Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

ISC2 CC Study Plan and Revision Schedule

Updated 10 min read
Key takeaway

A useful CC plan starts with the September 2026 outline, studies all five domains, and uses original scenarios to apply concepts.

  • This eight-week example mixes learning, recall and timed no-backtracking practice.
  • Adjust weekly hours to your background and date; the plan is a study structure, not an ISC2 requirement or pass guarantee.
On this page13 sections
  1. Build the plan around the current outline
  2. A weekly study rhythm
  3. Weeks 1 and 2: principles and governance
  4. Weeks 3 and 4: access, networks and cloud
  5. Week 5: operations and incident response
  6. Weeks 6 and 7: mix, retrieve and time
  7. Week 8: final revision and logistics
  8. Adjusting the schedule for your background
  9. A repeatable three-session week
  10. A detailed week-by-week routine
  11. Use active recall instead of rereading
  12. Use practice questions without overfitting
  13. Adapt the schedule to your baseline

Build the plan around the current outline

ISC2’s current Certified in Cybersecurity outline became effective September 1, 2026. It includes Security Principles (24%), Security Governance (17.3%), Identity and Access Management Concepts (20%), Networking and Cloud Security Concepts (21.3%), and Security Operations and Incident Response (17.3%). Start by comparing your knowledge with those five domains. Do not build a plan from an older outline or assume a course labeled CC automatically reflects the 2026 update.

The schedule below assumes about six to eight focused study hours each week for eight weeks. That is a planning example, not an official recommendation or required number of hours. A candidate with a networking background may need fewer hours there and more governance practice; a candidate new to IT may need extra time for networking, cloud and security vocabulary. Keep the order and exercises, but adjust total time to your actual gaps.

A weekly study rhythm

Use three study sessions a week if possible: one for learning new material, one for retrieval and examples, and one for mixed practice and review. Short repeated sessions usually make it easier to retain distinctions than one long weekend cram. Begin each session by recalling the previous topic without notes. End by recording questions you still cannot answer.

WeekFocusPractice task
1Current outline, security principles and riskExplain CIA, authentication versus authorization, controls and ethics using short examples
2Security governanceCompare policy, standard, procedure and guideline; distinguish continuity from recovery
3Identity and accessWork through MFA, least privilege, role access, access review and separation-of-duties cases
4Networking and cloud securityReview segmentation, firewalls, secure communication and shared responsibility
5Security operations and incident responseClassify alert, analyze, contain, eradicate, recover and preserve evidence in scenarios
6Cross-domain applicationMix governance, IAM, cloud and incident cases; repair weak topics
7Timed practice and targeted revisionComplete fresh mixed sets one item at a time and explain every answer
8Final review and exam readinessRevisit errors, current outline, account details and appointment plan; avoid cramming new material

Weeks 1 and 2: principles and governance

In week 1, learn confidentiality, integrity, availability, privacy, authentication, authorization, accounting and non-repudiation. For each term, write a plain-language example. Then study basic risk concepts and controls. Ask whether a measure is technical, administrative or physical and whether it prevents, detects or corrects a problem. Practice matching a control to a threat rather than memorizing isolated labels.

A useful exercise: an employee can view a payroll folder but does not need it. Identify confidentiality and authorization as the main concerns, then explain why least privilege is more direct than encrypting a laptop. A second example can involve a lost encrypted device, where encryption is more directly relevant. Contrast cases build discrimination.

In week 2, study governance, risk acceptance, policy hierarchy, compliance, awareness, redundancy, business continuity and disaster recovery. Build a one-page comparison: policy states direction, standard establishes mandatory requirements, procedure describes steps, and guideline recommends practice. Practice identifying who has authority to accept business risk.

Write a continuity scenario and a recovery scenario. A flood closes the office but invoices must be processed: continuity. A damaged server must be rebuilt and restored: disaster recovery. Then explain why a backup is not enough without a tested restoration process. These examples map broad governance terms to operational decisions.

Weeks 3 and 4: access, networks and cloud

In week 3, sequence identity concepts: identify, authenticate, authorize, account. Practice with a person who logs in successfully but sees records outside their duties; that is authorization. Compare passwords with multifactor factors from different categories. Add least privilege, role-based access, separation of duties and access reviews. For each control, name the failure it prevents.

In week 4, learn basic network segmentation, firewalls, secure communication and cloud models. Understand that service-provider physical security and customer cloud configuration are different responsibilities. Make a two-column list of provider and customer duties for a virtual machine and a managed service. Include data, identity permissions, underlying hardware and guest operating-system patches.

Practice: a cloud account has an overly permissive role. Correct access policy and investigate activity; do not assume that the cloud provider chooses customer permissions. Another case has an exposed provider facility; that concerns provider physical controls. The layer named in the prompt is the decisive clue.

Week 5: operations and incident response

Study monitoring, threat intelligence, incident reporting, evidence handling, containment, eradication and recovery. Draw a response sequence, but avoid treating it as a rigid answer to every scenario. A suspicious email that has not been opened calls for safe handling and reporting. A confirmed compromised host may require containment and evidence preservation. Rebuilding before evidence is captured can interfere with investigation.

Create three cases: a suspicious message, a stolen device, and unusual outbound network traffic. For each, state what you know, what you do not know, the safe first step, and who should be notified. Distinguish an alert from a confirmed incident. Include AI-enhanced phishing as a reason to verify unusual requests through a trusted channel, not as a reason to distrust every message.

Weeks 6 and 7: mix, retrieve and time

In week 6, stop studying topics only in isolation. Mix domains in short scenarios. A cloud user with excessive access combines IAM and cloud responsibility. A business outage combines governance, continuity and recovery. A suspicious message that exposed credentials combines awareness, IAM and response. Explain the clue and the correct role before looking at answer explanations.

