Skip to content

Next edition July 6th, 2026

ISC2 CISSP certification badge
ISC2AdvancedVery High Demand

CISSP

Exam code: CISSP

The gold standard for security management professionals. CISSP validates your ability to design, implement, and manage a best-in-class cybersecurity program.

Daute Delgado, Founder & Bootcamp Director at Unihackers
Written byDaute Delgado· A decade defending airlines, SOCs and international organisationsReviewed by Omar Aboelrous
Exam cost
≈ €644

$749

Exam duration
3 hours
Passing score
700
Salary boost
+38%

Overview

CISSP (Certified Information Systems Security Professional) is the world's premier cybersecurity management certification. Maintained by ISC2, it demonstrates expert knowledge across all aspects of information security.

CISSP is often called the "MBA of cybersecurity" because it:

  • Covers security from a strategic perspective
  • Requires significant work experience
  • Opens doors to leadership positions
  • Is recognized globally across industries

CISSP at the start of 2026

The part nobody warns first-timers about isn't the exam fee, it's the running cost: yes, the exam is still $749 USD (~€690) at Pearson VUE plus regional taxes, but once you pass you're committing to a $135/year Annual Maintenance Fee (or $50 for Associates of ISC2) and 120 CPE credits across every three-year cycle, split 90 Group A and 30 Group B. Plan that into your career budget before you sit. The 8-domain CBK refreshed in April 2024 is still the version on the test in 2026, and the Robert Half 2026 Technology Salary Guide puts US cybersecurity engineers in the $118,500–$190,750 band — the ISC2 2025 Cybersecurity Workforce Study reads that demand for senior CISSP-aligned roles is holding up even where junior hiring has slowed. If you're picking between CISSP and a more practical cert, that "senior" framing is the thing to pay attention to: CISSP is what unlocks the higher band, not the door.

Who Should Get This Certification?

CISSP is designed for experienced security professionals:

  • Security Managers overseeing security programs
  • Security Architects designing enterprise security
  • IT Directors with security responsibilities
  • Security Consultants advising organizations
  • CISOs and aspiring CISOs

Experience requirement: 5 years in 2+ of the 8 CISSP domains. A 4-year degree substitutes 1 year.

Exam Format

The CISSP CAT (Computerized Adaptive Testing) exam:

  • 100-150 questions (adaptive format)
  • 3 hours maximum
  • Passing score: 700 out of 1000
  • English exam is adaptive; other languages have 225 questions in 6 hours

Study Timeline

Experience LevelRecommended Study Time
5+ years security experience8-12 weeks
Adjacent IT experience16-20 weeks
Less experienceConsider Associate of ISC2 path

The 8 CISSP Domains

  1. Security and Risk Management - Governance, compliance, business continuity
  2. Asset Security - Data classification, retention, privacy
  3. Security Architecture - Design principles, cryptography
  4. Network Security - Secure network architecture, protocols
  5. IAM - Access control, identity management
  6. Security Testing - Audits, vulnerability assessments
  7. Security Operations - Incident response, disaster recovery
  8. Software Security - Secure SDLC, application security

Career Impact

CISSP is among the highest-paying IT certifications:

  • Average salary: ~€120,000 ($131,000 USD)
  • 38% salary premium over non-certified peers
  • Required for many senior security roles
  • Often listed as "required" or "strongly preferred" in job postings

Detailed Exam Walkthrough

What to Expect on Exam Day

The English CISSP exam uses Computerized Adaptive Testing (CAT), which adjusts question difficulty based on your performance. You will answer between 100 and 150 questions within 3 hours at a Pearson VUE testing center. If the algorithm determines with statistical confidence that you will pass or fail, the exam can end as early as question 100. If the algorithm remains uncertain, it continues to question 150.

Every question counts equally. There is no penalty for wrong answers. You cannot go back to previous questions; once you submit an answer, it is final. This is a critical difference from most certifications. The questions are scenario-based and require you to think like a security manager, not a technician. You must choose the "best" answer from options that may all seem partially correct.

