What Is the CISSP Passing Score and How Is It Calculated?
ISC2 tells you the number you need: 700 out of 1000. What it does not spell out anywhere on the official site is what that number actually means, or why it has almost nothing to do with the percentage of questions you got right.
Ask ten CISSP candidates what the passing score means and most will tell you "70%." That answer is understandable, and it is wrong in a way that causes real, unnecessary anxiety on exam day. The CISSP is not graded on a 0-to-100 percentage scale. It is graded on a 200-to-800 scaled score, with 700 as the passing line, and that scaled number is produced by a statistical model, not a tally of correct answers.
This guide walks through what the 700/1000 score actually represents, how ISC2's adaptive scoring model turns your answers into that number, why domain weighting matters more than raw question count, and why the "you must get X% right" myth keeps circulating even though it is not how the exam works.
The Short Answer: 700 Out of 1000
ISC2 sets the CISSP passing standard at a scaled score of 700 out of a possible 1000 points. This applies to both versions of the exam: the adaptive CAT format most English-speaking candidates sit, and the older fixed-form linear exam still used for non-English languages.
- Passing score: a scaled 700 out of 1000 possible points
- The scale is not a percentage. 700/1000 does not mean "70% of questions correct"
- Score is calculated across all 8 domains of the CISSP Common Body of Knowledge, weighted by domain
- Unscored pretest items are mixed into every exam and do not count toward your score, though you cannot tell which ones they are
- You receive a pass/fail result immediately at the test center; a full breakdown by domain follows if you fail
The reason ISC2 uses a scaled score instead of raw percent-correct comes down to fairness across exam forms. Because the CAT exam pulls a different set of questions, at a different difficulty, for every single candidate, "percentage correct" would not mean the same thing from one person's exam to the next. A scaled score, by contrast, is calibrated to represent the same underlying standard of competence no matter which specific questions you happened to receive.
Why the CISSP Score Is Not a Percentage
This is the single biggest misconception about CISSP scoring, so it is worth stating directly: getting 70% of your questions correct does not mean you passed, and getting less than 70% correct does not mean you failed. The two numbers, percent correct and scaled score, are not the same measurement and are not on the same scale.
A percentage treats every question as worth the same amount. Answer 105 of 150 questions correctly and a straight percentage says 70%. But the CISSP scoring model does not work that way. It weighs each answer by how difficult that specific question was and by which domain it came from, then converts the whole pattern of your answers into a single scaled ability estimate. Two candidates who both answer 70% of their questions correctly can land on opposite sides of the 700 line, because they did not answer equally difficult questions, and they were not tested on the same distribution across domains.
This is also why ISC2 has never published a simple formula like "you need to get N out of 150 right." No such fixed number exists, because the exam itself is not fixed.
How Item Response Theory Turns Answers Into a Score
The CISSP CAT exam is built on Item Response Theory (IRT), the same statistical framework used by many major adaptive certification and licensure exams. Under IRT, every question in ISC2's item bank has been pre-calibrated using data from thousands of prior test-takers, giving each item a known difficulty level and a known ability to discriminate between candidates who are and are not competent.
Instead of just counting correct answers, the scoring engine maintains a running estimate of your underlying ability level, often modeled as a value called theta, and updates that estimate after every single question based on two things: whether you got the question right, and how difficult that specific question was relative to your current estimate. Answering a hard, highly discriminating question correctly moves your estimate up by more than answering an easy question correctly. Missing a question you were expected to get right (based on the current estimate) moves it down more than missing one you were unlikely to get right in the first place.
That running ability estimate is what eventually gets converted to the 200-800 scale you see reported as your final score. The number you receive is a translation of "how capable does the evidence say you are," not "how many boxes did you check correctly."
Why this also explains variable exam length
Because the score comes from an ability estimate rather than a running tally, the CAT exam can stop anywhere between 100 and 150 questions, whenever the algorithm's statistical confidence in your pass or fail result crosses its threshold. If you want the mechanics of that adaptive stopping logic in more depth, see our companion guide on how the CISSP CAT exam format actually works.
Domain Weighting: Not All Questions Count the Same
On top of item-level difficulty weighting, your score is also balanced across all 8 domains of the CISSP Common Body of Knowledge, and ISC2 assigns each domain a different share of the exam. Per ISC2's published exam outline, the approximate domain weights are:
- Domain 1: Security and Risk Management — 16%
- Domain 2: Asset Security — 10%
- Domain 3: Security Architecture and Engineering — 13%
- Domain 4: Communication and Network Security — 13%
- Domain 5: Identity and Access Management (IAM) — 13%
- Domain 6: Security Assessment and Testing — 12%
- Domain 7: Security Operations — 13%
- Domain 8: Software Development Security — 10%
ISC2 periodically revises these weights when it refreshes the exam outline, so treat the figures above as the current published breakdown rather than a permanent constant. The practical takeaway does not change though: a candidate cannot pass by mastering one or two heavily weighted domains and neglecting the rest. The algorithm has to satisfy domain coverage requirements before it can close out your exam, which means every domain gets tested, and a serious weakness in any single domain, especially Security and Risk Management at 16%, can pull your scaled score below 700 even if you are strong everywhere else.
