CISSP Exam Guide
CISSP Exam: Format, Scoring & Requirements
The Certified Information Systems Security Professional (CISSP) examination tests broad cybersecurity knowledge across eight domains, combining technical understanding with security management, governance, risk and real-world decision making.
Understanding how the exam works is almost as important as understanding what it covers.
3 Hours
The CISSP examination has a maximum administration time of three hours.
Manage your TIME100โ150 Items
The number of questions varies because the exam uses Computerized Adaptive Testing.
Expect the UNEXPECTED700 / 1000
ISC2 states the passing standard as 700 out of 1000 points.
Demonstrate PROFICIENCYThis guide is based on the CISSP Exam Outline effective 15 April 2024 and ISC2 examination information reviewed in August 2026.
Exam policies, prices and administrative requirements can change, so candidates should always verify current information with ISC2 before booking.
CISSP exam quick facts
| Exam feature | Current CISSP format |
|---|---|
| Delivery | Computerized Adaptive Testing (CAT) |
| Time | Maximum 3 hours |
| Items | 100โ150 |
| Question format | Multiple-choice and advanced item types |
| Passing standard | 700 out of 1000 |
| Unscored items | 25 pretest items included in the minimum-length exam |
| Languages | Chinese, English, German, Japanese and Spanish |
| Testing | Authorised Pearson VUE testing centres |
| Results | Provided immediately after completing the CAT examination |
1 What does CISSP actually test? More than memorising cybersecurity terminology
CISSP covers a broad range of cybersecurity disciplines.
ISC2 describes the certification as validating both technical and managerial knowledge required to design, engineer and manage an organisation's overall security posture.
A candidate may understand firewalls, cryptography and penetration testing extremely well but still need strong knowledge of governance, risk, business continuity, legal concepts, asset management and security management.
2 The Eight CISSP Domains The complete exam knowledge structure
Governance, risk, ethics, law, policy, continuity and security awareness.
Classification, handling, ownership, lifecycle and protection of information and assets.
Secure design, security models, cryptography, architecture and physical security.
Network architecture, protocols, network components and secure communications.
Identification, authentication, authorization, federation and identity lifecycle management.
Security testing, assessment, auditing, metrics and remediation.
Incident response, monitoring, vulnerability management, recovery and operational security.
Secure development lifecycle, software security and secure coding.
Current CISSP domain weights
| Domain | Exam weight |
|---|---|
| 1. Security and Risk Management | 16% |
| 2. Asset Security | 10% |
| 3. Security Architecture and Engineering | 13% |
| 4. Communication and Network Security | 13% |
| 5. Identity and Access Management (IAM) | 13% |
| 6. Security Assessment and Testing | 12% |
| 7. Security Operations | 13% |
| 8. Software Development Security | 10% |
| Total | 100% |
Domain weight memory aid
Every domain matters.
3 Computerized Adaptive Testing (CAT) The exam adapts as you answer questions
CISSP uses Computerized Adaptive Testing.
This means you are not simply given a fixed set of identical questions that every candidate receives.
The examination continually estimates your ability based on your previous responses and selects future items accordingly.
The adaptive algorithm attempts to present questions appropriate to your estimated ability.
ISC2 explains that candidates should generally expect each item to feel challenging.
๐ง Why does CAT sometimes feel like you are failing? Difficulty is part of the design
After each answer, CAT chooses another item designed to provide useful information about your ability.
ISC2 explains that the selection algorithm aims to present an item that the candidate has approximately a 50% probability of answering correctly.
Candidate A has relatively strong CISSP knowledge.
CAT therefore needs increasingly challenging questions to determine exactly where Candidate A's ability sits.
Candidate A may walk out believing:
"That was incredibly difficult โ I must have failed."
But challenging questions are normal behaviour for an adaptive exam.
The important factor is the level of questions you successfully answer, not simply the raw number that felt easy or difficult.
๐ Why can the exam stop at different numbers of questions? 100 questions does not mean everyone receives the same exam
The CISSP examination contains between 100 and 150 items.
Once the minimum exam length has been reached, CAT can end the examination when it has sufficient statistical confidence to determine whether the candidate's estimated ability is above or below the passing standard.
CAT may already have sufficient statistical confidence to determine the result.
CAT requires additional information before it can confidently determine the candidate's proficiency.
The candidate's final estimated ability is compared with the passing standard using the maximum-length exam rule.
Receiving more than 100 questions does not itself mean that you are failing.
๐ The 95% Confidence Rule How CAT can make an early decision
After the minimum exam length has been satisfied, the CAT exam can terminate when the candidate's estimated ability excludes the pass point with 95% statistical confidence.
