CISSP
ISC2
Complete guide to passing the CISSP exam on your first attempt.
$749
~25%
3 years
Global
ISC2
$120k-$175k
Are you ready for CISSP?
Loading quiz...
Complete Overview
The CISSP is ISC2's flagship information security certification, assessed by a three-hour computerized adaptive exam of 100 to 150 items that costs US$749 in the Americas, Asia Pacific, the Middle East and Africa, EUR 719.04 in EMEA, and GBP 606.69 in the United Kingdom. It is aimed at practitioners who already have five years of cumulative, full-time paid work experience in at least two of the eight CISSP domains, which makes it a mid-career credential rather than an entry point. ISC2 delivers the exam only through Pearson Professional Centers and ISC2-authorized Pearson VUE Select test centres. There is no online proctored option for CISSP.
The blueprint has eight domains with published average weights that total 100 percent: Security and Risk Management 16 percent, Asset Security 10 percent, Security Architecture and Engineering 13 percent, Communication and Network Security 13 percent, Identity and Access Management 13 percent, Security Assessment and Testing 12 percent, Security Operations 13 percent, and Software Development Security 10 percent. Those weights hold regardless of how many items your adaptive exam runs to, because the item selection algorithm builds every exam to the content outline.
Scoring works differently from most certification exams, and the difference changes how you should prepare. ISC2 publishes a passing grade of 700 out of 1000 points in the exam outline, but the CAT format returns no numerical score at all. You get pass or fail. Failing candidates receive proficiency levels per domain, expressed as below proficiency, near proficiency or above proficiency, and nothing more granular. The exam ends as soon as the algorithm can place your ability estimate above or below the passing standard with 95 percent statistical confidence, which can happen at item 100 or at item 150. Item review is disabled, so once you confirm an answer it is final.
ISC2 designs the exam so that every candidate feels it going badly. Its own CAT documentation states that the selection algorithm targets items you have roughly a 50 percent chance of answering correctly, and that all candidates should expect to answer about half of what they see incorrectly. Candidates who read that sentence beforehand tend to stay calm at item 90; candidates who do not tend to panic.
Passing the exam is one step of several. You then have nine months to submit a certification application, be endorsed and digitally signed by an ISC2 certified professional, commit to the ISC2 Code of Ethics, and pay a US$135 Annual Maintenance Fee. Candidates who pass without the required experience become an Associate of ISC2 and have six years to earn the five years of experience. Maintaining the certification means 120 Continuing Professional Education credits across each three-year cycle with a minimum of 40 per year, plus the AMF each year. ISC2 does not publish a CISSP pass rate, and any figure you see quoted as one has been estimated by somebody outside ISC2.
Why Get CISSP Certified?
The exam is 180 minutes with 100 to 150 items, and ISC2 ends it the moment your ability estimate clears or misses the standard with 95 percent confidence.
ISC2 publishes eight domain weights that total 100 percent, so a 16 percent Security and Risk Management section is worth more preparation time than a 10 percent Software Development Security section.
CISSP was the first information security credential accredited to the ANAB ISO/IEC Standard 17024, which is why it appears on procurement and government requirement lists.
ISC2 reported more than 175,000 CISSP holders in a January 2025 article, thirty years after the credential launched with 46 holders in 1994.
The five-year experience requirement means the credential signals verified practice, and ISC2 requires endorsement and a digital signature from an existing certified professional.
US Bureau of Labor Statistics data for May 2024 puts median pay for information security analysts at $124,910 and for computer and information systems managers at $171,200.
Renewal costs 120 CPE credits over three years plus a US$135 Annual Maintenance Fee, and one AMF covers every ISC2 certification you hold.
Exam Format & Structure
Duration
180 minutes (3 hours maximum administration time, with all breaks counted inside it)
Questions
100 to 150 items, including 25 unscored pretest items
Passing Score
700 out of 1000 points per the ISC2 exam outline. No numerical score is reported to candidates: the result is pass or fail, and failing candidates receive per-domain proficiency levels only.
Question Types
- Multiple choice with one best answer
- Advanced item types, which ISC2 uses for drag-and-drop and hotspot style items
Delivery Method
Pearson Professional Centers and ISC2-authorized Pearson VUE Select test centres only. ISC2 states CISSP exams are not available at Authorized Training Provider events or mobile testing facilities, and there is no online proctored option. Chinese-language CISSP exams run only in four annual windows: 1 to 31 March, 1 to 30 June, 1 to 30 September and 1 to 31 December.
How scoring works
Score scale
The ISC2 exam outline states a passing grade of 700 out of 1000 points, but CAT candidates never see a numerical score. The reported outcome is pass or fail only.
Score needed to pass
700 of 1000 as published. Operationally, the pass point is an ability threshold on the adaptive scale, and ISC2 gives failing candidates only three proficiency bands per domain: below proficiency, near proficiency and above proficiency.
