Prepare across all eight CISSP domains using the current official outline. This guide connects each domain to a study task, explains the adaptive exam and certification routes, and gives you an original example of choosing appropriately limited access.
What the CISSP certifies and which outline applies
The CISSP validates deep technical and managerial knowledge for designing, engineering, and managing an organization's security posture. The current exam outline took effect on April 15, 2024.
As checked on 14 September 2026, the current outline is effective 15 April 2024. ISC2 has also integrated AI-specific security tasks across all eight existing domains — covering topics like AI supply-chain risk, model and data classification, and securing AI-assisted development — rather than adding a ninth AI domain.
Before you study from any summary, including this one, download the official outline PDF from ISC2. It is available in English, Chinese, Japanese, German, and Spanish, and it is the authoritative list of what can be tested.
Facts come from ISC2's official certification pages and NIST's CSRC glossary, checked September 14, 2026.: Review the ISC2 CISSP Certification Exam Outline — Effective April 15, 2024; exam information, weights, and domain objectives
The eight domains and their weights
Use the official weights to check coverage across all eight domains, alongside your own strengths and gaps.
Read each domain's detailed objectives in the official outline. The study tasks below are optional ways to practise them, not official sub-weights or a prescribed allocation of study hours.
| Domain | Weight | Topic focus | Study task |
|---|---|---|---|
| 1. Security and Risk Management | 16% | Ethics, governance principles, legal and privacy issues, risk concepts, threat modeling, supply-chain risk, business-continuity requirements, awareness programs | Explain the objective, risk, control and decision authority in a supplied scenario. |
| 2. Asset Security | 10% | Classifying and handling information and assets, data roles and lifecycle, retention, data states and protection methods | Trace a data asset through its lifecycle and identify its owners and handling needs. |
| 3. Security Architecture and Engineering | 13% | Secure design principles, security models, systems security capabilities, cryptography, cryptanalytic attacks, site and facility design, system lifecycle | Explain the assumptions and purpose of a secure design principle. |
| 4. Communication and Network Security | 13% | Secure network architecture (OSI/TCP-IP, segmentation, wireless, SDN), securing network components, secure communication channels | Sketch a network boundary and explain which communications should cross it. |
| 5. Identity and Access Management | 13% | Physical and logical access control, authentication strategy, federation, authorization mechanisms, provisioning lifecycle | Compare a requested permission with the assigned task, resource and duration. |
| 6. Security Assessment and Testing | 12% | Assessment and audit strategies, control testing (vulnerability, penetration, code review), process data, reporting | Match an assessment method to the evidence it produces. |
| 7. Security Operations | 13% | Investigations, logging and monitoring, configuration management, incident management, preventive tools, recovery strategies, DR testing, physical security | Explain how incident response, recovery and lessons learned relate. |
| 8. Software Development Security | 10% | Security in the SDLC, development ecosystem controls, acquired software risk, secure coding guidelines | Identify security checks during development and when acquiring software. |
Facts come from ISC2's official certification pages and NIST's CSRC glossary, checked September 14, 2026.: Review the ISC2 CISSP Certification Exam Outline — Effective April 15, 2024; exam information, weights, and domain objectives; Computerized Adaptive Testing — CAT FAQ: items, timing, results, and retake policy
How the adaptive exam actually works
Every CISSP exam is delivered as Computerized Adaptive Testing (CAT): 100–150 items, a 3-hour maximum, and no chance to return to an answer you have finalized.
CAT selects questions using an updated estimate of your ability. ISC2 explains that candidates should expect challenging items. Perceived difficulty alone does not tell you whether you are passing.
After the 100-item minimum, the exam can end when the ability estimate lies above or below the passing standard with 95% statistical confidence. If this rule has not ended the exam by 150 items, the final ability estimate is compared with the standard. Stopping at 100 can mean either result, and reaching 150 is not automatic failure.
If time runs out, the exam ends under the run-out-of-time rule: your final ability estimate is compared against the passing standard. However, if you have not answered at least 75 scored items plus 25 pretest items in the time allowed, you automatically fail. That is why pacing matters: budget for the possibility of all 150 items within the 3 hours, including any breaks, which count against your time.
You cannot review, change, or return to any finalized answer, and content is not delivered in domain sections or a fixed order — items follow the outline's domain weights regardless of where they fall in your session. Your result appears immediately as pass or fail, with no numeric score; failing candidates receive a proficiency level per domain to guide the next attempt.
- The minimum 100 items include 25 unscored pretest items that you cannot identify.
Facts come from ISC2's official certification pages and NIST's CSRC glossary, checked September 14, 2026.: Review the ISC2 CISSP Certification Exam Outline — Effective April 15, 2024; exam information, weights, and domain objectives; Computerized Adaptive Testing — CAT FAQ: items, timing, results, and retake policy
Experience, waivers, and the Associate path
You need five years of cumulative, full-time experience in two or more of the eight domains. A qualifying degree or one approved credential can waive one year — never both together.
