ISC2 CC Passing Score and Scaled Scoring
ISC2 sets the Certified in Cybersecurity passing grade at 700 out of 1,000 scaled points.
- That number is not a statement that 70 percent of items must be correct.
- ISC2 does not publish a raw-answer cutoff or a candidate-facing formula for converting practice results to the scaled score.
On this page14 sections
- The passing standard is 700 on a 1,000-point scale
- What a scaled score tells you
- How to interpret practice scores
- A worked example of score interpretation
- How to prepare toward the standard
- What ISC2 does not publish for candidates
- What candidates can and cannot infer from 700
- Practice scores are local diagnostic tools
- Domain weights guide coverage, not a guaranteed question count
- A practical readiness check
- Interpreting a fail result constructively
- A more useful review example
- Avoid false precision in score predictions
- Set a reasonable readiness threshold for yourself
The passing standard is 700 on a 1,000-point scale
ISC2 lists 700 out of 1,000 points as the passing grade for Certified in Cybersecurity. The important word is scaled. It is not a claim that a candidate must answer exactly 70 percent of the presented questions correctly. A scale expresses performance relative to the exam’s defined standard; candidates should not convert it into a raw percentage or calculate a target number of correct answers from 100 to 125 items.
For example, multiplying 125 by 70 percent to conclude that 88 correct answers guarantee a pass is not supported by ISC2’s published information. The exam is computer adaptive and item counts vary. The score is scaled; item difficulty and scoring treatment are not reducible to a public raw cutoff. Study to demonstrate knowledge across the outline rather than trying to game a secret number.
What a scaled score tells you
The scale communicates whether the candidate met the passing standard. ISC2 reports a pass or fail result rather than a detailed score report with a raw percentage. Candidates who do not pass receive proficiency information by domain. That feedback can show relative strengths and weaknesses, but it should not be treated as a precise item-by-item diagnosis or a promise about how many questions were missed.
CAT and scaled scoring are related ideas but not interchangeable. CAT describes how item selection adapts during an assessment. The scaled score describes the reported performance framework. Do not infer the scoring algorithm, the weight of a particular item or the candidate’s measured ability from the order in which questions appeared. ISC2 does not disclose a candidate-facing raw conversion formula.
How to interpret practice scores
Third-party practice quizzes use their own question sets and scoring rules. A 75 percent result on one quiz is useful evidence about that quiz’s topics, but it does not mean a 750 scaled exam score or predict a pass. Practice items may not match the live exam in difficulty, coverage, item format or calibration. Use them to identify misunderstood concepts and to practice applying principles.
A productive review asks why an answer is correct, why each distractor is wrong, and what scenario clue should trigger the concept next time. If a candidate misses an IAM item because authentication and authorization were confused, record that distinction and attempt a new scenario. If misses cluster around security governance, return to the relevant outline tasks. A raw percentage can guide study priorities without pretending to be an official score.
A worked example of score interpretation
Suppose a learner scores 68 percent on a commercial quiz, then improves to 82 percent on a second quiz. It is reasonable to say the second result suggests stronger performance on that provider’s material. It is not accurate to say the candidate is guaranteed 820 scaled points or has crossed ISC2’s pass line. The question pools may differ, and neither set has been equated to the official test scale.
Suppose a candidate fails and the report indicates lower proficiency in Networking and Cloud Security Concepts. That is a reason to revisit network segmentation, secure communication, cloud service responsibility and related tasks. It does not reveal that the candidate got a fixed percentage wrong in that domain. Use the information as direction, then return to the outline and correct conceptual gaps.
How to prepare toward the standard
The current five domains carry weights of 24 percent, 17.3 percent, 20 percent, 21.3 percent and 17.3 percent. These weights describe the outline, not an exact item count on every CAT session. A high-weight domain deserves attention, but candidates should not ignore a smaller domain. The exam is compensatory only to the extent ISC2 describes its score; avoid assuming any one weakness can always be offset by another without adequate knowledge.
Use readiness checks that measure explanation and application: Can you distinguish confidentiality from integrity? Can you say why a role should have only necessary access? Can you identify the party that patches a cloud guest operating system? Can you select an appropriate initial response to a suspected incident? Being able to answer new examples is a better preparation signal than memorizing a vendor quiz score.
What ISC2 does not publish for candidates
ISC2’s public CC pages identify the passing grade but do not give candidates a raw percent requirement, an answer key, a per-item score, or a formula for translating practice results to the scale. The CAT process also means candidates see a variable-length sequence rather than a fixed identical paper. Avoid websites that claim to know an exact raw cutoff or predict a score from the number of questions answered.
A responsible interpretation is simple: 700 scaled points is the passing standard; actual candidates receive a pass/fail result; failed candidates may receive domain proficiency feedback. Anything more exact about raw performance is an unsupported inference. Put study effort into the current outline and sound decision-making.
No. 700 is a scaled score out of 1,000. It is not a published rule requiring exactly 70 percent of items correct.
ISC2 lists 700 out of 1,000 scaled points as the passing grade.
ISC2 generally reports pass or fail. Candidates who fail receive proficiency feedback by domain, not a detailed raw answer percentage.
No. Practice quizzes use their own questions and scoring. Use scores to identify weak concepts, not as direct scaled-score predictions.
What candidates can and cannot infer from 700
The published 700 is a scaled passing standard, not a count of correct answers. The exam can present different numbers of items because it uses CAT, and the public materials do not provide item-by-item score values or an exact raw cutoff. A candidate cannot reliably calculate a result by multiplying the presented question count by 70 percent. That arithmetic confuses a reported scale with a raw fraction.