Time Management Strategy

With a maximum of 150 questions in 180 minutes, you have roughly 72 seconds per question. The CAT format means the first 50 to 75 questions are the most critical, because the algorithm is still calibrating your ability level. Resist the temptation to rush. Read each question fully, identify what is actually being asked (the "stem"), eliminate obviously wrong answers, and choose the most managerial, risk-based response.

If a question confuses you, take your best educated guess and move on. Spending 3 minutes on a single question when you cannot return to it is a poor use of time. Many candidates finish in 100 to 125 questions, so if the exam continues past 125, do not panic; the algorithm may simply need more data points.

Common Mistakes

The number one mistake is answering from a technical perspective rather than a managerial one. CISSP tests whether you can think like a CISO. When a question asks "What should you do FIRST?", the answer is almost never "patch the server" or "run a scan." It is usually "assess the risk," "notify management," or "follow the incident response plan." Think policy before technology, people before tools, prevention before detection.

Another common error is neglecting the "Security and Risk Management" domain, which carries the highest weight (15%) and underpins every other domain.

Study Strategy and Resources

Recommended Study Path

CISSP requires a fundamentally different study approach than technical certifications. Instead of memorizing facts, you must internalize frameworks, processes, and decision-making methodologies. The recommended path is: (1) read a comprehensive study guide cover to cover, (2) take domain-by-domain practice quizzes to identify weak areas, (3) deep-dive into weak domains, (4) take full-length practice exams, (5) review with a "think like a manager" mindset.

Best Resources

Study Guides:

  • "CISSP All-in-One Exam Guide" by Shon Harris and Fernando Maymí (9th Edition) is the gold standard. At 1,400+ pages, it is exhaustive but thorough.
  • "CISSP Study Guide" by Eric Conrad is more concise and better for candidates with strong existing experience.
  • ISC2 Official Study Guide (Sybex) aligns most closely with the actual exam language and is recommended as a primary or secondary reference.

Video Courses:

  • Mike Chapple's LinkedIn Learning CISSP Course covers all 8 domains with a managerial focus.
  • Thor Pedersen's CISSP Course on Udemy (~€14 to €28 / $15 to $30 USD on sale) is highly rated for its conversational teaching style and emphasis on the "why" behind concepts.
  • Kelly Handerhan's "Why You Will Pass the CISSP" (Cybrary) is free and focuses on the managerial mindset needed to interpret questions correctly.

Practice Questions:

  • Boson CISSP Practice Exams (~€91 / $99 USD) are widely considered the most realistic practice questions available.
  • ISC2 Official Practice Tests (Sybex) provide 1,300+ questions organized by domain.
  • CCCure (subscription) offers a massive question bank and is popular among CISSP candidates.

Study Schedule by Background

BackgroundWeekly HoursDurationTotal Hours
5+ years security experience10 to 158 to 12 weeks100 to 150
IT management/adjacent15 to 2016 to 20 weeks250 to 300
Associate path (less experience)15 to 2020 to 24 weeks350 to 400

Study Group Recommendations

CISSP is one of the few certifications where group study significantly improves pass rates. Discussing scenario questions with peers helps you understand different perspectives on "best" answers. Join the ISC2 study groups, local ISSA chapter study sessions, or online communities on Discord and Reddit.

Real World Career Impact

Job Roles That Require CISSP

CISSP is the most requested certification for senior security positions globally. Roles that frequently require it include: Chief Information Security Officer (CISO), Security Director, Security Architect, Security Manager, GRC (Governance, Risk, and Compliance) Director, IT Risk Manager, and Senior Security Consultant. Federal agencies and large enterprises often list CISSP as a non-negotiable requirement.

