Can Beginners Take the ISC2 CISSP Exam?

  • Can a beginner take CISSP?
  • Published by: André Hammer on May 20, 2024
Group classes

The CISSP is a widely recognised security certification associated with experienced practitioners who can connect security controls, governance, risk and business impact.

Last updated: June 2026. Beginners can take the ISC2 CISSP exam, but passing the exam does not automatically make someone a CISSP. A candidate who passes without the required professional experience can become an Associate of ISC2 while they build the experience needed for full certification and complete endorsement.

This article is based on official ISC2 and Pearson VUE policy areas, including CISSP eligibility, the current exam outline, the Associate of ISC2 pathway, annual maintenance requirements and exam delivery rules. Those policies change periodically, so candidates should verify the latest details directly with ISC2 and Pearson VUE before booking an exam. The editorial approach is to separate official requirements from practical career advice, rather than treating CISSP as either impossible for beginners or suitable for every newcomer.

The short answer for beginners

A true beginner can sit the CISSP exam if they are prepared to study at CISSP level and meet the testing provider’s registration requirements. The more important question is whether taking it now supports their career plan. CISSP is written for people who can reason across security domains, weigh trade-offs and answer management-oriented scenarios, so exam readiness is different from simple interest in cybersecurity.

The full CISSP credential requires five years of cumulative paid work experience in at least two CISSP Common Body of Knowledge domains. A relevant four-year degree or approved credential can usually satisfy one year of that requirement, but it does not remove the need for professional experience. There is no bachelor’s degree requirement to take the exam or to become certified; the degree is only one possible experience waiver.

If a beginner passes the exam before meeting the experience requirement, they may hold Associate of ISC2 status rather than using the CISSP title. On a CV, that should be written accurately, for example as “Associate of ISC2 working toward CISSP,” rather than “CISSP certified.” This distinction matters because some employers and regulated roles require an active CISSP, and Associate status will usually signal progress rather than satisfy that requirement.

Eligibility outcomes for CISSP candidates. Source attribution: ISC2 CISSP eligibility and Associate of ISC2 policy areas; verify current wording with ISC2 before applying.
Candidate situationLikely outcome after passing the examPractical implication
Has the required experience across at least two CISSP domainsCan apply for endorsement toward full CISSP certificationThe candidate must document relevant work and complete the endorsement process.
Has some experience but not the full requirementCan become an Associate of ISC2 after passingThe candidate continues building qualifying experience before full certification.
Has little or no cybersecurity experienceCan still take the exam, but full CISSP is not awarded yetThe candidate should weigh whether CISSP-level study is the right first step.

What CISSP is really testing

CISSP is often misunderstood as a deeply technical exam where success depends mainly on memorising tools, commands or low-level implementation details. Technical knowledge helps, but the exam places heavy emphasis on judgment: how to prioritise risk, protect assets, design controls, respond to incidents, govern security programmes and make defensible decisions in business context.

This is why beginners sometimes struggle even after reading large volumes of material. They may know definitions but miss the intent of long scenario questions. A stronger preparation approach is to ask what risk is being reduced, who owns the decision, what policy or control should guide the response and which answer is most appropriate at the organisational level.

Common mistakes include assuming that a bachelor’s degree is mandatory, studying technical trivia at the expense of governance and risk, using outdated exam-format information, and practising only short recall questions. Candidates preparing early should spend time with scenario-based questions and the current ISC2 exam outline so their study reflects how the exam is framed now.

CISSP exam at a glance

The English CISSP exam uses a computerised adaptive testing format. Candidates should expect a demanding exam session rather than a simple knowledge quiz, and they should confirm all operational details before booking because ISC2 and Pearson VUE may update policies, delivery conditions and fees.

CISSP exam logistics. Source attribution: ISC2 CISSP exam outline and Pearson VUE delivery information; candidates should verify current details when registering.
AreaCurrent planning point
Exam formatComputerised adaptive testing for the English exam.
Number of items125 to 175 items.
Time allowedUp to 4 hours.
Passing score700 out of 1000 on a scaled score.
DeliveryDelivered through Pearson VUE testing arrangements.
Fees and retake policyPublished by ISC2 and Pearson VUE during the registration process; verify current fees, waiting periods and identification rules before scheduling.

The annual maintenance fee and continuing certification obligations also matter. Passing the exam is one milestone, while keeping an ISC2 status active requires following ISC2’s maintenance rules. Beginners should understand these obligations before treating the exam as a one-time transaction.

How endorsement works after passing

After passing CISSP, a candidate seeking full certification must complete endorsement. That means documenting qualifying work experience and showing how it maps to the CISSP domains. Job titles alone are rarely enough; the stronger evidence is the security responsibility performed, the decisions made and the domains covered.

An endorsement is commonly completed by an active ISC2-certified professional who can validate the candidate’s experience. If the candidate does not know an eligible endorser, ISC2 can act as endorser through its own review process. Either way, candidates should keep clear records of roles, dates, responsibilities and domain alignment before they need them.

For beginners, this has an important career-planning consequence. Passing early may create momentum, but the work still has to follow. Roles in security operations, governance, risk, identity, audit support, incident response, cloud security or secure systems administration may all contribute, provided the work genuinely aligns with the CISSP domains and ISC2 rules.

When beginners should start elsewhere

A beginner does not need to reject CISSP completely, but many candidates benefit from taking a staged route. The right first step depends on current role, available study time and hiring goal. Someone already working in IT operations or security support may be closer to CISSP readiness than a career changer with no exposure to networks, identity, risk or incident handling.

