CISSP Study Plan
Dr. Abeer Alshammari · Published 7/29/2026
This plan assumes roughly 8-10 hours per week of study time, which is realistic for a working professional. If you have more or less time, compress or extend the weeks proportionally -- but keep the sequence, since later weeks depend on earlier ones.
| Weeks | Focus |
|---|---|
| 1-2 | Domain 1: Security and Risk Management (governance, legal, policy) |
| 3 | Domain 2: Asset Security |
| 4-5 | Domain 3: Security Architecture and Engineering (cryptography is dense -- give it real time) |
| 6 | Domain 4: Communication and Network Security |
| 7 | Domain 5: Identity and Access Management |
| 8 | Domain 6: Security Assessment and Testing |
| 9 | Domain 7: Security Operations |
| 10 | Domain 8: Software Development Security |
| 11 | Full review pass -- revisit your "missed twice" list from every domain |
| 12 | Full-length timed practice exams, exam-day logistics, rest before the exam |
Where people go wrong with the schedule
The most common failure is not the domain order -- it is skipping weeks 11-12. Candidates who study each domain well individually but never take a full-length timed exam are frequently surprised by exam pacing and question fatigue. Protect those final two weeks; do not let earlier domains bleed into them.
If you have deep hands-on experience in a domain (for example, years running network operations), you can compress that week and reallocate the time to a domain that is genuinely new to you, such as legal/regulatory content in Domain 1 for a purely technical practitioner.
Try it yourself
An interactive CyberAbeer experience for this topic is in development.
Coming soon