IT, Cloud & Cybersecurity • Certification
Certified Information Systems Security Professional
The flagship credential for senior security professionals.
Researched and maintained by TestPrepPilot Editorial BoardCloud, IT & cybersecurity certifications desk · Figures last verified August 2026
The short version
What is the Certified Information Systems Security Professional and is it worth it?
CISSP is a 3-hour, 100–150-question CAT exam scored 700/1000, costing $749. Five years of paid experience (or four with a qualifying degree) is required, with an Associate pathway if short. It is valid three years with CPE credits and the $135 Annual Maintenance Fee.
- The industry-standard senior security credential
- Eight domains spanning technical and management
- Often required for senior and leadership roles
- Associate pathway if you lack experience
What is it?
What exactly is the Certified Information Systems Security Professional?
The flagship credential for senior security professionals.
The Certified Information Systems Security Professional (CISSP) is ISC2’s flagship certification, covering eight security domains and requiring five years of paid experience. It is widely required or preferred for senior and management security roles and is the benchmark against which many other security certs are measured.
The path in brief
- Confirm 5yr experience
- Study the 8 domains
- Book CAT exam
- Pass at 700/1000
- Submit endorsement; maintain with CPE
Before you book
Who is eligible to sit the Certified Information Systems Security Professional?
Who it is for: Senior security engineers, architects and managers.
The test itself
What is the format of the Certified Information Systems Security Professional?
The Certified Information Systems Security Professional is administered by Pearson VUE test centre or online proctoring and runs 3 hours, contains 100-150 (CAT) questions and requires 700 / 1000 scaled to pass.
| Administered by | Pearson VUE test centre or online proctoring |
|---|---|
| Questions | 100-150 (CAT) |
| Time limit | 3 hours |
| Pass mark | 700 / 1000 scaled |
| Exam fee | $749 |
| Format | Multiple choice + advanced items (CAT) |
Content outline
What topics are on the Certified Information Systems Security Professional?
The Certified Information Systems Security Professional is weighted across 8 domains; the largest are Security and Risk Management (16%), Asset Security (10%), Security Architecture and Engineering (13%).
Weightings come from the official exam outline. Study time is best allocated in roughly these proportions rather than evenly across domains.
- Security and Risk Management 16%
Governance, ethics, compliance
- Asset Security 10%
Data classification and handling
- Security Architecture and Engineering 13%
Design and models
- Communication and Network Security 13%
Network defence
- Identity and Access Management 13%
IAM
- Security Assessment and Testing 12%
Evaluation
- Security Operations 13%
Monitoring and IR
- Software Development Security 10%
Secure SDLC
Money & time
How much does the Certified Information Systems Security Professional cost?
For the Certified Information Systems Security Professional, the exam fee is $749; the all-in cost is typically $749-$3,750; most candidates spend 3-6 months preparing.
Cost breakdown
| Exam fee | $749 |
|---|---|
| Training (optional) | $500-$3,000 |
| Typical total | $749-$3,750 |
AMF of $135/year applies after certification.
Timeline
- Study 3-6 months
Typical prep: 3-6 months
The path
How do you register for the Certified Information Systems Security Professional?
- 1
Confirm eligibility
Most ISC2 credentials require paid work experience; you may sit the exam first and earn the Associate of ISC2 title if short on experience.
- 2
Register and pay
Pay the exam fee and schedule through Pearson VUE.
- 3
Pass the CAT exam
Complete the adaptive exam at a Pearson VUE centre or via online remote proctoring.
- 4
Submit endorsement
Have your experience endorsed by an ISC2 member within nine months of passing.
The fine print
What are the retake and renewal rules for the Certified Information Systems Security Professional?
- Proctoring & delivery
- Delivered by Pearson VUE at test centres or via online proctoring. CC, CISSP, CCSP and SSCP use Computerized Adaptive Testing (CAT); CGRC, CSSLP and the CISSP concentrations use linear fixed forms.
- Retake policy
- If you fail, you wait 30 days for the second attempt, 60 days for the third, and 90 days for subsequent attempts within a one-year eligibility window.
- Score reporting
- All ISC2 exams are scored on a 700/1000 scale. CAT exams end when statistical confidence is reached; linear exams use the full item count.
- Recertification
- Certifications are valid for three years. Holders must earn Continuing Professional Education (CPE) credits and pay the Annual Maintenance Fee ($135) to keep the credential active.
What it pays
How much does this credential pay?
