CISSP Exam Guide

CISSP Exam Guide

CISSP Exam: Format, Scoring & Requirements

The Certified Information Systems Security Professional (CISSP) examination tests broad cybersecurity knowledge across eight domains, combining technical understanding with security management, governance, risk and real-world decision making.

Understanding how the exam works is almost as important as understanding what it covers.

โฑ๏ธ

3 Hours

The CISSP examination has a maximum administration time of three hours.

Manage your TIME
๐Ÿ“

100โ€“150 Items

The number of questions varies because the exam uses Computerized Adaptive Testing.

Expect the UNEXPECTED
๐ŸŽฏ

700 / 1000

ISC2 states the passing standard as 700 out of 1000 points.

Demonstrate PROFICIENCY
Current exam information

This guide is based on the CISSP Exam Outline effective 15 April 2024 and ISC2 examination information reviewed in August 2026.

Exam policies, prices and administrative requirements can change, so candidates should always verify current information with ISC2 before booking.

CISSP exam quick facts

Exam featureCurrent CISSP format
DeliveryComputerized Adaptive Testing (CAT)
TimeMaximum 3 hours
Items100โ€“150
Question formatMultiple-choice and advanced item types
Passing standard700 out of 1000
Unscored items25 pretest items included in the minimum-length exam
LanguagesChinese, English, German, Japanese and Spanish
TestingAuthorised Pearson VUE testing centres
ResultsProvided immediately after completing the CAT examination
1 What does CISSP actually test? More than memorising cybersecurity terminology

CISSP covers a broad range of cybersecurity disciplines.

ISC2 describes the certification as validating both technical and managerial knowledge required to design, engineer and manage an organisation's overall security posture.

Governance Risk Asset Security Architecture Cryptography Networks IAM Testing Operations Software Security
CISSP is broad rather than narrowly technical

A candidate may understand firewalls, cryptography and penetration testing extremely well but still need strong knowledge of governance, risk, business continuity, legal concepts, asset management and security management.

2 The Eight CISSP Domains The complete exam knowledge structure
1. Security and Risk Management

Governance, risk, ethics, law, policy, continuity and security awareness.

2. Asset Security

Classification, handling, ownership, lifecycle and protection of information and assets.

3. Security Architecture and Engineering

Secure design, security models, cryptography, architecture and physical security.

4. Communication and Network Security

Network architecture, protocols, network components and secure communications.

5. Identity and Access Management

Identification, authentication, authorization, federation and identity lifecycle management.

6. Security Assessment and Testing

Security testing, assessment, auditing, metrics and remediation.

7. Security Operations

Incident response, monitoring, vulnerability management, recovery and operational security.

8. Software Development Security

Secure development lifecycle, software security and secure coding.

Current CISSP domain weights

DomainExam weight
1. Security and Risk Management16%
2. Asset Security10%
3. Security Architecture and Engineering13%
4. Communication and Network Security13%
5. Identity and Access Management (IAM)13%
6. Security Assessment and Testing12%
7. Security Operations13%
8. Software Development Security10%
Total100%

Domain weight memory aid

Domain 1 16%
Domains 3, 4, 5 & 7 13% each
Domain 6 12%
Domains 2 & 8 10% each

Every domain matters.

3 Computerized Adaptive Testing (CAT) The exam adapts as you answer questions

CISSP uses Computerized Adaptive Testing.

This means you are not simply given a fixed set of identical questions that every candidate receives.

The examination continually estimates your ability based on your previous responses and selects future items accordingly.

๐Ÿ“ Question โ†’ You answer
๐Ÿ“Š Estimate โ†’ CAT updates its estimate of your ability
๐ŸŽฏ Select โ†’ The algorithm chooses the next useful question
๐Ÿ”„ Repeat โ†’ The estimate becomes increasingly precise
โœ… Decision โ†’ The system eventually determines pass or fail
Expect the exam to feel difficult

The adaptive algorithm attempts to present questions appropriate to your estimated ability.

ISC2 explains that candidates should generally expect each item to feel challenging.

