Exampractice
Cybersecurity

CISSP Experience Requirements Explained

What the CISSP five-year experience rule actually requires, how the one-year waiver works, and the Associate of ISC2 route if you fall short.

Alexander Novak · 7 min read
Scale weighing five years of work experience folders against a CISSP badge, with a degree scroll removing one year

To earn the Certified Information Systems Security Professional (CISSP) credential, ISC2 requires five years of cumulative, full-time, paid work experience in at least two of the eight CISSP domains. A relevant degree or an approved certification can waive one of those years — but only one waiver applies, ever. And if you do not have the experience yet, you can still sit the exam now and become an Associate of ISC2, with six years to accumulate the five qualifying years.

That is the whole rule in three sentences. The rest of this article unpacks the parts people actually get stuck on: what "cumulative" and "full-time" mean in practice, how part-time work and internships are counted, which waivers qualify, how endorsement verifies it all after you pass, and how to decide between waiting, using the waiver, or taking the Associate route. This is purely the eligibility question — for the exam's format, cost and content, see the CISSP certification guide.

What does "five years in two or more domains" actually mean?

The requirement is five years of cumulative, paid, full-time work experience in two or more of the eight domains of the CISSP exam outline: Security and Risk Management; Asset Security; Security Architecture and Engineering; Communication and Network Security; Identity and Access Management (IAM); Security Assessment and Testing; Security Operations; and Software Development Security.

Three words in that sentence carry the weight:

  • Cumulative — the years do not need to be consecutive or with one employer. Two years in one role and three in another, with a gap between, still add to five.
  • Paid — the baseline expectation is paid work, though ISC2 makes a specific allowance for documented internships (below).
  • In two or more domains — your job title does not need "security" in it. What matters is that your actual duties map to at least two domains. A systems administrator who manages access controls (Domain 5) and handles patching, logging and backups (Domain 7) is doing domain-relevant work, whatever the business card says.

Because the domains are broad, many candidates in networking, sysadmin, development, audit and IT-management roles have more qualifying experience than they assume. Map your duties honestly against the outline before concluding you are short — and if you want a fuller sense of what each domain covers, our CISSP exam domains explained article walks through all eight.

How do part-time work and internships count?

ISC2 converts part-time work by hours rather than dismissing it. Under the published rules, part-time means 20 to 34 hours per week, and:

  • 1,040 hours of part-time work counts as six months of experience;
  • 2,080 hours of part-time work counts as twelve months.

Internships count too, paid or unpaid, provided they are documented — ISC2 expects certification of the internship from the organisation on its letterhead (or from the registrar if the internship was arranged through a school). For career-changers who did an unpaid security placement, that time is not wasted; keep the paperwork.

How does the one-year experience waiver work?

You can satisfy one year of the five with either of the following — never both:

  1. Education: a relevant bachelor's degree (or a master's) in an applicable field; or
  2. An approved credential: one certification from ISC2's approved list, which includes credentials such as CompTIA Security+, Certified Cloud Security Professional (CCSP), Certified Information Security Manager (CISM), AWS Certified Security – Specialty, and various GIAC certifications.

The single most misunderstood point: the waiver is capped at one year, once. A master's degree plus Security+ plus a GIAC cert still waives exactly one year. Four years of qualifying experience plus one waiver is the practical minimum for full certification; three years plus two credentials is not. Check ISC2's experience-requirements page for the current approved-credential list before relying on a specific certification, as the list is maintained by ISC2 and can change.

Can you take the CISSP exam without the experience?

Yes. ISC2 lets you sit the exam before you meet the experience requirement. If you pass, you become an Associate of ISC2 rather than a CISSP, and the clock starts: you have six years to accumulate the five years of qualifying experience. Once you have it, you complete endorsement and convert to full CISSP status.

Points worth knowing about the Associate route:

  • You pass the same exam as everyone else — there is no easier "associate exam". The exam is fully adaptive, 100–150 questions in up to three hours, and as of 2026 costs $749 USD in the Americas (regional pricing varies; confirm on ISC2's site).
  • You may not call yourself a CISSP while an Associate. The designation is "Associate of ISC2".
  • Associates pay a lower annual maintenance fee than full members — $50 per year rather than $135 — and must earn 15 continuing professional education (CPE) credits annually while in Associate status.
  • Experience you earn after passing counts. Many candidates pass early precisely so that their next role's duties accrue toward the five years.

