ISC2 currently allows required CPE activities to be earned and submitted no later than 90 days after the certification expiration date, but the grace period does not remove the certification-maintenance obligations or make indefinite late reporting acceptable.
Use the correct credential total and Group A minimum
ISC2 totals differ by credential. CISSP, CCSP/CSSLP, SSCP/CGRC and CC do not all use the same total or Group A/B mix, so select the exact credential before calculating a gap.
CPEs are one part of active status
ISC2 maintenance also includes the annual maintenance fee. Keep the CPE requirement, fee status, cycle dates and grace-period timing as separate checks.
Save activity evidence and domain relevance
For Group A activities, retain enough detail to show how the activity relates to certification domains. A local total is useful for planning but the ISC2 portal remains the certification record.
Sources and verification
CPE maintenance framework for ISC2 credentials; credential-specific totals should be verified before reporting.
Open official/current source ↗