All Exam Questions

CISSP Exam: Official Cost, Format, Domains, and Requirements for 2026

Official details for Certified Information Systems Security Professional (CISSP) Exam Information Guide 2026 as published by the certification body.

Exam code
CISSP
Duration
3 hours
Cost
$749 USD
Certification body
International Information System Security Certification Consortium (ISC2)
Validity
Does not expire

What This CISSP Exam Actually Certifies

The Certified Information Systems Security Professional(CISSP)  doesn't test whether you can configure a firewall or write a Python script. It tests whether you can think like someone accountable for an entire security program — someone who has to weigh a control's cost against the risk it mitigates, decide who owns an exception, and defend that decision to a board. ISC2 built the exam around eight domains it calls the Common Body of Knowledge (CBK), and passing means you've demonstrated competence across all eight, not just excelled in a couple.

That breadth is the point and also the frustration for a lot of candidates. Someone who has spent a decade doing hands-on penetration testing can still fail the CISSP, not because they don't understand security, but because the exam keeps asking "what would you do as a manager," and their instinct is to answer as an engineer.

Who This CISSP Exam Is For (and Who It's Not For)

ISC2 designed this for people already working in security leadership or on their way there: security managers, architects, consultants, and directors who need a credential that signals they can run a program, not just execute a task. It's also one of the few certifications the U.S. Department of Defense recognizes under DoDM 8140.03 for cybersecurity roles, which is a large part of why it shows up as a requirement in government and defense contractor job postings.

It's a poor fit for someone early in their career. The five-year experience requirement isn't a suggestion — ISC2 checks it during endorsement, and candidates who pass the exam without the experience become an "Associate of ISC2" instead of a full CISSP until they accumulate the required time. If you're two years into IT and want a credential that opens doors now, Security+ or ISC2's own Certified in Cybersecurity (CC) will get you further, faster.

CISSP Exam Format and Structure

The English-language exam runs on Computerized Adaptive Testing, which changes the psychological experience more than most study guides admit. You get 100 to 150 items and up to three hours, but you can't skip a question or go back to change an earlier answer — the system picks your next question based on how you did on the last one. Answer well and the exam can end at the 100-question mark; struggle and it keeps going to gather more data, up to the 150-item ceiling.

That one-way structure means a rough patch early in the test carries more weight than it would on a traditional fixed-form exam, and it's the biggest single source of CISSP exam anxiety. Non-English versions (Simplified Chinese, German, Japanese, Spanish) don't use CAT — they're longer, fixed-form exams with more total items and more time, since ISC2 hasn't built adaptive item pools in every supported language yet.

Domains and Weightings

ISC2 refreshed the domain weights effective April 15, 2024, based on its triennial job task analysis, and that version is still current heading into 2026. Domain 1 carries the heaviest weight and sets the tone for the rest of the exam — it's where the "think like a manager" expectation is most explicit.

Domain

Weight

1. Security and Risk Management

16%

2. Asset Security

10%

3. Security Architecture and Engineering

13%

4. Communication and Network Security

13%

5. Identity and Access Management (IAM)

13%

6. Security Assessment and Testing

12%

7. Security Operations

13%

8. Software Development Security

10%

Candidates coming from a technical background often over-index on Domains 3, 4, and 7 because the material feels familiar, and under-study Domain 1 because governance and legal topics feel abstract. That's backwards given the weighting — Domain 1 alone is worth more than Domains 2 and 8 combined.

Since 2025, ISC2 has also woven AI-specific content into all eight domains rather than adding a standalone AI domain — governance of machine learning models in Domain 1, protecting training data in Domain 2, defending against prompt injection in Domain 3, securing AI agent identities in Domain 5, and so on. It's not a separate section to study; it's a lens applied across the existing material.

Cost Breakdown

The standard exam fee is $749 USD, though ISC2 adjusts regional pricing and local taxes apply outside the U.S. That fee buys one attempt with a 365-day scheduling window. ISC2 also sells an "Exam with Peace of Mind Protection" bundle that gives two attempts within a 180-day window for less than the cost of two separate registrations — worth considering if you're not confident about a first-pass, since a straight retake after a fail costs the full $749 again and requires a 30-day waiting period.

The fee most first-time candidates forget to budget for isn't the exam itself — it's what comes after. Once certified, you owe a $135 Annual Maintenance Fee (AMF) every year the credential stays active, plus 120 Continuing Professional Education (CPE) credits across each three-year cycle, split into 90 "Group A" (directly security-related) and 30 "Group B" (broader professional development) credits.

Prerequisites and Eligibility

You need five cumulative years of paid, full-time work experience across at least two of the eight CISSP domains. A relevant bachelor's or master's degree, or one credential from ISC2's approved list, can waive one of those five years — but only one waiver applies, no matter how many qualifying credentials or degrees you hold. Part-time work (20–34 hours per week) counts on a pro-rated basis, and both paid and unpaid internships qualify if documented on official letterhead.

If you pass the exam without the required experience, you don't fail outright — you become an Associate of ISC2 and have six years to accumulate the experience and earn full CISSP status.

How the Exam Is Scored and What Passing Requires

Because the CAT format adjusts question difficulty in time, your raw number of correct answers doesn't map directly to a percentage the way it might on a fixed-form test. ISC2 scales results to a 0–1000 point range, and you need 700 to pass. You'll get a preliminary pass/fail result on-screen immediately after finishing, with an official score report following by email — typically within a few weeks, once ISC2 completes item analysis and any post-exam review.

Renewal and Recertification

The CISSP itself doesn't expire on a fixed timeline the way some vendor certifications do — there's no "version 2026" you're forced to retake. What keeps it active is the combination above: paying the $135 AMF annually and logging 120 CPE credits every three years. Miss either one and ISC2 can suspend or revoke the credential, at which point reinstatement typically means paying back fees and, in some cases, retaking the exam.

How This CISSP Exam Compares to CISM

The most common alternative candidates weigh against the CISSP is ISACA's Certified Information Security Manager (CISM). The practical difference: CISSP tests broader technical-plus-managerial knowledge across eight domains, while CISM leans more heavily into governance, risk, and program management with less depth on architecture and engineering topics. Employers in the U.S. federal and defense space tend to specify CISSP by name because of the DoD 8140.03 approval; CISM shows up more often in enterprise GRC and audit-adjacent roles. Neither is strictly "harder" — they measure overlapping but distinct things, and some security leaders end up holding both.

Preparation Timeline

Most working professionals report spending three to five months of study, roughly 150 to 300 hours total, though this varies enormously based on how much of the CBK you've already absorbed on the job. Someone who has spent years in security architecture will move faster through Domains 3 and 4 and slower through Domain 1's legal and governance material; someone from a GRC background will find the reverse. A common structure is eight to twelve weeks working through each domain systematically, followed by two to four weeks of practice questions and targeted review of weak areas — with extra attention to Domain 1 given its 16% weight.

Frequently Asked Questions