Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

ISC2 CC Certification Requirements After the Exam

Updated 10 min read
Key takeaway

After passing CC, complete the certification application and agree to the ISC2 Code of Ethics within nine months.

  • Pay the first US $50 Annual Maintenance Fee through your ISC2 account.
  • CC has no work-experience endorsement or supervisor verification requirement.
  • After processing, verify the active certification and digital credential in your account.
On this page14 sections
  1. Passing the exam is not the last administrative step
  2. Step 1: receive and keep the result
  3. Step 2: submit the CC application and Code of Ethics agreement
  4. Step 3: pay the first AMF
  5. Step 4: verify active status and credential record
  6. What the CC credential says about you
  7. Common post-exam mistakes
  8. Worked post-exam examples
  9. A post-pass timeline that avoids rework
  10. Application and fee examples
  11. Use accurate credential language
  12. What if the nine-month deadline is close
  13. How the application differs from other ISC2 credentials
  14. Make your application record easy to verify

Passing the exam is not the last administrative step

A pass on the ISC2 Certified in Cybersecurity exam establishes that you met the exam standard. To receive the credential, you still need to complete the CC certification application, agree to the ISC2 Code of Ethics and pay the first Annual Maintenance Fee. ISC2 allows nine months from passing to submit the application. Treat this period as a firm deadline, not an optional window for gaining experience.

Unlike several other ISC2 credentials, CC does not require an experience endorsement, a supervisor’s attestation or a work-history review. You do not need to hold a cybersecurity job before applying. The process is designed to preserve an accessible route for newcomers while requiring candidates to accept the professional code and maintain the awarded credential.

Step 1: receive and keep the result

Many candidates receive a provisional result at the test center. ISC2’s FAQ says official email confirmation can take up to 72 business hours after Pearson transmits the result. Keep the appointment details and use the same email and account used to schedule. If the confirmation does not arrive after the expected window, contact Exam Administration rather than creating a new account or booking another attempt.

A provisional pass should prompt you to prepare the application steps, but you still need the official account record. Verify that the result corresponds to the right exam and that your account information is current. If the email is different or the result does not appear, contact support early and retain the candidate number or confirmation details.

Step 2: submit the CC application and Code of Ethics agreement

The CC application is completed through the ISC2 account. Candidates agree to abide by the ISC2 Code of Ethics. This is an ethical commitment, not an employment verification form. Complete the application within nine months of the pass date. ISC2 states that a candidate who does not submit within the deadline must retake the exam.

Do not wait for a manager to endorse you. CC is the exception to ISC2’s ordinary endorsement process, so a lack of cybersecurity employment does not block the application. You should still provide accurate account information and comply with any disclosures or instructions in the application. If something is unclear, ask ISC2 support before the deadline rather than assuming a different certification’s process applies.

Step 3: pay the first AMF

ISC2 requires the first US $50 Annual Maintenance Fee before the CC credential is granted. The fee is paid through the candidate’s account after the application process. This is distinct from the standard exam registration price of US $199 in the Americas and Asia Pacific regions listed in ISC2’s pricing table. Exam purchase and certification maintenance are separate charges.

ISC2’s Candidate dues may cover the CC AMF for the same year if the candidate already paid the US $50 annual dues and then earns CC. This is an account-specific same-year treatment, not a perpetual waiver. Check the dashboard balance before making an extra payment, and keep a receipt for any amount paid. Future annual AMF obligations still apply while maintaining CC.

Step 4: verify active status and credential record

After the application and AMF are processed, verify the certification title and active status in the ISC2 account. Check the cycle start, anniversary and expiration information so you can plan maintenance. ISC2 provides a digital certificate and badge; the current CC FAQ notes that CC holders do not receive a welcome pack by mail. Use the official badge sharing option if you want others to verify the credential.

If the status does not update after completing each step, review the account for a missing application, ethics agreement or payment. Contact ISC2 Member Services with the relevant confirmation details if all steps show completed. Do not claim the credential as active until the account confirms it. Keep a copy of the result and application confirmation with your records.

What the CC credential says about you

CC demonstrates foundational knowledge across current security principles, governance, IAM, networking and cloud security, and security operations and incident response. It signals that you passed an assessment designed for newcomers. It does not certify years of employment, independent operational authority, a security clearance, or expertise in a specific technology. Describe it accurately alongside separate evidence of projects and work experience.

For example, a student can list “ISC2 Certified in Cybersecurity” after the award is active. If that student has completed a lab, describe the lab separately and accurately. A service-desk professional may say the credential supports foundational security knowledge, while describing specific access or incident tasks performed at work. Neither should suggest that CC alone proves advanced system administration.

Common post-exam mistakes

  • Assuming the provisional pass automatically issues the credential without an application or AMF.
  • Waiting more than nine months to submit the CC application and then discovering the exam must be retaken.
  • Trying to obtain an experience endorsement that CC does not require.
  • Confusing the exam fee, first AMF, annual AMF and ISC2 Candidate dues.
  • Listing CC as active before the account confirms the award.
  • Describing an entry-level certificate as proof of job experience or a guaranteed employment outcome.

