ISC2 Certified in Cybersecurity Master Guide 2026
ISC2 Certified in Cybersecurity is an entry-level credential for foundational security knowledge.
- Its current outline took effect September 1, 2026 and covers principles, governance, IAM, network and cloud security, and security operations and incident response.
- No work experience is required.
- The CAT exam presents 100 to 125 items in two hours; 700 on a 1,000-point scale passes.
On this page17 sections
- What the CC credential demonstrates
- Exam format and score
- Security Principles: 24 percent
- Security Governance: 17.3 percent
- Identity and Access Management Concepts: 20 percent
- Networking and Cloud Security Concepts: 21.3 percent
- Security Operations and Incident Response: 17.3 percent
- Eligibility, current pricing and post-exam steps
- A practical study plan
- Work through a mixed-domain CC scenario
- Choose the next study action from your errors
- Who benefits from CC
- Results, retakes and timing implications
- Candidate status, certification and maintenance are different
- How to choose useful preparation
- Apply the current outline to everyday security decisions
- Choose study time by gap and domain weight
What the CC credential demonstrates
ISC2 Certified in Cybersecurity, commonly shortened to CC, is an entry-level credential for people beginning to learn cybersecurity and for professionals who need a structured foundation. It assesses core concepts and judgment across security principles, governance, identity and access, networking and cloud security, and security operations including incident response. Passing shows that a candidate met the exam standard. It does not establish years of security experience, independent engineering skill, or the ability to lead an incident response.
The current exam outline became effective September 1, 2026. It is the first major content refresh since the credential launched. The structure includes a dedicated Security Governance domain and updated coverage of identity, network and cloud security, threat intelligence, operations and incident response. Foundational AI security concepts are integrated throughout. Earlier materials may still explain enduring concepts, but their outline structure and weights do not describe the current exam.
| Current domain | Weight |
|---|---|
| 1. Security Principles | 24% |
| 2. Security Governance | 17.3% |
| 3. Identity and Access Management Concepts | 20% |
| 4. Networking and Cloud Security Concepts | 21.3% |
| 5. Security Operations and Incident Response | 17.3% |
Exam format and score
The CC exam uses Computerized Adaptive Testing at Pearson testing centers. It presents 100 to 125 variable-length items and allows two hours. Item formats include multiple choice and advanced item types. The passing grade is 700 out of 1,000 scaled points. English, Chinese, Japanese, German and Spanish are listed languages, with Chinese appointments restricted to particular annual windows. Appointment availability depends on the candidate’s location and language.
CAT selects items during the session based on the testing process, and a candidate answers items in the order presented. You cannot skip a question and return later. Do not infer your result from the number of questions, apparent difficulty of the last item, or your own feeling after the session. A CAT session can stop at different item counts. Use a steady approach: identify the concept being tested, eliminate choices that conflict with the principle, and make the best supported selection.
Security Principles: 24 percent
This domain covers confidentiality, integrity, availability, authentication, authorization, accounting, privacy and non-repudiation, along with risk management, governance, controls and professional conduct. Know what security controls are for and how technical, administrative and physical measures can complement one another. A written policy expresses organizational direction; a procedure explains steps; a standard defines a mandatory requirement. The details in a scenario often identify which kind of measure is needed.
Suppose a payroll spreadsheet is accessible to every employee. Encryption at rest can protect a device if it is lost, but does not correct broad access by authorized accounts. Least privilege and an access review address who may read the file. If the scenario instead concerns a lost, encrypted laptop, encryption is more directly relevant. Ask what security property is threatened and at what layer before choosing a control.
Security Governance: 17.3 percent
Governance aligns security choices with organizational objectives, risk tolerance, laws, assigned responsibilities and oversight. The domain includes governance, risk and compliance, redundancy, business continuity, disaster recovery and awareness. Business continuity plans keep essential functions operating through disruption. Disaster recovery plans restore technology and data. Backups are one recovery resource, not proof that a plan works; restoration should be tested against recovery priorities.
