ISC2 CC Study Plan and Revision Schedule
A useful CC plan starts with the September 2026 outline, studies all five domains, and uses original scenarios to apply concepts.
- This eight-week example mixes learning, recall and timed no-backtracking practice.
- Adjust weekly hours to your background and date; the plan is a study structure, not an ISC2 requirement or pass guarantee.
On this page13 sections
- Build the plan around the current outline
- A weekly study rhythm
- Weeks 1 and 2: principles and governance
- Weeks 3 and 4: access, networks and cloud
- Week 5: operations and incident response
- Weeks 6 and 7: mix, retrieve and time
- Week 8: final revision and logistics
- Adjusting the schedule for your background
- A repeatable three-session week
- A detailed week-by-week routine
- Use active recall instead of rereading
- Use practice questions without overfitting
- Adapt the schedule to your baseline
Build the plan around the current outline
ISC2’s current Certified in Cybersecurity outline became effective September 1, 2026. It includes Security Principles (24%), Security Governance (17.3%), Identity and Access Management Concepts (20%), Networking and Cloud Security Concepts (21.3%), and Security Operations and Incident Response (17.3%). Start by comparing your knowledge with those five domains. Do not build a plan from an older outline or assume a course labeled CC automatically reflects the 2026 update.
The schedule below assumes about six to eight focused study hours each week for eight weeks. That is a planning example, not an official recommendation or required number of hours. A candidate with a networking background may need fewer hours there and more governance practice; a candidate new to IT may need extra time for networking, cloud and security vocabulary. Keep the order and exercises, but adjust total time to your actual gaps.
A weekly study rhythm
Use three study sessions a week if possible: one for learning new material, one for retrieval and examples, and one for mixed practice and review. Short repeated sessions usually make it easier to retain distinctions than one long weekend cram. Begin each session by recalling the previous topic without notes. End by recording questions you still cannot answer.
| Week | Focus | Practice task |
|---|---|---|
| 1 | Current outline, security principles and risk | Explain CIA, authentication versus authorization, controls and ethics using short examples |
| 2 | Security governance | Compare policy, standard, procedure and guideline; distinguish continuity from recovery |
| 3 | Identity and access | Work through MFA, least privilege, role access, access review and separation-of-duties cases |
| 4 | Networking and cloud security | Review segmentation, firewalls, secure communication and shared responsibility |
| 5 | Security operations and incident response | Classify alert, analyze, contain, eradicate, recover and preserve evidence in scenarios |
| 6 | Cross-domain application | Mix governance, IAM, cloud and incident cases; repair weak topics |
| 7 | Timed practice and targeted revision | Complete fresh mixed sets one item at a time and explain every answer |
| 8 | Final review and exam readiness | Revisit errors, current outline, account details and appointment plan; avoid cramming new material |
Weeks 1 and 2: principles and governance
In week 1, learn confidentiality, integrity, availability, privacy, authentication, authorization, accounting and non-repudiation. For each term, write a plain-language example. Then study basic risk concepts and controls. Ask whether a measure is technical, administrative or physical and whether it prevents, detects or corrects a problem. Practice matching a control to a threat rather than memorizing isolated labels.
A useful exercise: an employee can view a payroll folder but does not need it. Identify confidentiality and authorization as the main concerns, then explain why least privilege is more direct than encrypting a laptop. A second example can involve a lost encrypted device, where encryption is more directly relevant. Contrast cases build discrimination.
In week 2, study governance, risk acceptance, policy hierarchy, compliance, awareness, redundancy, business continuity and disaster recovery. Build a one-page comparison: policy states direction, standard establishes mandatory requirements, procedure describes steps, and guideline recommends practice. Practice identifying who has authority to accept business risk.
Write a continuity scenario and a recovery scenario. A flood closes the office but invoices must be processed: continuity. A damaged server must be rebuilt and restored: disaster recovery. Then explain why a backup is not enough without a tested restoration process. These examples map broad governance terms to operational decisions.
Weeks 3 and 4: access, networks and cloud
In week 3, sequence identity concepts: identify, authenticate, authorize, account. Practice with a person who logs in successfully but sees records outside their duties; that is authorization. Compare passwords with multifactor factors from different categories. Add least privilege, role-based access, separation of duties and access reviews. For each control, name the failure it prevents.
In week 4, learn basic network segmentation, firewalls, secure communication and cloud models. Understand that service-provider physical security and customer cloud configuration are different responsibilities. Make a two-column list of provider and customer duties for a virtual machine and a managed service. Include data, identity permissions, underlying hardware and guest operating-system patches.
Practice: a cloud account has an overly permissive role. Correct access policy and investigate activity; do not assume that the cloud provider chooses customer permissions. Another case has an exposed provider facility; that concerns provider physical controls. The layer named in the prompt is the decisive clue.
Week 5: operations and incident response
Study monitoring, threat intelligence, incident reporting, evidence handling, containment, eradication and recovery. Draw a response sequence, but avoid treating it as a rigid answer to every scenario. A suspicious email that has not been opened calls for safe handling and reporting. A confirmed compromised host may require containment and evidence preservation. Rebuilding before evidence is captured can interfere with investigation.
Create three cases: a suspicious message, a stolen device, and unusual outbound network traffic. For each, state what you know, what you do not know, the safe first step, and who should be notified. Distinguish an alert from a confirmed incident. Include AI-enhanced phishing as a reason to verify unusual requests through a trusted channel, not as a reason to distrust every message.
Weeks 6 and 7: mix, retrieve and time
In week 6, stop studying topics only in isolation. Mix domains in short scenarios. A cloud user with excessive access combines IAM and cloud responsibility. A business outage combines governance, continuity and recovery. A suspicious message that exposed credentials combines awareness, IAM and response. Explain the clue and the correct role before looking at answer explanations.
