Exampractice
Cybersecurity

How to Build a CISSP Study Plan

A structured week-by-week CISSP study plan covering domain order, practice-test checkpoints and review cycles, adaptable to 8, 12 or 16 weeks.

Alexander Novak · 10 min read
Twelve-week CISSP study plan calendar with eight colour-coded domain blocks and practice-test checkpoint flags

A workable CISSP study plan does three things: it sequences the eight domains in an order that builds understanding rather than following the outline numerically, it fixes practice-test checkpoints at set weeks so you measure progress instead of guessing, and it protects the final fortnight for review rather than new material. This article gives you that structure — a twelve-week framework you can compress to eight weeks or stretch to sixteen — and explains the reasoning behind each decision so you can adapt it to your own gaps.

To be clear about scope: this is the structural plan. If you want a walkthrough of which books, courses and question banks to use, that lives in our CISSP exam preparation guide. If you are still deciding how many total weeks you need for your experience level, see how long CISSP preparation takes. This article assumes you have committed to a window and now need to fill it intelligently.

What the exam format means for your plan

The Certified Information Systems Security Professional (CISSP) exam, run by ISC2, has used Computerized Adaptive Testing (CAT) in all languages since April 2024. You face 100 to 150 questions in a maximum of three hours, the questions adapt to your performance, and you cannot return to a previous question. As of 2026 the exam costs $749 USD in the Americas (pricing varies by region — confirm on ISC2's site), and results are reported as pass or fail against a 700/1000 standard, with no numerical score released.

Three planning consequences follow directly from that format:

  1. You cannot afford weak domains. An adaptive exam probes until it finds your level in the material it samples. A plan that lets you skip Domain 8 because "it's only 10%" leaves a hole the exam can find. Every domain gets scheduled time.
  2. Decision speed matters. With no review and no going back, you need to practise committing to answers under time pressure. That is why this plan includes timed question blocks from week three onwards, not just at the end.
  3. Stamina is a trainable skill. Three hours of adaptive questioning is draining. At least one full-length timed simulation belongs in the plan before exam day.

One more format note that shapes sequencing: the April 2024 outline refresh nudged Domain 1 (Security and Risk Management) up to 16% and Domain 8 (Software Development Security) down to 10%. Domain 1 is both the heaviest and the most conceptual — which is exactly why it anchors the start of the plan below. For a full breakdown of what each domain actually tests, see our CISSP exam domains explained article; this plan deals with when to study them, not what is in them.

The domain study order, and why it is not 1 through 8

The eight CISSP domains in the 2024 outline are:

  1. Security and Risk Management
  2. Asset Security
  3. Security Architecture and Engineering
  4. Communication and Network Security
  5. Identity and Access Management (IAM)
  6. Security Assessment and Testing
  7. Security Operations
  8. Software Development Security

Studying them in numerical order is not wrong, but it front-loads the two most abstract domains (1 and 2) and back-loads Software Development Security — the domain most non-developers find alien — into the weeks when fatigue is highest. A better sequence for most candidates:

OrderDomainReasoning
1stDomain 1 — Security and Risk ManagementHeaviest weighting (16%) and supplies the vocabulary — risk, governance, legal concepts — every other domain assumes
2ndDomain 3 — Security Architecture and EngineeringThe technical backbone; models and cryptography concepts here resurface in Domains 4, 5 and 8
3rdDomain 4 — Communication and Network SecurityBuilds directly on Domain 3; most technical candidates find it familiar, so it provides momentum mid-plan
4thDomain 5 — Identity and Access ManagementTies architecture to operations; a frequent weak spot worth hitting while energy is high
5thDomain 2 — Asset SecurityShorter, more conceptual; pairs naturally with the classification ideas from Domain 1 you now revisit
6thDomain 7 — Security OperationsBroad but concrete; benefits from everything learned so far
7thDomain 6 — Security Assessment and TestingCompact and logical once operations context exists
8thDomain 8 — Software Development SecurityDeliberately last-but-before-review: unfamiliar content stays freshest, and its reduced 10% weighting means it deserves focused but not extended time

Adjust for yourself: if you are a developer, swap Domain 8 earlier and give the reclaimed late slot to whichever domain your diagnostic test (week one, below) flags as weakest.

