Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CISSP Eligibility

Updated 11 min read
Key takeaway

You may sit for CISSP before meeting the experience requirement.

  • To earn the credential, ISC2 requires five cumulative years of qualifying work across at least two domains.
  • A qualifying degree or approved credential can waive up to one year.
  • Passers who still need experience may apply for Associate of ISC2 status and have up to six years to qualify.
On this page10 sections
  1. The exam and the credential have different entry requirements
  2. The five-year, two-domain requirement
  3. What makes work relevant to a domain
  4. The one-year experience waiver
  5. Associate of ISC2 after passing
  6. Endorsement, application, and evidence
  7. Worked eligibility cases
  8. Plan experience alongside exam preparation
  9. What an endorser and reviewer need to see
  10. A short eligibility decision checklist

The exam and the credential have different entry requirements

ISC2 separates permission to take the CISSP examination from eligibility to receive the certification. You can register and sit for the exam before accumulating the required work history. Passing demonstrates that you met the exam standard; it does not by itself award the CISSP designation.

To earn CISSP, an applicant must document the required experience, submit the certification application, and complete the endorsement process. ISC2 requires the candidate to agree to its Code of Ethics and pay the applicable first annual maintenance fee after approval. If you pass while still short on experience, the Associate of ISC2 route gives you a way to record the exam pass while you continue qualifying work.

The five-year, two-domain requirement

The standard experience requirement is five years of cumulative, full-time professional experience in at least two of the eight domains in the current CISSP outline: Security and Risk Management; Asset Security; Security Architecture and Engineering; Communication and Network Security; Identity and Access Management; Security Assessment and Testing; Security Operations; and Software Development Security.

Cumulative means qualifying periods can add together; you do not need five uninterrupted years with one employer. But calendar time alone is not enough. ISC2 evaluates the work you actually performed and how it relates to domain tasks. A job title such as security analyst, auditor, engineer, or manager does not automatically prove that each month qualifies. Describe responsibilities, time periods, and the domains supported by the work.

ISC2 defines full-time experience as at least 35 hours a week for four consecutive weeks, counted as one month. Part-time work between 20 and 34 hours per week may count when converted to the equivalent full-time hours: 1,040 hours equals six months, and 2,080 hours equals twelve months. Work below 20 hours per week does not meet the described part-time threshold. Keep timesheets or other records if the work schedule is irregular.

Internships may count when properly documented, including unpaid internships. The evidence should establish the organization, dates, hours, duties, and relationship to one or more CISSP domains. ISC2's current experience guidance explains acceptable documentation. Do not assume that a course, personal project, volunteer activity, or general technology job substitutes for qualifying professional experience unless ISC2's published criteria support that specific work.

What makes work relevant to a domain

Consider a systems administrator whose regular duties include account provisioning, access reviews, and termination workflows. That work can support Identity and Access Management if the applicant can explain the responsibilities and their scope. The same person may also perform incident response or vulnerability management, potentially supporting Security Operations or Security Assessment and Testing. Report the work actually done rather than stretching a task across several domains.

For an auditor, evidence collection, control testing, and reporting may map to Security Assessment and Testing. Drafting an enterprise risk policy or coordinating risk acceptance may map to Security and Risk Management. Merely attending an audit meeting would not establish the same experience as planning tests or evaluating evidence. A reviewer needs to understand the candidate's contribution, not just the project name.

A software developer may have relevant Software Development Security experience when designing security requirements, performing threat modeling, reviewing code for security defects, or integrating security testing into release controls. Writing application features without security responsibilities does not automatically qualify. A network engineer may support Communication and Network Security through secure network design and segmentation; ordinary connectivity work alone may not be enough.

These examples are guides for describing duties, not automatic preapprovals. ISC2 states that it does not preapprove experience before the exam. The candidate remains responsible for submitting accurate information, and the endorser or ISC2 review determines whether the evidence meets the current standard.

