ISC2 cut the CISSP experience waiver list roughly in half on April 1, 2026, and the credentials that came off it include some of the most widely held certifications in security. Coverage at the time focused on the removals. Six months on, the more useful question is which credentials survived, and the reporting on that point contradicts itself often enough to be worth settling against the source.
Twenty-five credentials currently qualify for the CISSP one-year experience waiver, down from roughly 50 before April 1, 2026. CEH, CISA, CRISC, OSCP, and most GIAC certifications were removed. Security+, CySA+, CASP+, SecurityX, CISM, the Cisco security track, and the full ISC2 family survived. Applications submitted on or after April 1, 2026 are governed by the new list.
What is the CISSP experience waiver?
The CISSP requires five years of cumulative, full-time work experience across at least two of the eight domains. The waiver reduces that to four years for candidates who hold a qualifying post-secondary degree or an approved credential.
Only one waiver applies. A bachelor’s degree in computer science and a CISM don’t stack into a two-year reduction; a candidate picks one. The degree side of the waiver was untouched by the April change and still covers bachelor’s or master’s degrees in computer science, information technology, or a related field.
ISC2 counts full-time experience monthly, defining a qualifying month as at least 35 hours per week across four consecutive weeks. Part-time work between 20 and 34 hours per week converts at 1,040 hours for six months of credit, or 2,080 hours for 12 months. Paid and unpaid internships both count with documentation on official letterhead, and a registrar can verify academic internships.
What changed on April 1, 2026?
ISC2’s Standards and Practice team reviews the waiver list as part of the normal examination lifecycle, and the April revision applied three criteria to every credential on it. A qualifying certification needs a publicly available exam outline, ANAB ISO/IEC 17024 accreditation or equivalent proctored rigor from a reputable body, and at least 90% content alignment with two or more CISSP domains. Credentials that missed any of the three came off.
The cutoff is the application date, not the exam date. Anyone who submitted a CISSP certification application before April 1, 2026 was assessed against the older list. Applications from that date forward are assessed against the current one.
Which certifications still qualify for the CISSP experience waiver?
These 25 credentials satisfy one year of the experience requirement as of July 2026:
- AWS Certified Security – Specialty
- Certified Cloud Security Professional (CCSP)
- Certified in Governance, Risk and Compliance (CGRC)
- Certified Information Security Manager (CISM)
- Certified Secure Software Lifecycle Professional (CSSLP)
- Cisco Certified Internetwork Expert (CCIE) Security
- Cisco Certified Network Associate (CCNA)
- Cisco Certified Network Professional Security (CCNP Security)
- CompTIA Advanced Security Practitioner (CASP+)
- CompTIA CySA+
- CompTIA Security+
- CompTIA SecurityX
- GIAC Global Industrial Cyber Security Professional (GICSP)
- GIAC Information Security Fundamentals (GISF)
- GIAC Information Security Professional (GISP)
- GIAC Security Leadership Certification (GSLC)
- HealthCare Information Security and Privacy Practitioner (HCISPP)
- Information Systems Security Architecture Professional (ISSAP)
- Information Systems Security Engineering Professional (ISSEP)
- Information Systems Security Management Professional (ISSMP)
- Microsoft Certified Cybersecurity Architect
- Systems Security Certified Practitioner (SSCP)
- Zscaler Digital Transformation Administrator (ZDTA)
- Zscaler Digital Transformation Engineer (ZDTE)
- Zscaler Digital Experience Administrator (ZDXA)
Two entries on that list are worth noticing. The CCNA is a general networking certification rather than a security one, and it survived a cull that removed several credentials aimed squarely at security work. And four GIAC certifications remain out of the eight or more that previously qualified, with the survivors skewing toward leadership and industrial control rather than incident response or forensics.
Which certifications were removed?
