CISSP Experience Requirements 2026: How to Count Your 5 Years
- #CISSP
- #ISC2
- #Experience Requirements
- #Security Certification
- #Career
Part of our CISSP Certification Complete Guide 2026 series.
The CISSP’s 5-year experience requirement trips up more candidates than the exam itself. The rules are more nuanced than they appear, and many professionals who believe they do not qualify actually do — and vice versa.
This guide breaks down how experience is counted, which roles qualify, the documentation process, and your options if you are short on experience.
The Core Requirement
To earn CISSP certification (not just pass the exam), you must have:
Minimum 5 years of cumulative, paid, full-time work experience in 2 or more of the 8 CISSP CBK domains.
The key words here: cumulative (does not need to be consecutive), paid (unpaid work does not count), and full-time (part-time experience may be counted proportionally, but this requires documentation and (ISC)² review).
Which Roles and Activities Count?
The CISSP experience requirement is domain-based, not job-title-based. Work experience counts toward a domain if your role directly involved that domain’s content, regardless of what your job title was.
Domain 1 — Security and Risk Management: Risk assessment activities, compliance program management, security policy development, BCP/DRP planning, security governance involvement.
Domain 2 — Asset Security: Data classification programs, data governance, DLP implementation, secure disposal procedures, privacy program involvement.
Domain 3 — Security Architecture and Engineering: Security architecture design, cryptography implementation, system security design, PKI administration, secure coding framework development.
Domain 4 — Communication and Network Security: Network security design, firewall administration, VPN management, network architecture with security considerations, wireless security implementation.
Domain 5 — Identity and Access Management: IAM system administration, PAM implementation, SSO design, access control policy management, identity governance.
Domain 6 — Security Assessment and Testing: Vulnerability assessment, penetration testing, security audits, log review programs, security testing in SDLC.
Domain 7 — Security Operations: Incident response, SOC operations, SIEM management, digital forensics, patch management, BCP/DRP operations.
Domain 8 — Software Development Security: Application security review, secure SDLC implementation, DevSecOps, code review programs, SAST/DAST operations.
Important: Network engineers, system administrators, software developers, and IT managers frequently have qualifying experience that they do not initially recognize as CISSP-eligible. Review the domain descriptions carefully before concluding you do not qualify.
What Does NOT Count as Qualifying Experience
Volunteer work: Experience must be paid employment. Security community contributions, pro bono consulting, or volunteer incident response do not count toward the experience requirement.
Student projects and academic work: University or bootcamp projects do not qualify, even if technically sophisticated.
Non-security IT work with no domain overlap: General help desk support, desktop support, and IT roles with no substantive intersection with CBK domains do not count.
Certifications and training: Holding security certifications or completing training does not substitute for experience (though certain credentials can substitute for one year of experience — see below).
Experience Substitutions
4-Year College Degree
A 4-year bachelor’s degree (or regional equivalent) substitutes for 1 year of the required experience, reducing the minimum from 5 years to 4 years.
The degree does not need to be in computer science, information technology, or security. Any 4-year degree qualifies.
Approved Credentials
Certain credentials from the (ISC)² approved list also substitute for 1 year of experience. The list includes credentials such as:
- Other (ISC)² certifications (SSCP, CAP)
- CompTIA Security+
- GIAC certifications (GSEC, etc.)
- Some vendor-specific security certifications
Check the current (ISC)² approved credentials list at the time of your application, as the list is periodically updated.
Maximum substitution: Only 1 year of experience can be substituted, regardless of how many degrees or approved credentials you hold.
How to Document Your Experience
When you apply for CISSP certification after passing the exam, you will need to document your qualifying experience. The process:
- Complete the (ISC)² online experience endorsement form
- Have a current CISSP holder endorse your experience (the endorser verifies your experience is genuine and qualifies; they do not need to have worked with you directly)
- (ISC)² reviews the endorsement — this process takes several weeks
What you will need to document:
- Employer name, your job title, and employment dates for each qualifying position
- A description of your responsibilities in each domain you claim credit for
- Contact information for your endorser (a current CISSP holder)
Practical advice: Keep records of your professional experience as you accumulate it, not just when you need to document it for the endorsement. A running log of your security responsibilities by domain makes the documentation process significantly easier.
The Associate of (ISC)²: If You Are Short on Experience
If you pass the CISSP exam but have fewer than 5 years of qualifying experience, you become an Associate of (ISC)².
What Associate status includes:
- Formal (ISC)² recognition that you have passed the CISSP exam
- 6 years from your exam date to complete the experience requirement and earn full CISSP certification
- Designation “Associate of (ISC)²” that can be used on your resume and LinkedIn profile
- Access to the (ISC)² community and some member benefits
What Associate status does not include:
- The CISSP credential itself
- The same salary premium as full CISSP certification (though Associate status is not without value in some markets)
Who benefits from the Associate path:
Professionals in the 3–4 year range of qualifying experience who want to invest in the credential now and complete the experience requirement while holding the Associate designation. If you are 1–2 years away from the experience requirement, sitting the exam early and spending time as an Associate can be a reasonable strategy — particularly if you are in a role where CISSP exam preparation is best done now rather than later (more available study time, strong study community at your employer, etc.).
If you are more than 2 years away from qualifying, I would generally suggest waiting. The exam’s “think like a senior security manager” questions are much easier to answer correctly when you have actually experienced security management challenges.
How Many Years Do I Actually Have?
A common source of confusion: security professionals often undercount their qualifying experience by applying too narrow a definition of “security work.”
Questions to ask yourself:
-
Did any part of my non-security IT roles involve network architecture, access control, or system design with security implications? (Domain 3, 4, or 5 credit may apply)
-
Have I done any risk assessment work — even informally — as part of a larger IT or business role? (Domain 1 credit)
-
Have I been involved in any audit, compliance, or policy work? (Domain 1 or 6 credit)
-
Have I managed or responded to any security incidents, even minor ones, in a non-security role? (Domain 7 credit)
-
Have I been involved in any software development with security considerations? (Domain 8 credit)
Security professionals who move from IT generalist roles often have 2–3 more years of qualifying experience than they initially estimate when they conduct this analysis.
Related Articles in This Series
- CISSP Certification Complete Guide 2026
- Is CISSP Worth It? ROI Analysis for Security Professionals
- CISSP Study Plan: Week-by-Week Preparation Guide
FAQ
What counts as qualifying experience for CISSP?
Full-time paid work experience in one or more of the 8 CISSP CBK domains. The experience must be paid — volunteer, intern, or unpaid consulting work does not count. It does not need to be in a dedicated 'security' role; work in network engineering, software development, risk management, and similar fields can qualify if it covers CBK domain content.
Can I substitute a degree for CISSP experience?
Yes. A 4-year college degree (bachelor's or regional equivalent) or an approved credential from the (ISC)² approved list substitutes for 1 year of required experience, reducing the requirement from 5 years to 4 years.
What is the Associate of (ISC)² and how does it work?
If you pass the CISSP exam but don't yet have 5 years of qualifying experience, you become an Associate of (ISC)². This is a formal status recognized by (ISC)². You have 6 years from your exam date to accumulate the required experience and earn full CISSP certification.
About the authors
Sekiko Jo
CISSP and CCSP-certified security specialist focused on cloud threat modeling and security governance. A Registered Information Security Specialist (情報処理安全確保支援士) in Japan, she writes from hands-on incident-response experience.
Registered Information Security Specialist (情報処理安全確保支援士), Japan