CISSP Master Guide 2026
The CISSP is an international security certification for experienced practitioners and leaders.
- Its current English exam uses computerized adaptive testing, lasts up to three hours, and presents 100 to 150 items.
- A scaled score of 700 out of 1,000 passes.
- Passing the test alone does not award the credential: experience, endorsement, and application requirements also apply.
On this page18 sections
- What CISSP validates
- Who can sit and who can become certified
- Exam format and passing score
- The current eight domains
- A useful study method
- Original sample question
- How computerized adaptive testing changes the experience
- The eight domains in practice
- Registration, fees, and appointment details
- Results and retakes
- From a pass to the credential
- Renewal and limits of the certification
- A practical eight-week study sequence
- A fully worked original sample question
- Reason across domains instead of memorizing silos
- Choose study materials with a clear purpose
- Second original scenario: evaluating a provider
- When to schedule your attempt
What CISSP validates
The Certified Information Systems Security Professional credential is issued by ISC2. It tests broad judgment across security governance, risk, asset protection, architecture, networks, identity, assessment, operations, and software development. The exam is designed for professionals who can connect technical controls to organizational goals, legal duties, and risk decisions.
That breadth distinguishes CISSP from a narrow product certification. A question may describe a technical weakness, but the best answer can depend on business impact, policy, evidence, or the order in which a security professional should act. Candidates benefit from understanding how domains interact instead of studying each as an isolated vocabulary list.
Who can sit and who can become certified
You may schedule the exam before meeting the experience requirement. To receive the full CISSP credential, ISC2 requires five years of cumulative, paid, full-time work experience in at least two of the eight domains. A qualifying four-year degree or an approved credential can waive up to one year, leaving at least four years required. The qualifying pathways and acceptable experience are defined by ISC2.
If you pass before qualifying, you can apply for Associate of ISC2 status. The associate route records that you passed the examination while you work toward the experience needed for CISSP. It is not the CISSP credential and should be represented accurately on a resume. You must meet the experience requirement and complete the endorsement and application process within ISC2's stated period.
Exam format and passing score
The English CISSP exam uses computerized adaptive testing. It runs for up to three hours and contains between 100 and 150 items. ISC2 reports a passing grade of 700 on a 1,000 point scale. That score is scaled, not a raw percentage; do not interpret 700 as requiring exactly 70 percent of items correct.
The item count can vary because the test adapts as you answer. A static practice set cannot reproduce the adaptive algorithm or predict how many items you will see. Practice can still build knowledge, careful reading, and decision quality, but a fixed mock score is not an estimate of an official CAT result.
| Domain | Weight |
|---|---|
| Security and Risk Management | 16% |
| Asset Security | 10% |
| Security Architecture and Engineering | 13% |
| Communication and Network Security | 13% |
| Identity and Access Management | 13% |
| Security Assessment and Testing | 12% |
| Security Operations | 13% |
| Software Development Security | 10% |
The current eight domains
The current outline became effective April 15, 2024. Use the weights to allocate review, not to turn the outline into a question-count promise. The exam may assess a concept through a scenario that crosses domains. The official outline is the scope authority; provider topic lists are useful only when they map back to that outline.
A useful study method
Begin by tagging every outline task as strong, uncertain, or unfamiliar. For each weak task, learn the decision principle and then solve a fresh scenario without notes. Record not only a missed answer but why the attractive alternative fails. CISSP questions often distinguish a technically possible action from the most appropriate next action under the stated role, policy, or risk.
Build a weekly cycle around retrieval. Review a small group of concepts, explain them aloud in plain language, answer scenario questions, and revisit errors after a delay. Maintain a one page list of recurring distinctions: policy versus procedure, threat versus vulnerability, preventive versus detective control, identification versus authentication, and recovery versus continuity. Add distinctions only when your errors show they matter.
Original sample question
A company discovers that a business unit copied regulated customer data to an unapproved cloud service. No evidence of public access has been found. What should the security manager do first?
