The CISSP is a widely recognised security certification associated with experienced practitioners who can connect security controls, governance, risk and business impact.
Last updated: June 2026. Beginners can take the ISC2 CISSP exam, but passing the exam does not automatically make someone a CISSP. A candidate who passes without the required professional experience can become an Associate of ISC2 while they build the experience needed for full certification and complete endorsement.
This article is based on official ISC2 and Pearson VUE policy areas, including CISSP eligibility, the current exam outline, the Associate of ISC2 pathway, annual maintenance requirements and exam delivery rules. Those policies change periodically, so candidates should verify the latest details directly with ISC2 and Pearson VUE before booking an exam. The editorial approach is to separate official requirements from practical career advice, rather than treating CISSP as either impossible for beginners or suitable for every newcomer.
A true beginner can sit the CISSP exam if they are prepared to study at CISSP level and meet the testing provider’s registration requirements. The more important question is whether taking it now supports their career plan. CISSP is written for people who can reason across security domains, weigh trade-offs and answer management-oriented scenarios, so exam readiness is different from simple interest in cybersecurity.
The full CISSP credential requires five years of cumulative paid work experience in at least two CISSP Common Body of Knowledge domains. A relevant four-year degree or approved credential can usually satisfy one year of that requirement, but it does not remove the need for professional experience. There is no bachelor’s degree requirement to take the exam or to become certified; the degree is only one possible experience waiver.
If a beginner passes the exam before meeting the experience requirement, they may hold Associate of ISC2 status rather than using the CISSP title. On a CV, that should be written accurately, for example as “Associate of ISC2 working toward CISSP,” rather than “CISSP certified.” This distinction matters because some employers and regulated roles require an active CISSP, and Associate status will usually signal progress rather than satisfy that requirement.
| Candidate situation | Likely outcome after passing the exam | Practical implication |
|---|---|---|
| Has the required experience across at least two CISSP domains | Can apply for endorsement toward full CISSP certification | The candidate must document relevant work and complete the endorsement process. |
| Has some experience but not the full requirement | Can become an Associate of ISC2 after passing | The candidate continues building qualifying experience before full certification. |
| Has little or no cybersecurity experience | Can still take the exam, but full CISSP is not awarded yet | The candidate should weigh whether CISSP-level study is the right first step. |
CISSP is often misunderstood as a deeply technical exam where success depends mainly on memorising tools, commands or low-level implementation details. Technical knowledge helps, but the exam places heavy emphasis on judgment: how to prioritise risk, protect assets, design controls, respond to incidents, govern security programmes and make defensible decisions in business context.
This is why beginners sometimes struggle even after reading large volumes of material. They may know definitions but miss the intent of long scenario questions. A stronger preparation approach is to ask what risk is being reduced, who owns the decision, what policy or control should guide the response and which answer is most appropriate at the organisational level.
Common mistakes include assuming that a bachelor’s degree is mandatory, studying technical trivia at the expense of governance and risk, using outdated exam-format information, and practising only short recall questions. Candidates preparing early should spend time with scenario-based questions and the current ISC2 exam outline so their study reflects how the exam is framed now.
The English CISSP exam uses a computerised adaptive testing format. Candidates should expect a demanding exam session rather than a simple knowledge quiz, and they should confirm all operational details before booking because ISC2 and Pearson VUE may update policies, delivery conditions and fees.
| Area | Current planning point |
|---|---|
| Exam format | Computerised adaptive testing for the English exam. |
| Number of items | 125 to 175 items. |
| Time allowed | Up to 4 hours. |
| Passing score | 700 out of 1000 on a scaled score. |
| Delivery | Delivered through Pearson VUE testing arrangements. |
| Fees and retake policy | Published by ISC2 and Pearson VUE during the registration process; verify current fees, waiting periods and identification rules before scheduling. |
The annual maintenance fee and continuing certification obligations also matter. Passing the exam is one milestone, while keeping an ISC2 status active requires following ISC2’s maintenance rules. Beginners should understand these obligations before treating the exam as a one-time transaction.
After passing CISSP, a candidate seeking full certification must complete endorsement. That means documenting qualifying work experience and showing how it maps to the CISSP domains. Job titles alone are rarely enough; the stronger evidence is the security responsibility performed, the decisions made and the domains covered.
An endorsement is commonly completed by an active ISC2-certified professional who can validate the candidate’s experience. If the candidate does not know an eligible endorser, ISC2 can act as endorser through its own review process. Either way, candidates should keep clear records of roles, dates, responsibilities and domain alignment before they need them.
For beginners, this has an important career-planning consequence. Passing early may create momentum, but the work still has to follow. Roles in security operations, governance, risk, identity, audit support, incident response, cloud security or secure systems administration may all contribute, provided the work genuinely aligns with the CISSP domains and ISC2 rules.
