Cybersecurity Certification Prerequisites Explained (2026)
Updated August 2, 202625+ min read

Cybersecurity Certification Prerequisites: What You Actually Need

Required experience, education waivers, provisional options, and zero-prerequisite paths — mapped by career stage.

What you’ll learn in this article…

  • CompTIA Security Plus and ISC2 CC require zero prior work experience.
  • CISSP demands five years across two CBK domains, with degree waivers available.
  • Passing the exam first and earning Associate status lets you certify before meeting experience rules.

CISSP demands five years of cumulative paid experience across two of eight domains before ISC2 issues the credential outright. GIAC's GSEC and GCIH ask for nothing: no degree, no prior title, no verified history, just a passing exam score. That gap confuses candidates every day, and it shapes which credential actually fits where you stand right now.

The tension isn't just about eligibility. It's about sequencing: pursuing a five-year-gated credential while you have zero industry hours wastes money on early attempts and delays the associate-level detours that could get you working sooner.

Credential bodies increasingly build in provisional statuses, waivers, and stacked pathways precisely because the old all-or-nothing model shut out too many capable career changers.

When you browse the Cybersecurity Certification Finder, you'll see two types of experience language: hard gates and friendly suggestions. Formal prerequisites are mandatory eligibility requirements that a candidate must meet before they can sit for an exam or before the credential is awarded. Recommended experience is the vendor's guidance about the background that creates a realistic chance of success , but it does not block exam registration.

Mandatory vs. advisory requirements

CompTIA's lineup illustrates the gap clearly. The Security+ exam (SY0-701) has no formal prerequisites.1 Anyone can register. What you will find is a recommendation: two years of IT administration experience with a security focus.1 CySA+ and PenTest+ also lack formal gates but suggest three to four years of hands-on work.2 The advanced CASP+ recommends ten years of general IT experience and five years of hands-on security practice.2 Across all of these, meeting that recommended experience is not verified at any point before you take the test.

In contrast, the CISSP from (ISC)² enforces a mandatory five years of cumulative, paid, full-time work in at least two of the eight domains of the Common Body of Knowledge. You can pass the exam without that experience, but you will not receive the full CISSP designation until the requirement is verified. You join as an Associate of (ISC)² instead and have up to six years to earn the experience. This distinction between a registration gate and a post-exam endorsement requirement is critical for mapping your career timeline.

Certification, certificate, or bootcamp? Spotting the difference

Terminology gets muddied quickly. Cybersecurity certifications, like Security+ or CISSP, are Cybersecurity Certifications; they are standalone industry-recognized credentials that demonstrate mastery of a certain body of knowledge, typically via a proctored exam and with ongoing renewal requirements. A professional certificate is a course completion award from a training company or university platform, often lacking a live proctored exam and sometimes carrying no renewal obligation. An academic certificate is credit-bearing and granted by a college, sometimes stacking into a degree. A bootcamp credential is a badge of completion from a short intensive program, not accredited. A vendor product certification (think Microsoft SC-900) validates skill with a specific tool or platform. When you research "cybersecurity certification prerequisites," know which category you are dealing with: much confusion stems from not understanding the difference between cybersecurity certifications vs bootcamps, academic certificates, and product certifications.

No prerequisites does not mean no preparation

An open registration policy can be misleading. The Security+ exam is written for someone who already has two years of IT experience. Skipping straight to it without networking and operating system fundamentals leads to a significantly higher failure rate. Treat the recommended experience as a realistic gauge of the exam's difficulty level. Preparation time, study materials, and hands-on labs fill the gap that formal work history would normally cover. If a credential recommends two years of experience, budget several months of focused study to bridge that gap.

When do prerequisites actually apply?

Prerequisites can surface at three distinct moments: - Exam registration: Some credentials require documented experience before you can book a seat. - Post-exam endorsement: You pass the exam but must submit proof of work experience to earn the full title. This is the CISSP model, and it also exists in other (ISC)² certifications. - At renewal: Continuing education credits and sometimes active work experience in the field are required to maintain the credential.

