Certified in Cybersecurity (CC)

ISC2

Complete guide to passing the Certified in Cybersecurity (CC) exam on your first attempt.

MediumHigh Search Volume
Key Information at a Glance
Cost

$199

Pass Rate

Not published

Validity

3-year cycle, maintained with 45 CPE credits and a $50 annual maintenance fee

Region

Global

Provider

ISC2

Salary Impact

$62k-$125k

Are you ready for Certified in Cybersecurity (CC)?

Loading quiz...

Complete Overview

Certified in Cybersecurity (CC) is the entry-level certification from ISC2, the body behind CISSP, and ISC2 lists standard registration at U.S. $199, EUR 191.04 across EMEA, and GBP 161.19 in the United Kingdom. It is built for people entering cybersecurity without direct IT experience, and ISC2 states there are no prerequisites: no work experience in cybersecurity and no formal diploma or degree is required, though basic IT knowledge is recommended.

The exam outline changes on September 1, 2026, the first major content update since CC launched in August 2022. Sittings up to and including August 31, 2026 follow the 2022 outline: Security Principles 26 percent, Business Continuity, Disaster Recovery and Incident Response 10 percent, Access Controls Concepts 22 percent, Network Security 24 percent, and Security Operations 18 percent. From September 1 the five domains are renamed and reweighted to Security Principles at 24 percent, Security Governance at 17.3 percent, Identity and Access Management (IAM) Concepts at 20 percent, Networking and Cloud Security Concepts at 21.3 percent, and Security Operations and Incident Response at 17.3 percent. The domains listed on this page are the September 2026 version, because it governs every appointment booked from that date. Business Continuity, Disaster Recovery and Incident Response stops being a domain: continuity and recovery move under redundancy inside Security Governance, and incident response moves into Domain 5. Foundational AI topics run across all five domains.

The free One Million Certified in Cybersecurity programme has ended. ISC2 closed new enrolments on May 20, 2026, after more than one million people enrolled, and exam codes already issued must be used to schedule and sit an exam by December 31, 2026. New candidates pay the standard U.S. $199 fee.

CC uses Computerized Adaptive Testing in every language it is offered in. You get a maximum of two hours and between 100 and 125 items, of which 25 are unscored pretest items. The passing grade is 700 out of 1,000 points. The algorithm ends the exam once your ability estimate excludes the pass point with 95 percent statistical confidence, which is why two candidates can finish at different item counts. Item review is not permitted, so once you finalise an answer you cannot change it.

ISC2 delivers the exam only at Pearson Professional Centers and ISC2-authorised Pearson VUE Select Test Centers, in English, Chinese, Japanese, German, and Spanish. Chinese-language CC exams are available only in selected appointment windows. Candidates must be at least 16 years old, and 16 and 17 year olds must be accompanied by a parent or guardian.

Passing is not the end of the process. CC does not require the full ISC2 endorsement that CISSP requires, but you still submit a certification application within nine months of your exam pass date and confirm that you will abide by the ISC2 Code of Ethics. After the application is approved you pay the first annual maintenance fee of U.S. $50 to start your membership cycle, and you then earn 45 CPE credits across a three-year certification cycle to keep the credential active.

Why Get Certified in Cybersecurity (CC) Certified?

ISC2 sets no experience or education prerequisite for CC, unlike CISSP which requires five years of paid work experience in two or more of its eight domains

The exam fee is U.S. $199 against U.S. $749 for CISSP and U.S. $249 for SSCP

The annual maintenance fee for members holding only CC is U.S. $50, against U.S. $135 for other ISC2 certifications

CC complies with the ANSI National Accreditation Board ISO/IEC 17024 standard, which many public sector employers check for

ISC2 reports that more than 65,000 people earned CC through the One Million Certified in Cybersecurity programme before it closed on May 20, 2026

ISC2 survey data cited on its own programme page shows 65 percent of employed CC holders working in cybersecurity roles and another 22 percent in IT roles

The September 1, 2026 outline adds cloud security, zero trust, threat intelligence, and incident response, which are the topics entry-level job descriptions actually list