Answer: follow the organization's incident and data handling policies to establish facts, preserve relevant evidence, and coordinate with the accountable owners. Do not immediately wipe the account or announce a breach before determining exposure and reporting obligations. The point is to contain risk while preserving evidence and following the defined authority path. The exact action depends on the organization's incident plan and applicable requirements.
How computerized adaptive testing changes the experience
CAT estimates your ability as you answer. The exam selects later items using information from earlier responses and the difficulty level it is measuring. Your next item can therefore depend on your previous answers. A fixed-length mock may help you review knowledge and pacing, but it cannot reproduce the selection algorithm, secured live bank, or official scoring model.
Plan for up to three hours and do not use the difficulty of a final item as a pass signal. A difficult question does not prove you are failing; an adaptive exam is designed to keep measuring the edge of your current ability. Unscored items are not marked, so answer each one with the same care.
Read the scenario for the decision the question asks you to make. Identify the role, goal, constraint, and stage of the process. Eliminate choices that skip policy, ignore risk ownership, or jump to a technical fix before facts are known. This is a practical way to handle plausible distractors that name a valid control but apply it at the wrong time.
The eight domains in practice
Security and Risk Management (16%) includes governance, ethics, legal and regulatory duties, risk management, business continuity, and awareness. It is the largest domain. Study how an organization sets direction, identifies risk, assigns ownership, and checks whether controls support its objectives. A security leader's decision must fit the risk appetite and authority structure.
Asset Security (10%) covers classification, handling, retention, protection, and disposal. Distinguish the sensitivity and value of the information from the system where it is stored. Ownership, classification, and retention shape controls throughout the data life cycle.
Security Architecture and Engineering (13%) asks how security principles apply to systems. Learn trust boundaries, secure design, cryptographic concepts, resilience, and the properties of hardware and software. The test expects a reasoned control choice, not a list of product names.
Communication and Network Security (13%) focuses on network architecture, protocols, secure communication, and segmentation. Trace data across trust boundaries and ask what the control is meant to do. Firewalls, encryption, authentication, and monitoring solve different problems.
Identity and Access Management (13%) covers identity proofing, authentication, authorization, federation, account life cycle, and access review. Authentication establishes identity; authorization governs permitted actions. Role changes and departures should trigger an accountable access process.
Security Assessment and Testing (12%) concerns control validation, audits, testing, and metrics. A vulnerability scan identifies known weaknesses; a penetration test attempts exploitation within authorization; an audit evaluates evidence against criteria. Scope and follow-up ownership matter.
Security Operations (13%) includes incident response, investigation, logging, recovery, and operational controls. Preserve evidence and follow the response plan. Recovery objectives and backups are useful only when tied to business impact and tested.
Software Development Security (10%) covers security through requirements, design, testing, deployment, and maintenance. Integrating security early can reduce rework. Understand how threat modeling, code review, testing, and change control support one another.
Registration, fees, and appointment details
Start registration from your ISC2 account and follow the link to Pearson VUE. The live scheduler controls available appointments, location, and language. ISC2 lists English, Chinese, German, Japanese, and Spanish exam availability; delivery windows can differ by language and market. Confirm the exact exam and appointment conditions in the scheduler.
ISC2 currently lists the United States CISSP exam fee as US$749. Regional prices, currency, tax, and terms may differ, so confirm the checkout amount before paying. Registration pays for an attempt. Books, training, travel, and accommodation are separate costs. Verify voucher region, expiration, transferability, and refund terms before purchasing through another seller.
Before test day, reread ISC2's instructions for identification, check-in, prohibited items, breaks, and accommodation requests. Keep the appointment confirmation, check your time zone and name spelling, and plan for travel. Cancellation and rescheduling rights depend on the terms shown for your booking.
Results and retakes
ISC2 reports CAT results after the exam. The report provides pass or fail rather than a numeric scaled score. Candidates who fail after answering the required minimum number of items receive domain-level diagnostic feedback. Use it to prioritize further study, not as a complete map of every missed concept.