The one-year experience waiver

You can reduce the five-year requirement by at most one year through one qualifying pathway. A postsecondary bachelor's or master's degree in computer science, information technology, or a related field may satisfy up to one year. Alternatively, a credential on ISC2's approved experience waiver list may satisfy up to one year. You cannot combine a degree and a credential to waive two years.

The approved credential list is maintained by ISC2 and can change. In 2026 ISC2 updated the list, so an older blog, course handout, or colleague's experience may not reflect the active eligibility rules. Confirm that the specific credential and its status meet the current list before relying on it. Keep the certificate record or transcript available for the application.

A four-year degree does not erase the work requirement. Even with the maximum waiver, you need at least four years of qualifying experience in two or more CISSP domains. A degree in an unrelated field may not qualify under the stated degree pathway; if uncertain, do not count it until you confirm that it fits ISC2's current description.

Candidate situationPossible experience creditWhat remains
Five full years across two domainsFive years, if ISC2 accepts the documented workSubmit endorsement and certification application
Four years across two domains plus qualifying degree or approved credentialUp to four years of work plus one-year waiverConfirm waiver evidence and complete application
Three years plus degree and two approved credentialsAt most one waiver yearAt least one more qualifying work year is still needed
Passed exam, experience still shortNo certification yet; Associate route may applyApply within nine months and complete experience within six years

Associate of ISC2 after passing

If you pass the CISSP exam without the full experience requirement, apply for Associate of ISC2 status within nine months of the pass notification. CISSP associates have up to six years to earn the required experience and then submit the certification application. The associate designation is not the CISSP credential, so do not place CISSP after your name or describe yourself as certified while you hold associate status.

Associate status has its own maintenance requirements. ISC2 lists a US$50 annual maintenance fee and requires Associates of ISC2 to earn 15 CPE credits annually. Once an associate obtains the needed experience, the application to advance to certification must be submitted before the end of the six-year period. ISC2 then reviews the evidence and gives the approved applicant the next steps, including the applicable upgrade payment.

Passing is not a prerequisite for starting to build qualifying experience. Many candidates work in relevant roles for years before the exam. The associate route is useful when the exam pass comes first, but it is optional as a study strategy and does not make an unqualified work history count.

Endorsement, application, and evidence

After passing, the certification application asks for experience information. An ISC2 certified professional in good standing may endorse the applicant and attest that the experience claims are accurate to the best of their knowledge. If you do not know an eligible endorser, ISC2 can perform the endorsement review. ISC2 may require proof of employment, such as employer documentation.

Prepare your records before you submit. For each relevant role, note the employer, start and end dates, average weekly hours, title, actual security duties, and the CISSP domains those duties support. For part-time work, maintain hour totals that support the full-time equivalent calculation. For internships, retain letters or official records that show dates, hours, and responsibilities. For a waiver, retain the degree or approved credential evidence.

Do not inflate the same month of work into multiple years by listing overlapping jobs. Concurrent roles may add hours toward the full-time equivalent only within the rules ISC2 publishes; they do not make one calendar month become several months of elapsed experience. Be exact about dates and avoid counting study, exam preparation, or a credential itself as professional work experience.

Candidates who pass must complete the application within nine months. If the application is selected for audit, respond with the supporting evidence ISC2 requests. Keep copies of what you submitted and the endorser's contact details. The endorser is accountable for validating the claim, so make it easy for them to review your work history rather than asking them to approve a vague description.

Worked eligibility cases

Four years of work and a qualifying degree

Maya has four years of full-time paid security work. For two of those years she worked in security operations, and for two she conducted access reviews and identity lifecycle work. She also has a qualifying bachelor's degree in information technology. If the work and degree meet ISC2's evidence requirements, the degree may provide the one-year waiver, giving Maya the required total. She still needs to pass, submit her application, and obtain endorsement; the degree does not certify her by itself.

A degree plus several listed credentials

Noah has three years of qualifying work across network security and risk management, a related bachelor's degree, and two credentials appearing on ISC2's waiver list. The maximum waiver remains one year. Noah therefore has only four years of credited experience and still needs another qualifying year before earning CISSP. Multiple certificates do not create multiple waiver years.