Understanding which stage a requirement hits lets you plan whether you can start studying now and claim the credential later, or whether you need to build experience first.

Prerequisite Comparison Across Major Cybersecurity Certifications

The cybersecurity certification landscape is shifting toward clearer on-ramps for newcomers, even as top-tier credentials tighten their experience requirements. ISC2's three-tier framework, Certified in Cybersecurity (CC), Systems Security Certified Practitioner (SSCP), and Certified Information Systems Security Professional (CISSP), illustrates how prerequisites escalate with career stage, while still offering flexibility through waivers and associate paths.

Experience Requirements at a Glance

The work experience demanded by each certification sets the baseline for who should pursue it.

  • CISSP: Requires 5 years of cumulative paid work experience in at least 2 of the 8 CISSP domains, as detailed in the CISSP experience requirements. A 1-year education waiver reduces this to 4 years for holders of an approved degree or certain other certifications. The CISSP experience waiver list was tightened in April 2026, removing CEH, CISA, and OSCP, so candidates should verify current eligible credentials.
  • SSCP: Demands 1 year of paid work in at least 1 of the 7 SSCP domains, as outlined in the SSCP certification requirements. A relevant degree or approved credential can fully replace the 1-year requirement, making it accessible for those with academic background but limited practical hours. Part-time work and internships count proportionally: 1,040 hours equal 6 months, 2,080 hours equal 1 year.1
  • CC (Certified in Cybersecurity): Has zero experience or degree requirements, designed specifically for individuals with no IT or security background, serving as a foundational stepping stone among cybersecurity certifications without a degree.2

Education Waivers and Associate Pathways

Both CISSP and SSCP offer education waivers, but their scope differs. The CISSP waiver knocks off only 1 year, so even with a bachelor's degree, you still need 4 years of work experience. The SSCP waiver can eliminate the entire experience requirement, effectively turning it into an entry-level credential for degree holders.

For those who cannot yet meet the experience mandates, ISC2 provides an Associate designation. You can pass the CISSP or SSCP exam and become an Associate of ISC2, then gain the required experience within a 6-year window. Once verified, you convert to full certification. The CC certification does not offer an Associate path because it has no experience requirement, passing the exam alone grants the full credential.

Endorsement and Verification Differences

CISSP and SSCP both require endorsement from an existing ISC2-certified professional who can attest to your experience claims. ISC2 may audit your application, so documentation like job descriptions and pay stubs should be kept ready. The CC credential is self-endorsing: no sponsor or audit process, which streamlines entry.

This tiered model lets you align prerequisites with your current reality. If you have zero experience, start with CC. With some IT security background, target SSCP. For seasoned professionals, CISSP remains the gold standard, but only after you've logged the hours.

Prerequisites by Career Stage: Entry, Mid-Level, and Advanced

Cybersecurity certifications are not one-size-fits-all; the prerequisites you face, and the doors they open, shift dramatically depending on your career stage.

Entry Level (0-2 Years of Experience)

If you are brand new to cybersecurity, target cybersecurity certifications for beginners that have no formal work experience requirements. The ISC2 Certified in Cybersecurity (CC), CompTIA Security+, Google Cybersecurity Certificate, and GIAC GSEC all allow you to sit for the exam without prior professional experience. That said, "recommended experience" is exactly what it sounds like, ignoring it can make the exam tougher. CompTIA suggests Security+ candidates have two years of IT administration with a security focus; GIAC recommends practical knowledge equivalent to what the GSEC covers. Even the ISC2 CC expects familiarity with basic networking and risk concepts. Treat these recommendations as study-skills checklists, not vetoes. For the Google certificate, zero prerequisites means you can start today, but you will still need hands-on labs and self-paced modules to pass the assessments.

