cert eligibility

Can you earn CISSP - Certified Information Systems Security Professional? Eligibility and prerequisites

Review Can you earn CISSP - Certified Information Systems Security Professional? Eligibility and prerequisites exam facts, costs, eligibility notes, prep context, and official-source evidence.

Build my personalized career plan

Certification details change. Always confirm final pricing, availability, and credential terms on the official provider page linked in the sources below before you pay for anything.

Before you spend a dollar, know whether you can actually earn this credential now. Below is what the certifying body requires — every fact sourced and dated. A recommendation is labelled a recommendation, never a rule.

Eligibility: Not an entry credential. This requires years of verified, relevant work experience to fully earn. You can often pass the exam first and hold a provisional/associate status until you meet the experience — but it is not a first credential for someone with no experience. The alternative path is below.

See the certification itself: CISSP - Certified Information Systems Security Professional · what it costs · how to study for it free.

What it takes to earn it

RequirementDetailSource
Work experience to earn it5 years — 5 years of cumulative paid work experience in 2 or more of the 8 CISSP domains; qualifying part-time work and internships may count. ISC2 states that earning a post-secondary degree (bachelors or masters) in computer science, information technology (IT) or related fields may satisfy up to one year of the required experience, as may one additional credential from the ISC2 approved list, leaving a minimum of 4 years.official
PrerequisitesNone to sit the exam.official
EndorsementYes — endorsement by an ISC2-certified professional in good standing, completed within 9 months of the exam date.official
Recommended experience (not required)5 years of cumulative experience in 2 or more CISSP domains are required for full CISSP certification; up to 1 year may be waived by a qualifying degree or approved credential.official
Open registrationAnyone can sit the exam; full certification requires the experience and endorsement.official
Code of ethics / agreementAdherence to the ISC2 Code of Ethics is a condition of certification.official

If you don't have the experience yet

Pass the exam to become an Associate of ISC2; you then have up to 6 years to earn the 5 years of required experience before the full CISSP is awarded.

Alternative path source: official.

The honest read

If you're changing careers with no relevant experience, this is usually not the credential to start with — pursue an open, entry-friendly certification first and come back to this once you have the experience (or take the provisional/associate route above). Chasing an experience-gated credential first is the most common and most expensive wrong turn.

Being eligible to earn a credential is not the same as getting hired, and no certification guarantees a job. Requirements change — verify on the official page before you pay.

Good to know

Live-checked official CISSP experience requirements and Associate pages; full certification is experience-gated even though the exam may be taken earlier.

Core source records

This table lists the page’s core content records and their checked dates where recorded. Claim-specific citations appear beside the relevant text and may not be repeated here.

IDSupportsSourceChecked
CIT-01Eligibility & prerequisites for CISSP - Certified Information Systems Security Professional (as of 2026-07-26)Published source (isc2.org)Date not recorded
CIT-02Alternative path while required experience is incompletePublished source (isc2.org)Date not recorded

Ready to turn this decision into a plan?

Not sure which credential fits where you are now? Start the RoleMath planner to see which roles and entry-appropriate certifications match your background.