When results arrive
The Pearson VUE proctor hands you an unofficial result at check-out and ISC2 emails the official result afterwards. ISC2 warns results can be delayed roughly six to eight weeks when a form has too few test takers for its statistical analysis, and that all results remain subject to psychometric and forensic evaluation after release.
How the scale is built
Item response theory drives a variable-length adaptive test. Each answer re-estimates your ability, and the next item targets roughly a 50 percent chance of a correct response. After the 100-item minimum, the confidence interval rule ends the exam once your estimate excludes the pass point at 95 percent confidence. Scoring is compensatory across the eight domains, and 25 pretest items are unscored.
Pacing and time budget
100 to 150 questions in 180 minutes gives you 1 minute 12 seconds if you plan for the 150-item maximum, or 1 minute 48 seconds on a minimum-length 100-item exam. Plan to the shorter figure so a long exam never runs you out of time. per question.
Minute 30
At least 25 items, which keeps you on the 150-item pace rather than the 100-item pace
Minute 60
At least 50 items, the point at which you can still recover 5 minutes of drift without rushing
Minute 120
At least 100 items, meaning you have cleared the minimum length and any further items are the algorithm still deciding
Minute 160
At least 133 items if your exam has continued, leaving 20 minutes for the last block at the 150 maximum
| At this point | You should have answered |
|---|---|
| Minute 30 | At least 25 items, which keeps you on the 150-item pace rather than the 100-item pace |
| Minute 60 | At least 50 items, the point at which you can still recover 5 minutes of drift without rushing |
| Minute 120 | At least 100 items, meaning you have cleared the minimum length and any further items are the algorithm still deciding |
| Minute 160 | At least 133 items if your exam has continued, leaving 20 minutes for the last block at the 150 maximum |
- The run-out-of-time rule fails you automatically if you have not answered 75 operational and 25 pretest items within the 180 minutes, so time management is a pass condition, not just a comfort.
- Breaks are unlimited but come out of the same 180 minutes. If you take one, take it after a long scenario item, not before one.
- There is no benefit in slowing down to double-check, because item review is disabled. Once you are 80 percent sure, commit and move.
- Long scenario stems are the pace killer. Read the actual question first, then reread the scenario for the facts it asks about.
- If the exam is still running past item 100, your ability estimate is near the pass point. That is the moment to hold pace rather than gamble on speed.
Where the marks are
Security and risk management
16%
The heaviest domain. Expect risk treatment decisions, control selection, business impact analysis outputs, third-party risk, and the ISC2 Code of Ethics canons in priority order.
Security architecture and engineering
13%
Cryptographic lifecycle, PKI, security models, and vulnerabilities specific to cloud, container, serverless, embedded and industrial control systems, usually framed as which design flaw creates which exposure.
Communication and network security
13%
Attacks and controls placed at the correct OSI layer, secure channel selection for voice, remote access and third-party connectivity, and micro-segmentation and software defined networking implications.
Identity and access management
13%
Choosing between RBAC, ABAC, MAC and DAC for a described organisation, federation with SAML, OIDC and OAuth, access review and deprovisioning failures, and Kerberos weaknesses.
Security operations
13%
Incident response ordering, evidence handling and chain of custody, disaster recovery test types from read-through to full interruption, and choosing recovery sites against a stated recovery time objective.
Security assessment and testing
12%
Selecting the right assessment technique for a scenario, distinguishing audit types and their audiences, interpreting SOC report scope, and reporting findings through exception handling and disclosure.
Asset security
10%
Classification schemes, owner versus custodian versus controller versus processor, retention schedules, and picking the correct sanitisation method for the medium and the sensitivity level.
Software development security
10%
Placing security activities inside Agile, Waterfall and DevSecOps lifecycles, comparing SAST with DAST, and assessing commercial, open source and cloud-sourced software rather than writing code.