Exam Format & Structure

Duration

2 hours maximum

Questions

100-125 items

Passing Score

700 out of 1,000 points

Question Types

  • Multiple choice
  • Advanced item types

Delivery Method

Computerized Adaptive Testing at Pearson Professional Centers and ISC2-authorised Pearson VUE Select Test Centers

  • Every CC exam contains 25 unscored pretest items inside the minimum 100-item length, and candidates cannot tell which items those are.
  • To receive any result you must answer at least 75 operational items plus the 25 pretest items within the two hours, or the exam automatically fails.
  • Item review is not permitted. Once an answer is finalised it cannot be revisited or changed.
  • There is no minimum administration time. Candidates may finish early once the algorithm reaches its decision.
  • ISC2 does not limit the number or duration of breaks, but every break counts against the two hours.
  • The exam content is not delivered in sections; items are selected by the algorithm while still meeting the published domain weights.
  • The domain weights on this page are ISC2's outline effective September 1, 2026. Exams sat on or before August 31, 2026 are built to the 2022 outline instead, so check which one your appointment date falls under.
  • ISC2's printed weights for the September 2026 outline are 24, 17.3, 20, 21.3, and 17.3, which sum to 99.9 percent; ISC2's own outline labels the total as 100 percent.

How scoring works

Score scale

1 to 1,000 points

Score needed to pass

700

Roughly what that means raw

ISC2 publishes no raw-to-scaled conversion and states that the number of items answered correctly does not determine the result; the difficulty of the items answered correctly does.

When results arrive

Immediately at checkout as an unofficial result from the proctor, followed by an official result by email from ISC2. Where test volumes are low, results can be delayed roughly six to eight weeks.

How the scale is built

The adaptive algorithm re-estimates your ability after every item and selects the next item so that you have roughly a 50 percent chance of answering it correctly. Once 100 items are answered, the exam ends as soon as your ability estimate excludes the pass point with 95 percent confidence. If that never happens, the maximum-length rule at 125 items or the run-out-of-time rule at two hours compares your final estimate against the passing standard.

  • Candidates do not receive a numerical score on the pass or fail report.
  • Failing candidates receive a proficiency level for each domain: below proficiency, near proficiency, or above proficiency.
  • The exam is compensatory, so strong performance in a heavily weighted domain can offset weaker performance in a lighter one.
  • Failing at exactly 75 operational items does not indicate a poor performance; it means the algorithm reached its decision at the minimum length.
  • All results are subject to ISC2 psychometric and forensic evaluation, which can occur after the official result is issued.

Pacing and time budget

100-125 questions in 120 minutes gives you About 72 seconds per item if you plan for 100 items, or about 58 seconds if the exam runs to the 125-item maximum per question.

At this pointYou should have answered
30 minAt least 25 items
60 minAt least 50 items
90 minAt least 75 items
115 minAt least 100 items, the minimum needed for any result
  • Answering fewer than 75 operational items and 25 pretest items within the two hours is an automatic fail, so the 100-item mark is a hard floor rather than a target.
  • Every break is counted inside the two hours, and a palm vein scan is required before and after each one, which costs more time than the break itself.
  • There is no item review, so time spent second-guessing an earlier answer is wasted; the answer is already locked.
  • The exam can end at any point after item 100, so do not slow down expecting a fixed finish line.
  • Advanced item types take longer than plain multiple choice, so bank time on the short items early rather than late.

Where the marks are

TopicWeightWhy it scores
Security Principles24%The largest domain and the most definitional. Confidentiality, integrity, availability, AAA, non-repudiation, privacy, the three control categories, and the Code of Ethics are all learnable from the outline itself, which makes this the cheapest domain to score fully.
Networking and Cloud Security Concepts21.3%The second largest domain and the one that gained the most new material in 2026. Cloud characteristics, service and deployment models, the shared security model, zero trust, and micro-segmentation are all new bullets, so candidates using older material lose points here first.
Identity And Access Management Concepts20%Access control models, least privilege, and separation of duties were already tested, and the 2026 outline added the full identity lifecycle from role definition through deprovisioning plus IAM frameworks and tools. The lifecycle sequence is a reliable question format.
Security Governance17.3%An entirely new domain name in 2026. GRC purpose and frameworks, security awareness, organisational culture, and measurement through key metrics, key risk indicators, dashboards, and score cards are unfamiliar to anyone who studied the 2022 outline.
Security Operations and Incident Response17.3%The most rewritten domain. Threat actors, cyber threat intelligence, threat frameworks, event triage, incident response exercises, asset lifecycle management, and the blue, purple, and red teaming distinction were either new or expanded in 2026.
Cloud shared responsibility modelWithin 21.3%A named sub-objective under cloud security and a favourite question shape: a scenario names a task and asks whether the provider or the customer owns it. One table learned properly answers several items.
The ISC2 Code of EthicsWithin 24%Named explicitly in Domain 1 alongside due care and due diligence, and required again when you submit the certification application. The four canons have a defined order and questions test which canon applies.
Encryption and hashingWithin 17.3%Symmetric, asymmetric, hashing, and quantum-resistant cryptography sit under data security in Domain 5. The distinctions are factual and the 2026 addition of quantum-resistant cryptography signals fresh items in the pool.

The numbers

U.S. $199

Exam fee, Americas and Asia Pacific

Source: ISC2, exam pricing page

700 out of 1,000 points

Passing grade

Source: ISC2, CC Certification Exam Outline effective September 1, 2026

2 hours maximum, 100 to 125 items

Exam length and item count

Source: ISC2, CC Certification Exam Outline effective September 1, 2026

More than 65,000

Certifications earned through the free programme

Source: ISC2, One Million Certified in Cybersecurity page

65 percent employed in cybersecurity, 22 percent in IT roles

CC holders working in cybersecurity roles

Source: ISC2 survey data cited on the One Million Certified in Cybersecurity page

U.S. $50

Annual maintenance fee for CC-only members

Source: ISC2, Annual Maintenance Fees overview

24 / 17.3 / 20 / 21.3 / 17.3 percent

Domain weights, outline effective September 1, 2026

Source: ISC2 Insights, What's New for Entry-Level Cybersecurity, August 6, 2026

30, then 60, then 90 test-free days; 4 attempts per 12 months per programme

Retake waits and attempt cap

Source: ISC2, Computerized Adaptive Testing FAQ

If you fail

Wait before retaking

30 test-free days after the first attempt, 60 test-free days after the second, and 90 test-free days after the third and every attempt after that

Attempt limit

Up to 4 attempts within a 12-month period for each ISC2 certification programme

Retake fee

The full exam fee again, U.S. $199 in the Americas and Asia Pacific, unless you purchased Exam Peace of Mind Protection which includes two attempts inside a 180-day window

Rescheduling an appointment costs U.S. $50 and cancelling costs U.S. $100. A standard exam purchase must be scheduled and taken within 365 days; a Peace of Mind purchase shortens that window to 180 days for both attempts. Failing candidates receive a proficiency level for each domain at the test centre, which is the only diagnostic ISC2 provides for planning a retake.

Exam Domains & Topics

Security Principles
24%

The foundation domain and the largest single block on the exam. It covers confidentiality, integrity, and availability, then adds authentication, authorization, and accounting as a core concept, plus non-repudiation and privacy. It also covers the risk management lifecycle, governance concepts including regulations and frameworks, the three control categories, and professional conduct.

Key Topics to Master:

  • Confidentiality, integrity, and availability
  • Authentication, Authorization, Accounting (AAA)
  • Non-repudiation and privacy
  • Risk management lifecycle and processes
  • Regulations and laws, frameworks and guidelines
  • Policies, standards such as ISO and CIS, and procedures
  • Technical, administrative, and physical controls
  • Due care and due diligence
  • The ISC2 Code of Ethics
Security Governance
17.3%

New in the September 1, 2026 outline, replacing the old Business Continuity, Disaster Recovery and Incident Response domain. The emphasis moved from continuity planning to governance, risk, and compliance, organisational security awareness, and measuring how well a security programme performs. Business continuity and disaster recovery survive here as part of redundancy rather than as the main subject.

