Exampractice
Careers & Salaries

Certifications That Do Not Require Work Experience

How certification experience prerequisites actually work, which major exams are open-entry versus experience-gated, and how providers check eligibility.

Elena Rossi · 9 min read
Illustration of an open doorway to an exam desk beside a gated turnstile with an eligibility checklist

Here is a fact that surprises most people researching their first credential: not a single AWS certification — including the Professional-level exams that experienced architects sweat over — has a formal experience requirement. Neither do CompTIA's exams, from entry-level Tech+ all the way up to SecurityX. The lines you see about "recommended: two years in a security role" are guidance, not gates. Meanwhile, a credential like ISC2's CISSP genuinely will not be awarded without five years of documented, paid, relevant work — no matter how well you score.

Short answer: most major IT certifications have no enforced experience requirement at all. The industry runs on two distinct models — recommendations (advisory, unenforced, common to CompTIA, AWS and Microsoft's fundamentals and associate tiers) and requirements (enforced at application or endorsement, typical of governance and senior security bodies like ISC2 and ISACA). Understanding which model applies to your target certification tells you instantly whether a blank CV is a real obstacle or just a study-planning consideration.

This article is an eligibility explainer: how the two models work, which major certifications sit on each side of the line, and how providers actually verify experience when they do. If what you want is a ranked shortlist of the strongest certifications to take with an empty CV, that lives in our guide to the best IT certifications without experience.

Certification bodies describe candidate experience in two very different ways, and providers are usually careful with their wording even when blog posts summarising them are not.

Recommended experience is a description of the typical successful candidate. CompTIA recommends 12 months in an IT support role before A+, and Network+ plus two years in security or systems administration before Security+. AWS suggests around six months of cloud exposure before Cloud Practitioner and a year of hands-on design work before Solutions Architect – Associate. None of this is checked. You register, you pay, you sit the exam. If you pass, you are certified — full stop.

Required experience is a condition of certification, separate from the exam. ISC2 states that CISSP requires five years of cumulative, paid work experience across its domains. ISACA's CISA requires candidates to demonstrate relevant information-systems audit experience at the application stage. With these bodies, passing the exam is necessary but not sufficient: the credential is only issued once the experience condition is met and documented.

There is a third mechanism worth knowing that involves no work experience at all: certification prerequisites. Microsoft's Azure Solutions Architect Expert requires you to hold the Azure Administrator Associate certification (AZ-104) before the Expert credential is granted — passing the AZ-305 exam alone does not award it. That is a gate, but one you clear with another exam rather than with years on a payroll. The full taxonomy of requirement types — experience, education, endorsements, prior certifications — is mapped in our overview of certification requirements explained.

Why do providers bother publishing recommendations they never enforce?

Because the recommendations are calibration, not bureaucracy. An exam like CompTIA CySA+ assumes the pattern-recognition of roughly four years in a security-analyst seat; CompTIA will happily sell a voucher to anyone, but the recommendation warns you what the questions will assume you have seen. Reading recommended-experience lines as "difficulty ratings you are allowed to ignore" is the healthiest interpretation: ignore the gate, respect the warning.

The open-entry list: major certifications with no experience requirement

Every certification below can be registered for and sat by a candidate with zero days of industry employment. Recommendations are shown so you can judge the study gap honestly.

CertificationProviderEnforced experienceProvider's recommendation
Tech+ (FC0-U71)CompTIANoneNone — designed as pre-career
A+ (220-1201/220-1202)CompTIANone12 months in IT support
Network+ (N10-009)CompTIANoneA+ plus 9–12 months in network support
Security+ (SY0-701)CompTIANoneNetwork+ plus 2 years in security/sysadmin work
AWS Certified Cloud Practitioner (CLF-C02)AWSNone~6 months of general AWS exposure
AWS Solutions Architect – Associate (SAA-C03)AWSNone1+ year hands-on AWS design
AWS Solutions Architect – Professional (SAP-C02)AWSNone2+ years designing on AWS
Azure Fundamentals (AZ-900)MicrosoftNoneNone — beginner level
Azure Administrator Associate (AZ-104)MicrosoftNoneHands-on Azure/PowerShell/CLI experience
Security, Compliance, and Identity Fundamentals (SC-900)MicrosoftNoneNone — beginner level

A few notes that the table cannot carry:

  • CompTIA's entire catalogue is open-entry. Even SecurityX (formerly CASP+), where CompTIA recommends ten years of general IT experience including five in security, enforces nothing. The recommendation ladder — Tech+ → A+ → Network+ → Security+ and beyond — is a suggested order, not a rule; you may sit Security+ first if you wish.
  • AWS enforces no prerequisites at any tier, Foundational through Professional and Specialty. Experience levels on AWS exam pages are recommendations only, and all AWS certifications are valid for three years once earned.
  • Microsoft's fundamentals and associate certifications have no formal prerequisites. The only hard gates in the Microsoft catalogue as of August 2026 are the two Expert credentials: AZ-305 requires holding AZ-104, and AZ-400 requires AZ-104 (its alternative route, the now-retired Azure Developer Associate, is no longer earnable by new candidates).
  • Cisco's CCNA (exam 200-301) is Cisco's associate-level networking certification with a single exam; check Cisco's official CCNA page for its current entry conditions and exam details before registering.

Some of these are not merely experience-free but free of every formal gate — no degree, no endorsement, no prior cert. That stricter category has its own dedicated breakdown in certifications with no formal prerequisites.

