CredenTrek
Library / CISSP / Guide 05 of 8
CISSP · Study hours and plan

CISSP study hours: turn your real week into an exam date, and use your own work as the lab

By Mustafa K. Al-Dori · Edition 2026.2, verified 9 October 2026 · 7 min read

The short answer

ISC2 publishes no study-hour figure. CredenTrek uses 150 to 250 hours as a working assumption for someone who meets the experience rule: towards 150 if your experience covers most domains, towards 250 if it is concentrated in one or two. Split the hours by domain weight, divide by your real weekly hours and add roughly one buffer week for every eight. Give almost half the plan to scenario practice and full simulations.

"Pass CISSP in two weeks" stories are written by people with fifteen years in the field. They collapse in week one for everyone else. A plan starts from your calendar and from the domains where your experience is thin.

How many hours does CISSP really take?

ISC2 does not publish a study-hour figure. This book uses 150 to 250 hours as a working assumption for someone who meets the experience rule. Move towards 150 if your experience covers most of the eight domains, and towards 250 if it is concentrated in one or two. Your first full practice test tells you where you stand.

If your career has been in network security, you start with strong Domain 4 and weak Domains 1, 2 and 8. If you work in audit, Domains 1 and 6 are comfortable and Domains 3 and 4 are not. Map your experience to the domains before you decide the total.

How should you split the hours?

Split your hours in proportion to the domain weights, then move hours towards the objectives you rated lowest. For a 200-hour plan the starting split looks like this.

Domain and weight Hours Objectives to study first
Security and Risk Management (16%) 32 Risk management, governance, legal issues
Security Architecture and Engineering (13%) 26 Cryptography, security models, design principles
Communication and Network Security (13%) 26 Secure architecture, secure channels
Identity and Access Management (13%) 26 Authorisation models, federation
Security Operations (13%) 26 Incident management, recovery and testing
Security Assessment and Testing (12%) 24 Test strategies, audits
Asset Security (10%) 20 Classification, data lifecycle
Software Development Security (10%) 20 Secure development lifecycle, acquired software

Which weekly track is yours?

Track Hours a week Best for
Light 6 to 8 A demanding job with little spare time
Standard 10 to 15 Most working candidates
Intensive 20 or more A career break or a firm deadline

Pick the track that matches your real weekly time, not your best week.

How do hours become dates?

Divide your total by your weekly hours, then add roughly one buffer week for every eight weeks of plan. At 200 hours:

Track Weekly hours Weeks Buffer weeks Total
Light 8 25 3 28 weeks
Standard 12 17 2 19 weeks
Intensive 20 10 1 11 weeks

Nour, a security engineer in the book, had 12 hours a week and planned 200 hours. That gave her 17 weeks plus two buffer weeks. She booked for week 19, after her third practice exam came in well above her earlier ones. Starting on Monday 12 October 2026, week 19 would begin on 15 February 2027.

Check the answer against your purchase window. An exam purchase must be scheduled and taken within a set period, so check that period on the day you buy rather than buying early.

What goes in each of the four stages?

CISSP rewards judgement, so scenario practice and review deserve a large share of your hours.

  • Stage A, foundation (about 10 per cent). Rate yourself on every objective, take a diagnostic practice test and map your experience to the domains. For 200 hours that is about 20 hours.
  • Stage B, first coverage (about 45 per cent). Work through your study guide once, domain by domain. About 90 hours.
  • Stage C, practice (about 30 per cent). Scenario questions by domain and a review of every wrong answer, asking why the best answer is best. About 60 hours.
  • Stage D, simulation (about 15 per cent). Full timed practice exams and light revision of weak objectives. About 30 hours.

How do you practise the manager's mindset?

Your experience is your lab. For each domain, write a short case from your own work: what happened, what a security leader should have done first and why. Discuss one case a week with a colleague or study group. This builds the managerial judgement that scenario questions test.

When you review a wrong answer, do not stop at "the right one is B". Write one sentence on why the runner-up fails. In an adaptive exam, the difference between a good answer and the best answer is what moves your result.

How will you know you are ready?

Readiness is a pattern, not a single score. Look for consistent results across two or three full practice exams and no domain far behind the others. You should also be able to explain why the best answer beats the second best.

Book when that pattern holds. The cost and booking guide covers fees and retakes. Appendix B of CredenTrek For CISSP has the weekly plan template, including a row for your endorser.

Your next step
  1. Map your experience to the eight domains and mark the thin ones.
  2. Choose your track and a total between 150 and 250 hours.
  3. Divide by your real weekly hours and write down your dated stages.
  4. Write your first work case this week: what happened, what a leader should do first and why.

Questions readers ask

Can I pass CISSP in a month?
It is possible only if your experience covers most domains and you can give intensive hours. For most candidates, 150 to 250 hours is a better planning assumption, and ISC2 publishes no official figure.
How many practice questions should I do?
ISC2 gives no figure. Spend about 30 per cent of your hours on scenario questions by domain and 15 per cent on full timed exams, and review every wrong answer.
Should I join a study group?
It helps. Discussing one work case a week with a colleague or a local ISC2 chapter builds the judgement that scenario questions test, and it costs nothing.
What if one domain stays weak?
Move hours towards it and take a timed set again. The adaptive exam keeps probing weak areas, so a domain far behind the others is a bigger risk than a lower average.
Sources

This guide is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.