The 90-Day CISSP Study Plan (Week-by-Week)
A realistic, structured plan for people studying part-time around a full-time job: domain review, adaptive practice, and full mock exams building toward exam day.
Most CISSP study advice falls into one of two traps. Either it assumes you can study eight hours a day, or it hands you a generic "read the book, take a practice test" plan with no structure. Neither works for the typical CISSP candidate: someone already working full-time in IT or security, studying in the early morning, during lunch, or after the kids are asleep.
This is a 90-day plan built for that reality. It assumes roughly 45-60 minutes on weekdays and 2-3 hours on one weekend day, which lands most studiers in the 100-140 hour range by exam day, in line with what ISC2 and most CISSP instructors recommend for candidates with some existing security background. If you're newer to the field, plan to lean toward the higher end and consider stretching this to 120 days.
The plan is organized around three phases: foundation (weeks 1-6), integration (weeks 7-10), and exam readiness (weeks 11-13). Each phase shifts the mix of activity from reading and domain review toward adaptive practice questions and full-length mock exams.
- Foundation (Weeks 1-6): First pass through all 8 CISSP domains, one to two domains per week, with light practice questions after each
- Integration (Weeks 7-10): Cross-domain practice, weak-area drilling, and your first full-length mock exams
- Exam Readiness (Weeks 11-13): Adaptive CAT-style mock exams, targeted review of remaining weak domains, and a final taper week
Before You Start: Set Your Baseline
Before opening a study guide, take one full diagnostic assessment. This tells you which of the 8 CISSP domains need the most attention so you're not spending equal time on material you already know. Don't skip this step to "save time." An hour spent finding your actual weak areas saves many more hours later.
You can take a free, no-signup diagnostic (5 questions, instant results) to get a quick read before committing to the full plan. It won't replace a full domain-by-domain baseline, but it's a fast way to see where you stand.
Weeks 1-6: Foundation (Domain Coverage)
The goal of the foundation phase is simple: touch every domain at least once, in enough depth that the vocabulary and core concepts stop feeling foreign. Don't aim for mastery yet. Aim for familiarity.
| Week | Focus Domain(s) | Weekday Activity | Weekend Activity |
|---|---|---|---|
| 1 | Security and Risk Management | Read/watch domain material, 30-40 min | 20-30 practice questions, review every explanation |
| 2 | Asset Security | Read/watch domain material, 30-40 min | 20-30 practice questions, review every explanation |
| 3 | Security Architecture and Engineering | Read/watch material, 40-50 min (dense domain) | 25-30 practice questions |
| 4 | Communication and Network Security | Read/watch material, 40-50 min (dense domain) | 25-30 practice questions |
| 5 | Identity and Access Management (IAM) | Read/watch domain material, 30-40 min | 20-30 practice questions |
| 6 | Security Assessment and Testing + Security Operations | Read/watch material, 30-40 min each | 25-30 practice questions, mixed domain |
Notice weeks 3 and 4 get more time. Security Architecture and Engineering and Communication and Network Security are consistently the domains candidates find hardest, because they blend heavy technical detail (cryptography, network protocols, physical security) with the same managerial reasoning the rest of the exam demands. Don't rush them.
Software Development Security, the 8th domain, gets folded into week 6-7 as a shorter standalone session since it's typically the smallest domain by question volume and overlaps conceptually with change management and secure architecture, both of which you'll have already covered.
A realistic weekday/weekend split during the foundation phase:
Weeks 7-10: Integration (Cross-Domain Practice)
This is where the plan shifts from learning domains in isolation to practicing the way the exam actually works: questions that blend concepts from multiple domains into a single scenario. This phase also introduces your first full-length mock exams.
- Weeks 7-8: Mixed-domain practice sets daily (15-20 questions, all domains shuffled). Track your score by domain, not just overall, so you can see which domains are dragging down your average.
- Week 9: Your first full-length mock exam (125-175 questions, timed). Treat this as a diagnostic, not a pass/fail test. Review every missed question and every question you guessed on, even if you got it right.
- Week 10: Targeted drilling on whatever the mock exam exposed. If Security Operations was your weak domain, spend 3-4 days that week almost entirely on Security Operations questions and explanations.