Mid-Level (2-5 Years of Experience)

This is where formal prerequisites start appearing. The Certified Ethical Hacker (CEH) offers a dual path: complete official training or prove two years of information security work. CompTIA CySA+ has no mandatory years, but the exam is built around behavioral analytics skills typically gained after three to four years of security operations work. The (ISC)² SSCP requires a minimum of one year in one or more of the seven SSCP domains. ISACA certifications get specific here. CISA demands five years of IT audit, control, or security experience, though you can waive up to three years with certain degrees or other certifications, leaving you needing at least two years of actual work.1 CISM expects five years of information security experience, including three in management roles, across three of four domains within the past decade; waivers of up to two years are available if you hold CISSP, CISA, or a relevant master's degree.2 These waivers mean that career changers with adjacent IT management experience may qualify earlier than the raw number suggests.

Advanced (5+ Years of Experience)

At the advanced tier, experience must be both verifiable and domain-specific. The CISSP requires five years of paid, full-time work in at least two of the eight CISSP domains. CASP+ is designed for practitioners with ten years of IT administration, including five years of hands-on security, though CompTIA does not enforce a formal application audit for experience. The CRISC credential from ISACA asks for three years of experience in governance or risk response and reporting, covering a minimum of two domains, with no waiver options; every year must be earned. CISO-level certifications similarly demand senior leadership experience. Across these advanced credentials, the role target is clear: security architect, senior auditor, director of information security, or chief information security officer. If you are a few months short, investigate associate or provisional status for CISSP and ISACA exams5 to secure a time-bound window for building remaining experience.

Don't Self-Disqualify Before Checking Waivers

Many working IT professionals underestimate what counts. ISACA's experience windows extend ten years back4, and military time, internship roles, and part-time security duties can sometimes substitute. If you hold an adjacent certification like the CISSP, a bachelor's degree in information systems, or even certain business continuity credentials, you may reduce the five-year requirement for CISM or CISA. Always review the candidate handbook for the credential you are targeting before assuming you don't qualify. A conversation with a mentor or your local certification chapter can surface substitution paths you didn't know existed.

Cybersecurity Career Stage and Certification Pathway

Cybersecurity certifications align with three broad career stages, each defined by how much verified experience you need before you can sit for the exam or earn the full credential. This pathway shows representative certifications at each level, along with the roles they typically unlock.

Three-stage cybersecurity certification progression from entry level with zero experience through mid-level at two to five years to advanced at five or more years

How Work Experience Is Counted and Verified

ISC2 requires CISSP candidates to document five years of cumulative, paid, full-time work experience across at least two of the credential's eight Common Body of Knowledge (CBK) domains.1 That word "cumulative" matters: your years can span multiple employers, roles, and even career breaks, but you cannot count experience in two domains for the same period of employment unless your duties genuinely covered both. Understanding exactly how each certifying body tallies time, and what evidence you will need, prevents surprises during the endorsement stage.

Full-Time, Part-Time, and Contract Work

ISC2 defines full-time work as 35 or more hours per week. A four-week stretch at that pace equals one month of credited experience. Part-time work (20 to 34 hours per week) is converted using an hour-based formula: 1,040 hours of qualifying part-time work earns six months of credit, and 2,080 hours earns a full year. You must log at least 20 hours per week for any period to count at all.1

The SSCP credential uses the same hour-based conversion but defines full-time as 34 hours per week.3

ISACA takes a different approach. For credentials like CISM and CISA, ISACA counts qualifying work by calendar years in which you had at least partial engagement in the relevant domain. This means a contract that ran from March through October of a given year can still count as a full calendar year of experience, as long as the duties align with the certification's job practice areas. Neither organization distinguishes between W-2 employment and independent contracting, provided the work itself maps to the required domains.

