The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →ISC2 reported an average U.S. cybersecurity base salary of $147,138 for compensation earned in 2023, compared with $119,000 in its 2021 comparison figure. That is a nominal increase of $28,138, or approximately 23.6%.
The number is credible as an ISC2 survey finding, but it is not a typical or guaranteed salary for every cybersecurity worker. It represents self-reported base pay from U.S. respondents and is heavily influenced by senior professionals, managers and executives.
What the ISC2 figure actually measures
ISC2’s salary analysis concerns average annual U.S. base salary. The $147,138 figure excludes bonuses, equity, other compensation and taxes. ISC2 compared it with a $119,000 figure for 2021.
The difference is $28,138. Calculated against the 2021 figure, that is approximately 23.6%:
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
($147,138 − $119,000) ÷ $119,000 ≈ 23.6%
ISC2 published the U.S. salary analysis in April 2024. The broader 2024 ISC2 Cybersecurity Workforce Study collected online survey responses in April and May 2024 from 15,852 cybersecurity practitioners and decision-makers worldwide. The salary figure applies to the U.S. subset and to compensation reported for 2023—not to every participant or to current pay in every country.
ISC2’s later pay-equity analysis also makes clear that the figures are survey responses, not independently verified payroll records.
Average does not mean typical
An average, or mean, adds all reported salaries and divides by the number of respondents. A small number of highly paid CISOs, executives, architects, consultants and senior managers can therefore pull the result upward.
A median—the midpoint at which half of respondents earn more and half earn less—would often be more useful for describing a “typical” worker. The $147,138 figure is an average, not a median, and should not be treated as an expected starting salary.
Rank #2
Related ISC2 commentary cited an average of about $86,000 for entry-level respondents and about $215,000 for senior executive-level cybersecurity leaders. Those figures illustrate the range but are not a complete salary distribution or a substitute for role-specific salary data. See ISC2’s discussion of outsourced CISOs and small and midsize businesses.
- It is an average, not a median.
- It covers U.S. survey respondents.
- It concerns 2023 compensation.
- It is base salary, not total compensation.
- It is self-reported.
- It is not an entry-level benchmark.
Why reported pay rose from 2021
The 23.6% increase should not be interpreted as saying that each cybersecurity professional received a 23.6% raise. It reflects the difference between reported salary values in two survey comparisons.
Several factors may contribute:
- Inflation and broader wage movement between the two compensation periods.
- Continued demand for security expertise.
- More senior professionals or leadership roles in the respondent mix.
- Changes in industries, job titles, locations and employer types represented.
- Competition for skills such as cloud security, security architecture, incident response and governance.
- Higher pay attached to larger budgets, teams and organizational responsibility.
Because the survey is not a census and the respondent mix can change, the result does not isolate the effect of any single factor.
High average pay does not mean equal pay
ISC2 reported a $10,000 difference in median U.S. salary by gender in the analyzed data: $150,000 for men and $140,000 for women. The organization also reported role-specific differences among nonmanagerial and management respondents.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
These subgroup figures are medians, while the headline $147,138 figure is an average. They should not be blended into one statistic. More broadly, a high overall average does not mean compensation is distributed evenly by gender, ethnicity, experience, role or industry.
Geography also matters. Pay in markets such as San Francisco, New York, Washington, D.C., Boston and Seattle may differ materially from pay in lower-cost areas. Remote employers may use the employee’s location, the employer’s location or national pay bands. Government and defense roles can also reflect clearance requirements, contracting arrangements and locality rules.
What newer ISC2 research changes
The $147,138 result is historical: it concerns 2023 pay and the 2024 study. ISC2’s 2025 Workforce Study used survey data collected in July and August 2025 from 16,029 participants. It focused heavily on skills shortages, economic pressure, pay freezes, workload and job satisfaction.
ISC2’s newer salary material does not provide a directly interchangeable update to the $147,138 U.S. average. Its 2026 article presents global median salaries by certification, including:
Recommended Free Tools
Rank #4
| Certification | Global median salary |
|---|---|
| SSCP | $95,200 |
| CISSP | $127,000 |
| ISSAP | $140,620 |
| CCSP | $118,840 |
Those are certification-holder medians, not the U.S. average for all surveyed cybersecurity professionals. Comparing them as though they form one continuous time series would mix geography, statistic and sample.
Do certifications cause higher salaries?
No causal conclusion follows from the ISC2 certification data. Certification holders may already have more experience, senior titles, management responsibility, specialized skills, security clearances or jobs at larger employers.
ISC2 says compensation depends on factors including country or region, industry, years of experience, organizational level, individual performance and employer practices. A defensible conclusion is that certification holders in ISC2’s survey reported strong salaries—not that earning a credential alone produces a specific salary.
For a beginner, the ISC2 Certified in Cybersecurity (CC) is positioned as an entry-level credential. The CISSP is intended for experienced professionals moving toward senior, leadership, governance or architecture roles. Neither credential guarantees a six-figure job.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhat job seekers should infer
The data supports cybersecurity as a potentially well-paid professional field, but it does not promise $147,000 to a career changer. Entry-level candidates may compete for relatively few openings and may need experience in IT support, networking, systems administration, cloud, software, audit, risk, military service or compliance before moving into security.
ISC2 reported that nearly one-third of surveyed organizations had no entry-level cybersecurity professionals and 15% had no junior-level professionals. That helps explain why an industry can report high average pay and a talent shortage while beginners still struggle to obtain their first security role.
When comparing an offer, look beyond the headline salary:
- Job family, level and actual responsibilities.
- Base pay versus bonus, equity and total compensation.
- Location and the employer’s remote-pay policy.
- On-call, incident-response and travel requirements.
- Security-clearance requirements.
- Training budget, certification support and continuing education.
- Promotion path, benefits and job stability.
What employers should infer
A national average is not an appropriate pay band for every analyst, engineer or security leader. Employers should benchmark by job family, level, geography, industry, clearance requirements and management scope.
ISC2 has reported that workers at organizations without competitive salaries were more likely to report skills gaps than workers at organizations offering competitive pay. Building entry-level and junior pipelines, supporting internal mobility and investing in training may be more sustainable than competing only for experienced specialists.
Timeline for reading the headline correctly
| Date | What it represents |
|---|---|
| 2021 | ISC2 comparison salary: $119,000 |
| 2023 | Compensation year associated with the $147,138 figure |
| April 11, 2024 | ISC2 published its U.S. salary analysis |
| April–May 2024 | Fieldwork for the broader 2024 workforce study |
| October 31, 2024 | ISC2 released the 2024 Workforce Study |
| July–August 2025 | Fieldwork for the 2025 workforce study |
| 2026 | ISC2 published newer certification-based global salary figures |
Bottom line
ISC2’s $147,138 figure is a legitimate finding: it is the average U.S. base salary reported for 2023 by respondents in ISC2’s survey analysis, up approximately 23.6% from the $119,000 2021 comparison. It is useful as a broad benchmark, but not as a typical salary, entry-level expectation, current universal rate or return-on-investment promise for a certification.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




