Techclick Infosec
2026 Updated · Verified Against ISC2 Sources · April-2026 Waiver Change Included

The Honest CISSP Roadmap
From "What is CISSP?" → Certified, in 2026

No marketing fluff. Just what you actually need to know — eligibility, exam fees in India, the 8 domains, a personalised assessment that tells you which domain to start with, the mistakes that fail 60% of candidates, and the AI tutor that closes your gaps fastest.

🎯 Take the 6-Q Start-Domain Quiz 🤖 See the AI Advantage ⚠ Don't Do These
Exam Fee
$749
≈ ₹62k–65k (India, +18% GST)
Format
CAT
100–150 Q · 3 hours
Pass Score
700/1000
Scaled · per domain
Experience
5 yrs
in 2+ of 8 domains
🤖
NEW · JUST ADDED ⚡ AI POWERED Free with Techclick login

CISSP AI Learning Hub

An always-on tutor that explains every wrong answer in your context, generates fresh scenario questions on demand, drills your weakest sub-domain, and rewrites complex topics (RMF, Bell-LaPadula, Kerberos, BCP) in plain English. Pairs with all 8 domain assessments + the full 150-Q mock.

📚 Topic explainer 🎲 On-demand questions 🧠 Personal weak-spot drills 🇮🇳 Hinglish supported
Open AI Hub →
1

What CISSP Actually Is verified

The Cert in One Line

CISSP (Certified Information Systems Security Professional) is ISC2's gold-standard certification for security leaders — not technicians. It proves you can design, run, and govern an enterprise security program across 8 domains.

  • ✔ ANSI/ISO/IEC 17024 accredited — recognised globally
  • ✔ Meets U.S. DoD 8570/8140 IAT-III / IAM-III / IASAE-II
  • ✔ Counts toward CISO, security architect, audit-lead roles
  • ✔ Average India salary lift: ~30–60% post-cert (Glassdoor / PayScale 2026)

Honest Truth (Read This)

CISSP is mile-wide, inch-deep. It will NOT make you a hacker, a pentester, or a hands-on cloud engineer. It tests how a security manager thinks under uncertainty.

  • • If you love deep packet captures all day → CCNP Security / OSCP is a better fit first
  • • If you want to build secure code → SSCP or CSSLP first
  • • If you want a seat at the boardroom table → CISSP is the right cert
  • • Most candidates need 12–16 weeks of serious study; complete beginners 20+ weeks
2

Eligibility & Prerequisites isc2.org verified

📌 Work Experience

5 years cumulative, paid, full-time in 2 or more of the 8 CISSP domains. (35+ hrs/week × 4 weeks = 1 month.) Part-time is pro-rated.

🎓 Waiver (-1 year)

A 4-yr Bachelor's/Master's in CS / IT / cybersec OR one approved certification waives up to 1 year. You still need 4 years actual experience.

🆕 Associate of ISC2 Path

No experience yet? Pass the exam and become Associate of ISC2. You have 6 years to earn the 5-year experience and convert to full CISSP.

⚠ April 1, 2026 — Waiver List Cut

ISC2 reduced the approved waiver-credential list from ~50 to ~25 certs. Cheap "1-year-waiver hacks" using lesser certs no longer work. Apply before April 1, 2026 if your cert is on the older list; otherwise budget for the full 5 years or use the Associate path.

After you pass — the Endorsement step (9-month window)

Passing the exam is not certification. Within 9 months you must complete endorsement: an existing CISSP-holder (or ISC2 directly) verifies your work experience maps to 2+ domains and vouches for your professional conduct.

If you have no CISSP in your network, ISC2 can endorse you — it just takes longer (4–8 weeks).

Then pay the first annual AMF $125 and you're officially certified.

3

The Exam — Format, Fees, Booking

📊 CAT Format (Adaptive)

  • Questions: 100–150 (adaptive — exam ends when ISC2 has enough confidence)
  • Time: 3 hours max
  • Question types: Multiple-choice (MCQ) + advanced innovative (drag-drop, hotspot) — innovative items are unscored experimental
  • Once answered, gone — you cannot go back. Read every question twice.
  • Pass: Scaled 700/1000 across all domains (no per-domain pass — but weak domain hurts overall)
  • Result: Provisional pass/fail at test centre; official email 4–6 weeks later

💰 Full Cost Breakdown (India 2026)

Exam fee$749 (~₹62,000)
GST (18%)~₹11,200
Re-take (if fail) — 1st$599
Annual maint. fee (AMF)$125/yr
Training (self-study)₹0 – ₹15k
Training (boot-camp)₹40k – ₹2L
All-in (self-study path)~₹75k

Pearson VUE testing centres in India: Mumbai, Delhi, Bengaluru, Hyderabad, Chennai, Pune, Kolkata. Book 4–6 weeks in advance — popular slots fill fast.