The twelve-week CISSP study plan

This framework assumes roughly 10–15 hours per week. It is a structure, not a guarantee — nobody can promise that a set number of hours passes the exam — and if you are fitting study around a demanding job, our CISSP study schedule for working professionals adapts this same skeleton to early-morning and weekend blocks.

Weeks 1–2: Baseline and Domain 1

  • Week 1. Sit an untimed diagnostic set of practice questions across all eight domains before you study anything. The score does not matter; the per-domain spread does. Record it — this is the baseline every later checkpoint is compared against. Spend the rest of the week on the first half of Domain 1: security governance, legal and regulatory concepts, professional ethics.
  • Week 2. Finish Domain 1: risk management frameworks, threat modelling, supply-chain risk, awareness. End the week with a 30–40 question block on Domain 1 only, untimed, reviewing every answer — right or wrong — against the reasoning.

Weeks 3–5: The technical core

  • Week 3. Domain 3, first pass: security models, evaluation criteria, secure design principles. Introduce your first timed question block (aim for roughly a minute and a half per question) to start building CAT-style commitment habits.
  • Week 4. Domain 3, second half (cryptography, physical security), then begin Domain 4. Checkpoint 1: a mixed 50-question timed set covering Domains 1 and 3. Log per-domain accuracy.
  • Week 5. Complete Domain 4: secure network components, protocols, wireless and remote access. Weekly domain-specific question block as usual.

Weeks 6–8: Identity, assets and operations

  • Week 6. Domain 5 in full — identification, authentication, federation, authorisation mechanisms, access control attacks. This domain rewards hands-on mental walkthroughs: trace a login end to end and name every control it touches.
  • Week 7. Domain 2 (asset classification, handling, retention, data security controls), then start Domain 7. Because Domain 2 is compact, this is also your buffer week — if any earlier domain slipped, repay the debt now rather than letting it roll forward.
  • Week 8. Finish Domain 7: investigations, logging and monitoring, incident management, disaster recovery. Checkpoint 2: a half-length timed simulation (about 75 questions) across all domains studied so far. Compare per-domain results with your week-one baseline; any domain still below your average gets flagged for the review block.

Weeks 9–10: Final domains and first full simulation

  • Week 9. Domain 6 (assessment and testing strategies, vulnerability assessment, audits) — it is the shortest domain and pairs well with reviewing your own flagged weaknesses in the second half of the week.
  • Week 10. Domain 8: secure software development lifecycle, development environment security, software security assessment. At the weekend, sit your first full-length timed simulation under exam-like conditions — one sitting, no notes, no pausing. How you use that result matters more than the score; our CISSP practice test strategy article covers target scores and wrong-answer review in depth, so this plan simply fixes when the simulations happen.

Weeks 11–12: Review, not new material

  • Week 11. No new content. Work through your error log from every checkpoint, re-study the two or three weakest domains, and drill mixed timed blocks daily. Checkpoint 3: a second full-length simulation mid-week, leaving time to act on the result.
  • Week 12. Taper. Light mixed review, flashcards for memorisation-heavy items (models, key legal concepts, cryptographic characteristics), and rest. Book logistics early in the week and stop studying the day before the exam. Exam-day practicalities — ID, check-in, CAT pacing on the day — are covered in the CISSP exam day checklist, so they get one sentence here: read it in week 12, not the night before.

Compressing to 8 weeks or stretching to 16

The skeleton — sequence, three checkpoints, protected final review — survives rescaling; only the block lengths change.

  • 8-week version (for candidates with strong, current, broad security experience): merge Domains 2+5 into one block and Domains 6+7 into another, cut the buffer week, and keep both full-length simulations but only one mid-plan checkpoint. Non-negotiable: the final week remains review-only.
  • 16-week version (for candidates stretching toward the exam from adjacent IT roles, or studying under 10 hours a week): give Domains 1, 3 and 4 two full weeks each, add a fourth checkpoint after Domain 5, and schedule a deliberate one-week mid-plan rest around week 8 — long plans fail through burnout more often than through difficulty.