| Topic | Weight | Why it scores |
|---|---|---|
| Security and risk management | 16% | The heaviest domain. Expect risk treatment decisions, control selection, business impact analysis outputs, third-party risk, and the ISC2 Code of Ethics canons in priority order. |
| Security architecture and engineering | 13% | Cryptographic lifecycle, PKI, security models, and vulnerabilities specific to cloud, container, serverless, embedded and industrial control systems, usually framed as which design flaw creates which exposure. |
| Communication and network security | 13% | Attacks and controls placed at the correct OSI layer, secure channel selection for voice, remote access and third-party connectivity, and micro-segmentation and software defined networking implications. |
| Identity and access management | 13% | Choosing between RBAC, ABAC, MAC and DAC for a described organisation, federation with SAML, OIDC and OAuth, access review and deprovisioning failures, and Kerberos weaknesses. |
| Security operations | 13% | Incident response ordering, evidence handling and chain of custody, disaster recovery test types from read-through to full interruption, and choosing recovery sites against a stated recovery time objective. |
| Security assessment and testing | 12% | Selecting the right assessment technique for a scenario, distinguishing audit types and their audiences, interpreting SOC report scope, and reporting findings through exception handling and disclosure. |
| Asset security | 10% | Classification schemes, owner versus custodian versus controller versus processor, retention schedules, and picking the correct sanitisation method for the medium and the sensitivity level. |
| Software development security | 10% | Placing security activities inside Agile, Waterfall and DevSecOps lifecycles, comparing SAST with DAST, and assessing commercial, open source and cloud-sourced software rather than writing code. |
The numbers
3 hours, 100 to 150 items, including 25 unscored pretest items
Exam length and item count
Source: ISC2, CISSP Certification Exam Outline and Computerized Adaptive Testing FAQ, isc2.org
700 out of 1000 points, with no numerical score reported to candidates
Published passing grade
Source: ISC2, CISSP Certification Exam Outline, isc2.org
US$749 Americas, Asia Pacific, Middle East and Africa; EUR 719.04 EMEA; GBP 606.69 United Kingdom
Exam fee by region
Source: ISC2 Exam Pricing page, isc2.org
16 / 10 / 13 / 13 / 13 / 12 / 13 / 10 percent across the eight domains, totalling 100 percent
Domain weights
Source: ISC2, CISSP Certification Exam Outline, isc2.org
More than 175,000 CISSP holders, up from 46 in the credential's first year in 1994
Certification holders
Source: ISC2 Insights, Calling All CISSP Certification Holders, January 2025, and ISC2 Celebrates 30th Anniversary of CISSP Certification, March 2024
US$135 Annual Maintenance Fee, plus 120 CPE credits per three-year cycle with a 40 credit annual minimum
Ongoing cost and CPE requirement
Source: ISC2 Annual Maintenance Fees overview and ISC2 Member Policies, isc2.org
Approved under U.S. DoDM 8140.03, and ANAB accredited to ISO/IEC Standard 17024 as the first information security credential to meet it
Department of Defense approval
Source: ISC2, CISSP certification page and CISSP Certification Exam Outline, isc2.org
If you fail
Wait before retaking
30 test-free days after a first failed attempt, 60 test-free days after a second, and 90 test-free days after a third and each attempt after that.
Attempt limit
Four attempts in any 12-month period for the same certification programme. Candidates may pursue several ISC2 certifications at the same time, and the limit is counted per programme.
Retake fee
Full price each time: US$749 in the Americas, Asia Pacific, the Middle East and Africa, EUR 719.04 in EMEA, GBP 606.69 in the United Kingdom. ISC2 sells Exam Peace of Mind Protection at US$249 alongside the voucher, which covers one retake if both attempts happen inside 180 days of purchase.
Failing candidates receive per-domain proficiency levels at the test centre, and that report is the only diagnostic ISC2 gives, so keep it. Rescheduling costs US$50, GBP 35 or EUR 40 and cancelling costs US$100, GBP 70 or EUR 80. ISC2 also reserves the right to withhold or cancel results where it suspects irregularity, fraud or policy violation, and applies psychometric and forensic evaluation to results after release.
Exam Domains & Topics
The largest domain. Governance, compliance, legal and regulatory issues, professional ethics, business continuity, personnel security, risk management and threat modelling.
Key Topics to Master:
- Confidentiality, integrity and availability, plus authenticity and nonrepudiation
- Security governance principles and alignment of security function to business strategy
- Legal and regulatory issues across jurisdictions, including cybercrime, licensing, import and export controls, transborder data flow and privacy
- The ISC2 Code of Professional Ethics, which is testable and also binding on you after certification
- Business continuity requirements, business impact analysis, recovery time objective and recovery point objective
- Personnel security policies: screening, onboarding, transfer, termination, vendor and contractor agreements
- Risk identification, assessment, response, control selection, and applicable types of controls
- Threat modelling concepts and methodologies, and supply chain risk management
- Security awareness, education and training programme methods
Identifying, classifying, owning, handling, retaining and destroying information and assets across their lifecycle.
Key Topics to Master:
- Information and asset identification and classification
- Establishing ownership: data owners, system owners, custodians, processors and controllers
- Asset handling requirements, marking, labelling and storage
- Data lifecycle management including retention schedules and end-of-life
- Data remanence, sanitisation, degaussing, cryptographic erase and physical destruction
- Data states: at rest, in transit and in use, and the protections that apply to each
- Data loss prevention and digital rights management
Secure design principles, security models, cryptography, physical security, and the vulnerabilities of specific architectures.
Key Topics to Master:
- Secure design principles: least privilege, defence in depth, secure defaults, fail securely, separation of duties, zero trust, privacy by design
- Security models including Bell-LaPadula, Biba and Clark-Wilson, and what each one actually protects
- Security capabilities of information systems: memory protection, trusted platform module, encryption and decryption
- Vulnerabilities of client-based, server-based, database, cryptographic, industrial control, cloud, distributed, IoT, containerised, serverless and embedded systems
- Cryptographic lifecycle, symmetric and asymmetric algorithms, public key infrastructure, key management practices, digital signatures
- Cryptanalytic attacks: brute force, ciphertext only, known plaintext, side channel, fault injection, ransomware
- Site and facility design, and controls for wiring closets, server rooms, media storage, utilities, HVAC and fire suppression
Secure network architecture, secure components, and secure communication channels.
