In This Article
Nobody fails the CISSP experience requirement because the rule is complicated. They fail it because they counted optimistically — a part-time year at full weight, an overlap counted twice, a help desk role claimed as security work — and ISC2’s reviewer counted conservatively. The gap between those two counts is where returned and denied applications come from.
This guide is the conservative count: what ISC2 credits, at what weight, with a worked example you can copy for your own history.
You need five years of cumulative, paid work experience in two or more of the eight CISSP domains. A four-year college degree (or regional equivalent) or a credential on ISC2’s approved list waives one year — the waiver caps at one year total, no stacking. Experience can be accumulated any time in your career, and up to six years after passing the exam as an Associate of ISC2.
The Rule in One Paragraph
Five years, cumulative, paid, in two or more domains. “Cumulative” means the years do not need to be consecutive or at one employer. “Paid” means compensated work — salaried, hourly, contract, or self-employed all qualify. “In two or more domains” means your documented duties must map to at least two of the eight CISSP domains — and in practice most security roles touch four or five without trying. The count is measured in months of qualifying work, and the burden of demonstrating it sits entirely on your written experience descriptions.
What Counts (and at What Weight)
| Work Type | Counts? | Weight |
|---|---|---|
| Full-time employment (35+ hrs/week) | Yes | Full weight — 1 month worked = 1 month credited |
| Part-time work (20–34 hrs/week) | Yes | Prorated — 1,040 part-time hours ≈ 6 months; 2,080 ≈ 12 months |
| Paid internship | Yes | Same rules as employment; get documentation on employer letterhead |
| Unpaid internship | Yes, with documentation | Requires written confirmation of role and hours from the organization |
| Contract / freelance / self-employed security work | Yes | Prorated by documented hours; keep contracts and invoices |
| Military service in a security-relevant role | Yes | Full weight; map duties to domains just like civilian roles |
| Overlapping simultaneous roles | Yes, but… | Calendar time counts once — two jobs in the same month is still one month |
Part-time work below 20 hours a week does not accrue credit at all — and overlapping roles never double-count a month. Those two corrections alone explain a large share of experience-math returns.
What Does Not Count
- Pure end-user IT work. Password resets and ticket triage on a general help desk do not qualify on their own — but the security slice of a hybrid role can. If 40% of your help desk role was access provisioning, incident escalation, and endpoint remediation, document that slice specifically and claim only that fraction.
- Education and study time. Degrees, bootcamps, and cert prep are not work experience. (A four-year degree contributes through the one-year waiver instead.)
- Homelab, CTF, and personal projects. Unpaid and unverifiable — valuable for skills, worth zero months.
- Volunteer work without documentation. Security work for a nonprofit can qualify as unpaid experience only if the organization will document your role and hours in writing.
- Inflated titles. The reviewer scores duties, not titles. “Security Analyst” doing pure NOC monitoring maps worse than “Systems Administrator” who ran patch management, IAM, and backups.
Mapping Real Job Titles to the 8 Domains
You need two domains minimum. Here is how common pre-CISSP roles actually map — use these as starting points for your own descriptions, and make the mapping explicit when you write them (our description writing guide shows the format reviewers credit fastest):
| Role | Strongest Domain Mappings |
|---|---|
| Systems Administrator | D7 Security Operations (patching, backups, monitoring) · D5 IAM (account lifecycle) · D3 Security Architecture (hardening) |
| Network Engineer | D4 Communication & Network Security · D7 Security Operations · D3 Architecture (segmentation design) |
| SOC Analyst | D7 Security Operations (detection, IR) · D6 Security Assessment & Testing (tuning, validation) |
| Help Desk / IT Support (security slice only) | D5 IAM (provisioning, access reviews) · D7 Security Operations (endpoint remediation, escalation) |
| Software Developer | D8 Software Development Security (SDLC, code review) · D3 Architecture (secure design) |
| IT Auditor / GRC Analyst | D1 Security & Risk Management · D6 Assessment & Testing · D2 Asset Security (classification) |
| Military IT / Signals | D1 Risk Management (accreditation) · D4 Network Security · D7 Operations — translate service jargon to civilian domain language |
The One-Year Waiver: Degree or Credential
One year of the five can be waived by either a four-year college degree (or regional equivalent) or a credential on ISC2’s approved list — never both, and never more than one year. Two things changed the calculus in 2026:
- ISC2 removed 31 credentials from the approved list on April 1, 2026 — CEH, CISA, and OSCP among them. CISM, SSCP, CCSP, Security+, CySA+, and CASP+ remain as of this writing. Check the current list before building your math on a credential.
- If you hold both a degree and an approved credential, the second one buys you nothing — but it is worth listing anyway, because it strengthens the overall picture the reviewer sees.
Run Your Own Math (Worked Example)
Here is the conservative method, applied to a typical mixed history:
| History | Optimistic Count | ISC2-Conservative Count |
|---|---|---|
| 2 years help desk (~40% security duties) | 24 months | ~10 months (security slice only) |
| 18 months part-time SOC (24 hrs/week) during school | 18 months | ~11 months (prorated: ~1,870 hrs ÷ 2,080 × 12) |
| 3 years sysadmin, full-time | 36 months | 36 months |
| 6-month overlap of the SOC and sysadmin roles | counted in both | counted once (−6 months) |
| Total | 78 months “6.5 years” | ~51 months — 4 years 3 months |
The optimistic count sails past five years; the conservative count comes up nine months short of five — and clears only if a one-year waiver applies. That spread is exactly why candidates are blindsided by returns. Run the conservative version before you submit, and if it clears, write your descriptions so the reviewer reaches the same number without effort.
If You Come Up Short
If the conservative math lands under the requirement, you have three moves — and they stack:
- Sit the exam anyway and become an Associate of ISC2. The six-year window means a candidate 18 months short loses nothing by passing now — your current role keeps accruing months.
- Recover discounted time with better documentation. The security slice of hybrid roles is real, claimable experience when described precisely — vague descriptions are why it gets discounted to zero.
- Check the waiver list again. If you hold Security+, CySA+, CASP+, SSCP, CCSP, or CISM, one year of the requirement disappears.
Know Where You Stand Before Exam Day
The experience requirement has a six-year runway — exam readiness is the gate that matters now. CISSP.app’s adaptive mock exams show your predicted readiness across all eight domains, so you know when you are actually ready to book.
Check Your Readiness Free →7-day free trial · Covers CISSP, CCSP, and CISM
FAQ: CISSP Qualifying Experience
Does help desk experience count toward the CISSP?
The security portion can. Pure end-user support does not qualify, but access provisioning, incident escalation, endpoint remediation, and account lifecycle work are legitimate Domain 5 and Domain 7 experience. Claim the documented security fraction of the role, not the whole role.
Does part-time work count toward CISSP experience?
Yes, prorated. Part-time work of 20–34 hours per week accrues credit by hours: roughly 1,040 hours equals six months of credit and 2,080 hours equals a year. Work below 20 hours a week does not accrue credit.
Do internships count toward the CISSP experience requirement?
Paid internships count under the same rules as employment. Unpaid internships can count with written documentation of role and hours from the organization. Get the documentation while the internship is recent — it is much harder to obtain years later.
Can I take the CISSP exam before I have five years of experience?
Yes. Passing without the full experience makes you an Associate of ISC2, with up to six years from your exam date to accumulate the remainder. Your exam result does not expire within that window.
Does a master’s degree waive more experience than a bachelor’s?
No. The education waiver is one year, satisfied by a four-year degree or regional equivalent. A master’s degree does not stack a second year, and a degree plus an approved credential still waives only one year total.
Do overlapping jobs count twice?
No. Experience is measured in calendar months, and a month in which you held two qualifying roles is still one month of credit. This is one of the most common causes of experience-math returns.
CISSP.app Blog