CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingNo security certification requires a degree — experience rules are the real gate. Which certs substitute for a degree in hiring, and how to sequence them.

Here is the fact most "do I need a degree?" articles bury: not one major cybersecurity certification requires a degree. Not CompTIA Security+, not ISC2 CISSP, not OffSec's OSCP, not ISACA's CISM. The gates that actually stop non-graduates are experience requirements — CISSP wants five years, CISM wants five, ISC2's SSCP wants one — and those trip people up far more often than the missing diploma ever does.
Short answer: yes, you can build a cybersecurity career on certifications without a degree. Start with ISC2 Certified in Cybersecurity (CC) or CompTIA Security+ — neither has any prerequisite — get working, and let paid experience unlock the experience-gated certifications later. A degree mostly buys you two things certs cannot: a pass through degree-required HR filters at some conservative employers, and (usefully) a one-year waiver against CISSP's experience requirement. Everything else is earnable another way.
This article deals strictly with the no-degree question: what certs substitute for in hiring, which experience prerequisites matter, and how to sequence around them. For a general ranking of first certs by learning curve, see our best cybersecurity certifications for beginners guide instead.
Think of a degree as doing three jobs in hiring, and score certifications against each.
Job 1: passing the HR filter. Some listings say "bachelor's degree or equivalent experience". Certifications plus a couple of years of any IT work usually satisfy the "equivalent" clause. A minority of employers — some government bodies, some large conservative enterprises — hard-require degrees; no cert changes that, and the practical answer is to apply elsewhere. The market is large enough to route around them: CyberSeek reported roughly 450,000–514,000 US cybersecurity openings across its 2025–2026 data windows (live figures at cyberseek.org).
Job 2: proving baseline knowledge. Here certifications are arguably the stronger signal, because they are standardised and current. A Security+ pass certifies against a 2023-published objective set; a 2015 degree does not.
Job 3: proving you can finish hard, long things. A degree signals four years of sustained effort. A single entry exam does not — but a sequence of certifications earned while working does, which is why the roadmap matters more for non-graduates than for anyone else.
The verdict: certifications substitute well for jobs 1 and 2, and substitute for job 3 only when stacked over time. Plan for a stack, not a silver bullet.
Before choosing certs, know exactly where the experience walls are. This is the part non-graduates most often get wrong — booking an exam they can pass but cannot yet convert into a credential.
Two escape hatches matter enormously for non-graduates:
The sequence below is built around one principle: every step must either be prerequisite-free or be unlocked by the work experience the previous step got you.
Certified in Cybersecurity has no experience requirement and no endorsement hurdle at entry. It is a computerised adaptive exam of 100–125 items in up to two hours, covering security principles, access controls, network security, incident-response concepts and operations, priced at $199 (US, 2026). One caution: the famous free-exam programme closed to new enrolments on 20 May 2026, so ignore older advice that CC costs nothing. Its job in your stack is speed — a recognised credential on your CV within weeks, while you study for Step 2.
Security+ (SY0-701 as of August 2026) is the certification junior security listings name most, and it carries weight in US government-adjacent hiring through DoD 8140 recognition. Maximum 90 questions in 90 minutes, passing score 750/900, no prerequisites. For a non-graduate this is the single highest-leverage exam: it answers the "baseline knowledge" question a missing degree raises. Work through the official objectives domain by domain, then use free Security+ sample questions to check your understanding survives contact with exam-style wording.
This step is not an exam, and skipping it is the classic no-degree mistake. Helpdesk, desktop support, junior sysadmin, NOC — every month of this is experience that (a) makes your CV concrete and (b) runs the clock on SSCP's one year, CEH's two, and CISSP's five. ISC2 counts part-time work and documented internships pro rata, so imperfect jobs still move you forward.
With five years banked (minus one if you hold an approved waiver credential), CISSP ($749) moves you into senior and management-track roles where, in practice, the credential ends the degree conversation. Sit it earlier as an Associate if the study momentum is there. Browse the ISC2 exam hub for the current outline and question styles.
A 24-year-old warehouse shift-lead with a home-lab habit takes CC in month two and Security+ in month six while applying for IT support roles. Month eight: a helpdesk job. Over the next 18 months they take every security-adjacent ticket — phishing triage, access reviews, patching — and document it, because ISC2 and ISACA experience claims need verifiable work history, not job titles. Month 26: internal move to a junior SOC seat, partly on the strength of CySA+ study and a portfolio of investigation write-ups. By year three they hold CC, Security+, CySA+ and one year of countable security experience — SSCP-eligible, CEH-eligible via the application route, and two-fifths of the way to CISSP. No step required a university.
For getting hired and progressing in cybersecurity: substantially, yes — provided you respect the experience gates and build the stack in order. Start prerequisite-free (CC, then Security+), convert study into a paid IT seat quickly, and let the clock plus a specialist cert carry you to the experience-gated tier. Where a degree still wins is at the handful of employers who hard-require one and in the one-year CISSP waiver — and the waiver, at least, a certification can match. When you are ready to test whether your knowledge is exam-shaped, a timed practice-test simulation against your chosen exam's domains is the cheapest possible reality check before spending voucher money. If you are switching from a different career entirely, the sequencing trade-offs differ a little — see our guide for career changers moving into cybersecurity.
Do employers actually check for degrees?
Some verify education claims, so never invent one — but "or equivalent experience" wording is common, and certifications plus documented work generally satisfy it.
Is the ISC2 CC still free?
No. The One Million Certified in Cybersecurity programme stopped taking new enrolments on 20 May 2026; the standard exam price is $199, though vouchers issued before the closure remain usable to the end of 2026.
Which single cert matters most without a degree?
Security+, on breadth of recognition in junior listings and DoD-linked hiring. CC is a worthwhile warm-up; nothing else replaces Security+ as the screen-passer.
Can self-taught skills alone work, with no certs at all?
Occasionally, in offensive security with an exceptional public portfolio — but for the analyst and GRC roles where most people enter, certifications are the standard evidence and the cheaper bet.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading