The CISSP 60-Day Study Plan (Week-by-Week)
The middle-ground plan for candidates who already have some security experience: not as rushed as a 30-day sprint, not as drawn-out as a 90-day marathon. Here's a realistic, week-by-week schedule.
A lot of CISSP study advice treats every candidate the same way, either handing you an aggressive 30-day sprint or a comfortable 90-day marathon. Neither fits everyone. If you already have a few years of hands-on security or IT experience, have touched most of the 8 CISSP domains on the job even if you've never studied them formally, and can commit a consistent 60-90 minutes most days, a 60-day plan is often the better fit: fast enough to keep momentum, long enough to actually absorb the material instead of cramming it.
This guide lays out a week-by-week, 8-week (roughly 60-day) structure built around that profile. It assumes about 60-75 minutes on weekdays and 2-3 hours on one weekend day, which lands most candidates in the 100-130 hour range by exam day, consistent with what ISC2 and most CISSP instructors recommend. If that pace sounds too fast, the 90-day plan gives you more room. If you want to compress further, the 30-day plan explains who that aggressive timeline actually suits.
- 2-5 years of security or IT experience, ideally touching more than one domain (not just, say, pure networking or pure development)
- Some prior exposure to CISSP material, even informally, so the vocabulary isn't entirely new
- 60-90 minutes most weekdays plus a longer weekend session, sustained for two months
- A exam date you can commit to now, roughly 8-9 weeks out, rather than an open-ended "whenever I'm ready" target
If none of that describes you, that's useful information before you book an exam date, not after. Newer candidates or those with less consistent free time tend to do better stretching to 90-120 days; experienced retake candidates can often compress further. More on adjusting the plan below.
Before You Start: Set Your Baseline
Before opening a study guide, take one diagnostic assessment to see where you actually stand across the 8 domains. With only 8 weeks to work with, you can't afford to spend equal time on material you already know cold and material you've never touched. A baseline tells you where to lean in early.
A free, no-signup diagnostic (5 questions, instant results) gives you a quick read before you commit to the full plan. It's not a substitute for a full domain-by-domain baseline, but it's a fast first signal.
Weeks 1-4: Foundation (Domain Coverage)
The first four weeks exist to touch every domain once, in enough depth that the terminology and core frameworks stop feeling unfamiliar. Because the timeline is tighter than a 90-day plan, domains are paired rather than spread across six weeks, so plan for slightly longer sessions than you might expect.
| Week | Focus Domain(s) | Weekday Activity | Weekend Activity |
|---|---|---|---|
| 1 | Security and Risk Management + Asset Security | Read/watch domain material, 45-60 min | 25-30 practice questions, review every explanation |
| 2 | Security Architecture and Engineering | Read/watch material, 60-75 min (dense domain) | 30 practice questions |
| 3 | Communication and Network Security | Read/watch material, 60-75 min (dense domain) | 30 practice questions |
| 4 | Identity and Access Management (IAM) + Security Assessment and Testing | Read/watch domain material, 45-60 min | 30 practice questions, mixed domain |
Security Architecture and Engineering and Communication and Network Security each get a full week on their own. They're consistently the domains candidates find hardest, combining heavy technical detail (cryptography, network protocols, physical security) with the same managerial reasoning the rest of the exam demands. Don't compress them to save time elsewhere.
Security Operations and Software Development Security, the remaining two domains, get folded into the start of week 5 as shorter standalone sessions, since Software Development Security in particular overlaps conceptually with change management and secure architecture, both already covered.
A realistic weekday/weekend split during the foundation phase:
Weeks 5-6: Integration (Cross-Domain Practice)
This phase shifts from learning domains in isolation to practicing the way the exam actually works: scenario questions that blend concepts from multiple domains at once. It also introduces your first full-length mock exam.
- Early week 5: Security Operations and Software Development Security, shorter standalone sessions as noted above, then straight into mixed-domain practice.
- Rest of week 5: Mixed-domain practice sets daily (15-20 questions, all domains shuffled). Track your score by domain, not just overall, so you can see which domains are dragging down your average.
- Week 6: Your first full-length mock exam (125-175 questions, timed), taken early in the week. Treat it as a diagnostic, not a pass/fail test, and review every missed question and every question you guessed on, even if you got it right. Spend the rest of the week drilling whatever the mock exam exposed.