The retake policy sets test-free periods of 30 days after the first attempt, 60 days after the second, and 90 days after the third and later attempts. You may take a particular ISC2 certification exam at most four times within 12 months. A new fee normally applies unless your purchase includes a specific retake benefit.
A pass establishes that you met the exam standard. It does not itself award the CISSP designation or prove that your experience application has been accepted. Complete the certification or associate application promptly.
From a pass to the credential
ISC2 requires an application within nine months of the exam pass. If you meet the experience requirement, submit the endorsement application, describe relevant work, and obtain an eligible endorser. An ISC2 professional in good standing can endorse your experience. If you do not know an endorser, ISC2 can perform the review and may request proof of employment. Keep records because applications may be selected for audit.
If you pass but lack the required experience, apply for Associate of ISC2 status within the application window. The associate designation is not the CISSP credential. CISSP associates have up to six years to complete the experience requirement and submit the certification application. Associate status has its own annual fee and CPE requirement.
Renewal and limits of the certification
CISSP members maintain the credential with 120 CPE credits over each three-year cycle: 90 Group A credits tied to the credential and 30 Group A or B credits. The current annual maintenance fee is US$135 for members holding CISSP, regardless of the number of ISC2 certifications; Associates pay US$50. Taxes may apply. Check the active member policies for deadlines and grace periods.
Record activity and credits as you earn them. If a fee or CPE requirement is missed, the status can be suspended. A grace period exists, but it is not a reason to defer reporting until the end of the cycle. Do not present yourself as currently certified while suspended.
CISSP is an international professional certification, not a government license. It can demonstrate broad security knowledge, but it does not guarantee a job, promotion, salary, or authority to perform regulated work. Employers set their own experience and role requirements.
A practical eight-week study sequence
Week 1: read the outline and take a diagnostic across all eight domains. Treat the score as a map, not a pass prediction. Tag tasks as strong, uncertain, or unfamiliar. For every miss, write the specific distinction you failed to apply.
Weeks 2 to 5: rotate across the domains, giving more time to weak areas and high-weight domains while revisiting stronger areas briefly. Each study block should combine recall from memory, focused reference reading, and scenario questions with explanations. Avoid spending every session watching lessons or rereading highlights.
Week 6: mix questions from different domains. Explain why the best answer fits the objective and why the closest distractor fails. This helps when a question does not announce its topic.
Week 7: revisit every outline task and repair major gaps. Practice sustained attention under a time limit, but do not treat a fixed mock score as the CAT result. Review the official appointment instructions.
Week 8: focus on retrieval and repeated errors rather than cramming new sources. Revisit confused concepts, sleep adequately, and prepare identification and travel. If core gaps remain, consider moving the appointment instead of sitting simply because it is booked.
A fully worked original sample question
A hospital security team detects that a nurse's account downloaded an unusually large number of patient records. The nurse denies the activity. Logs show a valid session token, and the account remains active. What is the best immediate response?
Choose one: A. Delete the downloaded records and close the incident because the account was authenticated. B. Follow the incident plan, preserve relevant logs and evidence, and contain the account or session through the authorized process while investigating. C. Notify every patient immediately before determining the scope. D. Disable all hospital identity services until the investigation ends.
Answer: B. There is a credible incident indicator. The organization should contain potential access while preserving evidence and following its incident plan. A valid token does not establish that the nurse initiated the activity; the token may be compromised. Preserve authentication and system logs, coordinate with incident leadership and data owners, then revoke or contain the session through authorized procedures.
A confuses authentication with attribution and destroys evidence. C may ultimately be required, but notification depends on established facts, legal duties, and the responsible organization's process; broad notice before scoping can be premature. D is disproportionate and risks clinical operations. The best response controls the incident and preserves the evidence needed for sound decisions.
Reason across domains instead of memorizing silos
A vendor-hosted application holding customer data can raise several CISSP domains at once. Asset Security establishes classification and handling. Security and Risk Management frames impact and accountability. Architecture and IAM address trust boundaries and access. Assessment and Testing helps evaluate the provider's controls. Which idea matters most depends on the question: a contract decision, an access change, incident response, or assurance review.
