Certified Information Systems Security Professional (CISSP)
CISSP is the credential most people mean when they say senior security certification. It spans eight domains at management depth rather than technical depth, and it is deliberately a mile wide.
Three hours, adaptive, and gated behind an experience requirement most candidates underestimate.
Exam facts
- Exam code
- CISSP
- Level
- Expert
- Field
- Cybersecurity
- Duration
- 180 minutes
- Questions
- 100 to 150 items under Computerized Adaptive Testing (English); multiple choice and advanced item types
- Passing score
- 700 out of 1,000 points
- Languages
- English, German, Chinese, Japanese, SpanishThe German, Chinese, Japanese and Spanish editions run as a linear 6-hour, 250-item form rather than the adaptive English exam; ISC2's outline dates them to May 2021.
- Price
- 749 USD (read 12 September 2026)
- Validity
- 3 years, renewable
- Exam delivery
- Pearson VUE (test centres only, no online proctoring); membership after passing and having the experience endorsed
Prerequisites: Five years of paid work in two or more of the eight domains (one year waived for a relevant degree or approved credential); with less experience you pass the same exam and become an Associate of ISC2 with up to six years to earn the rest.
Renewal: 120 CPE credits over the three-year cycle (ISC2 suggests 40 a year) plus the 135 USD annual maintenance fee; the exam is not retaken
Source: exam page at ISC2 · Price: ISC2 regional exam pricing (read 2026-09-12): 749 USD Americas, 719.04 EUR EMEA, 606.69 GBP UK; plus 135 USD annual maintenance fee once certified
How to prepare
1. The vendor's free learning path
ISC2 publishes the exam objectives and a learning path free of charge — the authoritative source for scope and weighting. Open the learning path (opens in a new tab)
2. Online courses
Courses and practice questions from the directory that target exactly this exam — details, price and the provider link (affiliate) are on the course page.
- Practice testsCISSP Certification: 4 Top-Notch Practice Exams for Success
- Preparation courseCISSP Certification: Domains 1, 2, 3 & 4 Video Training-2025
- Preparation courseCISSP Certification: Domains 5, 6, 7 & 8 Video Training-2025
- Practice testsCISSP Practice Tests- 900 questions
- Practice testsCISSP practice questions #1 - ALL CISSP domains 250 Q - 2025
3. A practice test in the exam format
MeasureUp sells a practice test for CISSP with questions in the exam format, an explanation for every answer and a timed mode; the price shows in your currency on the shop page. Affiliate link.
Practice test for CISSP at MeasureUp (opens in a new tab)Book the exam
Delivered by Pearson VUE (test centres only, no online proctoring); membership after passing and having the experience endorsed. Schedule with ISC2 (opens in a new tab)
Affiliate disclosure: the course and practice-test links above are affiliate links — buying through them may earn us a commission at no extra cost to you. The vendor's learning path and booking links carry no commission.
Passing the exam does not make you certified
| Your position | What passing gives you | What still stands in the way |
|---|---|---|
| Five years in two or more domains | The certification, after endorsement | Nothing beyond the endorsement step |
| Four years plus a qualifying degree or credential | The certification, after endorsement | One year is waived, not two |
| Some experience, short of the bar | Associate of ISC2 status | Accrue the remaining years, then convert |
| No relevant paid experience | Associate status only | The whole requirement, and the annual fee meanwhile |
Adaptive testing changes how it feels
It is meant to feel hard the whole way through
The English exam adapts: answer well and the questions get harder, which means a competent candidate spends most of the sitting feeling uncertain. That is the mechanism working rather than a sign of failure, and candidates who panic at the difficulty and start second-guessing settled answers do worse than those who accept the discomfort. The paper can end well before the maximum number of items, in either direction.
- English is adaptive: three hours, between 100 and 150 items, and the engine stops when it is sure.
- German, Chinese, Japanese and Spanish are linear: a six-hour form of 250 items, built to an outline ISC2 dates to May 2021, with every question shown regardless of how you are doing.
- Every edition passes at 700 of 1,000, and all are sat only at ISC2-authorised Pearson VUE centres, not from home.
- The choice of language is therefore a choice of format. A German speaker who reads English well should think hard before choosing the six-hour paper.
That list is the part of this exam no course explains. The adaptive engine is why the English sitting ends early for strong and weak candidates alike, why practice-test percentages predict little, and why the felt difficulty is uninformative. The linear editions trade that discomfort for endurance: twice the items, twice the time, and an older outline. Neither is easier. They are different afternoons, and the record's language list hides a decision most candidates never realise they are making.
| Domain | Share |
|---|---|
| Security and risk management | 16 % |
| Security architecture and engineering | 13 % |
| Communication and network security | 13 % |
| Identity and access management | 13 % |
| Security operations | 13 % |
| Security assessment and testing | 12 % |
| Asset security | 10 % |
| Software development security | 10 % |
What it costs to hold, and why it is never retaken
Once endorsed, the credential lasts three years and is kept by 120 continuing-education credits across the cycle, which ISC2 suggests earning at forty a year, together with a maintenance fee due every year the credential is held. The exam is not sat again. Associates pay a lower annual fee while they accrue the missing years, and have up to six years to do it. The sitting fee is regional, hence three currencies in the cost table, and the endorsement step after a pass requires another certified professional to vouch for the experience you claimed. Eight domains at management depth, the largest of them risk and governance: this credential belongs to the person who will be asked to decide, and it says almost nothing about whether they can configure the thing they decided about.
