CISSP Exam: Official Cost, Format, Domains, and Requirements for 2026
Official details for Certified Information Systems Security Professional (CISSP) Exam Information Guide 2026 as published by the certification body.
What This CISSP Exam Actually Certifies
The Certified Information Systems Security Professional(CISSP) doesn't test whether you can configure a firewall or write a Python script. It tests whether you can think like someone accountable for an entire security program — someone who has to weigh a control's cost against the risk it mitigates, decide who owns an exception, and defend that decision to a board. ISC2 built the exam around eight domains it calls the Common Body of Knowledge (CBK), and passing means you've demonstrated competence across all eight, not just excelled in a couple.
That breadth is the point and also the frustration for a lot of candidates. Someone who has spent a decade doing hands-on penetration testing can still fail the CISSP, not because they don't understand security, but because the exam keeps asking "what would you do as a manager," and their instinct is to answer as an engineer.
Who This CISSP Exam Is For (and Who It's Not For)
ISC2 designed this for people already working in security leadership or on their way there: security managers, architects, consultants, and directors who need a credential that signals they can run a program, not just execute a task. It's also one of the few certifications the U.S. Department of Defense recognizes under DoDM 8140.03 for cybersecurity roles, which is a large part of why it shows up as a requirement in government and defense contractor job postings.
It's a poor fit for someone early in their career. The five-year experience requirement isn't a suggestion — ISC2 checks it during endorsement, and candidates who pass the exam without the experience become an "Associate of ISC2" instead of a full CISSP until they accumulate the required time. If you're two years into IT and want a credential that opens doors now, Security+ or ISC2's own Certified in Cybersecurity (CC) will get you further, faster.
CISSP Exam Format and Structure
The English-language exam runs on Computerized Adaptive Testing, which changes the psychological experience more than most study guides admit. You get 100 to 150 items and up to three hours, but you can't skip a question or go back to change an earlier answer — the system picks your next question based on how you did on the last one. Answer well and the exam can end at the 100-question mark; struggle and it keeps going to gather more data, up to the 150-item ceiling.
That one-way structure means a rough patch early in the test carries more weight than it would on a traditional fixed-form exam, and it's the biggest single source of CISSP exam anxiety. Non-English versions (Simplified Chinese, German, Japanese, Spanish) don't use CAT — they're longer, fixed-form exams with more total items and more time, since ISC2 hasn't built adaptive item pools in every supported language yet.
Domains and Weightings
ISC2 refreshed the domain weights effective April 15, 2024, based on its triennial job task analysis, and that version is still current heading into 2026. Domain 1 carries the heaviest weight and sets the tone for the rest of the exam — it's where the "think like a manager" expectation is most explicit.
Domain | Weight |
|---|---|
1. Security and Risk Management | 16% |
2. Asset Security | 10% |
3. Security Architecture and Engineering | 13% |
4. Communication and Network Security | 13% |
5. Identity and Access Management (IAM) | 13% |
6. Security Assessment and Testing | 12% |
7. Security Operations | 13% |
8. Software Development Security | 10% |
Candidates coming from a technical background often over-index on Domains 3, 4, and 7 because the material feels familiar, and under-study Domain 1 because governance and legal topics feel abstract. That's backwards given the weighting — Domain 1 alone is worth more than Domains 2 and 8 combined.
Since 2025, ISC2 has also woven AI-specific content into all eight domains rather than adding a standalone AI domain — governance of machine learning models in Domain 1, protecting training data in Domain 2, defending against prompt injection in Domain 3, securing AI agent identities in Domain 5, and so on. It's not a separate section to study; it's a lens applied across the existing material.
Cost Breakdown
The standard exam fee is $749 USD, though ISC2 adjusts regional pricing and local taxes apply outside the U.S. That fee buys one attempt with a 365-day scheduling window. ISC2 also sells an "Exam with Peace of Mind Protection" bundle that gives two attempts within a 180-day window for less than the cost of two separate registrations — worth considering if you're not confident about a first-pass, since a straight retake after a fail costs the full $749 again and requires a 30-day waiting period.
The fee most first-time candidates forget to budget for isn't the exam itself — it's what comes after. Once certified, you owe a $135 Annual Maintenance Fee (AMF) every year the credential stays active, plus 120 Continuing Professional Education (CPE) credits across each three-year cycle, split into 90 "Group A" (directly security-related) and 30 "Group B" (broader professional development) credits.
Prerequisites and Eligibility
You need five cumulative years of paid, full-time work experience across at least two of the eight CISSP domains. A relevant bachelor's or master's degree, or one credential from ISC2's approved list, can waive one of those five years — but only one waiver applies, no matter how many qualifying credentials or degrees you hold. Part-time work (20–34 hours per week) counts on a pro-rated basis, and both paid and unpaid internships qualify if documented on official letterhead.
If you pass the exam without the required experience, you don't fail outright — you become an Associate of ISC2 and have six years to accumulate the experience and earn full CISSP status.
How the Exam Is Scored and What Passing Requires
Because the CAT format adjusts question difficulty in time, your raw number of correct answers doesn't map directly to a percentage the way it might on a fixed-form test. ISC2 scales results to a 0–1000 point range, and you need 700 to pass. You'll get a preliminary pass/fail result on-screen immediately after finishing, with an official score report following by email — typically within a few weeks, once ISC2 completes item analysis and any post-exam review.
Renewal and Recertification
The CISSP itself doesn't expire on a fixed timeline the way some vendor certifications do — there's no "version 2026" you're forced to retake. What keeps it active is the combination above: paying the $135 AMF annually and logging 120 CPE credits every three years. Miss either one and ISC2 can suspend or revoke the credential, at which point reinstatement typically means paying back fees and, in some cases, retaking the exam.
How This CISSP Exam Compares to CISM
The most common alternative candidates weigh against the CISSP is ISACA's Certified Information Security Manager (CISM). The practical difference: CISSP tests broader technical-plus-managerial knowledge across eight domains, while CISM leans more heavily into governance, risk, and program management with less depth on architecture and engineering topics. Employers in the U.S. federal and defense space tend to specify CISSP by name because of the DoD 8140.03 approval; CISM shows up more often in enterprise GRC and audit-adjacent roles. Neither is strictly "harder" — they measure overlapping but distinct things, and some security leaders end up holding both.
Preparation Timeline
Most working professionals report spending three to five months of study, roughly 150 to 300 hours total, though this varies enormously based on how much of the CBK you've already absorbed on the job. Someone who has spent years in security architecture will move faster through Domains 3 and 4 and slower through Domain 1's legal and governance material; someone from a GRC background will find the reverse. A common structure is eight to twelve weeks working through each domain systematically, followed by two to four weeks of practice questions and targeted review of weak areas — with extra attention to Domain 1 given its 16% weight.
Frequently Asked Questions
Same exams as Featured on home
CompTIA
CompTIA Security+
Explore exam
Oracle Cloud
Oracle Cloud Infrastructure Foundations Associate
Explore exam
Amazon Web Services (AWS)
AWS Certified Solutions Architect – Associate
Explore exam
Servicenow
ServiceNow Certified Application Developer
Explore exam
PeopleCert
PRINCE2 Foundation
Explore exam
Information Systems Audit and Control Association (ISACA)
Certified in Risk and Information Systems Control (CRISC)
Explore exam
Google Cloud
Google Cloud Professional Cloud Architect
Explore exam
EC‑Council
Certified Ethical Hacker(CEH)
Explore exam
