Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CCSP Eligibility and Experience Requirements

Updated 10 min read
Key takeaway

You may sit the CCSP exam before meeting certification experience requirements.

  • To earn the credential, you generally need five years of cumulative IT experience, including three in cybersecurity and one in a current CCSP domain.
  • An eligible degree or CCSK can substitute one year total; an active CISSP can satisfy the full experience requirement.
On this page13 sections
  1. Exam eligibility and certification eligibility are different
  2. The standard five-year experience requirement
  3. Education and CCSK substitution
  4. Part-time work and internships
  5. Experience examples
  6. Associate of ISC2 pathway
  7. Document work so it can be evaluated
  8. Common eligibility errors
  9. Build a month-by-month experience record
  10. How job duties map to domains
  11. Waiver examples and limits
  12. Internship evidence
  13. When the Associate pathway is the better fit

Exam eligibility and certification eligibility are different

ISC2 does not require candidates to finish the CCSP work-experience requirement before sitting for the exam. The experience requirement applies to receiving the CCSP certification. A candidate can pass first and become an Associate of ISC2, then meet the professional experience requirement within six years. This makes it possible to prepare for the exam while still building qualifying cloud-security experience.

Passing is not the same as earning the CCSP title. A candidate who meets the experience requirement submits the application, completes ISC2’s endorsement and Code of Ethics steps, and pays the required AMF. A candidate who does not yet meet experience can use the Associate path but should not represent themself as a certified CCSP until the certification is granted.

The standard five-year experience requirement

The standard pathway requires five years of cumulative full-time work experience in information technology. Within that total, at least three years must be in cybersecurity, and at least one year must fall in one or more of the six domains in the current CCSP outline. The one CCSP-domain year is part of the cybersecurity experience requirement, not an additional year on top of five.

The current domains are Cloud Concepts, Architecture and Design; Cloud Data Security; Cloud Platform and Infrastructure Security; Cloud Application Security; Cloud Security Operations; and Legal, Risk and Compliance. Experience can map to one or multiple domains. Work should involve responsibilities related to cloud security, not merely use of a cloud service as an ordinary end user.

RequirementWhat it means
Five years totalCumulative full-time IT work
Three years cybersecuritySecurity duties must fit within the five-year IT total
One year in a CCSP domainCloud security work in one or more current domains; included within the cybersecurity experience
One-year waiver limitDegree or CSA CCSK may substitute for up to one year, not both years
Full CISSP substitutionAn active CISSP may satisfy the full CCSP experience requirement

Education and CCSK substitution

A post-secondary bachelor’s or master’s degree in computer science, information technology or a related field may satisfy up to one year of the required experience. CSA’s Certificate of Cloud Security Knowledge (CCSK) can substitute for one year of experience in one or more CCSP domains. Only one year can be waived. A candidate cannot stack a degree and CCSK to waive two years.

The waiver reduces one year from the total required experience; the remaining experience must still satisfy the requirements for IT, cybersecurity and a CCSP domain. For example, a qualifying degree may reduce the five-year total to four years, but the candidate still needs the specified cybersecurity and domain experience within the accepted experience record. Document the route accurately in the application.

An active CISSP is a separate full-prerequisite pathway. It may substitute for the entire CCSP experience requirement. This does not mean any expired or inactive CISSP provides the same substitution, nor does it eliminate the CCSP exam, application and maintenance requirements. Candidates should confirm the active status in their ISC2 record.

Part-time work and internships

ISC2 accrues full-time experience monthly. One month requires at least 35 hours a week for four weeks. Part-time work can count when it is between 20 and 34 hours a week. ISC2 equates 1,040 qualifying part-time hours to six months of full-time experience and 2,080 hours to 12 months. Track the dates and hours rather than treating every calendar month as a full-time month.

Paid and unpaid internships may count. ISC2 requires documentation on company or organization letterhead confirming the intern position; a school internship letter may use registrar stationery. Intern duties must still be relevant to the IT, cybersecurity and CCSP-domain criteria. A brief internship in general IT does not automatically satisfy a cloud security domain year.

Work arrangementISC2 rule or conversion
Full timeAt least 35 hours/week for four weeks accrues one month
Part timeBetween 20 and 34 hours/week may count
Part-time conversion1,040 hours equals six months; 2,080 hours equals one year
InternshipPaid or unpaid may count, with confirmation on organizational letterhead

Experience examples

A cloud security engineer with five years of IT work, four years in cybersecurity and two years protecting cloud platforms can meet the standard pathway, assuming duties align and are documented. A cloud support administrator with five years of IT work but only two years in cybersecurity does not yet meet the three-year cybersecurity condition, even if the role uses cloud infrastructure every day.

A privacy analyst with five years in IT, three years in security and a year performing cloud data governance or cloud privacy impact work may have domain-relevant experience. The candidate should describe actual responsibilities, not just job titles. A compliance professional who only reviewed generic vendor questionnaires may need to show how the work connects to CCSP domain tasks such as cloud audit, legal requirements, risk or contracts.

A candidate with a related master’s degree, three years of qualifying IT work and two years in cloud security may be able to use the one-year education waiver toward the five-year total. The degree does not waive the three-year cybersecurity requirement or turn unrelated experience into cloud security work. One waiver only is allowed.

A candidate with an active CISSP may use that credential to substitute for the full CCSP experience prerequisite. The candidate still needs to pass the CCSP exam and finish the CCSP application process. If the CISSP status is suspended, expired or otherwise not active, confirm whether the pathway applies before relying on it.

