CQSP logo
Focused certification exam prep
Start practice

CQSP Exam Format: Questions, Time Limit, and Scoring

TL;DR
  • The CQSP exam is 50 multiple-choice questions completed in exactly 60 minutes, administered through the SISA Institute exam platform.
  • A passing score of 66% means you need to answer at least 33 of the 50 questions correctly.
  • The exam spans six named domains covering quantum computing fundamentals through practical migration strategy.
  • SISA has not publicly disclosed domain percentage weights, so all six areas must be treated as equally important during preparation.

The CQSP Exam at a Glance

The Certified Quantum Security Professional (CQSP) is an ANAB-accredited credential issued by the SISA Institute, designed for security practitioners who need a defensible, structured understanding of quantum threats and the countermeasures being standardized right now. Unlike broader certifications that treat quantum security as a footnote, the CQSP blueprint is built exclusively around that subject matter - from the physics of quantum key distribution to the NIST post-quantum cryptography standards finalized in 2024.

Before diving into domain specifics, here is the complete structural picture of the exam:

Attribute Detail
Governing Body SISA Institute
Accreditation ANAB-accredited certification scope
Number of Questions 50
Time Limit 60 minutes (1 hour)
Question Format Multiple choice
Passing Score 66%
Testing Platform SISA Institute exam platform
Prerequisites 1 year infosec experience + cryptography basics, or 16-hour CQSP workshop, or equivalent 16-hour training
Domain Weights Not publicly disclosed
Exam Fee Not publicly disclosed; contact SISA directly

Understanding these mechanics upfront shapes every decision you make about preparation - how you allocate study hours, which topics you prioritize, and how you pace yourself on exam day.

Question Format and What It Really Tests

All 50 items are standard multiple-choice questions. That format might sound straightforward, but the subject matter ensures the questions are anything but simple. Quantum security occupies an unusual intellectual space: it requires you to understand both the theoretical underpinnings of quantum mechanics and the very practical, governance-oriented decisions that enterprise security teams must make today.

Expect questions that operate at several cognitive levels simultaneously:

  • Recall: Defining terms like quantum superposition, entanglement, or lattice-based cryptography.
  • Comprehension: Explaining why RSA and ECC are vulnerable to Shor's algorithm but symmetric AES-256 is considered relatively quantum-resistant at sufficient key lengths.
  • Application: Selecting the appropriate NIST-standardized post-quantum algorithm for a given use case - digital signatures versus key encapsulation.
  • Analysis: Evaluating a migration timeline scenario and identifying which legacy systems represent the highest-priority cryptographic risk.
Format Insight: Because the CQSP uses standard four-option multiple choice across a highly technical domain, distractor answers are frequently designed to exploit common misconceptions - for example, confusing quantum cryptography (physics-based, e.g., QKD) with post-quantum cryptography (mathematics-based, classical hardware). Knowing the precise definitions in the SISA blueprint is not optional.

The multiple-choice format also means there is no penalty for guessing on items you are uncertain about. With 50 questions and a 66% threshold, you cannot afford to leave any answer blank. If you have narrowed a question to two plausible options, committing to one is always the right move.

The 60-Minute Clock: What It Means in Practice

One hour for 50 questions gives you an average of 72 seconds per question. That is a tighter pace than many security certification exams. Candidates who have not specifically practiced timed multiple-choice under quantum security topics frequently report that the time constraint - not the difficulty of individual questions - is the primary source of pressure on exam day.

The practical implication: you cannot afford to spend three or four minutes deliberating on a single question. A reasonable time management approach is to move through questions at approximately 60-70 seconds each on your first pass, flagging anything that requires extended thought, then returning to flagged items in the remaining time. With 50 questions, even flagging 10 items still leaves you roughly 25 minutes of buffer on a disciplined pass.

Key Takeaway

Practice under timed conditions from the very beginning of your preparation. Answering CQSP-style questions accurately but slowly is a different skill from answering them accurately within the 72-second-per-question pace the exam demands. CQSP practice tests on this platform include timed modes specifically designed to simulate exam conditions.

The 60-minute window also means that deep, multi-part scenario questions - if they appear - consume a disproportionate share of your time budget. Prioritize questions you can answer confidently and quickly; bank that time for the harder items.

The 66% Passing Score Explained

A passing score of 66% on a 50-question exam translates to a raw minimum of 33 correct answers. That also means you can answer up to 17 questions incorrectly and still pass - but 18 incorrect answers means failure. There is very little margin for large gaps in any single domain.

SISA has not published domain weighting percentages, which matters here. If weights were published and one domain carried, say, only 10% of the exam, you could strategically de-prioritize it. Without disclosed weights, treating any domain as negligible is a risk you cannot responsibly take. A significant weakness in Quantum-Safe Migration Strategy or Practical Implementation - domains that feel more "applied" and might seem easier to skip - could be the difference between 33 and 32 correct answers.

Score Calculation: SISA's public materials do not describe a scaled scoring model for the CQSP; the passing threshold is stated as 66%. That percentage applied directly to 50 questions yields 33 as the minimum passing raw score. Plan your preparation with that concrete number in view.

