Doc CC-08Rev 2026-10Class study materialRead ~10 min
CISSP study plan: a self-paced 8–12 week schedule and what to study from
This self-paced study plan for the ISC2 CISSP (Certified Information Systems Security Professional) assumes 8 to 12 weeks at about 10 hours a week, spends its time in proportion to the 2024 domain weights — Domain 1 at 16% gets the most — and ends with two weeks of weak-spot repair instead of new reading.
Exam readout
- Format
- CAT, every language
- Items
- 100–150
- Time
- 3 hours
- Pass mark
- 700 / 1000 scaled
- Outline
- 8 domains · Apr 2024
How long to study for the CISSP
Plan on 8 to 12 weeks if you already work in security, and the full 12 if your experience sits in only two or three of the eight domains. The exam samples all eight, so the domains you have never touched at work decide how long the plan runs, not the ones you could teach.
Hours matter more than calendar weeks. Both schedules below assume about 10 focused hours a week: roughly 80 hours on the 8-week version, 120 on the 12-week one. Ten hours you actually sit through beat twenty you scheduled on a Sunday evening in a burst of optimism.
Settle the choice of certification before week 1: if you are still weighing this one against ISACA’s management credential, read CISSP vs CISM first. What the exam looks like on the day is on the exam format page, so this page skips it.
Where the hours go
The current outline (effective April 2024) splits the exam across eight domains. The plan follows the meters: Domain 1 gets two weeks, the two 10% domains the lightest slots.
D1Security and Risk Management
16%
D2Asset Security
10%
D3Security Architecture and Engineering
13%
D4Communication and Network Security
13%
D5Identity and Access Management
13%
D6Security Assessment and Testing
12%
D7Security Operations
13%
D8Software Development Security
10%
CISSP domain weights, outline effective April 2024
The 12-week CISSP study plan
One domain per content week, in outline order, with one concrete thing to be able to do by Sunday. If you cannot, the domain borrows an evening from the next week.
| Week | Focus | Weight | By the end of the week you can… |
|---|---|---|---|
| Week 1 | Domain 1, part 1: governance and roles, the ISC2 Code of Ethics canons, policy vs standard vs procedure vs guideline. Start with the Domain 1 guide | 16% | rank the four canons and say which one wins when two conflict |
| Week 2 | Domain 1, part 2: quantitative risk, risk responses, control types, BIA metrics, law and investigation types | 16% | work out whether a safeguard pays for itself, including its own annual cost |
| Week 3 | Domain 2 Asset Security: data roles, classification, retention, sanitization by media type, scoping vs tailoring | 10% | say who classifies data, who backs it up, and why degaussing does nothing to an SSD |
| Week 4 | Domain 3, part 1: security models, secure design principles, reference monitor and TCB. Use the Domain 3 guide | 13% | draw the Bell–LaPadula and Biba rules without swapping the arrows |
| Week 5 | Domain 3, part 2: cryptography and PKI, attacks on cryptography, site and facility controls, fire classes | 13% | count the keys n users need, symmetric and asymmetric |
| Week 6 | Domain 4 Communication and Network Security: OSI placement, IPsec, wireless, segmentation, SDN | 13% | place a protocol on its layer and tell AH from ESP |
| Week 7 | Domain 5 Identity and Access Management: factors, SSO and federation, Kerberos, access-control models, provisioning | 13% | tell role-based from rule-based access control — the two RBACs |
| Week 8 | Domain 6 Security Assessment and Testing: test types, audits, KPIs and KRIs, reporting | 12% | choose the kind of test that fits a stated goal |
| Week 9 | Domain 7 Security Operations: evidence handling, incident steps, change and patch management, backups, recovery sites, DR tests | 13% | list DR test types from least to most disruptive |
| Week 10 | Domain 8 Software Development Security: SDLC models, maturity models, SAST/DAST/IAST, acquired-software risk | 10% | say where security enters the SDLC (the beginning, every time) |
| Week 11 | Weak-spot repair: the two lowest domains on your readout, plus mixed sets across all eight | — | explain every miss from the last ten days in one line |
| Week 12 | Timed runs, the manager-mindset review, the exam-week checklist | — | finish a Timed 60 inside 72:00 without rushing the last ten items |
Domain 3 gets two weeks at 13% because it is the densest reading of the eight: models, cryptography and facility controls in one domain.
