CCSP Certification Requirements After the Exam
You may take the CCSP exam before meeting the experience requirement.
- To earn the credential, ISC2 requires five years of cumulative full-time IT experience, including three in cybersecurity and one in a current CCSP domain.
- A related degree or CCSK can substitute one year total; an active CISSP can replace the full requirement.
- Passing also requires a nine-month endorsed application.
On this page10 sections
- You can sit before you meet the certification experience
- What counts as IT and CCSP-domain experience
- Full-time, part-time and internship rules
- Use one experience substitution, not several
- Apply after passing and meet the nine-month deadline
- What happens if you pass before you qualify
- Prepare evidence for the endorsement review
- Follow the post-exam steps in order
- Work through qualification examples
- Keep an experience record that can be checked
You can sit before you meet the certification experience
CCSP separates permission to take the exam from the experience required to receive the credential. You may register and sit without first satisfying the work-experience requirement. To become a certified CCSP after passing, ISC2 requires five years of cumulative full-time IT experience, including three years in cybersecurity and one year in one or more of the six current CCSP domains. A permitted substitution can reduce that total.
The experience is not five IT years plus three extra cybersecurity years plus another domain year. The cybersecurity and CCSP-domain work forms part of the broader IT experience record, and at least one year must fit a current CCSP domain. The experience rule is about work actually performed, not just a job title or a candidate’s interest in cloud security.
| Path | Experience needed for certification | Important limit |
|---|---|---|
| Standard path | 5 years cumulative full-time IT; 3 in cybersecurity; 1 in a current CCSP domain | Three years and one year are within the overall IT experience record |
| Related bachelor’s or master’s degree | May substitute up to 1 year | Only one year total may be waived |
| CSA CCSK certificate | May substitute 1 year in one or more CCSP domains | Cannot combine with the degree to waive two years |
| Active CISSP credential | May substitute the full CCSP experience requirement | The CISSP credential must be active |
| Associate of ISC2 | Pass the CCSP exam and apply for Associate status | Earn the five required experience years within 6 years |
What counts as IT and CCSP-domain experience
ISC2 maps qualifying experience to the six current domains: Cloud Concepts, Architecture and Design; Cloud Data Security; Cloud Platform and Infrastructure Security; Cloud Application Security; Cloud Security Operations; and Legal, Risk and Compliance. Your work may involve one or several domains. A role supporting cloud identity, a secure data platform, incident response, cloud application delivery, audit or contract risk can provide relevant duties, but the actual responsibilities matter.
A title such as “cloud architect” does not automatically establish every requirement. Describe the work: what systems or data you protected, what decisions you made, which risks or controls you handled and the dates you performed those duties. Conversely, a job title that does not contain “cloud security” can still involve relevant responsibilities, such as reviewing a provider’s controls or operating a secure cloud service.
The five-year IT requirement, three-year cybersecurity requirement and one-year CCSP-domain requirement describe overlapping experience categories. A candidate should map months and duties carefully rather than add the categories together. Experience from separate qualifying jobs can be cumulative, but months that overlap in calendar time should not be counted twice as elapsed experience.
Full-time, part-time and internship rules
ISC2 accrues full-time experience monthly. Its published rule requires at least 35 hours per week for four weeks to accrue one month. Part-time experience must be at least 20 hours per week and no more than 34 hours per week. ISC2 equates 1,040 part-time hours to six months of full-time experience and 2,080 hours to twelve months.
| Work arrangement | ISC2 rule | How to document it |
|---|---|---|
| Full-time | At least 35 hours per week for four weeks accrues one month | Record employment dates, weekly schedule and duties |
| Part-time | 20 to 34 hours per week; 1,040 hours equals six months | Keep hours and dates so the total can be verified |
| Internship | Paid or unpaid work may count | Obtain organization letterhead confirming internship; school internships may use registrar stationery |
A part-time candidate should keep an hour record instead of converting a calendar year into a full-time year automatically. For instance, work at 20 hours per week qualifies for consideration under the part-time rule, but it accrues more slowly than full-time work. A candidate should also distinguish a true internship from coursework or a classroom lab. ISC2 says paid and unpaid internships can count when the required documentation is available.
Use one experience substitution, not several
A related post-secondary degree in computer science, IT or a related field may satisfy up to one year of the experience requirement. A CSA Certificate of Cloud Security Knowledge (CCSK) can substitute for one year in one or more CCSP domains. ISC2 permits only one year of experience to be waived, so a candidate with both credentials cannot apply both substitutions to remove two years.
Example: a candidate has four years of qualifying IT work, including cybersecurity and a year in a current CCSP domain, and holds a related bachelor’s degree. The degree may cover the remaining one year, subject to ISC2’s review. A second substitution from CCSK would not remove another year. If the candidate instead holds an active CISSP, that credential can replace the entire CCSP experience requirement.
Check the credential status for the CISSP pathway. An inactive or expired CISSP is not the active credential described in the CCSP experience rule. If you rely on a degree or CCSK substitution, retain evidence that supports it and identify which year you are asking ISC2 to waive.
Apply after passing and meet the nine-month deadline
After the passing result email, complete the online certification application and endorsement process within nine months of the exam date. The application cannot be submitted before ISC2 confirms the pass. You agree to the ISC2 Code of Ethics, document your work history and ask an eligible endorser to attest to your experience. ISC2 does not pre-approve work experience before the exam.
