Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CISSP Passing Score

Updated 11 min read
Key takeaway

The CISSP passing standard is 700 out of 1,000 on a scaled score.

  • It is not a 70% raw-answer cutoff.
  • The CAT exam reports pass or fail without a numeric score; ISC2 describes three stopping rules that compare an ability estimate with the standard.
  • Domain results are diagnostic for candidates who do not pass.
On this page11 sections
  1. The published passing standard is 700 scaled
  2. Why raw percentages do not convert directly
  3. How ISC2 describes CAT pass and fail decisions
  4. What 100, 150, and the three hours do not tell you
  5. The score is compensatory across domains
  6. Interpret practice scores realistically
  7. Original scoring scenarios
  8. What to do with the official result
  9. How scaled scoring handles different forms
  10. Why the unscored questions matter to raw-score guesses
  11. Turn proficiency feedback into a review plan

The published passing standard is 700 scaled

ISC2's CISSP outline sets the passing grade at 700 out of 1,000 points. This is a scaled score. It describes the minimum proficiency standard after ISC2 converts exam performance to its reporting scale; it is not a count of correct items, a percent of the questions, or a percentage grade from a classroom test.

The number 700 therefore does not mean you need exactly 70% of the presented items right. Raw answers are not reported as a simple percentage for CISSP CAT, and 25 pretest items are unscored. The adaptive exam also selects items according to prior responses and item difficulty. There is no official raw cutoff that candidates can use to count how many they may miss.

ISC2 uses a common scaled score to keep the passing standard stable across examination forms that may contain different combinations of items. The official result for the CAT exam is pass or fail, not a numerical result such as 712 or 684. A scaled threshold can be published while an individual CAT report still withholds a numerical scaled score.

Question candidates askWhat ISC2 publishesWhat it does not establish
What score passes?700 on a 1,000-point scaled standardA 70% raw requirement
How many items count?At least 75 operational items and 25 pretest items at the minimum length; the exam may continue to 150 total itemsA fixed number of scored questions for every candidate
Do I get a numeric CAT score?A pass/fail result; failed candidates receive domain proficiency feedbackA scaled score report that reveals raw performance
Must each domain pass separately?One compensatory overall result across operational itemsA separate pass mark for all eight domains

Why raw percentages do not convert directly

A raw percentage is calculated as correct responses divided by the number of questions answered. A scaled score is a transformed reporting value. It can support comparison across forms while accounting for differences in the item combinations and their statistical characteristics. ISC2 describes scaling as a conversion of raw performance to a predefined range, much like expressing the same temperature in Fahrenheit or Celsius.

The comparison is useful for understanding why the numbers differ, but it does not disclose the CISSP conversion table. Candidate reports for CAT do not provide the raw count or numeric scale score. ISC2 does not publish a universal conversion such as “70% equals 700” or “you can miss 30 questions.” Those claims go beyond its published information.

Even if two candidates answered the same fraction of two different practice sets, that does not show that they had the same ability on the live exam. The sets may differ in quality, difficulty, domain coverage, and explanation. More importantly, a fixed practice set is not the CAT item pool or scoring system. Use practice results to locate knowledge gaps, not to reverse-engineer a concealed raw cutoff.

How ISC2 describes CAT pass and fail decisions

ISC2 publicly describes three possible rules in sequence. The first is the Confidence Interval Rule. After the minimum 100 total items, the exam can stop when the estimated ability excludes the passing point with 95% statistical confidence. If the estimate is above the passing standard, the result is a pass; if below, it is a fail. The minimum length includes 25 unscored pretest items.

If that rule has not ended the exam by the maximum length of 150 items, the Maximum-Length Exam Rule compares the final ability estimate with the passing standard. An estimate at or above the standard passes; an estimate below it fails. The maximum item count is not an invitation to work toward a separate raw-question quota.

