Doc CC-03Rev 2026-10Class study materialRead ~8 min
CISSP requirements: experience, waivers, endorsement — and what it costs
To earn the ISC2 CISSP (Certified Information Systems Security Professional), you need five years of cumulative work in at least two of the eight exam domains, a pass on the exam, and an endorsement completed within 9 months of your exam date. One of the five years can be waived with a relevant degree or one approved credential, and if you have fewer years you can still sit the exam and finish the experience later as an Associate of ISC2.
Exam readout
- Format
- CAT, every language
- Items
- 100–150
- Time
- 3 hours
- Pass mark
- 700 / 1000 scaled
- Outline
- 8 domains · Apr 2024
The requirements at a glance
| Ref | Requirement | The rule | Where people slip |
|---|---|---|---|
| R-01 | Experience | 5 years cumulative, in 2 or more of the 8 domains | Counting years in one domain only |
| R-02 | Waiver | Up to 1 year: a relevant degree or one approved credential | Expecting a degree plus a certificate to waive two years |
| R-03 | Exam | Pass the CAT exam at a Pearson VUE test center | Booking before checking the name on your ID matches the registration |
| R-04 | Endorsement | Completed within 9 months of the exam date | Starting the paperwork in month eight |
| R-05 | Maintenance | 120 CPE per three-year cycle, 90 of them Group A, plus an annual fee | Treating 40 credits a year as the hard rule |
The five-year experience rule
ISC2 asks for a minimum of five years of cumulative work experience in two or more of the eight CISSP domains. “Cumulative” means the years do not have to be consecutive or with one employer, and the work does not have to carry a security job title — a network engineer running firewall changes or a developer doing secure code review is working in a domain, whatever the business card says.
Two domains is the floor, and it is rarely a problem in practice. Most security jobs touch Security Operations (Domain 7) and at least one neighbor, such as Communication and Network Security (Domain 4) or Identity and Access Management (Domain 5). What trips people is a career spent entirely inside one narrow function; in that case, describe the adjacent work you already do rather than inventing new work.
What counts as a year
Full-time means at least 35 hours a week. Part-time work of 20 to 34 hours a week also counts, at the rate of 2,080 hours for 12 months of experience. Internships count too, paid or unpaid, as long as the organization can document them on its letterhead.
What the endorser will look at
Job titles, dates and duties that map onto the domains. A tidy one-paragraph description per role, written in the language of the outline, saves a round of questions later. Writing it is about as exciting as it sounds, which is why most people postpone it until it is urgent.
The experience arithmetic
Three lines settle most “do I qualify?” questions before you open a calendar.
Years you must show
5 − waiver (0 or 1)The waiver is capped at one year, whatever combination of degree and credentials you hold.
Part-time conversion
2,080 hours = 12 monthsApplies to work of 20–34 hours a week.
Associate window
6 years to earn the remainderOnly relevant if you pass before the experience is complete.
The one-year waiver
You can knock one year off the five with either a relevant bachelor’s or master’s degree — computer science, information technology or a related field — or one credential from ISC2’s approved list. Only one waiver applies, so a degree plus a credential still leaves four years to show.
The approved list changes from time to time, which is why it is better read at the source than copied: see the experience page on isc2.org. As of October 2026 it includes credentials such as CompTIA Security+, ISACA’s CISM and ISC2’s own SSCP and CCSP.
Five candidates, worked out
The rules are short; applying them to a real career is where the questions start. Each case assumes the work maps to at least two domains.
| Ref | Candidate | Experience shown | Waiver | Result |
|---|---|---|---|---|
| R-01 | SOC analyst with Security+ | 4 years full-time | 1 year (approved credential) | Meets the five years — can be endorsed after the pass |
| R-02 | Network administrator with a CS degree | 3 years full-time | 1 year (degree) | 4 of 5 — passes as an Associate, needs one more year |
| R-03 | Degree and Security+ | 3 years full-time | Still 1 year — only one waiver applies | 4 of 5 — Associate; the second qualification adds nothing here |
| R-04 | IT auditor with CISA | 5 years full-time | None — CISA is not on the list | Meets the five years on experience alone |
| R-05 | Part-timer at 25 hours a week, with a degree | 4 years × 52 weeks × 25 h = 5,200 hours ≈ 2.5 years | 1 year (degree) | About 3.5 of 5 — Associate, with time to spare inside the six-year window |
No experience yet: the Associate of ISC2
The experience rule governs the credential, not the exam seat. You can register and sit the exam with any amount of experience. Pass without the five years and you become an Associate of ISC2, with six years to earn the experience and then complete the endorsement.
Associates keep membership obligations in the meantime, including an annual fee and yearly CPE credits, but may not use the CISSP designation. If the five years arrive sooner, the upgrade happens sooner. What the status means for your career is covered on CISSP certification; here the only point is that it postpones the experience requirement without reducing it.