📅 Booking Steps

  1. Create an ISC2 account at isc2.org — you'll get a 9-digit Member ID
  2. Go to Pearson VUE → schedule CISSP CAT → pick centre + date
  3. Pay $749 (Visa/Mastercard/Amex; some Indian banks ask for international-txn enablement)
  4. Bring 2 valid IDs (passport + PAN/Aadhaar) on exam day; arrive 30 min early
  5. NDA agreement, biometric scan, locker for belongings — only ID + locker key allowed in
4

The 8 Domains 2026 weights

Effective 2024-onward outline. D1 went up to 16% (was 15%) — even more management-mindset focus. D8 dropped to 10%.

#DomainWeightCore TopicsPractice
D1Security & Risk Management16%CIA, governance, risk frameworks (NIST RMF, ISO 31000), BCP, laws (GDPR, DPDP, HIPAA), ethicsStart →
D2Asset Security10%Classification, ownership, privacy (PII), retention, DLP, data states (rest/transit/use)Start →
D3Security Architecture & Engineering13%Crypto (sym/asym/PKI), security models (Bell-LaPadula, Biba, Clark-Wilson), TPM, secure design, cloud, IoTStart →
D4Communication & Network Security13%OSI/TCP-IP, secure protocols (TLS, IPsec, DNSSEC), VPN, wireless, segmentation, SDN, micro-segStart →
D5Identity & Access Management (IAM)13%AAA, MFA, SSO, federation (SAML, OAuth, OIDC), Kerberos, RBAC/ABAC, lifecycle, PAMStart →
D6Security Assessment & Testing12%Vuln scan, pentest, SAST/DAST/IAST, audit logs, KRI/KPI, internal/external audits, attestationStart →
D7Security Operations13%SOC, SIEM, IR (NIST 800-61), forensics, DR/BCP, patch mgmt, physical sec, change mgmtStart →
D8Software Development Security10%SDLC, secure coding, OWASP Top 10, DevSecOps, CI/CD security, API security, AI/ML securityStart →
Weights are approximate (ISC2 doesn't publish exact percentages year-round; values aggregated from ISC2 outlines + community-confirmed exam reports through April 2026.)
5

"Where Do I Start?" — Personalised Quiz

6 questions · 2 minutes · No login. We'll suggest your starting domain, the order to study the rest, and the first 3 actions you should take this week.

Question 1 of 6
Choose the closest match — there's no right answer
6

Full Process — Zero to Certified

1️⃣
Self-assess (Week 0)

Take the start-domain quiz above + the free 150-Q mock. Don't worry about score — you're measuring where the gaps are, not pass/fail.

2️⃣
Choose your study stack (Week 1)

One primary book (Sybex Official Study Guide 9th Ed OR Eric Conrad 11th Hour) + one video source (Destination Cert MindMaps on YouTube — free) + practice bank (our 8 domain assessments + AI Hub on this site). Three sources, not ten.

3️⃣
Study cycle (Weeks 2–12)

~10–15 hrs/week. Read 1 domain → watch its MindMap → take our domain assessment → use AI Hub to dissect every wrong answer. Do NOT move on with <75% mastery.

4️⃣
Mock-exam phase (Weeks 13–15)

3 full-length mocks under exam conditions (no breaks, no phone, no music). Aim for consistent 80%+. If you're stuck at 65–70%, you have a mindset problem, not a knowledge problem — see the Mistakes section ↓.

5️⃣
Book + take the exam (Week 16)

Schedule a morning slot (you'll be sharpest). Day-before: NO last-minute cramming — sleep 8 hrs, eat well, exercise lightly. Exam day: read every Q twice, look for MOST / BEST / FIRST, pick the manager's answer.

6️⃣
Endorsement (within 9 months of passing)

Find a CISSP-holder to endorse (LinkedIn search → polite DM works; we've seen 70% reply rate). Or use ISC2 endorsement (slower). Once endorsed + pay AMF → official cert appears in your portal.

