Skip to content
Cybridia CISSP® exam prep

Endorsement · Understand

Associate of ISC2: the status of those who passed the exam without the experience

Anyone who passes the CISSP exam without the required experience becomes an Associate of ISC2 and gets a window in which to accumulate the missing years — five years according to one candidate, six according to another, the exact duration being set by ISC2. During that period, you may present yourself neither as a CISSP nor as "CISSP In Progress", under the ISC2 code of ethics.

Updated on 7 min de lecture Par l'équipe Cybridia

Passing the exam without the five years of experience makes you an Associate of ISC2: a membership, not a certification, together with a window in which to accumulate the missing years. In the accounts, the subject comes up in two forms: the disappointment of those who discover that passing does not amount to certification, and the deliberate choice — sit the exam early, while the material is still fresh, and let the experience build up afterwards. The official reference on these rules remains isc2.org.

What is Associate of ISC2 status?

It is the status given to anyone who passes the exam without meeting the experience condition. The clearest formulation in the accounts comes from a recent graduate in accounting and business analytics, with no professional security experience at all, who sat and passed the exam at one hundred questions:

"Technically anyone can take it, but passing the exam without the required experience will only allow for an Associate of ISC2 membership without the certification (which is my case)."

Two points stand out. This is a membership, not a certification: the CISSP credential is not acquired, not even partially. And the exam itself is not gated by experience — the check happens at the next stage, endorsement.

An Associate is not without obligations, however. One of them describes his situation like this: "i will have to annually pay my membership maintenance and gather 15 CPE". He adds that he is counting on his Security+ to take one year off the five. Exact amounts and volumes are ISC2 rules, to be confirmed at source.

How long do you have to complete your experience?

This is the point where the accounts contradict each other most bluntly. Within one and the same discussion thread, two members give two different answers:

Claim in the accounts Original wording Status
5 years "You can be an associate and you have 5 years to gain the 5 years of expierence" unsourced
6 years "You actually have 6 years as an associate to gain your experience." unsourced, presented as a correction

Neither message points to an official page, and we do not settle it: the applicable duration is the one published on isc2.org.

The accounts are equally silent on what happens at the end of that window — whether the pass lapses, whether an extension is possible, whether the exam has to be sat again: no member describes reaching that deadline.

What can you write on your resume and your LinkedIn profile?

This is the point on which the community is firmest, and the only one it explicitly ties to the ISC2 code of ethics:

"You are not a CISSP and you cannot refer to yourself as being a CISSP until you've been properly credentialed by ISC2. You can't even put things like "CISSP In Progress" or "Passed CISSP exam" on your resume. At most, you can only put "Associate of ISC2". And quite frankly, most recruiters aren't even going to know what that means."

Three mentions are ruled out in one go: the credential itself, the "in progress" formula and any mention of having passed the exam. The justification is ethical — the ISC2 code of ethics requires members to be honest about their professional claims, and its text is published by ISC2.

In practice, cautious candidates carry the rule over to what they say out loud. One of them, in a job interview before his endorsement, sums up his line of conduct: "I was very careful to state that I had only provisionally passed CISSP".

Does the status carry any weight with recruiters?

It depends who is reading it: the accounts give two opposite answers, and both are credible depending on the context.

Scepticism dominates the general comments: "most recruiters aren't even going to know what that means". The argument is simple — a credential nobody recognises does not work as a signal. It comes with the reminder, also widely shared, that the CISSP is not an entry-level certification and that adverts presenting it as a "nice to have" for a junior role are out of touch.

Conversely, a twenty-year-old candidate is perfectly comfortable with his status: "I know, associate of isc2 works for all of my immediate goals though". His employer only required that the exam be passed — a common situation in organisations that fund the certification or impose it contractually.