Endorsement after you pass
Endorsement turns a pass into a certification. It is paperwork, and it has a deadline.
Step 01
Start the application
Apply for endorsement through your ISC2 account after the pass. The deadline is 9 months from the exam date, not from the day you remember.
Step 02
Find an endorser
An active ISC2-certified professional in good standing reviews your experience and attests to it. If you do not know one, ISC2 can act as endorser, with proof of employment.
Step 03
Document the experience
List each role with dates, hours and duties mapped to at least two of the eight domains. Internships need documentation on the organization’s letterhead.
Step 04
Agree to the Code of Ethics
Every applicant commits to the ISC2 Code of Ethics as part of certification. The canons are also examinable material in Domain 1.
Step 05
Wait for approval
Review usually takes a few weeks. Your certification begins on approval, and the first three-year CPE cycle with it.
Staying certified
Certification is a subscription to good standing, not a one-time event. Each three-year cycle you need 120 CPE credits, at least 90 of them in Group A — activity tied to the domains, such as training, conference sessions, writing or teaching security. The remaining 30 can be Group A or Group B.
ISC2 suggests a pace of about 40 credits a year, and that is a suggestion: the binding number is the three-year total. The annual maintenance fee, by contrast, is due every year. Members who fall behind on either risk suspension, so the calendar reminder is worth setting on the day you are approved.
What CISSP costs
The total cost of CISSP is the exam fee plus an annual maintenance fee for as long as you hold it, plus whatever you choose to spend on preparation. The exam price varies by region and currency, taxes depend on where you test, and ISC2 adjusts both from time to time, so check the current figure on the ISC2 exam pricing page on the day you book. A price printed on a third-party page — including this one, which is why there is none — is a historical document.
| Cost item | When it applies | Notes |
|---|---|---|
| Exam fee | Once per attempt, at booking | Set by region and currency; local taxes apply by test location |
| Reschedule or cancellation fee | Only if you move or cancel the appointment | Separate fixed charges; a cancellation costs more than a reschedule |
| Retake | After a fail | A new purchase, with test-free waiting periods between attempts — see the CISSP exam page |
| Annual maintenance fee | Every year once certified; a smaller fee as an Associate | Paid for as long as you hold the credential |
| CPE activities | Through each three-year cycle | Many credits can be earned at no cost; paid training is optional |
| Preparation | Before the exam | Optional: books, courses and practice items vary widely in price |
Before you book the exam
- Your work history shows at least two of the eight domains — or you accept starting as an Associate.
- You know whether a degree or an approved credential waives one year, and you have checked it against the current ISC2 list.
- You have the name of a potential endorser, or you are ready to request ISC2 as endorser.
- Your registration name matches your government ID exactly.
- You have checked the current exam price and reschedule rules on isc2.org.
- You have done a full timed run in practice — the CISSP practice test has a Timed 60 mode for pacing.
Three Asset Security questions
Domain 2, Asset Security, is 10% of the current outline — data ownership, classification, retention and disposal. Three original practice items, each option explained. They check your reasoning, not whether you meet the requirements; the domains themselves are mapped in the study guide.
Domain drill
Item 01 / 03
Answer, then read why each option is right or wrong. Keys 1–4 pick, N goes next.
A recent compliance audit revealed that despite having a robust, executive-approved media disposal policy, an organization could not prove its hard drives were securely sanitized. Which component is MOST likely missing from the organization's governance framework?
Rationale
Pick an answer. The reasoning for every option lands here — including why the wrong ones looked right.
Questions people ask
Q01How many years of experience is required for CISSP?
Five years of cumulative work in at least two of the eight CISSP domains. A relevant degree or one approved credential can waive one year, so the minimum you must show is four. Part-time work and documented internships, paid or unpaid, count.
Q02Can I take CISSP without 5 years experience?
Yes. Anyone can sit the exam. If you pass without the experience you become an Associate of ISC2 and have six years to earn the five years, then complete endorsement.
Q03Who is eligible for CISSP?
Anyone can take the exam. To be certified you need the experience requirement (or Associate status while you earn it), a pass, an approved endorsement within 9 months of the exam, and agreement to the ISC2 Code of Ethics.
Q04How much does a CISSP exam cost?
The exam fee depends on your region and currency, plus local taxes, and ISC2 changes it periodically — check the current price on the ISC2 pricing page. On top of the exam, certified members pay an annual maintenance fee, and retakes are a new purchase.
Q05Does CISA waive a year of CISSP experience?
No. CISA is not on ISC2’s approved-credential list as of October 2026. CISM, Security+, SSCP and CCSP are among the credentials that are; check the current list before relying on it.
Q06Do I need a degree to get CISSP?
No. A degree is one of two ways to waive a single year of experience. Without one, you show the full five years.
Field kit
Earning the five years? Practice while you do
The CISSP prep app keeps the domain drills on your phone, with the reasoning behind every option, on iPhone and Android.