CAT format · Understand
The 700/1000 score on the CISSP: what it measures, and what it does not
The CISSP is passed at 700 points out of 1000, but that figure is nothing like a percentage of correct answers: scoring is based on Item Response Theory (IRT), which weights each question by its difficulty. You can therefore pass with half of your answers correct and fail with 80%.
The CISSP is passed at 700 points out of 1000. The natural reflex is to read that as "70% correct answers" — and it is the misreading the candidate community corrects most systematically. The CISSP score is not a tally: it is an estimate of your ability, produced by a statistical model that takes into account the difficulty of every question asked. Two candidates with the same number of correct answers can therefore end up with very different scores.
These reference points come from candidate accounts (our method).
What exactly does 700/1000 mean on the CISSP?
It is the pass mark on a 1000-point scale. What it does not mean is well established:
"The exam is not 70%! [...] the 700/1000 is actually based on WHICH questions you answered correctly. It is NOT LINEAR!!!!!!!! One question could be worth 90 points and another 4."
On an adaptive exam of 100 to 150 questions — the format in force since 15 April 2024, down from 125 to 175 questions in 4 hours — no question carries the same weight as the next. The total number of correct answers is therefore not usable information.
A scale, not a published mark scheme
How the 1000 points are bounded, how the 700 threshold was set and the level of confidence required before reaching a verdict are not published: these are matters for ISC2's own documentation, see isc2.org.
How does the CAT's IRT scoring work?
The CAT relies on Item Response Theory, a model that estimates an ability from the answers given and the characteristics of the questions:
"CAT examinations use something called 'Item Response Theory' for scoring. Essentially, this is a statistical model that considers not only the correctness of answers but also the difficulty of each question and the test-taker's overall ability."
Two practical consequences. First, a correct answer to an easy question adds little: it was expected. Second, the algorithm constantly looks for the most informative questions at your level, which is why a candidate who is passing can feel out of their depth throughout.
Why is the score not linear?
Because the weight of a question depends on its calibrated difficulty and on its ability to discriminate between candidates, not on its position in the sequence. Candidates draw a counter-intuitive and much-quoted conclusion from this:
"This is also why people can score 50% on practice exams and pass, and why people who score 80% fail. This is also why there is no scoring provided to individuals!"
A community CAT simulator released in open beta in May 2025 made this non-linearity very visible to the candidates who use it:
| Score obtained (simulator) | Share of correct answers |
|---|---|
| 722 / 1000 | 60% (40 wrong out of 100 questions) |
| 950 / 1000 | 60% |
| 1000 / 1000 | 68% |
These three results come from different sessions and are not real exam scores. That two sessions with 60% correct answers produce 722 and 950 comes down to which questions were involved and how the adaptive sequence unfolded. The candidate who was surprised by his 722 with 40 wrong answers drew this reply:
"Scoring is based on your ability, not how many are right vs wrong; just like the real exam"
Can you infer your level from your practice exam percentage?
Not reliably, and the non-linearity described above is enough to explain why: a practice percentage measures an average over a fixed sample, whereas the official score estimates an ability. The scores reported by candidates who passed are in fact widely spread depending on the question bank used, and the 85% benchmark on practice tests is explicitly disputed. The observed ranges and the indicator to look at instead are detailed in what score to aim for on CISSP practice exams.
What are practice exams good for, then?
Three things: spotting the domains where you cannot explain a concept, getting used to the pace and the fatigue of 3 hours, and becoming familiar with the adaptive mechanism — going past question 100 without panicking, for example. It is in that spirit that Cybridia combines an adaptive mode modelled on the CAT with 8 timed practice exams: to work on the format and on how you read questions, not to produce a predictive percentage.
One limitation is flagged by the creator of the community simulator: "I can't remove questions you've seen in a CAT exam, as that would be the complete opposite of how a CAT engine should work." Some repetition is therefore unavoidable in adaptive practice.
What score do you get at the end of the exam?
None, if you pass. The paper document handed to you on the way out of the Pearson VUE test centre — the sequence is described in exam day at the Pearson VUE test centre — states a provisional status, with no figure:
"I didn't get any results just that I passed no in-depth breakdown"
If you fail, the report does provide a per-domain standing, on three levels:
| Item in the report | Pass | Fail |
|---|---|---|
| Numerical score | not given | not given |
| Per-domain standing | no | yes (Above / Near / Below Proficiency) |
| Number of questions and time remaining | not documented | shown on the document |
An example line from a report: "150 Questions — Result: 3 Above, 2 Near, 3 Below — Time Left: 5 minutes". Another useful point: you can be below the threshold in some domains and still pass — "on real exam you can 'fail' some domains and pass. [...] Every domain will be tested, just not sure what the 'minimum' is." That minimum is not public: check with ISC2.
The "provisionally passed" status is only confirmed once ISC2 has approved your endorsement application: reported timings are detailed in how long CISSP endorsement takes.
What happens if time runs out before the end?
Two opposite outcomes are documented, which rules out any simple rule.
On one side, a comment sets out the logic you would expect from IRT scoring:
"Running out of time is not detriment, unless you ability estimate is below 700."
One concrete case points that way: a candidate reports that "the system timed me out at question 149 [...] But this time, I passed."
On the other, timeout remains a documented cause of failure: "Last month I ran out of time and failed." In other words, being stopped by the clock does not destroy an ability estimate already established above the threshold, but it does not rescue one below it either. Time management therefore remains a real issue, covered in time management on the CISSP exam.
One final warning, which follows from everything above: treat no score threshold as a guarantee. Neither 700 as a target you can compute during the exam, nor a practice percentage as a ticket in. The only verdict is the sheet handed to you on the way out — and most candidates receive it convinced they have failed, an experience documented in the feeling of failing during the CISSP exam. What the stopping point means is covered in exam stopped at 100 questions: pass or fail?; for the full mechanics of the format, see the CAT format, 100 to 150 questions.
Frequently asked questions
Do you need 70% correct answers to pass the CISSP?
No. The 700/1000 threshold is an ability estimate weighted by question difficulty, not a percentage: one question may be worth 90 points and another 4.
What percentage should you aim for on practice exams?
There is no reliable threshold: the widely quoted 85% benchmark is explicitly disputed by the community, and no practice score guarantees a pass.
Do you receive your CISSP score?
Not if you pass: the report only states a provisional status, with no figure. If you fail, it gives a per-domain standing (Above, Near, Below Proficiency).
Can you fail a domain and still pass the exam?
Yes: you can 'fail' some domains and still pass. The minimum threshold per domain is not public, and should be checked with ISC2.
What happens if time runs out before the last question?
Running out of time is not damaging in itself if your ability estimate is already above 700: one candidate stopped by the clock at question 149 passed. Others have failed on timeout.
Where does this information come from?
This article draws on the public reports of several thousand candidates, published over the last three years (24 July 2023 to 24 July 2026) and synthesised topic by topic. Quoted extracts are anonymised. Our method in detail.
- The CAT format of the CISSP exam, explained question by questionThe CISSP is a computerized adaptive test: 100 to 150 questions in 3 hours since April 2024, beta questions, variable stopping point, result on paper.
- The exam stopped at 100 questions: what does that mean?Stopping at 100 questions on the CISSP means the algorithm has reached a verdict, either way. What candidate reports actually say.
- Handling the 3 hours of the CISSP exam: the pace to hold3 hours for 100 to 150 questions on the CISSP: pace yourself for 150, not 100. Documented timing benchmarks, timeout risk and breaks.