One clarification on this profile, because it appears elsewhere on this site from another angle: it is the same author in both cases, that of the thread "Failed at 100, passed at 100". This candidate reports around three years of cybersecurity experience; he was nineteen at his first attempt, which he failed at the hundredth question after betting everything on the managerial mindset at the expense of the technical side, and he passed on his second attempt at twenty. It is that initial failure that is cited in our accounts of candidates without cybersecurity experience; it is the pass that earns him his Associate status here. One path, two stages — not two people with contradictory outcomes.

The value of the status therefore depends on who is reading it: close to zero with a generalist recruiter, real with an employer who knows how the scheme works. Nowhere do the candidates' accounts quantify the effect of Associate status on salaries or interviews — the stories of immediate returns, recruiter approaches and pay rises included, all concern fully endorsed candidates; they are gathered in the career outcomes of the certified.

Should you sit the exam early or wait until you have the experience?

The debate exists on the forum and is not settled. The arguments found in the candidates' accounts, on both sides:

  • Sitting early: the exam is passed while the material is still fresh, the Associate clock runs while the experience accumulates, and some employers are satisfied with the pass. The most striking case is that of a candidate fully endorsed at 23 thanks to 4.5 years of experience and the SSCP waiver: he was looking for someone younger than himself and noted that "many were still Associates of ISC2 rather than fully certified CISSP holders with verified experience".
  • Waiting: the opposing position, expressed in reaction to that same account, rests on the spirit of the certification. "CISSP was not meant for a 23-year-old. […] the intent of this certification was for seasoned professionals not for someone that can pass a test." An immediate counter-example is put to him in the same thread: a woman who passed at 22, also a PMP holder.

A technical argument is added: operational experience does not necessarily prepare you for the exam, which expects the reasoning of a manager. "5 years of experience is great, but if it's not in that managerial role then it won't be as useful as you think." Waiting until you have the five years is therefore no guarantee of doing better in the exam.

The candidates' accounts do not decide between these positions and contain no comparative data on pass rates by seniority.

How do you go from Associate to certified CISSP?

By accumulating the missing experience, then having it validated through the endorsement procedure — identical to that of candidates who meet the condition from the outset. Yet it is the least documented part of the accounts: the fifty accounts analysed contain several candidates who became Associates, but no detailed story of a conversion to certified CISSP. Two points do stand out nonetheless:

  • the one-year waiver remains available in that calculation, several Associates saying they are counting on it (Security+, SSCP);
  • in the meantime, the Associate maintains their membership: annual fee and CPE credits.

For the rest — reopening the application, a new endorser, the fate of CPE credits already earned, the deadline reached without the experience — the procedure to follow is the one described by ISC2.

To assess whether your current background brings you closer to the five years, see the experience required for the CISSP. On where these accounts come from and their limits, see our method, and all the subjects covered on the blog or on Cybridia.

Frequently asked questions

Can you sit the CISSP exam without the required experience?

Yes: anyone can sit it, but passing without the required experience only gives access to Associate of ISC2 membership, without the certification. The official registration conditions are published on isc2.org.

How long does Associate of ISC2 status last?

Five years according to one candidate, six according to another — two unsourced claims in the same thread. The exact duration is an ISC2 rule, to be checked on isc2.org.

Can you write "CISSP" or "CISSP In Progress" on your resume in the meantime?

No: neither "CISSP", nor "CISSP In Progress", nor "Passed CISSP exam", the prohibition stemming from the ISC2 code of ethics. At most "Associate of ISC2".

Does Associate status impress recruiters?

It depends who is reading it: a widely shared comment warns that most recruiters do not know what the term means, but some employers only ask that the exam be passed — as with the twenty-year-old candidate in the "Failed at 100, passed at 100" thread, who passed on his second attempt.

Does an Associate have annual obligations?

Yes: one Associate describes an annual fee and fifteen CPE credits to earn each year. The exact amount and number are ISC2 rules, to be confirmed on the official site.

Where does this information come from?

This article draws on the public reports of several thousand candidates, published over the last three years (24 July 2023 to 24 July 2026) and synthesised topic by topic. Quoted extracts are anonymised. Our method in detail.

More on this topic

Explore other topics