Exampractice
Costs & Renewal

How Professional Experience Counts Toward Certification

How PMI, ISC2 and ISACA define qualifying experience — months vs hours, domain rules, waivers, part-time work and what verification actually checks.

Aisha Rahman · 7 min read
One career timeline measured by three rulers labelled months, hours and domains, representing different certification experience rules

A common false start: someone with six years in IT reads "CISSP requires five years of experience", assumes they qualify, and only discovers at application time that the rule is five years in at least two of eight named domains — and that their six years of desktop support may count for far less than they thought. Experience requirements are never a single number. Every certification body defines qualifying experience with its own unit of measurement, its own recency window, its own domain rules and its own waiver policy, and the same CV can clear one body's bar comfortably while missing another's entirely.

This article explains how the major bodies — the Project Management Institute (PMI), ISC2 and ISACA — actually count experience, so you can tell whether yours qualifies before you spend anything. Writing the experience up on the form itself is a separate craft, covered in how to document experience for certification applications.

The five dimensions every experience rule has

Before looking at individual certifications, it helps to know what to look for. Any experience requirement can be decomposed into:

  • Quantity — months, years, or cumulative hours.
  • Content — what the work must have involved (leading projects, security domains, IS audit), regardless of job title.
  • Recency — a window within which the experience must fall (e.g. the last 10 years).
  • Employment terms — full-time versus part-time, paid versus unpaid, and how each converts.
  • Substitutions — degrees, prior credentials or training that waive part of the requirement.

Read a certification's eligibility page against those five headings and ambiguity mostly disappears.

How PMI counts experience: months of leading projects

For the Project Management Professional (PMP), PMI offers two eligibility paths: a four-year degree plus 36 months of project leadership experience plus 35 contact hours of project management education (or the Certified Associate in Project Management, CAPM, in place of the hours), or a secondary diploma plus 60 months of experience plus the same education requirement. PMI's 2026 exam-content update mentions expanded eligibility pathways — check pmi.org for the current detail rather than relying on older summaries.

The points that decide borderline cases:

  • The title does not matter; the role does. You do not need "project manager" on a business card — time spent leading and directing projects counts, whatever you were called. A senior engineer who ran workstreams, owned schedules and coordinated stakeholders is accumulating qualifying months.
  • Education trades against experience. The degree-versus-diploma split changes the requirement by two full years — one of the largest education offsets in any major programme.
  • A credential can substitute for training. Holding the CAPM satisfies the 35-contact-hour education requirement.

At the heavier end of PMI's portfolio the counting gets stricter: the Program Management Professional (PgMP) demands 48 months of project management experience (or a PMP) plus 48 months of programme management experience within the last 15 years on the degree path, and applications go through a panel review of the documented experience before you may even schedule the exam. Recency windows like "within the last 15 years" (PgMP) or "within the last 10 years" (PMI Construction Professional) mean old experience quietly expires — a decade-old project run does not necessarily still count.

How ISC2 counts experience: cumulative paid work across domains

The Certified Information Systems Security Professional (CISSP) requires five years of cumulative, full-time, paid work experience in two or more of the exam's eight domains. Every word there is doing work:

  • Cumulative — the five years need not be continuous or with one employer.
  • Paid work — with one notable exception: ISC2 counts documented internships whether paid or unpaid.
  • Two or more domains — deep experience in a single domain does not qualify on its own; the work must span at least two of the eight.
  • Part-time converts by hours — ISC2 defines part-time as 20–34 hours per week and converts it: 1,040 hours counts as six months, 2,080 hours as twelve. Part-time work is not discarded, just prorated.

One year — and only one — can be waived through either a relevant bachelor's or master's degree or an approved credential such as CompTIA Security+, CISM, CCSP, AWS Security Specialty or listed GIAC certifications. The waivers do not stack: a degree plus a Security+ still waives only one year.

Two more ISC2 mechanics matter to planners. First, the Associate of ISC2 pathway: you may pass the exam before you have the experience, then have six years to accumulate the missing time — experience gates the credential, not the exam. Second, credentials can satisfy each other: an active CISSP satisfies the entire experience requirement for the Certified Cloud Security Professional (CCSP), which otherwise wants five years of IT experience including three in information security. ISC2's lighter certifications scale the same logic down — the Systems Security Certified Practitioner (SSCP) asks for one year in its domains, and the entry-level Certified in Cybersecurity (CC) requires no experience at all.