If CAT can determine with the required confidence that the candidate's ability exceeds the passing standard, the result is a pass.
If CAT can determine with the required confidence that the candidate's ability is below the standard, the result is a fail.
Question difficulty and the adaptive estimate of ability are part of the scoring process.
4 You cannot go back to previous questions Once an answer is finalised, it is final
One of the most important differences between CISSP CAT and many traditional exams is that item review is not permitted.
Once you finalise your answer and move to the next item, you cannot return and change the previous answer.
The next question is selected partly on the basis of previous responses.
Changing an earlier answer would undermine the adaptive sequence that has already occurred.
CAT question rule
5 25 Pretest Questions Some items do not contribute to your score
ISC2 includes 25 pretest or unscored items as part of the minimum-length examination.
These are questions being evaluated for possible future use.
Pretest questions are mixed into the examination and are not marked as unscored.
You should therefore treat every question as though it counts.
"This question looks strange. It must be one of the unscored ones, so I won't spend much time on it."
You have no way of knowing whether that assumption is correct.6 How CISSP Scoring Works 700 / 1000 does not mean "70% of questions"
ISC2 publishes the CISSP passing grade as 700 out of 1000 points.
However, because CISSP uses Computerized Adaptive Testing, this should not be interpreted as a simple requirement to answer 70% of the questions correctly.
The adaptive system estimates candidate ability using the questions presented, their difficulty and the responses provided.
You do not know the scoring status of individual items, their difficulty calibration or which 25 items are pretest questions.
โ๏ธ Do you need to pass every domain? CISSP uses compensatory scoring
No.
ISC2 describes its certification examinations as compensatory exams.
You do not need to achieve "Above Proficiency" independently in every single CISSP domain in order to pass.
Performance across the operational items contributes to the overall pass/fail decision.
A candidate performs extremely strongly in several heavily weighted domains but performs less strongly in one smaller domain.
That weaker domain does not automatically cause the candidate to fail.
All eight domains contribute to the examination and the CAT algorithm must construct the exam according to the published domain weights.
7 Exam Results When will you know?
CAT candidates receive their exam result immediately after completing the examination.
You receive a pass result but not a numerical scaled score.
ISC2 provides diagnostic domain feedback to help identify areas requiring further preparation.
Failing-candidate domain feedback
ISC2 does not provide candidates with a numerical scaled score on the pass/fail report.
8 Question Types Multiple-choice and advanced item types
ISC2 states that CISSP uses:
Questions may test straightforward knowledge, but many require application of knowledge to a scenario or business decision.
A question may describe a security problem and offer several answers that are technically possible.
Your task is to determine which answer best addresses the requirement in the scenario.
Several answers may be reasonable in the real world, while the exam asks for the answer that is most appropriate for the specific question.
๐ง The CISSP Mindset Think like a security professional responsible for the organisation
CISSP is not simply a technical troubleshooting examination.
Many questions reward thinking about security within the wider context of the organisation.
In many scenarios, understanding the requirement, risk and authority comes before selecting a technical implementation.
๐ BEST vs FIRST Pay attention to exactly what the question asks
Asks what should happen before the other actions.
Think: What is the correct sequence?
Asks which option provides the most appropriate overall answer.
Think: Which choice most completely addresses the requirement?
Asks which explanation or outcome is most probable.
Asks for the main reason, responsibility, concern or objective.
Do not select an answer simply because it describes a good security practice.
9 Time Management You must reach the minimum number of questions
The CISSP exam has a maximum duration of three hours.
Because the exam can contain up to 150 items, candidates should avoid spending excessive time repeatedly reconsidering individual questions.
Under ISC2's run-out-of-time rule, a candidate must answer at least the minimum examination length required for a valid pass/fail evaluation.
A practical approach
Identify exactly what the question is asking.
Reduce the decision where possible.
Do not spend ten minutes waiting for certainty that may never come.
Remember that you cannot return to the question later.
โ Breaks You can take them, but the clock keeps running
ISC2 does not impose a specific limit on the number or duration of breaks during a CAT exam.
However:
Candidates must follow the test-centre process when leaving and re-entering the examination room.
๐ Exam Languages CISSP CAT is available in multiple languages
CISSP is currently available in:
Older material may state that only the English examination uses Computerized Adaptive Testing. That information is outdated.
Chinese-language CISSP examinations are currently available only during specified appointment windows, so candidates using that language should check current ISC2 availability.
10 Where is the CISSP Exam Taken? Authorised Pearson VUE testing centres
ISC2 CISSP examinations are delivered through authorised Pearson VUE testing centres.
The exam is therefore not simply an unproctored examination that you take from your personal computer at home.
Test-centre availability varies by location and date.
