• Cohort starts Jan 16, 2027
Reserve seat
All posts
Certifications

CISSP Exam Guide 2026: Domains, Cost, and Study Plan

PrimeSec Academy·9/19/2026
CISSP Exam Guide 2026: Domains, Cost, and Study Plan

CISSP guide for 2026: the 8 domains and weights, CAT exam format, experience requirements, real costs, and a 16-week study plan.

The CISSP is ISC2's senior-level cybersecurity certification that validates broad security management knowledge across eight domains, and it requires five years of paid, full-time experience in at least two of those domains plus a passing score of 700 out of 1000 on an adaptive exam. It is a breadth certification aimed at people who design, govern, and lead security programs, not a hands-on technical lab exam.

That distinction matters more than most study guides admit. If you are coming from a cloud or engineering background, the CISSP will feel unusually managerial. Knowing that up front is half the battle.

What the CISSP actually tests

The CISSP measures whether you can think like a security manager who understands technology, rather than an engineer who knows one platform deeply. Questions are frequently scenario-based and ask you to pick the best answer among several that are technically correct. The exam rewards candidates who default to risk management, business alignment, policy, and human safety over the clever technical fix.

A useful mental model for the exam: think like a risk manager, answer like a policy owner, and only then consider the technical control.

This is very different from the hands-on skills we teach in the PrimeSec Academy curriculum, where you build and break real cloud environments. Both matter. The CISSP proves you can run a program; platform certifications and project work prove you can build one.

CISSP exam format at a glance

ISC2 delivers the CISSP as a Computerized Adaptive Test (CAT) in English. The algorithm re-estimates your ability after every answer and ends the exam once it has enough statistical confidence to place you clearly above or below the passing standard.

ElementDetail
FormatComputerized Adaptive Testing (CAT)
Item countVariable, commonly published in the range of roughly 100 to 150 items
Time limit3 hours
Passing score700 out of 1000 points
Question typesMultiple choice and advanced innovative items
Exam outline versionEffective April 15, 2024
DeliveryPearson VUE test centers

Two practical implications of CAT. First, you cannot go back and change an answer, so second-guessing is off the table. Second, a short exam is not automatically a pass and a long exam is not automatically a fail. The algorithm simply needed more evidence.

Always confirm the current item count, fees, and outline version on the official ISC2 CISSP exam outline before you book, since ISC2 adjusts these periodically.

The eight CISSP domains and their weights

ISC2 updated the domain weights effective April 15, 2024. That version is still the current outline going into 2026.

#DomainWeight
1Security and Risk Management16%
2Asset Security10%
3Security Architecture and Engineering13%
4Communication and Network Security13%
5Identity and Access Management (IAM)13%
6Security Assessment and Testing12%
7Security Operations13%
8Software Development Security10%

Domain 1 is the heaviest and also the most conceptual. Governance, risk frameworks, legal and regulatory concepts, business continuity, and security awareness live here. Candidates with strong engineering backgrounds tend to under-study Domain 1 and over-study Domains 4 and 7, which are already familiar territory. Resist that instinct.

Domains 3, 5, and 7 carry the most useful overlap with cloud security work. If you have been managing identity in Entra ID or AWS IAM, running a SIEM, or designing network segmentation, you already hold a real advantage there. Our guides on Zero Trust architecture and cloud logging and monitoring fundamentals map closely to Domains 5 and 7.

Experience requirements and the Associate path

To be certified, you need five years of cumulative, paid, full-time work experience in two or more of the eight domains.

You can reduce that to four years with one of the following:

  • A relevant four-year college degree, or a regional equivalent
  • An approved credential from the ISC2 approved list

Only one year of waiver is available. You cannot stack a degree and a credential for two years off.

If you pass the exam but do not yet have the experience, you become an Associate of ISC2. Associates have six years from the exam date to earn the required experience and convert to full CISSP status. This is a legitimate path, not a consolation prize, and it is common for career changers.

One deadline catches people out: the endorsement. After you pass, an active ISC2 certified professional must endorse your application, and that endorsement generally needs to be submitted within nine months of your exam date. Miss that window and you may have to sit the exam again. Line up an endorser before you take the test, not after.

What the CISSP costs

Budget for more than the exam fee.

Cost itemTypical amount (Americas)
Exam registrationAround $749 USD
Annual Maintenance Fee, certified memberAround $135 USD per year
Annual Maintenance Fee, Associate of ISC2Around $50 USD per year
Official study guide and practice tests$50 to $150 USD
Optional instructor-led trainingVaries widely

Pricing differs by region and ISC2 revises it from time to time, so treat these as planning figures and verify at registration. The ongoing costs matter too: maintaining the CISSP requires 120 Continuing Professional Education (CPE) credits over a three-year cycle, with 40 per year recommended to stay on pace, plus the annual maintenance fee.

