CISSP Retake Policy: Waiting Periods, Costs, and What to Do Next
A failed CISSP attempt is not the end of anything. It is data. Here is exactly how long ISC2 makes you wait, what it costs to sit again, and a practical plan for turning a fail into a pass on your next attempt.
Failing the CISSP exam is common, and it is rarely talked about openly. ISC2 does not publish an official first-attempt pass rate, but anecdotal data from study communities and training providers consistently suggests a meaningful share of first-time candidates do not pass, especially those who underestimate the exam's scenario-based, managerial style of questioning. If you are reading this after seeing a fail result at the test center, you are not an outlier, and the retake process is more straightforward than it feels right now.
This guide covers ISC2's actual retake rules (waiting periods, the annual attempt cap, and fees), what your score report does and does not tell you, and a concrete plan for using the weeks between attempts to close the specific gaps that cost you the exam the first time.
ISC2's Official CISSP Retake Rules
ISC2 governs retakes through its exam retake policy, which applies uniformly regardless of why you did not pass. The rules are based on how many times you have attempted the exam within a rolling 12-month period, not on your score or how close you came to passing.
- After your 1st failed attempt: wait at least 30 days before retesting
- After your 2nd failed attempt: wait at least 60 days before retesting
- After your 3rd failed attempt: wait at least 90 days before retesting
- Maximum attempts: up to 4 attempts within any rolling 12-month period
These waiting periods are minimums, not suggestions, and Pearson VUE's scheduling system will not let you book an exam that falls inside your required waiting window. Always confirm the current figures on ISC2's official retake policy page before you schedule, since ISC2 does periodically revise exam administration policies.
A few practical points that trip candidates up:
- The clock starts from your exam date, not your registration date. If you tested on a Tuesday and failed, your 30-day window begins that Tuesday.
- The 12-month attempt cap is rolling, not calendar-year based. It counts back 12 months from any given attempt, so your oldest attempt eventually rolls off the count as time passes.
- There is no limit on how many times you can retake the CISSP over your lifetime, only on how many attempts you can make within any 12-month window.
What It Costs to Retake the CISSP
There is no discounted "retake fee." Every attempt, including your first, is billed at ISC2's standard exam registration price, which Pearson VUE processes at the time of scheduling. Pricing varies somewhat by country and currency, and ISC2 updates it periodically, so check the current price on isc2.org or in your Pearson VUE account before you book rather than relying on a remembered figure.
Beyond the exam fee itself, factor in the real cost of a retake: additional study materials or practice question access, potential travel or time off work for the test center appointment, and the opportunity cost of the weeks you will spend preparing again. None of that is a reason to delay, but it is a reason to use the waiting period deliberately rather than simply re-reading the same material and hoping for a different outcome.
What Your Score Report Actually Tells You
When you do not pass, ISC2 provides a breakdown of your performance across the 8 CISSP domains at the test center, typically shown as a band such as "below proficient," "near proficient," or a similar relative indicator rather than a raw numeric score per domain. This report is the single most useful piece of information you have for planning your retake, and a lot of candidates barely glance at it before diving back into generic study materials.
Read the domain breakdown like a diagnosis, not a grade
The domain report is not telling you "you are bad at Domain 4." It is telling you where the exam's adaptive algorithm found the clearest evidence of a gap. Because the CAT exam concentrates questions near your ability threshold, a domain flagged as weak is very likely the domain where borderline, scenario-style reasoning broke down under pressure, not just an area you forgot to memorize. For more on how that scoring works, see our guide on how the CISSP passing score is actually calculated.
Before you register for your next attempt, take the report seriously as your study plan's starting point rather than a formality to skim past.
Why Candidates Fail: The Pattern Behind Most Retakes
Across CISSP study communities, a few failure patterns show up again and again, and most of them are fixable without redoing everything from scratch:
- Technician-level thinking on manager-level questions. The CISSP tests judgment for a security leader, not hands-on technical execution. Candidates who know the material but keep picking the "fix it directly" answer over the "assess, plan, or delegate" answer consistently underperform relative to their actual knowledge.
- Uneven domain coverage. Spending most of your study time on your favorite or most familiar domain while under-preparing a heavily weighted domain like Security and Risk Management can sink an otherwise strong overall performance.
