Skip to content
Log inRegister

CISSP Study Plan

Dr. Abeer Alshammari · Published 7/29/2026

IntermediateStudentsProfessionals

This plan assumes roughly 8-10 hours per week of study time, which is realistic for a working professional. If you have more or less time, compress or extend the weeks proportionally -- but keep the sequence, since later weeks depend on earlier ones.

WeeksFocus
1-2Domain 1: Security and Risk Management (governance, legal, policy)
3Domain 2: Asset Security
4-5Domain 3: Security Architecture and Engineering (cryptography is dense -- give it real time)
6Domain 4: Communication and Network Security
7Domain 5: Identity and Access Management
8Domain 6: Security Assessment and Testing
9Domain 7: Security Operations
10Domain 8: Software Development Security
11Full review pass -- revisit your "missed twice" list from every domain
12Full-length timed practice exams, exam-day logistics, rest before the exam

Where people go wrong with the schedule

The most common failure is not the domain order -- it is skipping weeks 11-12. Candidates who study each domain well individually but never take a full-length timed exam are frequently surprised by exam pacing and question fatigue. Protect those final two weeks; do not let earlier domains bleed into them.

Adjusting for your background

If you have deep hands-on experience in a domain (for example, years running network operations), you can compress that week and reallocate the time to a domain that is genuinely new to you, such as legal/regulatory content in Domain 1 for a purely technical practitioner.

Try it yourself

An interactive CyberAbeer experience for this topic is in development.

Coming soon
Back to insights