CISSP - Certified Information Systems Security Professional

Advanced ISC2 Cybersecurity

The Mensa membership of cybersecurity. Requires 5 years experience. Opens doors to CISO and security architecture roles.

Overview

The Experience Requirement Is the Real Story

Search "CISSP" and the exam gets most of the attention, but the five-year experience requirement is what actually determines whether this credential fits your current career stage — and it's more nuanced than most summaries suggest. You need five cumulative years of paid work experience across at least two of the eight domains in the (ISC)² Common Body of Knowledge (CBK). A four-year college degree, or an approved credential from (ISC)²'s list, can waive one year — so a relevant bachelor's degree brings the requirement down to four years.

If you don't yet meet the experience bar, you're not locked out — you can still pass the exam and become an Associate of (ISC)², then have up to six years to accumulate the required experience while holding that interim status. This pathway gets underused because it's not well publicized, but it means ambitious security professionals early in their careers can validate their knowledge now rather than waiting years to even attempt the exam.

The Eight CBK Domains — And Why the Weighting Matters

The exam draws from eight domains with different weights on the current outline: Security and Risk Management (16%), Asset Security (10%), Security Architecture and Engineering (13%), Communication and Network Security (13%), Identity and Access Management (13%), Security Assessment and Testing (12%), Security Operations (13%), and Software Development Security (10%). Security and Risk Management carries the heaviest weight for a reason — CISSP is explicitly designed as a management-oriented certification, testing governance, risk, and policy judgment more than hands-on technical execution. This is the single most common surprise for technically skilled candidates coming from hands-on roles like penetration testing or network engineering — CISSP rewards breadth and managerial judgment, not depth in any one technical specialty.

Computer Adaptive Testing Changes the Prep Strategy

The English-language CISSP exam uses Computerized Adaptive Testing (CAT), not a fixed question bank. Question difficulty adjusts in real time based on your answers — get questions right, and the exam serves harder ones; struggle, and it recalibrates. This means the exam length varies by candidate: it can end in as few as 100 questions or run up to 150, within a 3-hour window. Because of this format, guessing strategies that work on fixed-form exams (skip and return later) don't apply the same way — CAT exams generally don't allow returning to previous questions, so each answer needs to be your considered best guess before moving forward.

CISSP vs. CISM — The Comparison Everyone Eventually Makes

Both are advanced, management-oriented security certifications, and the decision between them often comes down to career direction rather than difficulty. CISSP, from (ISC)², covers a broader technical and architectural base across all eight domains and is generally viewed as the stronger fit if you want to stay adjacent to technical security architecture while moving into leadership. CISM, from ISACA, leans more heavily into information security governance, program management, and business alignment — it's often the better fit for candidates targeting a pure security-management or CISO track without needing deep architectural knowledge. Plenty of senior security leaders eventually hold both, since the domains overlap without being redundant.

What Passing Actually Signals to Employers

CISSP's five-year experience gate is precisely what gives it weight in hiring — unlike some certifications that anyone can attempt regardless of background, a CISSP holder has, by definition, already spent years doing the work. This is why it appears as a hard requirement in a meaningful share of senior security job postings, particularly in government, defense, and regulated industries where DoD 8570 compliance or similar frameworks explicitly name CISSP as an approved baseline credential for certain role tiers.

Maintaining the Credential

CISSP requires 40 Continuing Professional Education (CPE) credits per year and 120 over each three-year cycle, plus an annual maintenance fee. Unlike some certifications where lapsing just means a status change, letting CISSP fully expire means retaking the full exam from scratch — there's no abbreviated recertification path once it lapses completely, so most holders treat CPE tracking as a standing habit rather than something they catch up on right before renewal.

Frequently Asked Questions

Can I take the CISSP exam with no experience?

Yes, via the Associate of (ISC)² pathway — you pass the same exam, then have up to six years to accumulate the required experience before earning full CISSP status.

Is CISSP harder than CEH or Security+?

It's not a direct technical-difficulty comparison — CISSP tests breadth of security management knowledge across governance, architecture, and operations, while CEH and Security+ are more narrowly technical. Many candidates find CISSP's breadth more demanding precisely because it can't be crammed the way a narrower technical exam sometimes can.

How many domains do I need experience in?

At least two of the eight CBK domains, with your combined experience across them totaling the required years.

Study Roadmap

Full step-by-step roadmap coming soon. See the roadmap page for updates.