CISSP exam preparation
Practice for the Certified Information Systems Security Professional (CISSP) exam with adaptive questions, full-length mock exams, and a readiness score that tells you when you're actually ready to pass.
Before you register: You can sit the CISSP before you have the experience — but you become an Associate of ISC2, not a CISSP.
Certification requires five years of cumulative, paid work experience in at least two of the eight domains. A relevant four-year degree or an approved credential can satisfy one of those five years. If you pass the exam without the experience you become an Associate of ISC2 and have six years to earn it. Passing is also not the final step: another ISC2-certified professional must endorse your application within nine months, ISC2 may audit it, and you must agree to the ISC2 Code of Ethics and pay an annual maintenance fee while earning continuing professional education credits. Confirm the current rules with ISC2 before you plan around them.
CISSP exam at a glance
CISSP exam domains
The CISSP exam covers 8 domains, with the approximate weighting shown below:
- Security and Risk Management16%
- Asset Security10%
- Security Architecture and Engineering13%
- Communication and Network Security13%
- Identity and Access Management (IAM)13%
- Security Assessment and Testing12%
- Security Operations13%
- Software Development Security10%
What each CISSP domain covers
Security and Risk Management. The governance spine of the exam: risk concepts, security governance, legal and regulatory obligations, professional ethics, and business continuity planning. The largest domain, and the one whose mindset the other seven are graded against.
Asset Security. Classifying information and assets, ownership and handling requirements, data retention, and the controls that follow from a classification decision rather than preceding it.
Security Architecture and Engineering. Secure design principles, security models, cryptography, and the physical and environmental controls that protect facilities. The most technically demanding domain for candidates from a policy background.
Communication and Network Security. Secure network architecture, protocols and their weaknesses, and securing the components that move data between systems.
Identity and Access Management (IAM). Identification, authentication and authorisation, the identity lifecycle from provisioning through de-provisioning, and federated and third-party identity services.
Security Assessment and Testing. Designing assessment strategies, running and interpreting tests, collecting security process data, and reporting to an audience that has to act on it.
Security Operations. Running security day to day: investigations, logging and monitoring, incident management, recovery, and the operational discipline that keeps controls working after the project ends.
Software Development Security. Security across the development lifecycle, assessing the effectiveness of software security, and the risks introduced by acquired and third-party code.
CISSP exam facts
- Format: Computerized Adaptive Testing (CAT) for the English exam. Difficulty adjusts to your performance, so no two candidates sit the same paper.
- Items: 100 to 150, including multiple-choice and advanced item types.
- Duration: 3 hours.
- Scoring: Scaled 0 to 1000. Items are weighted by difficulty, so a raw percentage of items answered correctly does not map to your scaled score.
- Passing score: 700 out of 1000.
- Why it can end early: The exam stops once the engine is statistically confident you are above or below the standard — which can happen at the minimum item count. Finishing early is not in itself good or bad news.
- Content outline: The current exam outline took effect on 15 April 2024. It replaced a longer 125–175 item, four-hour format, so older prep material describes an exam that no longer exists.
- After passing: Endorsement by an ISC2-certified professional is required within nine months.
How CertPrepX helps you pass the CISSP
- Adaptive practice that focuses on your weakest CISSP domains.
- Full-length, timed mock exams that mirror the real CISSP format and scoring.
- A readiness score per domain, so you know when you're ready to sit the exam.
- Weak-area review and spaced repetition to lock in what you miss.
- A personalized study plan built around your target CISSP exam date.
Who the CISSP is for
Experienced security practitioners, managers, and executives — security analysts, architects, engineers, and CISOs pursuing the ISC2 flagship credential.
Start preparing for the CISSP — free
Create a free account and start practicing today. Go Premium ($99/year) for full mock exams, analytics, and a Pass Guarantee.
Start free practiceCISSP exam FAQ
How is the CISSP exam scored?
The English CISSP is a Computerized Adaptive Test (CAT) of 100–150 items in 3 hours, scored 0–1000 with a passing score of 700. Items are weighted by difficulty, so 700 is not 70% of the questions.
How many domains does the CISSP cover?
The CISSP Common Body of Knowledge has eight domains, from Security and Risk Management to Software Development Security.
What is CAT on the CISSP?
Computerized Adaptive Testing adjusts item difficulty to your performance and stops as soon as it is statistically confident you are above or below the standard. On the current outline that can happen anywhere between 100 and 150 items — an exam that ends early is not automatically a pass or a fail.
Do I need five years of experience to sit the exam?
No. You can sit it at any time. Without the five years of paid work experience across at least two of the eight domains you become an Associate of ISC2 and have six years to earn it. A relevant degree or approved credential can cover one of the five years.
Is old CISSP study material still accurate?
Check the format it describes. The current outline took effect on 15 April 2024 and runs 100–150 items in 3 hours. Material describing a 125–175 item, four-hour exam predates that change.
Can CertPrepX mock exams mirror the CISSP CAT?
CertPrepX builds full-length, domain-weighted mock exams and a readiness score across all eight CISSP domains so you can train under realistic conditions.
Sources
Exam details on this page come from ISC2’s own published materials and were last verified on 24 August 2026. ISC2 can change exam policy at any time, so confirm current requirements with ISC2 before you register.