$124,910 median for information security analysts (BLS, May 2024)
There is no Bureau of Labor Statistics occupation called "CISSP" — the Certified Information Systems Security Professional credential certifies experienced security leadership and engineering, and the wage question belongs to the role you perform with it. The closest official BLS occupation is Information Security Analysts, SOC 15-1212, which had a May 2024 median wage of $124,910, with the lowest 10 percent under $71,280 and the highest 10 percent above $173,780. The fit is deliberate: CISSP holders work as security engineers, security architects, managers and consultants — the experienced tier of this occupation — so the realistic benchmark for a CISSP holder sits at or above the median. BLS counted 182,300 information security analyst jobs in 2024 and projects a striking 30 percent growth from 2024 to 2034 — much faster than the average for all occupations — with about 17,500 openings a year. The limitation to state plainly: the BLS median covers the whole occupation, credentialed or not, and the CISSP's value is as a seniority and breadth signal; the credential requires five years of paid security experience across two or more of its eight domains, so holders are by definition experienced professionals. Read the number as the market for the occupation, with the CISSP concentrated at its upper half.
| Measure | Figure | Source / note |
|---|---|---|
| Median annual wage, information security analysts | $124,910 | BLS OOH, SOC 15-1212, May 2024 |
| Lowest 10 percent | Under $71,280 | BLS OOH, SOC 15-1212, May 2024 |
| Highest 10 percent | Above $173,780 | BLS OOH, SOC 15-1212, May 2024 |
| Projected openings per year | ~17,500 | BLS OOH, SOC 15-1212, 2024-2034 |
Job growth.BLS projects 30 percent growth for information security analysts from 2024 to 2034, about 17,500 openings per year.
Source: BLS Occupational Outlook Handbook - Information Security Analysts
Your odds
What are the pass rates?
ISC2 publishes no pass rate — it publishes the passing score: 700 of 1000, on an adaptive exam of 125-175 questions in up to 3 hours
ISC2 does not publish cohort pass rates for the CISSP, and third-party surveys are not official data, so we do not treat them as authoritative. What ISC2 does publish is the format and the passing standard: the CISSP is a computer-adaptive exam of 125 to 175 questions with a time limit of up to 3 hours, and a passing score of 700 on the 100-1000 scale. The adaptive design means the exam adjusts difficulty to your performance and stops when it is confident in your result — a candidate can finish early in as few as 125 questions. The exam is delivered at Pearson VUE centres or through online proctoring, and its content spans the eight CISSP domains: security and risk management; asset security; security architecture and engineering; communication and network security; identity and access management; security assessment and testing; security operations; and software development security. The absence of a published pass rate is not an absence of standards: the CISSP is widely considered one of the hardest exams in the field, and the 700 line on an adaptive paper rewards breadth across all eight domains plus the experience to reason like a security professional. The practical reading: target 80 percent-plus on practice and treat domain coverage and the mindset of "best security practice" as the core of preparation.
Read this before quoting the number.ISC2 publishes the passing score and format but no pass rate; any percentage circulating online is a third-party estimate.
Source: ISC2 - CISSP certification
Your schedule
How long should I study for it?
150-250 hours over 3-6 months (plus the 5-year experience requirement) of focused study
The CISSP is an adaptive exam of 125-175 questions in up to 3 hours with a 700/1000 passing score, and its curriculum is the eight domains of the ISC2 Common Body of Knowledge. The certification also requires five years of paid security experience across two or more domains (or four years with a qualifying degree), so the exam sits on top of real experience. A defensible plan runs 150 to 250 hours over 3 to 6 months. Phase one (weeks 1-4) builds the foundation: work the first domains — security and risk management, asset security, and security architecture and engineering — with a study guide or official course, taking notes by domain. Phase two (weeks 5-8) covers the technical domains: communication and network security, identity and access management, and security assessment and testing, with hands-on exploration of the technologies. Phase three (weeks 9-12) covers security operations and software development security, then shifts to question-bank drilling in volume. Phase four (weeks 13-16) adds timed practice exams at the adaptive format, at least three full simulations, with error-log review mapped to the domains. The plan is experience-anchored: candidates with real security work accelerate the technical phases, while the domains outside their daily work — often software development security or asset security — need the most study.
- Weeks 1-460
Foundation domains
- Security and risk management
- Asset security
- Security architecture and engineering
- Weeks 5-860
Technical domains
- Communication and network security
- Identity and access management
- Security assessment and testing
- Weeks 9-1260
Operations and development
- Security operations
- Software development security
- Question-bank drilling in volume
- Weeks 13-1650
Adaptive mocks
- Three full timed practice exams
- Review every miss mapped to the domains
- Final pass over weak domains
Adjusting the pace
Five-plus years in security.Compress the foundation domains; spend the extra time on the domains outside your daily work.
Four years plus degree.Confirm the waiver path; the plan is unchanged, but eligibility matters before you study.
How to study
How do I prepare most effectively?
