The CISSP is one of the most respected certifications in cybersecurity — and one of the most demanding. The exam covers 8 domains, uses adaptive testing with 100–150 questions, and demands you think like a risk-aware security leader rather than a technical operator. Most candidates who fail do so not because they lacked knowledge, but because they lacked a structured, domain-weighted study plan.
This 90-day CISSP study plan is designed for working professionals who can commit 1–2 hours on weekdays and 3–4 hours on weekends — roughly 200–250 total study hours. It's built around the official exam domain weights, so you spend more time on domains that account for more questions.
📋 Table of Contents
- CISSP Exam Overview: Know What You're Preparing For
- Domain Weights & Study Time Allocation
- Before You Start: Baseline Assessment
- Phase 1 (Days 1–30): Foundation — Domains 1–4
- Phase 2 (Days 31–60): Advanced — Domains 5–8
- Phase 3 (Days 61–90): Integration, Practice & Exam Prep
- Daily Study Routine That Actually Works
- Best CISSP Study Resources for 2026
- Exam Day Strategy
- Frequently Asked Questions
CISSP Exam Overview: Know What You're Preparing For
Before you open a single textbook, you need to understand the target. The CISSP exam in 2026 is delivered as a Computerized Adaptive Test (CAT) for English-language candidates. Here's what that means in practice:
Exam Format
- FormatCAT (Computerized Adaptive)
- Questions100–150 items
- Time Limit3 hours
- Passing Score700 out of 1000
- DeliveryPearson VUE test centers only
Eligibility
- Experience5 years in 2+ domains
- Education waiver1 year waived with 4-year degree
- No experience?Associate of ISC2 path available
- EndorsementRequired after passing
- CPEs required120 over 3-year cycle
The CAT format is important to understand: the exam adapts in real time to your performance. It stops when the algorithm is statistically confident you're above or below the passing threshold — which means stopping at 100 questions is not a sign of failure. It can mean you did exceptionally well. For a deep dive into how the adaptive algorithm works, see our guide to the CISSP CAT exam format.
Domain Weights & Study Time Allocation
The ISC2 publishes official domain weights for the CISSP exam. These weights directly determine how many questions come from each domain — so a domain worth 15% will generate roughly 15–22 questions in a 150-question exam. Use this to allocate your study time proportionally.
| # | Domain | Exam Weight | Study Days (90-day plan) |
|---|---|---|---|
| 1 | Security and Risk Management | 15% | 14 days |
| 2 | Asset Security | 10% | 7 days |
| 3 | Security Architecture & Engineering | 13% | 10 days |
| 4 | Communication & Network Security | 13% | 10 days |
| 5 | Identity and Access Management (IAM) | 13% | 10 days |
| 6 | Security Assessment and Testing | 12% | 9 days |
| 7 | Security Operations | 13% | 10 days |
| 8 | Software Development Security | 11% | 8 days |
The remaining ~12 days across the 90-day plan are reserved for review, practice exams, and exam-day preparation in Phase 3.
Before You Start: Baseline Assessment
Don't begin Day 1 without taking a diagnostic exam. A 50-question diagnostic across all 8 domains will reveal your strongest and weakest areas before you invest 90 days of study. This matters because:
- Strong domains can be studied faster — if you've been doing IAM work for 10 years, Domain 5 might need a week, not 10 days.
- Weak domains need more time — if you've never touched software development, Domain 8 may need more than 8 days.
- It calibrates your expectations — most candidates score 45–60% on their first diagnostic. If you're at 70%+, you may be ready sooner than 90 days.
Phase 1 (Days 1–30): Foundation — Domains 1–4
Phase 1 builds the conceptual foundation that every other domain rests on. Domain 1 (Security and Risk Management) is the largest domain and sets the intellectual framework for how to think on the CISSP exam. Do not rush it.
-
Week 1–2
(Days 1–14)Domain 1: Security and Risk Management
CIA triad, governance frameworks (ISO 27001, NIST RMF, COBIT), risk management lifecycle, threat modeling, legal and regulatory requirements (GDPR, HIPAA, SOX), ethics and professional conduct. Focus on understanding risk concepts — quantitative (ALE, SLE, ARO) and qualitative methods. This domain sets the "manager mindset" that pervades the entire exam. -
Week 3
(Days 15–21)Domain 2: Asset Security
Data classification, data ownership (owner vs. custodian vs. user), data lifecycle management, data retention policies, privacy protection, data handling standards. Shorter domain but foundational — know the data classification schemes (government vs. commercial) cold. -
Week 4
(Days 22–30)Domain 3: Security Architecture & Engineering
Security models (Bell-LaPadula, Biba, Clark-Wilson), cryptography fundamentals (symmetric, asymmetric, hashing, PKI), secure design principles, hardware security (TPM, HSM), cloud architecture, and physical security. Cryptography is heavily tested — understand concepts over memorizing algorithms.