If the time limit is reached before another rule decides the result, the published Run-Out-of-Time rule evaluates the ability estimate. A candidate must have answered at least 75 operational items and 25 pretest items within the maximum time to receive a result; failing to answer that minimum automatically results in failure. Candidates cannot identify the pretest items, so they should answer every presented item.

These descriptions explain the decision framework at a high level. They do not reveal an individual candidate's current ability estimate, the difficulty parameter of each live item, or a raw point-by-point score. There is no reliable way to infer the result from watching whether the exam stops at 100, continues to 150, or uses most of the clock.

What 100, 150, and the three hours do not tell you

The CISSP CAT exam begins with a minimum of 100 items and can continue to 150, with a maximum time of three hours. Since 25 are pretest items, the minimum-length test includes 75 operational items. But a candidate's length does not directly disclose how many were correct or whether the candidate met the passing standard.

An exam that stops after 100 items may have reached a confident pass decision or a confident fail decision. An exam that continues past 100 may need more information to determine whether the estimate is above or below the standard. An exam that reaches 150 has reached its maximum and is evaluated under the maximum-length rule if the confidence rule did not decide earlier. In each case, only the result communicates the outcome.

The same caution applies to time. Finishing quickly is not evidence that the exam was easy or that you passed. Using most of the available time is not evidence that you failed. Items remain challenging because CAT selects items to measure your estimated ability. Candidates should focus on sound decisions and sufficient pacing rather than interpreting the clock as a hidden score report.

The score is compensatory across domains

ISC2 describes the CISSP CAT as a compensatory exam. The result is calculated from the overall performance on operational items; a candidate does not need to reach above proficiency in every domain separately. Stronger performance in one area can offset weaker performance in another, but no specific combination guarantees a pass.

This does not make the domain weights optional. The outline assigns different shares of scored content to the eight domains, with Security and Risk Management the largest at 16%. Weighting affects the mix of content, while the final outcome remains one overall result. A low practice score in a domain is a useful reason to review it, even though ISC2 does not impose a separate domain passing score.

Candidates who fail receive proficiency levels by domain as diagnostic feedback. ISC2 uses labels such as below proficiency, near proficiency, and above proficiency. These descriptions help identify where additional study may be useful. They are not percentages, exact counts of missed items, or a complete transcript of every item response. Candidates who pass do not receive these domain proficiency levels.

Interpret practice scores realistically

Suppose a practice site reports 68% on a 100-question set and labels it a predicted CISSP pass. That percentage describes performance on that provider's selected questions under its own scoring method. It cannot be converted to a live CISSP scaled score without a validated conversion method that accounts for the item's properties and official scoring model. ISC2 does not publish such a candidate-facing conversion.

Use the result to ask better questions. Did the misses cluster around IAM, risk treatment, software development, or network controls? Did you know the concept but miss a role or timing cue? Did you select an answer that was technically valid but outside the authority given in the scenario? The useful output is a concrete review plan, not a prediction of the CAT's score.

Track performance across unfamiliar, well-explained items from different sources and revisit errors after a delay. If the same weakness reappears, learn the underlying distinction and solve another scenario. If practice questions are repeatedly familiar, they may overstate readiness. A fixed mock exam can still help with attention and pacing, but it should not be marketed as the official adaptive exam or a guaranteed score estimate.

Original scoring scenarios

A 70% practice result

Mina answers 70 out of 100 questions correctly on a commercial practice set and asks whether that guarantees a CISSP pass. It does not. The set's raw percentage is not the CAT score, and it may not match the official item pool, difficulty, or adaptive selection. Mina should examine which concepts she missed and whether her reasoning transfers to fresh questions.

An exam ends at 100 items

Omar receives a pass/fail result after the minimum 100 items and wants to infer the outcome because the exam did not continue. The length alone is inconclusive: the published Confidence Interval Rule can end a CAT after the minimum when the ability estimate is confidently above or below the standard. Omar must use the official result, not the stopping point.