๐Ÿง  Why does CAT sometimes feel like you are failing? Difficulty is part of the design

After each answer, CAT chooses another item designed to provide useful information about your ability.

ISC2 explains that the selection algorithm aims to present an item that the candidate has approximately a 50% probability of answering correctly.

Example

Candidate A has relatively strong CISSP knowledge.

CAT therefore needs increasingly challenging questions to determine exactly where Candidate A's ability sits.

Candidate A may walk out believing:

"That was incredibly difficult โ€” I must have failed."

But challenging questions are normal behaviour for an adaptive exam.

Do not try to judge your result from question difficulty

The important factor is the level of questions you successfully answer, not simply the raw number that felt easy or difficult.

๐Ÿ›‘ Why can the exam stop at different numbers of questions? 100 questions does not mean everyone receives the same exam

The CISSP examination contains between 100 and 150 items.

Once the minimum exam length has been reached, CAT can end the examination when it has sufficient statistical confidence to determine whether the candidate's estimated ability is above or below the passing standard.

Exam stops at 100

CAT may already have sufficient statistical confidence to determine the result.

Exam continues

CAT requires additional information before it can confidently determine the candidate's proficiency.

Exam reaches 150

The candidate's final estimated ability is compared with the passing standard using the maximum-length exam rule.

Question count does not reliably tell you whether you passed

Receiving more than 100 questions does not itself mean that you are failing.

๐Ÿ“Š The 95% Confidence Rule How CAT can make an early decision

After the minimum exam length has been satisfied, the CAT exam can terminate when the candidate's estimated ability excludes the pass point with 95% statistical confidence.

Estimate above the standard

If CAT can determine with the required confidence that the candidate's ability exceeds the passing standard, the result is a pass.

Estimate below the standard

If CAT can determine with the required confidence that the candidate's ability is below the standard, the result is a fail.

This is why CISSP is not simply "get X questions correct"

Question difficulty and the adaptive estimate of ability are part of the scoring process.

4 You cannot go back to previous questions Once an answer is finalised, it is final

One of the most important differences between CISSP CAT and many traditional exams is that item review is not permitted.

Once you finalise your answer and move to the next item, you cannot return and change the previous answer.

Why?

The next question is selected partly on the basis of previous responses.

Changing an earlier answer would undermine the adaptive sequence that has already occurred.

CAT question rule

Read Understand exactly what is being asked
Decide Select the BEST answer
Commit Move forward
Never Plan to return later
5 25 Pretest Questions Some items do not contribute to your score

ISC2 includes 25 pretest or unscored items as part of the minimum-length examination.

These are questions being evaluated for possible future use.

You cannot identify them

Pretest questions are mixed into the examination and are not marked as unscored.

You should therefore treat every question as though it counts.

Wrong strategy

"This question looks strange. It must be one of the unscored ones, so I won't spend much time on it."

You have no way of knowing whether that assumption is correct.
6 How CISSP Scoring Works 700 / 1000 does not mean "70% of questions"

ISC2 publishes the CISSP passing grade as 700 out of 1000 points.

However, because CISSP uses Computerized Adaptive Testing, this should not be interpreted as a simple requirement to answer 70% of the questions correctly.

The adaptive system estimates candidate ability using the questions presented, their difficulty and the responses provided.

Do not calculate your exam score while taking the exam

You do not know the scoring status of individual items, their difficulty calibration or which 25 items are pretest questions.

โš–๏ธ Do you need to pass every domain? CISSP uses compensatory scoring

No.

ISC2 describes its certification examinations as compensatory exams.

You do not need to achieve "Above Proficiency" independently in every single CISSP domain in order to pass.

Performance across the operational items contributes to the overall pass/fail decision.

Example

A candidate performs extremely strongly in several heavily weighted domains but performs less strongly in one smaller domain.

That weaker domain does not automatically cause the candidate to fail.

But do not ignore any domain

All eight domains contribute to the examination and the CAT algorithm must construct the exam according to the published domain weights.

7 Exam Results When will you know?

CAT candidates receive their exam result immediately after completing the examination.

If you pass

You receive a pass result but not a numerical scaled score.

