CISSP Exam Requirements & Prerequisites: Eligibility and Work Experience (2024)

Are you an aspiring Certified Information Systems Security Professional (CISSP)?

Well, you're not alone. Like you, many information security practitioners recognize the value of the CISSP certification and see it as a significant milestone in their careers. However, achieving the certification requires more than just passing the examination. It demands a comprehensive understanding of the complex information security landscape and a certain level of professional experience.

In this guide, we'll provide an in-depth view of the CISSP exam requirements—from the amount of professional experience required to the relevant education and certifications that are accepted. By the end of this guide, you'll be armed with the knowledge needed to take the first steps toward becoming a CISSP.

Let's get started!

Why should you take the CISSP examination?

The Certified Information Systems Security Professional (CISSP) certification is a globally recognized cybersecurity certification granted to qualified professionals by the International Information System Security Certification Consortium ISC2. This certification verifies an IT professional's ability to design, implement, and manage a cybersecurity program effectively.

Often considered a must-have for career advancement in cybersecurity, the CISSP certification offers various benefits. These include higher salaries, increased job opportunities, enhanced reputation within the industry, and a more in-depth understanding of cybersecurity principles.

Beyond these advantages, you'll also gain membership in one of the largest associations of cybersecurity professionals in the world today, along with the benefits that come with it.

Who should pursue the CISSP certification?

The CISSP is designed for experienced IT security practitioners, managers, and executives who are interested in proving their skills and knowledge across a wide array of cybersecurity practices and principles.

Some of the roles that often require the CISSP certification include:

  • Chief Information Security Officer (CISO)
  • Director of security
  • Information security analyst
  • Security manager
  • IT director
  • Security consultant
  • Security Architect
  • Security auditor
  • Security systems engineer
  • Network architect

Do note that while the CISSP certification can help you land one of these roles, it's not always a strict requirement. Nevertheless, the certification certainly enhances the credibility and career prospects of professionals in these roles.

CISSP exam requirements

To qualify for the CISSP examination, you must have at least five years of cumulative paid work experience in two or more of the eight domains of the CISSP Common Body of Knowledge (CBK):

  • Domain 1. Security and Risk Management
  • Domain 2. Asset Security
  • Domain 3. Security Architecture and Engineering
  • Domain 4. Communication and Network Security
  • Domain 5. Identity and Access Management (IAM)
  • Domain 6. Security Assessment and Testing
  • Domain 7. Security Operations
  • Domain 8. Software Development Security

This includes both full-time and part-time work experience, as well as paid and unpaid internships.

You can also substitute a maximum of one year of the work experience requirement if you have relevant education or hold one of the approved ISC2 certifications. This means that you would only need a total of 4 years of work experience to qualify for the CISSP examination.

What Counts as CISSP Experience?

As previously mentioned, having relevant experience in the field of cybersecurity is a critical requirement for earning a CISSP certification. This professional requirement ensures that CISSPs possess not only theoretical knowledge but also practical expertise in the different domains of information security.

So, what types of experiences qualify you to take the CISSP examination? Let's delve into the specifics.

Full-time and Part-time work experience

One of the fundamental CISSP examination requirements is having a minimum of five years of relevant work experience in two or more of the eight domains of CISSP CBK. Often, this experience comes from roles that explicitly have “security” in their titles, such as security architect, network security engineer, and security analyst, to name a few.

While working in these roles will naturally align with the ISC2 requirement of security work experience, it's not the only type of experience that can qualify you. It’s important to note that ISC2focuses on the nature of your work, not your job title. Thus, any work involving securing information systems can qualify as security work experience.

For instance, roles like network administrator or IT manager may not have "security" in their job titles, but they involve securing an organization's information systems. These roles include tasks like implementing secure network protocols, managing access controls, and conducting risk assessments, all of which can still count as valid work experience for the CISSP.

When preparing your resume for the CISSP certification, take a good look at the eight domains and their subdomains. If your work experience includes tasks that align with these domains, ensure to highlight them in your resume.

If some of your responsibilities fall under two or more of the eight domains, this counts as relevant experience toward the CISSP certification, even if your job title isn’t explicitly security-focused.

How does ISC2 calculate your years of professional experience?
Both full-time and part-time roles count towards work experience, but they are calculated differently.

  • Full-time work experience: Your work experience is accrued monthly. You need to have worked at least 35 hours for four weeks to earn one month of work experience.
  • Part-time work experience: Your part-time experience should range from 20 hours to 34 hours per week. A total of 1040 hours of part-time work translates into six months of full-time experience, and 2080 hours of part-time work equates to 12 months of full-time experience.