What is the endorsement process?

Passing the exam does not certify you; endorsement does. Within nine months of passing, you must submit an endorsement application attesting to your qualifying experience, endorsed by an ISC2-certified professional in good standing who can vouch for it. If you do not know an ISC2 member, ISC2 itself can act as endorser, using employment verification instead.

Two cautions. First, the nine-month window is real — passing and then drifting risks the deadline, so line up your endorser and your experience documentation before exam day, not after. Second, ISC2 audits a random selection of applications, so the experience you claim must survive scrutiny: dates, duties and domains, verifiable by the people you name. Describe your work accurately and map it to domains conservatively.

Waiver, wait, or Associate route: a decision framework

Your situation determines the sensible path. Work through these in order:

  1. Five or more qualifying years already? Book the exam when you are ready and prepare your endorsement evidence in parallel. Nothing in this article constrains you.
  2. Four years, plus a relevant degree or an approved cert? The waiver closes the gap. You can pursue full certification immediately after passing.
  3. Roughly two to four years, in security-adjacent work? Sit the exam when your preparation is ready and take the Associate route. The six-year window is generous, post-pass experience counts, and the credential-in-progress signals commitment to employers. Meanwhile, audit whether your current duties already map to two domains more fully than your title suggests.
  4. Little or no relevant experience at all? Passing the CISSP exam is possible in principle, but the Associate clock and the exam's managerial framing both work against you. Most people in this position get better value from an entry- or operational-level ISC2 credential first — the Systems Security Certified Practitioner (SSCP) requires only one year of experience, and the level gap between the two is exactly what our SSCP vs CISSP comparison covers.

A realistic example of tier 3: a service-desk analyst promoted two years ago into a security operations centre role. Her SOC time clearly spans Domains 6 and 7; her earlier helpdesk years may partially qualify where she administered accounts and access. With Security+ already held, she can waive a year, pass now as an Associate, and plausibly convert to full CISSP within two to three years — considerably sooner than "wait until I have five years in a security title" thinking would suggest.

Whether CISSP is the right investment for your career stage at all is a different question from whether you qualify — that verdict, including who should skip it, lives in Is CISSP worth it in 2026?

Frequently asked questions

Does experience have to be recent?

ISC2's requirement is cumulative rather than time-boxed, and its published rules centre on the total, the domains and full-time/part-time status. If a large share of your experience is from many years ago, review the current experience-requirements page or contact ISC2 before applying, and be prepared to document older roles thoroughly for endorsement.

Can I count the same period of work toward two domains?

The requirement is five years across two or more domains, not five years per domain. One role whose duties genuinely span multiple domains — common in security jobs — supports the two-domain condition; you are counting calendar time once, while showing it touched more than one domain.

Do self-employment or military service count?

Paid, full-time work mapping to the domains is the test ISC2 applies, and neither category is singled out in the headline rules. Document such experience carefully (contracts, references, duty descriptions) and verify how to present it via ISC2's experience-requirements page, since endorsement will require someone able to attest to it.

What happens if I don't earn the experience within the Associate's six years?

The six-year window is the time ISC2 allows an Associate to reach the five qualifying years. If you are approaching the limit, contact ISC2 about your options directly rather than relying on second-hand accounts — policy details of this kind should always be confirmed with the provider.

Where this leaves you

The CISSP experience requirement filters for practitioners, but it is more flexible than its reputation: cumulative counting, part-time conversion, documented internships, a one-year waiver and a six-year Associate runway all bend it toward people actively building a security career. Map your duties against the eight domains before assuming you fall short, confirm the current rules and approved-credential list on ISC2's experience-requirements page, and choose your route with the endorsement deadline in view. Once eligibility is settled and you turn to preparation itself, ExamPractice's free sample questions are a low-stakes way to gauge how the exam's question style feels before you commit to a study calendar.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like