Passing ScoreCISSPISC2 · Professional

CISSP Passing Score

You need 700 out of 1000 to pass — but CISSP is a computer adaptive (CAT) exam, so if you pass you usually just see “pass,” not a number. Here is how adaptive scoring really works, the eight CBK domains, what practice score means you are ready, and the retake policy.

700/1000Pass mark
CATAdaptive
100–150Items
Up to 3 hrsExam time
8Domains
CISSP passing score 700 out of 1000 on the CAT adaptive exam explained

01 The short answer

You need 700 out of 1000 to pass the CISSP. That figure sits on a scaled 0–1000 range, and 700 is the minimum ISC2 sets. The twist that catches everyone out: CISSP is a computer adaptive (CAT) exam, so if you pass you almost never see a number — you just get “Congratulations, you have provisionally passed.” The 700 standard is real, but the algorithm only needs to prove you are above or below it, not pin down exactly where you sit.
Below passPass zone
700 needed
700–1000
0 (min)1000 (max)
Because it is adaptive, there is usually no number to see. A pass is reported as a simple pass — ISC2 does not hand you a scaled mark when you clear the bar. The “700” matters conceptually as the standard your ability is measured against; only a failing result comes with a numeric score and a list of your weakest domains.

This is the single biggest difference between CISSP and the multiple-choice cloud and IT exams most candidates have sat before. On a fixed, linear exam such as AWS SAA-C03 or CompTIA Security+ you answer a set number of questions, your raw count is converted to a scaled mark, and you walk out with a number you can quote. CISSP throws that mental model out. You are not racing to accumulate points across a fixed paper; you are being measured against a standard, and the exam ends as soon as the result is no longer in doubt. Once you accept that, a lot of the anxiety around “what will my score be?” disappears — the only question that matters is whether you are clearly above 700.

02 How CAT scoring actually works

Computer Adaptive Testing is what makes CISSP scoring different from a fixed, linear exam — and it explains why “what was my score?” usually has no answer. Three mechanics do all the work.

1. The exam adapts to your ability

You start with an item pitched well below the passing standard. After each answer, the algorithm re-estimates your ability from the difficulty of every question you have seen and how you handled it. Answer correctly and the next item gets harder; slip and it eases off. With each response the estimate of your true ability becomes more precise, so the exam zeroes in on your level far faster than a fixed bank of questions could.

2. It ends on confidence, not a fixed length

The exam delivers between 100 and 150 items (up to three hours), and it stops the moment the algorithm is roughly 95% confident that your ability is clearly on one side of the 700 standard. If you are comfortably strong — or comfortably short — that confidence can arrive at the 100-item minimum and the screen simply ends. If you are hovering near the line, the exam keeps feeding you items to gather more evidence and can run all the way to the 150-item maximum. A long exam is not automatically a failing one; it just means you were borderline and the algorithm needed more data.

3. It is compensatory — no per-domain minimum

CISSP uses a compensatory model: a higher number of items answered correctly in one domain can make up for weaker performance in another. There is no minimum score per domain — only your overall ability against the 700 standard decides the result. Of the items you face, 25 are unscored pretest questions seeded at random to trial them for future exams, and you cannot tell which they are, so every item deserves your full attention.

Why a hard question is a good sign

One quirk of adaptive testing throws candidates off mid-exam: the questions often feel relentlessly difficult. That is the algorithm working as intended. As your running ability estimate climbs, the engine deliberately serves items near your level to extract the most information from each answer — so a strong candidate spends most of the exam being pushed. If every question feels hard, it frequently means you are performing well, not badly. The flip side is that you cannot read your result from how the questions felt, and you should never let a run of tough items rattle you into rushing. There is also no going back: once you submit an answer the engine has already used it to choose your next item, so you cannot flag, skip or revisit questions the way you can on a linear exam.

It is worth being precise about the “700” itself. ISC2 reports results on a scaled 0–1000 range so that candidates sitting slightly easier or harder item sets are held to the same standard — 700 is not “70% of questions correct.” Because the exam is adaptive and compensatory at once, no fixed percentage of items maps cleanly to a pass; what counts is the ability estimate the algorithm settles on. Aim to be comfortably clear of the standard so that neither a tough item set nor a borderline run can put the result in doubt.

The headline takeaway: 700/1000 is the bar, but because CISSP is adaptive you are graded pass or fail, not on a transcript number. Treat the goal as “be clearly above the standard,” not “chase a particular score.”

