Skip to content
Cybridia CISSP® exam prep

Candidate experiences · Understand

Passing the CISSP without cybersecurity experience: what candidates report

Of the 200 accounts published in full in the archive, about ten come from candidates with no cybersecurity role: recent graduates, auditors, risk consultants, pre-sales engineers, career changers. They pass, but only after longer preparation and by tackling the technical domains head-on.

Updated on 7 min de lecture Par l'équipe Cybridia

Yes, it is possible to pass the CISSP exam without working in cybersecurity, and candidates describe doing it: recent graduates, auditors, risk consultants, career changers. "Can I take the CISSP without working in cybersecurity?" is one of the questions candidates ask most often, and the archive of three years of public accounts makes it possible to answer with concrete cases. One clarification: passing the exam is not enough to be certified, since ISC2 also requires validation of professional experience, with rules set out on isc2.org. Everything that follows concerns the exam itself.

Can you pass the exam without working in cybersecurity?

Yes. Of the 200 accounts published in full, about ten come from candidates stating that they held no cybersecurity role at the time of the exam — roughly one account in twenty. These are voluntary accounts, not a candidate statistic.

The most explicit title is that of a candidate announcing that he had "no cybersecurity experience" and had passed on his first attempt at 150 questions, after four weeks of preparation, with basic IT experience and a master's in cybersecurity just completed. Another, an IT specialist in a hospital for two years, writes:

"I wanted to write this to tell everyone who thinks that they shouldn't take this, or can't take this, if they don't have the experience, that you can."

The opposite is just as well documented: the candidate accounts devoted to failures include candidates with far more experience who did not pass. A lack of experience does not rule out passing; having it does not guarantee anything.

Which profiles with no experience pass in these accounts?

The cases on record fall into four groups.

Recent graduates. One candidate holding a bachelor's degree in accounting and a master's in business analytics, with no professional experience at all, took the CISSP before joining an audit firm. Another, with two years of general IT and a bachelor's in cybersecurity, took it to try to break into the field.

Governance, audit and risk profiles. These are the most numerous. A management and enterprise risk consultant with twelve years' experience describes his situation without hedging:

"I've never provisioned accounts, troubleshot network issues, or worked with cryptography. However, my experience in risk management helped me understand what's best for the business."

Adjacent roles. A pre-sales engineer at a security platform, who started the job with "very little security experience", built a ten-week plan; a quality management professional in medical devices, later a PLM architect, went after the certification so that he could discuss security with his clients.

Career changers. One candidate sums up his route in three words — "no background, career change" — and adds that he started from a level where the word "kernel" meant nothing to him. He passed on his second attempt.

What is the difficulty for a non-technical profile?

It is concentrated in the technical domains, and the authors name it. One candidate from a governance, risk and compliance background, with no IT training, describes his starting point: a single domain above the threshold before he began revising — security and risk management. The domains cited as the most costly are architecture, communication and network security, and software development.

The second difficulty is psychological. Impostor syndrome comes up explicitly in several of these accounts, including that of a professional who used to open her meetings by announcing that she "wasn't technical".

The third trap is specific to these profiles: believing that reasoning "like a manager" removes the need for technical knowledge. A nineteen-year-old candidate, with around three years of cybersecurity experience, built his whole preparation on that assumption and failed at the hundredth question:

"I decided to focus on the mindset foremost […] This was a huge mistake. I was utterly blindsided by questions asking for technical applications of concepts I had never heard of."

The story does not end there, and this needs stating to avoid any confusion with the Associate accounts: the same author resat the exam and passed at twenty, also at the hundredth question, after going back over the content rather than the mindset alone. Not having the five years required, he became an Associate of ISC2 and is comfortable with that status, which was enough for his employer. So one candidate, two stages: the failure cited here, the pass cited there.

One of the most repeated formulations in the accounts of failures comes from a heavily upvoted comment: know the material like a technician, then apply it like a decision-maker — both, not one or the other.

A counterpoint, to close this section. Lacking experience is not the only possible handicap: the candidate accounts on failures identify preparation that is too technical as the most frequently self-diagnosed cause of failure, with candidates of ten to twenty years in networking, cloud or a security operations centre failing because they answered as implementers rather than as advisers. In other words, field experience does not excuse you from preparing, and its absence is not a disqualification. That side of the question is not the subject of this article: it is covered in why candidates fail the CISSP.

How long did these candidates study?

The stated durations range from six weeks to more than a year, with two constants.

Reported profile Stated duration
No IT experience 1.5 months intensive, while working
Recent graduate, no experience ~2 months at ~5 hours a day
No technical background 2.5 to 3 months intensive
Pre-sales engineer 10-week plan
Audit and risk consulting 11 months, including one failure
No core-domain experience More than a year, including one failure

First constant: these preparations are longer and denser than those of the experienced candidates in the same set of accounts, where two- to three-week routes exist. Second constant: several of these candidates go well beyond the hundredth question — 150 recurs in these accounts, and 175 in the older ones, under the format used before April 2024. The sample is too small to make a rule of it, but it justifies planning for the long version of the exam rather than hoping for an early stop.

Should you start with a more accessible certification?

It is not essential, and the accounts give arguments both ways.

In favour. The recent graduate mentioned above, despite passing, closes his account with a warning:

"Looking back […] the CISSP exam is probably not ideal for fresh graduates. I would recommend starting with something more foundational to build up your knowledge before tackling CISSP."

Another candidate, who already held a cloud certification from the same body, considers that having sat an earlier exam from that body spared him discovering the format on exam day. Several accounts mention working through a progressive sequence of general certifications before the CISSP, presented as the foundation that made the preparation bearable.

Against. Other authors find the CISSP less demanding in raw memorisation than certifications with a reputation for being more accessible, and one candidate with no IT training passed it with no prior certification at all. The risk management consultant quoted above sends a direct message to people like him: do not be discouraged by a non-technical profile or by mediocre practice scores, as long as you can apply the concepts to a business decision.

Finally, one candidate with no direct experience advises holding a certification that counts towards the ISC2 experience requirement, so as to have time to build a track record after the exam. That equivalence is capped at one year in total, whatever the supporting evidence, according to the community: the experience required for the CISSP sets out what candidates have managed to have accepted. The applicable rules themselves should be checked on isc2.org.

To place these cases within the body of accounts as a whole, see the 200 success stories and our method.

Frequently asked questions

Can you pass the CISSP exam without cybersecurity experience?

Yes: about ten of the 200 accounts published in full come from candidates with no cybersecurity role, including one recent graduate with no professional experience at all — cases published voluntarily, not a statistic.

Is passing the exam enough to become CISSP certified?

No. The exam is only one step: ISC2 also requires validation of professional experience, with rules and deadlines described on isc2.org.

What is the main difficulty for a non-technical profile?

The technical domains, particularly architecture, networks and software development. Several candidates from governance or audit backgrounds report that, at the start of their preparation, they were above the threshold in domain 1 alone.

Is a highly technical background an advantage?

Not automatically: the accounts include several failures by candidates with ten to twenty years in networking, cloud or a security operations centre. This subject is covered in detail in our article on why candidates fail the CISSP.

Should you take a more accessible certification before the CISSP?

It is not essential: some candidates have passed with no prior certification. Several accounts nonetheless recommend it, notably a recent graduate who considers the CISSP poorly suited to someone straight out of university.

Where does this information come from?

This article draws on the public reports of several thousand candidates, published over the last three years (24 July 2023 to 24 July 2026) and synthesised topic by topic. Quoted extracts are anonymised. Our method in detail.

More on this topic

Explore other topics