Part-time work plus a documented internship

Sam has 18 months working 25 hours weekly in a security operations role and a documented unpaid internship involving access control testing. The 18 months of part-time work cannot automatically be counted as 18 full-time months. Sam must convert documented hours under ISC2's calculation and establish that the internship duties, period, and supervision meet the current requirements. If the combined evidence is short, Sam can still take the exam, then consider Associate status after passing.

A passing result before enough experience

Avery passes the exam with three years of qualifying experience and no waiver. Avery is not yet eligible to use the CISSP designation. Avery should apply for Associate of ISC2 status within nine months, maintain the associate status, and continue accumulating qualifying work. Once five years are complete across at least two domains, Avery submits the certification application before the six-year associate period ends.

Plan experience alongside exam preparation

Candidates who are near the five-year threshold should audit their experience record while studying. Map duties to the current outline and identify months that need stronger documentation. Ask a potential endorser whether they can verify the work, but remember that ISC2 makes the certification decision. If a waiver is essential to your timeline, confirm that exact route early instead of discovering an evidence gap after passing.

Candidates who are early in their careers can still prepare for and take the exam. Decide whether earning Associate status now supports your goals, and understand the six-year experience deadline before paying for an attempt. For some candidates, waiting until the experience record is mature makes the post-pass application simpler. For others, passing first gives them a defined credential pathway while they continue in relevant work.

What an endorser and reviewer need to see

An endorser is confirming that the experience you report is accurate to the best of their knowledge and that you are in good standing in the cybersecurity profession. Make that review concrete. Provide a concise chronology with dates, employers, weekly hours, responsibilities, and the domains each responsibility supports. A phrase such as “worked in cybersecurity” is much harder to validate than a description of the control work you owned.

If you ask ISC2 to endorse your application, it may require proof of employment. Keep formal records such as employer letters, job descriptions, supervisor confirmation, or internship documentation. The particular evidence requested depends on the review. ISC2 may audit applications, so preserve what you submit and be prepared to explain the work without changing dates or exaggerating the level of responsibility.

Do not submit another person's work as your own or divide a team's outcome into individual duties you did not perform. A security program may involve several domains, but your claim should explain your actual contribution. Accurate descriptions make it easier for an endorser to determine whether the experience fits and reduce the chance that an application is delayed for clarification.

A short eligibility decision checklist

First, decide whether your question is about sitting for the exam or receiving the CISSP credential. If you only want to test, ISC2 lets you register without proving the experience first. If you want to apply for the credential after passing, count relevant work by months and domain, then subtract no more than one year for one qualifying waiver.

Next, check whether your work meets the hours definition and includes at least two domains. Calculate part-time hours using ISC2's full-time equivalent approach; document internships and any changing schedules. Check the waiver list for the exact credential or degree pathway, not a similar title. If there is a gap, plan when and how you will gain the missing experience.

Finally, map the pass date to the nine-month application window. If still short, apply for Associate status in time and mark the six-year deadline. Keep the associate fee, annual CPE, and application evidence in your plan. This separates the exam milestone from the credential milestone and prevents an exam pass from being mistaken for immediate certification.

Common questions

Can I take the CISSP exam with no experience?

Yes. ISC2 does not require the experience before you sit. You need qualifying experience to receive CISSP; an eligible passer may apply for Associate of ISC2 status.

Does a degree waive two years of CISSP experience?

No. A qualifying degree or an approved credential can waive up to one year total. At least four years of qualifying work remain.

Can an unpaid internship count?

ISC2's 2026 guidance says paid and unpaid internships can qualify with proper documentation. The duties, hours, dates, and evidence must meet the current experience rules.

How long do Associates have to qualify for CISSP?

CISSP Associates have up to six years to complete the required experience. Apply for associate status within nine months of passing.

Can ISC2 preapprove my experience before I take the exam?

No. ISC2 says it does not preapprove work experience. Document the duties and evidence carefully and use the current application process.

Is Associate of ISC2 the same as CISSP?

No. It records that you passed the exam while you gain experience. It does not authorize the CISSP designation.