DifficultyCISSP

How hard is CISSP?

What the format, the clock and the domain weights actually ask of you, framed by the experience you bring in. No invented pass rates anywhere on this page.

The short answer

ISC2 CISSP is an advanced exam. It is written for experienced practitioners, and the questions assume judgment built from real work, not memorized definitions. ISC2 classifies it at the advanced level, and the format is computerized adaptive testing (cat), multiple choice and advanced items, sat in 180 minutes.

Candidates with several years in the field find the difficulty is breadth across domains they have not personally worked in. Without that experience base, the exam is a long project, and the objectives list is the honest map of how long.

What actually makes it hard

  • Interactive items, not just multiple choice.

    Multiple choice plus advanced innovative items: drag-and-drop and hotspot questions where you place items or click a point on a diagram. These take longer than multiple-choice questions and punish rote memorization, because you have to do the task rather than recognize an answer.

  • Breadth across domains.

    The blueprint spans 8 domains, and the heaviest, Security and Risk Management, is 16% of the exam. You cannot skip a domain and rely on the rest; the weighting reaches everything.

  • The clock.

    100-150 (computerized adaptive) questions in 180 minutes leaves little room to dwell. Time pressure is a skill of its own, and it is the one thing reading can never prepare you for. Timed practice can.

Where the weight sits

Difficulty is not spread evenly. ISC2 publishes the domain weightings, and they tell you where your study time buys the most points:

  • Security and Risk Management16%
  • Security Architecture and Engineering13%
  • Communication and Network Security13%
  • Identity and Access Management (IAM)13%
  • Security Operations13%
  • Security Assessment and Testing12%
  • Asset Security10%
  • Software Development Security10%

Weightings from the official objectives. ISC2 exam page

What to hold first

ISC2 recommends coming to CISSP with Security+ level knowledge. That is a recommendation, not a gate; nothing stops you booking directly. It is honest guidance about the assumed baseline, and skipping it moves the missing material into your study plan rather than out of it.

How to find out where you stand

The fastest honest read on difficulty is not an opinion page, ours included. Answer real CISSP questions and see which domains push back. The first five questions of every practice exam here are free, each with the full explanation of why the right answer is right and the others are not.

The full CISSP study guideOfficial objectives ↗

Keep reading

Every guide and cost breakdown, by vendor

Practise CISSP for free while you decide

Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.

Start free CISSP questions