ISC2 released its 2026 Security Training Trends report on June 10, and the takeaway lands close to home for anyone weighing a certification this year. Companies are putting more money into training their security teams, and the skills they’re paying to build line up almost exactly with what the Certified Information Systems Security Professional (CISSP) exam covers.
The survey of 995 cybersecurity team leaders found that 73% saw their training budget grow over the past 12 months, and 47% named artificial intelligence as the most pressing skill their organization is working to address. For a candidate deciding whether the timing is right, that’s a useful signal about where employer dollars are going.
Money Moved First, and It Moved at Most Companies
The clearest signal in the report is spending. Almost three-quarters of security leaders, 73%, said their training budget grew over the past year. That’s not a quiet bump in one corner of the market. ISC2 surveyed managers and above who are personally involved in how their teams get trained, so the people answering are the ones who actually approve professional development dollars.
What’s driving it is a target that keeps moving. As AI tools, cloud platforms, and newer attack methods reshape day-to-day security work, organizations are trying to keep their people current instead of letting skills slip. ISC2 Chief Operating Officer Casey Marks described the shift as treating training like a business resilience question rather than a periodic exercise, the difference between a team that adapts and one that scrambles.
AI Edged Out Everything Else on the Skills List
When ISC2 asked which skills organizations are addressing through training, AI came out on top at 47%. Cloud security followed at 44%, tied with security analysis. Risk assessment and management and security administration each landed at 40%, rounding out the top five.
Here’s the part worth sitting with if you’re studying. Not one of those five priorities falls outside the exam. Risk assessment and management is the backbone of Domain 1. The architecture questions tied to AI and cloud live in Domain 3. Secure development, including the headaches that come from AI-written code, sits in Domain 8. The skills employers are spending to build are the same ones the certification asks you to demonstrate, which means a CISSP candidate is studying the market’s shopping list whether they planned to or not.
Confidence Is High. The Calendar Is Not.
Most leaders feel good about where their programs stand. 94% said they’re keeping up with or staying ahead of emerging tech and shifting requirements, and 86% said their training effectively addresses changing skill needs. Those are upbeat numbers for a field that usually frets about falling behind.
One finding cuts against all that optimism. More than half, 53%, named time and scheduling as the biggest barrier to effective training, even though 98% said professional development is allowed during work hours. Permission isn’t the holdup. Carving out the actual hours is what trips people up.
That gap between budget and time will sound familiar to anyone who has tried to prep for the CISSP while holding down a full security job. The money and the approval are usually sitting right there. The calendar is the thing that gives out first, which is why a realistic study schedule tends to matter more than raw study hours.
What a CISSP Candidate Can Take From This
A few practical reads come out of the report.
- ✓Employer demand is pointing straight at CISSP territory. AI, cloud, and risk are the skills getting funded, and all three are core to the exam. Holding the credential puts you on the right side of where budgets are actually flowing in 2026, not where they sat a few years ago.
- ✓Training is role-specific now, which favors a portable credential. 70% of organizations said they tailor training by job role instead of running one generic program, and 77% blend in-house and outside providers. A recognized certification like the CISSP carries across roles and employers in a way that a one-off internal course never will.
- ✓Time is the real constraint, so build around it. With more than half of leaders flagging scheduling as the top obstacle, the candidates who finish are usually the ones who set a pace they can hold week after week. A few of our exam tips are aimed squarely at people studying around a full-time job.
- ✓The field is investing, not cooling off. A 73% jump in training budgets tells you organizations still see real value in building security skills. That’s a healthy backdrop for anyone deciding whether the certification is still worth the effort.
How Much Weight the Numbers Carry
The findings hold up because of how the study was built. ISC2 surveyed 995 cybersecurity team leaders across six countries: Canada, Germany, India, Japan, the United Kingdom, and the United States. Every respondent was at manager level or higher and personally involved in their team’s training. Fieldwork ran in December 2025, and ISC2 put the margin of error at plus or minus 3% at a 95% confidence level.
That sampling matters for a report like this. Answers drawn from the people who control training decisions, spread across several major economies, tell you a lot more than a quick open-access poll would.
If You’ve Been Sitting on the Fence
For anyone who has been putting off CISSP prep, this report reads like a green light. Employers are funding the exact skills the certification validates, and they’re guarding training in the budget rather than trimming it. The one thing the data can’t hand you is the time. That part is yours to manage. Block out the hours, pick a pace you can actually keep, and the rest of the trend is already leaning your way.