Salary Data by Region

RegionBefore CISSPAfter CISSPIncrease
United States$95,000$131,000+38%
European UnionEUR 70,000EUR 95,000+36%
United KingdomGBP 65,000GBP 90,000+38%
Remote (global, senior)$100,000$140,000+40%

How Recruiters View CISSP

For leadership and management positions, CISSP is the gold standard credential. It signals that you have both the breadth of knowledge and the years of experience to make strategic security decisions. Many organizations mandate CISSP for anyone at the Director level or above in their security organization. In consulting, CISSP significantly increases your billing rate and credibility with clients.

Career Progression

CISSP is typically earned mid-career and unlocks the path to executive roles. A common trajectory: Security Analyst/Engineer (pre-CISSP), then Security Manager or Architect (with CISSP), then Director of Security or VP of Information Security, then CISO. CISSP holders who combine it with business acumen (MBA, PMP, or CISM) often reach C-suite positions within 5 to 7 years of certification.

Cost Breakdown and ROI

Total Investment 2026

Item2026 Cost
CISSP exam fee~€690 ($749 USD)
Annual Maintenance Fee (full holder)~€124/year ($135 USD)
Annual Maintenance Fee (Associate of ISC2)~€46/year ($50 USD)
Study guide (Shon Harris All-in-One, latest edition)$50 to $65
Practice exams (Boson)$99
Optional: video course (Udemy, on sale)$15 to $30
Optional: ISC2 Official Practice Tests$40
Total (self-study, minimal, year 1)$933 to $998
Total (comprehensive preparation, year 1)$1,038 to $1,068

Renewal Requirements

CISSP requires ongoing maintenance. You must earn 120 Continuing Professional Education (CPE) credits per three-year cycle (40 credits per year) and pay an Annual Maintenance Fee. The AMF is ~€124 ($135 USD) per year for full CISSP holders and ~€46 ($50 USD) per year for Associates of ISC2. Of the 120 CPE credits, 90 must be Group A credits (directly relevant to the eight CISSP domains) and 30 may be Group B credits (general professional development). CPE credits can be earned through: attending conferences, completing training courses, publishing security research, participating in ISC2 webinars (free), volunteering for ISC2 chapters, and mentoring other professionals. Many activities you already do in your security role count.

ROI Calculation

With an average salary increase of ~€33,000 ($36,000 USD) per year and a total investment of approximately ~€920 ($1,000 USD) for the exam and materials, CISSP delivers a 3,500%+ return in the first year. Over a 10-year career, the cumulative salary premium attributable to CISSP exceeds ~€330,000. The ongoing renewal cost of ~€124 ($135 USD) per year is negligible compared to the return.

Employer Sponsorship

Due to the high value CISSP brings to an organization, many employers will sponsor the exam fee and study materials. Present the case in terms of compliance requirements (many frameworks require certified personnel), reduced risk (CISSP holders make better security decisions), and competitive positioning (clients and partners expect certified leadership). Over 70% of CISSP holders report that their employer paid for the certification.

The 8 CISSP Domains Explained

The 2024 CISSP exam outline (current as of 2026) covers eight domains with the following weight distribution:

DomainWeightFocus
1. Security and Risk Management15%Governance, risk frameworks, ethics, BCP, compliance
2. Asset Security10%Information lifecycle, classification, retention, privacy
3. Security Architecture and Engineering13%Secure design principles, cryptography, security models
4. Communication and Network Security13%Network architecture, secure communication channels
5. Identity and Access Management (IAM)13%Identity provisioning, federation, authorisation
6. Security Assessment and Testing12%Testing strategies, audit, vulnerability assessment
7. Security Operations13%Investigations, logging, incident management, BCP/DR
8. Software Development Security11%Secure SDLC, security in development environments

The exam tests breadth, not depth, in any single domain. Most candidates fail because they over-prepare on technical detail and under-prepare on the strategic, manager-level thinking the exam rewards. The "Think Like a Manager" framing is essential for the long-form scenario questions.

