Short answer: after sitting through their boot camp myself — and after reading years of the same complaints on Reddit, Trustpilot, PissedConsumer and even Glassdoor — I don’t think Infosec Institute’s CISSP boot camp is worth the money in 2026. This page pulls those reviews together in one place, with links to every source, so you can decide for yourself before you hand over a few thousand dollars.

My verdict: 2 / 5 — overpriced, and shakier since the Cengage buyout
What people report liking

  • Instructors who know the material (when you get a good one)
  • Recognizable brand name
  • An “exam pass guarantee” — on paper
What keeps coming up

  • Outdated, error-filled courseware
  • A “pass guarantee” that’s hard to actually collect
  • Rude, unresponsive customer service
  • Pass-rate claims nobody can verify

Is Infosec Institute worth it?

In my experience, no — not at boot-camp prices. I paid for the intensive experience their site advertises and got something that felt thrown together: practice questions that didn’t match the real exam, explanations that were missing, and a room full of people who all felt the same unease I did. Plenty of former customers describe the exact same thing. If your employer is paying and you go in with low expectations, you may get value from a strong instructor. If it’s your own money, I think you can do better for less.

Is Infosec Institute a scam, or just overpriced?

Let me be precise, because the word matters. Infosec Institute is a real, established training company — now owned by Cengage — not an illegal operation. So in the strict sense, it isn’t a “scam.” But a lot of people feel scammed, and the reason is the gap between the marketing and the delivery. When a company advertises a “93% pass rate,” “hands-on labs,” and “the most-awarded” training, and customers repeatedly report the opposite, that gap is where the anger comes from. My own take: it’s an overpriced product propped up by claims it doesn’t consistently live up to.

Is the 94% pass-rate claim believable?

This is the one that bothers me most. I’ve seen Infosec’s marketing quote a 93%, a 94%, and a 95% pass rate at different times — and a number that keeps changing isn’t a measured statistic, it’s a marketing dial. No one ever shows the methodology behind it.

Meanwhile, the lived reports run the other way. One boot-camp attendee documented that every single person in his class failed the first exam and that the advertised pass rate simply never materialized. A CISSP subreddit user wrote that they took the boot camp and failed the exam twice despite the “95% pass rate” promise, and concluded you’re better off studying on your own. When the only data points you can actually verify all point down, I don’t buy the headline number.

How Infosec’s “Exam Pass Guarantee” actually works

The guarantee sounds great until you try to use it. Here is how one reader described the process after it was emailed to me:

“I was promised a free exam voucher and retake, but Infosec made it nearly impossible to use. They refused to give me the voucher until I scored 90% or higher on their practice test. Once I finally hit that score, they took about 30 days to send the voucher, which left me with barely any time before their 90-day deadline to take the real exam. Because of the delay, I missed the window for the ‘free retake’ they advertised.”

— reader report, forwarded from r/CISSP

Read that sequence again: you have to clear a 90% gate, then wait ~30 days for the voucher, all inside a 90-day clock. The structure makes the “guarantee” hard to ever collect. That’s not a guarantee — it’s an obstacle course.

What real customers say (with sources)

These aren’t my words — they’re public reviews other people posted, linked to the originals so you can verify them.

“Called INFOSEC to assist a team member in getting their promised exam voucher. The customer service rep was rude, dismissive, and even insulting. When I asked to speak with a manager, they abruptly disconnected the call.”

— Trustpilot review, date of experience July 10, 2025. Read on Trustpilot

“I took their bootcamp. Despite the 3-month limit and 95% pass rate advertisement, I failed the exam TWICE. You are better off to study the exam yourself with other books. Cheaper to study yourself.”

— r/CISSP commenter. Read on Reddit

“Dated, cheesy graphics, poor sound quality… monotonous videos. I felt ripped off.” (On their security-awareness training.)

— PissedConsumer review. Read on PissedConsumer

“Avoid Infosec Marketing. It’s a sinking ship.” The reviewer counted ten marketing leaders at director level or above leaving after the buyout, with HR and IT outsourced.

— 2024 Glassdoor employee review. Read on Glassdoor

More reports: outdated, error-filled courseware

Beyond the headline complaints, the most common theme in reviews is that the training materials feel stale and sloppy for the price:

“The instructor may have known the material, but the courseware itself felt stale and behind. Some examples, references, and sections did not feel current. When someone is paying for professional certification prep, updated course materials should not be optional.”

— r/CISSP

“The materials were filled with spelling errors, which immediately hurt its credibility. The instructor also sounded like he was half asleep, making the delivery dull and difficult to follow.”

— r/CISSP

“The worst training course I’ve ever taken. The PowerPoint slides have SO many spelling errors and some of the audio doesn’t even match up with the slides. Some slides are out of focus, and some are cut off so you can’t see everything.”

— verified customer, eight years of IT training for comparison

What changed after the Cengage acquisition

Cengage Group completed its $191 million acquisition of Infosec Institute in March 2022, folding it into the company’s Workforce Skills division alongside ed2go. From the outside, it looks like the new owner has been steadily hollowing the place out since — the Glassdoor review above describes heavy leadership churn and outsourced departments. That’s the same company asking you to trust it with your certification prep. If the people behind the product keep leaving, it’s fair to ask what happens to the product.

Better ways to prepare for the CISSP

Here’s the constructive part, because trashing one company isn’t the point — passing is. What actually worked for me was a domain-by-domain study plan paired with scenario-based practice questions, not a pricey boot camp. Two practice-question tools I’d recommend over Infosec’s:

  • Boson CISSP — well-crafted questions with explanations that tell you why each wrong answer is wrong.
  • Quantum Exams — hard, scenario-based questions that train you to think like a security manager.

And before you pay anyone, verify their ISC2 partnership yourself at isc2.org — don’t take the marketing’s word for it. More of what worked for me is on my better choices page.

Frequently asked questions

Who owns Infosec Institute now?

Cengage Group, a large education-technology company, owns Infosec Institute. Cengage completed the $191 million acquisition in March 2022 and folded Infosec into its Workforce Skills division alongside ed2go.

Is Infosec Institute legit or a scam?

It’s a real, established company, not an illegal scam. The problem most customers describe is the gap between what’s advertised — high pass rates, hands-on labs, an exam-pass guarantee — and what actually gets delivered.

Does Infosec Institute really have a 94% pass rate?

There’s no published methodology behind it, and Infosec has advertised 93%, 94%, and 95% at different times. Multiple boot-camp attendees report failing, including one who says his entire class failed the first exam. I don’t consider the figure verifiable.

How does Infosec’s exam pass guarantee work?

Readers report you must score 90%+ on their practice test before they release the exam voucher, then wait roughly 30 days for it — all inside a 90-day deadline, which can make the “free retake” nearly impossible to actually use.

What should I use to study for the CISSP instead?

A domain-by-domain plan plus scenario-based practice questions did more for me than any boot camp. I’d point you to Boson and Quantum Exams for questions, and always confirm any provider’s ISC2 partnership directly at isc2.org.

About the author

Terry is the person behind Infosec Institute Sucks. He earned his CISSP and has spent years working in cybersecurity. After a boot-camp experience that didn’t come close to what the marketing promised, he started documenting his own story and collecting other people’s reviews — with sources — so future candidates can make an informed choice instead of an expensive mistake. He still studies the CISSP material and shares what actually worked. More about Terry →

This article reflects my personal experience and opinions, together with publicly posted reviews written by other people, each linked to its original source. “Infosec Institute,” “Cengage,” and other names are trademarks of their respective owners; this is an independent consumer-opinion site and is not affiliated with them.

Sources