Candidates sometimes speculate that a minimum-length session means pass or fail, or that a difficult final item reveals the outcome. Those conclusions are not supported. The interface does not expose the CAT’s internal measurements, and perceived difficulty is subjective. The only dependable result is the result communicated by ISC2 and Pearson after the exam.
Practice scores are local diagnostic tools
A third-party practice test is scored according to its author’s choices. It may emphasize definitions, use old outline terminology, repeat familiar questions or have a different difficulty mix. A result can show whether you understand that set, but it has not been equated to ISC2’s scale. Do not translate an 80 percent practice score into an 800 exam score or claim that it guarantees a pass.
Track each miss by concept and reason: did you forget a definition, confuse two stages, ignore a qualifier, or select a tool that did not match the requested task? A learner who misses access questions after repeatedly scoring well on terminology may need more scenario work on authentication, authorization, least privilege and separation of duties. Reviewing only the total percentage can hide this useful pattern.
Practice should include fresh questions, not just a repeated bank. A candidate can remember an answer letter without knowing why it is correct. Explain the principle and reject each distractor in plain language. If you cannot explain why a choice is safer or more direct, add the concept to your review list even if the practice score marked it correct.
Domain weights guide coverage, not a guaranteed question count
The current weights are 24 percent for Security Principles, 17.3 percent for Security Governance, 20 percent for Identity and Access Management Concepts, 21.3 percent for Networking and Cloud Security Concepts, and 17.3 percent for Security Operations and Incident Response. These are published outline weights. They do not mean every session will contain a fixed number of questions from each domain, particularly when the CAT adapts and variable-length format applies.
Use the weights to avoid neglecting a large area, then adjust for your own gaps. If you work in networking, you may need more time with governance and professional ethics. If you work in policy, you may need to build confidence in IAM and cloud security. No single domain score should be treated as a substitute for overall readiness.
A practical readiness check
- Explain confidentiality, integrity and availability with one example each.
- Distinguish identification, authentication, authorization and accounting in a short access scenario.
- Explain who owns a cloud guest operating-system patch versus physical data-center security.
- Choose an appropriate first response to a suspicious message and explain what evidence should be preserved after a compromise.
- Read a new mixed question and identify the clue that makes the best answer fit better than its alternatives.
These checks are personal study criteria, not an ISC2 official practice cutoff. If you can answer them consistently and explain your reasoning across all five current domains, you have stronger evidence of understanding than a memorized percentage alone. If you cannot, use the outline to select the next topic to learn.
Interpreting a fail result constructively
A fail result means the candidate did not meet the passing standard on that sitting. Domain proficiency information may identify where to focus, but it does not reveal the precise items answered incorrectly. Combine that information with your practice log, then choose specific review actions. For an IAM gap, compare authentication and authorization and work through least-privilege examples. For a response gap, identify what to preserve, whom to notify and when containment is appropriate.
Do not rush into a retake solely because the waiting period has elapsed. ISC2 requires 30 test-free days after the first attempt, 60 after the second, and 90 after the third and later attempts, with a maximum of four attempts in a 12-month period. These are minimum gaps, not recommendations about study duration. Check whether a product’s exam window will still be open before selecting a date.
A more useful review example
A learner misses an IAM question because they see a successful login and conclude that the system verified the user incorrectly. In fact, the scenario says the account opened data outside its role. The distinction is authorization. Repeating the definition may help, but the better review is to work through a second example in which authentication fails, then compare it with a case where authentication succeeds but access is too broad.
A candidate who sees a weak Security Operations and Incident Response proficiency indication might review the response sequence and evidence handling. They should also inspect their own notes for premature actions, such as rebuilding a device before preserving evidence. The report points to a broad area; the candidate’s reasoning log turns it into a specific study task.
Avoid false precision in score predictions
A prep course may say its questions are harder than the exam or that a certain percentage is a safe target. Those statements are that provider’s judgment, not a published ISC2 conversion. Ask whether the question bank follows the September 2026 outline, includes fresh applied scenarios, and explains alternatives. Use a consistent result across new questions as evidence of preparation, but do not label it an official predictor.
The same caution applies to social-media reports about minimum question counts or exact passing patterns. A candidate’s recollection does not expose the scoring engine, and question count is not a public score report. Focus on mastering all domain tasks and receive the official result rather than trying to derive a hidden cutoff.
Set a reasonable readiness threshold for yourself
A self-imposed readiness check can include stable performance on unseen mixed questions, an ability to explain every answer, coverage of every domain, and a full timed study session without losing focus. Choose the practice threshold based on the quality and size of your materials. State it as your own preparation rule, not “ISC2 requires X percent.” This avoids misleading yourself or other learners.
If your practice results rise because you recognize repeated questions, change the set or write your own scenario. For example, instead of memorizing that least privilege limits access, construct a case in which an employee changes jobs and decide which access to remove. Transfer to a new problem is a more meaningful check than repeating the same item.
Common questions
What score do I need to pass ISC2 CC?
The passing grade is 700 out of 1,000 scaled points.
Is 700 the same as 70 percent correct?
No. It is a scaled score, and ISC2 does not publish a raw percentage cutoff.
Does ISC2 provide a detailed score report?
Candidates generally receive pass or fail; those who fail receive domain proficiency feedback.
Can a practice score predict my scaled result?
No. Independent practice sets use different questions and scoring rules.