Endorsement · Understand
CISSP experience requirements: five years, two domains, one waiver
The CISSP requires five years of relevant experience spread across at least two of the eight CBK domains, reducible by one year — one only — through an approved degree or certification. The accounts show that roles without "security" in the job title are accepted, provided they are broken down into tasks that map to CBK domains.
You need five years of relevant professional experience, spread across at least two of the eight CBK domains, reducible by one year through an approved degree or certification. The CISSP is unusual in that the exam is only half the journey: the other half is administrative, and candidates almost always talk about it after the fact, once the "provisional pass" is in hand. What follows uses their original wording; the criteria that apply are published on the CISSP experience page at ISC2.
How many years of experience do you really need?
Five. That is the figure that comes up without exception in the accounts, and the most frequent reminder to candidates who show up to announce that they have passed:
"Passing the test is one of the requirements, the second is that you need to have 5 years of relevant work experience in order to fully receive the certification."
The comment comes with a link to the official page — a reflex shared by most members who answer on this subject. Under the same post, a blunter message: "Congrats, you still won't have the CISSP certification for years though".
This requirement also explains the forum's recurring irritation at badly calibrated job adverts — an irritation that connects to the wider debate about what the credential actually delivers, covered in is the CISSP worth it?:
"Anyone who lists the CISSP as "nice to have" for an "entry-level" job is full of crap. […] The CISSP REQUIRES five full years of cybersecurity experience in the eight exam domains before a person can be granted the certification. That is, by definition, NOT AN ENTRY LEVEL CERTIFICATION."
Worth noting: none of the fifty accounts analysed covers internships, apprenticeships, part-time work, contracting or military service — on those points, only the ISC2 documentation gives an answer.
Across how many CBK domains must this experience be spread?
At least two of the eight. The fullest formulation in the accounts is addressed to an IT technician with two years in the job and a stack of certifications:
"Do you have the required experience to obtain the CISSP certification? Your current certifications would only count as 1 year. You would then need at least 4 years of working experience in at least 2 of the 8 security domains."
In other words, you are not asked to cover all eight domains, nor to have held a role with the word "security" in its title. Two domains are enough, and it is this reading that makes the application accessible to many infrastructure profiles.
Can a degree or a certification reduce the requirement?
Yes, by one year — and one year only. The community is consistent on this cap: degree and certification do not stack beyond a single year.
| Supporting item reported | Effect described | Candidate's situation |
|---|---|---|
| Bachelor's (BS) in cybersecurity | 1 year waiver | 4+ years of cyber out of 13 years of IT — endorsed |
| SSCP (ISC2) | 1 year waiver | 4.5 years of cyber — fully endorsed at 23 |
| Security+ | 1 year waiver (mentioned by an Associate) | insufficient experience — went through Associate status |
| A stack of IT certifications | 1 year in total, no more | 2 years in the job — four years still to accumulate |
The two cases where endorsement was actually obtained are explicit:
"Four + years of cyber, but cumulative 13 years of IT overall. Also a BS in cybersecurity to get that one year waiver."
"I currently have 4.5 years of cybersecurity experience, and the remaining one-year experience requirement was fulfilled through the ISC2 SSCP waiver."
No account, on the other hand, cites a French qualification — a master's in security, an RNCP title, an engineering degree — nor a list of the certifications that grant the waiver: that list is maintained by ISC2 and changes over time, and it is the one to consult before building an application around a waiver.
Does my support, sysadmin or network role count as security experience?
This is the most frequent question in this theme, and the community's answer is far broader than candidates fear. The key comment is addressed to a hospital "IT Specialist" convinced he has no security experience at all:
"During your 2 years as an IT Specialist have you worked with asset management, account creation/ permissions, end point security settings, VPN, OS hardening..etc? People seem to only consider the in-depth areas in each of the 8 domains."
The exercise therefore consists of breaking a generalist role down into tasks, then mapping those tasks to CBK domains: a helpdesk that handles accounts and permissions touches identity management, a network administrator who configures VPN and hardens systems touches communications and operations security.
Which profiles actually made it through endorsement?
