You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The Certified Information Systems Security Professional (CISSP) certification validates your ability to design, implement, and manage a best-in-class cybersecurity program. It is for experienced security practitioners, managers, and executives who lead organizational security strategy and operations. Earning CISSP proves your expertise across eight security domains and grants you ISC2 membership with access to exclusive resources and a global community of cybersecurity leaders.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The Certified Information Systems Security Professional (CISSP) is the world's premier cybersecurity certification, recognized globally as a benchmark for security leadership. It validates an information security professional's deep technical and managerial knowledge and experience to effectively design, engineer, and manage the overall security posture of an organization. CISSP covers eight comprehensive domains, from security and risk management to software development security, ensuring relevance across all disciplines in the field.
Earning the CISSP demonstrates that you have what it takes to lead an organization's information security program. It proves your expertise in designing, implementing, and managing best-in-class cybersecurity programs, and it opens doors to advanced career opportunities and higher earning potential. As an ISC2 member, you join a community of cybersecurity leaders and gain access to exclusive resources, educational tools, and peer-to-peer networking opportunities.
The CISSP is ideal for experienced security practitioners, managers, and executives who are responsible for leading an organization's information security program. It is designed for professionals who need to prove their knowledge across a wide array of security practices and principles, including those in positions such as Chief Information Security Officer, Chief Information Officer, Director of Security, IT Director/Manager, Security Systems Engineer, Security Analyst, Security Manager, Security Auditor, Security Architect, Security Consultant, and Network Architect. If you are a seasoned cybersecurity professional looking to validate your expertise, advance your career, and gain the support of a community of leaders, the CISSP is the credential for you.
A minimum of five years of cumulative, full-time experience in two or more of the eight CISSP domains is required. A post-secondary degree in computer science, IT, or a related field, or an approved credential, may waive up to one year of experience. Experience in security and risk management; Experience in asset security; Experience in security architecture and engineering; Experience in communication and network security; Experience in identity and access management; Experience in security assessment and testing; Experience in security operations; Experience in software development security
Every domain and objective ISC2 measures, with the weight they carry on the exam.
The official ISC2 exam outline · checked 30 July 2026 · See the source
Everything ISC2 publishes about sitting it, and nothing we inferred.
Minimum of five years of cumulative, full-time experience in two or more of the eight CISSP domains.
The path ISC2 lays out, how the credential is kept, and where to book.
Step-by-step path to Certified Information Systems Security Professional
CISSP certification is valid for three years. To maintain the credential, you must earn continuing professional education (CPE) credits and pay an annual maintenance fee (AMF). Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. ISC2 maintains this certification to validate current skills and industry relevance.
Register for the exam through Pearson VUE, ISC2’s authorized testing partner.
Schedule your examVisit the official ISC2 certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksCC is an entry-level certification for those new to cybersecurity, while SSCP is for hands-on security professionals with at least one year of experience. CISSP is the advanced credential for experienced practitioners and leaders. Earning CC or SSCP can help build foundational knowledge and prepare for the CISSP.
No, the CISSP can be taken directly. However, you must meet the required work experience in at least two of the eight domains. If you lack the experience, you can pass the exam and become an Associate of ISC2, then earn the required experience within six years.
Yes, the CISSP exam is available in Chinese, English, German, Japanese, and Spanish. Chinese language exams are only offered during specific appointment windows: March 1-31, June 1-30, September 1-30, and December 1-31.
ISC2 exam retake policies are detailed in the exam policies and procedures. Generally, if you fail an exam, you must wait a specified period before retaking it. For Peace of Mind Protection purchases, there is a 30-day waiting period between attempts.
ISC2 offers a Peace of Mind Protection option that includes two exam attempts at a lower cost than two single exams. This can be purchased with the exam or as part of training bundles. Discounts may be available through ISC2 membership or other promotions.
No, the CISSP exam is a Computerized Adaptive Test (CAT) consisting of multiple choice and advanced item types. There is no hands-on lab component.
You will receive a preliminary pass/fail result at the test center immediately after completing the exam. Official results and score reports are typically available within a few weeks.
The CISSP is ideal for experienced security practitioners, managers, and executives, including roles such as Chief Information Security Officer, Chief Information Officer, Director of Security, IT Director/Manager, Security Systems Engineer, Security Analyst, Security Manager, Security Auditor, Security Architect, Security Consultant, and Network Architect.
Yes, earning an advanced ISC2 certification, such as ISSAP, ISSEP, or ISSMP, may help you meet CPE requirements and demonstrate continued expertise, but it does not automatically renew the CISSP. You must still earn CPE credits and pay the AMF.
Yes, the CISSP exam is delivered at ISC2 Authorized PPC and PVTC Select Pearson VUE Testing Centers. Chinese language exams are only available during specific appointment windows, and availability may vary by region.
Every domain, every objective, and every concept ISC2 measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official ISC2 exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
26 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 62 objectives, 452 concepts written under them, and free questions against every one. When ISC2 changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.