August 7, 2026 · CISSP Certification

What Counts as CISSP Experience? The Qualifying Work Rules (2026)

Five years sounds simple until you try to count yours. Part-time roles, internships, overlapping jobs, help desk years, military service — here is what ISC2 actually credits, what it discounts, and how to run the math before you submit.

📖 10 min read

Nobody fails the CISSP experience requirement because the rule is complicated. They fail it because they counted optimistically — a part-time year at full weight, an overlap counted twice, a help desk role claimed as security work — and ISC2’s reviewer counted conservatively. The gap between those two counts is where returned and denied applications come from.

This guide is the conservative count: what ISC2 credits, at what weight, with a worked example you can copy for your own history.

🔑 The Rule

You need five years of cumulative, paid work experience in two or more of the eight CISSP domains. A four-year college degree (or regional equivalent) or a credential on ISC2’s approved list waives one year — the waiver caps at one year total, no stacking. Experience can be accumulated any time in your career, and up to six years after passing the exam as an Associate of ISC2.

The Rule in One Paragraph

Five years, cumulative, paid, in two or more domains. “Cumulative” means the years do not need to be consecutive or at one employer. “Paid” means compensated work — salaried, hourly, contract, or self-employed all qualify. “In two or more domains” means your documented duties must map to at least two of the eight CISSP domains — and in practice most security roles touch four or five without trying. The count is measured in months of qualifying work, and the burden of demonstrating it sits entirely on your written experience descriptions.

What Counts (and at What Weight)

Work Type Counts? Weight
Full-time employment (35+ hrs/week) Yes Full weight — 1 month worked = 1 month credited
Part-time work (20–34 hrs/week) Yes Prorated — 1,040 part-time hours ≈ 6 months; 2,080 ≈ 12 months
Paid internship Yes Same rules as employment; get documentation on employer letterhead
Unpaid internship Yes, with documentation Requires written confirmation of role and hours from the organization
Contract / freelance / self-employed security work Yes Prorated by documented hours; keep contracts and invoices
Military service in a security-relevant role Yes Full weight; map duties to domains just like civilian roles
Overlapping simultaneous roles Yes, but… Calendar time counts once — two jobs in the same month is still one month
✔ The Two Rules Candidates Miss

Part-time work below 20 hours a week does not accrue credit at all — and overlapping roles never double-count a month. Those two corrections alone explain a large share of experience-math returns.

What Does Not Count

Mapping Real Job Titles to the 8 Domains

You need two domains minimum. Here is how common pre-CISSP roles actually map — use these as starting points for your own descriptions, and make the mapping explicit when you write them (our description writing guide shows the format reviewers credit fastest):

Role Strongest Domain Mappings
Systems Administrator D7 Security Operations (patching, backups, monitoring) · D5 IAM (account lifecycle) · D3 Security Architecture (hardening)
Network Engineer D4 Communication & Network Security · D7 Security Operations · D3 Architecture (segmentation design)
SOC Analyst D7 Security Operations (detection, IR) · D6 Security Assessment & Testing (tuning, validation)
Help Desk / IT Support (security slice only) D5 IAM (provisioning, access reviews) · D7 Security Operations (endpoint remediation, escalation)
Software Developer D8 Software Development Security (SDLC, code review) · D3 Architecture (secure design)
IT Auditor / GRC Analyst D1 Security & Risk Management · D6 Assessment & Testing · D2 Asset Security (classification)
Military IT / Signals D1 Risk Management (accreditation) · D4 Network Security · D7 Operations — translate service jargon to civilian domain language

The One-Year Waiver: Degree or Credential

One year of the five can be waived by either a four-year college degree (or regional equivalent) or a credential on ISC2’s approved list — never both, and never more than one year. Two things changed the calculus in 2026:

Run Your Own Math (Worked Example)

Here is the conservative method, applied to a typical mixed history:

History Optimistic Count ISC2-Conservative Count
2 years help desk (~40% security duties) 24 months ~10 months (security slice only)
18 months part-time SOC (24 hrs/week) during school 18 months ~11 months (prorated: ~1,870 hrs ÷ 2,080 × 12)
3 years sysadmin, full-time 36 months 36 months
6-month overlap of the SOC and sysadmin roles counted in both counted once (−6 months)
Total 78 months “6.5 years” ~51 months — 4 years 3 months

The optimistic count sails past five years; the conservative count comes up nine months short of five — and clears only if a one-year waiver applies. That spread is exactly why candidates are blindsided by returns. Run the conservative version before you submit, and if it clears, write your descriptions so the reviewer reaches the same number without effort.

If You Come Up Short

If the conservative math lands under the requirement, you have three moves — and they stack:

Know Where You Stand Before Exam Day

The experience requirement has a six-year runway — exam readiness is the gate that matters now. CISSP.app’s adaptive mock exams show your predicted readiness across all eight domains, so you know when you are actually ready to book.

Check Your Readiness Free →

7-day free trial · Covers CISSP, CCSP, and CISM

FAQ: CISSP Qualifying Experience

Does help desk experience count toward the CISSP?

The security portion can. Pure end-user support does not qualify, but access provisioning, incident escalation, endpoint remediation, and account lifecycle work are legitimate Domain 5 and Domain 7 experience. Claim the documented security fraction of the role, not the whole role.

Does part-time work count toward CISSP experience?

Yes, prorated. Part-time work of 20–34 hours per week accrues credit by hours: roughly 1,040 hours equals six months of credit and 2,080 hours equals a year. Work below 20 hours a week does not accrue credit.

Do internships count toward the CISSP experience requirement?

Paid internships count under the same rules as employment. Unpaid internships can count with written documentation of role and hours from the organization. Get the documentation while the internship is recent — it is much harder to obtain years later.

Can I take the CISSP exam before I have five years of experience?

Yes. Passing without the full experience makes you an Associate of ISC2, with up to six years from your exam date to accumulate the remainder. Your exam result does not expire within that window.

Does a master’s degree waive more experience than a bachelor’s?

No. The education waiver is one year, satisfied by a four-year degree or regional equivalent. A master’s degree does not stack a second year, and a degree plus an approved credential still waives only one year total.

Do overlapping jobs count twice?

No. Experience is measured in calendar months, and a month in which you held two qualifying roles is still one month of credit. This is one of the most common causes of experience-math returns.