If you do not pass

ISC2 provides diagnostic domain feedback to help identify areas requiring further preparation.

Failing-candidate domain feedback

Below Proficiency Near Proficiency Above Proficiency
No numerical score report

ISC2 does not provide candidates with a numerical scaled score on the pass/fail report.

8 Question Types Multiple-choice and advanced item types

ISC2 states that CISSP uses:

Multiple Choice Advanced Item Types

Questions may test straightforward knowledge, but many require application of knowledge to a scenario or business decision.

Typical thinking pattern

A question may describe a security problem and offer several answers that are technically possible.

Your task is to determine which answer best addresses the requirement in the scenario.

Read words such as BEST, FIRST, MOST and PRIMARY carefully

Several answers may be reasonable in the real world, while the exam asks for the answer that is most appropriate for the specific question.

๐Ÿง  The CISSP Mindset Think like a security professional responsible for the organisation

CISSP is not simply a technical troubleshooting examination.

Many questions reward thinking about security within the wider context of the organisation.

๐ŸŽฏ Business โ†’ What is the organisation trying to achieve?
โš ๏ธ Risk โ†’ What is the actual risk?
๐Ÿ“œ Requirement โ†’ What does policy, law or governance require?
๐Ÿ‘ค Ownership โ†’ Who has authority to make the decision?
๐Ÿ›ก๏ธ Control โ†’ Which security response is appropriate?
๐Ÿ”ง Technology โ†’ Which technology implements the requirement?
Do not jump immediately to the keyboard

In many scenarios, understanding the requirement, risk and authority comes before selecting a technical implementation.

๐Ÿ” BEST vs FIRST Pay attention to exactly what the question asks
FIRST

Asks what should happen before the other actions.

Think: What is the correct sequence?

BEST

Asks which option provides the most appropriate overall answer.

Think: Which choice most completely addresses the requirement?

MOST likely

Asks which explanation or outcome is most probable.

PRIMARY

Asks for the main reason, responsibility, concern or objective.

Answer the question that was asked

Do not select an answer simply because it describes a good security practice.

9 Time Management You must reach the minimum number of questions

The CISSP exam has a maximum duration of three hours.

Because the exam can contain up to 150 items, candidates should avoid spending excessive time repeatedly reconsidering individual questions.

Important

Under ISC2's run-out-of-time rule, a candidate must answer at least the minimum examination length required for a valid pass/fail evaluation.

A practical approach

Read carefully

Identify exactly what the question is asking.

Eliminate clearly incorrect answers

Reduce the decision where possible.

Select the best remaining answer

Do not spend ten minutes waiting for certainty that may never come.

Move forward

Remember that you cannot return to the question later.

โ˜• Breaks You can take them, but the clock keeps running

ISC2 does not impose a specific limit on the number or duration of breaks during a CAT exam.

However:

Breaks count against your three-hour exam time.

Candidates must follow the test-centre process when leaving and re-entering the examination room.

๐ŸŒ Exam Languages CISSP CAT is available in multiple languages

CISSP is currently available in:

English Simplified Chinese German Japanese Spanish
All currently supported CISSP languages use CAT

Older material may state that only the English examination uses Computerized Adaptive Testing. That information is outdated.

Chinese-language CISSP examinations are currently available only during specified appointment windows, so candidates using that language should check current ISC2 availability.

10 Where is the CISSP Exam Taken? Authorised Pearson VUE testing centres

ISC2 CISSP examinations are delivered through authorised Pearson VUE testing centres.

The exam is therefore not simply an unproctored examination that you take from your personal computer at home.

Choose a suitable test centre when scheduling

Test-centre availability varies by location and date.

11 How to Book the CISSP Exam ISC2 account โ†’ purchase โ†’ Pearson VUE
๐Ÿ‘ค ISC2 Account โ†’ Create or sign in to your account
๐Ÿ›’ Purchase โ†’ Select and purchase the CISSP examination
๐Ÿ“š Courses & Exams โ†’ Select Schedule
๐Ÿชช Exam Information โ†’ Enter details exactly as shown on your ID
๐Ÿข Pearson VUE โ†’ Select test centre, date and time
Your name must match your identification

ISC2 warns that the information used for registration must match the ID presented at the test centre.