An endorser must be an ISC2-certified professional in good standing who can attest to the experience you report. The endorser does not have to hold CCSP. If you do not know an eligible ISC2 member, ISC2 can provide endorsement assistance; the organization may ask for employment evidence so it can assess the application.
ISC2 randomly selects some applications for audit and may request additional documentation. Keep employment dates, role descriptions, supervisor or human-resources contacts, internship letters and degree or CCSK evidence organized. Do not rely on an endorser to invent missing details or approve a timeline that you cannot support.
What happens if you pass before you qualify
If you pass without enough experience, you may apply for Associate of ISC2 status. Submit that application within the same nine-month period. An Associate is not certified as CCSP and should not present the exam pass as though it were the credential. The Associate pathway provides up to six years to earn the five years of qualifying experience.
When the experience requirement is met, submit a certification application with the required endorsement. The member policy also sets an upgrade fee for an Associate who completes certification, and Associate maintenance has separate annual fees and CPE rules. Treat those obligations as a distinct stage. The CCSP renewal page explains the maintenance requirements for a certified holder.
Prepare evidence for the endorsement review
| Application detail | What to record | Why it helps |
|---|---|---|
| Employment dates | Start and end dates for each role | Shows when experience accrued and helps reconcile gaps |
| Hours and arrangement | Full-time schedule or part-time hours | Supports the correct experience conversion |
| Cybersecurity duties | Specific protection, risk, audit or response work | Shows which months qualify as cybersecurity experience |
| CCSP domain mapping | Relevant domain tasks performed in each role | Connects work to the current outline |
| Substitution evidence | Related degree, CCSK or active CISSP details | Supports the exact waiver path claimed |
| Endorser or audit proof | Endorser contact and employment records | Allows ISC2 to verify statements if requested |
An experience record is stronger when each role has a short, specific description. “Managed cloud security” is hard to verify. “Reviewed access to a managed data platform, set approval requirements for privileged identities and tested retention controls” tells an endorser which work and domains you mean. Use accurate language from the role rather than rewriting ordinary IT duties as security work.
ISC2 may randomly audit some applications and ask for more evidence. Its FAQ lists employment documents such as an employment certificate, HR confirmation, pay records or offer and separation documentation as possible proof, depending on the facts. Keep original records and make sure dates agree across the application, resume and employer documentation. If an endorser cannot attest to a claim, revise it before submission.
Follow the post-exam steps in order
- Wait for ISC2’s official passing email; the test-center result is unofficial.
- Start the online application and record qualifying work experience and any allowed substitution.
- Ask an ISC2-certified professional in good standing to review and endorse the experience, or request ISC2 endorsement assistance if needed.
- Complete the Code of Ethics agreement and answer background questions honestly.
- Submit within nine months of the exam date and respond if ISC2 requests an audit or clarification.
- After approval, pay the first AMF if one is due, then retain the approval email and credential record.
This sequence keeps exam passage, experience review and credential award distinct. A passing email starts the application window; it does not mean an endorser has reviewed your history. Approval and any required first fee complete the award process. If you already hold another ISC2 credential, member policy generally applies one annual maintenance fee across certifications rather than a separate fee for each one.
Work through qualification examples
A candidate with five years in IT, three years in security operations and one year securing a cloud platform may satisfy the standard experience categories, provided the work is documented and accepted. The domain year can be part of the cybersecurity period. The application still needs endorsement and approval; meeting a time calculation does not automatically certify the experience.
A developer with five years in IT and three years building cloud applications may still need to establish that at least one year fits a current CCSP domain and that three years qualify as cybersecurity experience. Do not assume that all software development automatically counts as cybersecurity. Explain the security responsibilities, controls and decisions performed.
A candidate with four years of IT work, a relevant master’s degree and a CCSK cannot claim two waived years. Only one year may be substituted. An active CISSP offers a separate full-substitution route. If neither route is available, the candidate can sit the test, pass and pursue Associate status while gaining experience.
Keep an experience record that can be checked
Before applying, make a simple experience ledger with employer, start and end dates, hours per week, role, security duties, CCSP domain mapping and supporting evidence. Separate general IT duties from cybersecurity work and identify the one-year domain experience. For a substitution, record the relevant degree or CCSK. This makes an endorsement application clearer and helps answer an audit request consistently.
If a job included a mix of cloud engineering and general operations, describe the security work directly. Examples might include setting access rules, reviewing storage classification, managing cloud incident evidence, assessing provider audit scope or testing recovery controls. Avoid broad claims such as “responsible for cloud security” when a specific description would show the experience.
Common questions
Can I take the CCSP exam without five years of experience?
Yes. The experience requirement applies to earning the CCSP credential, not to sitting the exam. If you pass before you qualify, you may apply for Associate of ISC2 status and have six years to earn the required experience.
Can a degree and CCSK waive two years?
No. A related degree may substitute up to one year, and CCSK may substitute one year in a CCSP domain, but ISC2 allows only one year of experience to be waived in total.
Does my endorser have to be a CCSP?
No. The endorser must be an ISC2-certified professional in good standing who can attest to your experience. The person does not have to hold the same credential. ISC2 can also provide endorsement assistance when needed.
How long after passing do I have to apply?
You must complete the certification application and endorsement process within nine months of the exam date. The application cannot be submitted until ISC2 sends the passing result.