The CISSP exam runs entirely on a Computerized Adaptive Testing (CAT) engine. You get between 100 and 150 questions, up to three hours to finish, and you pass by reaching a scaled score of 700 out of 1000. Since April 15, 2024, every language version of the exam uses this same adaptive format. Here’s how each piece works and what it means for how you study.
What is the CISSP CAT exam?
CAT stands for Computerized Adaptive Testing. Instead of handing every candidate the same fixed question set, the exam adjusts to you as you go. Answer an item correctly and the next one tends to be harder; miss one and the next tends to be easier. The goal is to home in on your true ability level with fewer questions than a traditional linear exam would need.
ISC2 moved English-language CISSP exams to CAT back in 2017. As of April 15, 2024, the remaining languages joined them, so the format is now the same worldwide.
How many questions is the CISSP exam?
You’ll see a minimum of 100 items and a maximum of 150. Twenty-five of those are unscored pretest questions ISC2 is trialing for future exams, and you won’t be able to tell which ones they are. The exam can end anywhere in that 100–150 range once the scoring engine is confident about your result, so two people sitting the same day may answer a different number of questions.
How long is the CISSP exam?
The maximum administration time is three hours. That’s tighter than the six-hour linear exam CISSP used years ago, so pacing matters. With 100 to 150 questions in 180 minutes, you have somewhere between roughly 72 seconds and just under two minutes per item. Most candidates who run short on time do so because they second-guess early answers, not because the questions are long.
What score do you need to pass the CISSP?
The passing standard is 700 out of 1000 points. One thing that surprises people: you don’t get a numeric score. Because the exam is adaptive and pass/fail, ISC2 reports only whether you passed. There’s no percentage, no per-domain breakdown on a pass, and no way to “bank” a high score. You cleared the bar or you didn’t.
How does the adaptive scoring actually work?
After every answer, the engine re-estimates your ability and picks the next question so that you have roughly a 50% chance of getting it right. That’s why the exam can feel relentlessly hard — it’s supposed to sit right at the edge of what you can do.
The exam ends using what ISC2 calls the confidence interval rule: once you’ve answered the minimum 100 items, it stops as soon as it can determine, with 95% statistical confidence, that your ability is clearly above or clearly below the pass point. If it can’t reach that confidence, it keeps going until you hit 150 questions or run out of time, then decides based on where you landed.
What are the eight CISSP domains and their 2024 weights?
The exam draws from eight domains in the Common Body of Knowledge. ISC2 updated the weights in the April 15, 2024 refresh based on its latest Job Task Analysis. Current weights:
| Domain | Weight |
|---|---|
| 1. Security and Risk Management | 16% |
| 2. Asset Security | 10% |
| 3. Security Architecture and Engineering | 13% |
| 4. Communication and Network Security | 13% |
| 5. Identity and Access Management (IAM) | 13% |
| 6. Security Assessment and Testing | 12% |
| 7. Security Operations | 13% |
| 8. Software Development Security | 10% |
Security and Risk Management carries the most weight by a clear margin, so it’s the domain worth knowing coldest. For a plain-language walkthrough of what each area covers, see our breakdown of the eight CISSP domains.
What languages is the CISSP offered in?
The exam is available in Chinese, English, German, Japanese, and Spanish. The Chinese-language exam runs on a restricted schedule — it’s offered only during March, June, September, and December each year — while the others are available year-round at Pearson VUE test centers.
How should you prepare for a CAT exam?
Adaptive testing rewards genuine understanding over memorized facts, because you can’t skip ahead, flag questions, or go back to change an answer. A few things that actually move the needle:
- Build breadth first. The engine can pull from any of the eight domains at any point, so a weak domain will get exposed. Don’t leave gaps.
- Practice reading for the “best” answer. CISSP questions often have several answers that are technically correct; you’re picking the most complete or manager-minded one.
- Simulate the clock. Time pressure is the part most people underestimate. Work full-length practice exams under real conditions.
- Commit to your answer and move on. You can’t return to a question, so train yourself to decide and let go.
If you’re starting from scratch, our CISSP study plan guide lays out a domain-by-domain schedule, and the complete CISSP guide covers eligibility and the endorsement step after you pass.
Frequently asked questions
Can you go back and change answers on the CISSP CAT exam?
No. Once you submit an answer, it’s locked and the next question is chosen based on it. There’s no review screen and no going back.
Is a 100-question exam easier than a 150-question one?
Not necessarily. Finishing at 100 questions usually means the engine reached its confidence threshold quickly — which can happen for a clear pass or a clear fail. The number of questions doesn’t tell you how you did.
Do all 100–150 questions count toward your score?
No. Every exam includes 25 unscored pretest items mixed in. Only the scored items determine your result, and you can’t identify which is which.
What’s the passing score for the CISSP?
700 out of 1000. But you only receive a pass/fail result, not the numeric score itself.
Source: ISC2 CISSP Certification Exam Outline and ISC2 CISSP CAT information. Exam details reflect the outline effective April 15, 2024. Always confirm current details with ISC2 before you schedule.
Tara Kohl is a 20-year IT veteran whose career has centered on information security and risk management. She holds the CISSP and CISM along with a range of additional certifications, and she's spent most of those years consulting for major aerospace firms and government contractors, where security and compliance demands sit at the top of the priority list.
