CISSP study material // original practice items

Not exam content · rev 2026-10

CISSP CAT Practice

CISSP prep console8 domains · outline Apr 2024

Get the app

Doc CC-03Rev 2026-10Class study materialRead ~8 min

CISSP requirements: experience, waivers, endorsement — and what it costs

To earn the ISC2 CISSP (Certified Information Systems Security Professional), you need five years of cumulative work in at least two of the eight exam domains, a pass on the exam, and an endorsement completed within 9 months of your exam date. One of the five years can be waived with a relevant degree or one approved credential, and if you have fewer years you can still sit the exam and finish the experience later as an Associate of ISC2.

Exam readout

Format
CAT, every language
Items
100–150
Time
3 hours
Pass mark
700 / 1000 scaled
Outline
8 domains · Apr 2024

The requirements at a glance

Requirement register
RefRequirementThe ruleWhere people slip
R-01Experience5 years cumulative, in 2 or more of the 8 domainsCounting years in one domain only
R-02WaiverUp to 1 year: a relevant degree or one approved credentialExpecting a degree plus a certificate to waive two years
R-03ExamPass the CAT exam at a Pearson VUE test centerBooking before checking the name on your ID matches the registration
R-04EndorsementCompleted within 9 months of the exam dateStarting the paperwork in month eight
R-05Maintenance120 CPE per three-year cycle, 90 of them Group A, plus an annual feeTreating 40 credits a year as the hard rule

The five-year experience rule

ISC2 asks for a minimum of five years of cumulative work experience in two or more of the eight CISSP domains. “Cumulative” means the years do not have to be consecutive or with one employer, and the work does not have to carry a security job title — a network engineer running firewall changes or a developer doing secure code review is working in a domain, whatever the business card says.

Two domains is the floor, and it is rarely a problem in practice. Most security jobs touch Security Operations (Domain 7) and at least one neighbor, such as Communication and Network Security (Domain 4) or Identity and Access Management (Domain 5). What trips people is a career spent entirely inside one narrow function; in that case, describe the adjacent work you already do rather than inventing new work.

What counts as a year

Full-time means at least 35 hours a week. Part-time work of 20 to 34 hours a week also counts, at the rate of 2,080 hours for 12 months of experience. Internships count too, paid or unpaid, as long as the organization can document them on its letterhead.

What the endorser will look at

Job titles, dates and duties that map onto the domains. A tidy one-paragraph description per role, written in the language of the outline, saves a round of questions later. Writing it is about as exciting as it sounds, which is why most people postpone it until it is urgent.

The experience arithmetic

Three lines settle most “do I qualify?” questions before you open a calendar.

  • Years you must show

    5 − waiver (0 or 1)

    The waiver is capped at one year, whatever combination of degree and credentials you hold.

  • Part-time conversion

    2,080 hours = 12 months

    Applies to work of 20–34 hours a week.

  • Associate window

    6 years to earn the remainder

    Only relevant if you pass before the experience is complete.

The one-year waiver

You can knock one year off the five with either a relevant bachelor’s or master’s degree — computer science, information technology or a related field — or one credential from ISC2’s approved list. Only one waiver applies, so a degree plus a credential still leaves four years to show.

The approved list changes from time to time, which is why it is better read at the source than copied: see the experience page on isc2.org. As of October 2026 it includes credentials such as CompTIA Security+, ISACA’s CISM and ISC2’s own SSCP and CCSP.

Five candidates, worked out

The rules are short; applying them to a real career is where the questions start. Each case assumes the work maps to at least two domains.

Eligibility cases
RefCandidateExperience shownWaiverResult
R-01SOC analyst with Security+4 years full-time1 year (approved credential)Meets the five years — can be endorsed after the pass
R-02Network administrator with a CS degree3 years full-time1 year (degree)4 of 5 — passes as an Associate, needs one more year
R-03Degree and Security+3 years full-timeStill 1 year — only one waiver applies4 of 5 — Associate; the second qualification adds nothing here
R-04IT auditor with CISA5 years full-timeNone — CISA is not on the listMeets the five years on experience alone
R-05Part-timer at 25 hours a week, with a degree4 years × 52 weeks × 25 h = 5,200 hours ≈ 2.5 years1 year (degree)About 3.5 of 5 — Associate, with time to spare inside the six-year window

No experience yet: the Associate of ISC2

The experience rule governs the credential, not the exam seat. You can register and sit the exam with any amount of experience. Pass without the five years and you become an Associate of ISC2, with six years to earn the experience and then complete the endorsement.

Associates keep membership obligations in the meantime, including an annual fee and yearly CPE credits, but may not use the CISSP designation. If the five years arrive sooner, the upgrade happens sooner. What the status means for your career is covered on CISSP certification; here the only point is that it postpones the experience requirement without reducing it.

Endorsement after you pass

Endorsement turns a pass into a certification. It is paperwork, and it has a deadline.

