How Hard Is the CISSP Exam? CAT Format, Passing Score & 8 Domains (2026)

The CISSP is ISC2's flagship credential and one of the most respected certifications in cybersecurity. It's also one of the most misunderstood exams — mostly because of how it's scored. Here's what you're actually up against.

CISSP exam format at a glance

Check the format any study material describes before you trust it. The current exam outline took effect on 15 April 2024. Before that, the English CAT ran 125–175 items over four hours. A great deal of advice still circulating online — including the widely repeated claim that the exam "needs at least 125 questions" — describes the retired format. On the current paper the floor is 100.

What "CAT" actually means

Unlike a fixed exam, Computerized Adaptive Testing adjusts question difficulty based on your answers. Get one right and the next tends to be harder; miss one and it eases off. The algorithm is building a precise estimate of your ability with each item.

Practical consequences:

That last point causes real distress in the car park afterwards. An exam that ends at 100 items tells you the engine was sure. It does not tell you which way.

Why 700 out of 1000 is not 70%

This is the single most misunderstood thing about the CISSP, and it changes how you should read every practice score you get.

Items are weighted by difficulty. A hard item you answer correctly contributes more evidence about your ability than an easy one. Your scaled score reflects the difficulty level at which you answer consistently correctly — not the proportion of questions you got right.

Two consequences follow:

  1. There is no count of correct responses that guarantees a pass. Two candidates can answer the same number correctly and score differently, because they saw items of different difficulty.
  2. A practice percentage is a weak proxy. Scoring 72% on a bank of easy questions tells you very little. Scoring 65% on a bank pitched at exam difficulty tells you rather more.

Because you cannot see item difficulty, the useful signal is not your overall percentage but which domains you are consistently weak in — that is the thing you can actually act on.

The eight CISSP domains (and weights)

The CISSP Common Body of Knowledge (CBK) spans eight domains:

Domain Weight
Security and Risk Management 16%
Asset Security 10%
Security Architecture and Engineering 13%
Communication and Network Security 13%
Identity and Access Management (IAM) 13%
Security Assessment and Testing 12%
Security Operations 13%
Software Development Security 10%

The weighting is unusually flat — no single domain dominates, which is exactly why breadth is the challenge. Compare it with CISA or CISM, where two domains carry roughly two-thirds of the paper and you can rationally prioritise. On CISSP there is nowhere to hide: the smallest domain is still one item in ten.

Security and Risk Management deserves slightly more attention than its 16% suggests, because its mindset — risk-based, business-aligned decision-making — is the lens the other seven domains are graded through.

What makes CISSP hard

  1. It's a mile wide. Eight domains span risk, cryptography, networking, IAM, secure development, and operations. Few people are strong in all eight.
  2. "Think like a manager." CISSP rewards risk-based, business-aligned answers over the most technically aggressive option. The "best" answer is often the one that protects the organization's interests, not the coolest control.
  3. The CAT format is unforgiving of careless early mistakes and rewards consistency.
  4. You cannot review. Exams that let you flag and revisit forgive a misread stem. This one does not.

Where candidates actually lose marks

In practice, failures cluster in a few recognisable places:

Passing is not the end of it

Two things surprise candidates after the exam.

The experience requirement. Certification needs five years of cumulative paid work experience in at least two of the eight domains. A relevant four-year degree or an approved credential can cover one of those years. If you pass without the experience, you become an Associate of ISC2 and have six years to earn it — a real credential you can put on a CV in the meantime, but not the CISSP.

Endorsement. Your application must be endorsed by another ISC2-certified professional within nine months of passing, and ISC2 may audit it. You also agree to the ISC2 Code of Ethics, pay an annual maintenance fee, and earn continuing professional education credits to stay certified.

Plan for these before exam day. Finding an endorser is much easier when you have not left it until month eight.

How to prepare

Because CISSP is adaptive and broad, you want to find and close your weakest domains before exam day:

Review the questions you got right for the wrong reason, too. On an adaptive exam a lucky guess at the right difficulty inflates your estimate of yourself, which is the one thing you cannot afford.

That's the CertPrepX approach — a readiness score per domain so "ready" is a measurement, not a feeling.

See the full CISSP exam prep guide, or start free practice.

Sources

Format, scoring and experience requirements on this page were read from ISC2's own published material. Last verified 25 August 2026.

Frequently asked questions

What is a passing CISSP score? 700 out of 1000 on the scaled CAT score. It does not map to a simple percentage of questions correct, because items are weighted by difficulty.

How many questions are on the CISSP CAT? Between 100 and 150 items; the exam ends when the algorithm is confident in your result. Material claiming 125–175 items describes the format retired in April 2024.

Does finishing early mean I passed? No. The exam ends as soon as the engine is statistically confident either way. Early endings happen to strong and weak candidates alike.

How long should I study for the CISSP? Most candidates spend 3–6 months given the breadth — though experienced practitioners move faster. Plan backwards from your exam date and prioritize weak domains.

Can I take the CISSP without five years of experience? Yes. You sit the same exam and, on passing, become an Associate of ISC2 with six years to earn the required experience.

Know exactly when you're ready to pass

Adaptive practice, full-length mock exams, and a readiness score for CISA, CISM, CISSP, PMP, ISO 27001 and AAIA.

Start free practice

Related exam guide

More from the blog