Skip to content
Getting Digital
ISC2 certificationsISC2 · exam CISSP

Certified Information Systems Security Professional (CISSP)

CISSP is the credential most people mean when they say senior security certification. It spans eight domains at management depth rather than technical depth, and it is deliberately a mile wide.

Three hours, adaptive, and gated behind an experience requirement most candidates underestimate.

Exam facts

Exam code
CISSP
Level
Expert
Field
Cybersecurity
Duration
180 minutes
Questions
100 to 150 items under Computerized Adaptive Testing (English); multiple choice and advanced item types
Passing score
700 out of 1,000 points
Languages
English, German, Chinese, Japanese, SpanishThe German, Chinese, Japanese and Spanish editions run as a linear 6-hour, 250-item form rather than the adaptive English exam; ISC2's outline dates them to May 2021.
Price
749 USD (read 12 September 2026)
Validity
3 years, renewable
Exam delivery
Pearson VUE (test centres only, no online proctoring); membership after passing and having the experience endorsed

Prerequisites: Five years of paid work in two or more of the eight domains (one year waived for a relevant degree or approved credential); with less experience you pass the same exam and become an Associate of ISC2 with up to six years to earn the rest.

Renewal: 120 CPE credits over the three-year cycle (ISC2 suggests 40 a year) plus the 135 USD annual maintenance fee; the exam is not retaken

Source: exam page at ISC2 · Price: ISC2 regional exam pricing (read 2026-09-12): 749 USD Americas, 719.04 EUR EMEA, 606.69 GBP UK; plus 135 USD annual maintenance fee once certified

How to prepare

  1. 1. The vendor's free learning path

    ISC2 publishes the exam objectives and a learning path free of charge — the authoritative source for scope and weighting. Open the learning path (opens in a new tab)

  2. 2. Online courses

    Courses and practice questions from the directory that target exactly this exam — details, price and the provider link (affiliate) are on the course page.

  3. 3. A practice test in the exam format

    MeasureUp sells a practice test for CISSP with questions in the exam format, an explanation for every answer and a timed mode; the price shows in your currency on the shop page. Affiliate link.

    Practice test for CISSP at MeasureUp (opens in a new tab)
  4. Book the exam

    Delivered by Pearson VUE (test centres only, no online proctoring); membership after passing and having the experience endorsed. Schedule with ISC2 (opens in a new tab)

Affiliate disclosure: the course and practice-test links above are affiliate links — buying through them may earn us a commission at no extra cost to you. The vendor's learning path and booking links carry no commission.

Passing the exam does not make you certified

Your positionWhat passing gives youWhat still stands in the way
Five years in two or more domainsThe certification, after endorsementNothing beyond the endorsement step
Four years plus a qualifying degree or credentialThe certification, after endorsementOne year is waived, not two
Some experience, short of the barAssociate of ISC2 statusAccrue the remaining years, then convert
No relevant paid experienceAssociate status onlyThe whole requirement, and the annual fee meanwhile

Adaptive testing changes how it feels

It is meant to feel hard the whole way through

The English exam adapts: answer well and the questions get harder, which means a competent candidate spends most of the sitting feeling uncertain. That is the mechanism working rather than a sign of failure, and candidates who panic at the difficulty and start second-guessing settled answers do worse than those who accept the discomfort. The paper can end well before the maximum number of items, in either direction.

  • English is adaptive: three hours, between 100 and 150 items, and the engine stops when it is sure.
  • German, Chinese, Japanese and Spanish are linear: a six-hour form of 250 items, built to an outline ISC2 dates to May 2021, with every question shown regardless of how you are doing.
  • Every edition passes at 700 of 1,000, and all are sat only at ISC2-authorised Pearson VUE centres, not from home.
  • The choice of language is therefore a choice of format. A German speaker who reads English well should think hard before choosing the six-hour paper.

That list is the part of this exam no course explains. The adaptive engine is why the English sitting ends early for strong and weak candidates alike, why practice-test percentages predict little, and why the felt difficulty is uninformative. The linear editions trade that discomfort for endurance: twice the items, twice the time, and an older outline. Neither is easier. They are different afternoons, and the record's language list hides a decision most candidates never realise they are making.

DomainShare
Security and risk management16 %
Security architecture and engineering13 %
Communication and network security13 %
Identity and access management13 %
Security operations13 %
Security assessment and testing12 %
Asset security10 %
Software development security10 %

What it costs to hold, and why it is never retaken

Once endorsed, the credential lasts three years and is kept by 120 continuing-education credits across the cycle, which ISC2 suggests earning at forty a year, together with a maintenance fee due every year the credential is held. The exam is not sat again. Associates pay a lower annual fee while they accrue the missing years, and have up to six years to do it. The sitting fee is regional, hence three currencies in the cost table, and the endorsement step after a pass requires another certified professional to vouch for the experience you claimed. Eight domains at management depth, the largest of them risk and governance: this credential belongs to the person who will be asked to decide, and it says almost nothing about whether they can configure the thing they decided about.

