Cyber Security

Understanding the CISSP Experience Requirements Explained

iCertGlobal December 19, 2024 Cyber Security
Understanding the CISSP Experience Requirements Explained

The CISSP certification is a top credential in cybersecurity. It is well-known and respected. It is a benchmark for those wanting to prove their expertise and commitment to info security. However, candidates must meet experience requirements before taking the CISSP exam. This often raises questions for aspiring professionals. This blog will detail the requirements to qualify for the CISSP certification.

CISSP Experience Requirements at a Glance

To earn the CISSP certification, candidates must satisfy both examination and professional experience requirements established by (ISC)².

Requirement Details
Required Experience 5 years of paid work experience
Experience Domains Minimum 2 of the 8 CISSP CBK domains
Education Waiver 1-year reduction available through an approved degree or credential
Certification Provider (ISC)²
Experience Verification Required through endorsement process
Certification Validity Maintained through CPE credits and annual fees

Why Experience Requirements Matter

The CISSP certification is not just an exam. It shows a practical understanding of real-world cybersecurity challenges. The requirements ensure certified professionals know security practices and principles. This criterion helps keep the certification's value in the industry.

The CISSP Experience Requirements at a Glance

To qualify for the CISSP certification, candidates must meet the following experience requirements:

1. Five Years of Paid Work Experience: Candidates must have at least five years of paid work in two or more of the eight CISSP CBK domains. These domains are:

- Security and Risk Management

- Asset Security

- Security Architecture and Engineering

- Communication and Network Security

- Identity and Access Management (IAM)

- Security Assessment and Testing

- Security Operations

- Software Development Security

2. Education Waivers: Candidates can reduce the required work experience by one year if they have one of the following:

A four-year college degree in information security or a related field. A regional equivalent is also acceptable.

- An approved credential from the (ISC)² list, such as the CompTIA Security+ or CEH certification.

3. Associate of (ISC)² Option: Candidates without the required experience may earn the Associate of (ISC)² designation. This lets candidates take the CISSP exam. They must gain the required experience within six years to achieve full certification.

Understanding the CISSP CBK Domains

The eight CISSP CBK domains form the foundation of the certification. Let’s explore each domain briefly to understand where your experience might fit:

1. Security and Risk Management: It covers governance, risk, compliance, and the legal aspects of info security.

2. Asset Security: Covers the classification, handling, and protection of organizational information and assets.

3. Security Architecture and Engineering: Deals with designing and managing secure frameworks and environments.

4. Communication and Network Security: It secures networks and protects data in transit.

5. Identity and Access Management (IAM): Centers on authentication, authorization, and identity management.

6. Security Assessment and Testing: It tests and audits security systems and processes.

7. Security Operations: Involves incident management, disaster recovery, and operational continuity.

8. Software Development Security: Covers secure coding practices, application vulnerabilities, and development lifecycle management.

Candidates must have work experience in at least two of these domains to qualify for the CISSP certification.

CISSP Exam Format, Duration and Cost

Meeting the CISSP experience requirements is only one step. Candidates must also successfully complete the CISSP examination before applying for certification.

CISSP Exam Format

Exam Feature Details
Exam Provider (ISC)²
Question Format Computer Adaptive Testing (CAT)
Number of Questions 100–150 questions
Exam Duration Up to 3 hours
Passing Score 700 out of 1000
Exam Delivery Pearson VUE testing centers and online options where available

The CISSP exam evaluates practical knowledge across eight security domains, including security governance, risk management, architecture, operations, and software security.


CISSP Exam Fee

The CISSP certification cost includes examination registration and ongoing maintenance expenses.

Expense Cost
CISSP Exam Registration Fee $749
Annual Maintenance Fee (AMF) $125/year
CPE Requirements Required every 3-year certification cycle

Candidates should also consider preparation expenses such as:

  • Official (ISC)² study materials
  • Practice exams
  • Training courses
  • Boot camps

What Counts as Valid Work Experience?

Not all cybersecurity experience qualifies for CISSP certification. To ensure your experience counts, it must meet the following criteria:

1. Paid Professional Work: Only paid roles in a professional setting qualify. Internships or unpaid positions typically do not count unless explicitly recognized by (ISC)².

2. Full-Time or Part-Time Roles: Part-time work is acceptable. But, it requires extra docs to prove its equivalence to full-time experience.

3. Domain Relevance: Your work must align with the CISSP CBK domains.

4. Cumulative Experience: Roles or organisations can add to the required five years of experience.

Examples of qualifying roles include:

- Security analyst

- Systems engineer

- IT auditor

- Network administrator with security responsibilities

- Penetration tester

Documenting Your Experience

When applying for the CISSP certification, you must prove your work experience. Here are some tips for documenting your experience effectively:

1. Job Descriptions: Outline your duties and their links to the CISSP CBK domains.

2. Verification by Endorsers: A current (ISC)²-certified professional, like a CISSP holder, must endorse your experience. They will verify your claims before you receive the certification.