  1. Step 01

    Start the application

    Apply for endorsement through your ISC2 account after the pass. The deadline is 9 months from the exam date, not from the day you remember.

  2. Step 02

    Find an endorser

    An active ISC2-certified professional in good standing reviews your experience and attests to it. If you do not know one, ISC2 can act as endorser, with proof of employment.

  3. Step 03

    Document the experience

    List each role with dates, hours and duties mapped to at least two of the eight domains. Internships need documentation on the organization’s letterhead.

  4. Step 04

    Agree to the Code of Ethics

    Every applicant commits to the ISC2 Code of Ethics as part of certification. The canons are also examinable material in Domain 1.

  5. Step 05

    Wait for approval

    Review usually takes a few weeks. Your certification begins on approval, and the first three-year CPE cycle with it.

Staying certified

Certification is a subscription to good standing, not a one-time event. Each three-year cycle you need 120 CPE credits, at least 90 of them in Group A — activity tied to the domains, such as training, conference sessions, writing or teaching security. The remaining 30 can be Group A or Group B.

ISC2 suggests a pace of about 40 credits a year, and that is a suggestion: the binding number is the three-year total. The annual maintenance fee, by contrast, is due every year. Members who fall behind on either risk suspension, so the calendar reminder is worth setting on the day you are approved.

What CISSP costs

The total cost of CISSP is the exam fee plus an annual maintenance fee for as long as you hold it, plus whatever you choose to spend on preparation. The exam price varies by region and currency, taxes depend on where you test, and ISC2 adjusts both from time to time, so check the current figure on the ISC2 exam pricing page on the day you book. A price printed on a third-party page — including this one, which is why there is none — is a historical document.

Cost register — what you pay for, and when
Cost itemWhen it appliesNotes
Exam feeOnce per attempt, at bookingSet by region and currency; local taxes apply by test location
Reschedule or cancellation feeOnly if you move or cancel the appointmentSeparate fixed charges; a cancellation costs more than a reschedule
RetakeAfter a failA new purchase, with test-free waiting periods between attempts — see the CISSP exam page
Annual maintenance feeEvery year once certified; a smaller fee as an AssociatePaid for as long as you hold the credential
CPE activitiesThrough each three-year cycleMany credits can be earned at no cost; paid training is optional
PreparationBefore the examOptional: books, courses and practice items vary widely in price

Before you book the exam

  • Your work history shows at least two of the eight domains — or you accept starting as an Associate.
  • You know whether a degree or an approved credential waives one year, and you have checked it against the current ISC2 list.
  • You have the name of a potential endorser, or you are ready to request ISC2 as endorser.
  • Your registration name matches your government ID exactly.
  • You have checked the current exam price and reschedule rules on isc2.org.
  • You have done a full timed run in practice — the CISSP practice test has a Timed 60 mode for pacing.

Three Asset Security questions

Domain 2, Asset Security, is 10% of the current outline — data ownership, classification, retention and disposal. Three original practice items, each option explained. They check your reasoning, not whether you meet the requirements; the domains themselves are mapped in the study guide.

Domain drill

Item 01 / 03

Answer, then read why each option is right or wrong. Keys 1–4 pick, N goes next.

D2Asset Security

A recent compliance audit revealed that despite having a robust, executive-approved media disposal policy, an organization could not prove its hard drives were securely sanitized. Which component is MOST likely missing from the organization's governance framework?

Rationale

Pick an answer. The reasoning for every option lands here — including why the wrong ones looked right.

Questions people ask

Q01How many years of experience is required for CISSP?

Five years of cumulative work in at least two of the eight CISSP domains. A relevant degree or one approved credential can waive one year, so the minimum you must show is four. Part-time work and documented internships, paid or unpaid, count.

Q02Can I take CISSP without 5 years experience?

Yes. Anyone can sit the exam. If you pass without the experience you become an Associate of ISC2 and have six years to earn the five years, then complete endorsement.

Q03Who is eligible for CISSP?

Anyone can take the exam. To be certified you need the experience requirement (or Associate status while you earn it), a pass, an approved endorsement within 9 months of the exam, and agreement to the ISC2 Code of Ethics.

Q04How much does a CISSP exam cost?

The exam fee depends on your region and currency, plus local taxes, and ISC2 changes it periodically — check the current price on the ISC2 pricing page. On top of the exam, certified members pay an annual maintenance fee, and retakes are a new purchase.

Q05Does CISA waive a year of CISSP experience?

No. CISA is not on ISC2’s approved-credential list as of October 2026. CISM, Security+, SSCP and CCSP are among the credentials that are; check the current list before relying on it.

Q06Do I need a degree to get CISSP?

No. A degree is one of two ways to waive a single year of experience. Without one, you show the full five years.

Field kit

Earning the five years? Practice while you do

The CISSP prep app keeps the domain drills on your phone, with the reasoning behind every option, on iPhone and Android.

Get the appPractice free on this site

End of document

Handle with mild caffeine