CISSP Resources · Exam prep

CISSP Study Guide: A Complete Plan for the 2026 Exam

The CISSP is not a memorisation exam. It is a management exam written in security vocabulary. This guide sets out what to study across the eight domains, how to sequence it, and how to know when studying has actually worked.

What the CISSP actually tests

ISC2 describes the CISSP as testing breadth across eight domains rather than depth in any one. In practice that means most questions give you a short scenario and four answers where two or three are technically true. Your job is to pick the response a security manager would choose first, or the one that addresses the root problem rather than a symptom.

That is why strong engineers often fail their first attempt. Deep technical knowledge tells you which answers are true; it does not tell you which is BEST, FIRST, or MOST appropriate. Building that judgement is the actual study task.

DomainWeightWhat it really tests
1. Security and Risk Management16%Governance, risk treatment, law, ethics, BCP
2. Asset Security10%Classification, ownership, data lifecycle
3. Security Architecture and Engineering13%Secure design, models, cryptography, physical
4. Communication and Network Security13%Segmentation, secure protocols, network design
5. Identity and Access Management13%Authentication, authorisation, federation
6. Security Assessment and Testing12%Testing strategy, audits, metrics
7. Security Operations13%Incident response, investigations, DR
8. Software Development Security10%SDLC, secure coding, third-party risk

Study in the right order

Do not study the domains in numerical order and do not study them in isolation. Domain 1 sets the vocabulary the other seven are graded against, so it comes first and gets revisited last.

  1. Domain 1 first. Risk, governance, and the manager mindset. Everything else is judged through this lens.
  2. Domains 2 and 5 next. Asset ownership and identity are the connective tissue between policy and technology.
  3. Domains 3 and 4 in the middle. The heaviest technical content, best tackled when your energy is highest.
  4. Domains 6 and 7. Testing and operations lean heavily on process order — what you do first, second, third.
  5. Domain 8 last. The smallest domain and the easiest to consolidate late.
  6. Return to Domain 1. A second pass after everything else clicks is worth more than any other single study hour.

A week-by-week plan (12 weeks, ~10 hours a week)

WeeksFocusPractice target
1–2Domain 1 — governance, risk, law, ethics, BCP150 questions, review every explanation
3Domain 2 — classification, ownership, retention80 questions
4–5Domain 3 — models, crypto, physical security180 questions
6–7Domain 4 — OSI, segmentation, secure protocols180 questions
8Domain 5 — IAM, federation, lifecycle120 questions
9Domain 6 — assessment and testing100 questions
10Domain 7 — operations, IR, DR150 questions
11Domain 8 — SDLC and secure coding90 questions
12Full-length adaptive simulations and weak-area drilling2–3 full simulations
Cut the plan to fit your life, not the other way round

Six focused hours a week for sixteen weeks beats twenty hours a week for four weeks. Retention is a function of spacing, not intensity.

How to actually study each domain

  1. Read once, fast. One pass through the domain material to build a map. Do not highlight everything.
  2. Answer questions immediately. Practice questions are the study method, not the assessment. Do them while the material is still slightly unfamiliar.
  3. Read every explanation — including the ones you got right. Getting a question right for the wrong reason is the single biggest source of exam-day surprises.
  4. Write down the distinction that tripped you. Owner vs custodian. Preventive vs detective. RTO vs RPO. Those one-line distinctions are what the exam actually tests.
  5. Re-drill the weak domain within 48 hours. Spacing works; cramming does not.

Materials worth your money

  • One primary text. The Official Study Guide or Shon Harris — pick one and finish it. Two books is procrastination in disguise.
  • One large question bank with written rationales for every option, not just the correct one.
  • An adaptive practice mode that raises difficulty as you improve, so you are not repeatedly answering questions you have already mastered.
  • A one-page summary per domain you wrote yourself. Someone else's cheat sheet is worth roughly nothing.

Knowing when you are ready

  • You score consistently above 75% on unseen, difficulty-mixed questions — not on questions you have seen before.
  • No domain sits more than 10 points below your average.
  • You can explain why the three wrong answers are wrong, not just recognise the right one.
  • You finish 100 questions in under two hours without your accuracy collapsing in the last twenty.

If a readiness score is available to you, treat it as a trend line rather than a verdict. A stable, rising score across several sessions is far more meaningful than one good night.

Frequently asked questions

Can I pass the CISSP with self-study only?

Yes. Most candidates pass with a primary textbook, a large practice-question bank, and a disciplined schedule. Bootcamps compress the timeline but do not replace spaced practice.

Do I need to memorise port numbers and algorithms?

A small number are worth knowing, but the exam rewards understanding why a control is chosen far more than recall of specifics. Prioritise concepts and process order.

How many practice questions should I do?

Most successful candidates answer between 1,000 and 2,000 questions with full explanation review. Volume matters less than reviewing every rationale.

Study with adaptive, scenario-based questions

Domain Eight covers all eight domains with managerial, best-answer questions and a written rationale for every option — plus an adaptive engine that keeps you at the edge of your ability.

Related guides

More CISSP study material from Domain Eight: browse all resources.