Study Timeline

How Long to Study for CISSP

A complete week-by-week study plan for the CISSP (Very Hard difficulty, ~25% pass rate).

12

Weeks

14

Hrs/Week

164

Total Hours

~25%

Pass Rate

Blueprint mapping and honest gap analysis
Week 1

10-12 hours this week

  • Download the CISSP Certification Exam Outline PDF from isc2.org and read the sub-objectives, not just the eight domain names
  • Score yourself out of five on every sub-objective and multiply by the domain weight to find where your effort actually pays
  • Confirm you meet the experience rule: five years cumulative full-time in at least two domains, with at most one year waived by a degree or an approved credential
  • Read the ISC2 Computerized Adaptive Testing FAQ so the 100-item minimum, the 95 percent confidence rule and the no-review rule are not surprises
  • Book a provisional test date at a Pearson Professional Center, remembering that Chinese-language sittings run only in March, June, September and December
Security and risk management, part one
Week 2

12-15 hours this week

  • Study governance, security strategy alignment, and the difference between policy, standard, procedure and guideline
  • Learn the risk formulas end to end: asset value, exposure factor, single loss expectancy, annualised rate of occurrence, annualised loss expectancy
  • Compare quantitative and qualitative risk assessment and know when each is appropriate
  • Read the ISC2 Code of Professional Ethics in full and learn the canons in order, since order is testable
  • Work 50 practice items on this domain and write down why each wrong option is wrong
Security and risk management, part two, plus asset security
Week 3

12-15 hours this week

  • Study business continuity: business impact analysis, maximum tolerable downtime, recovery time objective, recovery point objective
  • Compare threat modelling methodologies including STRIDE and attack trees, and know what each produces
  • Learn personnel security across the employment lifecycle and third-party and supply chain risk
  • Study data classification, ownership roles, and the split between controller, processor, owner and custodian
  • Learn data remanence countermeasures in order of assurance: clearing, purging, degaussing, cryptographic erase, physical destruction
Security architecture and engineering, part one
Week 4

14-16 hours this week

  • Learn secure design principles by name and be able to give one example of each in an enterprise setting
  • Study Bell-LaPadula, Biba and Clark-Wilson and state which property protects confidentiality and which protects integrity
  • Study the vulnerabilities specific to cloud, containerised, serverless, embedded, industrial control and IoT systems
  • Study site and facility controls: wiring closets, media storage, utilities, HVAC, water and fire suppression classes
  • Work through the architecture chapters in the CISSP Official Study Guide by Chapple, Stewart and Gibson
Cryptography
Week 5

12-15 hours this week

  • Separate symmetric from asymmetric on speed, key distribution, and what each is actually used for in a hybrid scheme
  • Learn the cryptographic lifecycle: key generation, distribution, storage, rotation, escrow, revocation and destruction
  • Study PKI end to end, including certificate authorities, registration authorities, CRLs and OCSP
  • Learn digital signature construction and why hashing precedes signing
  • Name and describe cryptanalytic attacks: brute force, chosen plaintext, known plaintext, side channel, fault injection, birthday, pass the hash
Communication and network security
Week 6

12-15 hours this week

  • Map each OSI layer to the attacks and controls that live there, since CISSP asks at the layer level
  • Study converged protocols, micro-segmentation, software defined networking and software defined WAN
  • Study wireless security, cellular and satellite implications, and content distribution networks
  • Learn secure channel choices for voice, multimedia collaboration, remote access and third-party connectivity
  • Work 60 network domain practice items under timed conditions
Identity and access management
Week 7

12-14 hours this week

  • Compare RBAC, ABAC, MAC, DAC, rule-based and risk-based access control with a scenario for each
  • Study the identity provisioning lifecycle including access reviews, deprovisioning and privilege escalation risk
  • Learn federation properly: SAML assertions, OpenID Connect tokens, OAuth grant roles, and what each one is for
  • Study Kerberos message flow and its known weaknesses, which is a repeat exam favourite
  • Distinguish identification, authentication, authorization and accountability and use the words precisely
Security assessment and testing
Week 8

