Experience rules, education gates, prerequisite exams, endorsements and renewals — what certification requirements actually exist, why providers impose them, and where you fit.
Most newcomers assume "certification requirements" means one thing: whether you are allowed to book the exam. That assumption quietly breaks in both directions. Plenty of demanding-sounding credentials will let anyone register — CompTIA Security+ has no enforced entry rules at all, with Network+ knowledge and two years in a security role merely recommended — while others let you sit and even pass the exam yet still withhold the credential until you clear a separate gate afterwards. The ISC2 CISSP works exactly this way: five years of cumulative paid work experience across its domains stand between an exam pass and the full credential.
So the useful question is rarely "can I book it?" but "what does this certifying body enforce, at which stage, and does it apply to me?" There is no universal rulebook — each provider sets its own gates, ranging from nothing whatsoever to years of documented, endorsed professional practice. What follows is a map of that territory: every major requirement type, the reason providers impose each one, and a side-by-side look at how the big programmes compare, so that any eligibility page you open afterwards reads as a familiar pattern rather than fine print. The mechanics of confirming your own eligibility for a specific exam sit in a companion piece — our step-by-step guide to checking certification eligibility requirements covers locating, reading and confirming the rules for any credential you are considering.
The first distinction: requirements versus recommendations
Before anything else, learn to separate two words that providers use very differently.
A requirement is enforced. If you do not meet it, you cannot register, cannot certify, or can have the credential withheld or revoked later. CISSP's five years of experience is a requirement.
A recommendation is advice. CompTIA recommends 12 months of hands-on IT support experience before the A+ exams; AWS suggests a year of hands-on solution-design work before the Solutions Architect – Associate exam. Neither is checked, and neither blocks registration. Recommendations describe the candidate the exam was designed for, which makes them genuinely useful calibration — ignore them entirely and you are usually signing up for a much longer study period — but they are not gates.
Marketing pages sometimes blur this line, and third-party blogs blur it worse. The eligibility or exam-policies page of the certifying body is the only place the distinction is stated authoritatively.
The six types of certification requirement
Almost every rule you will ever meet on an eligibility page falls into one of six categories.
1. Work experience requirements
The most common hard gate at professional and expert level. The certifying body demands a stated number of years of relevant, usually paid, professional experience — sometimes in specific domains, sometimes with rules about how recent it must be and whether education can substitute for part of it.
Why providers do this: experience gates protect what the credential means. A certification that says "this person has practised information security for years and passed a rigorous exam" is a fundamentally different signal from "this person passed an exam", and employers price the two differently. The gate is the point.
How it typically works in practice, using CISSP as the sourced example: ISC2 requires five years of cumulative paid work experience across its eight domains, and candidates who pass the exam without the experience can become an Associate of ISC2 while they accumulate it — a common pattern across experience-gated credentials, where an "associate" or provisional status lets you bank the exam pass early. ISACA's CISA similarly ties certification to experience demonstrated at the application stage: you can pass the exam first and then have five years to apply for the certification itself, with your experience evidenced when you apply. Exact experience rules, domain-substitution allowances and waivers vary by provider — always confirm them on the official requirements page rather than a summary.
Some credentials require a degree or formal education level, or — far more often — use education as a substitute or modifier for experience: a relevant degree shaving a year or two off an experience requirement, or different eligibility tracks for degree-holders and non-degree-holders. Outside regulated professions, outright degree mandates are the minority, and the certification world is notably more open on this front than many newcomers fear — nearly all major IT certifications, from CompTIA's lineup to AWS and Microsoft fundamentals, have no education requirement whatsoever.
Why providers do this: where degree requirements exist, they usually anchor a credential aimed at professions where formal education is the norm, or feed substitution rules that keep an experience gate flexible without weakening it. Our guides to certifications that require a degree and certifications that don't name names on both sides.
3. Prerequisite certifications
Multi-level certification tracks often require the lower rung before the higher one: an associate-level credential before the professional level, a foundation exam before the practitioner exam. Vendors with tiered ladders (networking and cloud providers especially) use this pattern, though not universally — some let you jump straight to a higher tier if you can pass it.
