TCL Portal

CISSP Experience Requirements 2026: How to Count Your 5 Years

Published:
  • #CISSP
  • #ISC2
  • #Experience Requirements
  • #Security Certification
  • #Career

Part of our CISSP Certification Complete Guide 2026 series.

The CISSP’s 5-year experience requirement trips up more candidates than the exam itself. The rules are more nuanced than they appear, and many professionals who believe they do not qualify actually do — and vice versa.

This guide breaks down how experience is counted, which roles qualify, the documentation process, and your options if you are short on experience.

The Core Requirement

To earn CISSP certification (not just pass the exam), you must have:

Minimum 5 years of cumulative, paid, full-time work experience in 2 or more of the 8 CISSP CBK domains.

The key words here: cumulative (does not need to be consecutive), paid (unpaid work does not count), and full-time (part-time experience may be counted proportionally, but this requires documentation and (ISC)² review).

Which Roles and Activities Count?

The CISSP experience requirement is domain-based, not job-title-based. Work experience counts toward a domain if your role directly involved that domain’s content, regardless of what your job title was.

Domain 1 — Security and Risk Management: Risk assessment activities, compliance program management, security policy development, BCP/DRP planning, security governance involvement.

Domain 2 — Asset Security: Data classification programs, data governance, DLP implementation, secure disposal procedures, privacy program involvement.

Domain 3 — Security Architecture and Engineering: Security architecture design, cryptography implementation, system security design, PKI administration, secure coding framework development.

Domain 4 — Communication and Network Security: Network security design, firewall administration, VPN management, network architecture with security considerations, wireless security implementation.

Domain 5 — Identity and Access Management: IAM system administration, PAM implementation, SSO design, access control policy management, identity governance.

Domain 6 — Security Assessment and Testing: Vulnerability assessment, penetration testing, security audits, log review programs, security testing in SDLC.

Domain 7 — Security Operations: Incident response, SOC operations, SIEM management, digital forensics, patch management, BCP/DRP operations.

Domain 8 — Software Development Security: Application security review, secure SDLC implementation, DevSecOps, code review programs, SAST/DAST operations.

Important: Network engineers, system administrators, software developers, and IT managers frequently have qualifying experience that they do not initially recognize as CISSP-eligible. Review the domain descriptions carefully before concluding you do not qualify.

What Does NOT Count as Qualifying Experience

Volunteer work: Experience must be paid employment. Security community contributions, pro bono consulting, or volunteer incident response do not count toward the experience requirement.

Student projects and academic work: University or bootcamp projects do not qualify, even if technically sophisticated.

Non-security IT work with no domain overlap: General help desk support, desktop support, and IT roles with no substantive intersection with CBK domains do not count.

Certifications and training: Holding security certifications or completing training does not substitute for experience (though certain credentials can substitute for one year of experience — see below).

Experience Substitutions

4-Year College Degree

A 4-year bachelor’s degree (or regional equivalent) substitutes for 1 year of the required experience, reducing the minimum from 5 years to 4 years.

The degree does not need to be in computer science, information technology, or security. Any 4-year degree qualifies.

Approved Credentials

Certain credentials from the (ISC)² approved list also substitute for 1 year of experience. The list includes credentials such as:

Check the current (ISC)² approved credentials list at the time of your application, as the list is periodically updated.

Maximum substitution: Only 1 year of experience can be substituted, regardless of how many degrees or approved credentials you hold.

How to Document Your Experience

When you apply for CISSP certification after passing the exam, you will need to document your qualifying experience. The process:

  1. Complete the (ISC)² online experience endorsement form
  2. Have a current CISSP holder endorse your experience (the endorser verifies your experience is genuine and qualifies; they do not need to have worked with you directly)
  3. (ISC)² reviews the endorsement — this process takes several weeks

What you will need to document:

Practical advice: Keep records of your professional experience as you accumulate it, not just when you need to document it for the endorsement. A running log of your security responsibilities by domain makes the documentation process significantly easier.

The Associate of (ISC)²: If You Are Short on Experience

If you pass the CISSP exam but have fewer than 5 years of qualifying experience, you become an Associate of (ISC)².

What Associate status includes:

What Associate status does not include:

Who benefits from the Associate path:

Professionals in the 3–4 year range of qualifying experience who want to invest in the credential now and complete the experience requirement while holding the Associate designation. If you are 1–2 years away from the experience requirement, sitting the exam early and spending time as an Associate can be a reasonable strategy — particularly if you are in a role where CISSP exam preparation is best done now rather than later (more available study time, strong study community at your employer, etc.).

If you are more than 2 years away from qualifying, I would generally suggest waiting. The exam’s “think like a senior security manager” questions are much easier to answer correctly when you have actually experienced security management challenges.

How Many Years Do I Actually Have?

A common source of confusion: security professionals often undercount their qualifying experience by applying too narrow a definition of “security work.”

Questions to ask yourself:

  1. Did any part of my non-security IT roles involve network architecture, access control, or system design with security implications? (Domain 3, 4, or 5 credit may apply)

  2. Have I done any risk assessment work — even informally — as part of a larger IT or business role? (Domain 1 credit)

  3. Have I been involved in any audit, compliance, or policy work? (Domain 1 or 6 credit)

  4. Have I managed or responded to any security incidents, even minor ones, in a non-security role? (Domain 7 credit)

  5. Have I been involved in any software development with security considerations? (Domain 8 credit)

Security professionals who move from IT generalist roles often have 2–3 more years of qualifying experience than they initially estimate when they conduct this analysis.


@jo_sekiko

FAQ

What counts as qualifying experience for CISSP?

Full-time paid work experience in one or more of the 8 CISSP CBK domains. The experience must be paid — volunteer, intern, or unpaid consulting work does not count. It does not need to be in a dedicated 'security' role; work in network engineering, software development, risk management, and similar fields can qualify if it covers CBK domain content.

Can I substitute a degree for CISSP experience?

Yes. A 4-year college degree (bachelor's or regional equivalent) or an approved credential from the (ISC)² approved list substitutes for 1 year of required experience, reducing the requirement from 5 years to 4 years.

What is the Associate of (ISC)² and how does it work?

If you pass the CISSP exam but don't yet have 5 years of qualifying experience, you become an Associate of (ISC)². This is a formal status recognized by (ISC)². You have 6 years from your exam date to accumulate the required experience and earn full CISSP certification.

About the authors