CISSP Experience Requirements, Actually Explained
A practical breakdown of CISSP's five-year experience rule, waivers, and how the Associate designation actually works.
Most people get tripped up by CISSP not because of the exam content, but because of the fine print around who's actually eligible to hold the credential. The exam itself is open to almost anyone willing to pay the fee. Certification is a different story, and that gap causes real confusion.
The five-year rule, broken down
(ISC)² requires five years of cumulative, paid work experience in at least two of the eight CISSP domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security.
That experience has to be full-time, and it doesn't need to come from a job with "security" in the title. If you were a sysadmin who managed patching, firewall rules, and access reviews, that counts toward Security Operations and IAM. A developer who did threat modeling and secure code review as part of their role can count time toward Software Development Security. The domains are broad on purpose, so read the domain descriptions on the (ISC)² website carefully before assuming you don't qualify.
Part-time work and internships can count too, but they're prorated. (ISC)² publishes a specific formula: 1,040 hours of part-time work equals six months of experience, and 2,080 hours equals one year. Unpaid internships don't count at all, regardless of hours.
The one-year waiver
If you hold a four-year college degree, or one of the credentials on (ISC)²'s approved list (things like a CompTIA Security+, CISA, or a relevant master's degree), you get a one-year waiver. That drops the requirement from five years to four. This waiver applies once, not per credential, so stacking three qualifying certifications doesn't get you three years off.```
Double-check the approved list before assuming your certification qualifies. It changes over time, and not every security cert on the market is on it.
What happens if you don't have enough experience yet
This is where the Associate of (ISC)² designation matters. If you pass the exam but don't yet have the required experience, you don't fail or get turned away — you become an Associate of (ISC)². You then have six years to accumulate the needed experience and submit it for review.
This trips people up constantly because job postings list "CISSP required" without distinguishing between full certification and Associate status. If you're early in your career, passing the exam and holding Associate status is still a meaningful signal to a hiring manager. It tells them you know the material even if you haven't logged the years yet.
Documenting and endorsing your experience
After passing the exam, you submit an endorsement application describing your relevant work history, domain by domain. This has to be endorsed by another (ISC)² certified professional in good standing who can attest to your experience being accurate. If you don't know anyone who holds a current (ISC)² certification, (ISC)² itself can act as the endorser, though that process takes longer and involves more scrutiny of your submitted history.
Be specific in your write-up. "Responsible for network security" is vague and invites follow-up questions. "Configured and maintained Palo Alto firewall rulesets, conducted quarterly access reviews for 200+ user accounts, and led incident response for phishing-related compromises" gives an endorser and (ISC)² something concrete to verify.
Common mistakes people make with the requirement
The biggest one is assuming certifications alone substitute for experience. They don't, aside from the single one-year waiver. A CEH, a Security+, and a cloud security certification stacked together still only earn you one year off, not three.
The second mistake is undercounting relevant experience because it didn't happen in a role labeled
Written with AI assistance, reviewed and published by Michal Pilch (CISSP), Korra Studio.
This is one note from the Korra Studio knowledge base — the platform pairs every topic with 1-to-1 mentoring.
Get started freearrow_forward