The gated side: where experience is genuinely enforced

For contrast — and to stop you wasting an application fee — the best-known experience-gated credentials work like this:

  • ISC2 CISSP: five years of cumulative paid work experience across its eight domains. Candidates who pass the exam without the experience can become an Associate of ISC2, holding their exam pass while they accumulate the required years — check ISC2's site for the current mechanics of that route.
  • ISACA CISA: registration for the exam is open, but certification is applied for after passing, with relevant experience demonstrated at the application stage and up to five years allowed after the exam to submit that application. ISACA also charges a US$50 application processing fee on top of exam fees (US$575 members / US$760 non-members as of August 2026).
  • PMI's Project Management Professional is the most famous experience-and-education-gated credential outside IT; its specific hour and experience thresholds should be confirmed directly on pmi.org, as PMI is precise about them and audits applications.

The full roster of experience-gated certifications, their exact rules and the workaround routes is a sibling topic in its own right: see certifications that require work experience.

How providers actually verify — and what happens if you overstate

Verification intensity follows the requirement model exactly.

Open-entry providers verify identity, not history. When you sit a CompTIA exam online, Pearson VUE's OnVUE process requires ID presented via webcam that exactly matches your registration name, a room scan, and monitoring by human proctors and assistive AI throughout. Nobody asks where you have worked, because nothing about your employment affects eligibility.

Gated providers verify at application or endorsement. ISACA has CISA candidates document their experience when applying for certification after the exam. ISC2's process similarly separates "passed the exam" from "meets the requirement." The practical consequences: keep dates, employer names and role descriptions accurate and consistent, because these bodies review what you submit, and misrepresenting experience to a certification body is a straightforward ethics violation that can cost you the credential. The mechanics of locating and reading each provider's current eligibility rules — official pages, application forms, audit processes — are walked through step by step in how to check certification eligibility requirements.

A realistic scenario: a career changer finishing a coding bootcamp wants a security credential. She can register for Security+ today — no gate. She could even register for the CISA exam — ISACA gives a six-month eligibility window from registration — but she could not become certified afterwards without audit experience to document. Knowing that before paying US$575 is the entire value of understanding the two models.

Reading an eligibility page without getting misled

Provider pages reward careful reading. Five phrases and what they actually mean:

  1. "Recommended experience" — advisory. You can register regardless (CompTIA, AWS, Microsoft associate tier).
  2. "Prerequisite: [certification name]" — enforced, but satisfied by an exam, not employment (Microsoft AZ-305/AZ-400).
  3. "X years of cumulative paid work experience" — enforced at certification, documented and reviewable (ISC2).
  4. "Experience demonstrated at application" — the exam is open; the credential is gated afterwards (ISACA).
  5. "Intended audience" or "designed for" — pure audience description with no enforcement of any kind (Microsoft fundamentals pages).

If a training vendor's page says "requirements" without distinguishing these, go to the certification body's own page — it is the only authoritative source, and requirements do change. Microsoft alone retired roughly a dozen role-based certifications between mid-2025 and September 2026, which reshuffled prerequisite routes (AZ-400 being the clearest example).

Does skipping the experience actually work? An honest calibration

Eligibility and readiness are different questions, and conflating them is the classic first-timer mistake. Three honest observations:

  • Exams assume the experience even when they do not require it. Security+ performance-based questions simulate tasks a working administrator recognises. Without the recommended background you are not barred — you simply have more to build from scratch, ideally through a home lab or free-tier cloud account that substitutes deliberate practice for payroll time.
  • Scores are scaled, not percentages, so you cannot reason "I only need 75%." CompTIA passes range from 650 to 750 on a 100–900 scale depending on the exam; AWS uses 700–750 on a 100–1,000 scale. Scaled scoring equates different exam forms, which is also why practice results and real results can diverge.
  • Benchmark before you book. The cheapest way to discover whether the missing experience matters for you is evidence: work through free sample questions for your target exam, then sit a full-length timed simulation and analyse which domains drag your score down. A candidate who scores consistently across all domains without industry experience has effectively closed the gap; one who collapses on operational scenarios knows exactly what to practise next.

Frequently asked questions

Can I really sit an AWS Professional exam with no cloud job on my CV?

Yes. AWS enforces no prerequisites at any level; the Professional exams (75 questions, 180 minutes, $300 USD) are open to anyone. Whether that is wise is a readiness question — AWS recommends two or more years of hands-on experience for good reason — but nothing stops you registering.

If I pass the CISSP exam without five years' experience, is the exam wasted?

No — ISC2 offers an Associate of ISC2 status for candidates who pass without the full experience requirement, letting you bank the pass while you accumulate the years. Confirm the current terms of that route on ISC2's site.

Do recommendations affect my result in any way?

No. There is no disclosure of your experience at registration for open-entry exams and no scoring adjustment. The recommendation's only function is to describe the assumed knowledge base.

Are experience requirements the same in every country?

The requirement models described here are set globally by each certification body, though exam pricing and delivery options vary by country and region. Always confirm on the provider's official page for your market.

What to take away before you register

Sort any certification you are considering into one of three buckets: open-entry with recommendations (register whenever you are ready — most of CompTIA, AWS and Microsoft), certification-gated (plan an exam sequence — Microsoft's Expert tier), or experience-gated (count your documented years first — ISC2, ISACA, PMI). Only the third bucket can actually refuse you, and even there associate routes usually let you bank an exam pass early. For most beginners the honest constraint was never eligibility — it is preparation, and that one is entirely within your control.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like