How Hard Is the CISSP Exam? CAT Format, Passing Score & 8 Domains (2026)
The CISSP is ISC2's flagship credential and one of the most respected certifications in cybersecurity. It's also one of the most misunderstood exams — mostly because of how it's scored. Here's what you're actually up against.
CISSP exam format at a glance
- Format: Computerized Adaptive Testing (CAT)
- Questions: 100–150 items
- Time limit: 3 hours
- Scoring: Scaled score from 0 to 1000
- Passing score: 700
- Delivery: Computer-based at a test center
Check the format any study material describes before you trust it. The current exam outline took effect on 15 April 2024. Before that, the English CAT ran 125–175 items over four hours. A great deal of advice still circulating online — including the widely repeated claim that the exam "needs at least 125 questions" — describes the retired format. On the current paper the floor is 100.
What "CAT" actually means
Unlike a fixed exam, Computerized Adaptive Testing adjusts question difficulty based on your answers. Get one right and the next tends to be harder; miss one and it eases off. The algorithm is building a precise estimate of your ability with each item.
Practical consequences:
- You can't go back. Once you answer, the next question is chosen based on it. There is no review screen, no flagging, no changing your mind at the end.
- The exam can end anywhere from 100 to 150 items. It stops when the algorithm is confident that you're clearly above or below the passing standard.
- Finishing early isn't necessarily good or bad — it just means the algorithm reached confidence quickly. It reaches confidence quickly for strong candidates and weak ones alike.
That last point causes real distress in the car park afterwards. An exam that ends at 100 items tells you the engine was sure. It does not tell you which way.
Why 700 out of 1000 is not 70%
This is the single most misunderstood thing about the CISSP, and it changes how you should read every practice score you get.
Items are weighted by difficulty. A hard item you answer correctly contributes more evidence about your ability than an easy one. Your scaled score reflects the difficulty level at which you answer consistently correctly — not the proportion of questions you got right.
Two consequences follow:
- There is no count of correct responses that guarantees a pass. Two candidates can answer the same number correctly and score differently, because they saw items of different difficulty.
- A practice percentage is a weak proxy. Scoring 72% on a bank of easy questions tells you very little. Scoring 65% on a bank pitched at exam difficulty tells you rather more.
Because you cannot see item difficulty, the useful signal is not your overall percentage but which domains you are consistently weak in — that is the thing you can actually act on.
The eight CISSP domains (and weights)
The CISSP Common Body of Knowledge (CBK) spans eight domains:
| Domain | Weight |
|---|---|
| Security and Risk Management | 16% |
| Asset Security | 10% |
| Security Architecture and Engineering | 13% |
| Communication and Network Security | 13% |
| Identity and Access Management (IAM) | 13% |
| Security Assessment and Testing | 12% |
| Security Operations | 13% |
| Software Development Security | 10% |
The weighting is unusually flat — no single domain dominates, which is exactly why breadth is the challenge. Compare it with CISA or CISM, where two domains carry roughly two-thirds of the paper and you can rationally prioritise. On CISSP there is nowhere to hide: the smallest domain is still one item in ten.
Security and Risk Management deserves slightly more attention than its 16% suggests, because its mindset — risk-based, business-aligned decision-making — is the lens the other seven domains are graded through.
What makes CISSP hard
- It's a mile wide. Eight domains span risk, cryptography, networking, IAM, secure development, and operations. Few people are strong in all eight.
- "Think like a manager." CISSP rewards risk-based, business-aligned answers over the most technically aggressive option. The "best" answer is often the one that protects the organization's interests, not the coolest control.
- The CAT format is unforgiving of careless early mistakes and rewards consistency.
- You cannot review. Exams that let you flag and revisit forgive a misread stem. This one does not.
Where candidates actually lose marks
In practice, failures cluster in a few recognisable places:
- Answering as the engineer. The scenario describes a vulnerability and the instinct is to pick the strongest technical remedy. The exam usually wants the step that establishes ownership, risk or authorisation first. "Inform management" and "consult the risk owner" feel passive; they are frequently correct.
- Ignoring the qualifier. "BEST", "FIRST" and "MOST" change which of several defensible options is right. Several options usually work — the qualifier decides which one the exam is asking for.
- Depth without breadth. Strong practitioners over-study their own domain and skim the two they find dull. On a flat blueprint that is a losing trade.
- Rushing the early items. Early answers steer the difficulty path. Careless mistakes in the first twenty items cost more than careless mistakes at item ninety.
Passing is not the end of it
Two things surprise candidates after the exam.
The experience requirement. Certification needs five years of cumulative paid work experience in at least two of the eight domains. A relevant four-year degree or an approved credential can cover one of those years. If you pass without the experience, you become an Associate of ISC2 and have six years to earn it — a real credential you can put on a CV in the meantime, but not the CISSP.
Endorsement. Your application must be endorsed by another ISC2-certified professional within nine months of passing, and ISC2 may audit it. You also agree to the ISC2 Code of Ethics, pay an annual maintenance fee, and earn continuing professional education credits to stay certified.
Plan for these before exam day. Finding an endorser is much easier when you have not left it until month eight.
How to prepare
Because CISSP is adaptive and broad, you want to find and close your weakest domains before exam day:
- Practice across all eight domains and watch which ones lag.
- Take full-length, domain-weighted mock exams scored on the 0–1000 scale.
- Use spaced repetition to retain a body of knowledge this large.
- Practise the manager's mindset deliberately. When you get a question wrong, ask whether you answered as the person who would fix the problem rather than the person accountable for deciding about it.
Review the questions you got right for the wrong reason, too. On an adaptive exam a lucky guess at the right difficulty inflates your estimate of yourself, which is the one thing you cannot afford.
That's the CertPrepX approach — a readiness score per domain so "ready" is a measurement, not a feeling.
See the full CISSP exam prep guide, or start free practice.
Sources
Format, scoring and experience requirements on this page were read from ISC2's own published material. Last verified 25 August 2026.
Frequently asked questions
What is a passing CISSP score? 700 out of 1000 on the scaled CAT score. It does not map to a simple percentage of questions correct, because items are weighted by difficulty.
How many questions are on the CISSP CAT? Between 100 and 150 items; the exam ends when the algorithm is confident in your result. Material claiming 125–175 items describes the format retired in April 2024.
Does finishing early mean I passed? No. The exam ends as soon as the engine is statistically confident either way. Early endings happen to strong and weak candidates alike.
How long should I study for the CISSP? Most candidates spend 3–6 months given the breadth — though experienced practitioners move faster. Plan backwards from your exam date and prioritize weak domains.
Can I take the CISSP without five years of experience? Yes. You sit the same exam and, on passing, become an Associate of ISC2 with six years to earn the required experience.