ISC2 CISSP

CISSP Exam Format Explained: The Current CAT Structure

The CISSP is a 3-hour computer-adaptive exam of 100 to 150 items across eight weighted domains, passed at 700 out of 1000, delivered at Pearson VUE and ISC2 Authorized PPCs. This guide walks the current format as ISC2 publishes it, verified August 2026.

Last verified:

What is the format of the CISSP exam?

Per ISC2's current exam outline, the CISSP is a Computerized Adaptive Test (CAT): 3 hours long, 100 to 150 items in multiple-choice and advanced item types, with a passing score of 700 out of 1000. It runs at Pearson VUE test centers and ISC2 Authorized PPCs, and the current outline took effect April 15, 2024.

What computer-adaptive testing changes about the sitting

A fixed-form exam gives every candidate the same questions in the same order. The CISSP does not. The CAT engine selects each next item based on how you have performed so far, which produces three practical consequences you can train for.

First, your early answers shape the difficulty of everything that follows. A strong start pushes you into harder items that confirm competence; a weak start pushes the exam to probe for a floor. Second, the exam can end anywhere between 100 and 150 items once the engine is confident in its estimate, so a shorter sitting is not a bad sign. Third, you cannot return to earlier items — the format has no review-and-revise pass.

That last point is why pacing is a real skill on this exam. In a 3-hour window with up to 150 items, agonizing over any single question costs you the clock on three others, and there is no coming back to bank an answer you finally settle on.

CISSP length and item count, exactly as published

The published numbers are simple: 3 hours, 100 to 150 items, in multiple-choice and advanced item types. The nuance is what those numbers do not tell you — ISC2 does not publish the exact mix of item types per sitting, the difficulty calibration, or how many items any individual candidate will see.

Plan for the full 150 at the full 3 hours. Candidates who budget emotionally for 100 items and then receive a longer sitting run out of clock in the final domains, which are worth exactly as much as the first ones.

Language availability is published: Chinese, English, German, Japanese, and Spanish, with Chinese-language sittings offered only in select appointment windows (March, June, September, December).

CISSP format facts from the ISC2 exam outline, verified 19 August 2026
Format elementPublished value
DeliveryCAT — Computerized Adaptive Testing, all exams
Length3 hours
Items100 to 150
Item formatMultiple choice and advanced item types
Passing score700 out of 1000 points
Testing centersISC2 Authorized PPC and select Pearson VUE test centers
LanguagesChinese, English, German, Japanese, Spanish
Current outlineEffective April 15, 2024

Scroll horizontally to view all columns.

How the 700-of-1000 scale actually works

CISSP results report on a scaled score from 0 to 1000, with 700 required to pass. The scale is not a percentage: 700 does not mean 70 percent correct, and ISC2 does not publish the raw-item-to-scaled-score conversion or the exam's internal weighting.

Two practical implications follow. You cannot compute a safe number of allowable errors from any public source, so anyone quoting a pass rate or a miss-budget is estimating. And because the adaptive engine scores the whole performance trajectory rather than a fixed question set, preparation quality matters more than question-count arithmetic.

What you do get after the sitting is a pass or fail against the 700 bar, plus diagnostic domain feedback on a fail — useful if a second attempt is on the table.

The eight domains and their published weights

ISC2 publishes average domain weights on the exam outline, and they should drive your study allocation. The heaviest single domain is Security and Risk Management at 16%; the lightest are Asset Security and Software Development Security at 10% each.

Multiply each weight by your diagnostic weakness and you get a priority list. A practitioner strong in operations but weak in cryptography-heavy architecture work should spend disproportionate time on Security Architecture and Engineering (13%) even though Security Operations (13%) carries the same weight on paper.

Note what the exam is not: it is not a hands-on lab. The advanced item types are still selected-response formats, and the judgment being tested is leadership-level security decision-making across the eight domains — which is exactly what the five-year experience requirement exists to guarantee.

CISSP domain weights from the ISC2 exam outline, verified 19 August 2026
DomainAverage weight
1. Security and Risk Management16%
2. Asset Security10%
3. Security Architecture and Engineering13%
4. Communication and Network Security13%
5. Identity and Access Management (IAM)13%
6. Security Assessment and Testing12%
7. Security Operations13%
8. Software Development Security10%

Scroll horizontally to view all columns.

Scheduling, delivery sites, and the experience requirement

CISSP sittings are booked through ISC2 and delivered at Pearson VUE test centers and ISC2 Authorized PPCs, with photo ID verification at every site. There is no at-home CISSP option in the current delivery model, so build travel and check-in time into your plan.

The credential behind the exam has its own gate: five years of cumulative paid work experience in two or more of the eight domains, reducible by one year with a relevant degree or approved credential. Passing the exam and holding the credential are two separate milestones — confirm where you stand with ISC2 before you plan around the badge.

Exam fees are set at ISC2 registration and change by region and year; check the live price in the official registration flow rather than any remembered figure.

What this format means for how you prepare

Adaptive delivery rewards three habits and punishes their absence. Train timed sets where you commit and move, because the no-return format makes hesitation expensive. Study by weight-times-weakness, because even coverage is misallocation on a weighted exam. And rehearse the full 3-hour stamina profile, because decision quality in domain seven should not be worse than domain one.

If the sitting is standing between you and a fixed professional deadline, private exam help exists for exactly that case: Exam Assist handles the sitting end to end, and the service fee is due only after the agreed result posts. You can also compare the CISSP against the entry-level CC or against Security+ if the leadership credential is more than your current role requires.

Frequently Asked Questions

How many questions are on the CISSP exam? +
Between 100 and 150. The CAT engine decides the exact count based on your performance, so plan and pace for the full 150 rather than hoping for an early finish.
How long is the CISSP exam? +
3 hours, per the ISC2 exam outline. That window holds however many items the adaptive engine serves, which is why pacing discipline matters more than on a fixed-form exam.
What score do you need to pass the CISSP? +
700 out of 1000 on a scaled score. The scale is not a percentage, and ISC2 does not publish the conversion from raw items to scaled score, so treat any quoted pass rate or error budget as an estimate.
Can you go back and review questions on the CISSP? +
No. CAT delivery serves each item once and moves on; there is no review pass. Training the commit-and-move rhythm before test day is part of format-matched preparation.
Is the CISSP exam multiple choice? +
It uses multiple choice and advanced item types — all selected-response formats rather than hands-on labs. The tested skill is leadership-level security judgment across the eight weighted domains.

Ready to Pass Your CompTIA Security+?

Exam Assist handles the CompTIA Security+ sitting end to end. Pay only after you pass.

Book CISSP Exam Help