Certified Information Systems Security Professional (CISSP) Exam Guide
At a glance
- Time limit
- 3h
- Passing score
- 700/1000
- Exam fee
- $749
- Governing body
- ISC2
The Certified Information Systems Security Professional (CISSP) is a globally recognized credential for experienced cybersecurity professionals. It validates expertise across eight domains of information security and is ideal for those seeking senior roles in security architecture, governance, or compliance. The credential demonstrates commitment to ethical practices and deep technical knowledge of security principles.
The CISSP exam covers eight distinct domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security. Each domain represents a critical area of security practice, from policy and governance to technical implementation and incident response.
The standard CISSP examination registration fee is U.S. $749. This covers the computerized adaptive testing experience at a Pearson VUE test center. Additional fees apply for cancellations ($100) and rescheduling ($50) if you need to modify your exam appointment.
The CISSP exam uses Computerized Adaptive Testing (CAT) and contains 100 to 150 questions. The passing score is 700 out of 1000 points. The adaptive format adjusts question difficulty based on your responses, allowing the exam to efficiently assess your competency level across the eight domains.
Frequently asked questions
How much does the CISSP exam cost, and what are the reschedule and cancellation fees?
The standard CISSP examination registration fee is U.S. $749. If you need to move your appointment, ISC2 charges a rescheduling fee of U.S. $50, and canceling an appointment carries a cancellation fee of U.S. $100. Because rescheduling is far cheaper than canceling, it's generally worth moving your date rather than canceling outright if your plans change.
What score do I need to pass the CISSP, and how is the exam delivered?
You need a scaled score of 700 out of 1000 points to pass. The English-language exam uses Computerized Adaptive Testing (CAT) and contains 100 to 150 questions, meaning the number of items you see depends on how you're performing as you go. Because it's adaptive, the passing bar is fixed at 700 while the exact set of questions is tailored to each candidate, so you can't count on a set number of items in advance.
What work experience do I need to become a CISSP, and what if I don't have it yet?
You need a minimum of 5 years of cumulative, full-time paid work experience in two or more of the eight domains of the current CISSP Exam Outline. A relevant degree or approved credential may satisfy 1 year of that requirement, reducing it to four years. If you pass the exam but don't yet have the experience, you can become an Associate of ISC2, which gives you 6 years to earn the five years of required experience — a practical path if you're early in your security career.
How many domains does the CISSP cover, and which ones carry the most weight?
The CISSP exam is organized into 8 domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security. The domains are not weighted equally — Security and Risk Management is the largest at 16%, followed by a cluster at 13% each (Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, and Security Operations), Security Assessment and Testing at 12%, and Asset Security and Software Development Security at 10% each. Because Domain 1 alone is 16% of the exam, prioritizing your study time toward the higher-weighted domains can improve your odds of hitting the passing score.