Worked post-exam examples

A candidate passes on November 1 and has no IT employment. The candidate can still apply: CC does not require experience. The candidate should submit the application and ethics agreement before the nine-month deadline, then pay the first AMF. A manager signature is not required.

A candidate passes but has already paid annual ISC2 Candidate dues. Before paying again, check the account because the same-year dues may cover the initial CC AMF. Do not assume the payment covers the next year; note the certification anniversary for future maintenance.

A candidate completes the form and payment but sees no badge immediately. Check whether each step is recorded, allow account processing, and contact Member Services if the record remains incomplete. The badge is a digital representation of the credential, not a substitute for finishing application requirements.

Within nine months of passing. If the application is not submitted by then, ISC2 says the candidate must retake the exam.

No. CC has no experience endorsement or supervisor attestation requirement.

The first US $50 AMF is required before the credential is granted. Candidate dues already paid for the same year may cover it under ISC2’s terms.

After the application and first AMF are processed, verify active status in the ISC2 account and use the digital credential tools there.

A post-pass timeline that avoids rework

On the day of the exam, keep the appointment confirmation and any provisional result. Over the next few business days, check the ISC2 account email for the official result. Once the pass is recorded, complete the application promptly and note the nine-month cutoff. Pay the AMF shown in the dashboard, then return to confirm the award status and cycle dates. This sequence avoids confusing a test result with an active credential.

A candidate who passes on October 5 should not plan to apply in July simply because nine months sounds generous. Submit soon after the pass, while account access and identity details are current. If the applicant is relocating or changing employers, use an email address that remains accessible and update the account through official support if necessary.

Application and fee examples

A student passes and has never been an ISC2 Candidate. The student applies, agrees to the Code of Ethics and pays the initial US $50 AMF. There is no supervisor to find and no experience file to prepare. Once the award is active, the student should record the annual AMF anniversary and three-year CPE cycle.

A candidate has paid $50 in ISC2 Candidate dues in the same year as passing CC. ISC2 says those dues cover the CC AMF for that year. The candidate should check the account before paying a second time, and should not assume next year’s AMF is covered. The exam fee was a separate purchase and is not credited toward maintenance.

A candidate sees a provisional pass but receives no badge. The candidate should wait for the official record, confirm the application and payment status, and then contact Member Services if the account does not reflect completed steps. A badge delay does not mean that a new exam purchase is needed.

Use accurate credential language

After the account shows the active credential, use the official name, ISC2 Certified in Cybersecurity. Do not call yourself a CISSP or imply the CC proves advanced hands-on expertise. If the credential later expires or becomes suspended, do not display it as active. A digital badge can link to verification, while a resume should distinguish the certification from separate employment or project experience.

A careful profile line might say: “ISC2 Certified in Cybersecurity; foundational knowledge of governance, IAM, network and cloud security, and incident response.” If you completed a personal lab, list its task separately. This allows readers to understand what the exam verifies and what practical evidence you have built independently.

What if the nine-month deadline is close

If you passed but have not applied and the nine-month deadline is approaching, sign in and complete the process as soon as possible. If the application page or account is unavailable, contact ISC2 immediately and keep the support case number. Do not assume an email to a general address automatically extends the deadline. If the deadline passes without an application, ISC2 says you must retake the exam.

If a payment fails, review the account’s available payment method and contact support rather than creating a second profile. Use a payment receipt to confirm whether the AMF was processed. The purpose of the checklist is to finish the exact required steps once, without duplicating purchases or leaving the credential inactive.

How the application differs from other ISC2 credentials

Some ISC2 certifications require candidates to pass an exam and then demonstrate qualifying work experience through an endorsement process. CC is designed as an entry-level exception: no experience verification is required. Do not import CISSP or CCSP application steps into the CC process. The post-pass tasks are still real, but they center on the application, ethics agreement and AMF rather than a work-history claim.

The lack of an experience gate does not mean that the credential has no standards. The candidate must pass the exam and agree to the professional Code of Ethics. The certification’s scope remains foundational, and holders are responsible for keeping it active through fees and CPE. These boundaries help explain both why a newcomer can earn CC and why an employer may separately ask for applied experience.

Make your application record easy to verify

Use one account, retain the pass notice, and save the application and payment confirmations. If your Candidate profile and exam profile use different email addresses, resolve the account linkage with ISC2 support. Avoid opening duplicate accounts to access a badge or pay an AMF; duplicated profiles can make certification history harder to reconcile.

After the credential is active, check the anniversary date and submit CPE activities in the portal during the cycle. This does not alter the nine-month application rule; it begins the maintenance phase. A simple record of pass date, application date, fee payment, active status and next maintenance date gives a clear timeline if a future account question arises.

Common questions

What do I do after passing the ISC2 CC exam?

Submit the certification application, agree to the Code of Ethics and pay the first US $50 AMF.

How long do I have to submit the CC application?

Nine months from passing. Missing the deadline requires retaking the exam.

Does CC require work experience or endorsement?

No. CC has no experience endorsement requirement.

Is the CC AMF part of the exam fee?

No. The first US $50 AMF is a separate certification requirement after passing.