Milestone map
Milestone map
3 milestones
Audit your experience and build a study plan
2–3 weeks
CISSP requires five years of paid work experience in at least two of the eight Common Body of Knowledge (CBK) domains before you can sit the exam. Start by auditing your actual experience against all eight domains, identifying which five-year requirement you satisfy and where your knowledge gaps are. Then build a structured study plan that covers your weak domains in the time available before your planned exam date. This milestone produces a commitment document, not a completed action.
Proof required
Submit: (1) a domain experience audit — a table mapping your work history to each of the 8 CISSP CBK domains with estimated months of qualifying experience per domain, (2) your planned exam date, and (3) a week-by-week study schedule for at least 12 weeks showing domain sequence and estimated hours.
What gets checked
- Experience audit maps specific job roles and activities to named CBK domains — 'I have security experience' without domain mapping is not an audit
- Five-year experience requirement is clearly met or a specific plan to meet it is articulated — candidates without 5 years can sit as an Associate of ISC2 and earn a waiver later
- Study schedule covers all 8 domains in sequence, not just the ones the candidate already feels confident in
Common mistakes
- Underestimating how much time the CISSP requires — most candidates need 3–6 months of structured study, not a few weeks of reading
- Building a study plan that only reviews familiar domains — CISSP will test all 8 and the exam is adaptive; weak domains become the deciding factor
- Assuming current job experience fully substitutes for studying the CBK — practical experience and exam-domain knowledge overlap but are not identical
Resources
Foundationstart here
Depthgo deeper
Masteryfor the dedicated
What a verifier looks for
- Ask the submitter to confirm their five-year experience requirement: which two or more domains, and what specific roles or activities cover them — verbal confirmation of 'I have security experience' is not sufficient
- Study plan should cover all 8 domains: ask to see domain 3 (Security Architecture) and domain 8 (Software Development Security) specifically — these are commonly under-studied by candidates with operational backgrounds
- Planned exam date should be realistic given current experience level and schedule — 6 weeks of study for a first-time CISSP candidate is not realistic
You'll sign in first, then come straight back here.
Complete structured study across all 8 CBK domains
10–20 weeks (depending on prior experience and study hours per week)
Work through your study plan systematically, completing at least one full pass through all 8 CISSP CBK domains and scoring 75% or above on practice tests for each domain before attempting the real exam. CISSP is an adaptive exam — it does not stop when you reach passing score in familiar domains, it stops when it has established confidence across your performance on all domains. Consistent practice test performance is the most reliable predictor of exam readiness.
Proof required
Submit: (1) practice test scores for all 8 domains, each showing 75%+ on a timed test of at least 25 questions per domain, and (2) a brief note on the domain that required the most additional study and what you did to address it.
What gets checked
- 8 domain scores provided, each from a timed practice test of at least 25 questions — a single cumulative score without per-domain breakdown does not show readiness across all domains
- Scores are from reputable free or low-cost practice resources — self-authored questions do not count as practice tests
- The domain requiring the most additional study is named with a specific intervention — 'I re-read the chapter' is less credible than 'I worked through 50 additional practice questions on cryptography fundamentals and reviewed NIST SP 800-57'
Common mistakes
- Studying only from one source — CISSP is tested at a managerial depth, not just a technical one; multiple perspectives (ISC2 official material + practical guides) are needed
- Reaching 75% in a few domains and assuming that is sufficient — the adaptive exam will probe weak domains harder
- Taking practice tests without reviewing wrong answers — a wrong answer not understood is a wrong answer on exam day
Resources
Foundationstart here
Depthgo deeper
What a verifier looks for
- Ask to see practice test scores per domain, not a single cumulative score — a 78% average can hide a 55% in one domain that would cause exam failure
- Confirm the practice test source is reputable — ask the submitter what resource they used; self-authored flashcards or single-source memorisation are insufficient
- Ask which domain required the most additional study and what specific resources were used — a candidate who genuinely worked through CISSP should have a clear answer
You'll sign in first, then come straight back here.
Pass the CISSP exam and share your official result
1 day (exam) following M2 study completion
The only proof standard for CISSP is the official exam result from ISC2. Pass the exam and share the verification. CISSP certification requires both passing the exam and endorsement by an active ISC2 member, but for this milestone the exam pass is the proof event — endorsement follow-up is administrative. Your Credly digital badge or ISC2 transcript are the accepted evidence.
Proof required
Share your official CISSP pass result: an ISC2 transcript showing the pass result, a Credly badge link, or the ISC2 verification URL for your certification. Screenshots alone are acceptable if the ISC2 verification URL is included.
What gets checked
- Evidence is from ISC2 directly — employer confirmation or a LinkedIn 'certificate' not backed by an ISC2 verification link does not meet the standard
- Credly badge or ISC2 profile is publicly accessible or a verification URL is provided so the verifier can confirm independently
- Result is from the actual CISSP exam, not from an Associate of ISC2 or SSCP credential — those are valuable but are different certifications
Common mistakes
- Submitting a Credly badge for a different ISC2 certification — confirm the badge is specifically for CISSP, not SSCP or CC
- Sharing only a screenshot of a test score without the ISC2 verification link — screenshots can be altered; the ISC2 verification URL is the credible standard
- Endorsement delay: the certification is pending endorsement and not yet confirmed — submit this milestone only after the official certification letter is issued
Resources
Foundationstart here
What a verifier looks for
- Use the ISC2 Member Verification tool (isc2.org/MemberVerification) to confirm the certification independently — do not rely solely on screenshots
- Confirm the credential is CISSP specifically and that its status is Active, not Associate of ISC2 or pending endorsement
- Ask when the exam was taken and whether endorsement has been completed — if endorsement is still pending, the full CISSP certification is not yet active
You'll sign in first, then come straight back here.