A company may require annual phishing awareness training, a written incident escalation path, and executive approval for risk acceptance. Each mechanism has a different purpose: awareness helps people recognize threats, escalation assigns action, and risk acceptance records an authorized decision. Redundant systems can improve resilience but do not replace recovery planning. Security governance defines who makes decisions and how risk is monitored.
Identity and Access Management Concepts: 20 percent
Distinguish identification, authentication, authorization and accounting. A user identifies an account, proves the claim through authentication, receives permissions through authorization, and leaves activity records through accounting. Multifactor authentication uses factors from different categories, such as something known and something possessed. Two passwords are two instances of one factor category, not two-factor authentication.
Least privilege grants only the access needed for assigned work. Separation of duties prevents a single person from controlling every stage of a sensitive process. For example, one employee can prepare a payment while another approves it. Role-based access groups permissions by work function; an access review checks whether each person still needs the assigned access. The exam asks what risk a control reduces, not how to configure a particular product.
Networking and Cloud Security Concepts: 21.3 percent
This domain includes networking basics, segmentation, secure communications, cloud concepts and shared responsibility. Firewalls apply traffic rules, network segmentation limits paths between systems, and encryption protects information in transit. Cloud customers and providers divide work according to service model, but customers remain accountable for data, identity decisions and service settings they control. Provider data-center protection does not determine customer access permissions.
A business places public web servers and a sensitive database in separate network segments, then permits only required application traffic to reach the database. Segmentation reduces the paths available to an attacker. If a question asks who patches the guest operating system on a customer-managed cloud virtual machine, the customer owns that task. If it asks who protects the provider’s physical facility, that responsibility belongs to the cloud provider.
AI-related fundamentals appear across the outline. Candidates should recognize that AI systems and training data need governance, access protection, validation and risk review. Automated tools can also help an attacker scale phishing or analyze stolen information. Foundational questions focus on security implications and responsible practice rather than building a machine-learning model.
Security Operations and Incident Response: 17.3 percent
Operations includes monitoring, threat intelligence, response, evidence and recovery. A response plan typically prepares the organization, identifies and analyzes an incident, contains harm, eradicates the cause, recovers service and captures lessons. Follow the organization’s plan and authority structure. A responder should preserve relevant evidence and document actions; immediately wiping a potentially compromised device may destroy useful evidence.
Threat intelligence can help prioritize detections, but information must be assessed for credibility and relevance. Logs can show system or account activity, but access to evidence should be restricted and documented. If an employee receives a convincing urgent request to change a payment destination, verify it through a known channel rather than trusting the message. AI-enhanced phishing makes independent verification and reporting especially important.
Eligibility, current pricing and post-exam steps
There is no work experience prerequisite for taking or earning CC. ISC2 designed the credential for newcomers, and a degree or prior IT job is not required. ISC2 exam candidates must be at least 16 and follow account, identity and testing rules. The current standard registration price is US $199 for the Americas and Asia Pacific regions listed in the pricing table; other regions may show local currency and location-based tax.
The One Million Certified in Cybersecurity program has closed new enrollments after reaching its goal. Existing eligible participants with an unexpired exam code may still schedule and sit through December 31, 2026 under program terms. This is not an open-ended free offer for new candidates. New candidates should distinguish the former pledge from currently purchasable exam or training options.
After passing, the candidate agrees to the ISC2 Code of Ethics and submits a CC certification application within nine months. The first US $50 Annual Maintenance Fee is also required for the credential to be issued. CC does not require an experience endorsement or documented work-history review. Once certified, holders maintain CC with 45 CPE credits per three-year cycle and a US $50 annual maintenance fee; ISC2 recommends 15 CPE credits each year.
A practical study plan
Use the September 2026 exam outline as the map. For each task, label your knowledge solid, uncertain or new. Learn definitions in context: confidentiality prevents unauthorized disclosure; integrity protects correctness; availability supports timely access. Then apply each concept to a small workplace scenario. Ask what the risk is, who owns the decision, and whether a proposed measure prevents, detects or corrects the problem.
- Review all five domains and mark the subtopics you cannot explain without notes.
- Study paired terms such as authentication and authorization, policy and procedure, business continuity and disaster recovery.
- Practice original scenario questions and explain why each distractor is less suitable.
