
CISSP Experience Requirement Explained: What Counts and What Does Not
CISSP 5-year experience requirement breakdown: what paid work counts, what internships don't, degree waiver rules, ISC2 Associate path, and endorsement process.
What is this page about?
An explanation of the CISSP experience requirement, which trips up candidates who pass the exam but cannot prove their work history: five years of cumulative paid experience in two or more of the eight domains. It details what paid work counts (with domain-specific examples) and what does not (unpaid internships), the waivers that reduce it to four years (a four-year degree or an approved ISC2 credential), the Associate path (pass first, gain experience within six years), and the endorsement process, finding an endorser, documenting across employers, and the common mistakes that delay approval.
What has been corrected on this page?
Every accepted correction to this page is recorded with the exact change, so readers can see how the page improved over time.
-
2 flagged issues verified: an unverified footnoted quote citing a nonexistent 'ISC2 CISSP Endorsement Process Annual Review 2024' report (not a known real ISC2 publication) with a precise '18%' figure was softened and the unverified reference-list entry removed; an unverified footnoted quote citing the real '2024 Cybersecurity Workforce Study' but with an unverifiable specific breakdown ('14,865 professionals across 15 countries... 25%... Associate pathway') not a known published finding was softened while keeping the real report as a general reference.
BeforeN/A - fabrication not present in live content
AfterN/A - no edit made
Why: Searched the live article content, excerpt, meta_description, and the full site corpus for the two described fabrications (a quote citing a nonexistent 'ISC2 CISSP Endorsement Process Annual Review 2024' report with an '18%' figure, and a quote citing the real '2024 Cybersecurity Workforce Study' with an unverifiable '14,865 professionals across 15 countries...25%...Associate pathway' breakdown). Neither appears anywhere in the live site; the article's References section also contains no unverified entry matching this description (all 6 references are real ISC2/publisher citations). No edit was needed or made for this item. Separately noted for a future pass: this same article contains an unrelated unverified quote attributed to 'Phil Martin, CISSP holder and security awareness trainer' about the ISC2 Associate designation, and an unverifiable named-individual anecdote (David, a systems administrator; Jennifer, a recent CS graduate) illustrating endorsement rejection reasons -- neither is covered by this contribution's summary and both were left untouched.
View the full record →
Who checked this page?
1 contributor has checked "CISSP Experience Requirement Explained: What Counts and What Does Not" on Pass4Sure. Each name below links to that person's public CitePep profile, where every contribution they have made is listed with the exact change they proposed.