11 How to Book the CISSP Exam ISC2 account โ purchase โ Pearson VUE
ISC2 warns that the information used for registration must match the ID presented at the test centre.
๐ณ Exam Cost Pricing varies by region
CISSP examination pricing varies by the location in which the exam is administered.
| Region | Standard CISSP registration |
|---|---|
| United Kingdom | ยฃ606.69 |
| EMEA | โฌ719.04 |
| United States / standard USD region | US $749 |
Exam pricing and taxes can change. Always check the current ISC2 pricing page before purchasing.
๐ Scheduling, Rescheduling & Cancellation Know the administrative rules before booking
ISC2 currently gives candidates up to 365 days from exam purchase to schedule and sit the examination.
Exams cannot be rescheduled once the appointment is within 24 hours.
| Action | Current UK fee |
|---|---|
| Reschedule | ยฃ35 |
| Cancel | ยฃ70 |
Fees and policies can change, so verify current requirements directly with ISC2 and Pearson VUE.
12 Exam Day What to expect at the testing centre
ISC2 recommends arriving at the testing centre at least 30 minutes before your scheduled exam time.
You will normally need:
ISC2 currently requires two acceptable forms of identification for adult candidates:
Must meet ISC2 requirements and normally include a photograph and signature.
Must meet ISC2 requirements and normally include a signature.
Testing-centre process may include
Phones, recording devices and other electronic devices are prohibited under the ISC2 examination agreement and testing-centre security procedures.
๐ Exam Agreement & NDA Protecting the confidentiality of the examination
Before beginning the exam, candidates must accept the ISC2 Non-Disclosure Agreement.
ISC2 currently gives candidates three minutes to review and accept it at the testing workstation.
Candidates must not record, reproduce, disclose or distribute actual CISSP examination content.
13 CISSP Experience Requirement Passing the exam and holding the certification are not exactly the same thing
To become fully CISSP certified, candidates must normally have:
ISC2 also recognises qualifying part-time work and internships under its experience rules.
A candidate has experience in:
- Security Operations;
- Security Assessment and Testing;
- Security and Risk Management.
Experience spanning those domains can contribute toward the CISSP requirement.
๐ One-Year Experience Waiver Some education or certifications can reduce the requirement
Candidates may qualify to reduce the five-year requirement by up to one year.
This may be available through either:
A qualifying bachelor's or master's degree in computer science, information technology or a related field.
A credential appearing on ISC2's current approved experience-waiver list.
A degree and qualifying certification cannot be combined to remove two years from the experience requirement.
ISC2 updated its approved credential waiver list in April 2026, so candidates should check the current list rather than relying on an old study guide.
14 Can you take CISSP without five years of experience? Yes โ the Associate of ISC2 pathway exists
You do not need to wait until you have the full CISSP experience requirement before passing the examination.
A candidate who passes the CISSP examination but does not yet satisfy the experience requirement can become an Associate of ISC2.
ISC2 currently gives candidates using this pathway up to six years to accumulate the required experience.
15 What happens after you pass? Passing the exam starts the certification application process
Passing the examination is a major milestone, but candidates who meet the experience requirements must still complete the certification application and endorsement process.
๐ค Endorsement Your professional experience must be verified
Candidates normally provide an endorser who is an ISC2-certified professional in good standing and can attest to the candidate's professional experience.
ISC2 allows candidates to request endorsement by ISC2 instead. Supporting proof of employment is required for this route.
ISC2 currently requires the certification application process to be completed within nine months of the exam date.
ISC2 states that a percentage of certification applications are selected for audit and may require additional evidence to verify the experience claimed.
16 Maintaining CISSP after Certification The learning does not stop after the exam
CISSP is maintained through continuing professional education and the ISC2 Annual Maintenance Fee.
CISSP holders currently need 120 Continuing Professional Education credits during each three-year certification cycle.
The current ISC2 certified-member AMF is US $135 per year.
ISC2 certified members who hold multiple ISC2 certifications generally pay a single member AMF rather than a separate AMF for every certification.
17 What if you don't pass? Understand the current ISC2 retake policy
ISC2 currently applies increasing test-free periods between repeat examination attempts.
| Attempt | Minimum wait before another attempt |
|---|---|
| After first attempt | 30 test-free days |
| After second attempt | 60 test-free days |
| After third and subsequent attempts | 90 test-free days |
A candidate may currently attempt an ISC2 certification exam a maximum of four times within a 12-month period for that certification programme.
A candidate who does not pass receives domain proficiency feedback.
Rather than simply repeating the same study plan, use this feedback to identify domains requiring additional attention.
โ Common CISSP Exam Myths Things candidates frequently misunderstand
The published passing standard is 700/1000, but CAT uses an adaptive ability estimate rather than simply calculating a raw percentage of correct answers.
