ISC2 · cybersecurity

CISSP exam preparation

Practice for the Certified Information Systems Security Professional (CISSP) exam with adaptive questions, full-length mock exams, and a readiness score that tells you when you're actually ready to pass.

Before you register: You can sit the CISSP before you have the experience — but you become an Associate of ISC2, not a CISSP.

Certification requires five years of cumulative, paid work experience in at least two of the eight domains. A relevant four-year degree or an approved credential can satisfy one of those five years. If you pass the exam without the experience you become an Associate of ISC2 and have six years to earn it. Passing is also not the final step: another ISC2-certified professional must endorse your application within nine months, ISC2 may audit it, and you must agree to the ISC2 Code of Ethics and pay an annual maintenance fee while earning continuing professional education credits. Confirm the current rules with ISC2 before you plan around them.

CISSP exam at a glance

Issuer
ISC2
Questions
100–150 items (Computerized Adaptive Testing)
Duration
3 hours
Scoring
Scaled score 0–1000
Pass mark
700 to pass
Format
CAT — adaptive multiple choice plus advanced items

CISSP exam domains

The CISSP exam covers 8 domains, with the approximate weighting shown below:

What each CISSP domain covers

Security and Risk Management. The governance spine of the exam: risk concepts, security governance, legal and regulatory obligations, professional ethics, and business continuity planning. The largest domain, and the one whose mindset the other seven are graded against.

Asset Security. Classifying information and assets, ownership and handling requirements, data retention, and the controls that follow from a classification decision rather than preceding it.

Security Architecture and Engineering. Secure design principles, security models, cryptography, and the physical and environmental controls that protect facilities. The most technically demanding domain for candidates from a policy background.

Communication and Network Security. Secure network architecture, protocols and their weaknesses, and securing the components that move data between systems.

Identity and Access Management (IAM). Identification, authentication and authorisation, the identity lifecycle from provisioning through de-provisioning, and federated and third-party identity services.

Security Assessment and Testing. Designing assessment strategies, running and interpreting tests, collecting security process data, and reporting to an audience that has to act on it.

Security Operations. Running security day to day: investigations, logging and monitoring, incident management, recovery, and the operational discipline that keeps controls working after the project ends.

Software Development Security. Security across the development lifecycle, assessing the effectiveness of software security, and the risks introduced by acquired and third-party code.

CISSP exam facts

How CertPrepX helps you pass the CISSP

Who the CISSP is for

Experienced security practitioners, managers, and executives — security analysts, architects, engineers, and CISOs pursuing the ISC2 flagship credential.

Start preparing for the CISSP — free

Create a free account and start practicing today. Go Premium ($99/year) for full mock exams, analytics, and a Pass Guarantee.

Start free practice

CISSP exam FAQ

How is the CISSP exam scored?

The English CISSP is a Computerized Adaptive Test (CAT) of 100–150 items in 3 hours, scored 0–1000 with a passing score of 700. Items are weighted by difficulty, so 700 is not 70% of the questions.

How many domains does the CISSP cover?

The CISSP Common Body of Knowledge has eight domains, from Security and Risk Management to Software Development Security.

What is CAT on the CISSP?

Computerized Adaptive Testing adjusts item difficulty to your performance and stops as soon as it is statistically confident you are above or below the standard. On the current outline that can happen anywhere between 100 and 150 items — an exam that ends early is not automatically a pass or a fail.

Do I need five years of experience to sit the exam?

No. You can sit it at any time. Without the five years of paid work experience across at least two of the eight domains you become an Associate of ISC2 and have six years to earn it. A relevant degree or approved credential can cover one of the five years.

Is old CISSP study material still accurate?

Check the format it describes. The current outline took effect on 15 April 2024 and runs 100–150 items in 3 hours. Material describing a 125–175 item, four-hour exam predates that change.

Can CertPrepX mock exams mirror the CISSP CAT?

CertPrepX builds full-length, domain-weighted mock exams and a readiness score across all eight CISSP domains so you can train under realistic conditions.

Sources

Exam details on this page come from ISC2’s own published materials and were last verified on 24 August 2026. ISC2 can change exam policy at any time, so confirm current requirements with ISC2 before you register.

Related reading

Other certifications