Why providers do this: tiered prerequisites guarantee a knowledge floor, simplify exam design (the professional exam need not re-test fundamentals), and — less nobly — encourage candidates through a longer, revenue-generating track. When you meet a prerequisite-certification rule, check whether it is truly mandatory or whether the provider merely recommends the lower tier; both patterns exist, and the difference changes your plan and budget considerably.
4. Training requirements
Some programmes require documented training hours or completion of an approved course before you may apply or register — contact-hour rules, mandated official courseware, or accredited-training-partner requirements. This pack of requirements is provider-specific enough that you should treat any specific hour count you read on a blog with suspicion and confirm it on the certifying body's page. (Project management credentials are the famous example of contact-hour rules; confirm the current figures with the Project Management Institute directly, as they change with exam updates.)
Why providers do this: training gates standardise preparation quality and, where official courseware is mandated, fund the programme. From a candidate's perspective, they mostly convert into cost and calendar time — budget for both when a training requirement appears.
5. Endorsements, applications and codes of ethics
Experience-gated credentials rarely take your word for anything. Expect some combination of: a formal application distinct from exam registration; an endorsement, where an existing credential-holder or your employer attests to your experience; agreement to a code of ethics or professional conduct, breach of which can cost you the credential; and the possibility of an audit, where the certifying body asks for evidence — employment records, references — behind your claims. ISACA, for example, charges a US$50 application processing fee for CISA certification on top of the exam fee, which tells you the application is a genuine review step, not a formality.
Why providers do this: verification and ethics commitments are what let employers trust the credential without re-checking your history themselves. The practical implication for you: keep records. Job titles, dates, responsibilities and reachable referees make applications and audits painless; reconstructing them years later does not. The how-to of surviving an eligibility audit belongs to our eligibility-checking guide.
6. Administrative and logistical requirements
The unglamorous layer that trips up more candidates than any experience rule:
Eligibility windows. ISACA gives you a six-month window from exam registration in which to sit CISA. Miss it and you are re-registering.
Identity requirements. Online proctored exams enforce these strictly — CompTIA requires ID presented via webcam that exactly matches your registration name, with photocopies rejected, plus a room scan and a cleared work surface. Book under a nickname and you may be turned away on exam day.
Age and consent rules. CompTIA requires guardian authorisation for candidates under 17, and other providers have their own minimum-age policies.
Retake waiting periods. Providers limit how quickly you can rebook after a fail — Microsoft, for instance, imposes a 24-hour wait after a first failed attempt, with longer waits for subsequent retakes.
Post-pass deadlines. Passing the exam sometimes starts a clock: CISA candidates have five years after passing to complete the certification application.
None of these appears in a "requirements" headline, but each is enforced, and each can cost you money or a booked exam slot.
How the major providers compare
The table below shows how differently real programmes combine these requirement types, using only officially sourced rules (current as of August 2026 — always confirm on the provider's page before registering).
Certification (provider)
Experience required
Education required
Prerequisite cert
Other enforced gates
AWS Certified Cloud Practitioner (AWS)
None (suits up to ~6 months' exposure, non-IT backgrounds included)
Read the pattern, not just the rows: foundational and associate-level exams are almost universally open-entry, while the credentials that certify professional standing — audit, security leadership — are exactly the ones that gate on verified experience. Requirements scale with what the credential claims about you.
If open doors are what you want, a whole category of respected exams has no formal entry requirements of any kind; our guide to certifications with no prerequisites maps that territory.
Requirements after the exam: renewal is a requirement too
Newcomers read "requirements" as "what I must do before the exam", and then discover the ongoing kind. Most serious certifications now impose maintenance requirements:
AWS certifications are valid for three years; you recertify by retaking the current exam version or passing a higher-level AWS exam (with a 50% discount voucher earned by any pass softening the cost).
CompTIA runs a Continuing Education (CE) programme, including a single-course renewal option, so credentials stay current without re-sitting the exam.
