How to document your CISSP experience before you book the exam
Before booking, write one page that lists each role, its dates, your weekly hours and which of the eight CISSP domains the work covered. ISC2 asks for five years of cumulative, full-time experience in two or more domains. A record shows early whether your history meets that rule or whether general IT work needs reframing.
Candidates pass the exam and then discover that half of their so-called security experience was ordinary IT administration. The discovery is far cheaper before the exam than after it.
What ISC2 is asking for
ISC2's rule is at least five years of cumulative, full-time experience in two or more of the eight CISSP domains. Part-time work and internships may count under ISC2's conversion rules. A degree in a relevant field, or an approved credential, can waive up to one year, and the waiver is one year in total, not one for each.
After you pass, an active ISC2 credential holder must endorse you, and you must complete the endorsement within nine months of your exam date. If you do not know a holder, ISC2 can act as your endorser.
All of that is checkable now. So build the evidence before you pay for the exam.
Build the record in four columns
Use a simple table, one row per role.
| Role and employer | Dates | Hours a week | Domains touched |
|---|---|---|---|
| Example: Security analyst, regional bank | Mar 2021 to Nov 2023 | 40 | Security Operations; Identity and Access Management |
Under the table, add one sentence per domain describing a thing you did, not a thing your team did. Keep it plain: "reviewed quarterly access rights for finance staff and removed 40 stale accounts" is a fact. "Ensured access compliance" is a slogan.
Map the work to the domains honestly
The CredenTrek CISSP book gives examples of work that usually fits each domain. Here is the shorter version.
| Domain | Work that usually fits |
|---|---|
| Security and Risk Management | Risk registers, policy, compliance, awareness, vendor risk |
| Asset Security | Data classification, handling, retention, destruction |
| Security Architecture and Engineering | Design reviews, cryptography, secure builds |
| Communication and Network Security | Firewalls, segmentation, VPNs, wireless security |
| Identity and Access Management | Directory services, multi-factor authentication, access reviews |
| Security Assessment and Testing | Vulnerability scanning, audits, control testing |
| Security Operations | Monitoring, incident response, patching, disaster recovery |
| Software Development Security | Secure coding, code review, application security |
General IT administration with an occasional password reset does not map neatly to any of these. If most of a role's hours were help-desk tickets, say so in the record, and count only the part that was security content.
Read your own record like an assessor
Ask four questions of the finished page.
- Do at least two domains appear across the years, with real duties against each?
- Could a former manager confirm each line without having to guess?
- Do the dates leave unexplained gaps or overlaps?
- Does the total reach five years even after the one-year waiver is applied, if you rely on it?
If the total falls short, you have two honest choices. You can sit the exam as a future Associate, or you can spend a year gaining the missing domain experience first. Both are better than discovering the shortfall during endorsement.
Gather the supporting papers while you are at it
- Contact details for managers who can confirm your work
- Proof of any degree or credential you plan to use for the waiver
- The name of an ISC2 credential holder who might endorse you
- Government photo ID that matches your registration name exactly
Writing the record takes an afternoon. A candidate in the book who mapped eight years across risk management, security operations and identity before booking had a former manager, a credential holder, endorse her within two weeks of passing.
Where the book picks up
Build the record first. Then decide whether to book.
Questions readers ask
Does part-time security work count towards the five years?
Can I use my degree and a certification to waive two years?
What if I cannot find an endorser?
This article is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.