Laptop displaying cybersecurity text

CISSP Experience Waiver Changes 2026: CEH, CISA, and OSCP No Longer Count

On April 1, 2026, ISC2 quietly made one of the biggest changes to CISSP eligibility in years: the CISSP experience waiver list was cut roughly in half, from about 50 qualifying certifications down to 25. If you were planning to use CEH, CISA, CRISC, or OSCP to shave a year off the five-year experience requirement, that plan no longer works. This post covers exactly what changed, what still counts, and what it means if you’re a DoD cybersecurity professional working toward the CISSP.

How the CISSP Experience Waiver Works

The CISSP requires five years of cumulative, paid work experience in at least two of the eight domains. ISC2 allows a one-year waiver — bringing the requirement down to four years — if you hold either a qualifying four-year degree (or regional equivalent) or one credential from its approved list. You can only use one waiver total: degree or certification, not both.

That approved list is what changed. For years it had grown into a sprawl of roughly fifty certifications of wildly varying rigor. As of April 1, 2026, it’s a much shorter, stricter list.

What Was Removed in the 2026 CISSP Experience Waiver Change

The removals that will sting the most, because so many people in this field hold them:

  • CEH (Certified Ethical Hacker)
  • CISA (Certified Information Systems Auditor)
  • CRISC (Certified in Risk and Information Systems Control)
  • OSCP (Offensive Security Certified Professional)

Roughly two dozen other lower-profile certifications came off the list at the same time. Applications submitted before April 1, 2026 were grandfathered under the old list; anything after runs against the new one.

What Still Counts

The retained list is good news for the DoD crowd, because it’s heavy on the certifications DoD workforces already hold:

  • CompTIA Security+, CySA+, and CASP+/SecurityX — the workhorse DoD 8140 certs
  • GIAC certifications
  • CISM (Certified Information Security Manager)
  • CCSP and SSCP (ISC2’s own credentials)
  • CSSLP, AWS Certified Security – Specialty, and select Cisco security certifications

ISC2’s stated criteria for staying on the list: the certification needs a publicly available exam outline, ANAB ISO/IEC 17024 accreditation (or a proctored exam from a reputable body), and at least 90% alignment with two or more CISSP domains. That last requirement is what knocked out specialized certs like OSCP — deep in one domain, but not broad across two.

What This Means for DoD Cybersecurity Professionals

If you’re working under DoD 8140, odds are you already hold Security+ or CySA+ — which means your waiver path is intact and this change costs you nothing. The people genuinely affected are career changers coming from audit (CISA), offensive security (OSCP), or risk (CRISC) backgrounds who were counting on those certs for the year reduction. If that’s you, remember two things: your degree can still provide the same one-year waiver, and the waiver only ever moved the finish line by a year — the Associate of ISC2 path lets you pass the exam now and bank it while you accumulate the remaining experience.

It’s also worth reading the strategic signal: ISC2 is tightening the CISSP’s positioning as a senior credential. That’s consistent with where the certification sits in DoD career paths — the jump from ISSO toward ISSM and higher, which I broke down in DoD 8140 vs 8570: What It Means for Your ISSO Career.

What to Do Now

If your waiver cert was cut: count your actual experience carefully before assuming you need the waiver at all — five years across two domains is more attainable than people think, since ISSO work typically touches Security and Risk Management, Security Operations, and Security Assessment and Testing simultaneously. If you’re short, sit the exam as an Associate of ISC2 rather than waiting. And if you’re just starting your study plan, begin with the domain structure — my CISSP Domains Explained guide maps each domain to real-world work so the material sticks.

For the exam itself, the ISC2 CISSP Official Study Guide remains the standard reference — it’s the one resource I’d buy before anything else, and it covers every domain the waiver criteria are built around.

Final Thoughts

The 2026 CISSP experience waiver change is less dramatic than the headlines suggest for most DoD professionals — Security+ and the other 8140 staples survived the cut. But it’s a clear statement about where ISC2 wants the CISSP to sit: earned primarily through experience, with fewer shortcuts. Check your specific certification against the current list on isc2.org before you plan your application, since the list can change again without much notice.

As an Amazon Associate, RMF Insider earns from qualifying purchases.

Pro Tools for Working ISSOs

Working a real ATO package right now?

Skip the spreadsheet rebuild. These are the exact tools I use in the field as an active DoD ISSO.


Get the free RMF Quick Reference

All 7 RMF steps on one page — free when you subscribe to the weekly ISSO Insider.

One response

  1. CISSP Domains Explained (Simple + Real-World Examples for 2026) – RMFInsider

    […] reading: CISSP Experience Waiver Changes 2026 · CISSP Study Plan for DoD Cybersecurity Professionals (90-Day […]

Leave a Reply

Discover more from RMFInsider

Subscribe now to keep reading and get access to the full archive.

Continue reading