ISC2’s own rules, quoted and dated
CISSP, as ISC2 actually describes it
The fee, the format, the eight domains and their weightings, the five-year experience clause and what it costs to keep — every line below quoted from ISC2's own pages and dated 24 September 2026.
What CISSP is, in one paragraph
CISSP is ISC2's flagship professional certification for people who design, run and answer for security across a whole organisation. It is broad rather than deep: eight domains covering risk, assets, architecture, networks, identity, testing, operations and software, none of them worth more than 16% of the exam. It is not a beginner credential and it is not a technical specialism — it is the credential that says you can hold the whole picture in your head.
The exam, as published
ISC2's exam outline states the length as 3 hours, the question count as 100 - 150, the format as Computerized Adaptive Testing (CAT) for all exams, and the pass mark as 700 out of 1000 points. It is available in Chinese, English, German, Japanese and Spanish.
Adaptive testing is worth understanding before you book. The questions you get depend on how you answered the previous ones, which is why the exam can finish at 100 items or run to 150, and why comparing your experience with somebody else's is close to meaningless.
The eight domains, and what they weigh
CISSP domain weightings, ISC2 exam outline
- 16%Security and Risk Management
- 13%Security Architecture and Engineering
- 13%Communication and Network Security
- 13%Identity and Access Management
- 13%Security Operations
- 12%Security Assessment and Testing
- 10%Asset Security
- 10%Software Development Security
- 100% in total — the weightings add up, which is how we check we copied them correctly.
The weightings are the study plan. ISC2 puts Security and Risk Management at 16%, then four domains level at 13% — Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, and Security Operations — with Security Assessment and Testing at 12% and Asset Security and Software Development Security at 10% each.
Read that spread carefully: there is no dominant subject to cram and no domain small enough to skip. A tenth of a 100-to-150-question adaptive exam is not a rounding error.
The five-year clause, and the way round it
ISC2 requires a minimum of five years cumulative, full-time experience in two or more of the eight domains. A relevant bachelor's or master's degree in computer science or IT, or an approved ISC2 credential, waives up to one year — one year in total, not one per qualification.
If you do not have the years, you can still sit. ISC2's outline says candidates lacking the required experience become an Associate of ISC2 after passing and have six years to complete the five. That is a genuine route, not a consolation prize, but it comes with a rule people miss: until endorsement is complete, an Associate may not use the CISSP marks. You have passed the examination; you are not a CISSP yet.
Endorsement itself requires an existing ISC2-certified professional to vouch for your experience. ISC2 publishes a deadline for it that we could not open on 24 September 2026, so rather than repeat a window we have not read, we will say only that you should start finding your endorser before you sit, not after.
What it costs to sit, and to keep
What three years of holding it costs
- CISSP$1,154$749 exam + AMF $135 × 3 = $405 to keep it
- CCSP$1,004$599 exam + AMF $135 × 3 = $405 to keep it
- Security+exam price not publishedexam voucher, price unread + CE fees, whole cycle = $150 to keep it
ISC2's pricing page lists the CISSP exam at $749 across the Americas, Asia Pacific, the Middle East and Africa, at €719.04 for EMEA and £606.69 in the UK. Rescheduling costs $50 and cancelling costs $100, so an uncertain date is not free.
Holding it costs an annual maintenance fee of $135. That makes CISSP a $749 exam plus $135 a year, or $1,154 over a first three-year cycle. CCSP on the same arithmetic is $1,004, and CompTIA's Security+ is a different shape entirely: no published voucher price, plus $150 for the whole three-year period if you renew with continuing-education units.
The maintenance fee buys one thing worth knowing about: ISC2 states that members pay a single annual fee regardless of how many of its certifications they earn. A second ISC2 credential costs its exam and nothing else per year.
Keeping it alive: 120 credits, and a misconception
CISSP runs on a three-year cycle requiring 120 continuing professional education credits, of which at least 90 must be Group A — directly related to the domains. The part that is widely misreported is the annual figure: ISC2 recommends around 40 credits a year to keep you on track, but for certified members that is guidance rather than a requirement. The requirement is the 120 by the end of the cycle. Associates of ISC2 are the exception and do have an annual obligation.
The annual maintenance fee, by contrast, is a hard date: ISC2 charges it on the anniversary of your certification, every year, whether or not you have earned a credit.
What ISC2 does not publish, and neither do we
There is no CISSP pass rate on ISC2's pages. There is no average study time, no difficulty score and no salary figure by credential. Every one of those numbers exists online, and every one of them traces back to a company selling preparation. Hardenstep prints none of them.
If you want a figure about the work rather than the letters, the US Bureau of Labor Statistics gives a median of $129,180 a year for information security analysts as of May 2025, with 21% projected growth for 2025–35. That is an occupation, not a credential, and it is the only salary number on this site.
Where to go next
Work through the five-year experience rule in detail if the clause is what is blocking you, the full cost of sitting it if it is the money, or CISSP against Security+ if you are not sure you should be aiming here yet. If you are weighing it against a management track, CISM and CISSP head to head is the comparison to read.