Military and Federal Service

CISSP, CISM, CISA, and CEH all align with the DoD 8140 framework (the successor to 8570)1, which means military and federal cybersecurity roles are recognized as qualifying experience. If your Military Occupational Specialty (MOS), Navy Enlisted Classification (NEC), or Air Force Specialty Code (AFSC) maps to one or more CBK domains, that service time counts. ISC2 explicitly accepts military duties when they correspond to domain topics such as security operations, identity and access management, or risk management.2

Veterans should gather DD-214 forms and any duty-description memoranda before starting the application. These documents help an endorser verify your domain coverage. ISC2 also publishes resources specifically for veterans transitioning from military to cybersecurity, walking through how common defense roles translate to CBK domains.2

Internships and Self-Employment

ISC2 accepts both paid and unpaid internship experience, which is more generous than many candidates expect. The catch is documentation: you will need a letter on company or academic-registrar letterhead that confirms your position title, employment dates, and the duties you performed. The duties must map to at least one CBK domain.1

Self-employed consultants face an extra layer of proof. Because there is no HR department to vouch for you, plan to supply client reference letters, signed contracts or statements of work, and project summaries that describe in-domain activities. A portfolio of penetration-test reports, risk assessments, or incident-response documentation can strengthen your case if you are audited.

Acceptable Evidence and the Endorsement Process

When you submit your certification application, you will need an endorser, a current credential holder in good standing, who can attest to your professional experience. The endorser does not need to have worked with you directly, but they should be able to speak to the legitimacy of your claimed experience.

Typical supporting documents include:

  • HR verification letters: Formal letters on company letterhead listing your title, dates of employment, and relevant responsibilities.
  • DD-214 or military service records: Essential for veterans claiming defense-related experience.
  • Contracts and statements of work: Useful for freelancers and consultants proving project-based engagements.
  • LinkedIn history: Helpful as a supplementary timeline, though it is not accepted as primary evidence by ISC2 or ISACA.

ISC2 reserves the right to audit any application. If selected, you will be asked to provide the documentation listed above within a set window. Keeping organized records from the start, even if you are years away from sitting for an exam, saves significant stress later.

The bottom line: start tracking your hours, archiving project descriptions, and collecting reference contacts now. The experience clock is often already running; the challenge is proving it when the time comes to apply.

Questions to Ask Yourself

Many certifications define "qualifying experience" narrowly. If your background is in help desk, system administration, or software development, some of it may count and some may not. Knowing the difference before you apply prevents surprises during verification.

Programs like the ISC2 Associate path let you pass the exam first and earn full certification later. If your employer or a job posting requires the full credential now, a provisional status may not satisfy that requirement.

Some positions, especially in federal contracting and DoD environments, mandate a particular credential by name. If that credential requires years of domain experience you do not yet have, you may need to pursue a stepping stone certification first.

Education Waivers and Degree Substitutions

Certification bodies are steadily expanding pathways that allow academic degrees and existing credentials to replace portions of required experience, but the specifics shift with each update to an exam's candidate handbook. Understanding what qualifies, and what absolutely does not, can shorten your timeline without compromising your application.

ISC2 CISSP Experience Waivers

ISC2 permits a maximum reduction of two years from the five-year CISSP work experience requirement. A four-year accredited degree (or equivalent regional credential) automatically waives one year. Holding another approved ISC2 credential, such as the SSCP certification, CCSP certification, or ISACA's Certified Information Security Manager (CISM), waives a second year. You cannot combine multiple credentials to exceed the two-year cap. The degree and the credential must be current, and the waiver applies only to the experience requirement; you must still pass the exam and complete the endorsement process.

ISACA CISM and CISA Substitutions

ISACA offers similar flexibility for the Certified Information Security Manager (CISM) and Certified Information Systems Auditor (CISA). A degree in a related field -- typically information security, information technology, accounting, or business administration -- can substitute for up to two years of work experience, depending on program-specific guidelines. Holding select partner credentials (for example, CISSP, CISA, or CISM) may replace an additional year, with a combined maximum of up to three years waived. Because ISACA updates its list of approved degrees and credentials periodically, always reference the current CISM or CISA certification requirements on the official ISACA site before counting a substitution.