The experience rule is specific. Full-time means at least 35 hours per week for four weeks to accrue one month. Part-time work counts if it falls between 20 and 34 hours per week, converted at 1,040 hours for six months or 2,080 hours for twelve months of full-time experience. Paid and unpaid internships also count, provided you can document them on official letterhead.
You may reduce the five-year requirement by up to one year with a post-secondary degree in computer science, IT, or a related field, or with a credential from ISC2's approved waiver list. Only one waiver is permitted — you cannot combine a degree and a credential to remove two years. Note that ISC2 revised the waiver list effective April 1, 2026, so verify against the current list rather than an older summary.
If you pass the exam without the required experience, you can become an Associate of ISC2. You then have up to six years to earn the five years of experience and complete certification. The Associate designation shows you passed a rigorous ISC2 exam; it is not the CISSP certification itself, so represent it accurately to employers.
Facts come from ISC2's official certification pages and NIST's CSRC glossary, checked September 14, 2026.: Experience Needed for the ISC2 CISSP Certification — Experience, waiver, and Associate requirements; Become an Associate of ISC2 While You Gain Experience — Associate designation duration and upgrade process; ISC2 CISSP Experience Waiver Updates Requirements — April 1, 2026 waiver-list revision
After you pass: application, endorsement, and the first fee
Passing the exam is one step. You must complete the certification application within nine months of your exam date, verify your experience through endorsement, and pay your first Annual Maintenance Fee before certification is granted.
Complete the certification application process within nine months of your exam date. You can submit only after receiving the passing notification; plan your records and endorsement before the deadline.
Full certification requires an endorser — an ISC2-certified professional in good standing who attests to your experience and professional standing. Your endorser provides their ISC2 member ID and surname. If you do not know a certificant, you can ask ISC2 to endorse you, but that route requires proof of employment. Once your application is approved, you pay your first Annual Maintenance Fee, and only then does the certification take effect.
A few applications are randomly selected for audit and must supply additional verification, so keep your experience records organized from the start.
If you already hold an ISC2 certification, you do not pay an additional annual maintenance fee for the new certification.
Facts come from ISC2's official certification pages and NIST's CSRC glossary, checked September 14, 2026.: Endorsement | Online Endorsement Application | ISC2 — Application timeline, endorsement, and audit; Member Policies — CPE and Annual Maintenance Fee requirements
Should you always choose the managerial answer?
No. Read the role, requested decision and constraints before comparing the options.
ISC2 explicitly describes both technical and managerial knowledge. Its objectives include governance and risk decisions as well as architecture, networks, access controls and software security. A policy keyword does not make an option correct, and a technical option is not automatically wrong.
The reliable method is to read the question as written: identify the role you occupy, the decision being requested, the evidence and constraints stated in the stem, and then apply the relevant knowledge from the outline. Sometimes that answer is a technical control; sometimes it is a governance action. Neither a management-sounding word nor a technical-sounding word makes an option universally correct.
In practice, train this by reviewing wrong answers on legitimate practice questions: ask which stated fact in the scenario you overlooked. That habit builds judgment without relying on shortcuts or leaked material, which you should avoid entirely.
Facts come from ISC2's official certification pages and NIST's CSRC glossary, checked September 14, 2026.: Review the ISC2 CISSP Certification Exam Outline — Effective April 15, 2024; exam information, weights, and domain objectives
Worked example: authentication is not authorization
Authentication verifies a claimed identity. Authorization determines permitted access, and least privilege limits it to what the assigned task needs.
NIST defines authentication as verifying the identity of a user, process or device. In access control, authorization is the decision to permit or deny access to a resource. Least privilege limits privileges to the minimum needed for assigned tasks. A successful sign-in does not establish permission for every requested action.
Try the scenario in the exercise below. Its roles, the one-hour window, and the approval workflow are stated assumptions of the example, not ISC2 policy — read every scenario on its own stated facts.
Practice example: apply authentication, authorization, and least privilege to a stated scenario.
A vendor engineer has just authenticated successfully to your environment. In this fictional example, company policy says the application owner approves access and a system administrator implements it. The approved task is to read one named application log during a scheduled one-hour diagnostic window; no configuration changes and no other systems are involved. Which access should the administrator grant? A) Read access to that one log, expiring when the hour ends B) Read access to all company logs, indefinitely C) Administrator access to the application, indefinitely
Reveal the answer after committing to your choice — the reasoning matters more than the letter.