Key Topics to Master:
- OSI and TCP/IP models applied to security decisions, IPv4 and IPv6, and secure protocols
- Implications of multilayer protocols, converged protocols, micro-segmentation, software defined networks and wireless networks
- Cellular and satellite networks, content distribution networks and their security implications
- Operation of hardware: redundant power, warranty, support, transmission media and network access control devices
- Secure communication channels for voice, multimedia collaboration, remote access, data communications and virtualised networks
- Third-party connectivity and the controls that govern it
Controlling physical and logical access to assets, managing identities across their lifecycle, and federating identity.
Key Topics to Master:
- Physical and logical access to information, systems, devices, facilities and applications
- Identity management implementation: single sign-on, multifactor authentication, credential management, just-in-time access
- Federated identity with cloud and on-premises providers, including SAML, OpenID Connect and OAuth roles
- Authorisation mechanisms: role-based, rule-based, mandatory, discretionary, attribute-based and risk-based access control
- Identity and access provisioning lifecycle: account access review, provisioning, deprovisioning, role definition and privilege escalation
- Authentication systems including Kerberos and RADIUS, and their known weaknesses
Designing assessment strategies, running tests, collecting security process data, and reporting results to the right audience.
Key Topics to Master:
- Designing and validating assessment, test and audit strategies for internal, external and third-party audits
- Vulnerability assessment, penetration testing, log review, synthetic transactions, code review and testing
- Misuse case testing, test coverage analysis and interface testing
- Breach attack simulations and compliance checks
- Collecting security process data: account management, management review, key performance and key risk indicators, backup verification, training and awareness, disaster recovery and business continuity
- Analysing and reporting test output, including remediation, exception handling and ethical disclosure
Investigations, logging and monitoring, resource protection, incident management, recovery, disaster recovery and physical security operations.
Key Topics to Master:
- Investigation types: administrative, criminal, civil, regulatory and industry standards, and the evidence handling each requires
- Logging and monitoring, intrusion detection and prevention, SIEM, continuous monitoring, egress monitoring, threat intelligence and user behaviour analytics
- Configuration management, provisioning, baselining and automation
- Foundational security operations concepts: need to know, least privilege, separation of duties, job rotation, service level agreements
- Incident management: detection, response, mitigation, reporting, recovery, remediation and lessons learned
- Patch and vulnerability management, and change management processes
- Recovery strategies, backup storage strategies, and multiple processing sites
- Disaster recovery plan testing: read-through, walkthrough, simulation, parallel and full interruption
- Business continuity planning and exercises, and physical and personnel safety
Security in the software development lifecycle, controls in development ecosystems, software security effectiveness, and secure coding.
Key Topics to Master:
- Development methodologies: Agile, Waterfall, DevOps, DevSecOps, spiral, prototyping
- Maturity models, operation and maintenance, change management, and the integrated product team
- Security controls in development ecosystems: programming languages, libraries, toolsets, integrated development environments, runtime, continuous integration and delivery
- Software configuration management, code repositories and application security testing including SAST and DAST
- Assessing software security effectiveness through auditing, logging, risk analysis and mitigation
- Assessing the security of acquired software: commercial off the shelf, open source, third-party, managed services and cloud services
- Secure coding guidelines and standards, including security weaknesses at the source code level and API security
Recommended Study Plan
- 1Download the CISSP Certification Exam Outline PDF from isc2.org and read the sub-objectives, not just the eight domain names
- 2Score yourself out of five on every sub-objective and multiply by the domain weight to find where your effort actually pays
- 3Confirm you meet the experience rule: five years cumulative full-time in at least two domains, with at most one year waived by a degree or an approved credential
- 4Read the ISC2 Computerized Adaptive Testing FAQ so the 100-item minimum, the 95 percent confidence rule and the no-review rule are not surprises
- 5Book a provisional test date at a Pearson Professional Center, remembering that Chinese-language sittings run only in March, June, September and December
- 1Study governance, security strategy alignment, and the difference between policy, standard, procedure and guideline
- 2Learn the risk formulas end to end: asset value, exposure factor, single loss expectancy, annualised rate of occurrence, annualised loss expectancy
- 3Compare quantitative and qualitative risk assessment and know when each is appropriate
- 4Read the ISC2 Code of Professional Ethics in full and learn the canons in order, since order is testable
- 5Work 50 practice items on this domain and write down why each wrong option is wrong