Where the Bootcamp Fits

CISSP is a long-term credential, realistic 5 to 7 years after entry into the field once the experience requirement is met. A foundational bootcamp does not replace that experience but accelerates the path significantly. The Unihackers Cybersecurity Bootcamp builds breadth across all eight CISSP domains in concept form:

  • Unit 4 (Cryptography and Secure Communications) maps to Domain 3
  • Unit 5 (Security Governance, Risk and Compliance) maps directly to Domain 1
  • Unit 6 (Threat Modeling and Vulnerability Management) maps to Domain 6
  • Unit 7 (Security Operations and Monitoring) maps to Domain 7
  • Unit 8 (Advanced Security Operations) maps to Domain 7
  • Unit 9 (Web Application Security) and Unit 11 (Security Engineering) map to Domain 8

For most candidates, the realistic path is: Security+ at bootcamp completion, CySA+ or GCIH within twelve months, then CISSP after the five-year experience requirement is met. Read the pre-enrollment pathway for context on how to set up this multi-year arc.

Preparation Checklist

Am I Ready? Self-Assessment

Before scheduling your CISSP exam, you should be able to:

  • Explain how BCP/DRP differs from incident response at a process level
  • Describe the Bell-LaPadula and Biba models and when each applies
  • Articulate the differences between preventive, detective, corrective, and compensating controls
  • Discuss risk treatment options (avoid, transfer, mitigate, accept) with examples
  • Score consistently above 75% on full-length practice exams from reputable providers

Prerequisite Experience

The 5-year requirement is real and enforced during the endorsement process after you pass. You need 5 years of cumulative, paid, full-time work experience in at least 2 of the 8 CISSP domains. A 4-year degree (or ISC2-approved credential like Security+ or CCNA Security) substitutes for 1 year. If you lack the experience, you can still take the exam and hold the Associate of ISC2 designation for up to 6 years while building your experience.

Recommended Timeline Before Attempting

Start studying at least 3 months before your target exam date. Spend months 1 to 2 on content review (one domain per week) and month 3 on intensive practice exams and weak-area review. Schedule the exam for a date you cannot easily postpone to create accountability.

Mental Preparation

CISSP is a marathon, not a sprint. The breadth of material can feel overwhelming. Break it into domains and focus on understanding the "why" rather than memorizing the "what." On exam day, remember: you are a security executive making risk-based decisions. When in doubt, choose the answer that a thoughtful CISO would select, not what a system administrator would do. The exam is testing judgment, not recall.

Insider Tips from CISSP Holders

What the Official Guide Doesn't Tell You

The CAT format means the first 25 questions disproportionately influence your score trajectory. Answer these carefully and deliberately. If you get easy questions early on, it means the algorithm has placed you at a lower ability estimate; each correct answer raises it significantly.

CISSP questions almost never have a purely technical answer. If you find yourself choosing an answer because it is the most technically precise, reconsider. The correct answer is usually the one that involves process, governance, or risk-based thinking.

The exam draws heavily from real-world governance frameworks: NIST, ISO 27001, COBIT, and ITIL. Understanding these frameworks at a conceptual level (not memorizing every control) gives you an enormous advantage.

Community Resources

  • r/cissp on Reddit is the most valuable resource outside of study materials. Read "I passed" and "I failed" posts to understand what separates the two groups.
  • ISC2 Community Forums offer official study groups and peer discussion.
  • The CISSP Podcast by Shon Harris (legacy content, still relevant) and Destination Certification YouTube channel for concept reviews.
  • Local ISSA or ISC2 chapters often run free CISSP study groups.

When to Schedule Your Exam

Schedule for a weekday morning when the testing center is typically quieter. Avoid scheduling during tax season, year-end, or any period when work stress is unusually high. Many successful candidates recommend scheduling for Tuesday or Wednesday at 9:00 AM. The 3-hour exam window plus check-in means you will finish by early afternoon, with time to decompress.