Phase 1 Milestones
- End of Day 14: Score 65%+ on a 30-question Domain 1 quiz
- End of Day 21: Score 65%+ on a 20-question Domain 2 quiz
- End of Day 30: Score 65%+ on a 25-question Domain 3 quiz; take a 50-question cross-domain practice exam (target 60%+)
Phase 2 (Days 31–60): Advanced — Domains 5–8
Phase 2 covers the remaining four domains and begins integrating what you've learned. By Day 60, you should have touched all 8 domains and be ready to shift from learning to reinforcing.
-
Days 31–40
Domain 4: Communication & Network Security
OSI and TCP/IP models, network topologies, secure protocols (TLS/SSL, IPsec, SSH, HTTPS), firewalls, IDS/IPS, VPNs, wireless security (WPA3), network segmentation, and cloud networking. Know the OSI model layer-by-layer and what attacks target each layer. Understand VLANs, DMZs, and micro-segmentation concepts. -
Days 41–50
Domain 5: Identity and Access Management (IAM)
Authentication factors (MFA, biometrics), authorization models (DAC, MAC, RBAC, ABAC), identity federation (SAML, OAuth, OpenID Connect), privileged access management, Zero Trust principles, and directory services. IAM is deeply practical — connect concepts to real-world enterprise scenarios. -
Days 51–57
Domain 6: Security Assessment and Testing
Vulnerability assessments vs. penetration testing, audit types, log review, SAST/DAST, test coverage, and reporting. Lighter domain — focus on understanding what each test type is appropriate for and who should conduct it (internal vs. third-party). -
Days 58–67
Domain 7: Security Operations
Incident response lifecycle, evidence handling (chain of custody), BCP/DR concepts, change management, patch management, and physical/environmental security. BCP vs. DRP terminology is heavily tested — know RTO, RPO, MTBF, and MTTR cold. -
Days 68–75
Domain 8: Software Development Security
SDLC models (Waterfall, Agile, DevSecOps), security in the development process, OWASP Top 10, code review techniques, API security, and database security. If you're not a developer, focus on the management concepts — when to conduct security reviews, not how to write secure code.
Phase 2 Milestones
- End of Day 45: Score 65%+ on a combined Domain 4+5 quiz (40 questions)
- End of Day 60: Take a full 100-question timed practice exam — target 65%+. Review every missed question, focusing on why the correct answer is right, not just what it is.
Phase 3 (Days 61–90): Integration, Practice & Exam Prep
Phase 3 is where most candidates either cement their pass or doom themselves by continuing to read new material instead of practicing. Stop learning new content by Day 75. Phase 3 is about retrieval practice, weakness remediation, and building exam confidence.
-
Days 61–72
Weakness Remediation + Mini-Domain Reviews
Review your Phase 1 and 2 milestone quiz scores. Identify the 2–3 domains where you scored below 65%. Spend these 12 days doing deep dives into those specific weaknesses — not re-reading chapters, but doing targeted practice questions and reviewing explanations. -
Days 73–80
Full Practice Exams (Timed)
Take two full 100-question timed practice exams under real conditions: no notes, no breaks beyond what you'd get in the real exam. Target 70%+ before booking your real exam. After each exam, spend equal time reviewing wrong answers as you did taking the exam. -
Days 81–85
Scenario & Manager Mindset Drills
Focus specifically on scenario-based questions — the CISSP loves "which is the BEST first step?" and "which answer is MOST appropriate?" questions. Practice eliminating technically correct but managerially wrong answers. See our guide on thinking like a manager on the CISSP. -
Days 86–89
Light Review + Logistics
Light review of key frameworks and acronyms (RTO, RPO, ALE, SLE, ARO). Confirm your Pearson VUE test center, ID requirements, and travel plan. No heavy studying. Sleep 8 hours. -
Day 90
Exam Day
Arrive 30 minutes early. Bring valid ID. Breathe. Trust your preparation.
Practice Questions That Match the Real Exam
CISSP.app has thousands of adaptive practice questions with detailed explanations — organized by domain and calibrated to the CISSP's scenario-based format. Your 7-day free trial includes everything.
