study material?”

And now there is another development creating even more confusion:

ISC2 is developing a dedicated AI Security certification.

Add articles, LinkedIn posts, videos, courses and discussions around “CISSP 2026 AI updates,” and it becomes difficult for an aspirant to distinguish between an official ISC2 change and someone’s interpretation of that change.

So let’s separate the facts from the noise.

First: What Has ISC2 Actually Published?

On April 2, 2026, ISC2 published its Exam Guidance for Artificial Intelligence.

ISC2 describes the document as guidance showing where AI concepts appear across more than 50 core cybersecurity exam domains in its certification portfolio.

This is an official ISC2 document.

And importantly, the guidance does contain a specific section for the CISSP.

The CISSP section references the existing CISSP Exam Outline, effective April 15, 2024, and explains how AI-related security concepts are represented within the existing CISSP domains.

That distinction is critical.

ISC2 did not create a ninth CISSP domain called “Artificial Intelligence.”

The CISSP remains structured around its existing eight domains. ISC2’s current CISSP page continues to present the eight-domain examination structure and now provides a link to the AI Exam Guidance.

So, Is AI in the CISSP?

Yes—but not as a new standalone domain.

This is probably the simplest way to understand the situation.

AI-related concepts are being addressed within the existing CISSP knowledge structure.

That means an aspirant should not interpret the 2026 development as:

“ISC2 has added Domain 9 — AI Security.”

That statement would be incorrect.

Instead, AI security concepts are being connected to the existing cybersecurity disciplines represented by the CISSP.

This is an important distinction because the CISSP is fundamentally designed to test broad cybersecurity knowledge and the ability to apply security principles to organizational situations.

What Does the ISC2 AI Guidance Cover?

The guidance does not simply say:

“Learn Artificial Intelligence.”

It identifies specific AI-related security concepts associated with existing cybersecurity responsibilities.

That includes areas such as:

  • AI and machine-learning models
  • Large language models
  • AI risk
  • AI governance
  • AI ethics
  • Algorithmic bias
  • AI supply-chain risk
  • Training data
  • Pre-trained models
  • Model weights
  • Data poisoning
  • Prompt injection
  • Adversarial attacks
  • AI compute environments
  • AI agents
  • Automated service accounts
  • AI red teaming
  • Model drift
  • AI-assisted security operations
  • AI-assisted software development

The important point is that these concepts are presented in the context of cybersecurity domains, rather than as a separate AI engineering curriculum.

That is a very different proposition from asking a CISSP candidate to become a machine-learning engineer.

AI Does Not Replace the CISSP Domains

For a candidate, this is perhaps the most important takeaway.

The existing CISSP domains remain the foundation.

AI is being considered in relation to those domains.

For example, AI can intersect with:

Security & Risk Management

AI risk, governance, ethics, privacy and regulatory considerations.

Asset Security

Training datasets, models, model weights and protection of AI-related data.

Security Architecture & Engineering

AI infrastructure, secure AI environments and AI-specific attacks.

Communication & Network Security

AI infrastructure and the security implications of AI-enabled environments.

Identity & Access Management

AI agents, automated identities and authorization.

Security Assessment & Testing

AI red teaming, adversarial testing and assessment of AI systems.

Security Operations

AI-assisted detection, automation, model drift and adversarial activity.

Software Development Security

AI-assisted coding, AI-generated insecure code and AI-related software supply-chain concerns.

This is not a ninth domain.

It is the application of security knowledge to an environment in which AI is increasingly present.

Then Why Is ISC2 Building a Separate AI Security Certification?

This is where the 2026 story becomes particularly interesting.

On July 15, 2026, ISC2 announced that it had begun developing a new AI Security certification. ISC2 says the certification is intended to recognize and benchmark AI-security skills and competence within the cybersecurity workforce.

ISC2 expects a pilot examination by the end of 2026.

The certification is being developed separately from CISSP.

That gives us an important distinction:

CISSP provides broad cybersecurity competency, while the new AI Security certification is being developed as a specialized AI-security credential.

The latter is not a replacement for CISSP.

It is not “CISSP 2026.”

It is a separate certification initiative.

