CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingA structured week-by-week CISSP study plan covering domain order, practice-test checkpoints and review cycles, adaptable to 8, 12 or 16 weeks.

A workable CISSP study plan does three things: it sequences the eight domains in an order that builds understanding rather than following the outline numerically, it fixes practice-test checkpoints at set weeks so you measure progress instead of guessing, and it protects the final fortnight for review rather than new material. This article gives you that structure — a twelve-week framework you can compress to eight weeks or stretch to sixteen — and explains the reasoning behind each decision so you can adapt it to your own gaps.
To be clear about scope: this is the structural plan. If you want a walkthrough of which books, courses and question banks to use, that lives in our CISSP exam preparation guide. If you are still deciding how many total weeks you need for your experience level, see how long CISSP preparation takes. This article assumes you have committed to a window and now need to fill it intelligently.
The Certified Information Systems Security Professional (CISSP) exam, run by ISC2, has used Computerized Adaptive Testing (CAT) in all languages since April 2024. You face 100 to 150 questions in a maximum of three hours, the questions adapt to your performance, and you cannot return to a previous question. As of 2026 the exam costs $749 USD in the Americas (pricing varies by region — confirm on ISC2's site), and results are reported as pass or fail against a 700/1000 standard, with no numerical score released.
Three planning consequences follow directly from that format:
One more format note that shapes sequencing: the April 2024 outline refresh nudged Domain 1 (Security and Risk Management) up to 16% and Domain 8 (Software Development Security) down to 10%. Domain 1 is both the heaviest and the most conceptual — which is exactly why it anchors the start of the plan below. For a full breakdown of what each domain actually tests, see our CISSP exam domains explained article; this plan deals with when to study them, not what is in them.
The eight CISSP domains in the 2024 outline are:
Studying them in numerical order is not wrong, but it front-loads the two most abstract domains (1 and 2) and back-loads Software Development Security — the domain most non-developers find alien — into the weeks when fatigue is highest. A better sequence for most candidates:
| Order | Domain | Reasoning |
|---|---|---|
| 1st | Domain 1 — Security and Risk Management | Heaviest weighting (16%) and supplies the vocabulary — risk, governance, legal concepts — every other domain assumes |
| 2nd | Domain 3 — Security Architecture and Engineering | The technical backbone; models and cryptography concepts here resurface in Domains 4, 5 and 8 |
| 3rd | Domain 4 — Communication and Network Security | Builds directly on Domain 3; most technical candidates find it familiar, so it provides momentum mid-plan |
| 4th | Domain 5 — Identity and Access Management | Ties architecture to operations; a frequent weak spot worth hitting while energy is high |
| 5th | Domain 2 — Asset Security | Shorter, more conceptual; pairs naturally with the classification ideas from Domain 1 you now revisit |
| 6th | Domain 7 — Security Operations | Broad but concrete; benefits from everything learned so far |
| 7th | Domain 6 — Security Assessment and Testing | Compact and logical once operations context exists |
| 8th | Domain 8 — Software Development Security | Deliberately last-but-before-review: unfamiliar content stays freshest, and its reduced 10% weighting means it deserves focused but not extended time |
Adjust for yourself: if you are a developer, swap Domain 8 earlier and give the reclaimed late slot to whichever domain your diagnostic test (week one, below) flags as weakest.
This framework assumes roughly 10–15 hours per week. It is a structure, not a guarantee — nobody can promise that a set number of hours passes the exam — and if you are fitting study around a demanding job, our CISSP study schedule for working professionals adapts this same skeleton to early-morning and weekend blocks.
The skeleton — sequence, three checkpoints, protected final review — survives rescaling; only the block lengths change.
A useful test for any rescaled plan: count backwards from exam day. If new material appears inside the final 15% of your calendar, the plan is overloaded — cut depth from your strongest domain, never from review.
Consider a network engineer with six years' infrastructure experience, aiming for a mid-December exam from a mid-September start. Her week-one diagnostic shows Domains 3 and 4 comfortably above her average, Domains 1, 5 and 8 well below. She keeps the sequence above but shortens Domain 4 to half a week, reallocating the time to Domain 1, and moves Domain 8 from week 10 to week 6 — placing her most alien content in a high-energy slot and accepting slightly less freshness at exam time in exchange. Her checkpoints stay exactly where the framework puts them. That is the intended relationship between you and this plan: the sequence flexes around your diagnostic; the measurement structure does not.
For practice material to run those checkpoints against, ExamPractice offers free sample questions you can use for the week-one diagnostic, with fuller question sets and a timed simulation mode for the full-length sittings available to subscribers — see the practice test simulation overview when you reach week 4 and need your first properly timed block.
For many candidates with solid experience across several domains, a 12-week plan at 10–15 hours per week is a common and realistic structure — but "enough" depends on your baseline, which is why this plan starts with a diagnostic rather than an assumption. Candidates further from the material should use the 16-week variant.
There is no requirement to. The official outline orders domains 1 to 8 for reference, not pedagogy. The sequence in this article front-loads the heaviest domain, clusters technically related domains together, and schedules the most commonly unfamiliar one late enough to stay fresh — then bends to whatever your diagnostic reveals.
Fix the structure — a diagnostic, weekly domain blocks, three checkpoints, two full-length simulations — rather than chasing a raw question total. Volume without timed conditions and answer review adds little; a smaller number of questions, each reviewed properly, teaches more.
Not study time, but do check eligibility before booking: CISSP requires five years of qualifying work experience (with a possible one-year waiver), and there is an Associate of ISC2 route if you fall short — the details are in our CISSP experience requirements guide.
The content of the CISSP is fixed by ISC2's exam outline; what your study plan adds is measurement. The domain sequence gets you through the material in an order that compounds, but the diagnostic, the three checkpoints and the protected review fortnight are what separate a plan from a reading list — they tell you, weeks in advance, whether you are on track and exactly where you are not. Build those into whatever calendar you have, adjust the sequence to your own baseline, and confirm current exam details (fees, outline version, scheduling) on ISC2's official CISSP pages before you book.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading