ExamDetail Logo
HomeExamsCertificationCISSP Certification Exam Guide: Fees, CAT Format, Syllabus & Passing Score
Cybersecurity

CISSP Certification Exam Guide: Fees, CAT Format, Syllabus & Passing Score

Everything you need to know: Eligibility, application dates, syllabus, and official notification for 2026.

ongoing

Never Miss an Update!

Get instant notifications for CISSP Certification Exam Guide: Fees, CAT Format, Syllabus & Passing Score dates, admit cards, and results directly on your phone.

Join WhatsApp Channel
Exam: On-Demand Booking
ISC2
Last Updated: 28 August 2026

CISSP Certification (Certified Information Systems Security Professional) — Complete Guide

The Certified Information Systems Security Professional (CISSP), governed by (ISC)², is the undisputed global benchmark for senior cybersecurity leaders, enterprise security architects, and Chief Information Security Officers (CISOs). Accredited under ISO/IEC Standard 17024, it validates advanced managerial and architectural expertise to design, build, and oversee organizational cybersecurity postures.


1. CISSP Exam — At a Glance (Verified 2026)

ParameterOfficial Verified Details
Certifying Body(ISC)² (International Information System Security Certification Consortium)
Exam Fee (Global)$749 USD (Americas / Asia-Pacific)
Exam Fee (India)~₹62,500 INR + 18% GST
Exam Delivery FormatComputerized Adaptive Testing (CAT) (English)
Total Questions100 to 150 Questions (Includes 25 unscored research questions)
Exam Duration3 Hours (180 Minutes)
Passing Score700 / 1000 Points (Scaled Score)
Question NavigationLinear Forward-Only (No going back or reviewing previous answers)
Delivery ProviderPearson VUE Authorized Testing Centers
Experience Requirement5 Years in 2+ Domains (or 4 Years with Degree / Security+ waiver)
Maintenance120 CPE Credits over 3 years + $135 USD Annual Maintenance Fee (AMF)

2. The 8 CISSP CBK Domains & Weightage

The exam evaluates candidate mastery across the eight domains of the (ISC)² Common Body of Knowledge (CBK):

DomainExam WeightageCore Tested Areas
1. Security & Risk Management15%Confidentiality, Integrity, Availability (CIA Triad); Security Governance; Compliance (GDPR, HIPAA, PCI-DSS); Threat Modeling (STRIDE); Business Continuity Planning (BCP); Personnel Security Policies.
2. Asset Security10%Information and Asset Classification; Data States (Data at Rest, in Transit, in Use); Data Ownership (Data Owner, Custodian, Processor); Data Retention and Sanitization (Purging, Degaussing, Destruction).
3. Security Architecture & Engineering13%Security Models (Bell-LaPadula, Biba, Clark-Wilson); Cryptography (Symmetric AES, Asymmetric RSA/ECC, Hashing SHA-256/3); Digital Certificates & PKI; TPM; Physical Security controls.
4. Communication & Network Security13%OSI vs TCP/IP models; Secure Network Architecture (Firewalls, DMZ, VLANs, Zero Trust); Microsegmentation; Wireless Security (WPA3 Enterprise); Secure Protocols (IPsec, TLS 1.3, SSH).
5. Identity & Access Management (IAM)13%Authentication (MFA, Biometrics, FAR/FRR); Federation (SAML 2.0, OAuth 2.0, OpenID Connect); Access Control Models (DAC, MAC, RBAC, ABAC); Identity Lifecycle & Provisioning.
6. Security Assessment & Testing12%Vulnerability Assessment; Penetration Testing methodologies; Security Audits (SOC 1, SOC 2 Type II); Log Review and Code Review (SAST vs DAST); Disaster Recovery Testing (Walkthrough, Simulation, Full-interruption).
7. Security Operations13%Incident Response Lifecycle (NIST SP 800-61); Digital Forensics (Chain of Custody); SIEM / SOAR implementations; Patch & Vulnerability Management; High Availability & Disaster Recovery (RTO / RPO).
8. Software Development Security11%Secure Software Development Lifecycle (SSDLC); OWASP Top 10 vulnerabilities; DevSecOps pipeline security; Software supply chain security; Software-defined architectures.

3. How the CISSP CAT (Adaptive Testing) Engine Works

The English CISSP exam does not use a traditional fixed-length questionnaire:

  1. Adaptive Question Difficulty: The exam engine continuously re-evaluates your performance after every question. If you answer correctly, the next question is harder; if incorrectly, the next question is easier.
  2. Stopping Condition:
    • Early Pass: If you consistently demonstrate competence above the 700-point line, the exam can stop as early as Question 100.
    • Early Fail: If your performance is mathematically incapable of reaching 700 within 150 questions, it terminates early at Question 100.
    • Full Length: If your score oscillates near the boundary, you will answer up to the maximum of 150 questions.
  3. Critical Strategy: Because questions cannot be skipped or revised, spend extra care on the first 20–30 questions to establish a high baseline.

4. The "Think Like a Manager" Mindset

The single biggest reason technically brilliant engineers fail CISSP is answering from a technical technician perspective rather than an executive risk-management perspective:

  • Rule 1: Human Life & Safety First: In any scenario involving physical danger, protecting human life ALWAYS overrides system availability or financial data.
  • Rule 2: Don't Fix It Yourself: When an incident happens, the manager does NOT open the terminal to configure firewall rules; the manager informs stakeholders, invokes the incident response plan, and assesses business risk.
  • Rule 3: Cost-Benefit Analysis: Security controls must never cost more than the value of the asset being protected ($ALE \le Cost$).

5. Global Salary Benchmark: CISSP Certified Professionals

Country / RegionMedian Annual SalaryTypical Job Titles
India₹20.0 LPA – ₹48.0 LPALead Enterprise Architect, CISO, Head of InfoSec
United States$145,000 – $195,000Director of Cybersecurity, Principal Security Architect
United Kingdom£85,000 – £120,000Chief Information Security Officer, Security Lead
United Arab Emirates (UAE)AED 360,000 – AED 520,000Head of Cyber Risk & Governance
SingaporeSGD $160,000 – SGD $230,000VP Information Security, Regional Lead

Source: (ISC)² Official Portal: isc2.org

Advertisement

Important Dates

Exam Timeline

Notification ReleasedOngoing (365 Days)
Application StartsOpen Anytime
Application EndsNo Deadline
Exam DateOn-Demand Booking

Eligibility Criteria

Age Limit
Age Criteria

No age limit

Qualification
Education

5 years cumulative paid full-time work experience in 2+ CISSP CBK domains. 1-year waiver available for 4-year degree or approved credential (e.g., Security+ / CEH).

Attempts
Limits

Max 3 attempts in a 12-month period (Attempt 2: 30-day wait; Attempt 3: 60-day wait; Attempt 4: 90-day wait).

Advertisement

How to Apply

Follow this step-by-step guide to fill the CISSP Certification Exam Guide: Fees, CAT Format, Syllabus & Passing Score application form correctly.

Documents Required

  • Scanned Passport Size Photo (20-50kb, JPG)
  • Scanned Signature (10-20kb, JPG)
  • Class 10th & 12th Marksheets
  • Category Certificate (if applicable)

Syllabus & Pattern

Download Official Syllabus

The detailed syllabus and exam pattern are available in the official notification PDF.

Download Notification PDF

Frequently Asked Questions

Official Links & Resources

Apply Online / Registration

https://home.pearsonvue.com/isc2

Notification / Brochure

Download PDF

Detailed Syllabus

View Syllabus

Past Papers / Mock Tests

Access Papers
Advertisement