The CISSP rewards breadth plus security judgement, so the dominant strategy is full-domain coverage with applied reasoning: every domain appears, and the exam items ask you to think like an experienced security professional choosing the best practice for a described situation. Second, use official and well-regarded study materials mapped to the eight domains, and take notes by domain so your review is structured. Third, drill the "best answer" mindset: CISSP items frequently have more than one defensible option, and the exam rewards the most appropriate security practice, not the technically clever one — practise choosing the best, not just a correct, answer. Fourth, take at least three full timed practice exams, because the adaptive format and the stamina of up to 3 hours are part of the test. Fifth, master the domains outside your daily work; most candidates find their weakest domain is the one they never touch professionally. Finally, confirm the endorsement and experience requirements early: the credential is awarded only after an endorsement by an ISC2 member and the annual maintenance fee is established.
Cover all eight domains
Every domain appears; the exam rewards breadth plus judgement.
Take structured domain notes
Organise study by the eight domains for efficient review.
Drill the best-answer mindset
The exam rewards the most appropriate security practice, not the cleverest.
Run three full simulations
The adaptive format and up to 3 hours of stamina are part of the test.
Confirm endorsement early
The credential needs a member endorsement and the annual maintenance fee.
What to buy
Which study resources are worth paying for?
CISSP prep is a mature market with three tiers. Official ISC2 resources include the exam outline (free), the official ISC2 CISSP training course (roughly $600-$1,500 for the instructor-led or self-paced formats) and the official practice tests. The widely used third-party study guides and courses — including the popular CISSP study guides and question banks — run from roughly $50 for a book to $1,000 for a full course bundle; practice-exam products with thousands of questions are the standard supplement. Free resources include the domain outline, ISC2 sample questions, and the security community forums. A realistic total budget is $500 to $2,500 including the exam fee (about $749) and the annual maintenance fee (about $135). Prices below are list prices as of mid-2026 and change frequently; we rank nothing by commission.
| Resource | Price | Format | Best for |
|---|---|---|---|
| ISC2 exam outline | Free | Official PDF | The authoritative scope; read it first |
| CISSP study guides (book) | $50-$100 | Printed or digital book | Structured domain-by-domain reference |
| ISC2 official training | $600-$1,500 | Self-paced or instructor-led | The official learning path |
| Third-party courses | $200-$1,000 | Video courses and bundles | Structured walkthrough of the domains |
| Practice-exam products | $50-$200 | Large online question banks | The best-answer drilling the exam rewards |
List prices as of mid-2026, subject to change; the CISSP exam fee is about $749 plus the ~$135 annual maintenance fee; no commission or affiliate ranking is implied.
Avoid these
What mistakes do candidates most often make?
The most common CISSP mistake is studying the domains you already know and neglecting the rest: candidates with networking backgrounds pass the network domain and fail asset security or software development security, because every domain appears and the exam rewards breadth. The fix is full coverage with extra time on the unfamiliar domains. The second mistake is choosing technically correct but not best-practice answers: the CISSP rewards the most appropriate security response, and candidates who answer like hackers rather than security managers lose the judgement items. Third, many candidates underestimate the exam's length and adaptive nature, skipping full simulations and then flagging under the up-to-3-hour format. Fourth, some candidates rely on a single source; the exam draws on the whole Common Body of Knowledge, so a guide plus a large question bank is the standard stack. Finally, forgetting the endorsement and experience requirements means passing the exam but delaying the credential — confirm eligibility before studying, not after.
✕Studying only familiar domains
✓Cover all eight; most failures sit in the domains outside daily work.
✕Answering as a hacker, not a manager
✓Choose the best security practice, not the technically clever option.
✕Skipping full simulations
✓Three timed mocks; the adaptive format and stamina are part of the test.
✕Relying on one source
✓A guide plus a large question bank covers the Common Body of Knowledge.
✕Forgetting endorsement and experience
✓Confirm eligibility before studying; the credential needs both.
What you'll face
What question types will I see?
The CISSP is an adaptive exam of 125-175 questions in up to 3 hours, entirely multiple-choice. The items span the eight domains and are heavily judgement-flavoured: described security situations with multiple defensible options, where the exam rewards the best security practice rather than the only correct answer. A large share of items test risk and management reasoning — policy, governance, compliance, risk analysis — alongside the technical domains, reflecting the credential's seniority. Samples below are editor-written illustrations of the published exam outline, not live exam items; they show the best-answer style of the real items.
Situations with multiple defensible options; choose the best security practice.
Direct questions on principles, controls and framework concepts.
Governance, policy, compliance and risk-analysis reasoning.