What a question looks like

Written by us in the exam's style. It is not a real question from any question bank, and we do not publish those.

An organisation discovers that a third-party supplier with network access has suffered a breach. Business operations depend on that supplier and no alternative exists. What should the security manager do first?

Several options are defensible and one is best, which is the characteristic CISSP shape. Technical candidates reach for containment; the exam usually wants the governance move, because the credential is aimed at somebody who decides rather than somebody who executes. Learning to answer as a manager rather than as an engineer is most of the preparation for people already in security.

What it costs to get and to keep

ItemAmountNote
Exam fee, Americas749 USDthe highest single sitting covered on this site; regional pricing differs and ISC2 publishes each separately (read 12 September 2026)
Exam fee, EMEA719 EURISC2's published EMEA figure, which is close to but not a conversion of the Americas price (read 12 September 2026)
Annual maintenance fee135 USDpayable every year you hold the certification, whether or not you learn anything that year. Associates pay a lower annual figure (read 12 September 2026)
Continuing educationnot published120 credits across the three-year cycle, which ISC2 suggests spreading at roughly forty a year. The credits are free to earn and the time is not (read 12 September 2026)

How much preparation, from where you are

You manage security and meet the experience bar
The intended candidate. The work is breadth: the domains you have never owned, typically physical security, software development security and whichever of law and compliance your role avoids.
You are technical and meet the bar
The obstacle is register rather than content. You will know more than the exam asks and answer the wrong way, choosing the fix over the process. Practise reading every question as though you were accountable rather than responsible.
You do not meet the bar yet
Sit it if you want, take Associate status, and be clear that you are paying an annual fee for a credential you cannot yet use. Many people would be better served by an entry certificate and the intervening years of work.

What passing this does not prove

  • Depth in anything. Eight domains in three hours is breadth by construction.
  • Whether you can implement a single one of the controls it asks about.
  • Whether your judgement survives a board that does not want to hear it.
  • Current threats, since the outline moves far more slowly than attackers do.

Against the alternatives

CISMCertified Information Security Manager (CISM)
Narrower and squarely about managing a security programme, where this is broad and partly technical. CISM is the better fit if your work is governance rather than architecture.
SY0-701CompTIA Security+
The entry certificate, years apart from this in what it claims. Anyone weighing the two is asking the wrong question: they mark opposite ends of a career.
SC-300Microsoft Certified: Identity and Access Administrator Associate
A technical identity certificate with no experience gate and a fraction of the cost. Better value for somebody who wants to do the work rather than direct it.

CISSP — quick answers

Can I sit it without the experience?

Yes, and the body awards Associate status instead of the full credential. That status is legitimate and it is not the credential: you pay an annual fee while accruing the remaining years, then convert. Going in knowing that is very different from discovering it afterwards.

How much does it really cost to hold?

The sitting is the visible part. After it comes an annual maintenance fee every year you keep the certification, plus 120 continuing-education credits per three-year cycle. Over a decade the upkeep exceeds the exam, which is true of every credential from these bodies and is almost never in the comparison people make.

Why does it feel so hard while I am sitting it?

Because the English exam is adaptive and calibrates upward when you answer well. Sustained difficulty is the expected experience for a candidate who is passing. Candidates who interpret it as failure and start revisiting settled answers lose marks they had already earned.

Is it worth it for a technical role?

It is recognised everywhere and it is not a technical credential. If you want to be trusted with architecture and policy decisions, it opens doors. If you want to be better at the work itself, the money buys considerably more elsewhere, and the annual fee continues either way.

Should I sit it in German?

Only if reading three hours of dense English would genuinely cost you marks. The German edition is a linear six-hour form of 250 items built to an older outline, not an adaptive three-hour one, so choosing the language changes the exam you sit. Many German-speaking candidates who work in English choose the English paper for the shorter day.

What comes next

Concepts this exam draws on

Glossary entries with the reason each one matters for CISSP.

  • SSL/TLS

    Security architecture and engineering: cryptography, PKI and secure channels.

  • Security Risk Assessment

    Security and risk management is the largest domain, and risk analysis is its core.

  • Encryption

    Security architecture and engineering covers cryptographic systems and their lifecycle.

  • PKI

    Certificates, authorities and key management sit in the architecture domain.

  • IAM

    A domain of its own, weighted equally with architecture and operations.

  • Least Privilege

    Applied across the access-management and operations domains as a design principle.

  • Zero Trust

    Modern architecture questions expect the model rather than the perimeter.

  • Incident Response

    Security operations covers investigations, response and recovery at management depth.

  • Threat Modelling

    Secure design in the architecture domain starts with modelling threats to a system.

A vendor certificate — not a degree and not an accredited qualification. Facts are from the vendor's exam page on the date shown; prices are list prices that vary by country and tax.

Last reviewed 12 September 2026 · Getting Digital