CCSP Experience Requirements: What Counts Toward Eligibility
- #CCSP
- #Experience Requirements
- #Eligibility
- #ISC2
- #Endorsement
Part of our CCSP Complete Guide series.
Understanding the CCSP experience requirements before you start preparing will save you from discovering eligibility gaps late in the process. The requirements are specific but more flexible than they first appear.
The Official Requirements
ISC2 requires CCSP candidates to have:
- 5 years of cumulative, paid work experience in information technology
- Of those 5 years, 3 years must be in information security
- Of those 5 years, 1 year must be in one or more of the six CCSP CBK domains
All experience must be paid work experience. Volunteer work, internships, and academic experience generally do not qualify.
CISSP Substitution
If you hold CISSP, you satisfy the full CCSP experience requirement. ISC2 treats CISSP as sufficient verification of the experience threshold. This is a significant benefit — it means CISSP holders can pursue CCSP at any point after achieving CISSP, regardless of whether they independently meet the CCSP experience timeline.
What Counts as Information Security Experience
ISC2 broadly defines information security work. Roles that typically qualify include:
- Security analyst / security engineer roles
- Security operations center (SOC) roles
- Penetration testing and vulnerability management
- Security architecture and design
- Identity and access management
- Risk management and GRC
- Compliance and audit with a security focus
- Security management and leadership roles
IT roles in system administration, network engineering, database administration, or application development without a security function typically count toward the 5-year IT experience requirement but not the 3-year information security requirement.
What Counts as CCSP CBK Domain Experience
You need 1 year in at least one CCSP CBK domain. The six domains are:
| Domain | Examples of Qualifying Experience |
|---|---|
| 1: Cloud Architecture | Designing security architecture for cloud environments, cloud security strategy development |
| 2: Cloud Data Security | Data classification in cloud, encryption key management, DLP implementation for cloud |
| 3: Cloud Platform/Infrastructure | Kubernetes security, cloud network security, virtualization security, cloud hardening |
| 4: Cloud Application Security | DevSecOps for cloud applications, API security, cloud application security assessment |
| 5: Cloud Security Operations | Cloud security monitoring, incident response for cloud environments, vulnerability management |
| 6: Legal, Risk, and Compliance | Cloud risk assessment, CSP contract review, cloud compliance program management |
Many security professionals working in cloud environments accumulate Domain 5 experience (cloud security operations) even if their role title isn’t explicitly “cloud security.” If you’re managing security monitoring, responding to incidents, or conducting vulnerability management in environments that include cloud infrastructure, that likely qualifies.
Sit for the Exam Before Meeting Requirements
You can take and pass the CCSP exam before you’ve accumulated the required experience. If you pass the exam without meeting experience requirements, you become an Associate of ISC2. The Associate status allows up to 6 years to fulfill the experience requirements.
This approach makes sense for:
- Professionals who are close to but haven’t reached the experience threshold
- Professionals who want to build toward CCSP while still developing cloud security experience
- Those transitioning into cloud security from adjacent IT roles
Note: While Associate status doesn’t carry the full CCSP designation, holding the ISC2 Associate credential and noting “Associate of ISC2 (CCSP path)” on your resume demonstrates exam competency while you build experience.
The Endorsement Process
After passing the CCSP exam and confirming your experience meets requirements, you must complete an endorsement process:
-
Endorsement form: Document your qualifying work experience, including employer names, dates, job titles, and duties for each position.
-
Endorser: An active ISC2 member must endorse your application, confirming that your described experience is accurate. This can be a professional colleague, manager, or other ISC2 member familiar with your work. If you don’t know an ISC2 member, ISC2 can provide a staff endorser.
-
ISC2 review: ISC2 reviews the endorsement application. This typically takes a few weeks.
-
AMF payment: Once approved, you pay the Annual Maintenance Fee ($125) to activate your CCSP credential.
The endorsement doesn’t require submitting employment records — the endorser attests to the accuracy of your experience description. However, ISC2 may audit applications and can ask for verification.
Common Experience Eligibility Questions
“My role is ‘Cloud Engineer’ but it includes security. Does that count?”
Yes, if you can document that the security component was a meaningful part of your duties. Describe the security-specific tasks in your endorsement: access control management, security monitoring, vulnerability assessment, incident response, compliance activities. The role title matters less than the actual duties.
“I worked part-time. Does that count?”
Part-time work can qualify if it was paid. ISC2 counts years of experience, not hours. A two-year part-time role would typically count as a shorter period — ISC2 allows candidates to describe their roles and ISC2 makes the determination.
“I have military or government security experience without private sector roles.”
Yes, qualifying. Government and military security experience is recognized. You’ll need an endorser who can verify the work; this may require creative approaches given classification requirements, but ISC2 has processes for these situations.
“My current job started 8 months ago. I have 4 years before that in security. Do I qualify?”
You need 1 year in a CCSP CBK domain. If your previous 4 years of security work included cloud security components, that domain experience counts regardless of when it occurred. Experience doesn’t need to be recent.
Planning Your Path to Eligibility
If you’re not yet eligible but targeting CCSP:
- Audit your current experience against the requirements — you may be closer than you think
- If you need more cloud security domain experience, identify responsibilities in your current role that qualify and document them contemporaneously
- Consider whether CISSP makes sense in the interim — it satisfies CCSP experience requirements and has its own career value
- Take the exam as soon as you’re prepared, then fulfill endorsement requirements when experience is met
Next: CCSP Associate Certification Path | CCSP Pass Rate and Difficulty
FAQ
What are the CCSP experience requirements?
CCSP requires 5 years of cumulative, paid work experience in IT with 3 years in information security and 1 year in one or more of the six CCSP CBK domains. CISSP holders can substitute the CISSP for the full CCSP experience requirement.
Can I take the CCSP exam without the required experience?
Yes. You can take and pass the CCSP exam without meeting the experience requirements. If you pass without experience, you become an Associate of ISC2 until you accumulate the required experience (maximum 6 years as Associate). Once experience requirements are met, you apply for full CCSP certification.
What counts as cloud security experience for CCSP?
Experience in any of the six CCSP CBK domains counts: cloud architecture design, cloud data security, cloud platform/infrastructure security, cloud application security, cloud security operations, or legal/risk/compliance for cloud. This includes roles in cloud security engineering, cloud GRC, cloud architecture, security operations for cloud platforms, and similar positions.
About the authors
Sekiko Jo
CISSP and CCSP-certified security specialist focused on cloud threat modeling and security governance. A Registered Information Security Specialist (情報処理安全確保支援士) in Japan, she writes from hands-on incident-response experience.
Registered Information Security Specialist (情報処理安全確保支援士), Japan