CISSP Resources · Exam prep
CISSP Study Guide: A Complete Plan for the 2026 Exam
The CISSP is not a memorisation exam. It is a management exam written in security vocabulary. This guide sets out what to study across the eight domains, how to sequence it, and how to know when studying has actually worked.
What the CISSP actually tests
ISC2 describes the CISSP as testing breadth across eight domains rather than depth in any one. In practice that means most questions give you a short scenario and four answers where two or three are technically true. Your job is to pick the response a security manager would choose first, or the one that addresses the root problem rather than a symptom.
That is why strong engineers often fail their first attempt. Deep technical knowledge tells you which answers are true; it does not tell you which is BEST, FIRST, or MOST appropriate. Building that judgement is the actual study task.
| Domain | Weight | What it really tests |
|---|---|---|
| 1. Security and Risk Management | 16% | Governance, risk treatment, law, ethics, BCP |
| 2. Asset Security | 10% | Classification, ownership, data lifecycle |
| 3. Security Architecture and Engineering | 13% | Secure design, models, cryptography, physical |
| 4. Communication and Network Security | 13% | Segmentation, secure protocols, network design |
| 5. Identity and Access Management | 13% | Authentication, authorisation, federation |
| 6. Security Assessment and Testing | 12% | Testing strategy, audits, metrics |
| 7. Security Operations | 13% | Incident response, investigations, DR |
| 8. Software Development Security | 10% | SDLC, secure coding, third-party risk |
Study in the right order
Do not study the domains in numerical order and do not study them in isolation. Domain 1 sets the vocabulary the other seven are graded against, so it comes first and gets revisited last.
- Domain 1 first. Risk, governance, and the manager mindset. Everything else is judged through this lens.
- Domains 2 and 5 next. Asset ownership and identity are the connective tissue between policy and technology.
- Domains 3 and 4 in the middle. The heaviest technical content, best tackled when your energy is highest.
- Domains 6 and 7. Testing and operations lean heavily on process order — what you do first, second, third.
- Domain 8 last. The smallest domain and the easiest to consolidate late.
- Return to Domain 1. A second pass after everything else clicks is worth more than any other single study hour.
A week-by-week plan (12 weeks, ~10 hours a week)
| Weeks | Focus | Practice target |
|---|---|---|
| 1–2 | Domain 1 — governance, risk, law, ethics, BCP | 150 questions, review every explanation |
| 3 | Domain 2 — classification, ownership, retention | 80 questions |
| 4–5 | Domain 3 — models, crypto, physical security | 180 questions |
| 6–7 | Domain 4 — OSI, segmentation, secure protocols | 180 questions |
| 8 | Domain 5 — IAM, federation, lifecycle | 120 questions |
| 9 | Domain 6 — assessment and testing | 100 questions |
| 10 | Domain 7 — operations, IR, DR | 150 questions |
| 11 | Domain 8 — SDLC and secure coding | 90 questions |
| 12 | Full-length adaptive simulations and weak-area drilling | 2–3 full simulations |
Six focused hours a week for sixteen weeks beats twenty hours a week for four weeks. Retention is a function of spacing, not intensity.
How to actually study each domain
- Read once, fast. One pass through the domain material to build a map. Do not highlight everything.
- Answer questions immediately. Practice questions are the study method, not the assessment. Do them while the material is still slightly unfamiliar.
- Read every explanation — including the ones you got right. Getting a question right for the wrong reason is the single biggest source of exam-day surprises.
- Write down the distinction that tripped you. Owner vs custodian. Preventive vs detective. RTO vs RPO. Those one-line distinctions are what the exam actually tests.
- Re-drill the weak domain within 48 hours. Spacing works; cramming does not.
Materials worth your money
- One primary text. The Official Study Guide or Shon Harris — pick one and finish it. Two books is procrastination in disguise.
- One large question bank with written rationales for every option, not just the correct one.
- An adaptive practice mode that raises difficulty as you improve, so you are not repeatedly answering questions you have already mastered.
- A one-page summary per domain you wrote yourself. Someone else's cheat sheet is worth roughly nothing.
Knowing when you are ready
- You score consistently above 75% on unseen, difficulty-mixed questions — not on questions you have seen before.
- No domain sits more than 10 points below your average.
- You can explain why the three wrong answers are wrong, not just recognise the right one.
- You finish 100 questions in under two hours without your accuracy collapsing in the last twenty.
If a readiness score is available to you, treat it as a trend line rather than a verdict. A stable, rising score across several sessions is far more meaningful than one good night.
Frequently asked questions
Can I pass the CISSP with self-study only?
Yes. Most candidates pass with a primary textbook, a large practice-question bank, and a disciplined schedule. Bootcamps compress the timeline but do not replace spaced practice.
Do I need to memorise port numbers and algorithms?
A small number are worth knowing, but the exam rewards understanding why a control is chosen far more than recall of specifics. Prioritise concepts and process order.
How many practice questions should I do?
Most successful candidates answer between 1,000 and 2,000 questions with full explanation review. Volume matters less than reviewing every rationale.
Study with adaptive, scenario-based questions
Domain Eight covers all eight domains with managerial, best-answer questions and a written rationale for every option — plus an adaptive engine that keeps you at the edge of your ability.
Related guides
- CISSP Exam GuideQuestion count, time limit, adaptive scoring, test-centre rules and what happens on results day.
- Best CISSP Practice TestsHow to spot a question bank that actually mirrors the exam, and how to drill with it.
- How to Pass the CISSPThe mindset, the practice routine, and the exam-day discipline that produce a first-attempt pass.
- How Long to Study for CISSPHonest timelines by experience level, plus the readiness signals that say you are ready to book.
More CISSP study material from Domain Eight: browse all resources.
