Certification guide

CISSP

ISC2 CISSP: the honest guide

CISSP is the certification that says you can own security at the level of policy and risk, not the level of the firewall rule. It covers eight domains across the whole of an information security programme, and it is written for someone who decides what the control should be and why, rather than someone who types the command that implements it. It is an advanced credential, and it is gated by experience as much as by the exam.

The exam is computerized adaptive: 100 to 150 questions in 180 minutes, scored 700 out of 1000 to pass. The engine estimates your ability as you go and ends the exam early once it is statistically confident you are above or below the standard, so two people sitting it can answer very different numbers of questions. Behind the exam sits a requirement that catches people out: five years of paid security work before ISC2 will certify you.

The pattern every CISSP candidate hears about is real. The exam rewards the answer a manager would give: the one that addresses process, policy, risk, or human safety first, over the one that fixes the machine fastest. When two options are both technically correct, the business-aligned one usually wins, and learning to read questions that way is a large part of passing.

Who CISSP is for

A good fit if

  • You have roughly five years of security experience and want the credential hiring managers and job filters treat as the senior-security baseline.
  • You are moving from hands-on security into management, architecture, or governance, risk and compliance.
  • You need CISSP for a role or a contract, including DoD 8140 roles at the level where it is a hard requirement.
  • You already do the work of a security leader and need the paperwork to match what a recruiter can see.

Probably not, if

  • You are early in your career with well under five years of security experience. You can sit the exam and hold Associate of ISC2, but Security+ is the recommended earlier step and a better use of the time and money now.
  • You want a hands-on technical exam that tests you at a keyboard. CISSP is broad and management-oriented and never asks you to configure anything. A hands-on offensive or defensive certification fits that goal better.
  • You have no security background at all. This is not an entry-level certification. ISC2 CC or Security+ is where to start, and CISSP comes years later.

Is CISSP worth it?

For someone with the experience who is heading into security management or architecture, yes, clearly. CISSP is the most recognised senior security certification, it appears by name in a large share of security leadership job adverts, and it sits at the level of DoD 8140 roles that a whole category of government and defence work reserves for it. Few certifications move a mid-career security salary the way this one does.

For someone without the five years behind them, the honest answer is not yet. You can pass the exam and hold Associate of ISC2, but it does not certify you as a CISSP until you accrue the experience, and the annual maintenance fee starts regardless. Security+ now, then real domain experience, then this, is the cheaper and stronger path.

Weigh the cost of ownership, not just the sticker price. CISSP is a $749 exam followed by 120 continuing education credits over three years and an annual maintenance fee for as long as you hold it. That is worth paying when your role rewards the credential, and a slow drain when you earned it speculatively and moved on.

What the exam actually asks you to do

Multiple choice plus advanced innovative items: drag-and-drop and hotspot questions where you place items or click a point on a diagram.

Item formats

  • Multiple choice
  • Drag and drop
  • Hotspot

The highlighted formats are the ones you cannot answer from memory alone. ISC2, CISSP exam outline

Domain breakdown and official weightings

From the official ISC2 exam outlines. Security and Risk Management is the heaviest domain at 16 percent, followed by Security Architecture and Engineering at 13 percent.

  • Security and Risk Management16%
  • Asset Security10%
  • Security Architecture and Engineering13%
  • Communication and Network Security13%
  • Identity and Access Management (IAM)13%
  • Security Assessment and Testing12%
  • Security Operations13%
  • Software Development Security10%

ISC2: ISC2 exam outlines

Study plans by experience level

Experienced across most of the eight domains

10 to 12 weeksat 10 hours

  1. 1Weeks 1 to 2: read the exam outline against your own experience and mark every domain where your day job does not already cover the ground. For most working practitioners that is Software Development Security and the legal and regulatory parts of Security and Risk Management.
  2. 2Weeks 3 to 8: one domain at a time, heaviest first. Security and Risk Management is 16 percent and the single largest domain, so it earns the most time and the most of your management-thinking practice.
  3. 3Weeks 9 to 10: practise the question style rather than the facts. Work banks of scenario questions and, on every one, ask which answer a risk owner picks before you ask which is technically true.
  4. 4Weeks 11 to 12: full-length timed sets under adaptive conditions. Book the real exam when your bank scores are consistently well above the pass line, not on a date you picked in advance.

Deep in one area, thin in the softer domains

12 to 16 weeksat 8 to 10 hours

  1. 1Weeks 1 to 3: front-load the domains furthest from your specialism. A deep network engineer usually needs Asset Security, Software Development Security, and the governance half of Security and Risk Management the most.
  2. 2Weeks 4 to 9: work the remaining domains in weight order, keeping your strong area for last so you spend the least time where you already perform.
  3. 3Weeks 10 to 13: convert knowledge into CISSP-style judgement. The gap for a strong technician is rarely facts, it is choosing the business answer over the technical one, so drill that explicitly.
  4. 4Weeks 14 to 16: timed full-length practice, tracking accuracy by domain and spending each week on whichever domain the last set exposed.

Meet the experience, new to the CISSP style of question

16 to 20 weeksat 8 hours

  1. 1Weeks 1 to 4: read a full study guide end to end once, for coverage rather than mastery, so the shape of all eight domains is familiar before you go deep.
  2. 2Weeks 5 to 14: a domain a week or two, heaviest first, with practice questions after each rather than saved for the end. Security and Risk Management, then the three domains weighted at 13 percent, then the lighter ones.
  3. 3Weeks 15 to 18: question technique. This is the work that separates people who know the material from people who pass, and it is where the manager-mindset practice belongs.
  4. 4Weeks 19 to 20: full timed sets, and a deliberate rehearsal of pacing, because the adaptive format commits each answer as you go and gives you no way to flag and return.

Common mistakes

Answering every question as the technician you are
This is the mistake that fails prepared candidates. The exam wants the risk-based, business-aligned answer, so when two options are both technically correct the one addressing policy, process, or human safety first usually wins. Practise choosing that answer until it stops feeling wrong.
Studying for depth when the exam tests breadth
CISSP is a mile wide and an inch deep on purpose. Spending days on cryptography internals is time the legal, governance, and business continuity material never gets. Cover all eight domains to the depth the exam asks and no further.
Sitting it before the five years of experience
You can pass and hold Associate of ISC2, but you are not a CISSP until you accrue the experience, and the annual maintenance fee starts anyway. People who did not plan for that are surprised by both the status and the recurring bill.
Skimming Security and Risk Management because it reads dry
It is 16 percent of the exam, the largest domain, and the one where the management mindset is tested hardest. Risk, governance, law, and policy are where the business-answer pattern lives, so the dullest-looking domain carries the most marks.
Treating the adaptive format like a fixed paper
You cannot flag a question and come back to it. Each answer is committed before the next one is served, and the exam can end anywhere from 100 to 150 questions. Rehearse pacing and decision-making under those rules, not under the rules of an exam you can review at the end.

What comes after passing

Passing is not the last step. ISC2 verifies your five years of paid experience before it certifies you, and if you do not yet have it you hold Associate of ISC2 at a lower annual maintenance fee until you accrue the time and convert to full CISSP.

CISSP runs on a three-year cycle: 120 continuing professional education credits across the cycle, at least 40 each year, plus the annual maintenance fee every year. Log the credits as you earn them rather than scrambling in the final year, because the yearly floor makes a last-minute catch-up hard.

From here the direction is specialisation or seniority rather than another broad exam. ISC2 offers CISSP concentrations in architecture, engineering, and management for people who want to go deeper in one, but for many holders CISSP is the senior credential a security management or CISO-track career is built on, and the next move is the role rather than the next certificate.

Costs across the full renewal cycle are on the CISSP cost page.

Frequently asked questions

How much experience do I need for CISSP?

Five years of cumulative paid work in at least two of the eight domains, with one year waivable through a relevant degree or an approved certification. If you pass the exam without the experience, you become an Associate of ISC2 at a lower annual maintenance fee until you accrue it.

Is CISSP worth it in 2026?

For someone with the experience moving into security management or architecture, yes. It is the most recognised senior security certification, it is named directly in leadership job adverts, and it is a hard requirement for a category of DoD 8140 roles. For someone without the five years, Security+ first is the better spend.

How hard is CISSP?

It is hard in a specific way. The content is broad rather than deep, covering eight domains, and the difficulty is the volume plus the management mindset. When two answers are both technically correct, the exam wants the risk-based, business-aligned one, and learning to read questions that way is most of the challenge.

What score do I need to pass CISSP?

700 on a scale of 1000. The exam is computerized adaptive, so it serves between 100 and 150 questions over 180 minutes and ends early once it is statistically confident you are above or below that standard rather than running a fixed number of questions for everyone.

What does 'think like a manager' mean for CISSP?

It means the exam rewards the answer a risk owner would give over the answer an engineer would give. When two options both work technically, the one that addresses policy, process, or human safety first usually wins. Answering as the hands-on technician you may be is a common way to lose marks you did not need to.

Should I take Security+ before CISSP?

For most people, yes. Security+ is the recommended earlier step, it is far cheaper, and it builds the foundation CISSP assumes. CISSP is advanced and needs five years of experience to certify you, so Security+ now and CISSP once you have the background is the standard path rather than the exception.

Keep reading

Compared with

Side by side on cost, difficulty, and which one to take first.

Every guide and cost breakdown, by vendor

Practise CISSP for free while you decide

Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.

Start free CISSP questions