- Allocate review time using both domain weight and your own weak areas; return to every domain before the exam.
- Complete timed practice one item at a time, since the CAT does not allow skipping and returning.
An effective study loop is read, explain, apply, check. Read a concept from outline-aligned material, explain it in your own words, apply it to a fresh example, and then check the reasoning. If you remember an answer but cannot say why it protects a particular objective, you have recognition rather than transferable understanding. Use an error log to track the clue that should have changed your answer.
Work through a mixed-domain CC scenario
A finance employee reports that a shared cloud folder now contains payroll files, and the security team sees a sign-in from an unfamiliar location. Treat this as a short investigation, not an invitation to guess that the account was breached. The identity clue points to account protection and access review. The payroll data points to confidentiality and privacy. The cloud location points to customer configuration and logging. Start by following the organization’s incident reporting process, preserve relevant sign-in and file-access records, and ask the authorized response team to assess the account. Do not delete the files or reset every system without direction, because an uncoordinated response can remove evidence or interrupt legitimate work.
A staff member receives a message that appears to come from a manager, asking for immediate access to a confidential folder. The request is outside the staff member’s normal process. What is the best first action?
- Grant access, then ask the manager to confirm later.
- Verify the request through a known, separate communication channel and follow the access approval process.
- Send the folder to the manager’s personal email address.
- Disable the entire file service before investigating.
The lesson is to identify the objective and the decision owner before choosing a control. A CC question may mention a familiar technology, but the best answer often addresses the immediate risk with an authorized, proportionate step. Use this sequence in practice: name the asset, state the threatened security property, identify the responsible role, then choose prevention, detection or response based on the facts given.
Choose the next study action from your errors
After a practice set, do not record only the percentage. For each miss, write down the clue you overlooked and the concept that would have changed your choice. If you selected encryption when the problem was excessive access, review confidentiality controls and authorization. If you chose recovery before containment, revisit incident response and the order of actions. If two options both seem reasonable, explain which one fits the role and facts in the question more closely.
A learner with help-desk experience may already recognize account provisioning, password resets and service tickets. That background helps with IAM and operations, but it can also encourage a tool-first answer when a question is testing policy, risk acceptance or approval authority. A candidate new to IT may know governance language from school or business work, yet need more practice with network segmentation, cloud service models and the difference between a provider control and a customer setting. Use your errors to choose the next topic instead of spending equal time on every chapter.
In the final review, explain one concept aloud without notes, then apply it to a new setting. For example, describe how separation of duties reduces the risk of a single person creating and approving a payment, then consider an access request or a production change. If you can transfer the principle, move on. If you can repeat a definition but cannot select a proportionate action, practice another scenario before rereading the same paragraph.
Who benefits from CC
CC can give a student, career changer, help-desk employee or business professional a structured vocabulary for security conversations. It can support a transition into further study, but it does not guarantee a job, promotion or salary and does not replace applied experience. A candidate pursuing a technical role should combine foundational study with practical work in controlled environments and evidence of the skills required by that role.
If your preparation started under the earlier outline, compare it with the effective September 1, 2026 version. Pay particular attention to the separate governance domain, the current IAM and networking/cloud terminology, and the organization of operations and incident response. Older materials may explain valid basics while still misrepresenting current weights or structure.
Results, retakes and timing implications
Many candidates receive a provisional result at the test center, followed by an email from ISC2 after Pearson transmits the record. A passing candidate then completes the CC application and pays the first AMF. Candidates who do not pass receive proficiency feedback by domain rather than a detailed numeric score. Use that feedback to target study, but also review how you reasoned through scenarios; a weak domain label alone does not identify every misconception.
ISC2 allows up to four attempts in a 12-month period for each certification program. The wait between attempts increases: after the first attempt, wait 30 test-free days; after the second, 60 test-free days; after the third and later attempts, 90 test-free days. Each ordinary attempt requires another exam fee unless a purchased package explicitly includes a second attempt. A candidate should account for these waiting periods when buying a voucher near an expiration date.
