CISSP requirements: the five years, and the way round them
CISSP has one requirement that stops people, and it is not the exam. ISC2 requires a minimum of five years cumulative, full-time experience in two or more of the eight domains before it will certify you — and that clause is separate from, and stricter than, whether you can pass the paper. You can sit the exam tomorrow with no experience whatsoever. You simply will not be a CISSP when you pass it.
The gate in one picture
Years of experience the body asks for
- ISC2 CCnoneno work experience required
- Security+2 yearstwo years recommended, not required
- CISSP5 yearsfive years in two or more of eight domains
- CCSP5 yearsfive years IT, three in security, one in a domain
- CISM5 yearsfive years, three of the four domains, within ten
Every credential in this space draws its line somewhere different, and the differences are sharper than the marketing suggests. ISC2's entry-level Certified in Cybersecurity page says plainly: No Work Experience Required. CompTIA suggests for Security+ that candidates have Network+ and two years of experience working in a security/systems administrator job role, and then requires neither. ISACA demands five years of information security management experience in at least three of the four CISM domains. CCSP asks for five years of IT of which three years must be in cybersecurity.
CISSP sits at the strict end of that range, and its five years are the reason.
What ISC2 counts, and what it does not
The experience must be cumulative and full-time, and it must fall inside two or more of the eight domains — not one domain for five years. That second half catches people out. A network engineer with a decade of firewall work has deep experience in Communication and Network Security and may have very little in any other domain, and ISC2's clause is about breadth as much as time.
The eight domains are Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security. Most working engineers touch three or four of them without ever labelling the work that way, which is why the first useful exercise is not studying — it is mapping the last five years of your own job descriptions onto that list.
The waiver is one year, once
ISC2 allows a relevant bachelor's or master's degree in computer science or IT, or an approved ISC2 credential, to waive up to one year of the requirement. The wording matters: up to one year in total. A degree and an approved credential do not stack into two years. You are reducing five years to four, and no further.
That makes the waiver worth exactly one year of salary-earning time and nothing more, which is the right way to value it when you are deciding whether a certificate you already hold is worth listing on the application.
The Associate route, and the rule people miss
If the years are not there, ISC2's outline is explicit: candidates lacking the required experience become an Associate of ISC2 after passing the exam and have six years to complete the five years of experience. Six years to earn five is a generous window, and it means sitting early is a legitimate strategy rather than a gamble.
Here is the part that gets people into trouble. Until endorsement is complete, an Associate may not use the CISSP marks. Writing “CISSP” after your name because you passed the exam is not a grey area — it is a claim to a credential you do not hold, and it is the kind of thing that surfaces in a background check rather than in a job interview. What you can accurately say is that you have passed the CISSP examination and hold Associate of ISC2 status.
Endorsement: find your endorser before you sit
Certification is not automatic on passing. An existing ISC2-certified professional has to endorse your experience claim, which means somebody who knows your work well enough to vouch for it in writing. ISC2 publishes a deadline for submitting endorsement; we could not open that page on 24 September 2026, so rather than repeat a window we have not verified, the practical advice is simply to line up the endorsement before you book the exam, not after you pass it.
If you do not know a CISSP well enough to ask, that is useful information about your network, and it is easier to fix in the months before an exam than in the weeks after one.
Then it becomes a subscription
Certification is the start of an obligation, not the end of one. CISSP runs on a three-year cycle requiring 120 continuing professional education credits, of which at least 90 must be Group A — directly related to the domains. The annual figure you see quoted everywhere, 40 credits a year, is ISC2's recommendation for staying on track rather than a requirement for certified members; Associates of ISC2 are the exception and do carry an annual obligation.
The annual maintenance fee is not a recommendation. ISC2 charges $135 a year for CISSP and its other professional credentials, due on the anniversary of your certification date, and $50 a year for Certified in Cybersecurity and Associates. One fee covers every ISC2 certification you hold.
So should you sit it early?
Sit early if you are inside about two years of the requirement and the material already makes sense to you: Associate status is real, six years is a long runway, and the exam does not get easier by waiting. Do not sit early if you are five years away and hoping the credential substitutes for the experience — it does not, and $749 is a lot to pay for a certificate you cannot name on your CV until 2031.
And if the honest answer is that you are years off, the money is better spent one layer in. Compare what each certification asks before it will certify you, or read Security+ against CISSP — for most people two years into IT, that is the decision actually on the table.
One more clause worth reading twice
ISC2's wording is cumulative, which is kinder than it sounds. The five years do not have to be consecutive, and a career with a gap in it — a year out, a spell in a non-security role, a parental break — does not reset the count. What the years do have to be is full-time and inside the domains, and that is the pair of conditions worth checking before you fill in an application rather than after.
The same paragraph catches people moving into security from adjacent work. Three years of systems administration is not automatically three years of CISSP-domain experience, but the parts of it that were access reviews, patch governance, backup and recovery testing or network segmentation genuinely are. Break the role down by task rather than by job title, and the honest total is often higher than the one on your CV.
The experience clause, answered
Can I take CISSP without five years of experience?
Does a degree count towards CISSP experience?
Does part-time or contract work count?
How long does endorsement take?
Still deciding between credentials? Work through which cybersecurity certification fits the stage you are at, or read how every figure on this site is checked. Fees, formats and eligibility rules change without warning — open the certifying body’s page before you pay for anything.