Internship experience

Paid and unpaid internships can also have merit in your CISSP journey. As long as your tasks are connected to one of the domains, they can qualify as relevant work experience. Your internship experience is calculated in the same manner as your full-time or part-time work experience.

One important note: your internship experience must be accompanied by documentation on the company’s or organization’s letterhead confirming your position as an intern. If you’re interning at a school, the letter can be issued on the registrar’s stationery.

Relevant education or certifications held

You may also satisfy one year of the required experience by having relevant education or certifications. This means that you would only need 4 years of work experience to qualify for the CISSP examination.

For education to be considered relevant, you need to have a four-year college degree (or regional equivalent), or an advanced degree in information security from the U.S. National Center of Academic Excellence in Information Assurance Education (CAE/IAE).

If you don't hold a relevant degree, there's no need to worry. Certain security certifications can also be used to fulfill one year of the required experience. These include:

  • Cisco Certified Network Associate Security (CCNA Security)
  • CompTIA Security+
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Microsoft Security Operations Analyst
  • Microsoft Certified Cybersecurity Architect

You can check out the full list here.

Remember, you can only use either a relevant education or a certification to offset one year of experience. This means that even if you have both a relevant degree and a certification, you will still need to accumulate four years of work experience.

How to take the CISSP examination with no experience?

While the ISC2 typically requires candidates to have at least five years of relevant work experience, you can still take the CISSP exam even if you don’t have professional experience in the field. However, you won’t earn the CISSP certification right away. Instead, you’ll become an ISC2 Associate.

As an ISC2 Associate, you will be given six years to accumulate the required work experience to become a CISSP. During this period, you can access the resources and professional community that ISC2 offers to its associates and certified members.

This pathway also allows you to offset one of the five-year requirements by obtaining a relevant degree or certification.

Is CISSP for beginners?

No, the CISSP certification isn’t for beginners. It is aimed at experienced cybersecurity professionals who have at least 5 years of experience in the industry. However, beginners can still take the CISSP examination. But instead of getting CISSP certified, they will become ISC2 Associate.

Additional CISSP requirements

Acquiring the CISSP certification isn’t only about fulfilling the necessary work experience and passing the exam, but it’s also a commitment to ongoing professional development and ethics in the field of cybersecurity.

There are three things that you’ll need to fulfill after you passed the exam:

Endorsem*nt process

After passing the CISSP exam, you must be endorsed by an active ISC2 member before you can officially be certified. This endorsem*nt validates your necessary experience and attests to your ethical and professional conduct.

Annual Maintenance Fee

Once you're officially certified, you'll need to pay your first Annual Maintenance Fee (AMF). This fee is used to support the ISC2 costs of maintaining all the certifications they issue and related support systems. As of the time of this writing, the AMF for CISSP is USD$135. For Associates of ISC2, the AMF is USD$50.

Note that these fees can change over time, so it’s best to check ISC2’s official website for updated prices.

Continuing Professional Education (CPE) credits

The CISSP certification is only valid for three years. This means that you’ll need to recertify every three years, which can be accomplished by earning Continuing Professional Education (CPE) credits. You need to earn 40 CPE credits each year, and a total of 120 CPE credits over a three-year certification cycle. If you don’t earn these credits, you’ll have to take the exam again.

How do I earn CISSP CPE credits?

CPE credits are classified into two categories: Group A and Group B. You are required to earn 90 Group A CPEs and 30 Group B CPEs to get recertified.

Group A CPEs can be acquired by performing activities in the eight domains of CBK through projects or assignments outside your job responsibilities or description. This includes attending educational courses, seminars, and workshops related to information security, contributing to security publications, and participating in professional activities related to the field.

Group B CPEs are awarded for activities that don’t fall under the eight domains and are considered to help enhance general professional skills and knowledge of CISSPs, This can include public speaking or management classes.

FAQ's

Is there a minimum age requirement for getting a CISSP certification?

No, there is no minimum age requirement for getting a CISSP certification. As long as you meet the qualifications, you can apply and obtain the certification.

Can people of any nationality earn a CISSP certification?

Absolutely, the CISSP certification is available to individuals of any nationality, regardless of their location. In fact, the CISSP exam is available in several languages apart from English, including Chinese, Japanese, and German.

What is the minimum for CISSP?

The minimum requirement for CISSP is five years of cumulative, paid work experience in two or more of the eight domains of the CISSP.

How long does the CISSP exam take?