EC-Council Training Pathway

The Certified Ethical Hacker (CEH) uses a unique training waiver. EC-Council offers two eligibility routes: the experience path, requiring two years of verified information security work, and the training path, which eliminates the experience prerequisite entirely if you complete an official EC-Council CEH course. This means a newcomer can sit for the CEH exam with no prior job history, provided they attend instructor-led training, an online course, or an approved academic program. The experience waiver is absolute for the training route -- no additional degree or credential substitution is needed. However, employer verification of the training is not required; the course completion certificate serves as proof.1 A similar training-first philosophy extends to certain other EC-Council products, though some advanced credentials like the Certified Penetration Testing Professional (CPENT) still strongly recommend prior CEH or offensive security knowledge.2

What Does Not Qualify

  • Bootcamp certificates: Short-duration cybersecurity bootcamps, even those affiliated with universities, do not count as degree substitutes for ISC2 or ISACA experience waivers.
  • Vendor product certifications: Credentials tied to a specific product (e.g., a cloud platform's associate-level cert) are generally excluded from waiver lists unless explicitly listed by the certifying body.
  • Non-accredited credentials: Non-accredited or unregulated digital badges, microcredentials, and on-the-job training certificates rarely, if ever, replace formal experience requirements.

Verifying Your Specific Credentials

Because each issuing body maintains a living document of approved substitutions, never assume your degree or certificate qualifies. Before investing in an exam attempt, check the exact education and credential substitution list published by (ISC)², ISACA, or EC-Council for the version of the exam you intend to take. This step alone can prevent a rejected application or unexpected re-examination fees.

Associate and Provisional Certification Paths

Understanding Associate of (ISC)² Status

For career changers and recent graduates who pass the CISSP, SSCP, or CCSP exam but do not yet have the required work experience, (ISC)² offers an Associate designation. This status lets you demonstrate exam-level mastery to employers immediately while you accumulate the required professional experience. Associate of (ISC)² candidates have up to six years from the exam pass date to complete the experience requirement and upgrade to full certification.

The ISACA Approach: No Provisional Alternative

ISACA does not provide a parallel provisional pathway. Candidates for certifications like CISA, CISM, or CRISC must meet all experience requirements before applying, and passing the exam alone does not confer any interim status. If you pass an ISACA exam but lack the needed experience, you cannot use any ISACA mark or designation until you have completed the full application and been awarded the credential. This makes the (ISC)² Associate route particularly valuable for those who want to start signaling cybersecurity competence early.

Strategic Value for Career Changers

Associate status serves as a bridge credential. It tells hiring managers and recruiters that you have passed a rigorous exam and are on a documented path to full certification. For those with minimal professional cybersecurity experience , especially career changers weighing a cybersecurity degree vs certifications , the Associate of (ISC)² status adds immediate credibility to a resume, helping candidates stand out for cybersecurity jobs and opening doors to entry and mid-level roles that require foundational knowledge. While it is not a substitute for the full credential in every context, it can be the differentiator that gets a candidate an interview while they continue building verified work hours.

Limitations and Employer Requirements

Associate designations do not always satisfy formal mandates. For example, U.S. Department of Defense 8140 baseline certifications require the full CISSP, not associate status. Some employers and government contracts explicitly require the fully certified designation, so it is important to check job announcements carefully. Additionally, Associates are prohibited from using the full certification mark or claiming to hold the certification itself, a restriction enforced by (ISC)²'s code of ethics.

Maintaining Associate Status

Even during the provisional period, Associates must meet ongoing obligations. Annual maintenance fees apply, and CPE credits must be earned each year according to (ISC)²'s continuing education policy , free cybersecurity resources can help fulfill these requirements. Neglecting these requirements can result in the loss of associate standing, which would mean retaking the exam if you later want to pursue certification. Treat the associate period as an active, monitored phase, not a holding pattern.

Certifications With No Formal Prerequisites

Both the GIAC Security Essentials (GSEC)1 and the GIAC Certified Incident Handler (GCIH)3 list zero formal prerequisites, meaning any candidate can register and sit the exam without submitting proof of degrees, prior credentials, or verified work history. That open-door policy makes them unusual among mid-tier cybersecurity credentials, most of which gate entry through experience audits or endorsement.