- 1Study business continuity: business impact analysis, maximum tolerable downtime, recovery time objective, recovery point objective
- 2Compare threat modelling methodologies including STRIDE and attack trees, and know what each produces
- 3Learn personnel security across the employment lifecycle and third-party and supply chain risk
- 4Study data classification, ownership roles, and the split between controller, processor, owner and custodian
- 5Learn data remanence countermeasures in order of assurance: clearing, purging, degaussing, cryptographic erase, physical destruction
- 1Learn secure design principles by name and be able to give one example of each in an enterprise setting
- 2Study Bell-LaPadula, Biba and Clark-Wilson and state which property protects confidentiality and which protects integrity
- 3Study the vulnerabilities specific to cloud, containerised, serverless, embedded, industrial control and IoT systems
- 4Study site and facility controls: wiring closets, media storage, utilities, HVAC, water and fire suppression classes
- 5Work through the architecture chapters in the CISSP Official Study Guide by Chapple, Stewart and Gibson
- 1Separate symmetric from asymmetric on speed, key distribution, and what each is actually used for in a hybrid scheme
- 2Learn the cryptographic lifecycle: key generation, distribution, storage, rotation, escrow, revocation and destruction
- 3Study PKI end to end, including certificate authorities, registration authorities, CRLs and OCSP
- 4Learn digital signature construction and why hashing precedes signing
- 5Name and describe cryptanalytic attacks: brute force, chosen plaintext, known plaintext, side channel, fault injection, birthday, pass the hash
- 1Map each OSI layer to the attacks and controls that live there, since CISSP asks at the layer level
- 2Study converged protocols, micro-segmentation, software defined networking and software defined WAN
- 3Study wireless security, cellular and satellite implications, and content distribution networks
- 4Learn secure channel choices for voice, multimedia collaboration, remote access and third-party connectivity
- 5Work 60 network domain practice items under timed conditions
- 1Compare RBAC, ABAC, MAC, DAC, rule-based and risk-based access control with a scenario for each
- 2Study the identity provisioning lifecycle including access reviews, deprovisioning and privilege escalation risk
- 3Learn federation properly: SAML assertions, OpenID Connect tokens, OAuth grant roles, and what each one is for
- 4Study Kerberos message flow and its known weaknesses, which is a repeat exam favourite
- 5Distinguish identification, authentication, authorization and accountability and use the words precisely
- 1Compare vulnerability assessment with penetration testing, and know the phases of a penetration test
- 2Learn the audit types: internal, external and third-party, and who the audience is for each report
- 3Study synthetic transactions, misuse case testing, interface testing and test coverage analysis
- 4Study SOC 1, SOC 2 and SOC 3 reports and what each one is appropriate to share
- 5Practise reading a scenario and choosing the correct assessment technique rather than the most thorough one
- 1Learn the incident management sequence in ISC2 order: detection, response, mitigation, reporting, recovery, remediation, lessons learned
- 2Study evidence handling, chain of custody, and the standards of proof for administrative, civil, criminal and regulatory investigations
- 3Study logging and monitoring: SIEM, IDS and IPS placement, egress monitoring, threat intelligence, user behaviour analytics
- 4Learn need to know, least privilege, separation of duties and job rotation as controls against specific fraud scenarios
- 5Work 60 operations items and record which distractors tempted you
- 1Study recovery strategies, backup strategies, and hot, warm, cold and mobile processing sites with their tradeoffs
- 2Learn the disaster recovery test types in escalating order: read-through, walkthrough, simulation, parallel, full interruption
- 3Study secure development lifecycles and where security activities belong in Agile, Waterfall and DevSecOps
- 4Compare SAST, DAST, IAST and software composition analysis, and know what each one finds and misses
- 5Study assessing acquired software: commercial off the shelf, open source, managed services and cloud
- 1Rework 200 previously missed items and classify each miss as knowledge gap, misread stem, or wrong frame of reference
- 2Practise the ordering questions: what do you do first, what is the best next step, what is the most effective control
- 3Drill the standard priority order the exam rewards: human safety first, then policy and management approval, then technical action
- 4Use the Destination Certification CISSP mind maps to connect concepts that sit in different domains but appear in the same scenario
- 5Write one-paragraph summaries of the five weakest sub-objectives from memory
- 1Sit two 150-item timed practice exams on separate days, without pausing, to rehearse three hours of continuous concentration
- 2Practise never revisiting an answer, because ISC2 disables item review and changing your mind is not available on the day
- 3Confirm your test centre is a Pearson Professional Center or ISC2-authorized PVTC Select, since no other venue can deliver CISSP
- 4Check your identification against Pearson VUE requirements and confirm the name matches your ISC2 profile exactly
- 5Line up an endorser now: an ISC2 certified professional in good standing who will digitally sign your application inside the nine-month window
Ready to pass CISSP?
Get 500+ practice questions, video walkthroughs, and a pass guarantee.