What a question looks like
Written by us in the exam's style. It is not a real question from any question bank, and we do not publish those.
An organisation discovers that a third-party supplier with network access has suffered a breach. Business operations depend on that supplier and no alternative exists. What should the security manager do first?
Several options are defensible and one is best, which is the characteristic CISSP shape. Technical candidates reach for containment; the exam usually wants the governance move, because the credential is aimed at somebody who decides rather than somebody who executes. Learning to answer as a manager rather than as an engineer is most of the preparation for people already in security.
What it costs to get and to keep
| Item | Amount | Note |
|---|---|---|
| Exam fee, Americas | 749 USD | the highest single sitting covered on this site; regional pricing differs and ISC2 publishes each separately (read 12 September 2026) |
| Exam fee, EMEA | 719 EUR | ISC2's published EMEA figure, which is close to but not a conversion of the Americas price (read 12 September 2026) |
| Annual maintenance fee | 135 USD | payable every year you hold the certification, whether or not you learn anything that year. Associates pay a lower annual figure (read 12 September 2026) |
| Continuing education | not published | 120 credits across the three-year cycle, which ISC2 suggests spreading at roughly forty a year. The credits are free to earn and the time is not (read 12 September 2026) |
How much preparation, from where you are
- You manage security and meet the experience bar
- The intended candidate. The work is breadth: the domains you have never owned, typically physical security, software development security and whichever of law and compliance your role avoids.
- You are technical and meet the bar
- The obstacle is register rather than content. You will know more than the exam asks and answer the wrong way, choosing the fix over the process. Practise reading every question as though you were accountable rather than responsible.
- You do not meet the bar yet
- Sit it if you want, take Associate status, and be clear that you are paying an annual fee for a credential you cannot yet use. Many people would be better served by an entry certificate and the intervening years of work.
What passing this does not prove
- Depth in anything. Eight domains in three hours is breadth by construction.
- Whether you can implement a single one of the controls it asks about.
- Whether your judgement survives a board that does not want to hear it.
- Current threats, since the outline moves far more slowly than attackers do.
Against the alternatives
- CISM — Certified Information Security Manager (CISM)
- Narrower and squarely about managing a security programme, where this is broad and partly technical. CISM is the better fit if your work is governance rather than architecture.
- SY0-701 — CompTIA Security+
- The entry certificate, years apart from this in what it claims. Anyone weighing the two is asking the wrong question: they mark opposite ends of a career.
- SC-300 — Microsoft Certified: Identity and Access Administrator Associate
- A technical identity certificate with no experience gate and a fraction of the cost. Better value for somebody who wants to do the work rather than direct it.
CISSP — quick answers
Can I sit it without the experience?
Yes, and the body awards Associate status instead of the full credential. That status is legitimate and it is not the credential: you pay an annual fee while accruing the remaining years, then convert. Going in knowing that is very different from discovering it afterwards.
How much does it really cost to hold?
The sitting is the visible part. After it comes an annual maintenance fee every year you keep the certification, plus 120 continuing-education credits per three-year cycle. Over a decade the upkeep exceeds the exam, which is true of every credential from these bodies and is almost never in the comparison people make.
Why does it feel so hard while I am sitting it?
Because the English exam is adaptive and calibrates upward when you answer well. Sustained difficulty is the expected experience for a candidate who is passing. Candidates who interpret it as failure and start revisiting settled answers lose marks they had already earned.
Is it worth it for a technical role?
It is recognised everywhere and it is not a technical credential. If you want to be trusted with architecture and policy decisions, it opens doors. If you want to be better at the work itself, the money buys considerably more elsewhere, and the annual fee continues either way.
Should I sit it in German?
Only if reading three hours of dense English would genuinely cost you marks. The German edition is a linear six-hour form of 250 items built to an older outline, not an adaptive three-hour one, so choosing the language changes the exam you sit. Many German-speaking candidates who work in English choose the English paper for the shorter day.
What comes next
Concepts this exam draws on
Glossary entries with the reason each one matters for CISSP.
- SSL/TLS
Security architecture and engineering: cryptography, PKI and secure channels.
- Security Risk Assessment
Security and risk management is the largest domain, and risk analysis is its core.
- Encryption
Security architecture and engineering covers cryptographic systems and their lifecycle.
- PKI
Certificates, authorities and key management sit in the architecture domain.
- IAM
A domain of its own, weighted equally with architecture and operations.
- Least Privilege
Applied across the access-management and operations domains as a design principle.
- Zero Trust
Modern architecture questions expect the model rather than the perimeter.
- Incident Response
Security operations covers investigations, response and recovery at management depth.
- Threat Modelling
Secure design in the architecture domain starts with modelling threats to a system.
Last reviewed 12 September 2026 · Getting Digital