Myth-Busting: You Do Not Need Every Answer Correct
Because the scoring model rewards a consistent, above-threshold ability estimate rather than a perfect run, you can and are expected to answer some questions incorrectly and still pass comfortably. A handful of missed questions, especially difficult ones near or above your ability level, is normal and does not doom your result.
Two more things complicate the naive "count your wrong answers" instinct candidates bring in from other exams:
- Unscored pretest items are mixed in. ISC2 field-tests future exam questions inside live exams. These items look identical to scored questions, count toward your total item number and the clock, but do not count toward your score at all. You have no way to identify them, so there is no reliable way to count how many "real" questions you missed even after the exam.
- Some questions are worth more than others. As covered above, difficulty and domain weighting mean two missed questions are rarely equal in their effect on your final scaled score.
The upshot: obsessively trying to track your running score during the exam, or reconstructing it afterward from memory, is not a productive use of mental energy. It cannot be done accurately, and the exam does not work the way that instinct assumes.
Why ISC2 Does Not Publish an Exact "Questions Needed" Number
Candidates often go looking for a number like "you need to answer 78 of 100 correctly" the way they might for a college exam. ISC2 has never published such a figure, and it is not simply withholding it, that number does not exist in a fixed form. The specific IRT parameters ISC2 uses (item difficulty and discrimination values, the exact ability-estimate algorithm, and the confidence threshold that ends the exam) are proprietary and are not made public, in part because publishing them would let candidates reverse-engineer the exam rather than demonstrate genuine competence.
What ISC2 does publish, and what you should treat as the reliable source, is the 700/1000 scaled passing standard and the domain weighting in the current exam outline available at isc2.org. Anything more specific than that circulating in forums or study groups is speculation, however confidently it is stated.
What This Means For How You Should Study
Understanding the scoring model should change your prep strategy in a few concrete ways:
- Do not neglect any domain because it feels smaller. Even a 10% domain like Asset Security or Software Development Security can pull your score down if you consistently miss questions there, since a weak domain estimate does not get fully offset by strength elsewhere.
- Prioritize Domain 1 and the other 13% domains. Security and Risk Management, at 16%, carries the most weight of any single domain, and four domains sit at 13% each. Together those five domains represent close to two-thirds of the exam.
- Practice reasoning through hard, scenario-style questions, not just recall. Since difficult items that you answer correctly move your ability estimate up more than easy ones, the exam is specifically designed to reward candidates who can reason through ambiguous, harder scenarios, not just recite definitions.
- Stop trying to self-score during the real exam. Given unscored pretest items and weighted difficulty, there is no way to accurately track your running result in your head. Focus your attention on the question in front of you instead.
This is the same reasoning behind our guide on thinking like a manager on the CISSP exam: the scoring model is built to separate candidates who reason well under uncertainty from candidates who have simply memorized facts, and that distinction is exactly what the harder, more heavily weighted questions are designed to surface.
Frequently Asked Questions
What score do you need to pass the CISSP exam?
A scaled score of 700 out of a possible 1000 points, calculated across all 8 CISSP domains according to ISC2's published domain weighting. This standard is the same for both the adaptive CAT exam and the fixed-form linear exam.
Is the CISSP passing score a percentage?
No. 700/1000 is a scaled score derived from a statistical ability estimate (Item Response Theory), not the percentage of questions you answered correctly. Percent-correct and scaled score are different measurements and are not directly comparable.
How many questions do you need to get right to pass?
ISC2 has not published a fixed number, and no single fixed number exists, because item difficulty, domain weighting, and unscored pretest items all affect how any individual answer influences your final score. Two candidates who answer the same raw number of questions correctly can receive different results.
Do you need to pass every domain individually?
Your overall result is a single weighted scaled score, not eight separate pass/fail checks. That said, a serious weakness concentrated in one domain, particularly a heavily weighted one, can be enough to pull your overall scaled score below 700, so balanced preparation across all domains matters.
Can you tell your score during the exam?
No. The exam does not display a running score, and CAT does not allow you to skip questions or revisit earlier answers. You receive your pass/fail result at the test center immediately after finishing, with a domain-level performance breakdown provided only if you did not pass.
Practice With Real Exam-Style Scoring Pressure
Knowing how the scoring model works removes a lot of exam-day guesswork, but it does not replace practicing under the same weighted, adaptive-style pressure the real exam applies. The most useful preparation exposes you to harder, scenario-based questions across all 8 domains in the same proportions ISC2 actually tests, not a flat, evenly distributed question bank.
Try a Free 5-Question Diagnostic
See CISSP-style scenario questions for yourself, no account required. Then start a full 7-day free trial to practice with our adaptive-style question bank, weighted the way the real exam is weighted, across all 8 domains.
Take the Free DiagnosticNo credit card required for the 7-day trial · CISSP, CCSP & CISM included
CISSP.app