12-14 hours this week

  • Compare vulnerability assessment with penetration testing, and know the phases of a penetration test
  • Learn the audit types: internal, external and third-party, and who the audience is for each report
  • Study synthetic transactions, misuse case testing, interface testing and test coverage analysis
  • Study SOC 1, SOC 2 and SOC 3 reports and what each one is appropriate to share
  • Practise reading a scenario and choosing the correct assessment technique rather than the most thorough one
Security operations, part one
Week 9

12-15 hours this week

  • Learn the incident management sequence in ISC2 order: detection, response, mitigation, reporting, recovery, remediation, lessons learned
  • Study evidence handling, chain of custody, and the standards of proof for administrative, civil, criminal and regulatory investigations
  • Study logging and monitoring: SIEM, IDS and IPS placement, egress monitoring, threat intelligence, user behaviour analytics
  • Learn need to know, least privilege, separation of duties and job rotation as controls against specific fraud scenarios
  • Work 60 operations items and record which distractors tempted you
Security operations, part two, plus software development security
Week 10

12-15 hours this week

  • Study recovery strategies, backup strategies, and hot, warm, cold and mobile processing sites with their tradeoffs
  • Learn the disaster recovery test types in escalating order: read-through, walkthrough, simulation, parallel, full interruption
  • Study secure development lifecycles and where security activities belong in Agile, Waterfall and DevSecOps
  • Compare SAST, DAST, IAST and software composition analysis, and know what each one finds and misses
  • Study assessing acquired software: commercial off the shelf, open source, managed services and cloud
Managerial framing and cross-domain integration
Week 11

14-16 hours this week

  • Rework 200 previously missed items and classify each miss as knowledge gap, misread stem, or wrong frame of reference
  • Practise the ordering questions: what do you do first, what is the best next step, what is the most effective control
  • Drill the standard priority order the exam rewards: human safety first, then policy and management approval, then technical action
  • Use the Destination Certification CISSP mind maps to connect concepts that sit in different domains but appear in the same scenario
  • Write one-paragraph summaries of the five weakest sub-objectives from memory
Adaptive rehearsal and logistics
Week 12

14-18 hours this week

  • Sit two 150-item timed practice exams on separate days, without pausing, to rehearse three hours of continuous concentration
  • Practise never revisiting an answer, because ISC2 disables item review and changing your mind is not available on the day
  • Confirm your test centre is a Pearson Professional Center or ISC2-authorized PVTC Select, since no other venue can deliver CISSP
  • Check your identification against Pearson VUE requirements and confirm the name matches your ISC2 profile exactly
  • Line up an endorser now: an ISC2 certified professional in good standing who will digitally sign your application inside the nine-month window
Working Full-Time Schedule

Duration: 18 weeks

Hours/week: 10 hours

Daily: ~2 hours on weeknights

Weekends: 3-4 hours Saturday + Sunday

Study during lunch breaks and commute time. Use weekends for deeper study sessions and practice tests.

Weekend-Only Schedule

Duration: 24 weeks

Hours/week: 7 hours

Saturday: 4-5 hours of focused study

Sunday: 3-4 hours of practice tests

Longer timeline but sustainable. Review flashcards on weeknights for 15-20 minutes to maintain retention.

Frequently Asked Questions

How long does it take to study for the CISSP?

Plan for 12 weeks of dedicated study at 14 hours per week (164 total hours). If studying while working full-time, extend to 18 weeks.

Can I pass the CISSP in 2 weeks?

It's unlikely for most candidates. The CISSP is rated "Very Hard" difficulty and typically requires 12 weeks of preparation. Rushing increases your risk of failing and paying the exam fee again.

How many hours a day should I study for CISSP?

Aim for 3-4 hours per day on weekdays. Quality matters more than quantity, use active recall and practice tests rather than passive reading.

Is CISSP hard to pass?

The CISSP is rated "Very Hard" difficulty with a pass rate of ~25%. Significant preparation is essential.

Ready to start your CISSP journey?

Get the complete exam guide with tips, resources, and practice questions.

View CISSP Guide