Passed the CISSP Exam But Still Not "Certified"? Here's What Happens Next

Passing the CISSP exam feels like the finish line. For a lot of candidates, it isn’t — and the gap between “I passed” and “I’m certified” catches people off guard because almost nothing in your exam prep prepares you for it. Here’s exactly how the process works, and what to do if you’re stuck.

Why Passing the Exam Isn’t the Same as Being Certified

CISSP isn’t awarded purely on exam performance. ISC2 requires every candidate to have their claimed professional experience independently verified before the credential is issued. If you don’t yet meet the full experience requirement, or haven’t completed endorsement, you become an Associate of ISC2 instead — you passed the exam, but the CISSP title isn’t yours yet.

This isn’t a technicality ISC2 buried in the fine print. It’s the actual design of the credential: CISSP is meant to signal both knowledge and verified real-world experience, which is part of why it carries more weight than exams that only test knowledge.

The Two Requirements You Need After Passing

1. Experience — five years, with some flexibility built in

CISSP requires five years of cumulative, paid work experience in at least two of the eight CISSP domains. A few things soften this:

  • A relevant four-year college degree (or approved credential) can satisfy up to one year of the requirement.
  • Certain ISC2-approved certifications can also count toward up to one year.
  • If you don’t yet have the full five years, you become an Associate of ISC2 and have up to six years from your exam pass date to accumulate the remaining experience and complete endorsement.

2. Endorsement — someone has to vouch for you

This is the part that trips people up most. You need an active ISC2-certified professional in good standing to formally attest that your claimed experience is genuine. This isn’t a formality check box — your endorser is putting their own standing behind your application.

What If You Don’t Know Anyone With an ISC2 Certification?

This is the single most common blocker, especially for candidates without an existing security network. A few real paths forward, in rough order of how commonly they work:

  • Check your current or former workplace first. A colleague, manager, or even someone in a different department who happens to hold CISSP, SSCP, or CC is your fastest path — they don’t need to be your direct supervisor.
  • Reach out to former employers and coworkers, even ones you haven’t spoken to in years. A quick heads-up email that ISC2 may verify your employment goes a long way, and most people are happy to help someone finish a credential they know is hard-earned.
  • ISC2 local chapters. These exist in most major cities and regions specifically to connect candidates with the broader certified community — chapter meetings and online forums are a legitimate, commonly used route to find an endorser you don’t already know.
  • Let ISC2 endorse you directly. If you genuinely cannot locate anyone, ISC2 itself can serve as your endorser. The tradeoff: your application is subject to audit, so keep your employment documentation (offer letters, pay stubs, manager contacts) organized and ready.

The Audit Reality

A percentage of all certification applications get randomly selected for audit regardless of how you got endorsed. This isn’t a red flag if it happens to you — it’s routine. What matters is having your documentation ready in advance: dates of employment, job titles, a description of duties that map to CISSP domains, and contact information for people who can confirm it. Candidates who get audited unprepared are the ones who end up delayed for months; candidates who kept records from the start clear it in days.

What Happens While You’re an Associate of ISC2

You’re not certified yet, but you’re not starting from zero either:

  • Your Associate status is real and can be listed on a resume or LinkedIn — accurately labeled as “Associate of ISC2,” not CISSP.
  • You have up to six years to complete the experience and endorsement requirements.
  • Continuing education and community involvement during this period can help — some ISC2 activities and approved credentials count toward the experience requirement itself.

Bottom Line

If you passed the exam and are now staring at “Associate of ISC2” instead of the CISSP title you expected, you haven’t failed anything — you’ve hit a deliberately designed verification step, not a bug in the process. The fastest way through it is almost always the boring one: reach out to people who already know your work, keep your documentation organized, and don’t wait until year five to start looking for an endorser.

Once you’re certified, see our certification stacking guide for what to build toward next.


Working toward CISSP? DailyDebian’s CISSP question set covers the exam itself — pairing it with an early start on your endorsement paperwork saves months later.

Back to blog