CredenTrek
Library / CISSP / Guide 02 of 8
CISSP · Experience and endorsement

CISSP experience, the Associate route and endorsement: check your history before you book

By Mustafa K. Al-Dori · Edition 2026.2, verified 9 October 2026 · 6 min read

The short answer

ISC2 requires at least five years of cumulative, full-time experience in two or more of the eight CISSP domains. A degree or an approved credential may waive up to one year. Without the experience you can pass and become an Associate of ISC2, with six years to earn it. After you pass, an active ISC2 credential holder must endorse you, and you must complete the endorsement within nine months of your exam date.

Passing the exam is the middle of the CISSP journey, not the end. Candidates who skip the paperwork discover after the exam that some of their history does not count, and the nine-month clock starts running while they rewrite it.

What is the experience rule?

ISC2's exam outline states the rule: at least five years of cumulative, full-time experience in two or more of the eight CISSP domains. Part-time work and internships may also count, under ISC2's rules for converting them. A bachelor's or master's degree in computer science, information technology or a related field may satisfy up to one year of the requirement. ISC2 also lists approved credentials that can satisfy up to one year.

Check isc2.org for how these combine and read the current list before you rely on it. The waiver is at most one year in total, so a degree plus a credential does not double it.

"Security experience" means work with real security content. General IT administration with an occasional password reset does not map neatly to a domain.

Domain Work that usually fits
Security and Risk Management Risk registers, policy, compliance, awareness, vendor risk
Asset Security Data classification, handling, retention, destruction
Security Architecture and Engineering Design reviews, cryptography, secure builds, facility security
Communication and Network Security Firewalls, segmentation, VPNs, wireless security
Identity and Access Management Directory services, MFA, access reviews, provisioning
Security Assessment and Testing Vulnerability scanning, audits, control testing
Security Operations Monitoring, incident response, patching, disaster recovery
Software Development Security Secure coding, code review, application security

What is the Associate route?

If you do not yet have the experience, you can still sit the exam. If you pass, you become an Associate of ISC2. ISC2's outline gives an Associate six years to earn the five years of experience, and Associates pay a lower annual fee and earn fewer CPE credits while they build it.

As an Associate, write "Associate of ISC2" on your CV and LinkedIn, not CISSP, until you are fully certified. Dana, in the book, had three years of experience. She chose the Associate route, passed the exam while she built her experience and gave herself a dated plan to reach five.

The route is genuinely useful, but it has a cost. The exam is a large effort, and a candidate with very little security experience may find that the six years pass without the right roles. The first guide in this series has the fit test that tells you which side you are on.

What is endorsement?

After you pass, you must be endorsed. An active ISC2 credential holder in good standing confirms your experience and your professional conduct. If you do not know one, ISC2 can act as your endorser. You must complete the endorsement within nine months of your exam date.

Do not leave it to the last month. Samira, in the book, mapped her eight years before booking. Three roles covered risk management, security operations and identity, each with dates and duties. Her former manager, a CISSP holder, endorsed her within two weeks of her pass. Yara submitted her endorsement the day after she passed, and ISC2 confirmed her certification within the month.

What about the code of ethics?

Every candidate must agree to the ISC2 Code of Ethics. Its four canons ask you to protect society, act honourably, provide competent service and advance the profession. Exam questions draw on the code, and breaching it can cost you the credential. When a scenario asks what to do first, the canons usually point toward the answer that protects people and follows law and policy.

Which documents should you prepare?

  • An experience record: each role, its dates, hours a week and the domains it covered
  • Contact details for managers who can confirm your work
  • Proof of any degree or credential you will use for the waiver
  • The name of an ISC2 credential holder who could endorse you
  • A government-issued photo ID that matches your registration name exactly

Build the experience record before you book, not after. Appendix D of CredenTrek For CISSP has message templates for endorsement status and for asking ISC2 to act as your endorser. Chapter 4 walks through the rule step by step.

If your record looks strong, the exam map is the next stop. If it looks thin, consider whether the Associate route or an earlier credential would serve you better.

Your next step
  1. List every role you have held, with dates, hours a week and the domains each one covered.
  2. Add up your qualifying years and check whether a degree or credential could waive up to one year.
  3. Choose your route: full CISSP, the Associate route or an earlier credential.
  4. Write down the name of an ISC2 credential holder who could endorse you.

Questions readers ask

Can part-time work count towards the five years?
Part-time work and internships may count, under ISC2's rules for converting them. Read the current rules on isc2.org before you rely on them.
Who can endorse me?
An active ISC2 credential holder in good standing who can confirm your experience and professional conduct. If you do not know one, ISC2 can act as your endorser.
How long do I have to complete endorsement?
Nine months from your exam date. Start the day after you pass, with your experience record ready.
What do Associates of ISC2 pay?
Associates pay a lower annual fee, US$50 in the book, and must earn at least 15 Group A CPE credits each year while they build the experience.
Sources
  • ISC2 CISSP certification page
  • ISC2 CISSP experience requirements
  • ISC2 CISSP exam outline, effective 15 April 2024
  • ISC2 Code of Ethics
  • ISC2 Candidate Information Bulletin

This guide is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.