A departing employee is an IAM case, but also involves HR, asset recovery, logs, and possibly evidence preservation. If the question asks what to do first, identify the stage and authority. Do not start forensic collection while an active account presents an immediate threat if policy permits scoped containment. Avoid disabling an entire service when a narrower authorized action controls the risk.
Risk acceptance belongs with the accountable business owner under governance. Security can explain exposure, assess options, recommend treatment, and verify controls, but should not silently accept business risk for an owner. This principle crosses governance, architecture, operations, and audit scenarios.
Choose study materials with a clear purpose
The official outline is the study plan's anchor because it names the tested tasks. Map each book, course, or question set to current tasks and note whether it teaches concepts, offers practice, or explains strategy. A detailed resource can still leave a gap if it follows an earlier outline or gives little attention to a weak domain.
Use a reference to build understanding, then close it and retrieve the idea from memory. Use practice items to find misunderstandings, not as a replacement for learning. For each question, demand an explanation of the right answer and the plausible alternatives. A list of correct letters trains recognition more than judgment.
ISC2 materials explain its scope and policies; independent resources can offer other teaching styles. Verify their coverage against the active outline. Since CAT adapts item selection, a fixed practice set cannot promise the number or difficulty of live questions. Avoid claims that a question bank reproduces protected live items or guarantees a pass.
Second original scenario: evaluating a provider
A company plans to move a sensitive customer support system to a cloud provider. The provider shares an independent security assessment, but the business owner has not documented the data classification or recovery needs. What should the security professional recommend before approval?
Choose one: A. Accept the assessment as proof that the company's use complies with every requirement. B. Classify the information, document business and regulatory needs, then evaluate provider controls and contract responsibilities against them. C. Reject cloud services because a third party cannot protect sensitive data. D. Ask the provider to take responsibility for all customer access and data handling.
Answer: B. Provider assurance is useful evidence, but it does not define the customer's use, access decisions, data handling, or legal duties. Establish requirements, assess whether controls and contract commitments meet them, and identify responsibilities the customer retains. A overstates the assessment's scope. C makes a blanket decision without risk analysis. D ignores customer control over its identities and data.
This scenario joins governance, asset classification, architecture, and assurance. The sequence matters: without knowing what information is involved and which business outcomes matter, a team cannot judge whether a provider's control report is sufficient.
When to schedule your attempt
Choose a date after you have mapped the outline, worked through weak tasks, and practiced explaining decisions across domains. Readiness is not one practice percentage: provider sets differ and the live exam is adaptive. Stronger signs include repeated performance on unfamiliar scenarios, clear reasoning for rejecting distractors, and the ability to explain a concept without relying on a memorized phrase.
Treat the appointment as a planning boundary, not proof of readiness. If core tasks remain unfamiliar or you are guessing between controls, identify the gaps and adjust your plan. Candidates with deep experience may need less time in familiar areas, but still need to learn the current outline and how it frames security decisions.
On exam day, follow the provider's check-in and identification rules. Keep attention on the item in front of you instead of inferring whether it is experimental or trying to estimate an adaptive score from its apparent difficulty. Afterward, use the official result and application instructions for the next step.
Common questions
How many items does the CISSP CAT exam have?
It presents between 100 and 150 items and lasts up to three hours.
What is the CISSP passing score?
The passing standard is 700 out of 1,000 on a scaled score. The CAT pass or fail report does not provide a numeric score.
Can I take the exam before five years of experience?
Yes. If you pass without enough experience, apply for Associate of ISC2 status within nine months; you then have up to six years to complete the experience requirement.
How much does the CISSP exam cost?
ISC2 currently lists the United States fee as US$749. Regional prices and taxes may differ, so confirm the checkout amount.
How do I maintain CISSP?
Complete 120 CPE credits in a three-year cycle, including 90 Group A credits and 30 Group A or B credits, and pay the annual maintenance fee.
How soon can I retake after failing?
The waiting period is 30 days after attempt one, 60 days after attempt two, and 90 days after attempt three and later attempts. The maximum is four attempts in 12 months.