Salary & Career Data / June 12, 2026 / 7 min read

CISSP Without Experience: Associate of ISC2 vs SSCP

The CISSP’s five-year experience requirement stops a lot of early-career people before they start, and it shouldn’t, at least not in the way most assume. ISC2 lets anyone sit the exam, experience or not. For candidates who aren’t at five years yet, there are two real on-ramps: pass the CISSP now and hold Associate of ISC2 status while the experience accrues, or take the SSCP, a shorter and cheaper exam with a one-year requirement that later shaves a year off the CISSP’s five.

Anyone can sit the CISSP exam without the five years of experience; passing earns Associate of ISC2 status and a six-year window to finish the requirement. The other route for early-career candidates is the SSCP, a $249 exam with a one-year experience requirement that also waives one year of the CISSP’s five later on. Which path makes sense mostly comes down to how far the candidate is from the five-year mark.

Can you take the CISSP exam without five years of experience?

Yes. There’s no experience check at registration. ISC2 verifies experience during the endorsement process after a candidate passes, not before they sit. A candidate who passes without the required experience is offered the Associate of ISC2 designation during the certification application, pays a first Annual Maintenance Fee of $50, and starts the clock on a six-year window to accumulate the experience.

It’s the same exam every CISSP candidate takes: $749, adaptive format, 100 to 150 questions in a three-hour limit, same passing threshold. Nothing about the exam gets easier because the candidate is early in their career. The Associate route changes when the experience is verified, not what’s tested.

What the full CISSP actually requires

Full certification requires five years of cumulative, full-time work experience in at least two of the eight domains of the CISSP Exam Outline. The accounting is more flexible than the headline number suggests. ISC2 counts full-time experience monthly, with a month defined as at least 35 hours per week for four consecutive weeks. Part-time work between 20 and 34 hours a week converts at 1,040 hours for six months of credit or 2,080 hours for a full year. Internships count too, paid or unpaid, with documentation on official letterhead.

One year of the five can be waived, once, in one of two ways: a bachelor’s or master’s degree in computer science, IT, or a related field, or a credential from ISC2’s approved waiver list. A degree and a credential can’t be stacked to waive two years.

How the Associate of ISC2 route works

Pass the CISSP exam, select the Associate pathway during the certification application, and pay the $50 AMF. From the exam date, an Associate has six years to reach the five-year experience threshold (effectively four years of work for anyone using the degree or credential waiver). Maintaining the designation costs $50 a year plus 15 CPE credits annually. When the experience is in place, the Associate submits an endorsement application, has the experience verified by an ISC2 member in good standing, pays an $85 upgrade fee, and converts to full CISSP status on a standard three-year certification cycle.

The catch is in the title. An Associate of ISC2 cannot use the CISSP designation in any form, on a resume, a LinkedIn profile, or an email signature. The digital badge ISC2 issues doesn’t even disclose which exam the Associate passed. For a hiring manager reading closely, “Associate of ISC2, CISSP exam passed” in a resume’s text is a meaningful signal. For an automated filter screening on the string “CISSP,” it usually isn’t.

How does the SSCP compare?

The Systems Security Certified Practitioner is ISC2’s operational credential, aimed at the hands-on side of security work: administering access controls, monitoring, incident response, network security. It covers seven domains, and the bar to full certification is one year of full-time experience in any one of them. A bachelor’s or master’s degree in a related field satisfies the entire year, which means many recent graduates qualify for the full credential the day they pass.

The exam costs $249. Since October 1, 2025 it has used the same adaptive format as the CISSP: 100 to 125 questions, a two-hour limit, and a passing score of 700 out of 1,000. The SSCP is approved under the U.S. Department of Defense’s 8140 directive, which matters for anyone targeting defense or government contracting roles. And because it sits on ISC2’s waiver list, holding the SSCP later removes one year from the CISSP’s five-year requirement.

CISSP-as-Associate vs. SSCP at a glance

CISSP (Associate route) SSCP
Exam fee $749 $249
Exam format Adaptive, 100–150 questions, 3 hours Adaptive, 100–125 questions, 2 hours
Experience for full certification 5 years in 2 of 8 domains 1 year in 1 of 7 domains
Effect of a qualifying degree Waives 1 of the 5 years Satisfies the full year
Time allowed as an Associate 6 years 2 years
What the candidate can claim now Associate of ISC2 only Full SSCP title once the year is verified
Counts toward the other later No effect on SSCP Waives 1 year of CISSP experience

Which route fits which candidate?

For a candidate with no qualifying experience at all, neither path produces a full credential right away, and the Associate windows differ sharply: six years on the CISSP side, two on the SSCP side. A career changer who passes the SSCP exam before landing a first security or IT role has a tight two-year deadline to log that one year of experience.

For a candidate one to three years into IT or security work, the SSCP delivers a full, claimable credential immediately, banks a one-year waiver against the future CISSP requirement, and costs a third of the CISSP exam fee. The case for jumping straight to the CISSP exam instead is momentum: the candidate studies once for the harder exam, locks in the pass, and lets the six-year window absorb the remaining experience. Both arguments hold; they optimize for different things, a credential now versus the bigger exam behind them.

Candidates at four years or more should check their math before choosing either. Four years of qualifying experience plus a degree or waiver-list credential meets the full requirement today. Reviewing work history against the eight domains carefully, including part-time work and internships, sometimes reveals a candidate is closer than they assumed.

Frequently Asked Questions

Can you take the CISSP exam with no work experience?

Yes. ISC2 doesn’t verify experience at registration, only during endorsement after a pass. A candidate who passes without the required five years becomes an Associate of ISC2 and has six years to complete the experience.

Can an Associate of ISC2 put CISSP on a resume?

No. The CISSP title belongs only to fully certified members. An Associate can state that they passed the CISSP exam and hold the Associate of ISC2 designation, but using “CISSP” as a credential violates ISC2’s rules.

Does the SSCP count toward the CISSP experience requirement?

It waives one year of the five. The SSCP appears on ISC2’s approved credential waiver list, updated April 1, 2026, so an SSCP holder needs four years of qualifying experience for the full CISSP instead of five.

How much does each path cost up front?

The CISSP exam is $749 and the SSCP exam is $249. Associates of ISC2 on either path pay a $50 annual maintenance fee and earn 15 CPE credits per year until they convert to full certification.

What happens if the Associate window runs out?

The designation expires. A candidate who doesn’t complete the experience requirement and endorsement within the window (six years for CISSP, two for SSCP) loses the Associate status and would need to pass the exam again to pursue certification.

The verdict

For candidates with at least one year of qualifying experience and three or more years still to go before hitting five, the SSCP first is the stronger play: a full credential immediately, a year removed from the CISSP requirement, and a $249 exam instead of a $749 one. For candidates within roughly two years of the five-year threshold, sitting the CISSP now as an Associate usually wins. The hard exam gets done while study momentum is high, and the six-year window carries essentially no risk at that distance. For candidates with no qualifying experience at all, the better investment is the first IT or security role itself; both exam fees spend better after that job exists than before it.

Tara Kohl

Tara Kohl is a 20-year IT veteran whose career has centered on information security and risk management. She holds the CISSP and CISM along with a range of additional certifications, and she's spent most of those years consulting for major aerospace firms and government contractors, where security and compliance demands sit at the top of the priority list.