ISACA requires ongoing Continuing Professional Education (CPE) hours under its published policy.
Fundamentals-level certifications are the usual exception to expiry — but confirm the current policy for any specific credential on its official page rather than assuming. When you compare two certifications' requirements, compare their renewal burdens too: a cheap exam with heavy annual maintenance can cost more over five years than an expensive exam with light renewal.
Why providers gate at all — and why you should be glad they do
It is worth stating plainly, because frustrated candidates often read requirements as revenue extraction or gatekeeping for its own sake. Requirements serve three real functions:
They define the signal. An employer seeing "CISSP" on a CV knows it encodes verified multi-year experience plus an exam pass. Remove the experience gate and the same three letters would mean less — for every holder, including you.
They calibrate the exam. A programme that knows its candidates have a guaranteed floor of knowledge or practice can test deeper. Open-entry exams must spend questions establishing fundamentals.
They protect candidates from mispriced bets. Recommendations especially: AWS telling you its associate architect exam suits people with a year of hands-on experience is free, honest calibration of your study timeline.
There is also a legitimacy angle: published, enforced requirements are one of the marks separating genuine certification programmes from certificate mills, which gate nothing because every barrier costs them a sale — a signal we unpack in our guide to verifying whether a certification is legitimate.
A worked scenario: reading requirements before committing
Consider a helpdesk analyst with two years' experience who wants to move towards security and has shortlisted Security+ and, as a long-term target, CISSP. Reading the requirements properly changes her plan. Security+: no enforced gates, and she actually matches CompTIA's recommended profile (two years in a relevant role), so she can book as soon as her practice results say she is ready. CISSP: the five-year experience gate means the sensible question is not "can I pass?" but "when will my evidenced, cumulative experience qualify?" — and whether passing early for Associate status suits her. She also logs the unglamorous layer: her exam registrations must match her legal ID exactly, and her long-term budget should include renewal (CE for CompTIA, CPE commitments later). Fifteen minutes with two eligibility pages just converted a vague ambition into a sequenced, costed plan.
Once your own shortlist is set, the same discipline applies at the study stage: check the exam's official objectives, then benchmark yourself honestly — working through free sample questions for your target exam is a quick way to test whether the provider's recommended-experience profile describes you or not, before you spend anything on registration.
Where to go from here
You now have the full taxonomy: requirements versus recommendations; the six gate types (experience, education, prerequisite certifications, training, endorsements and ethics, administrative rules); renewal as the requirement that outlives the exam; and the logic behind all of it. The next step depends on your situation. If you have a specific credential in mind, verify its rules at the source using our eligibility-checking walkthrough. If your constraint is a thin CV or no degree, start from the sibling guides that map open-entry credentials. And if you are still choosing a direction entirely, requirements are only one column in that decision — demand, cost and renewal belong beside them.
Frequently asked questions
Do certification requirements apply to booking the exam or to holding the credential?
Both patterns exist, and the difference matters. Some programmes block registration until you qualify; others (CISA, CISSP) let you sit the exam first and enforce requirements at the certification application, with associate or provisional status available in the gap. The provider's eligibility page states which model applies.
Can requirements change after I start preparing?
Yes — exam versions, content outlines and policies are refreshed on multi-year cycles, and eligibility rules can move with them. Recheck the official requirements page when you register, not just when you first shortlist the credential.
Is unverified experience ever checked later?
Experience-gated programmes typically reserve the right to audit applications and to revoke credentials granted on false claims, and ethics codes make misrepresentation a violation in itself. Claim only what you can evidence.
Do any certifications require membership of the certifying body?
Membership is more often a discount than a gate — ISACA, for example, prices the CISA exam at US$575 for members versus US$760 for non-members rather than requiring membership. Check each body's pricing and policy pages for how membership interacts with eligibility and renewal fees.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
A five-step decision process for choosing a professional certification: goals, market demand, true cost, prerequisites and renewal — with a comparison worksheet.
The strongest professional certifications for 2026, ranked on demand, recognition and cost of ownership — with the year's retirements and AI-driven changes factored in.