Candidate status, certification and maintenance are different
An ISC2 Candidate is a pre-certification status and is not the CC credential. The One Million pledge once provided a route to training and a free exam, but ISC2 has closed new enrollment. A valid existing code is governed by its own expiration and the December 31, 2026 final testing deadline. After passing, the application, Code of Ethics agreement and first US $50 AMF complete the award process. Once certified, the holder maintains the credential through 45 CPE credits per three-year cycle and an annual US $50 AMF.
A person whose first-year Candidate dues were paid may find that the same US $50 covers the CC AMF for that year under ISC2’s terms. That does not mean future certification maintenance is free: the recurring AMF is due annually, and the CPE cycle still applies. Keep a record of the account’s due date and any payment so you can resolve a discrepancy before a certification status changes.
How to choose useful preparation
Start from the current outline rather than a vendor’s broad cybersecurity course description. A resource should cover the 2026 domain structure and emphasize beginner-level understanding of security concepts, governance, IAM, cloud and networking, and operations. A course that focuses entirely on technical labs may leave gaps in professional ethics, risk governance and continuity. A glossary helps with vocabulary, while scenario practice tests whether you can apply it.
For example, a learner who recognizes the phrase least privilege should also be able to decide which of two proposed permissions is excessive. Someone who memorized incident response stages should be able to explain why evidence is preserved before a system is rebuilt. Study tools should prompt that reasoning. Use original practice questions and official outline statements; avoid dumps that claim to reproduce protected live exam items.
If your previous study used the earlier CC outline, make a mapping list: old topic, new domain, what remains valid, and what needs fresh study. Do not assume an old prep book becomes useless, but do not use its old percentage weights or domain labels as current. The new outline reorganizes content, and current appointments are based on the September 2026 version.
Apply the current outline to everyday security decisions
Use a specific clue to choose a control. If a former employee still has access to a file share, the issue is identity lifecycle and authorization; disable the account and review related access. If a laptop is stolen, encryption and device procedures can reduce exposure, while an incident process determines what to report. If a power outage threatens an office, redundancy may keep a service available, while business continuity identifies which operations must continue. These examples connect vocabulary to decisions rather than making terms into flash cards.
For governance, imagine a small organization has no approved process for accepting security risk. A technical employee should not silently decide that an exposed service is acceptable. Governance assigns decision authority, documents the risk and ties it to business priorities. If a scenario names a policy, standard, procedure or guideline, identify whether it sets direction, mandatory requirements, repeatable steps or recommended conduct before selecting an answer.
For operations, separate detection from response. A monitoring alert is a signal to investigate, not proof that an incident occurred. A response plan defines who validates the alert, how evidence is preserved, how systems are contained, and who may authorize recovery. A learner should know why responders avoid unapproved changes that could destroy logs or evidence. For networking and cloud, identify whether the question concerns the provider’s physical controls or the customer’s identities, workload configuration and data.
Choose study time by gap and domain weight
A simple prioritization method combines two inputs: how much of the outline a domain represents and how well you can explain its tasks. Domain 4 has the largest weight at 21.3 percent, but a candidate who already understands network basics may benefit more from repairing a governance gap. Conversely, someone with a policy background may need more time for IAM and networking. Do not allocate time by weight alone or by comfort alone.
During the final review, use mixed scenarios rather than reading notes from beginning to end. A scenario that asks who should authorize access might combine governance and IAM. A suspicious cloud log may combine customer responsibility with incident handling. State the clue, choose the action, and explain why a plausible alternative is premature or belongs to a different role. This is especially helpful under CAT, where you cannot postpone a difficult item for a later review.
Common questions
What is the current ISC2 CC exam outline?
The current outline took effect September 1, 2026 and contains five domains.
How many items and how much time are on the CC exam?
The CAT exam presents 100 to 125 items in two hours.
What is the ISC2 CC passing score?
The passing score is 700 out of 1,000 scaled points.
Do I need cybersecurity experience for CC?
No. No professional experience is required.
Is the free CC program open to new applicants?
No. New enrollment is closed, though existing eligible holders of valid codes may test through December 31, 2026 under program terms.
Does CC require an experience endorsement?
No. Passing candidates submit an application, agree to the Code of Ethics and pay the first AMF.