Should you take the CISSP before a cloud certification?

For most people moving into cloud security, the answer is no.

If you are early in your career or changing fields, platform-specific certifications and demonstrable project work open doors faster. Hiring managers filling a cloud security engineer role want evidence you can configure and defend a real environment. A CISSP on a resume with no hands-on record can read as theory without practice.

A reasonable sequence for a career changer:

  1. Build foundational security knowledge, for example with CompTIA Security+
  2. Go deep on one cloud platform and earn its security certification
  3. Build and document real projects that prove the skills
  4. Add the CISSP once you have the experience and are moving toward architect or leadership work

The CISSP earns its keep at the senior level, where job postings list it explicitly and where governance is a real part of the job. Our CISSP, CCSP and Security+ comparison walks through the decision in more detail, and you can see how certifications fit into the wider path on our certifications page.

A realistic 16-week study plan

Most working professionals need three to five months. A workable structure:

  • Weeks 1 to 2: Domain 1. Read it twice. Risk concepts, frameworks, legal and ethics.
  • Weeks 3 to 4: Domains 2 and 3. Data classification, cryptography, secure design principles.
  • Weeks 5 to 6: Domain 4. Network models, protocols, secure communications.
  • Weeks 7 to 8: Domain 5. Identity lifecycle, federation, access control models.
  • Weeks 9 to 10: Domain 6. Assessment strategies, audits, testing techniques.
  • Weeks 11 to 12: Domain 7. Incident response, forensics, continuity, physical security.
  • Weeks 13 to 14: Domain 8. SDLC, secure coding, software assurance.
  • Weeks 15 to 16: Full practice exams, targeted review of weak domains, exam-day strategy.

Practice questions are the highest-value activity in the final month, but only if you read the explanation for every question, including the ones you got right. The CISSP punishes pattern matching and rewards understanding why the other three options are wrong.

Common reasons candidates fail

  • Studying like an engineer. Choosing the most technical answer when the exam wants the managerial or risk-based one.
  • Neglecting Domain 1. It is 16% of the exam and the mindset foundation for everything else.
  • Memorizing instead of reasoning. CAT items are scenario-driven and resist flashcard recall.
  • Relying on a single source. One book plus one question bank leaves blind spots.
  • Poor pacing. Three hours for up to 150 dense scenario questions is tight.

Frequently asked questions

Is the CISSP hard for beginners? The CISSP is not designed for beginners. It assumes several years of professional security experience and tests judgment more than recall. Beginners are usually better served by an entry-level certification and hands-on projects first, then the CISSP once they have the required experience.

Can I take the CISSP exam without any experience? Yes. You can sit the exam without meeting the experience requirement and, if you pass, become an Associate of ISC2. You then have six years from your exam date to earn the required experience and convert to full CISSP certification.

How long does it take to study for the CISSP? Most working professionals spend three to five months, or roughly 150 to 300 hours, depending on how much of the material overlaps with their daily work. Candidates with strong governance and risk backgrounds often need less time than pure engineers.

How many questions are on the CISSP exam? The CISSP uses Computerized Adaptive Testing, so the item count varies by candidate within a published range and the exam ends once the scoring algorithm reaches a confident decision. You have three hours and need 700 out of 1000 points to pass. Check the current item range on the ISC2 exam outline before booking.

Does the CISSP expire? The CISSP does not expire as long as you maintain it. You must earn 120 Continuing Professional Education credits over each three-year cycle, with 40 per year recommended to stay on pace, and pay the annual maintenance fee.

Is the CISSP better than a cloud security certification? They serve different purposes. The CISSP proves broad security management knowledge and is often required for senior and leadership roles. A cloud security certification proves platform-specific skill and tends to matter more for hands-on engineering roles. Many senior practitioners eventually hold both.

Where to go from here

If your goal is a cloud and AI platform security engineering role, start by building the hands-on skills employers test for, then layer the CISSP on top once your experience qualifies you. PrimeSec Academy's 20-week program covers AWS, Azure, GCP, and AI security with real labs, 36 projects, and a defended capstone.

Explore the curriculum or enroll now to get started.

Stay ahead in cybersecurity

Get the Latest Security Insights

Subscribe to our newsletter and get updates on new courses, labs, events, and career tips.

We respect your privacy. Unsubscribe at any time.