Certification Exam Costs Explained
·13 min read
What certification exams actually cost across CompTIA, AWS, Cisco, Microsoft, ISC2 and PMI, why prices differ so much, and how pricing tiers work.
Continue readingHow PMI, ISC2 and ISACA define qualifying experience — months vs hours, domain rules, waivers, part-time work and what verification actually checks.

A common false start: someone with six years in IT reads "CISSP requires five years of experience", assumes they qualify, and only discovers at application time that the rule is five years in at least two of eight named domains — and that their six years of desktop support may count for far less than they thought. Experience requirements are never a single number. Every certification body defines qualifying experience with its own unit of measurement, its own recency window, its own domain rules and its own waiver policy, and the same CV can clear one body's bar comfortably while missing another's entirely.
This article explains how the major bodies — the Project Management Institute (PMI), ISC2 and ISACA — actually count experience, so you can tell whether yours qualifies before you spend anything. Writing the experience up on the form itself is a separate craft, covered in how to document experience for certification applications.
Before looking at individual certifications, it helps to know what to look for. Any experience requirement can be decomposed into:
Read a certification's eligibility page against those five headings and ambiguity mostly disappears.
For the Project Management Professional (PMP), PMI offers two eligibility paths: a four-year degree plus 36 months of project leadership experience plus 35 contact hours of project management education (or the Certified Associate in Project Management, CAPM, in place of the hours), or a secondary diploma plus 60 months of experience plus the same education requirement. PMI's 2026 exam-content update mentions expanded eligibility pathways — check pmi.org for the current detail rather than relying on older summaries.
The points that decide borderline cases:
At the heavier end of PMI's portfolio the counting gets stricter: the Program Management Professional (PgMP) demands 48 months of project management experience (or a PMP) plus 48 months of programme management experience within the last 15 years on the degree path, and applications go through a panel review of the documented experience before you may even schedule the exam. Recency windows like "within the last 15 years" (PgMP) or "within the last 10 years" (PMI Construction Professional) mean old experience quietly expires — a decade-old project run does not necessarily still count.
The Certified Information Systems Security Professional (CISSP) requires five years of cumulative, full-time, paid work experience in two or more of the exam's eight domains. Every word there is doing work:
One year — and only one — can be waived through either a relevant bachelor's or master's degree or an approved credential such as CompTIA Security+, CISM, CCSP, AWS Security Specialty or listed GIAC certifications. The waivers do not stack: a degree plus a Security+ still waives only one year.
Two more ISC2 mechanics matter to planners. First, the Associate of ISC2 pathway: you may pass the exam before you have the experience, then have six years to accumulate the missing time — experience gates the credential, not the exam. Second, credentials can satisfy each other: an active CISSP satisfies the entire experience requirement for the Certified Cloud Security Professional (CCSP), which otherwise wants five years of IT experience including three in information security. ISC2's lighter certifications scale the same logic down — the Systems Security Certified Practitioner (SSCP) asks for one year in its domains, and the entry-level Certified in Cybersecurity (CC) requires no experience at all.
ISACA inverts the usual order: anyone can sit the CISA, CISM or CRISC exam with zero experience. Experience is checked only when you apply for certification after passing — and you have five years from your pass date to apply. That makes ISACA's exams unusually accessible to career changers who expect to accumulate the experience soon.
The requirements themselves, and their very different waiver rules:
| Certification | Experience required | Waiver available |
|---|---|---|
| CISA | 5 years of IS/IT audit, control, assurance or security work, within the 10 years before applying | Up to 3 years via substitutions |
| CISM | 5 years in information security management | Up to 2 years |
| CRISC | 3 years in IT risk management and IS control | None |
| CGEIT | 5 years in an advisory/oversight role in enterprise IT governance | None |
| CDPSE | 3 years in privacy governance, risk/compliance or engineering | None |
The asymmetry is the trap: people assume ISACA waivers are uniform, but CISA's generous three-year substitution allowance has no counterpart at all on CRISC, CGEIT or CDPSE — for those, only the real years count.
Claiming experience is not the end of it. ISC2 requires an endorsement within nine months of passing: an ISC2-certified professional in good standing attests to your experience (or ISC2 itself endorses you with employment verification), and ISC2 runs random audits of applications. PMI applications can likewise be selected for audit, and panel-reviewed credentials such as PgMP have humans read the experience summaries before approval. The practical implication: count only experience you could evidence through employers or references if asked. What happens procedurally after you submit is walked through in what happens after you submit a certification application, and the errors that trigger audits and rejections are catalogued in common certification application mistakes.
If step 5 is your situation, the exam becomes the near-term project: the PMP exam overview and CISSP exam overview pages on ExamPractice include free sample questions, which are a quick way to judge how far your working knowledge already stretches across the domains the experience rules care about.
The rules quoted above hinge on the nature of the work, not the employment structure — ISC2's requirement is cumulative paid work, and PMI's is months spent leading projects. Freelance and contract work of the right kind generally accumulates the same way, but you will need clients or contracts who can verify it if audited, which is where self-employed applicants most often struggle.
Yes. Experience is not "spent" when you apply — five years of security work can simultaneously satisfy CISSP and, if it fits the domain definitions, contribute toward CISM's requirement. Each body assesses your history independently.
No. Training satisfies education requirements (such as PMP's 35 contact hours) and waivers, never the experience quantity itself. The two are separate columns on every eligibility page.
Bodies handling verification and endorsement accept alternative evidence routes — former managers or colleagues as references, or the body's own employment-verification process (ISC2 can endorse applicants directly). Plan your evidence before you apply rather than after an audit notice arrives.
Probably more of it than you fear, and less of it than the headline number suggests. Bodies consistently count substance over titles — leading projects without the PM title, security work inside a sysadmin job, audit work inside a consultancy role — but they are strict about domains, recency, and evidence. Decompose the requirement into quantity, content, recency, terms and substitutions; measure your history against each; and where you fall short, remember that two of the three major bodies will let you pass the exam first and finish qualifying afterwards. Once you are confident the experience qualifies, the next task is presenting it properly — start with how to prepare for a certification application.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·13 min read
What certification exams actually cost across CompTIA, AWS, Cisco, Microsoft, ISC2 and PMI, why prices differ so much, and how pricing tiers work.
Continue reading·7 min read
The real end-to-end cost of earning a professional certification — exam fees, training, materials and the extras most first-time candidates forget.
Continue reading·5 min read
When paid certification training earns its price and when self-study wins — a decision framework comparing courses, bootcamps and self-study by candidate situation.
Continue reading