CertGrid
Security

The CISSP Experience Requirement Explained (and the Associate of ISC2 Path)

By CertGrid TeamUpdated July 29, 20269 min read

SecurityCareer

CISSP has a reputation for being a hard exam, and it is, but the part that actually derails candidates most often is not the test content - it is the experience requirement. (ISC)2 will not hand you full CISSP status just because you passed the exam. You also need a specific amount of relevant work experience, and if you do not have it yet, you need to understand the pathway that lets you bank your exam pass and grow into full certification over time. This guide breaks down exactly how the requirement works, what counts, how a degree or another certification can reduce it, and what the Associate of ISC2 designation means in practice.

The core rule: five years, across two of eight domains

To hold full CISSP certification, (ISC)2 requires a minimum of five cumulative years of paid, full-time work experience in at least two of the eight domains that make up the CISSP Common Body of Knowledge (CBK):

The experience does not need to come from a job with 'security' in the title. It needs to genuinely involve meaningful work within at least two of those eight domains - for example, someone doing network security architecture and access control administration as part of a broader systems administration role can often count that time, even if their title is 'Systems Administrator' rather than 'Security Engineer.' The key test is substance over title: (ISC)2 looks at what you actually did, not what your business card said.

What counts as qualifying experience

Qualifying experience generally needs to be paid, full-time (or the part-time equivalent, prorated), and directly relevant to at least two of the eight domains above. Internships, unpaid work, and time spent purely on unrelated general IT tasks typically do not count toward the requirement. Time spent as a full-time student pursuing your degree does not count either - it can only reduce the requirement through the waiver described below, not stack additional years on top of it. If you have worked across multiple employers or in multiple roles, you can combine non-consecutive periods of qualifying experience to reach the five-year total; the years do not need to be continuous or with a single employer.

The one-year waiver: degree or approved certification

(ISC)2 allows one year of the five-year requirement to be waived if you hold either a four-year college degree (or regional equivalent) or a credential from (ISC)2's approved list of qualifying certifications. This effectively reduces the requirement to four years of qualifying experience for anyone who already has a relevant degree. Only one waiver can be applied, regardless of how many degrees or approved certifications you hold - you cannot stack a degree waiver and a certification waiver to reduce the requirement further. Check (ISC)2's current approved certification list directly when you apply, since which certifications qualify can change over time.

What happens if you pass the exam without enough experience: Associate of ISC2

This is the part that surprises a lot of candidates in a good way: you do not need to already have the five years of experience to sit the CISSP exam. You can study for and pass the exam at any point. If you pass but do not yet meet the experience requirement, (ISC)2 designates you an Associate of ISC2 rather than a full CISSP. From that point, you have up to six years to accumulate the required experience (four years if you already have the degree or certification waiver applied) and submit it for review. Once your experience is verified, your status converts to full CISSP - no need to retake the exam.

The Associate of ISC2 pathway applies specifically to CISSP and several other (ISC)2 certifications. It lets ambitious early-career professionals prove they have the knowledge years before they have the tenure, which can be a meaningful differentiator on a resume even before the experience clock runs out.

Endorsement: the final step to full certification

Passing the exam and accumulating the experience are not quite the whole process. Before (ISC)2 issues full CISSP status, your application also needs to be endorsed by another (ISC)2-certified professional in good standing, who confirms your professional experience is genuine to the best of their knowledge. If you do not personally know anyone who already holds an (ISC)2 certification, (ISC)2 itself can act as the endorser in many cases - check the current endorsement process on (ISC)2's site, since this option and its exact requirements can change. Endorsement is typically a short form, not a lengthy reference process, but it is a required step that candidates sometimes overlook until they are ready to submit.

Practical guidance by experience level

You already have 5+ years across two domains

Study for and take the exam whenever you are ready. Once you pass, submit your experience for verification and get endorsed - you should be able to move to full CISSP status relatively quickly.

You have 2-4 years of relevant experience

Check whether a degree or approved certification you already hold can apply the one-year waiver, which may put you closer to qualifying than you think. If you are still short, consider taking the exam now under the Associate of ISC2 pathway rather than waiting - you bank the hardest part (passing the exam) while your experience clock keeps running toward full conversion.

You have less than 2 years or are new to security entirely

CISSP is not the right near-term target yet. Build experience and consider an associate-level certification like CompTIA Security+ first - it requires no experience, builds the kind of applied security background that later counts toward CISSP's domains, and is far more attainable as an immediate goal.

The bottom line

CISSP's experience requirement is not a formality - it is five cumulative years of paid work across at least two of eight domains, reducible to four years with an approved degree or certification. If you do not have the experience yet, the exam itself is still open to you: pass it now and become an Associate of ISC2, then convert to full CISSP once you have logged the required years and secured an endorsement. Understanding this pathway up front means you can start building toward CISSP years before you technically qualify, instead of waiting on the sidelines.

FAQ

How many years of experience does CISSP require?

Five cumulative years of paid, full-time work experience across at least two of the eight CISSP domains. A relevant four-year degree or an approved certification can waive one of those years, reducing the requirement to four years.

Can I take the CISSP exam without any work experience?

Yes. You can sit and pass the exam at any point. If you pass without the required experience, you become an Associate of ISC2 and have up to six years to accumulate the experience and convert to full CISSP status.

Does time spent getting my degree count toward the experience requirement?

No. Full-time study does not count as work experience. A relevant degree can instead waive one year of the five-year requirement, but it does not add years on top of your work history.

What counts as one of the two required domains?

Any of the eight CISSP CBK domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security. Your work needs to substantively involve at least two of these, regardless of your job title.

What is an Associate of ISC2?

It is the designation given to someone who has passed the CISSP exam but has not yet met the five-year experience requirement. Associates have up to six years to gain the required experience and convert to full CISSP status without retaking the exam.

Can I stack a degree waiver and a certification waiver to reduce the requirement by two years?

No. Only one waiver applies regardless of how many qualifying degrees or certifications you hold, so the maximum reduction is one year, bringing the requirement to four years.

What is CISSP endorsement and do I need it?

Endorsement is a required final step where another (ISC)2-certified professional in good standing confirms your experience claim. If you do not know an endorser personally, (ISC)2 can often act as the endorser directly - confirm the current process on (ISC)2's site when you apply.

Do non-consecutive years of experience count toward the five-year requirement?

Yes. Your qualifying experience does not need to be continuous or with a single employer; you can combine separate periods of relevant work across different roles and employers to reach the total.

Read next

Keep practicing on CertGrid

CertGrid is not affiliated with or endorsed by Microsoft, AWS, Google, Cisco, CompTIA, the Linux Foundation, HashiCorp, or other certification vendors. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.

Browse practice exams · Pricing · Study guides