The candidates' accounts yield a list of backgrounds that made it through, or whose author declared meeting the conditions at the time of posting. Read it as a sample of what has been accepted or presented as acceptable — not as an official yardstick.
| Profile reported | Endorsement situation |
|---|---|
| Helpdesk, sysadmin then netadmin, role described as a dead end | Endorsed (April → May 2023), first cyber role afterwards |
| 4+ years of cyber out of 13 years of IT, plus a BS in cybersecurity | Endorsed |
| 4.5 years of cyber plus SSCP waiver, 23 years old | Fully endorsed |
| Around 5 years of experience plus SSCP | Application under verification ("experience box-checking") |
| 5 years of GRC exclusively | Considers himself qualified after passing |
| IAM (5 years) plus security architecture | Passed, conditions met |
| DBA 3.5 years, ISSO 1 year, IT risk analyst 2 years | Passed on the third attempt |
| Systems engineer, pentest, SOC, product security | Passed |
| IT lawyer who moved into privacy and risk, 8 years of security | Passed |
| Desktop support then infosec, 16 years | Passed |
| Big 4 consulting (7 years) plus 1.5 years as a security expert | Passed |
| Incident response, compliance, SOC 2 readiness in an MSP | Passed, endorsement pending |
The contrast with profiles that have no experience is sharp: those end up as Associate of ISC2, without a single reported exception in the accounts. Their exam stories are gathered in passing the CISSP without cybersecurity experience.
One final nuance recurs among very technical candidates: experience counts for the application, but does not guarantee passing the exam, which expects a manager's reasoning. One member puts it this way: "5 years of experience is great, but if it's not in that managerial role then it won't be as useful as you think". It is the most frequently self-diagnosed cause of failure in the accounts, detailed in why people fail the CISSP.
Do candidates get their experience rejected?
No endorsement rejection appears in the fifty accounts analysed. What they do contain are two intermediate situations, both followed by an approval:
- a request for additional information about the career timeline, received during processing, with the application validated two and a half weeks later;
- an in-depth review message ("audit review message"), experienced as an unpleasant surprise but with no bearing on the outcome.
This absence does not prove that rejections do not exist — a rejected candidate rarely posts — and the accounts say nothing about grounds for rejection or appeal routes.
What should you check with ISC2 before submitting your application?
The list of points these accounts leave open is short but decisive:
- the exact definition of full time, and how part-time work is treated;
- how internships and apprenticeships are counted;
- how military service or equivalent public service roles are counted;
- the up-to-date list of degrees and certifications that grant the waiver year, and in particular how French qualifications are handled;
- the exact duration of Associate status, on which two members of the same thread contradict each other (five years for one, six for the other);
- the grounds for rejection and the possible appeals.
On each of these points, the answer is on isc2.org.
Once the application is ready, what comes next is described in our article on how long endorsement takes and the stages of the application. To understand where these accounts come from and what they support, see our method or all the blog's themes.
Frequently asked questions
Do you need five years of experience before sitting the CISSP exam?
No. Nothing prevents you from sitting the exam without the experience: the candidate then becomes an Associate of ISC2 and accumulates the missing years afterwards. That is the path described by several candidates, including a recent graduate with no professional security experience at all.
Does a master's degree or an engineering degree reduce the requirement to four years?
A one-year waiver at most, whatever the degree: the accounts cite a US bachelor's degree in cybersecurity, never a French qualification (BTS, licence, master, RNCP title, engineering school). The list of accepted degrees and certifications is published by ISC2.
Can a degree and a certification be combined to remove two years?
No, according to the community: the waiver is capped at one year, all supporting documents combined. One comment puts it directly to a heavily certified candidate: his certifications would only count for one year.
Do my years of general IT count?
Partly, if you can map them to at least two CBK domains. One member takes candidates to task precisely for counting only their purely security work, when asset management, accounts and permissions, VPN or OS hardening already fall within the domains.
Have any candidates had their experience rejected?
No endorsement rejection is reported in the fifty accounts analysed. What they contain are requests for additional information and one case of in-depth review, both followed by approval.
Where does this information come from?
This article draws on the public reports of several thousand candidates, published over the last three years (24 July 2023 to 24 July 2026) and synthesised topic by topic. Quoted extracts are anonymised. Our method in detail.
- Associate of ISC2: the status of those who passed the exam without the experiencePassing the CISSP exam without the five years of experience leads to Associate of ISC2 status: duration, real value and what you are allowed to write.
- CISSP endorsement: the observed processing time and the stages of the applicationNine real timelines from candidates between 2023 and 2026: three to six and a half weeks after submission, and the mistakes that stretch the wait.