Is the CISSP exam changing in 2026? No. The CISSP exam outline was last refreshed on April 15, 2024, and as of this writing there is no new outline announced for 2026. If you’ve seen chatter online suggesting otherwise, it’s almost certainly a mix-up with two other ISC2 certifications that are refreshing this year — not CISSP.
I keep getting versions of this question from people who are sitting on a study plan, waiting for “the new version” before they schedule an exam date. That wait has no basis. Here’s what’s actually happening in 2026, and why you should stop waiting and go test.
The Direct Answer
CISSP is not changing in 2026. The current exam outline has been in effect since April 15, 2024, and it remains valid through 2026. Nothing has been published by ISC2 announcing a new domain structure, new weighting, or a new format for CISSP this year.
The exam format itself — a computerized adaptive test (CAT) drawn from a pool of 125 to 175 items, with a maximum time limit of four hours — is also unchanged. If you’ve already built a study plan around the eight domains in the current outline, that plan is still accurate.
The Eight CISSP Domains — Still the Same
Since the April 2024 refresh, CISSP has been organized around eight domains, and that structure hasn’t moved:
- Domain 1 — Security and Risk Management
- Domain 2 — Asset Security
- Domain 3 — Security Architecture and Engineering
- Domain 4 — Communication and Network Security
- Domain 5 — Identity and Access Management
- Domain 6 — Security Assessment and Testing
- Domain 7 — Security Operations
- Domain 8 — Software Development Security
If you’re studying from materials published after April 2024, you’re aligned with the live exam. If your study guide predates that refresh, that’s the one thing actually worth double-checking — not whether a 2026 change is coming.
What’s Actually Refreshing in 2026 (and Why People Confuse It With CISSP)
The confusion has a clear source: ISC2 does have two certification refreshes landing in 2026, and both get lumped into “the CISSP is changing” rumor mill because they’re ISC2 certifications too.
| Certification | 2026 Refresh Date | Is This CISSP? |
|---|---|---|
| CCSP (Certified Cloud Security Professional) | August 1, 2026 | No — separate cloud security credential |
| CC (Certified in Cybersecurity) | September 1, 2026 | No — separate entry-level credential |
| CISSP | No refresh announced for 2026 | N/A — outline unchanged since April 15, 2024 |
Both CCSP and CC are legitimate ISC2 certifications with their own exam outlines, and both are getting content refreshes this year. Neither of those refreshes touches CISSP’s domain structure, weighting, or question pool. If you’re studying for CISSP specifically, these dates are irrelevant to your prep.
Why the “Wait for the New Version” Instinct Is Wrong
Even when a certification genuinely does refresh, waiting rarely pays off. Refreshes tend to add content, not remove it — new domains reflect emerging risk areas that get layered on top of, not instead of, existing material. A refreshed outline is not usually easier to pass; it’s usually a longer syllabus.
For CISSP specifically, none of that applies right now because there’s nothing to wait for. But even hypothetically, delaying a certification exam on the rumor of a future refresh is a bad trade against the certainty of a completed certification today. Every month spent waiting is a month you could have been studying against the outline that’s actually live, with study materials that are current and accurate.
If you already have a study plan built around the current CISSP domains, our CISSP study plan for DoD cybersecurity professionals lays out a 90-day schedule against the outline as it stands today — no need to hold off for a revision that isn’t coming.
CISSP Exam Cost in 2026
The CISSP exam costs $749 USD at Pearson VUE for a first attempt, plus applicable regional taxes depending on your testing location. That price has held steady and reflects the current, unchanged exam.
Beyond the exam fee, budget for the Annual Maintenance Fee (AMF) of $135 per year to keep the certification active — or $50 per year if you’re holding an ISC2 Associate designation while completing your experience requirement. You’ll also need 120 Continuing Professional Education (CPE) credits across each three-year certification cycle to maintain the credential once you’ve passed.