Weeks 11-13: Exam Readiness (Simulate the Real Thing)
The final three weeks are about simulating exam-day conditions and closing remaining gaps, not learning new material. If you're still encountering entirely unfamiliar concepts in week 11, that's a signal to consider pushing your exam date back rather than cramming.
| Week | Primary Goal | Activity |
|---|---|---|
| 11 | Full-length adaptive mock exam #2 | Take a CAT-style adaptive mock under timed conditions. Review misses by domain and by "manager vs. technician" reasoning errors. |
| 12 | Close remaining gaps | Domain-specific drilling on your two or three weakest areas, plus a shorter second mock exam mid-week |
| 13 | Taper and confidence-building | Light review only (no new material), 15-20 questions per day, rest the final 1-2 days before your exam |
🎯 Taper Week Matters
Don't cram the night before. The CISSP is a reasoning exam, not a recall exam; showing up mentally fresh matters more than one extra late-night review session. Most experienced CISSP instructors recommend stopping new material 48-72 hours before your exam appointment.
Adapting the Plan to Your Schedule
90 days is a target, not a rule. Here's how to adjust:
- If you have 5+ years of hands-on security experience: you can likely compress the foundation phase to 4 weeks and add an extra week to exam readiness instead.
- If you're newer to security or coming from a different IT specialty: stretch the foundation phase to 8-9 weeks, particularly for Security Architecture and Engineering and Communication and Network Security.
- If life gets in the way for a week: don't try to double up the next week. Extend the plan by a week instead. A realistic 100-day plan beats an abandoned 90-day one.
What "Practice Questions" Should Actually Look Like
Not all practice questions are equal. Questions that only test recall ("which of the following is an example of a preventive control") build vocabulary but won't prepare you for the exam's actual format: long scenario-based questions that require you to weigh competing priorities and pick the best answer, not just a correct one.
As you move through the plan, prioritize practice sources that use scenario-based, "choose the BEST answer" question styles over pure definition recall, and that explain why the wrong answers are wrong, not just which answer is right. That explanation is where the actual learning happens.
Frequently Asked Questions
Is 90 days enough time to study for the CISSP?
For most candidates with some existing security experience, yes. ISC2 generally recommends 100-150+ hours of preparation, and a 90-day plan at 45-60 minutes on weekdays plus a longer weekend session lands comfortably in that range. Candidates newer to security, or without much on-the-job exposure to the 8 domains, often benefit from stretching to 120 days.
How many practice questions should I do before the exam?
There's no single magic number, but most successful candidates work through somewhere in the range of 1,500-3,000+ practice questions across their study period, including at least 2-3 full-length mock exams taken under timed conditions. Volume matters less than reviewing every explanation, including for questions you got right.
Should I read a full study guide cover to cover, or focus only on practice questions?
Both, in sequence. Reading builds the vocabulary and conceptual framework you need; practice questions test whether you can apply it under exam-style reasoning. A plan that's 100% reading tends to produce candidates who know the material but freeze on scenario questions. A plan that's 100% practice questions with no foundational reading tends to produce guessing rather than reasoning.
What if my mock exam scores aren't improving?
Check whether you're reviewing wrong answers thoroughly or just moving on to the next set. Flat scores usually mean the same reasoning mistakes are repeating unaddressed, not that you need more raw question volume. Slow down, review by domain, and look specifically for "technician-thinking" traps, choosing the technically correct action over the managerially correct one.
When should I schedule my CISSP exam appointment?
Schedule it once you commit to the plan, roughly 90-100 days out, rather than waiting until you "feel ready." A firm date on the calendar is one of the most effective motivators for actually sticking to a study schedule, and Pearson VUE appointment availability can be limited in some areas.
Putting It Together
A 90-day plan works because it forces a rhythm: learn, practice, review, repeat, with the mix shifting from learning-heavy to practice-heavy as exam day approaches. The specific hours matter less than the consistency. Someone who studies 45 minutes a day for 90 days will outperform someone who crams 10 hours every other weekend, because spaced repetition and cumulative review are how the material actually sticks for a reasoning-based exam like the CISSP.
The single biggest failure mode isn't lack of knowledge. It's inconsistent practice combined with never taking a full-length timed mock exam until the final week. Build the mock exams into the plan early, and treat every missed question as information, not a setback.
Start Your 90-Day Plan Today
Take a free 5-question diagnostic, no signup required, to see where your weak domains are before you build your study schedule. Then start a 7-day free trial for full adaptive CAT-style mock exams and domain-by-domain practice.
Take the Free DiagnosticNo credit card required · CISSP, CCSP & CISM included
CISSP.app