3. Supporting Documents: Keep contracts, job offers, or any proof of your work experience.

CISSP Endorsement Process: What Happens After You Pass?

Passing the CISSP exam does not immediately make you CISSP-certified.

You must complete the CISSP endorsement process.

The endorsement process allows ISC2 to confirm that your professional experience satisfies the certification requirements.

How Long Do You Have to Complete CISSP Endorsement?

After passing the CISSP exam, candidates have nine months to complete the endorsement process.

CISSP Endorsement Process Step by Step

Step 1: Pass the CISSP Exam

First, successfully complete the CISSP examination.

After ISC2 confirms that you passed, you can proceed with your certification application.

Step 2: Submit Your CISSP Certification Application

Your application will include information about your professional experience.

Be prepared to provide details such as:

  • Employer information
  • Job titles
  • Employment dates
  • Professional responsibilities
  • CISSP domains related to your work
  • Education or credentials used for an experience waiver

Accuracy is important because ISC2 may verify the information.

Step 3: Select a CISSP Endorser

The application normally requires endorsement from an ISC2-certified professional who can verify your professional experience.

ISC2 says the endorsement application requires the endorser's ISC2 Member ID and surname.

Your endorser should be able to confirm that the experience described in your application is legitimate and relevant.

What If You Don't Know a CISSP to Endorse You?

This is a frequent concern, but it does not prevent you from becoming certified.

If you do not know an appropriate ISC2-certified professional, you can request ISC2 to act as your endorser.

In that situation, proof of employment will be required so ISC2 can verify your professional experience.

Step 4: ISC2 Reviews Your Application

ISC2 reviews your certification application and endorsement.

Some candidates may also be selected for an audit and asked to provide additional supporting information.

Step 5: Pay Your First Annual Maintenance Fee

After your certification application has been approved, you must pay the applicable Annual Maintenance Fee.

Once the certification requirements are completed, your CISSP certification and membership cycle can begin.

The Education Waiver: Saving Time

The one-year experience waiver can be a game-changer for many candidates. If you qualify for the waiver through a degree, you need four years of relevant work experience. Some of the approved credentials include:

- CompTIA Security+

- Certified Ethical Hacker (CEH)

- Cisco Certified Network Associate Security (CCNA Security)

Associate of (ISC)²: A Path for Beginners

If you're new to cybersecurity or lack experience, try the Associate of (ISC)². It is a great alternative. Passing the CISSP exam and earning the designation gives you six years to get the required work experience. This option lets you show your knowledge and commitment to the field. It also builds your practical experience.

CISSP Exam Format and Fee in 2026

Once you understand the CISSP experience requirements, the next major step is preparing for the certification exam.

What Is the Current CISSP Exam Format?

The CISSP exam currently uses Computerized Adaptive Testing (CAT).

Current ISC2 exam specifications are:

CISSP Exam Detail Current Format
Exam method Computerized Adaptive Testing (CAT)
Number of items 100–150
Maximum exam time 3 hours
Passing score 700 out of 1,000
Question types Multiple choice and advanced item types
Exam domains 8
Testing provider Pearson VUE authorized testing centers

Because CAT adapts as the examination progresses, not every candidate receives exactly the same number of questions.

What Is the CISSP Exam Fee?

For the Americas and many other regions, the standard CISSP exam registration price is currently:

US$749.

Regional pricing may differ.

ISC2 currently lists, for example:

  • Americas and many other regions: US$749
  • Asia Pacific: US$749
  • Middle East: US$749
  • EMEA: EUR 719.04
  • United Kingdom: GBP 606.69

Taxes and final pricing may depend on the location where the exam is administered.

Candidates should always verify current pricing with ISC2 and Pearson VUE before registering.

Can You Take the CISSP Exam Online?

No, not currently.

ISC2 says its certification examinations are not available as online-proctored exams at this time.

After testing online-proctored examination programs, ISC2 concluded that the available methods did not meet its exam-security requirements.

CISSP candidates should therefore plan to take the exam at an authorized Pearson VUE testing center.

What Score Do You Need to Pass CISSP?

The CISSP passing standard is 700 out of 1,000 points.

Because CISSP uses adaptive testing, candidates should focus on understanding and applying cybersecurity principles rather than simply memorizing practice questions.

CISSP Experience Requirements

The Certified Information Systems Security Professional (CISSP) certification is one of the most recognized cybersecurity credentials for experienced security professionals.

But passing the CISSP exam alone does not make you CISSP-certified.

To earn the certification, you must meet ISC2's professional experience requirements, pass the CISSP exam, complete the endorsement process, and maintain your certification through Continuing Professional Education (CPE) credits and the Annual Maintenance Fee (AMF).