Best Study Resources
CISSP Certification Exam Outline (ISC2)
Official blueprintThe authoritative document, published by ISC2 in English, Chinese, Japanese, German and Spanish. It carries the eight domain weights and every sub-objective, and it is the only reference that decides what is in scope.
Free
ISC2 Computerized Adaptive Testing FAQ
Official policy pageExplains the 100-item minimum, the 150-item maximum, the 25 unscored pretest items, the 95 percent confidence stopping rule, the run-out-of-time rule and the ban on item review. Reading it removes most exam-day surprises.
Free
CISSP Official Study Guide, 10th edition, Sybex
BookThe ISC2-endorsed text by Mike Chapple, James Michael Stewart and Darril Gibson, mapped to the current outline, with chapter review questions and an online test bank.
Roughly US$60
CISSP Official ISC2 Practice Tests, Sybex
Practice questionsDomain-by-domain question sets plus full practice exams, written to the same outline as the study guide. Useful for isolating one weak domain at a time.
Roughly US$40
CISSP All-in-One Exam Guide, McGraw Hill
BookThe Fernando Maymi and Shon Harris volume, longer and more discursive than the Sybex guide. Better as a second explanation of a concept you did not follow the first time.
Roughly US$70
Destination Certification CISSP MindMap videos
Video seriesRob Witcher and John Berti walk each domain as a single connected diagram. Effective for the cross-domain scenarios that CISSP builds its harder items from.
Free on YouTube
Boson ExSim-Max for CISSP
Practice exam engineTimed practice exams with explanations that argue the case for the correct answer and against each distractor, which is the reasoning CISSP items demand.
Listed at US$99 by Boson
ISC2 Official CISSP Online Self-Paced Training
Official courseISC2's own courseware, written by the certifying body. It also earns CPE credits if you already hold another ISC2 certification.
Paid, sold through isc2.org
ISC2 Exam Peace of Mind Protection
Second-attempt bundleBuys a second attempt. Both attempts must be taken within 180 days of purchase and the retake waiting period still applies between them.
US$249 on top of the US$749 exam voucher
Common Mistakes to Avoid
Preparing against a 4-hour, 125 to 175 item exam
That was an older CISSP CAT specification. ISC2 currently publishes 3 hours and 100 to 150 items, including 25 unscored pretest items. Practising to the wrong length trains the wrong pace.
Expecting a numerical score
ISC2 states that candidates receive no numerical scaled score. The result is pass or fail, and only failing candidates receive per-domain proficiency levels. Chasing a target percentage in practice tests measures something the real exam never reports.
Panicking when the exam feels hard at item 90
ISC2 states the algorithm targets items you have about a 50 percent chance of answering correctly, so every candidate answers about half of what they see incorrectly. Difficulty is the design, not a signal about your result.
Assuming a 100-item finish means failure
ISC2 says the opposite is equally possible: an exam ending at the 100-item minimum means the algorithm reached 95 percent confidence quickly, in either direction. Exam length carries no information you can act on.
Answering as the engineer who would fix the problem
CISSP items usually ask what should happen first or what is most effective at the programme level. The correct answer is often to assess risk, obtain management approval, or check the policy, before anyone touches a system.
Skipping Software Development Security because you are not a developer
It is 10 percent of a compensatory exam, which is the same weight as Asset Security. ISC2 asks you to compare SAST and DAST, place security activities inside a lifecycle, and assess acquired software, none of which requires writing code.
Leaving the endorsement to later
ISC2 gives you nine months from the exam date to complete the certification application, and it must be endorsed and digitally signed by an ISC2 certified professional. Identify your endorser before you sit, or ask ISC2 to act as endorser.
Treating breaks as free time
ISC2 does not limit the number or duration of breaks, but every minute counts inside the three-hour maximum administration time. A ten-minute break costs ten minutes of exam.
Booking a Chinese-language sitting without checking the window
ISC2 offers the Chinese-language CISSP only during four annual windows: 1 to 31 March, 1 to 30 June, 1 to 30 September and 1 to 31 December. Outside those, the sitting does not exist.
Planning to skip an item and return to it
Item review is disabled on CAT. ISC2 states that once an answer is finalised, it cannot be reviewed or changed, because the next item is chosen from your response. Every answer is a commitment.
Exam Day Tips
- 1
Test only at a Pearson Professional Center or an ISC2-authorized Pearson VUE Select centre. ISC2 does not deliver CISSP at training provider events, mobile facilities, or online.
- 2
Bring the identification Pearson VUE specifies for ISC2, with the name matching your ISC2 profile exactly. A mismatch is the most common reason a booked sitting is refused.
- 3
Plan your three hours before you start. Breaks are unlimited in number and length but they run inside the same 180 minutes.
- 4
Answer the first 100 items as though they are the whole exam, because for many candidates they are: the confidence interval rule can end the session at exactly 100.
- 5
Never leave an item unanswered while time remains. If you fail to answer 75 operational items and 25 pretest items inside the time limit, ISC2 fails you automatically.
