How to Pass the ISC2 CISSP in 2026: Format, Cost, Domains and Study Plan

Adaptive format, US$749 fee, all eight domain weights and an eight week study plan for the ISC2 CISSP, plus what to expect on the day.

What the CISSP is and who it is for

The CISSP from ISC2 is the most widely recognised cybersecurity credential in the world, with more than 190,000 CISSPs worldwide. It certifies broad expertise across eight domains of information security, from cryptography and network architecture through to governance, risk management and software security. It is the benchmark for security architects, CISOs and senior security management roles.

It is a management level exam, not a technical deep dive. Questions ask what a security professional should do for the organisation, and the best answer usually considers risk, business impact and policy rather than the cleverest technical fix.

Eligibility matters. You need five years of paid security experience across at least two of the eight domains. If you pass before you have that experience, you become an Associate of ISC2 and have up to six years to earn the remaining experience and claim the full credential.

ISC2 CISSP at a glance

Item Detail
Exam code CISSP
Questions 100 to 150, computerised adaptive testing
Time allowed 3 hours
Passing score 700 out of 1000
Exam fee US$749 per attempt
Where you sit it Pearson VUE testing centres only
Certification valid for 3 years

What is on the exam

Security and risk management (16%). The largest domain and the one that sets the tone for the whole exam. It covers governance, risk assessment and treatment, legal and regulatory issues, security policies, business continuity planning and professional ethics. Most of the “what should the security manager do first” questions come from here.

Asset security (10%). Classifying and handling information and the assets that hold it: ownership, data lifecycle, retention, privacy protections and the controls that follow data from creation to destruction.

Security architecture and engineering (13%). Secure design principles, security models, cryptography, physical security and the weaknesses in common system architectures. This is where the more technical material sits, but it is still tested at the level of choosing the right approach rather than configuring it.

Communication and network security (13%). Network architecture, secure protocols, network components and secure communication channels. You need to understand how networks are attacked and defended, not memorise port numbers.

Identity and access management (13%). Controlling who can access what: identification, authentication, authorisation, federation, access control models and the lifecycle of identities and accounts.

Security assessment and testing (12%). Designing and running assessments, audits, vulnerability testing and control testing, and interpreting the results so the organisation can act on them.

Security operations (13%). Investigations, logging and monitoring, incident management, disaster recovery, change management and the day to day running of security.

Software development security (10%). Security in the development lifecycle, secure coding practices, and how to assess the security of software you buy or build.

Why people fail it

The adaptive format is the first problem. The CISSP uses Computerized Adaptive Testing, so the exam adjusts to your performance as you go and ends anywhere between 100 and 150 questions. You cannot go back to a previous question, you cannot skip, and you never know where you stand until it is over. Candidates used to flagging and returning lose their rhythm, and the uncertainty wears people down over three hours.

The second problem is thinking like an engineer. The exam wants the answer a senior security professional would give: the one that manages risk for the business, follows policy and considers people and process. A technically correct answer that ignores those things is usually a distractor. That habit of mind takes exposure to many exam style questions to build.

The third is the cost of getting it wrong. At US$749 per attempt, and with a 30 day wait before you can try again, a failed attempt is far more than an expensive afternoon. That pressure pushes people to sit before they are ready, which is its own cause of failure.

A study plan that fits the exam

Eight weeks suits most working candidates. The weights are close to even, so the plan spends roughly a week on each domain with extra time for security and risk management. Before you start, take the free CISSP practice questions so you have a baseline and a feel for the phrasing.

  1. Week 1: security and risk management. Governance, risk, legal and continuity. Spend the full week here because its thinking underpins every other domain.
  2. Week 2: asset security and software development security. The two 10% domains together. Focus on data classification, lifecycle and the security activities in each development phase.
  3. Week 3: security architecture and engineering. Models, cryptography and secure design. Keep it at the level of choosing between approaches.
  4. Week 4: communication and network security. Architecture, protocols and secure channels, with an emphasis on why one design is safer than another.
  5. Week 5: identity and access management. Access control models, authentication, federation and identity lifecycle.
  6. Week 6: security assessment and testing, then security operations. Cover assessment first, then operations, which will feel familiar because it draws on everything earlier.
  7. Week 7: questions in volume. Work through the 484 questions in the CISSP practice pack with the explanations open, and for every wrong option read why it is wrong. That is where the management mindset gets built.
  8. Week 8: timed runs and weak spots. Use the questions only copy for long timed sessions of 150 questions, answering in order without going back, to mimic the adaptive format. Return to the domains where you still miss questions.

On exam day

You sit the CISSP at a Pearson VUE testing centre. ISC2 does not offer online proctoring for its exams, so there is no option to take it at home. Book early, because the three hour block plus check in takes most of a morning, and expect a strict identity check on arrival.

Pace for the full 150 questions in three hours, which is a little over a minute each, and do not slow down if the exam runs past 100 questions. It ending early or late tells you nothing reliable about the result. Because you cannot return to a question, commit to your best answer and let it go. Read every question as “what would the organisation’s senior security person do”, and if two options look right, prefer the one that manages risk or follows process over the one that fixes a technical detail.

Frequently asked questions

What happens if I fail the CISSP?

You pay the full US$749 again and you must wait 30 days before your next attempt. ISC2 also limits how many attempts you can make in a rolling period, so check the current retake policy on the ISC2 site before you rebook. Use the wait to work on the domains that felt weakest rather than restarting from the top.

Is the practice pack enough on its own?

No. The pack is 484 practice questions with full explanations, and its job is to make the question style and the management mindset familiar before test day. It is not a course. You still need a proper study source covering all eight domains. Use the pack to find gaps and to rehearse, not as your only reading.

Can I sit the CISSP without five years of experience?

Yes. If you pass without the required experience you become an Associate of ISC2, and you then have up to six years to accumulate the five years of paid experience across at least two domains and claim the full CISSP.

How long is the CISSP valid?

Three years. Check ISC2’s current maintenance requirements once you pass.

When you are ready to rehearse the real thing, the CISSP practice question pack is US$39, refunded if you fail.