How ISACA counts experience: exam first, evidence later

ISACA inverts the usual order: anyone can sit the CISA, CISM or CRISC exam with zero experience. Experience is checked only when you apply for certification after passing — and you have five years from your pass date to apply. That makes ISACA's exams unusually accessible to career changers who expect to accumulate the experience soon.

The requirements themselves, and their very different waiver rules:

CertificationExperience requiredWaiver available
CISA5 years of IS/IT audit, control, assurance or security work, within the 10 years before applyingUp to 3 years via substitutions
CISM5 years in information security managementUp to 2 years
CRISC3 years in IT risk management and IS controlNone
CGEIT5 years in an advisory/oversight role in enterprise IT governanceNone
CDPSE3 years in privacy governance, risk/compliance or engineeringNone

The asymmetry is the trap: people assume ISACA waivers are uniform, but CISA's generous three-year substitution allowance has no counterpart at all on CRISC, CGEIT or CDPSE — for those, only the real years count.

How experience gets verified

Claiming experience is not the end of it. ISC2 requires an endorsement within nine months of passing: an ISC2-certified professional in good standing attests to your experience (or ISC2 itself endorses you with employment verification), and ISC2 runs random audits of applications. PMI applications can likewise be selected for audit, and panel-reviewed credentials such as PgMP have humans read the experience summaries before approval. The practical implication: count only experience you could evidence through employers or references if asked. What happens procedurally after you submit is walked through in what happens after you submit a certification application, and the errors that trigger audits and rejections are catalogued in common certification application mistakes.

A quick self-assessment before you apply

  1. Translate your CV into the body's unit. Months of project leadership for PMI; cumulative paid full-time-equivalent years for ISC2; years of domain-relevant work within the recency window for ISACA.
  2. Map work to domains, not job titles. List the certification's domains and assign real tasks to each; for CISSP you need credible coverage of at least two.
  3. Apply waivers last, and only once. Identify the single largest substitution you hold (degree, credential, ISACA substitution) and subtract it — remembering the no-stacking rules.
  4. Check the recency window. Drop anything outside "the last 10/15 years" where a window applies.
  5. If you are short, choose the exam-first route deliberately. Associate of ISC2 (six years to close the gap) and ISACA's five-year post-pass application window both let you bank the exam while the experience accrues.

If step 5 is your situation, the exam becomes the near-term project: the PMP exam overview and CISSP exam overview pages on ExamPractice include free sample questions, which are a quick way to judge how far your working knowledge already stretches across the domains the experience rules care about.

Frequently asked questions

Does self-employment or freelance work count as qualifying experience?

The rules quoted above hinge on the nature of the work, not the employment structure — ISC2's requirement is cumulative paid work, and PMI's is months spent leading projects. Freelance and contract work of the right kind generally accumulates the same way, but you will need clients or contracts who can verify it if audited, which is where self-employed applicants most often struggle.

Can the same years of experience be used for two different certifications?

Yes. Experience is not "spent" when you apply — five years of security work can simultaneously satisfy CISSP and, if it fits the domain definitions, contribute toward CISM's requirement. Each body assesses your history independently.

Do certification study hours count as experience?

No. Training satisfies education requirements (such as PMP's 35 contact hours) and waivers, never the experience quantity itself. The two are separate columns on every eligibility page.

What if my employer no longer exists to verify my experience?

Bodies handling verification and endorsement accept alternative evidence routes — former managers or colleagues as references, or the body's own employment-verification process (ISC2 can endorse applicants directly). Plan your evidence before you apply rather than after an audit notice arrives.

Does your experience qualify? The honest summary

Probably more of it than you fear, and less of it than the headline number suggests. Bodies consistently count substance over titles — leading projects without the PM title, security work inside a sysadmin job, audit work inside a consultancy role — but they are strict about domains, recency, and evidence. Decompose the requirement into quantity, content, recency, terms and substitutions; measure your history against each; and where you fall short, remember that two of the three major bodies will let you pass the exam first and finish qualifying afterwards. Once you are confident the experience qualifies, the next task is presenting it properly — start with how to prepare for a certification application.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like