What "No Prerequisites" Actually Means

GIAC's policy is straightforward: pay the exam fee, register, and schedule your proctored session. There is no application review, no endorser signature, and no experience attestation form to complete before you test. Both GSEC and GCIH exams are proctored and open-book, with GSEC requiring a 72% passing score. Certification is valid for four years before renewal.

That said, the absence of a formal prerequisite is not the same as the absence of a recommended background. GIAC suggests roughly 1 to 2 years of hands-on IT security work before attempting GSEC1, and 2 to 3 years of incident response or security operations exposure before GCIH4. These are guidelines meant to protect your investment, not gatekeeping rules.

Cost and Practical Considerations

  • Exam fee: $949 to $999 for either GSEC or GCIH, one of the higher single-exam price points in the industry.
  • Renewal: $469 to $499 every four years, plus 36 continuing professional education (CPE) credits.
  • Training: SANS training courses are strongly associated with GIAC exams but are not required. You can challenge the exam directly, though self-study candidates should plan for substantial preparation using the official exam objectives and practice tests.
  • Best fit: GSEC suits IT security generalists moving into a defined security role; GCIH fits analysts working in a SOC, incident response team, or threat detection function.

Other credentials with no formal prerequisites include CompTIA Security+, CompTIA CySA+, EC-Council CEH (via the self-study challenge path), and most vendor-specific certifications from Microsoft, Cisco, and AWS, see the cybersecurity certification directory for a complete list. These are the credentials career changers can pursue immediately, without waiting to accumulate verified work hours, and they can be the first step toward becoming a cybersecurity professional.

What Certified Cybersecurity Professionals Earn

The table below draws from the most recent Occupational Employment and Wage Statistics published by the U.S. Bureau of Labor Statistics (2024 data) for Information Security Analysts, the occupational category that most closely maps to the roles these certifications support. Keep in mind that these figures reflect the profession broadly and do not isolate the salary impact of any single certification. Factors such as employer size, geographic region, clearance level, years of experience, and the specific combination of credentials you hold all influence actual compensation.

MetricInformation Security Analysts (BLS 15-1212)
Total National Employment179,430
25th Percentile Annual Wage$92,160
Median Annual Wage$124,910
Mean Annual Wage$127,730
75th Percentile Annual Wage$159,600

Endorsement, Application, and Audit Process

Earning a passing score on a cybersecurity certification exam is only the first milestone. For credentials issued by ISC2 and ISACA, the endorsement and application process that follows is where your experience claims become official, and where audits can delay or derail certification if you are unprepared. Understanding the overall Cybersecurity Certification Methodology can help you navigate each step.

The ISC2 Endorsement Process

After passing an ISC2 exam such as the CISSP, you have nine months to complete the endorsement process. Here is what that involves:

  • Submit the online endorsement form: Log into your ISC2 candidate portal and complete the application, detailing how your work experience aligns with the certification's domain requirements.
  • Secure an endorser: You need an active ISC2 member in good standing to review and endorse your experience. If you do not know anyone who holds an ISC2 credential, the organization can act as your endorser, though this typically adds processing time.
  • ISC2 review and potential audit: Once submitted, ISC2 staff review your application. A percentage of applications are randomly selected for audit, which means you may be asked to provide employment verification documents, HR letters confirming job titles and dates, or project descriptions demonstrating domain coverage. Audit reviews typically take four to eight weeks, though complex cases can extend longer.

If your endorsement is approved, you receive your certification and begin the annual maintenance cycle. If audited and your documentation is incomplete, certification is delayed until you satisfy the verification requirements.

ISACA's Application and Verification Steps

ISACA credentials such as CISM and CISA follow a similar pattern, though the mechanics differ slightly:

  • Online experience verification: Submit your work experience through ISACA's certification portal, mapping your responsibilities to the relevant job practice domains.
  • Manager or supervisor references: Provide contact information for supervisors who can confirm your experience. ISACA may reach out directly to verify your claims.
  • Ethics agreement: Before certification is granted, you must formally agree to ISACA's Code of Professional Ethics. This is a binding prerequisite, not a box to check casually. Violations can result in certification revocation.
  • Audit risk: Like ISC2, ISACA randomly audits a portion of applications. Audited candidates must supply employment records, HR verification letters, or detailed project documentation.

