CISSP eligibility guide

You can take the CISSP exam before you have the full experience required for certification. But passing the exam and becoming CISSP certified are different milestones. This guide explains the current ISC2 rules, how work can count, and how to plan an honest next step.

The short answer

Can you take the CISSP exam without five years of experience?

Yes. ISC2 allows candidates to sit the CISSP exam before they meet the certification experience requirement. If you pass without enough qualifying experience, you can become an Associate of ISC2 and have up to six years to earn the required experience. You should not call yourself CISSP certified until ISC2 accepts your experience and endorsement.

That distinction is the central decision point. The exam tests broad enterprise-security judgement. Certification also requires verified professional experience. If you are ready to budget the route, see the separate CISSP exam cost, fees and maintenance guide. A good plan treats those as two connected projects: prepare for the exam, and separately map your responsibilities to the official standard.

Simple rule: passing CISSP is an exam result. Becoming CISSP certified requires the exam result, qualifying experience and ISC2’s endorsement process. This article explains the route; our main CISSP guide explains the credential, domains and career fit.
The certification baseline

What experience does ISC2 require for CISSP certification?

ISC2’s baseline is five years of cumulative, paid, full-time work experience in two or more of the eight CISSP domains. The word “cumulative” matters: the experience can come from more than one employer, project or role. The point is to show real work across the CISSP body of knowledge, not to match one job title.

Requirement What ISC2 says What it means in practice
Total experience Five years of cumulative, paid work experience. Experience can build across roles and employers when the work is documented clearly.
Domain breadth Work must cover two or more current CISSP domains. A security title alone is not enough; describe the responsibilities and decisions you actually handled.
Possible waiver One year may be satisfied by a qualifying degree or an approved credential. The remaining experience must still meet the two-domain condition.
Before you qualify Pass the exam and pursue Associate of ISC2 status. Use the designation accurately while you complete the experience route.

These requirements come from ISC2’s current CISSP experience requirements. Read the source before paying for an exam or submitting an endorsement because policies can change.

Match work, not job titles

What type of work can count toward CISSP experience?

Qualifying experience is about the security work you performed. A network engineer, cloud engineer, GRC analyst, security architect, incident responder, developer or audit professional may have relevant experience if their responsibilities map to two or more domains. ISC2, not an employer or training provider, makes the final determination.

Governance and risk

Policy, risk and resilience work

Security policy, risk assessment, business continuity, awareness, legal or regulatory security decisions can relate to Security and Risk Management.

Design and engineering

Architecture, network and identity work

Secure design, cryptography, network segmentation, access management and platform controls can span several CISSP domains.

Operations and assurance

Testing, response and secure delivery

Control testing, incident handling, vulnerability work, investigations and secure-development responsibilities may be relevant.

Kashif’s practical advice: do not write “I worked in cybersecurity for five years” and stop there. Build a dated record of projects, systems, decisions, controls and outcomes. Then map that record to the current outline. It is clearer for you and more useful when you reach endorsement.

The waiver is often misunderstood

Can a degree or another credential reduce the CISSP experience requirement?

Yes, but only by one year. ISC2 states that a post-secondary degree in computer science, IT or a related field may satisfy one year of the requirement. One credential from ISC2’s approved list may also satisfy one year. You cannot stack waivers to erase the practical experience requirement.

Degree route

Up to one year

A qualifying bachelor’s or master’s degree can reduce the experience requirement. Confirm your degree against ISC2’s current wording rather than relying on a forum answer.

Approved credential route

Up to one year

ISC2 maintains an approved credential list. It includes examples such as CISM, CCSP, SSCP and certain vendor or security certifications, but the list can change.

The correct calculation is usually four years of qualifying work plus one permitted waiver, while still showing work across two or more domains. It is not “a degree plus a certification equals two years off.”

Non-standard work patterns

Do part-time roles and internships count toward CISSP experience?

They can. ISC2 says full-time experience accrues monthly when a candidate works at least 35 hours a week for four weeks. Part-time work must be between 20 and 34 hours a week; ISC2 lists 1,040 part-time hours as six months of full-time experience and 2,080 hours as 12 months. Paid or unpaid internships may count with appropriate documentation.