- 6
Read the last line of the stem first when a scenario runs long. The question often asks for the first step, not the complete solution.
- 7
When two answers are both defensible, choose the one a security manager would authorise over the one a technician would execute.
- 8
Expect the exam to feel roughly as hard at the end as at the start. That is the adaptive algorithm converging, and it says nothing about whether you are passing.
- 9
Collect your unofficial result from the proctor at check-out. ISC2 emails the official result separately, and results are never given over the phone.
- 10
If you fail, keep the printed domain proficiency feedback. Below, near and above proficiency per domain is the only diagnostic ISC2 provides for planning a retake.
Career Paths & Salary Ranges
Information security analyst
The core practitioner role that maps to most of the eight domains. CISSP is commonly listed as preferred rather than required at this level, and the five-year experience rule means most holders arrive here already.
$69,660 to $186,420, median $124,910 (US Bureau of Labor Statistics, May 2024)
Computer and information systems manager
Running security or IT teams and budgets. The managerial framing of CISSP items reflects this work, which is why the exam rewards process answers over technical ones.
$104,450 to $239,200, median $171,200 (US Bureau of Labor Statistics, May 2024)
Security architect
Designing controls and reference architectures across the estate. Domain 3, Security Architecture and Engineering, at 13 percent, is the direct preparation for it.
Not separately measured by BLS. Closest published series is computer network architects at a median of $130,390, range $79,520 to $198,030 (May 2024)
Security consultant or assessor
Advising multiple clients on programme design, audit readiness and control selection. Domain 6, Security Assessment and Testing, at 12 percent, maps closely.
Not separately measured by BLS. Management, scientific and technical consulting services paid information security analysts a median of $120,050 (May 2024)
Chief information security officer
Owning the security programme and reporting to executives or the board. ISC2 does not publish CISO salary data, and figures quoted elsewhere are survey estimates rather than official statistics.
Not separately measured by BLS. Falls within computer and information systems managers, where the top 10 percent exceeded $239,200 (May 2024)
Prerequisites & Requirements
- Five years of cumulative, full-time paid work experience in at least two of the eight domains of the current CISSP Exam Outline.
- Full-time experience accrues monthly, defined by ISC2 as at least 35 hours a week for four consecutive weeks. Part-time work of 20 to 34 hours a week converts at 1,040 hours for six months or 2,080 hours for twelve months of full-time experience.
- Paid and unpaid internships count with documentation on official letterhead, and academic internships may be verified by a registrar.
- One year may be waived by a bachelor's or master's degree in computer science, information technology or a related field, or by one credential from the ISC2 approved waiver list. Only one waiver is permitted; a degree and a credential cannot be stacked.
- ISC2 revised the approved waiver list on 1 April 2026. Credentials must have a publicly available exam outline, be ANAB ISO/IEC 17024 accredited or come from a reputable organisation with a proctored exam, and align at least 90 percent with two or more CISSP domains. Check the list before assuming your credential still qualifies.
- No experience is needed to sit the exam. Passing without the experience makes you an Associate of ISC2, with six years to earn the five years required.
- After passing you must be endorsed and digitally signed by an ISC2 certified professional in good standing, or ask ISC2 to act as endorser, and commit to the ISC2 Code of Ethics.
Frequently Asked Questions
How long is the CISSP exam and how many questions does it have?
Three hours maximum, with 100 to 150 items. ISC2 includes 25 unscored pretest items inside the minimum-length exam, so a 100-item sitting contains 75 scored items. There is no minimum administration time, and all breaks count inside the three hours.
What is the passing score?
The ISC2 exam outline states 700 out of 1000 points. In practice, no candidate ever sees a number: CAT returns pass or fail only, and failing candidates receive proficiency levels per domain rather than a score. Nothing you can compute during the exam tells you where you stand.
How much does the exam cost in my region?
ISC2 publishes US$749 for the Americas, Asia Pacific, the Middle East, Africa and all regions not listed separately; EUR 719.04 for EMEA; and GBP 606.69 for the United Kingdom. Pricing and taxes follow the location of the exam, and Pearson VUE shows the final amount at registration.
How long must I wait to retake CISSP if I fail?
Thirty test-free days after a first attempt, 60 test-free days after a second, and 90 test-free days after a third and every attempt thereafter. Separately, you may sit an ISC2 exam a maximum of four times in any 12-month period for the same certification programme.
What happens if I fail?
You get an unofficial fail from the proctor at check-out and an official confirmation by email. At the test centre you also receive a list of proficiency levels for each domain: below proficiency, near proficiency or above proficiency. You pay the full fee again for the next attempt.
When do I get my result?
Usually immediately. ISC2 states results are given at the end of the exam and that the proctor provides an unofficial result at check-out, with the official result emailed afterwards. ISC2 also warns that when test volume for a form is low, results can be delayed roughly six to eight weeks while it completes statistical and psychometric analysis, and that real-time results may occasionally be unavailable.