๐Ÿ’ณ Exam Cost Pricing varies by region

CISSP examination pricing varies by the location in which the exam is administered.

RegionStandard CISSP registration
United Kingdomยฃ606.69
EMEAโ‚ฌ719.04
United States / standard USD regionUS $749
Prices above were checked in August 2026

Exam pricing and taxes can change. Always check the current ISC2 pricing page before purchasing.

๐Ÿ“… Scheduling, Rescheduling & Cancellation Know the administrative rules before booking

ISC2 currently gives candidates up to 365 days from exam purchase to schedule and sit the examination.

Exams cannot be rescheduled once the appointment is within 24 hours.

ActionCurrent UK fee
Rescheduleยฃ35
Cancelยฃ70

Fees and policies can change, so verify current requirements directly with ISC2 and Pearson VUE.

12 Exam Day What to expect at the testing centre

ISC2 recommends arriving at the testing centre at least 30 minutes before your scheduled exam time.

You will normally need:

Primary ID Secondary ID Matching Registration Name

ISC2 currently requires two acceptable forms of identification for adult candidates:

Primary ID

Must meet ISC2 requirements and normally include a photograph and signature.

Secondary ID

Must meet ISC2 requirements and normally include a signature.

Testing-centre process may include

ID Check Photo Signature Security Screening Secure Storage Palm Vein Scan
Electronic devices are strictly controlled

Phones, recording devices and other electronic devices are prohibited under the ISC2 examination agreement and testing-centre security procedures.

๐Ÿ“œ Exam Agreement & NDA Protecting the confidentiality of the examination

Before beginning the exam, candidates must accept the ISC2 Non-Disclosure Agreement.

ISC2 currently gives candidates three minutes to review and accept it at the testing workstation.

Exam questions are confidential

Candidates must not record, reproduce, disclose or distribute actual CISSP examination content.

13 CISSP Experience Requirement Passing the exam and holding the certification are not exactly the same thing

To become fully CISSP certified, candidates must normally have:

Five years of cumulative full-time cybersecurity work experience across at least two of the eight CISSP domains.

ISC2 also recognises qualifying part-time work and internships under its experience rules.

Example

A candidate has experience in:

  • Security Operations;
  • Security Assessment and Testing;
  • Security and Risk Management.

Experience spanning those domains can contribute toward the CISSP requirement.

๐ŸŽ“ One-Year Experience Waiver Some education or certifications can reduce the requirement

Candidates may qualify to reduce the five-year requirement by up to one year.

This may be available through either:

Relevant Degree

A qualifying bachelor's or master's degree in computer science, information technology or a related field.

Approved Credential

A credential appearing on ISC2's current approved experience-waiver list.

Maximum waiver = one year

A degree and qualifying certification cannot be combined to remove two years from the experience requirement.

ISC2 updated its approved credential waiver list in April 2026, so candidates should check the current list rather than relying on an old study guide.

14 Can you take CISSP without five years of experience? Yes โ€” the Associate of ISC2 pathway exists

You do not need to wait until you have the full CISSP experience requirement before passing the examination.

A candidate who passes the CISSP examination but does not yet satisfy the experience requirement can become an Associate of ISC2.

๐Ÿ“ Pass CISSP Exam โ†’ Demonstrate examination knowledge
๐Ÿ‘ค Associate of ISC2 โ†’ Build required professional experience
๐Ÿ’ผ Experience โ†’ Meet the CISSP experience requirement
โœ… Certification โ†’ Complete certification requirements
Six-year window

ISC2 currently gives candidates using this pathway up to six years to accumulate the required experience.

15 What happens after you pass? Passing the exam starts the certification application process

Passing the examination is a major milestone, but candidates who meet the experience requirements must still complete the certification application and endorsement process.