03 The eight CBK domains and their weights

The CISSP Common Body of Knowledge (CBK) spans eight domains. Because scoring is compensatory and adaptive, the smart move is to weight your study toward the heaviest domains — though on a security exam you cannot afford a genuine blind spot anywhere. These are the weights from the current (April 2024) exam outline.

1. Security & Risk Management
16%
2. Asset Security
10%
3. Security Architecture & Engineering
13%
4. Communication & Network Security
13%
5. Identity & Access Management
13%
6. Security Assessment & Testing
12%
7. Security Operations
13%
8. Software Development Security
10%
Where to spend your time: Domain 1 (Security & Risk Management) is the single heaviest at 16% and sets the governance, risk and legal vocabulary the whole exam leans on. The four 13% domains — Architecture & Engineering, Network Security, IAM and Security Operations — are the technical core. Get those five solid before polishing Asset Security and Software Development Security.

04 What practice score means you are ready

Here is the honest caveat: real CISSP practice tests are not adaptive. No third-party bank can reproduce the live CAT algorithm, so your practice percentage is a proxy for readiness, not a forecast of a scaled score. Used that way, a repeatable percentage on fresh, full-length, timed practice exams is still the best signal you have.

< 70%Not ready — this is the band where most failures cluster
70–80%Borderline — you would likely run the exam to 150 items, results either way
80%+Ready — a repeatable 80%+ on fresh questions is a strong proxy for clearing 700

Make the proxy honest. A single 82% on a question bank you have already cycled through twice tells you almost nothing — you are scoring your memory, not your knowledge. What you want is the same 80%+ landing on fresh, full-length, timed sets, two or three sittings in a row, with the harder question styles (drag-and-drop, scenario, “best”-answer items) included rather than filtered out. If your accuracy swings wildly between sittings, you are still in borderline territory regardless of your best run; consistency is the signal. Track it by domain too, so a weak area cannot quietly drag your live result down while a strong one flatters your average.

The danger zone is 70–80%. On a fixed exam that feels close enough to book, but on CISSP it is exactly the borderline band where the adaptive engine keeps feeding you items and the result can fall either side of 700. Because practice tests are not adaptive, treat a repeatable 80%+ on questions you have never seen as your proxy for “clearly above the standard” — not a single lucky run.

05 If you fail: the retake policy

Falling short of 700 is not the end — but ISC2 makes the waits get longer with each attempt and charges the full fee every time, so it is worth being ready first. Unlike a pass, a failed CISSP does come with a numeric score and a ranked breakdown of the domains where you were weakest — use it. That breakdown is the most valuable thing a failed attempt gives you: it converts a vague “I need to study more” into a precise list of where the live exam actually found you short, which is exactly the targeting a self-set practice schedule tends to lack.

AttemptWait before you can retest
After 1st fail30 days from your exam date
After 2nd fail60 days from your most recent attempt
After 3rd fail (and later)90 days from your most recent attempt
Annual capMaximum 4 attempts in any rolling 12-month period
Cost per attemptThe full exam fee every time — no discounted retake
Use the fail productively: the failing score report ranks your domains from strongest to weakest. Rebuild the bottom two or three, push your fresh practice score to a repeatable 80%+, then rebook — do not just resit on day 31 hoping the adaptive engine is kinder.

06 FAQ

What is the passing score for the CISSP?

You need 700 out of 1000 to pass the CISSP. Scores sit on a scaled 0 to 1000 range, and 700 is the minimum standard ISC2 sets. Because CISSP is a computer adaptive (CAT) exam, the algorithm only has to confirm you are above or below 700 — it does not need to pin down an exact number.

Does CISSP show your score?

If you pass, no — you simply receive a pass result with no number. CISSP is adaptive, so once the algorithm is statistically confident you are above 700 it ends the exam, and a precise score is never reported. Only candidates who fail get a numeric scaled score plus a breakdown of the domains where they were weakest, to guide a retake.

Do I need to pass each domain on the CISSP?

No. CISSP uses a compensatory model, so only your overall ability estimate against the 700 standard matters. There is no minimum score for any individual CBK domain — strong performance in one area can offset a weaker one, as long as your overall result clears the bar.

How long do I wait to retake the CISSP if I fail?

ISC2 makes you wait 30 days after a first failure, 60 days after a second, and 90 days after a third or later attempt, with a maximum of four attempts in any rolling 12-month period. You pay the full exam fee each time, so it pays to be genuinely ready before rebooking.

ExamCert
ExamCert TeamCertified cloud & security pros helping you pass faster.