Can I take CISSP online from home?
No. ISC2 delivers CISSP only at Pearson Professional Centers and ISC2-authorized Pearson VUE Select test centres, and states explicitly that CAT exams cannot be taken at Authorized Training Provider events or mobile testing facilities.
Can I use a calculator or any reference material?
No reference material is permitted, and none is needed. CISSP asks you to reason about risk formulas conceptually rather than compute long arithmetic, so there is no on-screen calculator dependency in the way a finance exam would have. Test centre rules bar personal items from the testing room.
How does the adaptive scoring actually work?
Every candidate starts with an item below the passing standard. After each answer, the algorithm re-estimates your ability and selects a next item you have roughly a 50 percent chance of getting right. Once 100 items are done, the exam ends as soon as your estimate excludes the pass point with 95 percent statistical confidence. If that never happens, the maximum-length rule at 150 items or the run-out-of-time rule at 180 minutes decides the result.
Do I need to be above proficiency in all eight domains?
No. ISC2 states CISSP is a compensatory exam: strong performance in one domain can offset weaker performance in another, and a single pass or fail is computed across all operational items. ISC2 also notes that a weak showing in a lightly weighted domain can still be survivable, without guaranteeing it.
Can I go back and change an answer?
No. ISC2 disables item review on CAT because each item is selected from your previous responses. Once an answer is finalised it cannot be reviewed or changed.
What identification do I need?
Pearson VUE requires government-issued identification matching the name on your ISC2 registration, and it captures your photo and signature at check-in. Check the ISC2 programme page on the Pearson VUE site before travelling, since accepted document types vary by country.
How do I request testing accommodations?
Accommodations must be pre-approved by ISC2 before you schedule. ISC2 states that exceptions to the three-hour maximum administration time are provided only to candidates with medical accommodations approved in advance. Apply through ISC2 rather than at the test centre.
What is the CISSP pass rate?
ISC2 does not publish a pass rate for the CISSP. No official first-attempt or overall figure exists, and the percentages quoted on training-provider sites are estimates. ISC2 also does not release the number of items you answered correctly, so no candidate can reconstruct one.
What do I have to do after passing?
Complete the certification application within nine months of your exam date, be endorsed and digitally signed by an ISC2 certified professional in good standing, agree to the ISC2 Code of Ethics, and pay the first Annual Maintenance Fee of US$135. ISC2 will act as endorser if you do not know a certified professional.
How do I keep the certification once I have it?
Earn 120 Continuing Professional Education credits across each three-year cycle, with a minimum of 40 credits per year, and pay the US$135 Annual Maintenance Fee annually. One AMF covers every ISC2 certification you hold. ISC2 grants a 90-day grace period after cycle expiry to submit outstanding CPEs and pay past due fees.
What happens if I miss my CPE requirement?
Your certification is suspended. Reinstatement requires submitting all outstanding CPE credits and paying all past due AMFs. Suspension can be maintained for up to two consecutive years; after that ISC2 terminates membership and revokes all rights, and reinstatement then requires retaking and passing the exam.
What does it cost to reschedule or cancel?
ISC2 publishes a rescheduling fee of US$50, GBP 35 or EUR 40, and a cancellation fee of US$100, GBP 70 or EUR 80. If you bought Exam Peace of Mind Protection for US$249, both attempts must be taken within 180 days of purchase.
How does CISSP compare with CCSP?
Both are ISC2 CAT exams of 100 to 150 items with a three-hour limit, but CCSP costs US$599 against CISSP's US$749 and covers cloud security specifically rather than eight general domains. CCSP requires five years of IT experience with at least three in information security and one in a CCSP domain, and holding CISSP satisfies the whole CCSP experience requirement.
Is CISSP worth taking before I have five years of experience?
You can sit it and become an Associate of ISC2, with six years to accumulate the five years required. That is a real option, but the exam is written for people who have made programme-level decisions, and candidates without that background usually spend longer on Security and Risk Management and Security Operations than the domain weights alone would suggest.
Success Stories
“CISSP was the hardest professional exam I've ever taken, but also the most valuable. Within a year of certification, I was promoted to CISO. The managerial mindset the exam teaches directly applies to executive leadership.”
James Wilson
CISO at Healthcare Company
“Failed my first attempt, passed on second. The difference was understanding that CISSP wants you to think like a security executive, not a technician. Kelly Handerhan's videos helped me shift my mindset.”
Lisa Chen
Security Director at Financial Services
“CISSP opened doors that my decade of technical experience couldn't. Clients trust the credential, and it gives me the vocabulary to speak with C-suite executives about security strategy.”
Michael Torres
Senior Security Consultant at Big 4
Is this the right exam for your situation?
Verifiable through ISC2 member lookup, which is what makes the line on your resume checkable.
Pass CISSP, Guaranteed
94% pass rate on first attempt
One-time • Lifetime access