For CMMC professionals and assessors
Your expertise.
A new framework.
At no cost.
Take your CMMC experience further with a fully funded route to PECB ISO/IEC 27001 certification.
Find your transition routeApplications close December 31, 2026
Build on what you already know
Active, verifiable CMMC credential required.
Build on your CMMC experience
Expand your expertise
with ISO/IEC 27001
Following the suspension of CMMC Phase II requirements, PECB is helping CMMC professionals and assessors apply their experience to a new certification pathway.
ISO/IEC 27001 provides a framework for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). Build on your knowledge of security controls, risk, evidence, and compliance to implement an ISMS or audit its effectiveness.
Find the pathway for your credential
Choose your certification pathway
Start with the pathway that matches your active CMMC credential.
PECB ISO/IEC 27001
Lead Implementer
Build on your understanding of risk and security controls to establish, implement, maintain, and continually improve an information security management system.
PECB ISO/IEC 27001
Lead Auditor
Bring your experience in audit planning, evidence sampling, control testing, and reporting findings to the assessment of information security management systems.
Your credential establishes eligibility for the offer. PECB evaluates your application against the relevant certification requirements.
Fully funded, from learning to application
What’s included in your transition
The same support package applies to both certification routes.
The full eLearning course
Trainer-led videos and self-study materials, with learning at your own pace.
Two exam attempts
Two exam attempts, initial and retake.
Certification application
PECB covers your certification application fee.
First-year maintenance
Your first Annual Maintenance Fee is covered.
After your first year: standard maintenance terms apply, currently $130 per year plus continuing professional development (CPD) requirements.
eLearning for professionals
Learn at your own pace
Use your existing cybersecurity or assessment experience as a starting point. Build the ISO/IEC 27001 knowledge you need through trainer-led videos and self-study materials.
Plan for approximately 15–20 hours of study, depending on your experience and pace.
Explore ISO/IEC 27001 with PECB ↗From your current credential to your next
How to apply
- 1
Send your credential
Email the contact for your route with proof of your active CCP, CCA, or Lead CCA credential. Include an equivalent ISO/IEC 27001 certificate if you hold one.
- 2
Receive your review
PECB provides a documented evaluation of your credentials against its certification requirements within one business day.
- 3
Study on your schedule
Access the full eLearning course and prepare for your exam at your own pace.
- 4
Pursue certification
Pass the exam and complete the applicable certification requirements to receive your PECB credential.
Already certified in ISO/IEC 27001?
If another accredited certification body issued your equivalent Lead Implementer or Lead Auditor certificate, submit it with your application. Where PECB’s evaluation supports it, certification may be issued without a further exam.
Building digital trust
Why choose PECB?
A world leader in digital trust training and certification.
Training programs
A broad portfolio of training courses to help you develop your expertise and advance your professional goals.
Partners worldwide
A global network of Partners and 2,000+ trainers supporting professional development.
UKAS · COFRAC
International accreditations
PECB holds accreditations from these bodies and others. Accreditation scopes vary by program.
IAS, UKAS, and COFRAC accreditations cover personnel certification. ANAB accreditation covers certificate programs.
Explore PECB’s accreditations ↗Is the offer really free?
Yes. For eligible CMMC-CCP, CMMC-CCA, and CMMC-LCCA credential holders, PECB offers the eLearning course, two exam attempts, the certification application fee, and the first year of Annual Maintenance, at no cost. From the second year onward, standard maintenance terms apply, currently $130 per year, along with the applicable CPD requirements.
Who is eligible to apply?
Active and verifiable CMMC Certified Professional (CCP) credential holders are eligible for the ISO/IEC 27001 Lead Implementer route.
Active and verifiable CMMC Certified Assessor (CCA) or Lead CCA credential holders are eligible for the ISO/IEC 27001 Lead Auditor route.
Simply provide proof of your active CMMC credential, and PECB will review and confirm your eligibility.
Does my CMMC credential automatically convert to a PECB certification?
No. This offer provides a funded pathway to a PECB certification; it is not an automatic credential conversion. PECB will evaluate your eligibility against its certification requirements, and the standard pathway includes completing the required learning and passing the exam.
If you already hold an equivalent ISO/IEC 27001 certification from another accredited certification body, PECB may be able to recognize it without requiring you to take another exam, subject to a credential review.
When do I need to apply?
Applications must be submitted by December 31, 2026.
We recommend applying as early as possible. Your learning access and exam scheduling will be confirmed after PECB reviews your application, giving you sufficient time to prepare and complete the exam before the offer expires.
How do I apply?
Click the Apply button for your preferred route: Lead Implementer or Lead Auditor.
This will open an email addressed to the team listed in the brochure. Include proof of your active CMMC credential and, if applicable, a copy of your ISO/IEC 27001 certificate for review.
Why is PECB offering this?
PECB has established a strong global community of certified information security professionals, while ISO/IEC 27001 continues to serve as the international benchmark for information security management across industries and borders. Unlike credentials tied to a specific program or agency, ISO/IEC 27001 provides expertise that can be applied broadly across organizations and sectors. As CMMC's Phase 2 timeline is reassessed, we see an opportunity to bring experienced CMMC professionals into that broader ecosystem. This offer reflects our commitment to supporting the cybersecurity workforce and expanding access to internationally recognized credentials, at no cost to eligible applicants.
Applications close December 31, 2026
Put your expertise to work
in ISO/IEC 27001
Your next professional chapter starts with the experience you already have.
Continue your professional development
Interested in more training courses?
Explore the PECB Training Catalog to find courses in cybersecurity, information security, artificial intelligence, risk management, and more. Discover learning opportunities that support your next professional goal.