CISSP (Certified Information Systems Security Professional)
The CISSP covers designing, engineering and managing an organization's overall security posture. Its eight domains run from risk management to software development security. ISC2 aims it at experienced practitioners, managers and executives such as CISOs, security architects, security managers and auditors.
Exam Details
Computerized Adaptive Testing with multiple choice and advanced item types, taken at ISC2-authorized Pearson VUE test centers (PPC and PVTC).
Standard registration in the Americas, Asia Pacific, Middle East and Africa. ISC2 also lists EUR 719.04 for EMEA and GBP 606.69 for the UK. Currency and taxes depend on the exam location. Rescheduling costs U.S. $50 and cancelling U.S. $100.
Requirements and Renewal
Prerequisites
Five years of cumulative, full-time work experience in two or more of the eight CISSP domains. A relevant degree or one credential from the ISC2 approved list can waive one year, and only one waiver applies. Candidates without the experience can pass the exam and become an Associate of ISC2, with six years to earn the five years of experience.
Renewal
120 CPE credits per three-year cycle (at least 90 Group A, the rest Group A or B) plus a U.S. $135 annual maintenance fee.
Current Version
CISSP Exam Outline effective April 15, 2024, in effect since Apr 15, 2024.
Exam Domains
8 domains| Domain | Weight |
|---|---|
| Security and Risk Management | 16% |
| Asset Security | 10% |
| Security Architecture and Engineering | 13% |
| Communication and Network Security | 13% |
| Identity and Access Management (IAM) | 13% |
| Security Assessment and Testing | 12% |
| Security Operations | 13% |
| Software Development Security | 10% |
DoD 8140 Work Roles
10 work rolesThe DoD 8140 Qualification Matrix V2.1 lists CISSP as a foundational qualification option for these DoD Cyber Workforce Framework work roles, up to the proficiency level shown. Lower levels of the same work role are also covered.
Certification Lists
Related Tool Categories
Compliance automation frameworks, SCAP policy scanners, and risk management platforms.
Secrets managers, identity engines, and access control platforms for managing credentials and privilege.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Frequently Asked Questions
How much does the CISSP exam cost?→
ISC2 lists standard CISSP registration at U.S. $749 in the Americas and Asia Pacific, EUR 719.04 in EMEA and GBP 606.69 in the UK. Taxes depend on where the exam is taken.
Can I take the CISSP without five years of experience?→
Yes. A candidate who passes without the required experience can become an Associate of ISC2 and then has six years to accumulate the five years of experience. Associates pay a U.S. $50 annual fee and earn 15 CPE credits a year.
Which credentials count toward the CISSP experience waiver?→
The ISC2 approved list includes CompTIA Security+, CySA+ and SecurityX, CISM, AWS Certified Security Specialty, CCNP Security and several GIAC certifications, among others. ISC2 revised the list on April 1, 2026, and a waiver reduces the requirement by at most one year.
How long is the CISSP exam and what is the passing score?→
The adaptive exam allows 3 hours for 100 to 150 items. The passing grade is 700 out of 1000 points.
What does CISSP stand for?→
CISSP stands for Certified Information Systems Security Professional, a certification issued by ISC2.
Sources
- CISSP - Certified Information Systems Security Professional
- CISSP Certification Exam Outline
- CISSP Experience Requirements
- CISSP Experience Waiver Updates
- CISSP Exam Refresh FAQ
- ISC2 Exam Pricing
- ISC2 Member Policies (CPE requirements)
- ISC2 Annual Maintenance Fees (AMF)
- Become an Associate of ISC2
- ISC2 Certification Maintenance Handbook
Exam details are checked against official ISC2 pages. Fees, exam versions, and renewal rules change; confirm with ISC2 before registering. CISSP is a trademark of its owner. This site is not affiliated with or endorsed by ISC2.