Weeks 7-8: Exam Readiness (Simulate the Real Thing)
The final two weeks are about simulating exam-day conditions and closing remaining gaps, not learning new material. If you're still encountering entirely unfamiliar concepts in week 7, that's a signal to consider pushing your exam date back by a couple of weeks rather than cramming.
| Week | Primary Goal | Activity |
|---|---|---|
| 7 | Full-length adaptive mock exam #2 | Take a CAT-style adaptive mock under timed conditions early in the week. Review misses by domain and by "manager vs. technician" reasoning errors, then drill your two or three weakest areas. |
| 8 | Taper and confidence-building | A shorter third mock exam mid-week, then light review only (no new material), 15-20 questions per day, rest the final 1-2 days before your exam |
🎯 Taper Matters
Don't cram the night before. The CISSP is a reasoning exam, not a recall exam; showing up mentally fresh matters more than one extra late-night review session. Most experienced CISSP instructors recommend stopping new material 48-72 hours before your exam appointment.
Adapting the Plan to Your Schedule
60 days is a target, not a rule. Here's how to adjust:
- If you have 5+ years of broad security experience, or you're retaking the exam: you can likely compress the foundation phase by a week and add that week to exam readiness instead, or look at the 30-day plan to see if that tighter timeline fits you better.
- If you're newer to security, or your experience is concentrated in one specialty: stretch the foundation phase by 2-3 weeks, particularly for Security Architecture and Engineering and Communication and Network Security, and consider the full 90-day plan instead.
- If life gets in the way for a week: don't try to double up the next week. Extend the plan by a week instead. A realistic 70-day plan beats an abandoned 60-day one.
What "Practice Questions" Should Actually Look Like
Not all practice questions are equal. Questions that only test recall ("which of the following is an example of a preventive control") build vocabulary but won't prepare you for the exam's actual format: long scenario-based questions that require you to weigh competing priorities and pick the best answer, not just a correct one.
As you move through the plan, prioritize practice sources that use scenario-based, "choose the BEST answer" question styles over pure definition recall, and that explain why the wrong answers are wrong, not just which answer is right. That explanation is where the actual learning happens, and it's especially important on a compressed timeline where you don't have spare weeks to relearn a concept you only half-understood the first time.
Frequently Asked Questions
Is 60 days enough time to study for the CISSP?
For candidates with some existing security or broad IT experience, generally yes. ISC2 commonly points toward 100-150+ hours of preparation, and a 60-day plan at roughly 60-75 minutes on weekdays plus a longer weekend session lands in that range. Candidates newer to security, or without much on-the-job exposure to the 8 domains, usually do better with a 90-day plan instead.
How is a 60-day plan different from the 30-day and 90-day plans?
It's the middle ground. The 30-day plan assumes 3.5-5 hours a day and suits experienced candidates or retakes. The 90-day plan spreads the same material over 13 weeks at a gentler pace. The 60-day plan compresses to 8 weeks at roughly 60-90 minutes a day, which fits candidates with some experience who want faster progress than 90 days without the intensity of a 30-day sprint.
How many practice questions should I do before the exam?
There's no single magic number, but most successful candidates work through somewhere in the range of 1,500-2,500+ practice questions across a 60-day period, including at least 2-3 full-length mock exams taken under timed conditions. Volume matters less than reviewing every explanation, including for questions you got right.
What if my mock exam scores aren't improving?
Check whether you're reviewing wrong answers thoroughly or just moving on to the next set. Flat scores usually mean the same reasoning mistakes are repeating unaddressed, not that you need more raw question volume. Slow down, review by domain, and look specifically for "technician-thinking" traps, choosing the technically correct action over the managerially correct one.
When should I schedule my CISSP exam appointment?
Schedule it once you commit to the plan, roughly 60-65 days out, rather than waiting until you "feel ready." A firm date on the calendar is one of the most effective motivators for actually sticking to a study schedule, and Pearson VUE appointment availability can be limited in some areas.
Putting It Together
A 60-day plan works when it matches the candidate: someone with enough existing security exposure that the 8 domains aren't starting from zero, who can sustain a consistent 60-90 minutes a day without the all-consuming pace of a 30-day sprint. The structure, learn, practice, review, repeat, matters more than the exact hour count, and the mix should shift from learning-heavy in weeks 1-4 to practice-heavy by weeks 7-8.
The single biggest failure mode on any timeline isn't lack of knowledge. It's inconsistent practice combined with never taking a full-length timed mock exam until the final week. Build the mock exams into the plan early, and treat every missed question as information, not a setback.
Start Your 60-Day Plan Today
Take a free 5-question diagnostic, no signup required, to see where your weak domains are before you build your study schedule. Then start a 7-day free trial for full adaptive CAT-style mock exams and domain-by-domain practice.
Take the Free DiagnosticNo credit card required · CISSP, CCSP & CISM included
CISSP.app