Cybersecurity

CISSP (ISC2)

expert

Certified Information Systems Security Professional

By The Exam Atlas Editorial Team · Verified 2026-05-29

Free CISSP practice questions 273 questions with full answer explanations. No sign-up. Start practice →

Overview

CISSP is the best-known senior cybersecurity certification. It is broad rather than deep: the eight-domain Common Body of Knowledge spans risk management, architecture, operations, identity, and software security, viewed from a manager's perspective.

CISSP is not an entry-level exam. It requires five years of relevant paid experience to become fully certified (you can pass first and become an Associate of ISC2 while you accrue experience). It is frequently required for security leadership and government roles.

✓ Who it is for

  • Experienced security professionals moving into management
  • Security architects and senior analysts
  • People targeting roles that list CISSP as a requirement
  • Mid-career practitioners who want a broad, vendor-neutral signal across the eight security domains
  • Government and defence contractors meeting DoD 8140 / 8570 IAT and IAM requirements

✕ Who it is not for

  • Newcomers to security - CISSP needs five years of paid experience to certify (you can pass first as an Associate of ISC2).
  • Hands-on specialists who want deep tooling skills rather than broad management-level breadth.
  • Anyone needing a quick, cheap credential - this is a long, senior, costly exam.

Exam structure

Security and Risk Management16%
Asset Security10%
Security Architecture and Engineering13%
Communication and Network Security13%
Identity and Access Management (IAM)13%
Security Assessment and Testing12%
Security Operations13%
Software Development Security10%

How the exam is weighted

  • Security & Risk Management 16%
  • Asset Security 10%
  • Security Architecture & Engineering 13%
  • Communication & Network Security 13%
  • Identity & Access Management 13%
  • Security Assessment & Testing 12%
  • Security Operations 13%
  • Software Development Security 10%
Approximate official domain weighting - confirm the current split in the official exam objectives. Verified 2026-05-29.

What each domain covers

Security & Risk Management
CIA & governance · Compliance & legal · Risk management · Policies & security awareness
Asset Security
Information classification · Data lifecycle & handling · Data roles & retention
Security Architecture & Engineering
Secure design principles · Cryptography · Physical security
Communication & Network Security
Secure network architecture · Secure protocols · Network components
Identity & Access Management
Identity lifecycle · Authentication & SSO · Authorization models
Security Assessment & Testing
Assessment strategies · Security testing · Audits & logging
Security Operations
Investigations & monitoring · Incident management · Disaster recovery & BCP
Software Development Security
Secure SDLC · Security in dev tooling · Assessing software security

Realistic study time

  • Experienced security pro (5+ yrs) 60-100 hours over 2-3 months
  • Mid-level, some domains new 120-180 hours over 3-5 months
  • Career changer 200+ hours; consider Security+ first

Bars show relative effort, not a guarantee. Your time depends on background and study method.

Turn this into a week-by-week schedule with the Study Plan Generator.

What it really costs

Exam fee US$749
Retake Full fee again after a waiting period
Study materials US$0-400 free outlines to paid books/courses
ISC2 annual maintenance fee ~US$135 / year to keep the cert active

Fees change and vary by region. Confirm the current amount on the official site before you register.

Want your full out-of-pocket figure? Try the Cost Calculator.

Salary & career value

Indicative ranges for orientation only - not surveyed data, and not financial or career advice. Sources and date below.

CISSP is one of the highest-paid security credentials. In the US, roles that list it commonly report roughly US$120k-190k, with architect/senior roles higher. Outside the US the absolute figures are lower, but holders consistently report a premium over non-certified peers.

Pass rate: Not published. ISC2 does not release an official CISSP pass rate, so the figures you see quoted online are unofficial estimates, not verified data. The known benchmark is the passing standard itself: a scaled score of 700 out of 1000 on the adaptive exam.

Security Analyst / Engineer ~$100k-140k
GRC / Risk Lead ~$110k-150k
Information Security Manager ~$120k-160k
Security Architect ~$140k-190k
CISO (with experience) ~$180k-250k+

Indicative annual pay (USD), each role's typical band on a shared scale.

Other markets (indicative)

United Kingdom~£55k-90k
Canada~CA$100k-150k
Australia~AU$120k-170k

Jobs that often ask for it:

  • Information Security Manager
  • Security Architect
  • Security Consultant
  • GRC / Risk Analyst
  • CISO (with experience)

Is it worth it?

For mid-to-senior security careers, CISSP is one of the highest-return certifications and is often a hard requirement for leadership and cleared roles. It is not worth rushing into early: without the five years of experience you can only hold Associate status, and the management-level material is hard to absorb without context.

Not sure this is the right exam for you? Compare your options with the Exam Finder.

Our specialty · side by side

Compare CISSP with other exams

Independent, like-for-like comparisons to help you choose the right one.

Where it leads

Career paths featuring CISSP

What to do next

Already certified? Add a concentration (ISSAP/ISSEP/ISSMP), or compare CISSP with CISM to move toward security management. See the Cybersecurity Analyst career path.

On exam day

Delivered at Pearson VUE test centres as a Computerised Adaptive Test: 100-150 questions in up to 3 hours, adapting to your answers. Bring two valid IDs and arrive ~30 minutes early.

Keeping your certification

Maintained on a 3-year cycle: earn 120 CPE credits (40 minimum per year) and pay the ISC2 annual maintenance fee (~US$135). Let it lapse and you may have to re-sit.

FAQ

Can I take CISSP without experience?
You can sit and pass the exam, then become an Associate of ISC2 and have up to six years to earn the required five years of experience. Full CISSP status requires the experience.
Is CISSP harder than Security+?
Yes, considerably. Security+ is entry level; CISSP is an expert, management-oriented exam covering eight broad domains. Most candidates study three to six months.
How do I keep CISSP valid?
Earn Continuing Professional Education (CPE) credits and pay the annual maintenance fee. The cycle is three years.
Is CISSP worth it in 2026?
For experienced security professionals moving into senior, architect or management roles, yes - it is high signal and frequently a hard requirement. For beginners it is premature; earn Security+ first and target CISSP later.
Can I self-study for CISSP?
Yes. Most candidates self-study using the official outline, a standard guide and practice questions. What you cannot shortcut is the five years of real experience CISSP certifies.
What jobs can CISSP help me get?
Security manager, security architect, security consultant, GRC and risk roles, and it is common on the path toward CISO. It is rarely required for entry-level jobs.
How much does CISSP cost in total?
Budget the US$749 exam fee, optional materials (free outlines up to a few hundred dollars for courses), and the ISC2 annual maintenance fee of around US$135 to keep it active.

Related exams

Free study resources

Sources