Choosing a starter route toward CISSP readiness. Source attribution: practical interpretation of CISSP eligibility and common entry-level security pathways.
Starting pointWhen it makes senseHow it supports CISSP later
CISSP now, as an Associate of ISC2 routeThe candidate already has strong IT or security-adjacent experience and needs CISSP-level knowledge for a planned role.It builds early familiarity with governance, risk and domain breadth while experience is still being earned.
SSCP firstThe candidate is in or near a hands-on security operations role.It can strengthen operational security foundations before moving into broader CISSP judgment and governance.
Security+ or ISC2 CC firstThe candidate is new to cybersecurity or changing careers from a non-technical background.It creates vocabulary, basic control knowledge and confidence before attempting CISSP-level material.

Structured study can help, but it should match the candidate’s current level. A newcomer who still needs core security vocabulary may be better served by foundational study before browsing broader ISC2 course options. Someone building technical context alongside security governance may also find adjacent topics such as Certified Ethical Hacker training useful, though ethical hacking preparation is not a substitute for CISSP eligibility or endorsement.

In practice, a staged route often produces better learning than rushing straight to advanced material. A candidate might first build networking and identity basics, then gain experience through service desk, systems administration, SOC analyst, audit support or cloud operations work, and later return to CISSP when the exam domains map to real responsibilities.

A realistic roadmap for a beginner

The most useful CISSP plan begins with a candid assessment of current experience. A candidate should compare their work against the CISSP domains, identify gaps and decide whether they are preparing for the exam now or preparing for the roles that will eventually make the credential meaningful.

  1. Read the current CISSP exam outline and note unfamiliar domains.
  2. Choose a starter certification or CISSP-level study route based on current experience.
  3. Build practical exposure through IT, security, governance, audit or cloud responsibilities.
  4. Practise long scenario questions that require risk-based reasoning.
  5. Document work experience as it develops so endorsement is easier later.

Study time should be spent on both concepts and decision-making. For example, access control study should cover authentication models and identity lifecycle, but candidates should also understand when business requirements, least privilege, segregation of duties and auditability affect the right answer. This style of thinking is closer to the exam than memorising isolated facts.

For candidates planning several security certifications over time, a subscription model such as Unlimited Security Training may be worth comparing with individual courses. The choice should be based on the planned pathway, not on the assumption that more certificates automatically replace the CISSP experience requirement.

Where CISSP fits in a security career

CISSP is often most valuable when it confirms experience that already exists or is clearly developing. It can support moves into security management, architecture, governance, risk, assurance and senior technical roles where broad security judgment is expected. For an early-career candidate, the Associate of ISC2 route can show ambition and discipline, but it should be presented accurately.

Hiring managers should also be precise when advising junior staff. If a role requires an active CISSP for compliance, customer assurance or contract reasons, Associate status will usually not meet that requirement. If the goal is development planning, Associate status can still be useful because it shows the person has passed the exam and is working toward the experience requirement.

The practical decision is therefore nuanced. Beginners can take CISSP, and some should. Others will progress faster by building foundations first, earning an entry-level credential, gaining security-adjacent experience and returning to CISSP when the material connects to their daily work.

Applying the decision

The key takeaway is simple: CISSP is available to beginners as an exam, but full CISSP certification is reserved for candidates who meet the experience and endorsement requirements. The Associate of ISC2 pathway is the bridge, not a shortcut around professional experience.

Readynez can support candidates who want structured preparation, but the better first move is to choose the route that matches current experience: foundational study for newcomers, operational certification for hands-on security staff, or CISSP preparation for candidates ready to reason across the full domain set. Anyone unsure which route fits can contact the team to discuss a sensible training path without treating CISSP as the only possible starting point.

FAQ

Can beginners take the ISC2 CISSP exam?

Yes. Beginners can take the CISSP exam, but they cannot become fully CISSP certified until they meet the professional experience requirement and complete endorsement. If they pass before that point, they may become an Associate of ISC2.

Is CISSP a good first cybersecurity certification?

Usually, it is not the easiest first certification for someone with no IT or security background. Many beginners are better served by ISC2 CC, Security+ or a similar foundation before attempting CISSP-level breadth. Candidates with strong IT experience may reasonably start CISSP earlier if they understand the Associate pathway.

Do you need a degree for CISSP?

No. A bachelor’s degree is not mandatory. A relevant four-year degree or approved credential may reduce the required experience by one year under ISC2 rules, but candidates still need qualifying professional experience for full certification.

What happens if you pass CISSP without enough experience?

You can become an Associate of ISC2 while you continue gaining the required experience. During that period, you should describe the status accurately on a CV and avoid presenting yourself as fully CISSP certified.

How should beginners prepare for CISSP?

Beginners should first read the current ISC2 exam outline, then decide whether to study CISSP now or build foundations first. Strong preparation includes scenario-based practice, risk and governance study, and practical exposure through IT or security-related work.

Two people monitoring systems for security breaches

Unlimited Security Training

Get Unlimited access to ALL the LIVE Instructor-led Security courses you want - all for the price of less than one course. 

  • 60+ LIVE Instructor-led courses
  • Money-back Guarantee
  • Access to 50+ seasoned instructors
  • Trained 50,000+ IT Pro's

Basket

{{item.CourseTitle}}

Price: {{item.ItemPriceExVatFormatted}} {{item.Currency}}