A useful test for any rescaled plan: count backwards from exam day. If new material appears inside the final 15% of your calendar, the plan is overloaded — cut depth from your strongest domain, never from review.

Common study-plan mistakes to design out

  • Sequencing by the book's chapter order without checkpoints. Reading cover to cover feels like progress but hides weak domains until it is too late to fix them. The checkpoints exist to make weakness visible early.
  • Doing thousands of questions but never a timed sitting. Untimed accuracy does not predict performance on an adaptive exam where you cannot revisit questions. From week 3, some portion of practice is always timed.
  • Memorising answers instead of reasoning. If you see a practice question twice and recognise the answer rather than re-deriving it, that question has stopped teaching you. Rotate question sources and always review the why, including for questions you got right. Practice questions test your understanding of the exam objectives — they are a measuring instrument, not a script to learn.
  • Treating the plan as fixed once written. The checkpoints are decision points. If Checkpoint 2 shows Domain 5 lagging, weeks 9–11 change. A plan you never revise is a plan you have stopped using.
  • Skipping the taper. Candidates who study until midnight before a three-hour adaptive exam trade marginal knowledge for meaningful fatigue. The taper is part of the plan, not a reward.

A worked example: the plan in one candidate's hands

Consider a network engineer with six years' infrastructure experience, aiming for a mid-December exam from a mid-September start. Her week-one diagnostic shows Domains 3 and 4 comfortably above her average, Domains 1, 5 and 8 well below. She keeps the sequence above but shortens Domain 4 to half a week, reallocating the time to Domain 1, and moves Domain 8 from week 10 to week 6 — placing her most alien content in a high-energy slot and accepting slightly less freshness at exam time in exchange. Her checkpoints stay exactly where the framework puts them. That is the intended relationship between you and this plan: the sequence flexes around your diagnostic; the measurement structure does not.

For practice material to run those checkpoints against, ExamPractice offers free sample questions you can use for the week-one diagnostic, with fuller question sets and a timed simulation mode for the full-length sittings available to subscribers — see the practice test simulation overview when you reach week 4 and need your first properly timed block.

Frequently asked questions

Is three months enough for a CISSP study plan?

For many candidates with solid experience across several domains, a 12-week plan at 10–15 hours per week is a common and realistic structure — but "enough" depends on your baseline, which is why this plan starts with a diagnostic rather than an assumption. Candidates further from the material should use the 16-week variant.

Should I study the CISSP domains in the official order?

There is no requirement to. The official outline orders domains 1 to 8 for reference, not pedagogy. The sequence in this article front-loads the heaviest domain, clusters technically related domains together, and schedules the most commonly unfamiliar one late enough to stay fresh — then bends to whatever your diagnostic reveals.

How many practice questions should my plan include?

Fix the structure — a diagnostic, weekly domain blocks, three checkpoints, two full-length simulations — rather than chasing a raw question total. Volume without timed conditions and answer review adds little; a smaller number of questions, each reviewed properly, teaches more.

Do I need to schedule time for the experience and endorsement requirements?

Not study time, but do check eligibility before booking: CISSP requires five years of qualifying work experience (with a possible one-year waiver), and there is an Associate of ISC2 route if you fall short — the details are in our CISSP experience requirements guide.

Your plan is a measurement system, not a syllabus

The content of the CISSP is fixed by ISC2's exam outline; what your study plan adds is measurement. The domain sequence gets you through the material in an order that compounds, but the diagnostic, the three checkpoints and the protected review fortnight are what separate a plan from a reading list — they tell you, weeks in advance, whether you are on track and exactly where you are not. Build those into whatever calendar you have, adjust the sequence to your own baseline, and confirm current exam details (fees, outline version, scheduling) on ISC2's official CISSP pages before you book.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like