Practical Tips for a Smooth Process

Whether pursuing ISC2, ISACA, or other credentials with endorsement requirements, preparation makes all the difference:

  • Keep employment records organized: Maintain copies of offer letters, HR verification letters, and performance reviews that document job titles, dates, and responsibilities.
  • Request HR verification letters in advance: Do not wait until you pass the exam. Ask your HR department for a letter confirming your employment dates and cybersecurity responsibilities while you are still employed, especially if you are changing jobs soon.
  • Maintain a project log: Track cybersecurity projects, incident response activities, policy development work, and other domain-relevant tasks. Note dates, your role, and outcomes. This log becomes invaluable during audits.
  • Identify your endorser early: For ISC2 credentials, reach out to potential endorsers before exam day. Confirm they are willing and that their membership is current.

The endorsement and application process exists to protect the value of these credentials. Treating it as a formality invites delays. Treating it as a professional milestone, with documentation prepared in advance, keeps your certification timeline on track.

Did You Know?

Don't count yourself out too early. If you've worked in networking, system administration, or development, that experience often maps directly onto a certification's required domains, even without a security-specific job title. Before assuming you fall short, check the issuing body's official experience mapping guidance; adjacent IT roles frequently qualify for partial or full waivers.

Recertification Prerequisites and Continuing Education

Earning a cybersecurity certification is not a one-time event. Every major credential requires ongoing maintenance, and if you let that maintenance lapse, the certification itself becomes invalid. Think of recertification as a standing prerequisite: you must continuously meet continuing-education and fee requirements to keep the credential you worked so hard to earn.

Continuing Professional Education Requirements

Most certifying bodies use a credit-based system, often called CPE (Continuing Professional Education), CEU (Continuing Education Units), or ECE (EC-Council Continuing Education) credits. The totals and pacing rules vary by organization.

  • CISSP (ISC2): 120 CPE credits over a three-year cycle2, with a minimum of 40 credits each year3. The annual maintenance fee is $1353.
  • CISM and CISA (ISACA): 120 CPE credits over a three-year cycle, with a minimum of 20 credits per year. Annual maintenance fees for ISACA credentials are $45 per certification for members.
  • CompTIA Security+: 50 CEUs over a three-year cycle, or you can retake the current version of the exam instead. The annual fee is roughly $50 per year.
  • CEH (EC-Council): 120 ECE credits over a three-year cycle, with an annual maintenance fee of $80.
  • GIAC GSEC (SANS/GIAC): 36 CPE credits over a four-year cycle, with a renewal fee in the range of $429 to $459 per cycle.

Activities that typically qualify for credits include attending industry conferences, completing training courses, publishing research, participating in capture-the-flag events, and contributing to open-source security tools. Each issuing body publishes its own list of eligible activities, so always check the official handbook for your credential.

Exam Retake Policies

If you need to retake a certification exam, whether because your certification lapsed or you did not pass on the first attempt, most organizations enforce waiting periods. ISC2, for example, requires a 30-day wait after a first failed attempt, 90 days after a second, and 180 days after a third, with a maximum of four attempts per year. ISACA and CompTIA have their own retake windows and fees. Planning ahead matters because these waiting periods, which are governed by each vendor's online proctored exam retake policies, can delay your timeline significantly if you are not prepared.

What Happens When a Certification Lapses

This is the part that catches people off guard. If you stop paying annual fees or fall short on your CPE credits, most organizations offer a short grace period, often around 90 days for ISC2 credentials5. Once that window closes, you cannot simply pay the back fees and pick up where you left off. In most cases, a fully lapsed certification means you must sit for the exam again, pay the full exam fee, and meet all current prerequisites from scratch. For a credential like the CISSP, where the exam fee alone is $749, that is an expensive and time-consuming reset.

Practical Advice for Staying Current

Build recertification into your annual professional development plan rather than treating it as an afterthought. Set calendar reminders for fee deadlines, track your CPE credits throughout the year, and take advantage of low-cost or free earning opportunities like webinars, podcasts with structured learning components, and volunteer work with professional organizations. Employers sometimes cover maintenance fees and training costs, so check whether your organization offers a professional development budget before paying out of pocket.

The bottom line: a certification is only as valid as your commitment to maintaining it. Factor recertification costs and effort into your decision before you pursue any credential, and you will avoid unpleasant surprises down the road.

Frequently Asked Questions About Cybersecurity Certification Prerequisites

Below are answers to the most common questions about cybersecurity certification prerequisites. Each answer references specific credential requirements current as of mid-2026. For deeper guidance on any topic, see the relevant sections earlier in this guide.

Prerequisites vary widely by credential. Some certifications, such as CompTIA Security+ (a common first step on the CompTIA cybersecurity path) and ISC2 Certified in Cybersecurity (CC), have no formal degree or experience requirements to sit for the exam.1 Others require documented professional experience: CISSP requires five years,1 CISM requires five years,2 and CEH requires two years (or completion of official EC-Council training as a substitute).3 Most major certifications accept applications on a rolling basis and do not require a specific degree.1

For those making a cybersecurity career change, several respected certifications have no mandatory work experience. ISC2 Certified in Cybersecurity (CC) is free to take, ANSI-accredited, and open to anyone.4 CompTIA Security+ has no formal experience prerequisite, though CompTIA recommends about two years of IT experience.1 CompTIA CySA+ similarly has no hard prerequisite, though three to four years of hands-on experience is recommended.3 OSCP requires completion of the PEN-200 course but no prior professional experience.5

For CISSP, you must document five years of cumulative, paid, full-time work experience across at least two of the eight CISSP domains.1 An ISC2-certified professional must endorse your application, as outlined in the CISSP certification guide. ISACA follows a similar process for CISM, requiring five years of information security management experience.2 Both organizations may audit applications, so keep detailed records including job titles, dates, and descriptions of security-related responsibilities.

ISC2 accepts part-time work and internships toward CISSP experience requirements, but the hours are typically prorated. For example, part-time work is calculated at a rate that converts cumulative hours into full-time equivalent years. ISACA also allows part-time experience for CISM and CISA, provided it is relevant and verifiable. Unpaid internships may not qualify with every certifying body, so check the specific candidate handbook before relying on those hours.

Yes, but only partially. For CISSP, an approved four-year degree (such as a cybersecurity degree program) can waive one year of the five-year requirement, reducing it to four years. Note that ISC2 trimmed its approved waiver credential list from 50 to 25 effective July 1, 2026.6 For CISA, a two-year degree substitutes for one year of experience, and a four-year degree substitutes for two years.1 No major certification allows a degree to fully replace all required experience.

Associate status lets you pass a certification exam before you have the required work experience, then earn the full credential later. ISC2 offers an Associate of ISC2 designation for candidates who pass the CISSP exam but have not yet accumulated enough professional experience. ISACA offers a similar provisional path for CISM and CISA. This approach is especially useful for career changers and recent graduates who want to validate their knowledge while building qualifying experience.

After passing the CISSP exam, ISC2 grants you six years to accumulate the required five years of professional experience (four years if you qualify for the degree or credential waiver). During this window you hold the Associate of ISC2 designation. If you do not meet the experience requirement within six years, your exam result expires and you would need to retake the exam. Tracking your experience carefully from the start is essential.

If you have no IT background, start with a credential that has no experience prerequisite, like CompTIA Security+ or ISC2 Certified in Cybersecurity. For those planning a cybersecurity career change, associate or provisional status can bridge the gap while you earn required years. Experienced professionals can target advanced certs like CISSP that verify existing expertise. The certification finder on onlinecybersecurity.org helps you match your background to the right path, and a cybersecurity certification roadmap provides a step-by-step progression. Regardless of the path you choose, always verify the latest prerequisites directly with the certifying body: exam requirements and acceptable experience substitutions can change without notice.

Recent Articles

In this article

Follow us