CISSP study hours: turn your real week into an exam date, and use your own work as the lab
ISC2 publishes no study-hour figure. CredenTrek uses 150 to 250 hours as a working assumption for someone who meets the experience rule: towards 150 if your experience covers most domains, towards 250 if it is concentrated in one or two. Split the hours by domain weight, divide by your real weekly hours and add roughly one buffer week for every eight. Give almost half the plan to scenario practice and full simulations.
"Pass CISSP in two weeks" stories are written by people with fifteen years in the field. They collapse in week one for everyone else. A plan starts from your calendar and from the domains where your experience is thin.
How many hours does CISSP really take?
ISC2 does not publish a study-hour figure. This book uses 150 to 250 hours as a working assumption for someone who meets the experience rule. Move towards 150 if your experience covers most of the eight domains, and towards 250 if it is concentrated in one or two. Your first full practice test tells you where you stand.
If your career has been in network security, you start with strong Domain 4 and weak Domains 1, 2 and 8. If you work in audit, Domains 1 and 6 are comfortable and Domains 3 and 4 are not. Map your experience to the domains before you decide the total.
How should you split the hours?
Split your hours in proportion to the domain weights, then move hours towards the objectives you rated lowest. For a 200-hour plan the starting split looks like this.
| Domain and weight | Hours | Objectives to study first |
|---|---|---|
| Security and Risk Management (16%) | 32 | Risk management, governance, legal issues |
| Security Architecture and Engineering (13%) | 26 | Cryptography, security models, design principles |
| Communication and Network Security (13%) | 26 | Secure architecture, secure channels |
| Identity and Access Management (13%) | 26 | Authorisation models, federation |
| Security Operations (13%) | 26 | Incident management, recovery and testing |
| Security Assessment and Testing (12%) | 24 | Test strategies, audits |
| Asset Security (10%) | 20 | Classification, data lifecycle |
| Software Development Security (10%) | 20 | Secure development lifecycle, acquired software |
Which weekly track is yours?
| Track | Hours a week | Best for |
|---|---|---|
| Light | 6 to 8 | A demanding job with little spare time |
| Standard | 10 to 15 | Most working candidates |
| Intensive | 20 or more | A career break or a firm deadline |
Pick the track that matches your real weekly time, not your best week.
How do hours become dates?
Divide your total by your weekly hours, then add roughly one buffer week for every eight weeks of plan. At 200 hours:
| Track | Weekly hours | Weeks | Buffer weeks | Total |
|---|---|---|---|---|
| Light | 8 | 25 | 3 | 28 weeks |
| Standard | 12 | 17 | 2 | 19 weeks |
| Intensive | 20 | 10 | 1 | 11 weeks |
Nour, a security engineer in the book, had 12 hours a week and planned 200 hours. That gave her 17 weeks plus two buffer weeks. She booked for week 19, after her third practice exam came in well above her earlier ones. Starting on Monday 12 October 2026, week 19 would begin on 15 February 2027.
Check the answer against your purchase window. An exam purchase must be scheduled and taken within a set period, so check that period on the day you buy rather than buying early.
What goes in each of the four stages?
CISSP rewards judgement, so scenario practice and review deserve a large share of your hours.
- Stage A, foundation (about 10 per cent). Rate yourself on every objective, take a diagnostic practice test and map your experience to the domains. For 200 hours that is about 20 hours.
- Stage B, first coverage (about 45 per cent). Work through your study guide once, domain by domain. About 90 hours.
- Stage C, practice (about 30 per cent). Scenario questions by domain and a review of every wrong answer, asking why the best answer is best. About 60 hours.
- Stage D, simulation (about 15 per cent). Full timed practice exams and light revision of weak objectives. About 30 hours.
How do you practise the manager's mindset?
Your experience is your lab. For each domain, write a short case from your own work: what happened, what a security leader should have done first and why. Discuss one case a week with a colleague or study group. This builds the managerial judgement that scenario questions test.
When you review a wrong answer, do not stop at "the right one is B". Write one sentence on why the runner-up fails. In an adaptive exam, the difference between a good answer and the best answer is what moves your result.
How will you know you are ready?
Readiness is a pattern, not a single score. Look for consistent results across two or three full practice exams and no domain far behind the others. You should also be able to explain why the best answer beats the second best.
Book when that pattern holds. The cost and booking guide covers fees and retakes. Appendix B of CredenTrek For CISSP has the weekly plan template, including a row for your endorser.
- Map your experience to the eight domains and mark the thin ones.
- Choose your track and a total between 150 and 250 hours.
- Divide by your real weekly hours and write down your dated stages.
- Write your first work case this week: what happened, what a leader should do first and why.
Questions readers ask
Can I pass CISSP in a month?
How many practice questions should I do?
Should I join a study group?
What if one domain stays weak?
- ISC2 CISSP certification page
- ISC2 CISSP exam outline, effective 15 April 2024
- ISC2 Candidate Information Bulletin
This guide is independent and is not endorsed by ISC2. Facts change: confirm them on the official page before you act.