The CISSP CAT exam will have a maximum duration of 3 hours for the new version, effective from April 15, 2024, and 4 hours for the previous version. In contrast, the linear exam provides a maximum duration of 6 hours for both the updated and older versions.

What’s Next?

Now that you have a solid understanding of the CISSP exam requirements and how to meet them, you’re ready to move on to the next stage of your journey: exam preparation. A well-rounded and comprehensive study plan is key to passing the CISSP examination and Destination Certification is the perfect guide.

Our CISSP MasterClass can equip you with the knowledge you need to pass the rigorous CISSP exam. This isn't your typical online study training. It adapts to your current level of knowledge, focusing on any knowledge gaps you may have. On top of that, our MasterClass is flexible and adjusts to your schedule, which allows you to progress at your own pace.

So, if you’re ready to take the leap, Destination Certification is here to support you. Best of luck as you prepare for your journey to become CISSP certified!

Rob Witcher

Rob is the driving force behind the success of the Destination Certification CISSP program, leveraging over 15 years of security, privacy, and cloud assurance expertise. As a seasoned leader, he has guided numerous companies through high-profile security breaches and managed the development of multi-year security strategies. With a passion for education, Rob has delivered hundreds of globally acclaimed CCSP, CISSP, and ISACA classes, combining entertaining delivery with profound insights for exam success. You can reach out to Rob on LinkedIn.

CISSP Exam Requirements & Prerequisites: Eligibility and Work Experience (2024)
Top Articles
Apply for Instant Personal Loan Online at 10.25% - Myzeon
Can You Get A Small Business Loans With No Credit Check? 2024
Craigslist San Francisco Bay
St Thomas Usvi Craigslist
Exclusive: Baby Alien Fan Bus Leaked - Get the Inside Scoop! - Nick Lachey
Where are the Best Boxing Gyms in the UK? - JD Sports
فیلم رهگیر دوبله فارسی بدون سانسور نماشا
Stadium Seats Near Me
Valley Fair Tickets Costco
Apex Rank Leaderboard
Poe Pohx Profile
Lycoming County Docket Sheets
Katie Boyle Dancer Biography
Weather Annapolis 10 Day
Bill Devane Obituary
Otr Cross Reference
Mawal Gameroom Download
Sport Clip Hours
Local Collector Buying Old Motorcycles Z1 KZ900 KZ 900 KZ1000 Kawasaki - wanted - by dealer - sale - craigslist
Spartanburg County Detention Facility - Annex I
Truth Of God Schedule 2023
Check From Po Box 1111 Charlotte Nc 28201
Alfie Liebel
FDA Approves Arcutis’ ZORYVE® (roflumilast) Topical Foam, 0.3% for the Treatment of Seborrheic Dermatitis in Individuals Aged 9 Years and Older - Arcutis Biotherapeutics
Amazing deals for Abercrombie & Fitch Co. on Goodshop!
O'Reilly Auto Parts - Mathis, TX - Nextdoor
Jeffers Funeral Home Obituaries Greeneville Tennessee
Villano Antillano Desnuda
John Deere 44 Snowblower Parts Manual
Redbox Walmart Near Me
Street Fighter 6 Nexus
Amici Pizza Los Alamitos
Winco Money Order Hours
Fototour verlassener Fliegerhorst Schönwald [Lost Place Brandenburg]
Mars Petcare 2037 American Italian Way Columbia Sc
Deshuesadero El Pulpo
Cpmc Mission Bernal Campus & Orthopedic Institute Photos
Stewartville Star Obituaries
The Realreal Temporary Closure
California Craigslist Cars For Sale By Owner
Walgreens On Secor And Alexis
Ehome America Coupon Code
Craigslist Rooms For Rent In San Fernando Valley
3367164101
Waco.craigslist
San Diego Padres Box Scores
Runescape Death Guard
Where Is Darla-Jean Stanton Now
Download Twitter Video (X), Photo, GIF - Twitter Downloader
Taterz Salad
Noaa Duluth Mn
Latest Posts
Article information

Author: Tuan Roob DDS

Last Updated:

Views: 5472

Rating: 4.1 / 5 (62 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Tuan Roob DDS

Birthday: 1999-11-20

Address: Suite 592 642 Pfannerstill Island, South Keila, LA 74970-3076

Phone: +9617721773649

Job: Marketing Producer

Hobby: Skydiving, Flag Football, Knitting, Running, Lego building, Hunting, Juggling

Introduction: My name is Tuan Roob DDS, I am a friendly, good, energetic, faithful, fantastic, gentle, enchanting person who loves writing and wants to share my knowledge and understanding with you.