A surprising number of candidates discover their experience problem at the wrong moment: after passing the exam. That is because "requires work experience" means two completely different things depending on the provider. Some certifications stop you at the door — you cannot even book the exam without documented years on the job. Others let anyone sit the exam and only demand the experience afterwards, when you apply to actually hold the credential. Knowing which model your target certification uses changes your entire plan, and often means you can start far earlier than you think.
This article lists the major experience-gated certifications, their exact rules as of 2026, and the legitimate workarounds — waivers, associate designations and certify-later windows. If you are looking for the opposite — respected credentials with no experience requirement at all — that list lives in our companion guide to certifications with no work experience requirements.
The two models of experience gating
Model 1 — experience before the exam. PMI is the classic example: your PMP application documents your months of project leadership before you are authorised to test. Fail the paperwork and there is no exam.
Model 2 — experience before certification. ISACA and ISC2 largely work this way: anyone can sit the CISA or CISM exam, and ISC2 lets you take the CISSP and hold "Associate" status. The experience requirement bites when you apply to be certified, and both bodies give you years of runway to accumulate it.
The distinction matters for sequencing. Under Model 2 you can pass the exam while the material is fresh, then let your career catch up. Under Model 1 the experience must exist — and survive scrutiny — first.
ISC2: experience verified at endorsement
ISC2 lets you sit any of its exams first; the experience requirement is enforced through an endorsement application after you pass, backed by random audits.
CISSP — 5 years
The headline requirement everyone asks about: the Certified Information Systems Security Professional needs five years of cumulative, full-time paid work experience in at least two of its eight domains. The useful fine print:
One year (maximum) is waivable with a relevant bachelor's or master's degree, or with an approved credential such as CompTIA Security+, CCSP, CISM, AWS Security Specialty or various GIAC certifications. Only one waiver applies — you cannot stack a degree and a certification for two years.
Part-time work counts: 1,040 hours equates to six months, 2,080 hours to twelve, for roles of 20–34 hours per week.
Internships count, paid or unpaid, when documented.
No experience yet? Pass the exam and become an Associate of ISC2, with six years to earn the five. You pay a reduced $50 annual fee and must log 15 CPEs a year, but you cannot use the CISSP title until certified.
Once eligible, your application must be endorsed within nine months of passing by an ISC2-certified professional in good standing (or by ISC2 itself with employment verification).
CCSP — 5 years, with a powerful shortcut
The Certified Cloud Security Professional requires five years of cumulative full-time IT experience, of which three must be in information security and one in its cloud domains. Two shortcuts exist: the CSA's CCSK or a relevant degree can substitute for one year (one waiver only) — and an active CISSP satisfies the entire CCSP experience requirement. The Associate route applies here too.
SSCP and CSSLP
The Systems Security Certified Practitioner needs just one year of cumulative paid experience across its domains — the gentlest experience gate in the ISC2 stable. The Certified Secure Software Lifecycle Professional requires four years in secure software work. Both offer the Associate pathway.
The CISSP concentrations — ISSAP, ISSEP, ISSMP
These stack experience on experience: each requires a CISSP in good standing plus two years in the concentration's domains — or, via an alternative path many candidates miss, seven years of cumulative relevant experience without a CISSP.
ISACA: sit now, certify within five years
Every core ISACA exam is open to candidates with zero experience. The gate arrives at the certification application, and you have five years from your pass date to get through it. Waiver rules differ sharply by credential:
Certification
Experience required
Waivers available
Notes
CISA
5 years in IS/IT audit, control, assurance or security
Up to 3 years
Experience must fall within the 10 years before application
CISM
5 years in information security management
Up to 2 years
Exam content outline changes 3 November 2026
CRISC
3 years in IT risk management and IS control
None
No substitutions of any kind
CGEIT
5 years in an IT-governance advisory or oversight role
None
CDPSE
3 years in data privacy work
None
Two practical implications. First, CISA is more reachable than its "five years" headline suggests — with the maximum three-year waiver, some candidates qualify with two years of relevant work. Second, CRISC, CGEIT and CDPSE are stricter than they look precisely because nothing substitutes for the years. All ISACA exams cost $575 for members / $760 for non-members, with a $50 application processing fee when you apply for certification.
ISACA's newer AI credentials gate on credentials rather than raw years: AAIA requires an active CISA (or listed audit and accountancy qualifications), and AAISM requires an active CISM or CISSP — experience requirements inherited, in effect, from the prerequisite certification.
PMI: experience audited before you may test
PMP — 36 or 60 months, documented up front
The Project Management Professional uses the strictest common model: experience is part of the application, before exam authorisation. The two classic paths as of 2026:
Four-year degree + 36 months of project leadership experience + 35 contact hours of project management education (a CAPM satisfies the education part), or
High school diploma or associate degree + 60 months of experience + the same 35 contact hours.
