CISSP has a reputation for being a hard exam, and it is, but the part that actually derails candidates most often is not the test content - it is the experience requirement. (ISC)2 will not hand you full CISSP status just because you passed the exam. You also need a specific amount of relevant work experience, and if you do not have it yet, you need to understand the pathway that lets you bank your exam pass and grow into full certification over time. This guide breaks down exactly how the requirement works, what counts, how a degree or another certification can reduce it, and what the Associate of ISC2 designation means in practice.
The core rule: five years, across two of eight domains
To hold full CISSP certification, (ISC)2 requires a minimum of five cumulative years of paid, full-time work experience in at least two of the eight domains that make up the CISSP Common Body of Knowledge (CBK):
- Security and Risk Management
- Asset Security
- Security Architecture and Engineering
- Communication and Network Security
- Identity and Access Management (IAM)
- Security Assessment and Testing
- Security Operations
- Software Development Security
The experience does not need to come from a job with 'security' in the title. It needs to genuinely involve meaningful work within at least two of those eight domains - for example, someone doing network security architecture and access control administration as part of a broader systems administration role can often count that time, even if their title is 'Systems Administrator' rather than 'Security Engineer.' The key test is substance over title: (ISC)2 looks at what you actually did, not what your business card said.
What counts as qualifying experience
Qualifying experience generally needs to be paid, full-time (or the part-time equivalent, prorated), and directly relevant to at least two of the eight domains above. Internships, unpaid work, and time spent purely on unrelated general IT tasks typically do not count toward the requirement. Time spent as a full-time student pursuing your degree does not count either - it can only reduce the requirement through the waiver described below, not stack additional years on top of it. If you have worked across multiple employers or in multiple roles, you can combine non-consecutive periods of qualifying experience to reach the five-year total; the years do not need to be continuous or with a single employer.
The one-year waiver: degree or approved certification
(ISC)2 allows one year of the five-year requirement to be waived if you hold either a four-year college degree (or regional equivalent) or a credential from (ISC)2's approved list of qualifying certifications. This effectively reduces the requirement to four years of qualifying experience for anyone who already has a relevant degree. Only one waiver can be applied, regardless of how many degrees or approved certifications you hold - you cannot stack a degree waiver and a certification waiver to reduce the requirement further. Check (ISC)2's current approved certification list directly when you apply, since which certifications qualify can change over time.
What happens if you pass the exam without enough experience: Associate of ISC2
This is the part that surprises a lot of candidates in a good way: you do not need to already have the five years of experience to sit the CISSP exam. You can study for and pass the exam at any point. If you pass but do not yet meet the experience requirement, (ISC)2 designates you an Associate of ISC2 rather than a full CISSP. From that point, you have up to six years to accumulate the required experience (four years if you already have the degree or certification waiver applied) and submit it for review. Once your experience is verified, your status converts to full CISSP - no need to retake the exam.
Endorsement: the final step to full certification
Passing the exam and accumulating the experience are not quite the whole process. Before (ISC)2 issues full CISSP status, your application also needs to be endorsed by another (ISC)2-certified professional in good standing, who confirms your professional experience is genuine to the best of their knowledge. If you do not personally know anyone who already holds an (ISC)2 certification, (ISC)2 itself can act as the endorser in many cases - check the current endorsement process on (ISC)2's site, since this option and its exact requirements can change. Endorsement is typically a short form, not a lengthy reference process, but it is a required step that candidates sometimes overlook until they are ready to submit.
Practical guidance by experience level
You already have 5+ years across two domains
Study for and take the exam whenever you are ready. Once you pass, submit your experience for verification and get endorsed - you should be able to move to full CISSP status relatively quickly.
You have 2-4 years of relevant experience
Check whether a degree or approved certification you already hold can apply the one-year waiver, which may put you closer to qualifying than you think. If you are still short, consider taking the exam now under the Associate of ISC2 pathway rather than waiting - you bank the hardest part (passing the exam) while your experience clock keeps running toward full conversion.
You have less than 2 years or are new to security entirely
CISSP is not the right near-term target yet. Build experience and consider an associate-level certification like CompTIA Security+ first - it requires no experience, builds the kind of applied security background that later counts toward CISSP's domains, and is far more attainable as an immediate goal.
The bottom line
CISSP's experience requirement is not a formality - it is five cumulative years of paid work across at least two of eight domains, reducible to four years with an approved degree or certification. If you do not have the experience yet, the exam itself is still open to you: pass it now and become an Associate of ISC2, then convert to full CISSP once you have logged the required years and secured an endorsement. Understanding this pathway up front means you can start building toward CISSP years before you technically qualify, instead of waiting on the sidelines.