๐ŸŽ‰ Pass Exam โ†’ Receive successful exam result
๐Ÿ“‹ Application โ†’ Describe relevant professional experience
๐Ÿค Endorsement โ†’ Have experience endorsed
โš–๏ธ Ethics โ†’ Commit to the ISC2 Code of Ethics
๐Ÿ’ณ AMF โ†’ Pay the applicable Annual Maintenance Fee
๐Ÿ† CISSP โ†’ Become certified after approval
๐Ÿค Endorsement Your professional experience must be verified

Candidates normally provide an endorser who is an ISC2-certified professional in good standing and can attest to the candidate's professional experience.

Don't know an ISC2 member?

ISC2 allows candidates to request endorsement by ISC2 instead. Supporting proof of employment is required for this route.

ISC2 currently requires the certification application process to be completed within nine months of the exam date.

Applications may be audited

ISC2 states that a percentage of certification applications are selected for audit and may require additional evidence to verify the experience claimed.

16 Maintaining CISSP after Certification The learning does not stop after the exam

CISSP is maintained through continuing professional education and the ISC2 Annual Maintenance Fee.

120 CPE Credits

CISSP holders currently need 120 Continuing Professional Education credits during each three-year certification cycle.

Annual Maintenance Fee

The current ISC2 certified-member AMF is US $135 per year.

One ISC2 member AMF

ISC2 certified members who hold multiple ISC2 certifications generally pay a single member AMF rather than a separate AMF for every certification.

17 What if you don't pass? Understand the current ISC2 retake policy

ISC2 currently applies increasing test-free periods between repeat examination attempts.

AttemptMinimum wait before another attempt
After first attempt30 test-free days
After second attempt60 test-free days
After third and subsequent attempts90 test-free days
Maximum attempts

A candidate may currently attempt an ISC2 certification exam a maximum of four times within a 12-month period for that certification programme.

Use the diagnostic report

A candidate who does not pass receives domain proficiency feedback.

Rather than simply repeating the same study plan, use this feedback to identify domains requiring additional attention.

โŒ Common CISSP Exam Myths Things candidates frequently misunderstand
"I need 70% of the questions correct."

The published passing standard is 700/1000, but CAT uses an adaptive ability estimate rather than simply calculating a raw percentage of correct answers.

"If my exam continues past 100 questions, I am failing."

Not necessarily. Additional questions mean the CAT system needs more information before making its decision.

"If my exam stops at 100, I definitely passed."

No. The CAT system can reach sufficient confidence for either a pass or a fail at the minimum examination length.

"I can flag difficult questions and come back later."

No. CISSP CAT does not permit review of previously finalised answers.

"I can identify the 25 unscored questions."

Candidates are not told which items are pretest questions.

"Every candidate receives the same questions."

CAT adapts item selection according to candidate performance while continuing to meet the CISSP exam-outline requirements.

"I need to pass every domain independently."

CISSP uses compensatory scoring across the examination.

"CISSP is primarily a hacking exam."

CISSP spans technical and managerial cybersecurity across eight broad domains.

"The most technical answer must be correct."

Many CISSP questions require consideration of governance, business objectives, risk, policy and appropriate authority before technical implementation.

"I need five years of experience before I am allowed to sit the exam."

Candidates without the full experience requirement may pass the exam and use the Associate of ISC2 pathway while gaining the required experience.

"Passing the exam means I can immediately claim full CISSP certification."

Full certification also requires satisfying the experience, application, endorsement, ethics and maintenance-fee requirements.

"Only English CISSP uses CAT."

This is outdated information. CISSP is now delivered using CAT in all currently supported exam languages.

CISSP Exam Technique

How to approach a difficult CISSP question

When two or three answers appear reasonable, slow down and identify the precise objective of the question.

1. Identify the role

Security Manager? Engineer? Auditor? Business Owner?

2. Find the clue word

FIRST BEST MOST PRIMARY

3. Identify the objective

Confidentiality? Integrity? Availability? Risk?

4. Check authority

Who decides? Who owns risk? Who approves?

5. Check sequence

Assess Plan Approve Implement

6. Choose the best answer

Business aligned Risk based Policy compliant Proportionate
Do not invent facts that are not in the question

Answer based on the scenario you have been given rather than adding assumptions that change the problem.