Strategic Exam Approach

Read the last sentence of each question first; it tells you what is actually being asked. Then read the full scenario. Eliminate answers that are technically focused when the question asks for a management decision. Between two seemingly correct answers, choose the one that addresses the root cause or the broader organizational risk, not the symptom.

Exam domains

Security and Risk Management
15%
Asset Security
10%
Security Architecture and Engineering
13%
Communication and Network Security
13%
Identity and Access Management (IAM)
13%
Security Assessment and Testing
12%
Security Operations
13%
Software Development Security
11%

Salary Impact

Average before

€68,000

$95,000

Average after

€94,000

$131,000

Average increase

€26,000 (+38%)

$36,000

Source: ISC2 Cybersecurity Workforce Study 2024

Prerequisites

  • 5 years cumulative paid work experience in 2+ CISSP domains
  • 4-year degree can substitute 1 year of experience
  • ISC2-approved credential can substitute 1 year

Related careers

Key terms

Frequently asked questions

How much does the CISSP exam cost in 2026?

The CISSP exam fee is ~€690 ($749 USD), payable to ISC2. This covers one exam attempt at Pearson VUE testing centers. Pricing and applicable taxes vary by location of exam administration.

What is the annual maintenance fee for CISSP?

Full CISSP holders pay an Annual Maintenance Fee (AMF) of ~€124 ($135 USD) per year. Associates of ISC2 (those who passed the exam but have not yet completed the 5-year experience requirement) pay ~€46 ($50 USD) per year.

How hard is CISSP compared to other certifications?

CISSP is considered one of the most challenging security certifications. It requires 5 years of experience and covers 8 broad domains at a strategic level.

What are the 8 CISSP domains?

Domain 1 is Security and Risk Management (15%). Domain 2 is Asset Security (10%). Domain 3 is Security Architecture and Engineering (13%). Domain 4 is Communication and Network Security (13%). Domain 5 is Identity and Access Management (13%). Domain 6 is Security Assessment and Testing (12%). Domain 7 is Security Operations (13%). Domain 8 is Software Development Security (11%).

Can I get CISSP without 5 years experience?

Yes, you can pass the exam and become an Associate of ISC2 while gaining the required experience. A 4-year degree in computer science or IT may substitute up to 1 year, and an ISC2-approved credential may substitute another 1 year. The Associate has up to six years to acquire the remaining experience and become a full CISSP.

What CPE credits are required to maintain CISSP?

CISSP holders must earn 120 Continuing Professional Education (CPE) credits per three-year cycle, equivalent to 40 credits per year. Of those, 90 must be Group A credits (directly relevant to the eight CISSP domains) and 30 may be Group B credits (general professional development). Credits can be earned through training, conferences, publications, teaching, and approved volunteer work.

Is CISSP worth it for career advancement?

Yes. CISSP holders earn an average base salary of ~€120,000 ($131,000 USD), a 22% to 38% premium over generalist security roles, and the credential is required or strongly preferred for most senior security manager, security architect, and CISO positions.

How does a cybersecurity bootcamp fit into the CISSP path?

CISSP is a long-term credential. The 5-year experience requirement means CISSP is realistic 5 to 7 years after entry into the field. A foundational bootcamp like the Unihackers Cybersecurity Bootcamp builds the technical breadth across 8 domains that CISSP later demands at a strategic level. Most pragmatic candidates earn Security+, then CySA+ or GCIH, then CISSP after meeting the experience bar.

Official Resources & Further Reading

Authoritative sources for exam objectives, study guides, and hands-on labs.

Foundation path

Build the foundation for CISSP with the Unihackers Bootcamp

CISSP rewards practitioners who already have hands-on defensive or offensive experience. The Unihackers Cybersecurity Bootcamp gives you 360 hours of structured training, CompTIA Security+ as a foundational credential, and the lab depth that makes the next certification realistic to attempt.

Related certifications