One weak domain

Leah's failed result lists one domain below proficiency and others near or above. She should treat that report as diagnostic and use the outline to plan review. It does not prove that she missed a specific number of items in the low domain. Because the result is compensatory, the report shows areas to strengthen rather than separate domain pass/fail outcomes.

What to do with the official result

After the exam, use the pass/fail result and official next-step instructions. If you pass, you still need the experience and application process to earn the certification. If you do not pass, use the domain proficiency feedback where provided, observe the retake waiting period, and prepare for the next attempt. Neither path is clarified by reconstructing a raw percentage that ISC2 does not report.

How scaled scoring handles different forms

ISC2 maintains a large item pool and uses multiple forms. Its scoring information explains that item performance is statistically reviewed and forms are constructed to minimize difficulty differences. Equating adjusts for slight variations among the combinations of items so that the same passing standard can be applied across forms. Candidates are not ranked against one another; the exam decides whether each person meets the competency standard.

This is why one candidate's remembered question set cannot establish a raw cutoff for another candidate. Even if two people receive different items, the forms are designed to measure the same outline against the same passing standard. A candidate who focuses on rumor about an easier or harder version is trying to control a feature that the scoring process is designed to account for.

The score report for the adaptive CISSP remains pass or fail. The public explanation of scaled scores clarifies the general measurement model, but does not provide the live CAT's item-level difficulty values, raw response record, or ability estimate for an individual. Do not turn the published 700 standard into an invented conversion chart.

Why the unscored questions matter to raw-score guesses

Each CISSP CAT exam includes 25 pretest items. These are used to evaluate possible future exam items and do not count in the candidate's result. They are mixed with operational items, and candidates cannot identify them. At the minimum 100-item exam, at least 75 items are operational and 25 are pretest; the exam can continue with more items up to 150 total.

A practice set that reports a simple percentage usually treats every item in that set as scored. The live CAT does not present a candidate-facing raw tally in the same way. Even knowing the number of operational items shown would not tell you how many were correct or how ISC2's estimate compared with the passing standard. This makes calculations like “I got 70 of the 100 so I must have passed” unsound.

Use the exam count as a format fact only. The score is determined by the published adaptive rules, and the candidate receives the official outcome. If the result is a fail, domain proficiency feedback is more useful for planning than trying to estimate an unseen raw score.

Turn proficiency feedback into a review plan

If you fail, the domain feedback shows relative proficiency levels, not a list of wrong answers. Start by comparing the lowest domains with the current outline tasks. For each task, identify whether the gap was factual knowledge, a confused distinction, or scenario judgment. A low result in IAM might call for reviewing identity life cycle and authorization; a low result in Security Operations might call for revisiting incident sequence and evidence handling.

Then practice with fresh questions that include explanations. For every miss, write the decision cue and explain why the best alternative is wrong. Review the topic again after a delay. Keep strong domains in rotation so that focused repair does not cause avoidable forgetting elsewhere.

Do not assume that one below-proficiency domain means the next attempt will fail, or that all domains near proficiency add up to a specific score. The exam is compensatory, but the total result depends on operational items and the adaptive estimate. The feedback is a guide to study, not a promise about a future result.

Common questions

What score do I need to pass CISSP?

The published passing standard is 700 on a 1,000-point scaled score. CAT candidates receive a pass/fail report without a numeric score.

Is 700 equal to 70 percent correct?

No. A scaled score is not a raw percentage, and ISC2 does not publish a universal raw-answer cutoff for the CAT exam.

Can I find out how many CISSP questions I got right?

No. The CAT report gives pass or fail. Candidates who fail receive domain-level proficiency feedback, not a raw score.

Do I have to pass every CISSP domain?

No. ISC2 describes the exam as compensatory and calculates one overall result across operational items.

Does stopping at 100 items mean I passed?

No. The exam can stop at the minimum after the ability estimate is confidently above or below the passing standard.

How many questions can I miss?

ISC2 does not publish a fixed number. Item count varies, 25 items are unscored, and CAT decisions use an ability estimate rather than a candidate-facing raw count.