This is useful for professionals who built security exposure through consulting, study, a career transition, a university placement or a reduced-hours role. It is not a reason to guess. Maintain start and end dates, hours, employer details, a manager or supervisor reference, and a concise description of the domain-relevant work.

For an internship, ISC2 asks for documentation on organisation letterhead confirming your intern position. If the internship is through a school, the registrar can provide the confirmation. Keep records early; reconstructing them years later is much harder.

Cybersecurity professional mapping CISSP work experience evidence for an eligibility plan
Start mapping security responsibilities and evidence before you book the CISSP exam.
If you are not eligible yet

What is the Associate of ISC2 route after passing CISSP?

If you pass the CISSP exam before you meet the experience requirement, you may become an Associate of ISC2. ISC2 gives Associates pursuing CISSP up to six years to accumulate the required five years of qualifying experience. Associate status is a legitimate pathway, but it is not the CISSP certification or a licence to use the CISSP designation.

For many early- and mid-career candidates, this can be a sound route if the exam study itself supports the next role. For others, waiting may be smarter if an entry-level credential, hands-on project work or a specialist certification better fits the next 12 months. The decision should be based on your role trajectory, not the pressure to collect an acronym.

Read ISC2’s current Associate of ISC2 information for the latest designation, maintenance and progression requirements.

A better pre-exam checklist

How should you check CISSP eligibility before booking the exam?

The safest way to plan CISSP is to build an evidence map first. It will not replace ISC2’s endorsement review, but it exposes gaps early and gives you a more credible study and career plan. Treat it as a professional self-audit rather than a self-certification exercise.

  1. Download the current outline. Work from ISC2’s live eight-domain document, not an old training slide.
  2. List roles chronologically. Record employer, dates, working pattern, supervisor and the systems or programmes you supported.
  3. Map responsibilities to domains. Use plain examples: access reviews, threat modelling, incident handling, control testing, security design, risk reporting or secure-development controls.
  4. Apply one waiver only if it clearly qualifies. Keep degree or credential evidence alongside your experience record.
  5. Choose your honest route. If you are short of the standard, plan for Associate of ISC2 rather than presenting exam preparation as full certification.
Frequently asked questions

Common CISSP eligibility questions

Do I need five years in every CISSP domain?

No. ISC2 requires five years of cumulative, paid work experience across two or more of the eight current CISSP domains. The requirement is not five years in each domain. Your endorsement should still explain what work you performed and how it relates to the relevant domains.

Can I take the CISSP exam with no work experience?

Yes. You may sit the exam without the full experience requirement. If you pass, the Associate of ISC2 route gives you up to six years to gain the experience required for CISSP certification. Until then, do not use the CISSP designation.

Does Security+ waive one year of CISSP experience?

ISC2 publishes an approved credential list that may satisfy one year of experience. The list has included CompTIA Security+ but can change. Confirm that your credential and version are on the current official list before counting a waiver in your plan.

Can unpaid internship work count for CISSP?

ISC2 states that paid or unpaid internships can count if you provide appropriate documentation. Keep evidence on organisation letterhead confirming your position. If the internship was through a school, ISC2 notes that registrar documentation may be used.

Who verifies CISSP experience?

ISC2’s endorsement process verifies whether a candidate’s experience meets the certification requirements. A training provider can help you understand the route, but cannot approve your eligibility or award CISSP certification.

Prepare with the right expectation

Looking for CISSP preparation after your eligibility check?

Once you understand which route applies, choose preparation support that helps you master the current outline and exam judgement. Training is separate from ISC2 examination, experience and endorsement decisions.

Global live-online route

Explore global CISSP preparation for structured study support and exam-planning discussions across locations.

Dubai and UAE route

Explore CISSP training in Dubai for classroom, hybrid, live-online and corporate discussions.

Primary sources

Official sources used for this guide

Certification policies can change. Check these ISC2 sources again before you register, pay, submit an endorsement or describe your status to an employer.

About the author

Kashif Akhtar is a Qualified Engineer and professional certification trainer with credentials including CISA, CISM, CRISC, CDPSE, PMP and CSCP. His CISSP planning approach begins with the official requirements, realistic role evidence and a study plan that matches the candidate’s next professional step.

Share this article:

Leave a Reply

Your email address will not be published. Required fields are marked *