A
Authentication has verified the engineer's claimed identity, but that is a separate step from authorization — the decision to grant access to a specific resource. The approved task needs exactly one resource (the named log), one action (read), and a bounded duration (the one-hour window). Least privilege means granting the minimum necessary for the assigned task, so option A matches the task and option C, broad standing privilege, exceeds it by far. Option B grants the right action (read) but across the wrong scope and duration; unbounded log access is not necessary for this diagnostic. The workflow also matters: per the stated policy, the application owner approves and the administrator implements the limited grant — the successful login does not establish permission beyond the stated approval.
Facts come from ISC2's official certification pages and NIST's CSRC glossary, checked September 14, 2026.: least privilege - Glossary | CSRC — NIST definitions of least privilege; authentication - Glossary | CSRC — NIST definitions of authentication; authorization - Glossary | CSRC — NIST definitions of authorization
Your preparation checklist
Anchor your study to the official outline, practice breadth across all eight domains, and verify your own logistics before booking.
Use domain weights alongside your own gaps. Review legitimate practice questions against the relevant objective and explain why alternatives fit or fail the supplied facts. Do not convert a practice percentage into a guaranteed CAT result.
- Cover all eight domains and revisit objectives behind repeated errors.
- Practise pacing for up to 150 items in three hours, including breaks.
- Explain a security decision using the role, evidence and constraints supplied.
- Confirm your experience or Associate route, current waiver list and booking details.
- Prepare accurate experience records and note the nine-month application deadline.
Facts come from ISC2's official certification pages and NIST's CSRC glossary, checked September 14, 2026.: Review the ISC2 CISSP Certification Exam Outline — Effective April 15, 2024; exam information, weights, and domain objectives; Experience Needed for the ISC2 CISSP Certification — Experience, waiver, and Associate requirements; Computerized Adaptive Testing — CAT FAQ: items, timing, results, and retake policy; Endorsement | Online Endorsement Application | ISC2 — Application timeline, endorsement, and audit; Become an Associate of ISC2 While You Gain Experience — Associate designation duration and upgrade process; ISC2 CISSP Experience Waiver Updates Requirements — April 1, 2026 waiver-list revision
Costs, scheduling, and retakes
Check regional pricing, language availability and the authorized test center before paying. Retake rules apply to each certification program.
ISC2's published CISSP prices include U.S. $749 in several regions, EUR 719.04 for EMEA and GBP 606.69 for the United Kingdom. Confirm the applicable region, taxes and current rescheduling or cancellation charges at booking.
Exams are taken in person at ISC2-authorized Pearson Professional Centers and selected Pearson VUE test centers — there is no at-home delivery. The exam is offered in Chinese, English, German, Japanese, and Spanish, all in adaptive format; Chinese-language appointments are limited to March, June, September, and December each year, so book those windows early.
If you need another attempt, two rules apply together. After your first attempt you wait 30 test-free days; after your second, 60 days; after your third and any subsequent attempt, 90 days. You may also take at most four attempts within any 12-month period for the certification program.
Facts come from ISC2's official certification pages and NIST's CSRC glossary, checked September 14, 2026.: Review the ISC2 CISSP Certification Exam Outline — Effective April 15, 2024; exam information, weights, and domain objectives; Computerized Adaptive Testing — CAT FAQ: items, timing, results, and retake policy; How Much Do ISC2 Certification Exams Cost? — Regional pricing and change fees
Keeping the credential: CPEs and the annual fee
Certified members earn 120 CPE credits over each three-year cycle (at least 90 from Group A) and pay a U.S. $135 annual maintenance fee. Associates follow a lighter annual schedule.
CISSP holders earn and report 120 continuing professional education (CPE) credits over each three-year cycle, including at least 90 Group A credits; the remaining 30 may be Group A or B. The annual maintenance fee is U.S. $135 and covers multiple ISC2 certifications.
Associates of ISC2 pay a U.S. $50 annual fee and earn 15 Group A CPE credits each year. Missing these requirements past a 90-day grace period suspends your status, which means you may no longer use the designation.
Facts come from ISC2's official certification pages and NIST's CSRC glossary, checked September 14, 2026.: Member Policies — CPE and Annual Maintenance Fee requirements; Become an Associate of ISC2 While You Gain Experience — Associate designation duration and upgrade process
Facts come from ISC2's official certification pages and NIST's CSRC glossary, checked September 14, 2026.
Key exam facts were verified against ISC2 sources on September 14, 2026.:
- Review the ISC2 CISSP Certification Exam Outline
- Experience Needed for the ISC2 CISSP Certification
- Computerized Adaptive Testing
- Endorsement | Online Endorsement Application | ISC2
- How Much Do ISC2 Certification Exams Cost?
- Member Policies
- Become an Associate of ISC2 While You Gain Experience
- ISC2 CISSP Experience Waiver Updates Requirements
- least privilege - Glossary | CSRC
- authentication - Glossary | CSRC
- authorization - Glossary | CSRC