This guide explains the complete CISSP certification journey, including experience requirements, experience waivers, CPE requirements, endorsement, maintenance fees and the current CISSP exam format and cost.

To qualify for CISSP certification, candidates generally need at least five years of cumulative professional work experience in two or more of the eight CISSP domains. One year of the experience requirement may be waived if you hold an eligible post-secondary degree or an approved credential.ISC2 confirms that CISSP candidates need five years of cumulative experience across at least two CISSP domains. A qualifying bachelor's or master's degree in computer science, IT, or a related area—or an approved credential—can satisfy up to one year of the experience requirement.

CISSP Requirement Current Requirement
Professional experience 5 years
Domains required At least 2 of 8 CISSP domains
Experience waiver Up to 1 year
Exam Pass the CISSP examination
Endorsement Required after passing
CPE requirement 120 credits over 3 years
Annual Maintenance Fee US$135 per year
Associate option Available if experience is incomplete

Tips for Gaining CISSP-Qualifying Experience

For those who meet the CISSP experience requirements, here are some tips to gain relevant experience:

1. Target Relevant Roles: Look for roles that are within the CISSP CBK domains. Examples are IT security analyst, risk manager, or network security engineer.

2. Pursue Internships: Unpaid internships don't typically count. Some structured internships in cybersecurity may qualify if they meet (ISC)² criteria.

3. Seek Cross-Functional Opportunities: In your role, take on tasks that fit the CISSP domains.

4. Use Certifications: Entry-level certs, like CompTIA Security+, can boost your resume. They can open doors to jobs.

Do You Need a Cybersecurity Job Title for CISSP?

No. You do not need a job title that specifically includes “security” to qualify for CISSP.

Your responsibilities matter more than your job title.

Examples of qualifying roles:

  • Security Analyst
  • Network Engineer with security responsibilities
  • Systems Administrator managing access controls
  • IT Auditor
  • Cloud Security Engineer
  • Risk Analyst
  • Security Consultant

Your experience must demonstrate responsibilities related to one or more CISSP CBK domains.

CISSP Endorsement Process Explained

Passing the CISSP exam does not automatically award certification. Candidates must complete the (ISC)² endorsement process to verify their professional experience.

Steps in the CISSP Endorsement Process

Step 1: Pass the CISSP Exam

Candidates must achieve the required passing score before starting endorsement.

Step 2: Submit Certification Application

Applicants provide:

  • Employment history
  • Professional experience details
  • Certification information
  • Supporting documentation

Step 3: Obtain an Endorser

The applicant needs an endorsement from:

  • An active (ISC)²-certified professional, preferably a CISSP holder

The endorser confirms that:

  • Your work experience is accurate
  • Your responsibilities align with CISSP domains
  • Your professional background meets certification requirements

Step 4: Application Review

(ISC)² reviews the submission and approves certification after validating eligibility.

How to obtain CISSP certification?

We are an Education Technology company providing certification training courses to accelerate careers of working professionals worldwide. We impart training through instructor-led classroom workshops, instructor-led live virtual training sessions, and self-paced e-learning courses.

We have successfully conducted training sessions in 108 countries across the globe and enabled thousands of working professionals to enhance the scope of their careers.

Our enterprise training portfolio includes in-demand and globally recognized certification training courses in Project Management, Quality Management, Business Analysis, IT Service Management, Agile and Scrum, Cyber Security, Data Science, and Emerging Technologies. Download our Enterprise Training Catalog from https://www.icertglobal.com/corporate-training-for-enterprises.php and https://www.icertglobal.com/index.php

Popular Courses include:

  • Project Management: PMP, CAPM ,PMI RMP
  • Quality Management: Six Sigma Black Belt ,Lean Six Sigma Green Belt, Lean Management, Minitab,CMMI
  • Business Analysis: CBAP, CCBA, ECBA
  • Agile Training: PMI-ACP , CSM , CSPO
  • Scrum Training: CSM
  • DevOps
  • Program Management: PgMP
  • Cloud Technology: Exin Cloud Computing
  • Citrix Client Adminisration: Citrix Cloud Administration

CISSP CPE Requirements: Maintaining Your Certification

After earning CISSP, professionals must maintain their certification through Continuing Professional Education (CPE) credits.

CISSP CPE Requirements at a Glance

Requirement Details
Certification Cycle 3 years
Total CPE Credits Required 120 CPE hours
Annual Requirement Approximately 40 CPE hours per year
Ethics Requirement Annual contribution toward ethics education
Purpose Maintain current cybersecurity knowledge

CPE activities can include:

  • Attending cybersecurity conferences
  • Completing training courses
  • Publishing security research
  • Teaching cybersecurity topics
  • Participating in professional events


CISSP Annual Maintenance Fee: How Much Is the AMF?