Why Is This Causing Confusion?

Because three different things are happening at the same time.

1. AI is becoming increasingly important to cybersecurity

This is an industry reality.

2. ISC2 has published official AI exam guidance

This explains where AI concepts appear within its existing certification examinations.

3. ISC2 is developing a dedicated AI Security certification

This is a separate certification initiative, with a pilot expected later in 2026.

When these three developments are combined without context, it is easy to conclude:

“The CISSP exam has been completely changed for AI.”

That conclusion goes further than the official information supports.

What Should a CISSP Aspirant Do?

This is where I would keep the advice very practical.

Don’t panic and restart your CISSP preparation

If you are already preparing against the current CISSP Exam Outline, the existence of ISC2’s AI guidance does not mean you should abandon your entire study plan.

The foundation remains the CISSP body of knowledge.

Don’t treat AI as Domain 9

There is no ninth CISSP domain called AI.

The examination remains based on the established eight-domain structure.

Don’t turn CISSP preparation into an AI engineering course

A CISSP candidate does not need to become an ML researcher simply because AI security concepts are appearing in cybersecurity certification guidance.

The relevant question is:

Can I understand the security and risk implications of AI?

That is much more aligned with the CISSP mindset.

Do understand the basic AI-security vocabulary

Candidates should be comfortable encountering terms such as:

LLM → Generative AI → Training → Inference → Prompt Injection → Data Poisoning → AI Agent → Model Drift → Adversarial Attack → AI Supply Chain

But don’t study these terms in isolation.

Understand the security problem behind the term.

For example:

Prompt injection

Don’t stop at memorizing the definition.

Understand the security concern:

An attacker may manipulate instructions provided to an AI system in an attempt to influence its behavior or cause unintended actions.

That immediately connects to familiar CISSP concepts:

risk → threat → vulnerability → control → monitoring → governance.

That is the type of thinking that makes AI relevant to CISSP preparation.

The CISSP Mindset Still Matters

This is perhaps the biggest point that can get lost in the AI discussion.

The CISSP is not simply a terminology examination.

The candidate must still think in terms of:

Risk

Governance

Business objectives

Security architecture

Least privilege

Defense in depth

Data protection

Accountability

Incident response

Secure development

Continuous assessment

AI introduces new technologies and new attack patterns.

But the fundamental security principles do not suddenly disappear.

In many cases, AI simply creates new scenarios in which established security principles must be applied.

What About People Who Already Have CISSP?

The situation is slightly different.

If you already hold CISSP, the new ISC2 AI Security certification may be worth watching—but there is no reason to assume that you must immediately pursue it.

ISC2 is still developing the certification.

The organization has invited cybersecurity professionals, including CISSP holders, to participate in the development process and help shape the certification.

Therefore, we do not yet have the final certification blueprint that would allow us to make definitive statements about its eventual examination depth, domains or preparation requirements.

That information should come from ISC2 once the certification development process produces the final specifications.

The Most Important Message for CISSP Aspirants

If you are preparing for CISSP in 2026, don’t let the AI discussion create unnecessary anxiety.

There is a difference between:

“AI is now relevant to cybersecurity certification.”

and

“CISSP has been replaced by an AI-focused examination.”

The first is supported by ISC2’s published material.

The second is not.

The official direction is much more nuanced.

ISC2 is acknowledging the growing importance of AI security through its examination guidance while simultaneously developing a dedicated certification for deeper AI-security competence.

That is a logical evolution of the certification ecosystem.

Final Takeaway

For the CISSP aspirant, the message is simple:

Don’t study AI because you are afraid that CISSP suddenly became an AI exam. Study AI security because AI is becoming part of the environment in which cybersecurity professionals must make decisions.

Your CISSP preparation should remain anchored to the current ISC2 CISSP Exam Outline.

Then add enough AI-security understanding to recognize how those established security principles apply when the organization uses AI.

And keep the two ISC2 initiatives separate:

CISSP + AI guidance

is not the same thing as

ISC2’s new AI Security certification.

That distinction will save candidates from unnecessary confusion, unnecessary preparation costs and—perhaps most importantly—misinformation.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.