CISSP Experience Requirements

Candidates must have a minimum of five years cumulative, full-time experience in two or more of the eight domains of the current CISSP Exam Outline. Earning a post-secondary degree (bachelors or masters) in computer science, information technology (IT) or related fields may satisfy up to one year of the required experience or an additional credential from the ISC2 approved list may satisfy up to one year of the required experience. Part-time work and internships may also count towards the experience requirement.

A candidate who doesn't have the required experience to become a CISSP may become an Associate of ISC2 by successfully passing the CISSP examination. The Associate of ISC2 will then have six years to earn the five years required experience.

Work Experience

Your work experience must fall within two or more of the eight domains of the ISC2 CISSP Exam Outline:

  • Domain 1. Security and Risk Management
  • Domain 2. Asset Security
  • Domain 3. Security Architecture and Engineering
  • Domain 4. Communication and Network Security
  • Domain 5. Identity and Access Management (IAM)
  • Domain 6. Security Assessment and Testing
  • Domain 7. Security Operations
  • Domain 8. Software Development Security

Full-Time Experience: Your work experience is accrued monthly. Thus, you must have worked a minimum of 35 hours/week for four weeks in order to accrue one month of work experience.

Part-Time Experience: Your part-time experience cannot be less than 20 hours a week and no more than 34 hours a week.

  • 1040 hours of part-time = 6 months of full time experience
  • 2080 hours of part-time = 12 months of full time experience

Internship: Paid or unpaid internship is acceptable. You will need documentation on company/organization letterhead confirming your position as an intern. If you are interning at a school, the document can be on the registrar's stationery.

Relevant Education or Certifications Held

You may satisfy one year of required experience through holding one of the following below (you will then need four years of relevant work experience):

Four-Year College Degree or Regional Equivalent

You can substitute a maximum of one year of work experience if you hold one of the following:

  • A four-year college degree or regional equivalent
  • An advanced degree in information security from the U.S. National Center of Academic Excellence in Information Assurance Education (CAE/IAE).

OR

Approved Credential on the ISC2 Approved List
You can satisfy one year work experience if you hold one of the approved credentials on the below ISC2 approved list.

  • AWS Certified Security - Specialty
  • Certified in Governance, Risk and Compliance (CGRC)
  • Certified Cloud Security Professional (CCSP)
  • Certified Computer Examiner (CCE)
  • Certified Ethical Hacker v8 or higher
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Certified Internal Auditor (CIA)
  • Certified Protection Professional (CPP) from ASIS
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Secure Software Lifecycle Professional (CSSLP)
  • Certified Wireless Security Professional (CWSP)
  • Cisco Certified CyberOps Associate/Professional
  • Cisco Certified Internetwork Expert (CCIE) Security
  • Cisco Certified Network Associate Security (CCNA Security)
  • Cisco Certified Network Professional Security (CCNP Security)
  • CIW Web Security Professional
  • CIW Web Security Specialist
  • CompTIA Advanced Security Practitioner (CASP+)
  • CompTIA CySA+
  • CompTIA Security+
  • Computer Hacking Forensic Investigator (CHFI)
  • CSA Certificate of Cloud Security Knowledge (CCSK)
  • EC-Council Certified Security Specialist (ECSS)
  • EC-Council Certified SOC Analyst (CSA)
  • GIAC Certified Enterprise Defender (GCED)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Cyber Threat Intelligence (GCTI)
  • GIAC Global Industrial Cyber Security Professional (GICSP)
  • GIAC Information Security Fundamentals (GISF)
  • GIAC Information Security Professional (GISP)
  • GIAC Security Essentials Certificate (GSEC)
  • GIAC Security Leadership Certification (GSLC)
  • GIAC Strategic Planning, Policy, and Leadership (GSTRT)
  • GIAC Systems and Network Auditor (GSNA)
  • HealthCare Information Security and Privacy Practitioner (HCISPP)
  • Information Security Management Systems Lead Auditor (IRCA)
  • Information Security Management Systems Principal Auditor (IRCA)
  • Juniper Networks Certified Internet Expert (JNCIE-SEC)
  • Microsoft Identity and Access Management
  • Microsoft Security Operations Analyst
  • Microsoft Certified Cybersecurity Architect
  • Offensive Security Certified Professional/Expert (OSCP/E)
  • Systems Security Certified Practitioner (SSCP)