In week 7, complete fresh timed practice. The live exam lasts two hours and presents 100 to 125 variable-length CAT items. You cannot skip and return. Use a no-backtracking drill so each choice is final. Do not use practice percentages as scaled-score predictions; use the missed concepts to select review topics. Practice reading the final sentence first to identify the requested decision, then inspect the details.
Week 8: final revision and logistics
Review the current exam outline and your error log. Revisit weak concepts with a fresh example, then stop adding large new resources. Check the first and last name in your exam account against your ID, confirm the Pearson appointment and plan the route. Arrive early according to exam guidance. Sleep and attention are more useful on exam day than a last-minute stack of unfamiliar flash cards.
A final readiness conversation can be five questions: Can I distinguish identity verification from permission? Can I explain security of versus security in the cloud? Can I tell continuity from recovery? Can I identify a safe initial response and preserve evidence? Can I apply the 2026 outline across every domain? If an answer is weak, review that specific topic rather than restarting the whole course.
Adjusting the schedule for your background
A candidate with no IT experience can add a preliminary week for basic networking and computer concepts, extending the plan to nine weeks. An experienced administrator may shorten familiar networking review but should still practice governance, privacy, ethics and IAM. A busy professional can use 30-minute sessions on weekdays plus a longer weekly scenario review. The goal is repeated retrieval and application, not a fixed calendar that ignores real life.
If using a free program code, check its account expiry and any program deadline before following an eight-week plan. New pledge enrollment has closed; existing code holders may need to test by December 31, 2026 and also before their individual code expires. If the available time is too short for a sound plan, weigh a paid registration date that allows adequate study rather than rushing into an expiring voucher.
This example uses eight weeks and six to eight hours a week, but it is not an official ISC2 recommendation. Adjust it to your current knowledge and schedule.
Study the September 1, 2026 outline. Older materials may use different domain names and weights.
Yes. The live exam is CAT and does not allow skipping and returning, so practice choosing one answer at a time.
Use a practice score to find gaps, not predict the scaled score. ISC2 does not publish a raw percentage cutoff.
A repeatable three-session week
Session one can introduce a concept and take notes in your own words. Session two should retrieve it without notes and apply it to a new example. Session three can mix it with older concepts and review errors. For a seven-hour study week, one possible split is three hours learning, two hours retrieval and scenarios, and two hours mixed practice. Keep those three activities even if the session lengths change.
At the end of each week, update a tracker with the domain task, your confidence, an example solved and the next review date. Do not mark a topic complete just because you watched a lesson. Mark it complete when you can explain it, identify it in a scenario and reject a plausible wrong answer.
A detailed week-by-week routine
| Week | Session A | Session B | Session C |
|---|---|---|---|
| 1 | Learn CIA, risk and control types | Recall terms and build payroll/file examples | Review ethics and solve control-selection cases |
| 2 | Study governance terms and risk roles | Compare continuity, disaster recovery and redundancy | Work through policy and outage scenarios |
| 3 | Learn identity sequence and authentication factors | Practice least privilege and separation of duties | Review role changes and access reviews |
| 4 | Study networks, segmentation and cloud boundaries | Map customer and provider duties by service layer | Solve firewall, cloud access and encryption cases |
| 5 | Learn monitoring and response concepts | Practice response sequence, evidence and communications | Analyze phishing and compromise examples |
| 6 | Mix domains in short cases | Review weak topics and explain distractors | Complete a fresh practice set and error log |
| 7 | Take a timed no-backtracking set | Correct errors by concept | Repeat a different mixed set and target gaps |
| 8 | Review outline and compact notes | Practice selected weak scenarios | Confirm appointment and do light recall |
Use active recall instead of rereading
After studying a topic, close the material and answer a practical prompt. What is the difference between authentication and authorization? Who patches a cloud guest operating system? Why is a backup not the same as a tested recovery plan? What is the first safe action when an employee receives a suspicious attachment? If you cannot answer, reopen the relevant source, correct your notes and try again later.
Use spaced review: revisit new material the next day, several days later and in the following week. Flash cards can help with terms, but scenarios should vary the facts. The goal is not to predict ISC2 wording; it is to apply a concept in a new situation.
Use practice questions without overfitting
For each item, record the decisive clue, your selected answer, why it fits and why the strongest distractor does not. If you get a question right by guessing, count it as a review item. Use new questions after a miss so you test the concept instead of memorizing original wording. Avoid dumps or material claiming to reproduce protected live items.
During the live CAT you cannot skip and return. If a practice platform allows backtracking, do a separate drill where each decision is final. This trains you to manage uncertainty without leaving questions for a later pass. Timed practice can build concentration, but its percentage is not a conversion to ISC2’s 700 scaled score.
Adapt the schedule to your baseline
If you have no IT background, add a preliminary week for basic computer, networking and security vocabulary. If you work in support or administration, do not skip governance, ethics or continuity because your job is technical. If you work in compliance, add practical examples for networking and cloud. Use the current outline tasks, not your job title, to decide what remains to learn.
If a voucher expires soon, check whether the available study time is realistic. New enrollment in the free pledge has closed; existing codes have individual expirations and a final December 31, 2026 testing deadline. Paid bundles can have shorter exam periods, especially products with two attempts. A calendar should include both the intended exam day and the code’s final valid date.
Common questions
How long should I study for ISC2 CC?
It depends on prior knowledge and study time. This article offers an eight-week example, not an official requirement.
What study outline should I use for CC in 2026?
Use the current outline effective September 1, 2026.
Should I practice with a timer?
Yes, timed mixed practice can help sustain attention, but do not equate its percentage with ISC2’s scaled score.
Can I return to questions during CC?
No. ISC2 does not allow candidates to skip an item and return later.