Associate of ISC2 pathway

If you pass the CCSP exam without the required experience, you can become an Associate of ISC2. The Associate has six years to earn the five years required for CCSP. This is a route to continue building experience after passing, not a temporary CCSP certification. Use the Associate designation accurately and follow its separate maintenance obligations.

A candidate should decide whether taking the exam now makes sense. The Associate route can be useful when the knowledge is ready but the work timeline is not. It also starts a time-limited six-year period. Keep records of qualifying work from the beginning and review the current ISC2 experience requirements as duties evolve.

Document work so it can be evaluated

Prepare a month-by-month employment history showing employer, role, dates, hours and responsibilities. For each role, map actual duties to the current CCSP domains. A cloud data security example might include classification, encryption, key governance, retention or data-loss prevention. An infrastructure example might include cloud network controls, hardening, patching, virtualization or recovery planning.

Avoid relying on titles alone. “Cloud architect” could include relevant security design, but the application needs a clear account of the work performed. “IT analyst” could include cloud compliance, access reviews or incident response. Specific responsibilities and dates let the endorsement process assess relevance more consistently.

Common eligibility errors

  • Assuming the five years must be complete before taking the exam. It is a certification requirement; the Associate path permits passing first.
  • Adding the one CCSP-domain year on top of the five-year total. It is included within the cybersecurity experience requirement.
  • Using both degree and CCSK to waive two years. ISC2 allows only one year to be waived.
  • Counting ordinary cloud-service use as cloud-security experience without security responsibilities.
  • Assuming a CISSP substitution removes the exam or maintenance steps. It waives only the experience prerequisite.
  • Calling an Associate of ISC2 a CCSP. The Associate has passed but is not yet the certified credential holder.

Build a month-by-month experience record

Because experience is cumulative and monthly, create a timeline rather than estimating from rounded years. List each employer, start and end month, average hours per week, IT responsibilities, cybersecurity responsibilities and any cloud-domain tasks. Mark overlapping employment carefully; two simultaneous jobs do not necessarily double the months accrued. Use the application’s current instructions and supporting evidence rather than adding overlapping calendar time twice.

For a part-time role of 24 hours per week, ISC2 permits the hours to count because the range is 20 to 34. The conversion is based on total qualifying hours: 1,040 hours equals six months and 2,080 equals a year. A 15-hour-per-week role falls below the stated minimum, so do not assume it accumulates experience under the published part-time rule.

How job duties map to domains

Work responsibilityPossible CCSP domain connection
Classify cloud records, manage keys, retention and deletionCloud Data Security
Design secure landing zones, network isolation or recoveryCloud Concepts, Architecture and Design; Cloud Platform and Infrastructure Security
Threat model cloud software, secure APIs and pipeline dependenciesCloud Application Security
Operate monitoring, incident response, patching and forensicsCloud Security Operations
Assess privacy, provider contracts, audits or cloud riskLegal, Risk and Compliance

The same job can span several domains. An architect may design encryption and access controls for data, evaluate recovery objectives, and review a provider contract. Describe each actual responsibility and its dates. Avoid forcing duties into a domain based only on terminology; focus on what decisions or controls you personally performed.

Waiver examples and limits

A candidate with a related master’s degree and four years of otherwise qualifying experience may be able to apply the one-year education waiver. The candidate still needs three years in cybersecurity and a qualifying year in a CCSP domain. A candidate with both a related degree and CCSK cannot waive two years because ISC2 caps the waiver at one.

A candidate with an active CISSP can use it to substitute for the entire experience prerequisite. This is not the same as having passed a CISSP exam without the credential or holding an inactive credential. Confirm active status and follow the application’s evidence instructions. The substitution removes the CCSP experience condition, not the CCSP exam or certification maintenance obligations.

Internship evidence

Paid and unpaid internships can count if their work is relevant and documented. ISC2 requires a letter on company or organization letterhead confirming the intern position; a school-based internship may use registrar stationery. Keep dates and duties, and be prepared to explain how the internship involved IT, cybersecurity and a current CCSP domain. An internship title alone does not establish the required content.

For example, an unpaid internship helping a cloud-security team review IAM roles, logging and encryption may support domain-relevant experience if documented. An internship doing unrelated office administration would not qualify merely because the organization operates cloud services. Evidence should explain the candidate’s own work.

When the Associate pathway is the better fit

A candidate may choose to sit before meeting experience if exam preparation is complete and the Associate route fits the career plan. Passing first can demonstrate knowledge while experience accumulates. The six-year clock means candidates should plan the work requirement rather than assume it can be completed whenever convenient. Track qualifying duties from the start and ask an employer for opportunities aligned to the six domains.

If you are close to five years, compare actual month totals and cybersecurity/domain overlap before applying. Do not count a year of generic IT work as a cybersecurity year unless the responsibilities support that classification. If you have a related degree, identify which single year you will waive and ensure remaining conditions are met.

Common questions

Can I take the CCSP exam without five years of experience?

Yes. You can pass and become an Associate of ISC2, then complete the experience requirement within six years.

What experience is required for CCSP?

Five years of IT experience, including three years in cybersecurity and one year in one or more current CCSP domains.

Can a degree waive CCSP experience?

A related bachelor’s or master’s degree may satisfy up to one year. Only one year total may be waived.

Does CISSP waive the CCSP experience requirement?

An active CISSP can substitute for the entire CCSP experience requirement.