Try these
Q1An organisation must reduce the risk of a data breach from lost laptops. The most effective control set is:
Answer:A
Protecting lost-laptop data requires encryption (confidentiality at rest), strong authentication (access control) and remote wipe (remediation) — a layered control set. Password-only, outbound-firewall or background-check-only measures each address a different or insufficient risk.
Q2A security manager must decide which business impact drives the recovery time objective (RTO). The RTO is best defined as:
Answer:A
The RTO is the maximum acceptable downtime — how quickly systems must be restored to avoid unacceptable business impact. Data-loss tolerance describes the RPO, restore time is a measurement, and cost is a budget constraint.
Q3A developer proposes storing passwords as MD5 hashes. The security architect should:
Answer:B
MD5 is cryptographically weak for password storage; modern practice requires a salted, slow hashing algorithm such as bcrypt or Argon2. Approving MD5, relying on password length alone, or reversible encryption each fail current password-storage standards.
Samples are editor-written illustrations of the published exam outline, not live exam items.
The big day
What should I expect on exam day?
The CISSP is an adaptive computer-based exam of 125-175 questions in up to 3 hours at a Pearson VUE centre or through online proctoring. Bring two forms of ID (including a government-issued photo ID matching your registration name) and your appointment confirmation; personal items go in the locker. Arrive 30 minutes early; late arrivals forfeit the appointment and the $749 fee. Because the exam is adaptive, it may end early when ISC2 is confident in your result — do not panic if it finishes at 125 questions; that is the design. Pace at about 1 minute per item and treat every question as the best-answer choice. You receive your score on screen at the end, against the 700/1000 line. If you fail, ISC2 requires a waiting period before retaking. On a pass, the credential is awarded after your endorsement application is approved, and it is maintained with 40 continuing professional education (CPE) credits per year plus the annual maintenance fee. The afterwards matters: complete the endorsement promptly, then set up the CPE logging habit, because ISC2 audits.
Bring
- Two forms of ID, including a government-issued photo ID
- Appointment confirmation
Leave at home
- Phone, smartwatch and all electronics
- Notes and study materials
- Personal bags beyond what the centre allows
How the day runs
Rules in the room
- No personal electronics in the testing room
- The exam is adaptive and may end after 125 questions
- A waiting period applies before retaking after a fail
Afterwards.On a pass, complete the endorsement application to be awarded the CISSP, then maintain it with 40 CPEs per year and the annual maintenance fee. On a fail, wait the required period and retake after additional study.
Reference
What are the key facts about the Certified Information Systems Security Professional?
Certified Information Systems Security Professional is a certification credential; awarded by ISC2; the exam fee is $749; typical preparation is 3-6 months; holders typically earn $120,000-$170,000.
| Credential | Certified Information Systems Security Professional |
|---|---|
| Abbreviation | CISSP |
| Type | Certification |
| Profession | IT, Cloud & Cybersecurity |
| Specialty | Cybersecurity (Vendor-Neutral) |
| Awarded by | ISC2 |
| Difficulty | Hard |
| Typical prep time | 3-6 months |
| All-in cost | $749-$3,750 |
| Typical salary range | $120,000-$170,000 |
| Delivery | Pearson VUE CAT exam |
| Retake | 30/60/90-day waiting periods |
| Validity | 3 years; CPE + $135 AMF |
| Scope | National / Multi-state |
| Also known as | CISSP |
Real questions
Frequently asked questions about the Certified Information Systems Security Professional
How much experience do I need for CISSP?
Five years of paid experience in two or more domains, or four years with a relevant degree. You can pass first and use the Associate of ISC2 pathway if short.
What is the pass mark?
A scaled 700 out of 1000 on the CAT exam.
Is CISSP multiple choice?
It uses multiple-choice and advanced item types delivered adaptively; there are no hands-on labs in the base exam.
How do I maintain CISSP?
Earn CPE credits (120 over three years) and pay the $135 Annual Maintenance Fee to keep the credential active.
What score do I need to pass an ISC2 exam?
A scaled score of 700 out of 1000 on every ISC2 certification exam.
Can I take the exam before I have the required experience?
Yes. You receive the Associate of ISC2 title and have a set period (commonly two years) to submit verified experience.
In short
Is the Certified Information Systems Security Professional worth it?
- CISSP is ISC2’s flagship senior credential
- 100-150 CAT questions, 3 hours, 700/1000, $749
- Eight domains; 5yr experience (Associate path available)
- 3-year validity; CPE + $135 AMF
Trust
Where does this information come from?
Everything above is taken from the awarding body's own published material. Fees, question counts and domain weights are revised regularly — check the official page before you pay.
- ISC2 Awarding body
- Official Certified Information Systems Security Professional exam page Exam page
- ISC2 certification programme Programme rules
Research confidence: high · Last reviewed 2026-08