Start Free 7-Day Trial →Daily Study Routine That Actually Works
Consistency beats cramming. The candidates who pass the CISSP are the ones who study regularly, not the ones who pull 12-hour marathon sessions the week before the exam. Here's a daily routine that's sustainable for working professionals:
Weekday Structure (60–90 minutes)
- 0:00–0:20 — Review yesterday's material using flashcards or brief notes (spaced repetition)
- 0:20–0:60 — Read new material or watch video lesson for current domain
- 0:60–0:90 — Do 10–15 practice questions on today's topic, review all explanations
Weekend Structure (3–4 hours per day)
- Hour 1 — Review the week's key concepts; update your notes
- Hours 2–3 — Deep work: new domain content, harder practice questions
- Hour 4 — 30-question mixed-domain quiz; review all answers (not just wrong ones)
Best CISSP Study Resources for 2026
You don't need every resource — you need the right ones. Here's what the community recommends for each phase:
Primary Study Material (pick one)
- ISC2 Official Study Guide (OSG) — The definitive reference. Dense but comprehensive. Best used as a reference, not cover-to-cover reading.
- Mike Chapple & David Seidl "CISSP Official Study Guide" — More readable than the OSG; good for Phase 1–2 learning.
- Thor Teaches / Inside Cloud and Security (YouTube) — Free video content; excellent for visual learners. Good supplement to books.
Practice Questions (essential)
- CISSP.app — Adaptive questions calibrated to CAT format, scenario-based, with detailed explanations. Covers all 8 domains. Free 7-day trial at cissp.app.
- Boson ExSim — Industry-standard practice exam software. Known for difficulty parity with the real exam.
- Official ISC2 Practice Tests — Chapple/Seidl companion volume; good for domain-by-domain drills.
For the Manager Mindset (critical)
- Kelly Handerhan "Why You Will Pass the CISSP" (YouTube, free) — Essential 13-minute video that reframes how to think about every question. Watch it at the start and end of each phase.
- Prabh Nair "Coffee Shots" (YouTube) — Short, focused domain deep-dives. Great for commute listening.
Exam Day Strategy
You've done the work. Now execute cleanly.
Logistics
- Arrive 30 minutes early. Test centers will turn you away if you're late.
- Bring two valid forms of ID — government-issued photo ID is required.
- No electronics, notes, or food in the testing room.
- You'll get a locker for your belongings.
During the Exam
- Read every question twice. CAT questions often hinge on a single word ("first," "best," "most," "immediately").
- Eliminate obviously wrong answers first — most questions have two obvious distractors. Choose between the remaining two using the manager mindset.
- Don't panic at question count. Whether you stop at 100 or 150, the algorithm is working — it's not a sign of performance. Stay focused on the current question.
- Manage your time. 3 hours for up to 150 questions = about 1.2 minutes per question. Don't linger. Flag and move on if stuck.
- If two answers both seem correct: Choose the one that is more proactive, policy-driven, and risk-management-oriented. The CISSP rarely wants you to jump straight to a technical fix.
Frequently Asked Questions
How many hours do I need to study for the CISSP?
Most candidates report 200–350 hours of total preparation. This 90-day plan targets approximately 220 hours — 1.5 hours on weekdays and 3.5 hours on weekend days. Candidates with strong security backgrounds may need fewer hours; those newer to security should plan for the higher end.
Is 90 days enough to pass the CISSP?
Yes — for most candidates with 5+ years of security experience. The 90-day timeline assumes you already have the work experience and baseline knowledge. If you're starting from scratch, consider a 6-month plan. If you have an IT security background but not yet 5 years' experience, consider pursuing the Associate of ISC2 designation first.
Which domain is hardest on the CISSP?
Domain 1 (Security and Risk Management) is hardest for most candidates because it's the largest, the most conceptual, and sets the mindset for the entire exam. Domain 3 (Security Architecture) is technically dense. Domain 8 (Software Development Security) trips up candidates without a development background.
Can I pass CISSP without a boot camp?
Absolutely. Many candidates pass with self-study alone — a good textbook, quality practice questions, and the Kelly Handerhan manager mindset video are often sufficient. Boot camps help candidates who need accountability and structured time away from work. They are not required.
What score do I need to pass the CISSP?
700 out of 1000. The CAT exam uses scaled scoring, not a raw percentage. This means your performance on harder questions is worth more than easier ones. The algorithm adapts question difficulty in real time — so don't be surprised if questions feel very hard. That's often a good sign.
Should I also consider CCSP or CISM?
If your role involves cloud security, the CCSP pairs naturally with the CISSP. If you're moving into security management and strategy, the CISM is the most respected management-focused certification. Both are available through the same CISSP.app subscription.
Ready to Start Preparing?
Practice with thousands of expert-verified CISSP questions. AI-powered gap analysis tells you exactly where to focus.
Start Free 7-Day Trial →