CISSP Exam Guide 2026: Domains, Format, Eligibility and Prep
A practical CISSP exam guide for 2026: the eight ISC2 domains, CAT exam format, experience rules, the Associate of ISC2 path and a realistic way to prepare.
At a glance
| Awarding body | ISC2 |
|---|---|
| Domains | Eight, from Security and Risk Management to Software Development Security |
| Format | English exam uses adaptive testing (CAT); check current outline |
| CAT rules | No skipping or going back to change answers |
| Experience | Five years paid work in two or more domains |
| No experience yet | Pass to become an Associate of ISC2 |
| Exam mindset | Think like a risk adviser, not a technician |
The Certified Information Systems Security Professional (CISSP) from ISC2 is one of the best-known cybersecurity certifications in the world. It is aimed at experienced practitioners who design, manage and oversee security programmes, and it is often listed in job adverts for security architects, managers and senior engineers. This CISSP exam guide covers what the certification is, how the exam works, who is eligible and how to prepare without burning out.
What the CISSP certification proves
CISSP is a broad, management-oriented credential. It does not test deep command-line skill in a single technology. Instead, it checks that you can make sound security decisions across an organisation: balancing risk, cost and business goals, and choosing controls that fit the situation. That breadth is why many candidates describe it as "a mile wide and an inch deep", although some topics go deeper than that phrase suggests.
Holders must also follow the ISC2 Code of Ethics, earn continuing professional education (CPE) credits and pay an annual maintenance fee to keep the credential active. Check the ISC2 website for current requirements.
Passing the exam is not the final step. After you pass, you complete an endorsement process and agree to the Code of Ethics before ISC2 awards the credential. It helps to understand this whole lifecycle at the start, so the exam fits into a longer plan for your career rather than being a one-off hurdle.
The eight CISSP domains
The CISSP Common Body of Knowledge (CBK) is organised into eight domains. ISC2 publishes a weighting for each in the exam outline, and it revises the outline from time to time, so always check the current version.
- Security and Risk Management - governance, compliance, risk, policy, business continuity and professional ethics.
- Asset Security - classification, ownership, handling and retention of information and assets.
- Security Architecture and Engineering - secure design principles, models, cryptography and physical security.
- Communication and Network Security - secure network architecture, components and channels.
- Identity and Access Management (IAM) - identification, authentication, authorisation and lifecycle.
- Security Assessment and Testing - audits, testing strategies and analysing results.
- Security Operations - investigations, logging, incident management, recovery and change control.
- Software Development Security - secure development lifecycles and assessing software security.
CISSP exam format
At the time of writing, the English-language CISSP exam uses Computerized Adaptive Testing (CAT). With CAT, each question is chosen based on how you answered the previous ones, and the exam can end once the system is confident whether you have passed or failed. That means the number of questions you see can vary within a range, and the exam has a maximum time limit. Some other languages have used a fixed-form linear format.
ISC2 has changed the question count and duration in recent years, so check the current CISSP exam outline and candidate information before booking. Two practical points apply regardless of the exact numbers:
- You cannot skip questions or go back to change answers in a CAT exam, so you need to commit to each answer.
- Finishing early is not a signal of failure or success; it only means the algorithm has reached a decision.
Eligibility: experience and the Associate of ISC2 path
To become a CISSP, ISC2 has generally required five years of cumulative, paid work experience in two or more of the eight domains. A relevant degree or an approved credential may waive one year. After passing the exam, you also need an endorsement from an existing ISC2 credential holder.
If you do not yet have the experience, you can still sit the exam. Passing without the full experience can make you an Associate of ISC2, which gives you a set period to gain the required experience and then convert to full CISSP. The rules, waivers and time limits are set by ISC2 and can change, so confirm them in the official requirements before you plan around them.
How to prepare for the CISSP exam
Most successful candidates combine broad reading with a lot of question practice and a clear "manager's mindset". A practical approach:
- Baseline yourself. Take a diagnostic set of practice questions across all domains to find your weakest areas.
- Use the official outline as a checklist. Map every sub-topic to a resource, such as the official study guide, and tick it off.
- Study for breadth first, then depth. Your first pass should cover everything; your second pass targets weak domains.
- Practise with explanations. For each question, understand why the best answer is better than the other reasonable options. See how to use practice questions effectively.
- Think like a risk adviser. Many questions reward answers that protect people first, follow policy and address business risk, rather than jumping straight to a technical fix.
- Rehearse under timed conditions. Build the stamina and pacing you need for an adaptive exam you cannot go back through.
How long this takes depends on your background. Someone with broad, recent experience across several domains may need a few months of steady study; someone strong in one area but new to others may need longer. Rather than picking an exam date first, set a target and adjust it based on how you perform on varied, unfamiliar practice questions over several weeks.
Common mistakes to avoid
- Studying only your strongest technical areas and neglecting governance, legal and software topics.
- Treating the exam as a technical test and choosing hands-on fixes over management decisions.
- Relying on question "dumps", which breach ISC2's rules and are frequently inaccurate.
- Booking the exam before you have consistently performed well on varied, unfamiliar practice questions.
How a personal 1-to-1 assistant helps
FoxyCert's CISSP personal 1-to-1 assistant builds a domain-by-domain study plan around your experience and schedule, helps you interpret practice results, explains difficult concepts and scenarios on Telegram, and keeps you on track until you pass. You sit the exam yourself; we help you get ready for it. Comparing options? Browse our security certifications.
Frequently asked questions
Can I take the CISSP exam without five years of experience?
Yes. Candidates without the full experience can sit the exam and, if they pass, may become an Associate of ISC2 while they gain the required experience. Check ISC2's current rules for details.
How many questions are on the CISSP exam?
The English CISSP exam uses Computerized Adaptive Testing, so the number of questions varies within a range set by ISC2. The range and time limit have changed before, so check the current exam outline.
Is CISSP technical or managerial?
It covers technical topics, but the exam mostly tests judgement and risk-based decision-making across eight domains. Many questions reward the answer a security leader or adviser would choose.
Official sources
Other topics
AI CertificationAI GovernanceAIGPAWSCareerCCNACCNPCertificationCISACiscoCISMCISSPCloudCloud ComputingCloud PractitionerCompTIACybersecurityExam DayExam GuideExam IntegrityExam PreparationExam RulesInformation SecurityISACAISC2IT AuditIT CertificationIT Service ManagementITIL 4ITIL Foundation