Not necessarily. Additional questions mean the CAT system needs more information before making its decision.
No. The CAT system can reach sufficient confidence for either a pass or a fail at the minimum examination length.
No. CISSP CAT does not permit review of previously finalised answers.
Candidates are not told which items are pretest questions.
CAT adapts item selection according to candidate performance while continuing to meet the CISSP exam-outline requirements.
CISSP uses compensatory scoring across the examination.
CISSP spans technical and managerial cybersecurity across eight broad domains.
Many CISSP questions require consideration of governance, business objectives, risk, policy and appropriate authority before technical implementation.
Candidates without the full experience requirement may pass the exam and use the Associate of ISC2 pathway while gaining the required experience.
Full certification also requires satisfying the experience, application, endorsement, ethics and maintenance-fee requirements.
This is outdated information. CISSP is now delivered using CAT in all currently supported exam languages.
How to approach a difficult CISSP question
When two or three answers appear reasonable, slow down and identify the precise objective of the question.
1. Identify the role
2. Find the clue word
3. Identify the objective
4. Check authority
5. Check sequence
6. Choose the best answer
Answer based on the scenario you have been given rather than adding assumptions that change the problem.
๐ Final Exam-Day Checklist Knowledge is only useful if you actually get into the exam
Know where you are going and how long the journey takes.
Make sure it matches the identification you will present.
Check they meet current ISC2 requirements and have not expired.
Allow time for the testing-centre check-in and security process.
Once you finalise an answer, you cannot return to it.
You cannot identify the 25 pretest items.
The three-hour limit includes breaks.
Do not assume that reaching question 101 or 130 means you are failing.
CAT has already moved on. You should too.
The complete CISSP journey
CISSP Exam memory aid
Read. Decide. Commit. Move forward.
CAT mindset
Don't predict CAT. Answer the question.
Key takeaways
CISSP currently uses Computerized Adaptive Testing for all supported exam languages.
The exam lasts a maximum of three hours.
Candidates receive between 100 and 150 items.
The exam contains multiple-choice and advanced item types.
Twenty-five pretest items are included in the minimum-length examination and do not contribute to the score.
Candidates cannot identify which questions are pretest items, so every item should be treated seriously.
The published CISSP passing standard is 700 out of 1000.
Because CISSP uses CAT, 700/1000 should not be interpreted as simply needing 70% of questions correct.
Once you finalise an answer, you cannot return to the previous question.
CAT continually estimates candidate ability and chooses subsequent items based on previous responses.
The exam can finish once the minimum item count is reached and CAT has sufficient statistical confidence to determine the result.
Reaching more than 100 questions does not automatically mean you are failing.
Likewise, finishing at 100 questions does not by itself reveal whether the result is a pass or fail.
CISSP uses compensatory scoring, so candidates do not need to independently achieve above-proficiency performance in every domain.
All eight domains still matter.
Results are provided immediately after completing the CAT examination.
Candidates do not receive a numerical scaled score on the pass/fail report.
Failing candidates receive domain-level proficiency information to help guide further study.
Breaks are permitted, but break time counts against the three-hour exam limit.
Candidates should arrive at the testing centre at least 30 minutes before the examination and bring the required identification.
To become fully CISSP certified, candidates normally require five years of cumulative experience across at least two CISSP domains.
Up to one year of the experience requirement may be waived through qualifying education or an approved certification.
Candidates without sufficient experience may use the Associate of ISC2 pathway after passing the exam.
After passing and meeting the experience requirements, candidates must complete the certification application and endorsement process.
The certification application must currently be completed within nine months of the exam date.
CISSP certification is maintained through continuing professional education and the ISC2 Annual Maintenance Fee.
Most importantly: understand the concepts, understand the business context, read exactly what the question asks and make the best decision based on the information provided.
๐ Official Sources & Further Reading Current ISC2 examination information
- ISC2 โ CISSP Certification Exam Outline
View the current CISSP exam outline - ISC2 โ Computerized Adaptive Testing (CAT)
Learn how ISC2 adaptive testing works - ISC2 โ Exam Language Availability
View currently supported exam languages - ISC2 โ Exam Pricing
View current examination prices - ISC2 โ Register for Your Certification Exam
View registration instructions - ISC2 โ Schedule Your Exam
View scheduling, rescheduling and cancellation information - ISC2 โ Prepare for Exam Day
View identification and test-centre requirements - ISC2 โ CISSP Experience Waiver Updates
View current CISSP experience requirements and waiver information - ISC2 โ Certification Application & Endorsement
View the certification application process - ISC2 โ Annual Maintenance Fees
View current ISC2 maintenance-fee information
