What is the format of the CISSP exam?
Per ISC2's current exam outline, the CISSP is a Computerized Adaptive Test (CAT): 3 hours long, 100 to 150 items in multiple-choice and advanced item types, with a passing score of 700 out of 1000. It runs at Pearson VUE test centers and ISC2 Authorized PPCs, and the current outline took effect April 15, 2024.
What computer-adaptive testing changes about the sitting
A fixed-form exam gives every candidate the same questions in the same order. The CISSP does not. The CAT engine selects each next item based on how you have performed so far, which produces three practical consequences you can train for.
First, your early answers shape the difficulty of everything that follows. A strong start pushes you into harder items that confirm competence; a weak start pushes the exam to probe for a floor. Second, the exam can end anywhere between 100 and 150 items once the engine is confident in its estimate, so a shorter sitting is not a bad sign. Third, you cannot return to earlier items — the format has no review-and-revise pass.
That last point is why pacing is a real skill on this exam. In a 3-hour window with up to 150 items, agonizing over any single question costs you the clock on three others, and there is no coming back to bank an answer you finally settle on.
CISSP length and item count, exactly as published
The published numbers are simple: 3 hours, 100 to 150 items, in multiple-choice and advanced item types. The nuance is what those numbers do not tell you — ISC2 does not publish the exact mix of item types per sitting, the difficulty calibration, or how many items any individual candidate will see.
Plan for the full 150 at the full 3 hours. Candidates who budget emotionally for 100 items and then receive a longer sitting run out of clock in the final domains, which are worth exactly as much as the first ones.
Language availability is published: Chinese, English, German, Japanese, and Spanish, with Chinese-language sittings offered only in select appointment windows (March, June, September, December).
| Format element | Published value |
|---|---|
| Delivery | CAT — Computerized Adaptive Testing, all exams |
| Length | 3 hours |
| Items | 100 to 150 |
| Item format | Multiple choice and advanced item types |
| Passing score | 700 out of 1000 points |
| Testing centers | ISC2 Authorized PPC and select Pearson VUE test centers |
| Languages | Chinese, English, German, Japanese, Spanish |
| Current outline | Effective April 15, 2024 |
Scroll horizontally to view all columns.
How the 700-of-1000 scale actually works
CISSP results report on a scaled score from 0 to 1000, with 700 required to pass. The scale is not a percentage: 700 does not mean 70 percent correct, and ISC2 does not publish the raw-item-to-scaled-score conversion or the exam's internal weighting.
Two practical implications follow. You cannot compute a safe number of allowable errors from any public source, so anyone quoting a pass rate or a miss-budget is estimating. And because the adaptive engine scores the whole performance trajectory rather than a fixed question set, preparation quality matters more than question-count arithmetic.
What you do get after the sitting is a pass or fail against the 700 bar, plus diagnostic domain feedback on a fail — useful if a second attempt is on the table.
The eight domains and their published weights
ISC2 publishes average domain weights on the exam outline, and they should drive your study allocation. The heaviest single domain is Security and Risk Management at 16%; the lightest are Asset Security and Software Development Security at 10% each.
Multiply each weight by your diagnostic weakness and you get a priority list. A practitioner strong in operations but weak in cryptography-heavy architecture work should spend disproportionate time on Security Architecture and Engineering (13%) even though Security Operations (13%) carries the same weight on paper.
Note what the exam is not: it is not a hands-on lab. The advanced item types are still selected-response formats, and the judgment being tested is leadership-level security decision-making across the eight domains — which is exactly what the five-year experience requirement exists to guarantee.
| Domain | Average weight |
|---|---|
| 1. Security and Risk Management | 16% |
| 2. Asset Security | 10% |
| 3. Security Architecture and Engineering | 13% |
| 4. Communication and Network Security | 13% |
| 5. Identity and Access Management (IAM) | 13% |
| 6. Security Assessment and Testing | 12% |
| 7. Security Operations | 13% |
| 8. Software Development Security | 10% |
Scroll horizontally to view all columns.
Scheduling, delivery sites, and the experience requirement
CISSP sittings are booked through ISC2 and delivered at Pearson VUE test centers and ISC2 Authorized PPCs, with photo ID verification at every site. There is no at-home CISSP option in the current delivery model, so build travel and check-in time into your plan.
The credential behind the exam has its own gate: five years of cumulative paid work experience in two or more of the eight domains, reducible by one year with a relevant degree or approved credential. Passing the exam and holding the credential are two separate milestones — confirm where you stand with ISC2 before you plan around the badge.
Exam fees are set at ISC2 registration and change by region and year; check the live price in the official registration flow rather than any remembered figure.
What this format means for how you prepare
Adaptive delivery rewards three habits and punishes their absence. Train timed sets where you commit and move, because the no-return format makes hesitation expensive. Study by weight-times-weakness, because even coverage is misallocation on a weighted exam. And rehearse the full 3-hour stamina profile, because decision quality in domain seven should not be worse than domain one.
If the sitting is standing between you and a fixed professional deadline, private exam help exists for exactly that case: Exam Assist handles the sitting end to end, and the service fee is due only after the agreed result posts. You can also compare the CISSP against the entry-level CC or against Security+ if the leadership credential is more than your current role requires.