The weekly loop
Every content week runs the same five moves. The order matters more than which material you use for each one.
Step 01
Read (two evenings)
Read the week’s chapters in one comprehensive textbook aligned to the April 2024 outline. Read for contrasts — owner vs custodian, AH vs ESP, due care vs due diligence — because that is where the exam puts its distractors.
Step 02
Watch (one evening, optional)
Use video only for what the reading did not land: usually cryptography, the security models and Kerberos.
Step 03
Drill
Open the practice test, pick the week’s domain chip in Drill and answer every item in it. Read the note on all four options, including the ones you got right for the wrong reason.
Step 04
Log the misses
Write each miss as a one-line rule in your own words, such as
the owner classifies; the custodian protects
. By week 11 this page is your entire revision sheet.Step 05
Mixed set and readout (weekend)
A short mixed set across every domain so far, then the domain readout. A finished domain that is sliding gets 30 minutes of the coming week.
What to study from
You need four things: the exam outline, one comprehensive textbook, one large set of practice questions with explanations, and something for the topics that refuse to stick. A video course and flashcards are optional. A second textbook is rarely worth the hours; a second pass through the first one usually is.
The outline is free on isc2.org and is the only list of what can be asked. It explains nothing; that is the textbook’s job. Read it in week 1 for the shape of the domains and again in week 11 as a checklist.
| Material | Good for | Weak at | Where it sits in the plan |
|---|---|---|---|
| Exam outline | the full list of domains and sub-topics, with weights | explaining any of them | week 1, then as a checklist in week 11 |
| Comprehensive textbook | depth, vocabulary and the contrasts the exam tests | judgment under time pressure | weeks 1–10, two evenings a week |
| Video course or class | topics where a diagram beats a page: cryptography, models, network layers | covering all eight domains efficiently | as needed, one evening a week |
| Practice questions with rationales | finding gaps and learning the manager’s answer | teaching a domain from zero | from week 1, every week |
| Flashcards | acronyms, formulas, model rules, BIA terms | anything scenario-based | ten minutes a day, never instead of drilling |
| Domain readout | showing which domain is sliding before you notice | predicting a pass — it does not | every weekend |
On courses: ISC2 sells its own self-paced and instructor-led training, and many independent providers run classes and bootcamps. We do not rank them and we are not one of them. The same filter as for books applies — aligned to the April 2024 outline, practice items explained option by option, no promise of actual exam content. A course is a pacing device; the plan works with or without one.
Answer as the security manager who has to sign the decision, not the administrator who has to type it.
The rule behind most close calls on the CISSP
Study the judgment, not only the facts
Most CISSP items have two options that would work and one that the exam wants. The one it wants usually follows a fixed order of priorities: human safety first, then the organization’s business objectives, then policy and process, and only then the technical fix. Senior management owns risk and accepts it; the security function advises, recommends and escalates.
That is why technically strong candidates miss items they could solve at work in five minutes. In your misses log, note which rung of that order you skipped; after three weeks it is usually the same rung.
Can you pass the CISSP in 30 days?
It can work if two things are true: day-to-day experience across most of the eight domains, and 20 or more study hours a week for the whole month. The 30-day plan is the 8-week table below run at double speed, not a shorter list of topics.