7

16-Week Study Plan (10–15 hrs/wk)

Phase 1 · Foundation (W1–W4)
  • W1: D1 — Security & Risk Management (the manager mindset)
  • W2: D1 continued + D2 — Asset Security
  • W3: D3 — Architecture & Engineering (crypto deep-dive)
  • W4: D3 continued + checkpoint mock #1
Phase 2 · Technical Depth (W5–W9)
  • W5: D4 — Network Security
  • W6: D5 — IAM (federation deep-dive)
  • W7: D6 — Assessment & Testing
  • W8: D7 — Security Operations
  • W9: D8 — Software Dev Security + checkpoint mock #2
Phase 3 · Revision (W10–W13)
  • W10: Re-take weakest 3 domain assessments
  • W11: 11th Hour CISSP book — full pass
  • W12: Memorisation: ports, crypto algos, BCP/DR metrics, OSI layers
  • W13: Full mock #3 — analyse every wrong answer with AI Hub
Phase 4 · Polish & Pass (W14–W16)
  • W14: Two more full mocks; target 80%+
  • W15: Review notes only; one mock; ease off
  • W16: Light review · sleep · gym · pass the exam

Beginners: stretch to 20 weeks. Experienced security folks: compress to 8–10 weeks. The phases are the same — only the time per phase differs.

8

Top 10 Mistakes — DON'T do these

These are why ~40–50% fail CISSP on first try (ISC2 doesn't publish pass-rates, but trainer-community estimates agree on this range). Avoid these and you're already top quartile.

1. Thinking like a technician

The exam tests how a security manager decides. "Patch the system" is rarely the BEST answer — "do a risk assessment, get management approval, then patch" is. Shift your mindset on day one.

2. Reading 5 books instead of 1, twice

Pick ONE primary book (Sybex 9e or Conrad 11th Hour). Read it twice. Multiple sources = scattered facts, no mental model.

3. Memorising without understanding

CISSP questions are scenario-based. Memorising "Bell-LaPadula = no read up, no write down" doesn't help when the question is about a real-world banking control. Understand why the model exists.

4. Ignoring weak domains

Network engineers love D4, hate D1. Devs love D8, hate D7. Failing one weak domain badly will sink your scaled score even if the rest are strong. Schedule extra time for weak areas, not less.

5. Skipping the keyword trap

Every question has a magic word: MOST, BEST, FIRST, NOT, EXCEPT, LEAST. Circle it mentally. "What's the FIRST step?" and "What's the BEST control?" usually have different correct answers.

6. Answering from your company's playbook

"In my company we do X" is wrong-mindset. CISSP wants standardised/best-practice answers. Forget what your team does — answer what NIST/ISO would recommend.

7. Brain-dumps from boot-camp providers

Posting/asking for actual exam questions is an ISC2 ethics violation — your cert can be revoked. Use practice banks (like ours), not leaked questions. The CAT format makes dumps useless anyway.

8. Last-week cramming

CISSP is 3 hours of dense judgement calls. Cramming destroys decision-making. The week before, ease off — sleep, exercise, light review only.

9. Booking before you're ready

Some boot-camps push "book the exam first, you'll force yourself to study." It works for some. For most, it leads to a $749 fail and a 30-day retake wait. Book only after 3 consecutive 80%+ mocks.

10. Ignoring time-of-day effect

You'll get the exam slot you book. If you're a morning person, NEVER book a 2pm slot. Decision-fatigue is real — the last 30 questions are where most fail.

9

Verified Resources curated, not sponsored

📕 Books
  • Sybex Official Study Guide 9e (Chapple, Stewart, Gibson) — primary
  • Eric Conrad — 11th Hour CISSP 3e — final-week revision
  • (ISC)² CBK Reference — official, dense, dictionary-style
🎥 Free Video
  • Destination Cert MindMaps (YouTube) — 8-domain visual guide
  • Pete Zerger's "Exam Cram" — 9-hr full course, free
  • Kelly Handerhan — "Why You Will Pass CISSP" (cccure) — mindset masterclass
🎯 Practice (Techclick + others)
  • This site — 8 domain assessments + 150-Q full mock + AI Tutor
  • Boson ExSim — closest difficulty to real exam (paid)
  • Cybrary / Wentz Wu blog — free explanations
⚡ Pro Tip: Pick one from each column. Three sources, not ten. Add the AI Tutor when you hit a topic that won't click — it'll explain it in your context (e.g. "explain Kerberos like I'm a network engineer").

Ready? Start with our free CISSP practice library.

All 8 domain assessments · The full 150-Q mock · The AI Tutor · Free, no sign-up needed for first attempt.