๐ŸŒ™ Final Exam-Day Checklist Knowledge is only useful if you actually get into the exam
โœ“ Confirm the test centre

Know where you are going and how long the journey takes.

โœ“ Check your booking name

Make sure it matches the identification you will present.

โœ“ Prepare two acceptable IDs

Check they meet current ISC2 requirements and have not expired.

โœ“ Arrive at least 30 minutes early

Allow time for the testing-centre check-in and security process.

โœ“ Remember CAT rules

Once you finalise an answer, you cannot return to it.

โœ“ Treat every question as scored

You cannot identify the 25 pretest items.

โœ“ Watch your time

The three-hour limit includes breaks.

โœ“ Ignore the question counter psychologically

Do not assume that reaching question 101 or 130 means you are failing.

โœ“ Keep answering the question in front of you

CAT has already moved on. You should too.

The complete CISSP journey

๐Ÿ“š Learn โ†’ Understand all eight CISSP domains
๐Ÿงช Practice โ†’ Apply knowledge to scenario-based questions
๐Ÿ“ Exam โ†’ Complete the CISSP CAT examination
๐ŸŽ‰ Pass โ†’ Receive the successful examination result
๐Ÿ’ผ Experience โ†’ Meet the professional experience requirement
๐Ÿค Endorsement โ†’ Complete certification application and verification
๐Ÿ† CISSP โ†’ Become an ISC2-certified professional
๐Ÿ”„ Maintain โ†’ Continue learning through CPE and certification maintenance

CISSP Exam memory aid

Format CAT
Time 3 HOURS
Items 100โ€“150
Pretest 25 UNSCORED
Passing Standard 700 / 1000
Review NO BACKTRACKING

Read. Decide. Commit. Move forward.

CAT mindset

Hard questions Are NORMAL
100 questions Can mean PASS or FAIL
More than 100 Does NOT mean you are failing
Previous question Is FINISHED
Current question Is the ONLY one that matters

Don't predict CAT. Answer the question.

Key takeaways

CISSP currently uses Computerized Adaptive Testing for all supported exam languages.

The exam lasts a maximum of three hours.

Candidates receive between 100 and 150 items.

The exam contains multiple-choice and advanced item types.

Twenty-five pretest items are included in the minimum-length examination and do not contribute to the score.

Candidates cannot identify which questions are pretest items, so every item should be treated seriously.

The published CISSP passing standard is 700 out of 1000.

Because CISSP uses CAT, 700/1000 should not be interpreted as simply needing 70% of questions correct.

Once you finalise an answer, you cannot return to the previous question.

CAT continually estimates candidate ability and chooses subsequent items based on previous responses.

The exam can finish once the minimum item count is reached and CAT has sufficient statistical confidence to determine the result.

Reaching more than 100 questions does not automatically mean you are failing.

Likewise, finishing at 100 questions does not by itself reveal whether the result is a pass or fail.

CISSP uses compensatory scoring, so candidates do not need to independently achieve above-proficiency performance in every domain.

All eight domains still matter.

Results are provided immediately after completing the CAT examination.

Candidates do not receive a numerical scaled score on the pass/fail report.

Failing candidates receive domain-level proficiency information to help guide further study.

Breaks are permitted, but break time counts against the three-hour exam limit.

Candidates should arrive at the testing centre at least 30 minutes before the examination and bring the required identification.

To become fully CISSP certified, candidates normally require five years of cumulative experience across at least two CISSP domains.

Up to one year of the experience requirement may be waived through qualifying education or an approved certification.

Candidates without sufficient experience may use the Associate of ISC2 pathway after passing the exam.

After passing and meeting the experience requirements, candidates must complete the certification application and endorsement process.

The certification application must currently be completed within nine months of the exam date.

CISSP certification is maintained through continuing professional education and the ISC2 Annual Maintenance Fee.

Most importantly: understand the concepts, understand the business context, read exactly what the question asks and make the best decision based on the information provided.

๐Ÿ“š Official Sources & Further Reading Current ISC2 examination information