TCL Portal

CCSP Experience Requirements: What Counts Toward Eligibility

Published:
  • #CCSP
  • #Experience Requirements
  • #Eligibility
  • #ISC2
  • #Endorsement

Part of our CCSP Complete Guide series.

Understanding the CCSP experience requirements before you start preparing will save you from discovering eligibility gaps late in the process. The requirements are specific but more flexible than they first appear.

The Official Requirements

ISC2 requires CCSP candidates to have:

  1. 5 years of cumulative, paid work experience in information technology
  2. Of those 5 years, 3 years must be in information security
  3. Of those 5 years, 1 year must be in one or more of the six CCSP CBK domains

All experience must be paid work experience. Volunteer work, internships, and academic experience generally do not qualify.

CISSP Substitution

If you hold CISSP, you satisfy the full CCSP experience requirement. ISC2 treats CISSP as sufficient verification of the experience threshold. This is a significant benefit — it means CISSP holders can pursue CCSP at any point after achieving CISSP, regardless of whether they independently meet the CCSP experience timeline.

What Counts as Information Security Experience

ISC2 broadly defines information security work. Roles that typically qualify include:

IT roles in system administration, network engineering, database administration, or application development without a security function typically count toward the 5-year IT experience requirement but not the 3-year information security requirement.

What Counts as CCSP CBK Domain Experience

You need 1 year in at least one CCSP CBK domain. The six domains are:

DomainExamples of Qualifying Experience
1: Cloud ArchitectureDesigning security architecture for cloud environments, cloud security strategy development
2: Cloud Data SecurityData classification in cloud, encryption key management, DLP implementation for cloud
3: Cloud Platform/InfrastructureKubernetes security, cloud network security, virtualization security, cloud hardening
4: Cloud Application SecurityDevSecOps for cloud applications, API security, cloud application security assessment
5: Cloud Security OperationsCloud security monitoring, incident response for cloud environments, vulnerability management
6: Legal, Risk, and ComplianceCloud risk assessment, CSP contract review, cloud compliance program management

Many security professionals working in cloud environments accumulate Domain 5 experience (cloud security operations) even if their role title isn’t explicitly “cloud security.” If you’re managing security monitoring, responding to incidents, or conducting vulnerability management in environments that include cloud infrastructure, that likely qualifies.

Start Preparing Now: Experience requirements don't prevent you from studying for CCSP. The Udemy CCSP course is the best way to prepare for the exam regardless of where you are in meeting experience requirements.

Sit for the Exam Before Meeting Requirements

You can take and pass the CCSP exam before you’ve accumulated the required experience. If you pass the exam without meeting experience requirements, you become an Associate of ISC2. The Associate status allows up to 6 years to fulfill the experience requirements.

This approach makes sense for:

Note: While Associate status doesn’t carry the full CCSP designation, holding the ISC2 Associate credential and noting “Associate of ISC2 (CCSP path)” on your resume demonstrates exam competency while you build experience.

The Endorsement Process

After passing the CCSP exam and confirming your experience meets requirements, you must complete an endorsement process:

  1. Endorsement form: Document your qualifying work experience, including employer names, dates, job titles, and duties for each position.

  2. Endorser: An active ISC2 member must endorse your application, confirming that your described experience is accurate. This can be a professional colleague, manager, or other ISC2 member familiar with your work. If you don’t know an ISC2 member, ISC2 can provide a staff endorser.

  3. ISC2 review: ISC2 reviews the endorsement application. This typically takes a few weeks.

  4. AMF payment: Once approved, you pay the Annual Maintenance Fee ($125) to activate your CCSP credential.

The endorsement doesn’t require submitting employment records — the endorser attests to the accuracy of your experience description. However, ISC2 may audit applications and can ask for verification.

Common Experience Eligibility Questions

“My role is ‘Cloud Engineer’ but it includes security. Does that count?”

Yes, if you can document that the security component was a meaningful part of your duties. Describe the security-specific tasks in your endorsement: access control management, security monitoring, vulnerability assessment, incident response, compliance activities. The role title matters less than the actual duties.

“I worked part-time. Does that count?”

Part-time work can qualify if it was paid. ISC2 counts years of experience, not hours. A two-year part-time role would typically count as a shorter period — ISC2 allows candidates to describe their roles and ISC2 makes the determination.

“I have military or government security experience without private sector roles.”

Yes, qualifying. Government and military security experience is recognized. You’ll need an endorser who can verify the work; this may require creative approaches given classification requirements, but ISC2 has processes for these situations.

“My current job started 8 months ago. I have 4 years before that in security. Do I qualify?”

You need 1 year in a CCSP CBK domain. If your previous 4 years of security work included cloud security components, that domain experience counts regardless of when it occurred. Experience doesn’t need to be recent.

Planning Your Path to Eligibility

If you’re not yet eligible but targeting CCSP:

  1. Audit your current experience against the requirements — you may be closer than you think
  2. If you need more cloud security domain experience, identify responsibilities in your current role that qualify and document them contemporaneously
  3. Consider whether CISSP makes sense in the interim — it satisfies CCSP experience requirements and has its own career value
  4. Take the exam as soon as you’re prepared, then fulfill endorsement requirements when experience is met

Next: CCSP Associate Certification Path | CCSP Pass Rate and Difficulty

FAQ

What are the CCSP experience requirements?

CCSP requires 5 years of cumulative, paid work experience in IT with 3 years in information security and 1 year in one or more of the six CCSP CBK domains. CISSP holders can substitute the CISSP for the full CCSP experience requirement.

Can I take the CCSP exam without the required experience?

Yes. You can take and pass the CCSP exam without meeting the experience requirements. If you pass without experience, you become an Associate of ISC2 until you accumulate the required experience (maximum 6 years as Associate). Once experience requirements are met, you apply for full CCSP certification.

What counts as cloud security experience for CCSP?

Experience in any of the six CCSP CBK domains counts: cloud architecture design, cloud data security, cloud platform/infrastructure security, cloud application security, cloud security operations, or legal/risk/compliance for cloud. This includes roles in cloud security engineering, cloud GRC, cloud architecture, security operations for cloud platforms, and similar positions.

About the authors