It is also worth noting that the ANAB accreditation of the CQSP certification scope signals that the exam construction follows recognized standards for professional certification - meaning question quality, item validity, and the passing standard itself are subject to external oversight. That context should give candidates confidence that the 66% threshold reflects a genuine competency benchmark, not an arbitrary cutoff.

Inside the Six Exam Domains

The CQSP blueprint organizes its content across six distinct knowledge domains. SISA has listed these domains in official public materials but has not published the percentage of exam questions allocated to each. That means your preparation must treat all six seriously. Here is what each domain title signals about its content scope:

Domain 1: Foundation of Quantum Computing and Cryptography

The conceptual bedrock of the entire certification. This domain ensures candidates understand what makes quantum computing fundamentally different from classical computing - and why that difference breaks current cryptographic assumptions.

  • Quantum bits (qubits), superposition, and entanglement
  • Quantum gates and circuit models
  • How Shor's algorithm threatens RSA, DSA, and ECC
  • How Grover's algorithm affects symmetric key security
  • Classical cryptography primitives and their quantum-era vulnerabilities

Domain 2: Quantum Cryptography and Key Distribution

This domain covers cryptographic techniques that use quantum mechanical properties - most prominently Quantum Key Distribution (QKD). Candidates must understand both the theoretical guarantees and the real-world limitations of these approaches.

  • BB84 and other QKD protocols
  • Quantum random number generation (QRNG)
  • Physical constraints on QKD deployment (distance, fiber, trusted nodes)
  • Distinctions between QKD and post-quantum cryptography

Domain 3: Quantum Threats, Risk, and Mitigation

A risk-management-oriented domain that connects quantum computing capabilities to enterprise security posture. Expect questions that require you to reason about threat timelines and prioritization frameworks.

  • "Harvest now, decrypt later" attack vectors
  • Cryptographically relevant quantum computer (CRQC) timelines
  • Asset classification by cryptographic sensitivity
  • Risk frameworks applied to quantum threat scenarios

Domain 4: Post-Quantum Cryptographic Standards and Guidelines

This is the standards-heavy domain. The NIST post-quantum cryptography standardization process concluded with FIPS 203, 204, and 205 in 2024. Candidates must know what was standardized, why, and what guidance bodies like NIST, ETSI, and ENISA have published.

  • CRYSTALS-Kyber (ML-KEM / FIPS 203) for key encapsulation
  • CRYSTALS-Dilithium (ML-DSA / FIPS 204) and SPHINCS+ (SLH-DSA / FIPS 205) for signatures
  • NIST IR 8413 and migration guidance documents
  • Algorithm selection criteria: security level, performance, implementation maturity

Domain 5: Quantum-Safe Migration Strategy

The operational and strategic domain. This shifts focus from "what is quantum-safe?" to "how does an organization actually get there?" Expect scenario-based questions about migration planning, hybrid approaches, and stakeholder communication.

  • Cryptographic inventory and agility principles
  • Hybrid classical/post-quantum transitional architectures
  • Prioritizing migration of long-lived data and critical infrastructure
  • Organizational governance and executive communication for quantum risk

Domain 6: Practical Implementation of Quantum Security

The applied capstone domain. Candidates must demonstrate that they can translate standards and strategy into real implementation decisions - the kind of technical judgment that employers hire CQSP-certified professionals to exercise.

  • Integrating post-quantum algorithms into TLS, PKI, and code-signing workflows
  • Performance and interoperability considerations for PQC deployment
  • Secure hardware and key management in a post-quantum context
  • Testing and validation approaches for PQC implementations

What Each Domain Actually Demands

Understanding the domain titles is one thing; knowing the depth of preparation each demands is another. Domains 1 and 2 are the most conceptually dense - they require you to internalize genuinely unfamiliar physics and mathematics if your background is primarily in classical security. Candidates who rush through these foundational areas frequently find that Domains 3 through 6 make less sense because the underlying threat model is not fully internalized.

Domains 4 and 5 are the most rapidly evolving. The NIST PQC standardization concluded in 2024, and guidance from CISA, NSA, NIST, and allied bodies continues to be updated. Your preparation materials must reflect the current SISA CQSP outline - older resources predating the FIPS 203/204/205 finalization may reference algorithm candidates that were not ultimately standardized.

Domain 6 rewards candidates who have practical exposure to cryptographic implementation - PKI administrators, application security engineers, and cryptographic architects will find this domain more intuitive than those approaching purely from a policy background.

Before sitting the exam, confirm that your eligibility meets the SISA requirements. The full details, including how prior training counts toward the prerequisite, are covered in our article on CQSP Prerequisites and Eligibility Requirements 2026.

Registration and the SISA Exam Platform

The CQSP exam is administered through SISA Institute's own exam platform. SISA has not publicly disclosed the use of a third-party proctoring or testing center network, so candidates should contact SISA directly to confirm current delivery modality - whether remote proctored, in-person at a SISA facility, or through a partner channel.

The exam fee is also not publicly listed on SISA's marketing materials at time of writing. Pricing may vary based on geography, organizational purchase, or bundling with the 16-hour CQSP workshop. If you are pursuing the certification independently, contact SISA directly for the current individual registration rate.