ISC2 published the active list rather than a removal list, so the removals have to be established by absence. The credentials most commonly reported as cut, and confirmed absent from the current list, are the Certified Ethical Hacker (CEH), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Offensive Security Certified Professional and Expert (OSCP and OSCE), and the bulk of the GIAC catalog including GSEC, GCIH, GCFA, and GCIA.
Applying ISC2’s stated criteria explains most of the pattern. CEH and OSCP test offensive technique, which maps to a narrow slice of Domain 6 rather than 90% of two domains. CISA tests audit and assurance practice. CRISC is scoped to IT risk identification and control. None of them span the breadth the criteria demand, whatever their standing in the market.
The practical effect is that the CEH-then-CISSP progression a lot of candidates were told to follow no longer produces a year of credit. Anyone weighing that path now can compare the two credentials on their own merits in the CISSP versus CEH breakdown, or look at how the CISSP and OSCP differ in scope, without the waiver factoring into the decision.
What should candidates do if their credential was removed?
The Associate of ISC2 path is the mechanism ISC2 built for exactly this gap. Passing the exam without the full experience requirement converts to Associate status, which carries a $50 annual maintenance fee instead of $135 and gives a candidate up to six years to complete the experience and convert to full certification.
The alternative is earning a credential that’s still on the list, and the arithmetic there rarely works. A Security+ or CySA+ exam costs a few hundred dollars and takes weeks of preparation to buy back one year, which is worth doing only for a candidate sitting at exactly four years of experience with no degree. At three years or fewer, the waiver doesn’t close the gap and the effort goes into accruing experience instead.
One timing detail catches people. Passing the exam starts a nine-month clock to submit the certification application. The five-year experience requirement and that nine-month window are separate constraints, and a candidate who passes early can miss the application deadline while still short on experience. The full certification path covers how the exam, endorsement, and experience requirements sequence together.
Frequently Asked Questions
Does CEH still count toward the CISSP experience requirement?
No. The Certified Ethical Hacker was removed from the ISC2 waiver list effective April 1, 2026. Applications submitted before that date were assessed against the older list.
How many certifications qualify for the CISSP experience waiver now?
Twenty-five, as published by ISC2 in July 2026, down from roughly 50 before the April revision. The list is reviewed as part of the normal examination lifecycle and can change again.
Can I combine a degree and a certification to waive two years?
No. ISC2 permits only one waiver per candidate. A qualifying degree and an approved credential each reduce the requirement by one year, and they can’t be stacked.
Does CISA still waive a year for the CISSP?
No. CISA was removed from the approved list effective April 1, 2026, along with CRISC. CISM from the same issuing body remains on the list.
Is Security+ still on the CISSP waiver list?
Yes. CompTIA Security+, CySA+, CASP+, and SecurityX all remain approved for the one-year waiver as of July 2026.
What happens if I pass the CISSP exam without enough experience?
You become an Associate of ISC2 and have up to six years to accrue the required experience. The Associate annual maintenance fee is $50, compared with $135 for full certification.
Which GIAC certifications still qualify?
Four: GICSP, GISF, GISP, and GSLC. Other GIAC credentials including GSEC, GCIH, and GCFA are no longer on the approved list.
The verdict
Candidates within a year of meeting the full requirement should check their credential against the list above before submitting anything, because the cost of getting it wrong is a rejected application and a restarted nine-month clock. Everyone else should stop optimizing for the waiver. It buys one year against a five-year requirement, the list has now proven itself changeable, and planning a certification path around a policy ISC2 reviews on its own schedule is a poor use of study time.
For candidates who lost a waiver they were counting on, Associate of ISC2 status is the better move than chasing a replacement credential. It costs $50 a year, preserves the exam result for six years, and puts the CISSP letters on the résumé timeline without a second exam in between.
Tara Kohl is a 20-year IT veteran whose career has centered on information security and risk management. She holds the CISSP and CISM along with a range of additional certifications, and she's spent most of those years consulting for major aerospace firms and government contractors, where security and compliance demands sit at the top of the priority list.
