CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingFailed the CISA exam? Here are ISACA's retake rules, waiting periods and fees, plus a diagnosis-first plan for turning a near miss into a pass.

You saw the preliminary "fail" on the screen, and it stings. Here is the practical position: under ISACA's retake policy you may attempt the Certified Information Systems Auditor (CISA) exam up to four times within a rolling twelve-month period, you must wait 30 days after a first failed attempt (90 days after the second and third), and each attempt requires the full registration fee again — US$575 for ISACA members, US$760 for non-members, as of 2026. That 30-day floor is not an obstacle; used properly, it is roughly the minimum time a well-diagnosed second campaign needs anyway.
A failed CISA attempt is also far less predictive than it feels in the moment. The exam is scored on a 200–800 scale with 450 to pass, and a miss tells you that on one four-hour afternoon your performance fell short of a line — not that you cannot clear it. What separates candidates who pass the retake from those who repeat the result is almost never raw effort. It is whether they diagnose why attempt one failed before deciding how to prepare for attempt two. This guide covers exactly that post-failure path: the rules, the diagnosis, and the revised plan. (If you are planning a first attempt, start instead with the CISA exam preparation guide.)
The retake logistics come from ISACA's certification exam candidate guide, and they shape every scheduling decision:
Two planning consequences follow. First, do not re-register in the heat of the moment — your new six-month eligibility clock starts at registration, so register when your revised plan has a realistic exam date, not the day after the bad news. Second, wait for the official score report before building that plan, because it is your single best diagnostic document.
Your official CISA score report shows how you performed by domain, and this is where retake preparation genuinely begins. Resist the urge to simply "study everything harder". Instead, sort your result into one of three failure profiles, because each demands a different second campaign.
Your scaled score landed close below 450 and one or two domains stand out as clearly weaker. This is the most fixable profile. Your revised plan should be short and asymmetric: perhaps 70% of your hours on the weak domains, 30% on maintaining the rest. Note the arithmetic of the 2024 outline: Domain 4 (Information Systems Operations and Business Resilience) and Domain 5 (Protection of Information Assets) each carry 26% of the exam, while Domain 3 carries just 12%. A weak Domain 4 is a much bigger leak than a weak Domain 3, and deserves proportionally more of your remediation time. A refresher on what each domain actually tests is in CISA exam domains explained.
Your score fell well short and no single domain explains it. This usually means the first preparation was too shallow across the board — often reading-heavy and question-light. The fix is not the same plan repeated louder; it is a structurally different one: a longer runway (think in months, not weeks), a return to the CISA Review Manual or an equivalent core resource for genuine gaps, and far more question practice woven through from week one. The 90-day wait that follows a second failed attempt is expensive in time and confidence, so it is worth taking an honest extra month now rather than rushing back at 30 days underdone.
Your domain results look respectable, your practice scores were decent, and yet the total fell short. Suspect execution rather than knowledge: pacing that collapsed in the final hour, misread operative words (FIRST, BEST, MOST likely), second-guessing, or exam-day nerves. Your remediation is conditions, not content — full-length timed simulations, a drilled question-reading routine, and a rehearsed exam-day plan. Many candidates in this profile need only two or three weeks of targeted work, almost all of it under timed conditions.
The score report tells you where marks were lost; only you can work out why. Before writing the new plan, answer these questions honestly — in writing, ideally:
The answers convert a vague sense of "I need to study more" into two or three specific defects your second campaign is built to eliminate.
With a diagnosis in hand, structure the retake window in three stages. For a near miss, the whole cycle can fit inside four to six weeks; a broad shortfall may need two to three months. (ISACA publishes no official study-hours figure, so calibrate to your own diagnosis rather than to forum folklore.)
Restudy only what the diagnosis indicts. Work through the weak domains with your core resource, but change the method from round one: summarise each topic in your own words, and follow every study session with a short block of questions on that topic the same day. If your first attempt relied on one prep source, add a second perspective on the weak areas — a different explanation often dislodges a misunderstanding that repetition of the same material cannot.
Shift the balance of your week decisively toward practice questions across all five domains, reviewed rigorously: log every miss, classify it (knowledge, misreading, judgement, timing), and write the rationale for the correct answer in your own words. Fresh questions matter more than ever on a retake, because inflated familiarity with your old bank is one plausible reason attempt one's practice scores misled you. The free CISA sample questions on ExamPractice are a low-cost way to add an unfamiliar source, with fuller sets and a timed simulation mode available to subscribers. The detailed method for sequencing, scoring and reviewing this work is its own discipline, covered in our CISA practice test strategy — treat that loop as the engine of your retake.
Before you sit again, demand evidence that the defects are fixed. That means at least two full-length, four-hour timed mocks on questions you have not seen, scored by domain. The verification standard is simple: the domains that failed you last time should now be performing at least as well as your strong ones, under full exam conditions, on fresh material. If they are not, move the exam date — rescheduling is free with 48 hours' notice, and a slipped week is cheaper than a third registration fee.
Two psychological traps catch retakers. The first is rushing: booking at exactly 30 days to "get it over with", with a plan built on urgency rather than diagnosis. The second is drift: letting the retake slide indefinitely because the first result dented your confidence, until the material has gone stale and the six-month eligibility window becomes a deadline problem. The corrective for both is the same — set the exam date off the back of your verification stage, register when the plan says so, and let evidence, not emotion, choose the day.
It also helps to reframe what the first attempt bought you. You have sat the real exam once: you know the check-in process, the question style, the feel of hour three. No first-time candidate has that. Combined with a domain-level map of your weaknesses, you are objectively better positioned than you were before attempt one — provided you use the information. And if part of what unsettled you was the exam living up to its reputation, it may help to know that experienced professionals routinely find it demanding; see how hard the CISA exam is for that context in full.
Consider an internal auditor who scored just under the pass mark, with Domain 5 (Protection of Information Assets) clearly weakest and time pressure in the final 30 questions. Her retake plan: register for a date roughly six weeks out; two weeks rebuilding Domain 5 topics with same-day question blocks; two weeks of mixed timed sets across all domains with a strict 90-seconds-per-question cap and a written error log; then two full mocks a week apart, both scored by domain. Domain 5 rises to match her other domains on fresh questions in the second mock, she keeps her booked date, and she walks in having already fixed — in private — the two specific problems that failed her in public. That is the entire philosophy of retake preparation in one paragraph.
Thirty days after a first attempt. After a second or third attempt the wait extends to 90 days, and ISACA permits at most four attempts in any rolling twelve-month period. You must register and pay the full fee again for each attempt.
Yes. Each attempt requires a new registration at the standard fee — US$575 for members, US$760 for non-members as of 2026 (confirm current pricing on isaca.org). There is no reduced retake rate, which is a strong financial argument for verifying readiness with full-length mocks before booking.
A failed attempt does not block you from certifying once you pass. Certification is applied for after a passing score (within five years of it, alongside the experience requirement and a US$50 application fee); ISACA's process is built around your passing result.
Switch or supplement in your weak areas, keep what worked elsewhere. If your diagnosis points to shallow coverage or a memorised question bank, adding a fresh question source and a second explanation of weak topics is usually more valuable than replacing everything.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading