CISSP Domains and Weights: The Full Exam Outline

All eight CISSP domains with their official ISC2 weights, what each one actually asks of you, and the trap inside each. One thing to get out of the way first, because it is the most common question about this exam right now: ISC2 has not announced a CISSP refresh for 2027. The outline below is the one in force, unchanged since 15 April 2024, and it is what you sit today.

FormatCAT
Items100 - 150
Time3 hours max
Pass mark700 / 1000
Domains8
Your free CISSP exam code

See your score broken down by these exact domains

The outline tells you what is testable. A full-length practice exam tells you which of the eight is going to fail you. The first one is free - written in the manager-perspective style, with an explanation on every item and a personalized Exam Coach that names your weak domains. Create an account on the next screen and the code applies itself.

CISSP-EXAM-FULL Start the free exam

Already have an account? Log in to start · Prefer a 5-question taster? Try the short version.

The weights, and why they mislead

1. Security and Risk Management
16%
3. Security Architecture and Engineering
13%
4. Communication and Network Security
13%
5. Identity and Access Management
13%
7. Security Operations
13%
6. Security Assessment and Testing
12%
2. Asset Security
10%
8. Software Development Security
10%

Notice how flat that is. Six of the eight domains sit between 12% and 13%, and the spread from top to bottom is six percentage points. That is deliberate - the CISSP is a breadth exam, and ISC2 is telling you plainly that no domain can be skipped and no domain will carry you.

The practical consequence is that CISSP weights are much less useful for planning than a CompTIA or Cisco blueprint, where a 28% domain genuinely deserves triple the time of a 10% one. Here, the number that should drive your schedule is not the weight - it is the gap between the weight and your own competence. A 13% domain you have never worked in will cost you far more marks than the 16% domain you live in every day.

The exam is adaptive, which changes what a weight means. On a linear exam, 13% means roughly 13% of the questions. On CAT, the algorithm chases your ability level, so a domain you are weak in will keep producing questions until it has measured you. A single badly-neglected domain does not cost you its listed percentage - it can dominate your exam. How CISSP CAT actually works.

The eight domains, one by one

16%

1. Security and Risk ManagementThe largest domain, and the one engineers underestimate.

Covers: professional ethics and the ISC2 code, security concepts, governance principles, legal and regulatory issues across jurisdictions, investigation types and their evidence requirements, policies, standards, procedures and guidelines, business continuity requirements and business impact analysis, personnel security policies, risk management concepts, threat modelling, supply chain risk management, and security awareness and training.

This is the domain that decides the exam for most technical candidates. It is where the "manager perspective" is not a style note but the actual content - governance, due care versus due diligence, and knowing that the first correct action is almost never the technical one.

Where marks go: the quantitative risk formulas. SLE, ALE and ARO appear reliably and they are the most mechanical marks on the whole exam - pure arithmetic once you know which number goes where. Worked examples of the risk math.
10%

2. Asset SecuritySmall, tightly scoped, and the cheapest domain to master.

Covers: identifying and classifying information and assets, establishing handling requirements, provisioning resources securely, managing the data lifecycle including roles (owner, controller, processor, custodian, user), retention and remanence, determining data security controls and compliance requirements, and secure data destruction.

Ten percent for a genuinely small body of material, most of which is definitional. If you are short on time near the exam, this is the highest marks-per-hour domain on the list.

Where marks go: the data roles. Owner versus custodian versus controller versus processor is a favourite distractor set, and the answers turn on who holds accountability rather than who does the work.
13%

3. Security Architecture and EngineeringThe widest technical spread in the CBK.

Covers: secure design principles, security models, controls based on requirements, capabilities of information systems, vulnerabilities in systems from client and server to industrial control, IoT, embedded, virtualized, cloud, microservices and containers; cryptography and cryptanalytic attacks, public key infrastructure and key management, digital signatures and non-repudiation, plus site and facility design and physical security controls.

An unusually broad domain for its weight - it runs from Bell-LaPadula to data-centre fire suppression. Do not try to master all of it evenly.

Where marks go: the security models. Bell-LaPadula, Biba and Clark-Wilson are cheap, reliable marks once the mirror-image trick clicks, and expensive if it never does. Biba vs Bell-LaPadula vs Clark-Wilson.
13%

4. Communication and Network SecurityFamiliar ground for network people, hostile for everyone else.

Covers: secure design principles in network architectures including the OSI and TCP/IP models, IP networking, secure protocols, multilayer protocols, micro-segmentation and wireless, cellular and content distribution networks; securing network components including hardware, transmission media and endpoint security; and secure communication channels - voice, remote access, data communications, virtualized networks and third-party connectivity.

If you hold a CCNA or Security+ this domain is largely revision, and it is the strongest argument for sitting one of those first. If your background is audit or policy, budget real time here.

Where marks go: the OSI layer a control or attack belongs to. It sounds trivial and it is asked constantly, often as the pivot that makes one of four plausible answers correct. OSI model refresher.
13%

5. Identity and Access ManagementThe most consistently examined technical domain.

Covers: physical and logical access control to assets, managing identification and authentication of people, devices and services, federated identity services, third-party identity services, implementing and managing authorization mechanisms, and managing the identity and access provisioning lifecycle including account access review, provisioning and de-provisioning, role definition and privilege escalation.

Dense but learnable, and the concepts recur inside Domains 1, 3 and 7 - so time spent here pays more than its 13% suggests.

Where marks go: the access control models. DAC, MAC, RBAC, ABAC and rule-based are asked by scenario rather than by definition - you get a situation and have to name the model that fits, which is much harder than reciting what each means.
12%

6. Security Assessment and TestingThe domain people confuse with Domain 7.

Covers: designing and validating assessment, test and audit strategies; conducting security control testing including vulnerability assessment, penetration testing, log reviews, synthetic transactions, code review and testing, misuse case testing, coverage analysis and interface testing; collecting security process data; analysing test output and generating reports; and conducting or facilitating internal, external and third-party audits.

The boundary with Security Operations is where candidates lose marks: assessment is about verifying that controls work, operations is about running them.

Where marks go: knowing who may perform which audit, and the independence requirements that make an assessment credible. Also the difference between a vulnerability assessment and a penetration test, which is asked more often than it deserves.
13%

7. Security OperationsThe most scenario-driven domain on the exam.

Covers: investigations and their requirements, logging and monitoring, configuration and change management, applying foundational security operations concepts, resource protection, incident management, detective and preventative measures, patch and vulnerability management, recovery strategies, disaster recovery processes and testing, business continuity, physical security, and personnel safety and security concerns.

This is where the "what do you do FIRST" questions live, and they are the signature CISSP item type. The technically effective action and the correct answer routinely differ - the exam wants the response a security leader would defend, which usually means containment, safety or notification before remediation.

Where marks go: human life first, always. Any question where safety is on the table has one answer, whatever else is happening technically. After that, the incident response phase order.
10%

8. Software Development SecuritySmallest domain, and the one non-developers fear most.

Covers: understanding and integrating security in the software development lifecycle, identifying and applying security controls in development ecosystems, assessing the effectiveness of software security, assessing the security impact of acquired software, and defining and applying secure coding guidelines and standards.

Good news for the many CISSP candidates who have never shipped code: you are not asked to write any. The domain is about governance of development - lifecycle models, maturity models, where controls belong in a pipeline, and how to judge acquired software.

Where marks go: the maturity and lifecycle models, and the principle that security requirements belong at the requirements stage rather than at testing. Cost-of-fix reasoning shows up repeatedly.
Your free CISSP exam code

Find out which of the eight will fail you

On an adaptive exam, one neglected domain does not cost you its listed percentage - it can dominate your test. A full-length practice exam is the only way to see the shape before the real one finds it. Free, with an explanation on every item and a coach that ranks your weak domains.

CISSP-EXAM-FULL Redeem the code

Already have an account? Log in to redeem

Is the CISSP changing in 2027?

ISC2 has not announced a CISSP refresh. That is the whole factual answer, and it is worth stating plainly because a lot of pages will tell you otherwise with invented domain weights attached. Here is the actual situation, and why the question keeps coming up:

  • The current outline took effect on 15 April 2024. That refresh was modest: Domain 1 moved from 15% to 16%, Domain 8 moved from 11% to 10%, and the German, Japanese and Spanish exams joined English in the CAT format. The other six domains were untouched.
  • ISC2 reviews credentials on a roughly three-year job task analysis cycle. April 2024 plus three years lands in 2027, which is where every prediction you will read comes from. It is a reasonable inference. It is not an announcement.
  • ISC2 has been busy elsewhere. The CCSP moved to a new outline on 1 August 2026 and the CC follows on 1 September 2026, both bringing AI and machine learning security content into the portfolio. If that pattern reaches the CISSP, AI is the obvious candidate for what a future refresh adds.
💡
What to do with that: nothing. Unlike the CCNA, which is genuinely restructuring in February 2027, there is no CISSP deadline to race and no version boundary to plan around. If a refresh is announced, ISC2 gives months of notice and publishes the new outline in advance - and CISSP refreshes have historically shifted weights by a point or two rather than redrawing domains. Study the outline above; check the ISC2 exam outlines page before you book.

One thing that is worth knowing regardless of refreshes: dumps sold online are useless for this exam in a way that has nothing to do with version dates. The CISSP is adaptive and drawn from a large item pool, so there is no fixed question set to have memorised. Add that the correct answer usually turns on judgement rather than fact, and a leaked question with a remembered answer letter teaches you nothing transferable - while using one breaks the ISC2 code of ethics you are formally agreeing to, which is itself examinable in Domain 1.

How to actually allocate your time

Since the weights are nearly flat, allocate against your own gaps instead. A sequence that works:

  1. Sit a full practice exam cold, before revising anything. On a breadth exam with eight nearly-equal domains, guessing at your own weak spots is unusually unreliable - people consistently misidentify them. This is the single most valuable hour in a CISSP plan.
  2. Take Domain 1 seriously if you are technical. It is the biggest domain and the one that carries the manager perspective. Getting comfortable choosing the governance answer over the technical one is most of what separates a pass from a fail for engineers.
  3. Bank the cheap marks. The risk formulas in Domain 1, the security models in Domain 3, the data roles in Domain 2. All three are mechanical once learned, and all three appear reliably.
  4. Close your worst domain, not your favourite. Because the exam is adaptive, the domain you avoid is the one it will probe hardest.
  5. Sit a second full exam, a different one, and compare the domain shape rather than the headline score.
  6. Book when the shape is even, using the readiness rubric as the final check before you commit the exam fee.

Frequently asked questions

What are the eight CISSP domains and their weights?

Security and Risk Management 16%, Asset Security 10%, Security Architecture and Engineering 13%, Communication and Network Security 13%, Identity and Access Management 13%, Security Assessment and Testing 12%, Security Operations 13%, and Software Development Security 10%. These are ISC2's published figures for the outline in force since 15 April 2024.

Is the CISSP exam changing in 2027?

ISC2 has not announced a refresh. The current outline dates from 15 April 2024, and ISC2 works on a roughly three-year job task analysis cycle, which is why 2027 keeps being predicted - it is an inference from the cadence, not a published date. ISC2 did refresh the CCSP on 1 August 2026 and the CC on 1 September 2026, so the CISSP is plausibly next, but any site giving you 2027 CISSP domain changes as fact is guessing.

How many questions is the CISSP, and what is the pass mark?

The English exam is Computerized Adaptive Testing: 100 to 150 items in a maximum of three hours, pass mark 700 out of 1000. Since April 2024 the German, Japanese and Spanish versions are also CAT. The item count tells you nothing useful during the exam - the algorithm stops as soon as it is confident you are clearly above or clearly below the standard, so finishing at 100 is not a good sign or a bad one.

Which CISSP domain is the hardest?

Whichever is furthest from your day job. Engineers usually struggle with Domain 1, Security and Risk Management, because it is governance and business judgement rather than technology - and at 16% it is the biggest domain, so that struggle is expensive. Managers and auditors more often lose marks in Domain 3, Security Architecture and Engineering, and Domain 8, Software Development Security.

Should I allocate study time by domain weight?

Only loosely. Six of the eight domains sit between 12% and 13%, so the weights barely separate priorities - unlike a CompTIA or Cisco blueprint where a 28% domain really does deserve triple the time. Allocate by the gap between the weight and your competence, and remember that on an adaptive exam a neglected domain can take over your test rather than costing you a fixed percentage.

Do I need five years of experience to sit the exam?

No - the experience requirement applies to the certification, not the exam. Pass without it and you become an Associate of ISC2, with six years to accumulate five years of paid work experience across two or more of the eight domains. A relevant four-year degree or an approved credential can waive one of those five years.