Cut reading in the domains you practice daily. Never cut Domain 1 at 16%, the weak-spot week or the timed runs. If one domain still trails the others at the end of week three, move the date: the adaptive exam will notice, since noticing is its whole method.
| Week | Focus | What you give up |
|---|---|---|
| Week 1 | Domain 1 Security and Risk Management | depth on law and investigation types; keep risk math and the ethics canons |
| Week 2 | Domain 2 and Domain 8, the two 10% domains | a full read of both; let drilling find the gaps |
| Week 3 | Domain 3 Security Architecture and Engineering | the second week; cryptography first, facilities last |
| Week 4 | Domain 4 Communication and Network Security | video for anything you configure at work |
| Week 5 | Domain 5 and Domain 6 | a quarter of the outline in seven days; skim what you do daily |
| Week 6 | Domain 7 Security Operations | re-reading; go straight to items after one pass |
| Week 7 | Weak-spot repair from the readout | nothing — this week stays |
| Week 8 | Timed runs and the exam-week checklist | nothing — this one stays too |
How to tell you are ready
No practice score predicts a CISSP pass. These are the signs worth trusting instead.
- Every domain on the readout sits close to the others; none trails far behind.
- Your misses log for the last two weeks holds more repeats you now get right than brand-new rules.
- You finish a Timed 60 inside 72:00 — the same 72 seconds per item that 150 items in 3 hours allows — without rushing the end.
- On items you got right, you can say why each wrong option is wrong.
- You can do SLE/ALE and key-count arithmetic without looking anything up.
- You no longer change answers on a second read, which matters on an exam with no going back.
Try three Domain 4 items
Week 6 of the plan, Communication and Network Security, at 13% of the outline. Read the note on every option before you move on.
Domain drill
Item 01 / 03
Answer, then read why each option is right or wrong. Keys 1–4 pick, N goes next.
A network engineer is diagnosing performance degradation on a high-throughput site-to-site IPsec VPN. The tunnel frequently drops packets during periods of peak utilization. Investigation reveals that both the IKE Phase 1 and IPsec Phase 2 Security Association (SA) lifetimes are configured to expire simultaneously every hour. Which configuration adjustment BEST resolves this performance disruption?
Rationale
Pick an answer. The reasoning for every option lands here — including why the wrong ones looked right.
If you failed: rebuilding the plan
A failed attempt comes with domain proficiency levels instead of a score, which is a bad day with a genuinely useful printout. Rebuild the plan from it: domains reported below proficiency get the content weeks back, everything else drops to one mixed set a week to stay warm.
Plan on roughly 4 to 6 weeks for a retake: one or two weak domains at a week each, a fresh weak-spot week, and timed runs. Waiting periods and attempt limits change from time to time, so check them on the exam format page and on isc2.org before you book.
Exam week
- Stop new reading two days out. Re-read your misses log instead.
- Confirm the Pearson VUE test center, the time and the route. CISSP is delivered at test centers, not from home.
- Check that the name on your registration matches your ID exactly — this week, not at the front desk.
- Pace at roughly 72 seconds an item. There is no going back, so answer, commit and move on.
- Sleep. Domain 1 at two in the morning has never moved anyone’s result in the right direction.
Questions people ask
Q01How long should I study for the CISSP?
This plan assumes 8 to 12 weeks at about 10 hours a week, which is 80 to 120 hours, for someone already working in security. Treat that as a starting budget, not a norm: take the full 12 weeks, or more, if your experience covers only two or three of the eight domains.
Q02What is the best way to study for the CISSP?
Weight your weeks by the 2024 domain weights, read one comprehensive textbook, drill practice items with explanations every week, and log every miss as a one-line rule. Then train the manager’s judgment: safety first, business objectives next, technology last.
Q03Can I pass CISSP in 30 days?
It is possible if you already work across most of the domains and can study 20 or more hours a week. Run the 8-week schedule at double pace and keep Domain 1, the weak-spot week and the timed runs.
Q04Is there free CISSP training available?
Free material covers more than people expect: the exam outline on isc2.org, the free practice test and domain guides on this site, and many textbooks through libraries. Paid courses exist from ISC2 and independent providers, but a course is not required to sit the exam.
Q05Which CISSP book should I use?
One comprehensive textbook aligned to the April 2024 outline, plus a large bank of practice questions with explanations. We don’t rank publishers; check the edition date and that the book shows the current domain weights.
Keep going
Field kit
Take the weekly drill on the road
Twelve weeks of drilling fits a commute better than a desk. The CISSP prep app carries a larger question bank, on iPhone and Android.