Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CCSP Certification Requirements After the Exam

Updated 10 min read
Key takeaway

You may take the CCSP exam before meeting the experience requirement.

  • To earn the credential, ISC2 requires five years of cumulative full-time IT experience, including three in cybersecurity and one in a current CCSP domain.
  • A related degree or CCSK can substitute one year total; an active CISSP can replace the full requirement.
  • Passing also requires a nine-month endorsed application.
On this page10 sections
  1. You can sit before you meet the certification experience
  2. What counts as IT and CCSP-domain experience
  3. Full-time, part-time and internship rules
  4. Use one experience substitution, not several
  5. Apply after passing and meet the nine-month deadline
  6. What happens if you pass before you qualify
  7. Prepare evidence for the endorsement review
  8. Follow the post-exam steps in order
  9. Work through qualification examples
  10. Keep an experience record that can be checked

You can sit before you meet the certification experience

CCSP separates permission to take the exam from the experience required to receive the credential. You may register and sit without first satisfying the work-experience requirement. To become a certified CCSP after passing, ISC2 requires five years of cumulative full-time IT experience, including three years in cybersecurity and one year in one or more of the six current CCSP domains. A permitted substitution can reduce that total.

The experience is not five IT years plus three extra cybersecurity years plus another domain year. The cybersecurity and CCSP-domain work forms part of the broader IT experience record, and at least one year must fit a current CCSP domain. The experience rule is about work actually performed, not just a job title or a candidate’s interest in cloud security.

PathExperience needed for certificationImportant limit
Standard path5 years cumulative full-time IT; 3 in cybersecurity; 1 in a current CCSP domainThree years and one year are within the overall IT experience record
Related bachelor’s or master’s degreeMay substitute up to 1 yearOnly one year total may be waived
CSA CCSK certificateMay substitute 1 year in one or more CCSP domainsCannot combine with the degree to waive two years
Active CISSP credentialMay substitute the full CCSP experience requirementThe CISSP credential must be active
Associate of ISC2Pass the CCSP exam and apply for Associate statusEarn the five required experience years within 6 years

What counts as IT and CCSP-domain experience

ISC2 maps qualifying experience to the six current domains: Cloud Concepts, Architecture and Design; Cloud Data Security; Cloud Platform and Infrastructure Security; Cloud Application Security; Cloud Security Operations; and Legal, Risk and Compliance. Your work may involve one or several domains. A role supporting cloud identity, a secure data platform, incident response, cloud application delivery, audit or contract risk can provide relevant duties, but the actual responsibilities matter.

A title such as “cloud architect” does not automatically establish every requirement. Describe the work: what systems or data you protected, what decisions you made, which risks or controls you handled and the dates you performed those duties. Conversely, a job title that does not contain “cloud security” can still involve relevant responsibilities, such as reviewing a provider’s controls or operating a secure cloud service.

The five-year IT requirement, three-year cybersecurity requirement and one-year CCSP-domain requirement describe overlapping experience categories. A candidate should map months and duties carefully rather than add the categories together. Experience from separate qualifying jobs can be cumulative, but months that overlap in calendar time should not be counted twice as elapsed experience.

Full-time, part-time and internship rules

ISC2 accrues full-time experience monthly. Its published rule requires at least 35 hours per week for four weeks to accrue one month. Part-time experience must be at least 20 hours per week and no more than 34 hours per week. ISC2 equates 1,040 part-time hours to six months of full-time experience and 2,080 hours to twelve months.

Work arrangementISC2 ruleHow to document it
Full-timeAt least 35 hours per week for four weeks accrues one monthRecord employment dates, weekly schedule and duties
Part-time20 to 34 hours per week; 1,040 hours equals six monthsKeep hours and dates so the total can be verified
InternshipPaid or unpaid work may countObtain organization letterhead confirming internship; school internships may use registrar stationery

A part-time candidate should keep an hour record instead of converting a calendar year into a full-time year automatically. For instance, work at 20 hours per week qualifies for consideration under the part-time rule, but it accrues more slowly than full-time work. A candidate should also distinguish a true internship from coursework or a classroom lab. ISC2 says paid and unpaid internships can count when the required documentation is available.

Use one experience substitution, not several

A related post-secondary degree in computer science, IT or a related field may satisfy up to one year of the experience requirement. A CSA Certificate of Cloud Security Knowledge (CCSK) can substitute for one year in one or more CCSP domains. ISC2 permits only one year of experience to be waived, so a candidate with both credentials cannot apply both substitutions to remove two years.

Example: a candidate has four years of qualifying IT work, including cybersecurity and a year in a current CCSP domain, and holds a related bachelor’s degree. The degree may cover the remaining one year, subject to ISC2’s review. A second substitution from CCSK would not remove another year. If the candidate instead holds an active CISSP, that credential can replace the entire CCSP experience requirement.

Check the credential status for the CISSP pathway. An inactive or expired CISSP is not the active credential described in the CCSP experience rule. If you rely on a degree or CCSK substitution, retain evidence that supports it and identify which year you are asking ISC2 to waive.

Apply after passing and meet the nine-month deadline

After the passing result email, complete the online certification application and endorsement process within nine months of the exam date. The application cannot be submitted before ISC2 confirms the pass. You agree to the ISC2 Code of Ethics, document your work history and ask an eligible endorser to attest to your experience. ISC2 does not pre-approve work experience before the exam.