You do not need "project manager" in your job title — leading projects in any role counts, but you must document it, and PMI audits a proportion of applications. PMI's 2026 exam-content announcement mentions expanded eligibility pathways; describe your experience honestly and check pmi.org for the current application rules rather than relying on older summaries. Note the exam itself changed on 9 July 2026 and fees rose in August 2026 to a reported $445 member / $675 non-member — confirm at checkout.
Anyone short of the months has a natural fallback: the CAPM, which requires only a secondary degree plus 23 contact hours of education and no experience at all, and which then feeds the PMP's education requirement.
The rest of the PMI ladder
PMI-RMP: 36 months of project risk management experience (within the last five years) plus 40 hours of risk education on the secondary-degree path; a four-year-degree path with lower thresholds exists — verify exact figures on pmi.org.
PMI-SP: hours-based rather than months-based — 3,500 hours of schedule-management experience with a four-year degree, or 5,000 hours with a secondary diploma, plus scheduling education.
PgMP: 48 months of project management experience (or PMP) plus 48 months of programme management experience with a degree (84 months of programme experience on the diploma path), all within the last 15 years — and a panel review of your experience before you may sit the exam.
PfMP: the steepest gate on this page — 96 months of professional business experience within the last 15 years plus 48 months of portfolio management experience with a degree (84 without), again with a panel review.
PMI-CP: 36 months of construction project management experience with a bachelor's degree, or 60 months with secondary education.
What about CompTIA, AWS and Microsoft?
None of the mainstream CompTIA, AWS or Microsoft certifications enforce experience requirements — their "recommended experience" lines (twelve months for A+, roughly four years for CySA+, ten for SecurityX) are guidance, not gates. They belong on the no-experience list, which our sibling article covers in full; the requirements landscape as a whole — experience, degrees, endorsements and why providers impose them — is mapped in certification requirements explained. Degree-specific gates are rarer still and get their own treatment in certifications that require a degree.
Does your experience actually count? A self-check
Before you build a plan around any credential above, run your CV through this checklist:
Domain match — providers count experience in their defined domains, not job titles. Map your duties to the official exam outline, line by line.
Recency windows — CISA counts only the ten years before application; PMI-RMP's risk experience must sit within five years; PgMP and PfMP look back fifteen. Old experience can silently expire.
Cumulative vs continuous — all the bodies here accept cumulative experience; gaps in employment do not reset the clock.
Full-time equivalence — ISC2 explicitly converts part-time hours; other providers expect you to document equivalence. Keep records.
Verifiability — ISC2 endorsements, ISACA verifications and PMI audits all involve someone else confirming your claims. Line up managers or colleagues who can, before you apply.
Waiver stacking — assume waivers do not stack unless the provider says otherwise; ISC2 and ISACA both cap them explicitly.
Consider an IT auditor with 30 months in the role and a computing degree, aiming high. CISA is closer than it appears: the degree contributes toward ISACA's three-year waiver allowance, so she can register, sit the exam now while study momentum is high, and apply for certification the moment her countable experience clears the bar — any time within five years of passing. CISSP, by contrast, would leave her an Associate of ISC2 for roughly another 30 months even with a one-year degree waiver, since audit work maps to fewer of the eight CISSP domains. Same CV, very different distances to each credential — which is exactly why you check the rules per certification rather than assuming "senior cert = five years."
Whichever gate you are approaching, the exam itself still has to be passed, and experience-gated exams tend to be long: CISA and CISM run four hours at 150 questions. A timed, full-length rehearsal — for instance through ExamPractice's practice test simulation — tells you whether your pacing survives a four-hour format before the real fee is on the line.
Frequently asked questions
Can I put an exam pass on my CV before I am certified?
Yes, if you label it truthfully — "Associate of ISC2" or "CISA exam passed, certification pending experience requirement" are accurate; using the certification's letters before you hold it is not, and providers treat misuse as an ethics violation.
Do experience waivers reduce the exam difficulty or just the years?
Only the years. A waiver never changes the exam, the fee or the maintenance requirements.
What happens if my ISACA five-year application window lapses?
Your exam pass expires with it and you would need to retake the exam. Diary the deadline the day you get your result.
Is unpaid or volunteer work ever countable?
Sometimes — ISC2 counts documented internships whether paid or unpaid, while ISC2's headline requirement otherwise specifies paid work. Check each provider's wording; never assume volunteer hours transfer between bodies.
Reading the gate before you run at it
Experience requirements are not there to keep you out; they exist so the credential means something when you hold it. The practical takeaway from this list is sequencing: under ISACA's and ISC2's rules you can pass the hardest exam of your career years before you technically "qualify," while PMI-track credentials reward getting your documentation in order before anything else. Work out which model your target uses, count your months against the official outline, and you will usually find the gate is nearer — or at least more navigable — than the headline number suggests.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
A five-step decision process for choosing a professional certification: goals, market demand, true cost, prerequisites and renewal — with a comparison worksheet.
The strongest professional certifications for 2026, ranked on demand, recognition and cost of ownership — with the year's retirements and AI-driven changes factored in.