CredenTrek
Blog / CISSP / Article 02 of 10
CISSP · Decide and apply

How to document your CISSP experience before you book the exam

By Mustafa K. Al-Dori · Checked against official documents on 11 October 2026 · 7 min read

The short answer

Before booking, write one page that lists each role, its dates, your weekly hours and which of the eight CISSP domains the work covered. ISC2 asks for five years of cumulative, full-time experience in two or more domains. A record shows early whether your history meets that rule or whether general IT work needs reframing.

Candidates pass the exam and then discover that half of their so-called security experience was ordinary IT administration. The discovery is far cheaper before the exam than after it.

What ISC2 is asking for

ISC2's rule is at least five years of cumulative, full-time experience in two or more of the eight CISSP domains. Part-time work and internships may count under ISC2's conversion rules. A degree in a relevant field, or an approved credential, can waive up to one year, and the waiver is one year in total, not one for each.

After you pass, an active ISC2 credential holder must endorse you, and you must complete the endorsement within nine months of your exam date. If you do not know a holder, ISC2 can act as your endorser.

All of that is checkable now. So build the evidence before you pay for the exam.

Build the record in four columns

Use a simple table, one row per role.

Role and employer Dates Hours a week Domains touched
Example: Security analyst, regional bank Mar 2021 to Nov 2023 40 Security Operations; Identity and Access Management

Under the table, add one sentence per domain describing a thing you did, not a thing your team did. Keep it plain: "reviewed quarterly access rights for finance staff and removed 40 stale accounts" is a fact. "Ensured access compliance" is a slogan.

Map the work to the domains honestly

The CredenTrek CISSP book gives examples of work that usually fits each domain. Here is the shorter version.

Domain Work that usually fits
Security and Risk Management Risk registers, policy, compliance, awareness, vendor risk
Asset Security Data classification, handling, retention, destruction
Security Architecture and Engineering Design reviews, cryptography, secure builds
Communication and Network Security Firewalls, segmentation, VPNs, wireless security
Identity and Access Management Directory services, multi-factor authentication, access reviews
Security Assessment and Testing Vulnerability scanning, audits, control testing
Security Operations Monitoring, incident response, patching, disaster recovery
Software Development Security Secure coding, code review, application security

General IT administration with an occasional password reset does not map neatly to any of these. If most of a role's hours were help-desk tickets, say so in the record, and count only the part that was security content.

Read your own record like an assessor

Ask four questions of the finished page.

  • Do at least two domains appear across the years, with real duties against each?
  • Could a former manager confirm each line without having to guess?
  • Do the dates leave unexplained gaps or overlaps?
  • Does the total reach five years even after the one-year waiver is applied, if you rely on it?

If the total falls short, you have two honest choices. You can sit the exam as a future Associate, or you can spend a year gaining the missing domain experience first. Both are better than discovering the shortfall during endorsement.

Gather the supporting papers while you are at it

  • Contact details for managers who can confirm your work
  • Proof of any degree or credential you plan to use for the waiver
  • The name of an ISC2 credential holder who might endorse you
  • Government photo ID that matches your registration name exactly

Writing the record takes an afternoon. A candidate in the book who mapped eight years across risk management, security operations and identity before booking had a former manager, a credential holder, endorse her within two weeks of passing.

Where the book picks up

Build the record first. Then decide whether to book.

Questions readers ask

Does part-time security work count towards the five years?
It can, under ISC2's rules for converting part-time work and internships. Check the current conversion rule on isc2.org and keep dates and weekly hours in your record.
Can I use my degree and a certification to waive two years?
No. The waiver is at most one year in total, so a degree plus an approved credential does not double it.
What if I cannot find an endorser?
ISC2 can act as your endorser. A precise experience record makes that process quicker, whoever endorses you.
Sources

This article is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.