An endorser must be an ISC2-certified professional in good standing who can attest to the experience you report. The endorser does not have to hold CCSP. If you do not know an eligible ISC2 member, ISC2 can provide endorsement assistance; the organization may ask for employment evidence so it can assess the application.

ISC2 randomly selects some applications for audit and may request additional documentation. Keep employment dates, role descriptions, supervisor or human-resources contacts, internship letters and degree or CCSK evidence organized. Do not rely on an endorser to invent missing details or approve a timeline that you cannot support.

What happens if you pass before you qualify

If you pass without enough experience, you may apply for Associate of ISC2 status. Submit that application within the same nine-month period. An Associate is not certified as CCSP and should not present the exam pass as though it were the credential. The Associate pathway provides up to six years to earn the five years of qualifying experience.

When the experience requirement is met, submit a certification application with the required endorsement. The member policy also sets an upgrade fee for an Associate who completes certification, and Associate maintenance has separate annual fees and CPE rules. Treat those obligations as a distinct stage. The CCSP renewal page explains the maintenance requirements for a certified holder.

Prepare evidence for the endorsement review

Application detailWhat to recordWhy it helps
Employment datesStart and end dates for each roleShows when experience accrued and helps reconcile gaps
Hours and arrangementFull-time schedule or part-time hoursSupports the correct experience conversion
Cybersecurity dutiesSpecific protection, risk, audit or response workShows which months qualify as cybersecurity experience
CCSP domain mappingRelevant domain tasks performed in each roleConnects work to the current outline
Substitution evidenceRelated degree, CCSK or active CISSP detailsSupports the exact waiver path claimed
Endorser or audit proofEndorser contact and employment recordsAllows ISC2 to verify statements if requested

An experience record is stronger when each role has a short, specific description. “Managed cloud security” is hard to verify. “Reviewed access to a managed data platform, set approval requirements for privileged identities and tested retention controls” tells an endorser which work and domains you mean. Use accurate language from the role rather than rewriting ordinary IT duties as security work.

ISC2 may randomly audit some applications and ask for more evidence. Its FAQ lists employment documents such as an employment certificate, HR confirmation, pay records or offer and separation documentation as possible proof, depending on the facts. Keep original records and make sure dates agree across the application, resume and employer documentation. If an endorser cannot attest to a claim, revise it before submission.

Follow the post-exam steps in order

  1. Wait for ISC2’s official passing email; the test-center result is unofficial.
  2. Start the online application and record qualifying work experience and any allowed substitution.
  3. Ask an ISC2-certified professional in good standing to review and endorse the experience, or request ISC2 endorsement assistance if needed.
  4. Complete the Code of Ethics agreement and answer background questions honestly.
  5. Submit within nine months of the exam date and respond if ISC2 requests an audit or clarification.
  6. After approval, pay the first AMF if one is due, then retain the approval email and credential record.

This sequence keeps exam passage, experience review and credential award distinct. A passing email starts the application window; it does not mean an endorser has reviewed your history. Approval and any required first fee complete the award process. If you already hold another ISC2 credential, member policy generally applies one annual maintenance fee across certifications rather than a separate fee for each one.

Work through qualification examples

A candidate with five years in IT, three years in security operations and one year securing a cloud platform may satisfy the standard experience categories, provided the work is documented and accepted. The domain year can be part of the cybersecurity period. The application still needs endorsement and approval; meeting a time calculation does not automatically certify the experience.

A developer with five years in IT and three years building cloud applications may still need to establish that at least one year fits a current CCSP domain and that three years qualify as cybersecurity experience. Do not assume that all software development automatically counts as cybersecurity. Explain the security responsibilities, controls and decisions performed.

A candidate with four years of IT work, a relevant master’s degree and a CCSK cannot claim two waived years. Only one year may be substituted. An active CISSP offers a separate full-substitution route. If neither route is available, the candidate can sit the test, pass and pursue Associate status while gaining experience.

Keep an experience record that can be checked

Before applying, make a simple experience ledger with employer, start and end dates, hours per week, role, security duties, CCSP domain mapping and supporting evidence. Separate general IT duties from cybersecurity work and identify the one-year domain experience. For a substitution, record the relevant degree or CCSK. This makes an endorsement application clearer and helps answer an audit request consistently.

If a job included a mix of cloud engineering and general operations, describe the security work directly. Examples might include setting access rules, reviewing storage classification, managing cloud incident evidence, assessing provider audit scope or testing recovery controls. Avoid broad claims such as “responsible for cloud security” when a specific description would show the experience.

Common questions

Can I take the CCSP exam without five years of experience?

Yes. The experience requirement applies to earning the CCSP credential, not to sitting the exam. If you pass before you qualify, you may apply for Associate of ISC2 status and have six years to earn the required experience.

Can a degree and CCSK waive two years?

No. A related degree may substitute up to one year, and CCSK may substitute one year in a CCSP domain, but ISC2 allows only one year of experience to be waived in total.

Does my endorser have to be a CCSP?

No. The endorser must be an ISC2-certified professional in good standing who can attest to your experience. The person does not have to hold the same credential. ISC2 can also provide endorsement assistance when needed.

How long after passing do I have to apply?

You must complete the certification application and endorsement process within nine months of the exam date. The application cannot be submitted until ISC2 sends the passing result.