In week 7, complete fresh timed practice. The live exam lasts two hours and presents 100 to 125 variable-length CAT items. You cannot skip and return. Use a no-backtracking drill so each choice is final. Do not use practice percentages as scaled-score predictions; use the missed concepts to select review topics. Practice reading the final sentence first to identify the requested decision, then inspect the details.

Week 8: final revision and logistics

Review the current exam outline and your error log. Revisit weak concepts with a fresh example, then stop adding large new resources. Check the first and last name in your exam account against your ID, confirm the Pearson appointment and plan the route. Arrive early according to exam guidance. Sleep and attention are more useful on exam day than a last-minute stack of unfamiliar flash cards.

A final readiness conversation can be five questions: Can I distinguish identity verification from permission? Can I explain security of versus security in the cloud? Can I tell continuity from recovery? Can I identify a safe initial response and preserve evidence? Can I apply the 2026 outline across every domain? If an answer is weak, review that specific topic rather than restarting the whole course.

Adjusting the schedule for your background

A candidate with no IT experience can add a preliminary week for basic networking and computer concepts, extending the plan to nine weeks. An experienced administrator may shorten familiar networking review but should still practice governance, privacy, ethics and IAM. A busy professional can use 30-minute sessions on weekdays plus a longer weekly scenario review. The goal is repeated retrieval and application, not a fixed calendar that ignores real life.

If using a free program code, check its account expiry and any program deadline before following an eight-week plan. New pledge enrollment has closed; existing code holders may need to test by December 31, 2026 and also before their individual code expires. If the available time is too short for a sound plan, weigh a paid registration date that allows adequate study rather than rushing into an expiring voucher.

This example uses eight weeks and six to eight hours a week, but it is not an official ISC2 recommendation. Adjust it to your current knowledge and schedule.

Study the September 1, 2026 outline. Older materials may use different domain names and weights.

Yes. The live exam is CAT and does not allow skipping and returning, so practice choosing one answer at a time.

Use a practice score to find gaps, not predict the scaled score. ISC2 does not publish a raw percentage cutoff.

A repeatable three-session week

Session one can introduce a concept and take notes in your own words. Session two should retrieve it without notes and apply it to a new example. Session three can mix it with older concepts and review errors. For a seven-hour study week, one possible split is three hours learning, two hours retrieval and scenarios, and two hours mixed practice. Keep those three activities even if the session lengths change.

At the end of each week, update a tracker with the domain task, your confidence, an example solved and the next review date. Do not mark a topic complete just because you watched a lesson. Mark it complete when you can explain it, identify it in a scenario and reject a plausible wrong answer.

A detailed week-by-week routine

WeekSession ASession BSession C
1Learn CIA, risk and control typesRecall terms and build payroll/file examplesReview ethics and solve control-selection cases
2Study governance terms and risk rolesCompare continuity, disaster recovery and redundancyWork through policy and outage scenarios
3Learn identity sequence and authentication factorsPractice least privilege and separation of dutiesReview role changes and access reviews
4Study networks, segmentation and cloud boundariesMap customer and provider duties by service layerSolve firewall, cloud access and encryption cases
5Learn monitoring and response conceptsPractice response sequence, evidence and communicationsAnalyze phishing and compromise examples
6Mix domains in short casesReview weak topics and explain distractorsComplete a fresh practice set and error log
7Take a timed no-backtracking setCorrect errors by conceptRepeat a different mixed set and target gaps
8Review outline and compact notesPractice selected weak scenariosConfirm appointment and do light recall

Use active recall instead of rereading

After studying a topic, close the material and answer a practical prompt. What is the difference between authentication and authorization? Who patches a cloud guest operating system? Why is a backup not the same as a tested recovery plan? What is the first safe action when an employee receives a suspicious attachment? If you cannot answer, reopen the relevant source, correct your notes and try again later.

Use spaced review: revisit new material the next day, several days later and in the following week. Flash cards can help with terms, but scenarios should vary the facts. The goal is not to predict ISC2 wording; it is to apply a concept in a new situation.

Use practice questions without overfitting

For each item, record the decisive clue, your selected answer, why it fits and why the strongest distractor does not. If you get a question right by guessing, count it as a review item. Use new questions after a miss so you test the concept instead of memorizing original wording. Avoid dumps or material claiming to reproduce protected live items.

During the live CAT you cannot skip and return. If a practice platform allows backtracking, do a separate drill where each decision is final. This trains you to manage uncertainty without leaving questions for a later pass. Timed practice can build concentration, but its percentage is not a conversion to ISC2’s 700 scaled score.

Adapt the schedule to your baseline

If you have no IT background, add a preliminary week for basic computer, networking and security vocabulary. If you work in support or administration, do not skip governance, ethics or continuity because your job is technical. If you work in compliance, add practical examples for networking and cloud. Use the current outline tasks, not your job title, to decide what remains to learn.

If a voucher expires soon, check whether the available study time is realistic. New enrollment in the free pledge has closed; existing codes have individual expirations and a final December 31, 2026 testing deadline. Paid bundles can have shorter exam periods, especially products with two attempts. A calendar should include both the intended exam day and the code’s final valid date.

Common questions

How long should I study for ISC2 CC?

It depends on prior knowledge and study time. This article offers an eight-week example, not an official requirement.

What study outline should I use for CC in 2026?

Use the current outline effective September 1, 2026.

Should I practice with a timer?

Yes, timed mixed practice can help sustain attention, but do not equate its percentage with ISC2’s scaled score.

Can I return to questions during CC?

No. ISC2 does not allow candidates to skip an item and return later.