A beginner does not need to reject CISSP completely, but many candidates benefit from taking a staged route. The right first step depends on current role, available study time and hiring goal. Someone already working in IT operations or security support may be closer to CISSP readiness than a career changer with no exposure to networks, identity, risk or incident handling.
| Starting point | When it makes sense | How it supports CISSP later |
|---|---|---|
| CISSP now, as an Associate of ISC2 route | The candidate already has strong IT or security-adjacent experience and needs CISSP-level knowledge for a planned role. | It builds early familiarity with governance, risk and domain breadth while experience is still being earned. |
| SSCP first | The candidate is in or near a hands-on security operations role. | It can strengthen operational security foundations before moving into broader CISSP judgment and governance. |
| Security+ or ISC2 CC first | The candidate is new to cybersecurity or changing careers from a non-technical background. | It creates vocabulary, basic control knowledge and confidence before attempting CISSP-level material. |
Structured study can help, but it should match the candidate’s current level. A newcomer who still needs core security vocabulary may be better served by foundational study before browsing broader ISC2 course options. Someone building technical context alongside security governance may also find adjacent topics such as Certified Ethical Hacker training useful, though ethical hacking preparation is not a substitute for CISSP eligibility or endorsement.
In practice, a staged route often produces better learning than rushing straight to advanced material. A candidate might first build networking and identity basics, then gain experience through service desk, systems administration, SOC analyst, audit support or cloud operations work, and later return to CISSP when the exam domains map to real responsibilities.
The most useful CISSP plan begins with a candid assessment of current experience. A candidate should compare their work against the CISSP domains, identify gaps and decide whether they are preparing for the exam now or preparing for the roles that will eventually make the credential meaningful.
Study time should be spent on both concepts and decision-making. For example, access control study should cover authentication models and identity lifecycle, but candidates should also understand when business requirements, least privilege, segregation of duties and auditability affect the right answer. This style of thinking is closer to the exam than memorising isolated facts.
For candidates planning several security certifications over time, a subscription model such as Unlimited Security Training may be worth comparing with individual courses. The choice should be based on the planned pathway, not on the assumption that more certificates automatically replace the CISSP experience requirement.
CISSP is often most valuable when it confirms experience that already exists or is clearly developing. It can support moves into security management, architecture, governance, risk, assurance and senior technical roles where broad security judgment is expected. For an early-career candidate, the Associate of ISC2 route can show ambition and discipline, but it should be presented accurately.
Hiring managers should also be precise when advising junior staff. If a role requires an active CISSP for compliance, customer assurance or contract reasons, Associate status will usually not meet that requirement. If the goal is development planning, Associate status can still be useful because it shows the person has passed the exam and is working toward the experience requirement.
The practical decision is therefore nuanced. Beginners can take CISSP, and some should. Others will progress faster by building foundations first, earning an entry-level credential, gaining security-adjacent experience and returning to CISSP when the material connects to their daily work.
The key takeaway is simple: CISSP is available to beginners as an exam, but full CISSP certification is reserved for candidates who meet the experience and endorsement requirements. The Associate of ISC2 pathway is the bridge, not a shortcut around professional experience.
Readynez can support candidates who want structured preparation, but the better first move is to choose the route that matches current experience: foundational study for newcomers, operational certification for hands-on security staff, or CISSP preparation for candidates ready to reason across the full domain set. Anyone unsure which route fits can contact the team to discuss a sensible training path without treating CISSP as the only possible starting point.
Yes. Beginners can take the CISSP exam, but they cannot become fully CISSP certified until they meet the professional experience requirement and complete endorsement. If they pass before that point, they may become an Associate of ISC2.
Usually, it is not the easiest first certification for someone with no IT or security background. Many beginners are better served by ISC2 CC, Security+ or a similar foundation before attempting CISSP-level breadth. Candidates with strong IT experience may reasonably start CISSP earlier if they understand the Associate pathway.
No. A bachelor’s degree is not mandatory. A relevant four-year degree or approved credential may reduce the required experience by one year under ISC2 rules, but candidates still need qualifying professional experience for full certification.
You can become an Associate of ISC2 while you continue gaining the required experience. During that period, you should describe the status accurately on a CV and avoid presenting yourself as fully CISSP certified.
Beginners should first read the current ISC2 exam outline, then decide whether to study CISSP now or build foundations first. Strong preparation includes scenario-based practice, risk and governance study, and practical exposure through IT or security-related work.
Get Unlimited access to ALL the LIVE Instructor-led Security courses you want - all for the price of less than one course.
You're viewing our global site from United States
Would you like to view the site in
English
with prices in
Dollar?