The 16-hour workshop pathway is notable: it simultaneously satisfies the prerequisite and provides structured instruction aligned to the exam blueprint. Candidates who take this route essentially complete their eligibility and their formal instruction in a single engagement, then need only supplementary self-study and practice testing before sitting the exam.

Prerequisite Pathways: There are three routes to eligibility - one year of information security experience combined with cryptography basics; completion of the official 16-hour CQSP workshop; or equivalent 16-hour training that covers the CQSP blueprint. The equivalency path requires that your prior training genuinely maps to the six-domain structure, not just security training in general. Review the details in our CQSP Prerequisites and Eligibility Requirements 2026 guide before registering.

A Domain-Anchored Preparation Schedule

Given the 60-minute, 50-question format, preparation for the CQSP rewards depth over breadth. The following schedule assumes approximately 6-8 weeks of part-time study (roughly 8-10 hours per week) for a candidate who meets the experience prerequisite but does not have deep familiarity with quantum computing concepts. Adjust aggressively if your background is stronger in specific areas.

Weeks 1-2

Domain 1 & 2: Build the Quantum Foundation

  • Master qubit mechanics, superposition, entanglement, and the quantum circuit model
  • Understand Shor's and Grover's algorithms at a conceptual level - you do not need to implement them, but you must explain their security implications
  • Study QKD protocols (BB84 in detail), QRNG, and the physical limitations of quantum cryptography deployment
  • Take baseline timed CQSP practice tests to identify your starting knowledge gaps
Weeks 3-4

Domain 3 & 4: Threats, Standards, and the NIST Output

  • Deep-dive "harvest now, decrypt later" scenarios and the CRQC timeline debate
  • Memorize the finalized NIST PQC standards: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA)
  • Study NIST migration guidance and CISA quantum readiness advisories
  • Use spaced repetition specifically for algorithm names, standard numbers, and their intended use cases - this is rote-heavy content where that technique delivers real value
Weeks 5-6

Domain 5 & 6: Strategy, Migration, and Implementation

  • Work through cryptographic inventory and agility frameworks - understand what "crypto-agility" means operationally, not just definitionally
  • Study hybrid classical/PQC architecture patterns and their transition logic
  • Review PQC integration points in TLS 1.3, PKI hierarchies, and code-signing workflows
  • Run full-length timed practice exams and analyze every incorrect answer at the domain level
Weeks 7-8

Full Exam Simulation and Weak Domain Remediation

  • Take at least three full 50-question timed practice exams under realistic conditions
  • Identify which domains show the lowest accuracy and allocate targeted review hours accordingly
  • Review the CQSP exam format details - CQSP Exam Format: Questions, Time Limit, and Scoring - to confirm you understand the scoring threshold and time management strategy going in
  • Final day: light review only; avoid cramming new material in the 24 hours before the exam

Candidates with a strong cryptographic engineering background can likely compress Weeks 1-2 significantly. Candidates from a governance or audit background should expand those foundational weeks rather than rush them.

Frequently Asked Questions

How many questions do I need to get right to pass the CQSP exam?

The CQSP passing score is 66% on a 50-question exam. That means you need a minimum of 33 correct answers. You can miss up to 17 questions and still pass, but 18 or more incorrect answers results in a failing score. There is no published partial credit or scaled scoring mechanism - the 66% threshold applies directly to the raw question count.

Are the six CQSP domains equally weighted on the exam?

SISA Institute has not publicly disclosed the percentage of exam questions allocated to each of the six domains. Because no weighting information is available, the safest preparation strategy is to treat all six domains as equally important and avoid de-prioritizing any area. A significant weakness in any single domain could cost you the exam.

Can I take the CQSP exam without completing the 16-hour workshop?

Yes. The workshop is one of three eligibility pathways, not a mandatory prerequisite. Candidates who have at least one year of information security experience combined with cryptography basics, or who have completed equivalent 16-hour training covering the CQSP blueprint from another source, are also eligible. See the full breakdown in our CQSP Prerequisites and Eligibility Requirements 2026 article.

How much time does each question allow on the CQSP exam?

The exam provides 60 minutes for 50 questions, which works out to an average of 72 seconds per question. This is a relatively tight pace for technically complex content. Practicing timed exams before your test date - not just reviewing content - is essential to arriving at the exam comfortable with that time pressure.

Where can I practice CQSP exam questions that reflect the actual format?

The CQSP Exam Prep practice test platform offers questions aligned to all six CQSP domains in the same multiple-choice format as the real exam, with timed modes that simulate the 60-minute constraint. Practicing on domain-specific question sets lets you identify weak areas before they cost you points on exam day.

Ready to Start Practicing?

The CQSP exam is 50 questions in 60 minutes with a 66% passing threshold - and every domain counts. Build the timed exam confidence you need with practice questions mapped to all six CQSP domains, from Quantum Computing Foundations through Practical Implementation.

Start Free Practice Test

Ready to pass your CQSP exam?

Put this into practice with free CQSP questions across every exam domain.