For comparison, since people sometimes confuse pricing across certifications the same way they confuse refresh dates: CompTIA Security+ (SY0-701) runs about $404 USD and refreshed its own objectives on July 1, 2026. That’s a different certification track entirely, but it’s worth knowing if you’re mapping out a DoD 8140 baseline alongside CISSP.
If You’re Deciding Between Testing Now or Waiting
Here’s the practical framing I give people who ask me this question directly:
- The current outline is valid through 2026 — there’s no published expiration date for it that would make your prep obsolete
- ISC2 typically announces outline changes well in advance of implementation, with a transition window — there’s no history of surprise same-day changes
- The two 2026 refreshes (CCSP, CC) are unrelated credentials — don’t let their announcement dates create false urgency around your CISSP timeline
- A certification in hand has immediate value for job applications, promotions, and DoD 8140 baseline compliance — a hypothetical future version has none
If your study materials are current — meaning published or updated after April 2024 — you’re studying against the live outline. Schedule the exam.
CISSP and DoD 8140: Why the Timing Question Matters
For DoD cybersecurity professionals specifically, CISSP isn’t just a resume line — it maps directly to work role requirements under DoD 8140, the framework that replaced the older 8570 baseline. If you’re an ISSO or ISSM working toward a role that lists CISSP as a qualifying certification, sitting on your prep because of a rumored 2026 change delays your eligibility for that role with zero corresponding benefit.
The same applies if CISSP is a condition of a promotion, a contract requirement, or a GS-14 track. Certification timelines on government contracts don’t pause for exam rumors, and hiring managers reviewing your file care about the certification being active, not about which outline version you tested against.
Frequently Confused Questions
Is the CISSP getting a ninth domain in 2026? No. There is no published outline change adding, removing, or restructuring domains for 2026.
Did the CISSP price change for 2026? No. The exam fee is $749 USD at Pearson VUE for a first attempt, unchanged from the current published pricing.
Is CCSP the same thing as CISSP with cloud content added? No. CCSP is a fully separate certification focused specifically on cloud security. Its August 1, 2026 refresh updates CCSP’s own outline and has no bearing on CISSP.
Should I wait to see if ISC2 announces a CISSP refresh later this year? If you’re prepared now, no. ISC2 has a track record of announcing refreshes with lead time before they take effect, so there’s no risk of your exam attempt being invalidated mid-cycle by a surprise change.
Where to Verify This Yourself
Don’t take a blog post’s word for it on something this consequential. ISC2 publishes an official Exam Outline document and an Exam Refresh FAQ page for every certification it administers, including CISSP. Before you schedule, pull the current CISSP exam outline PDF directly from isc2.org and check the effective date printed on it — it should read April 15, 2024, confirming nothing has moved.
It only takes a few minutes, and it removes any doubt before you commit to a Pearson VUE testing slot. Cross-referencing the official source directly is also good practice generally — certification requirements tied to DoD 8140 baselines get updated periodically, and your primary source should always be the issuing body, not secondhand summaries, including this one.
If you want a domain-by-domain breakdown of what’s actually on the current exam and how it maps to DoD work, start with CISSP Domain 1 explained for DoD professionals. And once you’ve got your study plan locked, the practical side of prep — what to actually buy, how to set up your study space, which reference materials are worth the money — is covered in the CISSP study setup that got me through.
The Bottom Line
CISSP is not changing in 2026. The last refresh was April 15, 2024, and no new outline has been announced. The certifications that are refreshing this year — CCSP on August 1 and CC on September 1 — are separate credentials that happen to share an issuing body with CISSP, and that’s the entire source of the confusion.
If you’ve been holding off on scheduling your exam because you heard something was coming, there’s nothing coming. The $749 fee, the current domain structure, and the CAT format are what you’ll face whether you test next month or next year — so there’s no upside to waiting and a real cost in delayed opportunity. Lock in your date.
If you’re building toward your first cleared role and CISSP is part of a bigger roadmap — not just one exam but a full plan from zero experience to a job offer — the Zero to Hired roadmap ($29) lays out the six-month path, certification sequencing included, so you’re not guessing at what to study next.

Leave a Reply