How Long to Study for CISSP
A complete week-by-week study plan for the CISSP (Very Hard difficulty, ~25% pass rate).
12
Weeks
14
Hrs/Week
164
Total Hours
~25%
Pass Rate
10-12 hours this week
- Download the CISSP Certification Exam Outline PDF from isc2.org and read the sub-objectives, not just the eight domain names
- Score yourself out of five on every sub-objective and multiply by the domain weight to find where your effort actually pays
- Confirm you meet the experience rule: five years cumulative full-time in at least two domains, with at most one year waived by a degree or an approved credential
- Read the ISC2 Computerized Adaptive Testing FAQ so the 100-item minimum, the 95 percent confidence rule and the no-review rule are not surprises
- Book a provisional test date at a Pearson Professional Center, remembering that Chinese-language sittings run only in March, June, September and December
12-15 hours this week
- Study governance, security strategy alignment, and the difference between policy, standard, procedure and guideline
- Learn the risk formulas end to end: asset value, exposure factor, single loss expectancy, annualised rate of occurrence, annualised loss expectancy
- Compare quantitative and qualitative risk assessment and know when each is appropriate
- Read the ISC2 Code of Professional Ethics in full and learn the canons in order, since order is testable
- Work 50 practice items on this domain and write down why each wrong option is wrong
12-15 hours this week
- Study business continuity: business impact analysis, maximum tolerable downtime, recovery time objective, recovery point objective
- Compare threat modelling methodologies including STRIDE and attack trees, and know what each produces
- Learn personnel security across the employment lifecycle and third-party and supply chain risk
- Study data classification, ownership roles, and the split between controller, processor, owner and custodian
- Learn data remanence countermeasures in order of assurance: clearing, purging, degaussing, cryptographic erase, physical destruction
14-16 hours this week
- Learn secure design principles by name and be able to give one example of each in an enterprise setting
- Study Bell-LaPadula, Biba and Clark-Wilson and state which property protects confidentiality and which protects integrity
- Study the vulnerabilities specific to cloud, containerised, serverless, embedded, industrial control and IoT systems
- Study site and facility controls: wiring closets, media storage, utilities, HVAC, water and fire suppression classes
- Work through the architecture chapters in the CISSP Official Study Guide by Chapple, Stewart and Gibson
12-15 hours this week
- Separate symmetric from asymmetric on speed, key distribution, and what each is actually used for in a hybrid scheme
- Learn the cryptographic lifecycle: key generation, distribution, storage, rotation, escrow, revocation and destruction
- Study PKI end to end, including certificate authorities, registration authorities, CRLs and OCSP
- Learn digital signature construction and why hashing precedes signing
- Name and describe cryptanalytic attacks: brute force, chosen plaintext, known plaintext, side channel, fault injection, birthday, pass the hash
12-15 hours this week
- Map each OSI layer to the attacks and controls that live there, since CISSP asks at the layer level
- Study converged protocols, micro-segmentation, software defined networking and software defined WAN
- Study wireless security, cellular and satellite implications, and content distribution networks
- Learn secure channel choices for voice, multimedia collaboration, remote access and third-party connectivity
- Work 60 network domain practice items under timed conditions
12-14 hours this week
- Compare RBAC, ABAC, MAC, DAC, rule-based and risk-based access control with a scenario for each
- Study the identity provisioning lifecycle including access reviews, deprovisioning and privilege escalation risk
- Learn federation properly: SAML assertions, OpenID Connect tokens, OAuth grant roles, and what each one is for
- Study Kerberos message flow and its known weaknesses, which is a repeat exam favourite
- Distinguish identification, authentication, authorization and accountability and use the words precisely
12-14 hours this week
- Compare vulnerability assessment with penetration testing, and know the phases of a penetration test
- Learn the audit types: internal, external and third-party, and who the audience is for each report
- Study synthetic transactions, misuse case testing, interface testing and test coverage analysis
- Study SOC 1, SOC 2 and SOC 3 reports and what each one is appropriate to share
- Practise reading a scenario and choosing the correct assessment technique rather than the most thorough one
12-15 hours this week
- Learn the incident management sequence in ISC2 order: detection, response, mitigation, reporting, recovery, remediation, lessons learned
- Study evidence handling, chain of custody, and the standards of proof for administrative, civil, criminal and regulatory investigations
- Study logging and monitoring: SIEM, IDS and IPS placement, egress monitoring, threat intelligence, user behaviour analytics
- Learn need to know, least privilege, separation of duties and job rotation as controls against specific fraud scenarios
- Work 60 operations items and record which distractors tempted you
12-15 hours this week
- Study recovery strategies, backup strategies, and hot, warm, cold and mobile processing sites with their tradeoffs
- Learn the disaster recovery test types in escalating order: read-through, walkthrough, simulation, parallel, full interruption
- Study secure development lifecycles and where security activities belong in Agile, Waterfall and DevSecOps
- Compare SAST, DAST, IAST and software composition analysis, and know what each one finds and misses
- Study assessing acquired software: commercial off the shelf, open source, managed services and cloud
14-16 hours this week
- Rework 200 previously missed items and classify each miss as knowledge gap, misread stem, or wrong frame of reference
- Practise the ordering questions: what do you do first, what is the best next step, what is the most effective control
- Drill the standard priority order the exam rewards: human safety first, then policy and management approval, then technical action
- Use the Destination Certification CISSP mind maps to connect concepts that sit in different domains but appear in the same scenario
- Write one-paragraph summaries of the five weakest sub-objectives from memory
14-18 hours this week
- Sit two 150-item timed practice exams on separate days, without pausing, to rehearse three hours of continuous concentration
- Practise never revisiting an answer, because ISC2 disables item review and changing your mind is not available on the day
- Confirm your test centre is a Pearson Professional Center or ISC2-authorized PVTC Select, since no other venue can deliver CISSP
- Check your identification against Pearson VUE requirements and confirm the name matches your ISC2 profile exactly
- Line up an endorser now: an ISC2 certified professional in good standing who will digitally sign your application inside the nine-month window
Duration: 18 weeks
Hours/week: 10 hours
Daily: ~2 hours on weeknights
Weekends: 3-4 hours Saturday + Sunday
Study during lunch breaks and commute time. Use weekends for deeper study sessions and practice tests.
Duration: 24 weeks
Hours/week: 7 hours
Saturday: 4-5 hours of focused study
Sunday: 3-4 hours of practice tests
Longer timeline but sustainable. Review flashcards on weeknights for 15-20 minutes to maintain retention.
How long does it take to study for the CISSP?
Plan for 12 weeks of dedicated study at 14 hours per week (164 total hours). If studying while working full-time, extend to 18 weeks.
Can I pass the CISSP in 2 weeks?
It's unlikely for most candidates. The CISSP is rated "Very Hard" difficulty and typically requires 12 weeks of preparation. Rushing increases your risk of failing and paying the exam fee again.
How many hours a day should I study for CISSP?
Aim for 3-4 hours per day on weekdays. Quality matters more than quantity, use active recall and practice tests rather than passive reading.
Is CISSP hard to pass?
The CISSP is rated "Very Hard" difficulty with a pass rate of ~25%. Significant preparation is essential.
Ready to start your CISSP journey?
Get the complete exam guide with tips, resources, and practice questions.
View CISSP Guide