CISSP holders must pay an Annual Maintenance Fee, commonly called the CISSP AMF.

What Is the CISSP Annual Maintenance Fee in 2026?

The current CISSP Annual Maintenance Fee is:US$135 per year.

This is important because older CISSP articles may still list the previous $125 annual fee.

Do You Pay Multiple AMFs for Multiple ISC2 Certifications?

Generally, no.

ISC2 states that members holding multiple qualifying ISC2 certifications pay one US$135 annual maintenance fee, rather than a separate AMF for every certification.

For example, a professional holding CISSP and another ISC2 certification would not normally pay $135 separately for each credential.

Why Does ISC2 Charge an Annual Maintenance Fee?

The AMF supports the administration and maintenance of ISC2 certification and membership programs.

More importantly for CISSP holders, paying the AMF is one of the requirements for keeping certification status in good standing.

Therefore, maintaining CISSP requires both:

1. Completing the required CPE credits

and

2. Paying the Annual Maintenance Fee

CISSP Annual Maintenance Fee (AMF)

Certified professionals must pay an annual maintenance fee to keep their CISSP credential active.

Certification

Annual Maintenance Fee

CISSP

$125 per year

Failure to maintain annual fees and CPE requirements can result in certification suspension.

The annual maintenance fee supports:

  • Certification administration
  • Security professional community programs
  • Credential management services

Conclusion

The CISSP experience requirements are key to its value and credibility. Meeting these requirements may seem daunting. A detailed understanding of them and a good career plan can make the journey easier. Whether you're already in the field or just starting, gain experience in the CISSP CBK domains. This will set you on the path to earning this prestigious certification. Use resources, endorsements, and waivers to speed your progress. Then, you'll be on your way to joining the ranks of CISSP-certified professionals.

Frequently Asked Questions

How many years of experience do you need for CISSP?
You normally need five years of cumulative professional experience covering at least two CISSP domains. An eligible degree or approved credential may reduce the requirement by up to one year.
Can I get CISSP with four years of experience?
Yes, potentially.
If you qualify for the one-year education or credential waiver, you may satisfy the experience requirement with four years of relevant professional experience.
Can I take CISSP without experience?
You can take and pass the CISSP exam without meeting the full experience requirement.
If you do not yet qualify for certification, you can pursue the Associate of ISC2 designation and accumulate the required CISSP experience afterward.
How long do I have to gain CISSP experience as an Associate?
CISSP Associates can have up to six years to accumulate the required professional experience and complete the certification process.
How many CPE credits are required for CISSP?
CISSP holders must complete 120 CPE credits during each three-year certification cycle. ISC2 suggests approximately 40 per year.
What is the CISSP Annual Maintenance Fee?
The current CISSP AMF is US$135 per year.
How much does the CISSP exam cost?
The standard CISSP examination fee is currently US$749 in the Americas and many other regions, although pricing and taxes can vary depending on location.
How many questions are on the CISSP exam?
The CAT-format CISSP exam contains between 100 and 150 items and allows up to three hours.
Can CISSP be taken online from home?
Not currently. ISC2 directs candidates to authorized Pearson VUE testing centers.
Who can endorse my CISSP application?
An appropriate ISC2-certified professional can endorse your application. If you do not know someone who can endorse you, you can request ISC2 endorsement and provide the required proof of employment.
How long does CISSP endorsement have to be completed after the exam?
Candidates have nine months after passing the exam to complete the certification application and endorsement requirements.
Do I need a security job title for CISSP?
No. You do not need a job title such as “Security Analyst” or “Cybersecurity Engineer” to qualify for CISSP. What matters is whether your actual work responsibilities align with at least two of the eight CISSP domains. Roles such as network engineer, systems administrator, IT auditor or risk analyst may qualify if the work includes relevant security responsibilities.
Can I take CISSP with no experience?
Yes. You can take and pass the CISSP exam even if you do not yet have the required professional experience. If you pass the exam without meeting the experience requirement, you can become an Associate of ISC2 and work toward the required experience before applying for full CISSP certification.
iCert Global Author
About iCert Global

iCert Global is a leading provider of professional certification training courses worldwide. We offer a wide range of courses in project management, quality management, IT service management, and more, helping professionals achieve their career goals.

Write a Comment

Your email address will not be published. Required fields are marked (*)


Still have questions?
Schedule a free counselling session

Our experts are ready to help you with any questions about courses, admissions, or career paths. Get personalized guidance from industry professionals.

Request a Call Back

Search Online

We Accept

We Accept

Follow Us

"PMI®", "PMBOK®", "PMP®", "CAPM®" and "PMI-ACP®" are registered marks of the Project Management Institute, Inc. | "CSM", "CST" are Registered Trade Marks of The Scrum Alliance, USA. | COBIT® is a trademark of ISACA® registered in the United States and other countries.

Book Free Session

Book Free Session