- Passive studying. Re-reading a book or watching videos builds recognition, not the applied reasoning the exam actually tests. Candidates who study passively often feel confident going in and are surprised by how unfamiliar the scenario format feels once questions get harder.
- Underestimating the CAT format itself. Not knowing that answers are locked in permanently, that the exam gets harder as you do well, or how the adaptive algorithm decides when to stop can cost focus and pacing on exam day even when the underlying knowledge is solid.
A Practical Regroup Plan for Your Next Attempt
Use your mandatory waiting period as a structured runway, not just a countdown. Here is a framework that works whether you have 30, 60, or 90 days:
- Start with your domain report. Identify the 2 to 3 domains flagged weakest and treat them as your priority, without abandoning the rest.
- Shift from reading to answering. Spend the majority of your remaining prep time on scenario-style practice questions, not re-reading chapters you have already covered. Recognition is not the same skill as decision-making under exam pressure.
- Track your reasoning, not just your score. When you miss a practice question, ask why you picked the wrong answer. Was it a knowledge gap, or did you pick the technically correct but managerially wrong option? Those require different fixes.
- Simulate the real conditions. Practice in timed blocks that mimic the pressure of not being able to skip or revisit questions, since that structural constraint catches candidates off guard on exam day more than people expect.
- Reassess weekly, not just once. A weak domain in week one should be visibly improving by week three. If it is not moving, that domain needs a different study approach, not just more repetition of the same one.
This is also where the manager-mindset shift matters most. If your fail was concentrated in scenario-heavy domains rather than pure recall domains, the fix is rarely "learn more facts." It is learning to reliably choose the answer a security leader would choose. Our guide on how to think like a manager on the CISSP exam walks through eight worked examples of exactly that shift.
Rescheduling Logistics: What Actually Happens
Once your waiting period has passed, retaking the exam is procedurally identical to your first attempt. You register and pay through Pearson VUE (via your ISC2 account), select an available test center or online proctoring slot, and sit the same CAT-format exam covering all 8 domains. There is no separate "retake exam" with different content or format, and no note or flag is attached to your record that examiners or future employers can see. A pass is a pass, regardless of how many attempts it took.
One logistics detail worth planning around: popular test centers can book out several weeks in advance, especially near the end of a month or quarter. If your waiting period ends on a specific date, check scheduling availability for your preferred center as soon as that date approaches rather than waiting until the day you are eligible.
Frequently Asked Questions
How long do you have to wait to retake the CISSP exam?
At least 30 days after a first failed attempt, 60 days after a second, and 90 days after a third, per ISC2's published retake policy. You may attempt the exam up to 4 times within any rolling 12-month period.
How many times can you fail the CISSP exam?
There is no lifetime limit on total attempts, only a cap of 4 attempts within any rolling 12-month period. Once older attempts age past 12 months, they no longer count against that rolling limit.
Does a CISSP retake cost less than the first attempt?
No. ISC2 does not offer a discounted retake fee. Every attempt, including retakes, is billed at the standard exam registration price in effect at the time you schedule.
Does failing the CISSP exam go on your record?
No visible flag or note is attached to your ISC2 profile or shared with employers. Once you pass, your certification record simply shows a pass; it does not disclose how many attempts it took to get there.
Can you use the same study materials for a retake?
You can, but doing only that rarely changes the outcome. Your domain score report exists specifically to redirect your effort toward the gaps that caused the fail; layering targeted, scenario-based practice on top of your original materials is far more effective than a straight repeat of the same study routine.
Turn Your Domain Report Into a Study Plan
The fastest path back to the test center is targeted practice against your actual weak domains, under conditions that mirror the real exam's adaptive difficulty and scenario style. Guessing at what to restudy from memory wastes the one advantage a retake gives you: a diagnostic report the exam itself handed you for free.
Try a Free 5-Question Diagnostic
See CISSP-style scenario questions for yourself, no account required. Then start a full 7-day free trial to target your weak domains with adaptive-style practice across all 8 domains.
Take the Free DiagnosticNo credit card required for the 7-day trial · CISSP, CCSP & CISM included
CISSP.app