Key Topics to Master:

  • Purpose and importance of Governance, Risk, and Compliance
  • GRC frameworks and tools
  • Redundancy concepts
  • Business continuity
  • Disaster recovery
  • Organisational culture and security leadership
  • Social engineering, password protection, and phishing awareness
  • Key metrics and Key Risk Indicators
  • Dashboards, score cards, and reports
Identity And Access Management (IAM) Concepts
20%

The former Access Controls Concepts domain, broadened to cover identity as a whole. Classic access control principles remain, but the outline now runs the full identity lifecycle from role definition through provisioning, review, and deprovisioning, and adds IAM frameworks and tools. Physical and logical access controls are both examined.

Key Topics to Master:

  • Identity lifecycle: roles definition, provision, review, deprovision
  • IAM frameworks and tools
  • Principle of Least Privilege
  • Separation of Duties
  • Access control models
  • Discretionary, mandatory, and role-based access control
  • Physical access controls and monitoring
  • Privileged accounts and service accounts
Networking and Cloud Security Concepts
21.3%

The old Network Security domain with a cloud section bolted on and a stronger architecture focus. Traditional networking still appears through the OSI and TCP/IP models, IPv4 and IPv6, VPNs, firewalls, wireless, and embedded systems. The new material is segmentation, defence in depth, zero trust, and the cloud characteristics, service models, deployment models, and shared responsibility model.

Key Topics to Master:

  • OSI model and TCP/IP model
  • IPv4, IPv6, and VPNs
  • Firewalls, ports, and applications
  • Wi-Fi and Bluetooth security
  • Embedded systems, industrial control systems, and the Internet of Things
  • Network segmentation, firewall zones, VLANs, and micro-segmentation
  • Defence in depth and zero trust
  • Cloud characteristics including elasticity and measured service
  • Cloud service models and deployment models
  • Shared security model roles and responsibilities
Security Operations and Incident Response
17.3%

The most heavily rewritten domain in the 2026 outline. Data security now includes masking, sanitisation, and quantum-resistant cryptography. Security operations added threat actors, cyber threat intelligence, threat frameworks, and event triage. Incident response moved here from the old Domain 2, and asset protection and security testing round the domain out.

Key Topics to Master:

  • Data handling: classification, labelling, masking, sanitisation
  • Symmetric and asymmetric encryption, hashing, quantum-resistant cryptography
  • Logging and monitoring security events
  • Security event triage, prioritisation, and correlation
  • Threat actor types and motivations
  • Cyber threat intelligence and threat frameworks
  • Incident Response Plan implementation
  • Incident response exercises including tabletop testing
  • Asset lifecycle management and end-of-life software
  • Configuration and change management
  • Blue, purple, and red teaming
  • Vulnerability scanning, static and dynamic analysis, threat modelling
  • Physical penetration testing including phishing and tailgating

Recommended Study Plan

Week 1: Set the baseline against the correct outline
4-5 hours
  • 1Download the CC exam outline with the effective date of September 1, 2026 and print the domain list
  • 2Check that any course you plan to use teaches Security Governance and IAM, not the 2022 domain names
  • 3Write the five domain names and weights on one card and keep it visible
  • 4Read Domain 1 sub-objectives 1.1 to 1.5 in full and mark every term you cannot define
  • 5Read the ISC2 Code of Ethics preamble and four canons
Week 2: Security Principles part one
5-6 hours
  • 1Define confidentiality, integrity, and availability with one real example each
  • 2Learn authentication, authorization, and accounting as three separate steps
  • 3Explain non-repudiation using a digital signature example
  • 4Distinguish privacy from confidentiality in writing
  • 5Answer 20 practice questions on Domain 1 concepts only
Week 3: Risk management, governance concepts, and controls
6 hours
  • 1Walk the risk management lifecycle from identification through treatment to monitoring
  • 2Learn the four risk treatment options and a scenario that fits each
  • 3Separate regulations and laws from frameworks, policies, standards, and procedures
  • 4Sort 15 example controls into technical, administrative, and physical
  • 5Write one sentence each on due care and due diligence
Week 4: Security Governance
6 hours
  • 1Explain what governance, risk, and compliance means and why an organisation invests in it
  • 2List three GRC frameworks and what each is used for
  • 3Learn redundancy concepts and where business continuity and disaster recovery now sit
  • 4Compare recovery time objective and recovery point objective with a worked example
  • 5Learn key metrics, key risk indicators, dashboards, score cards, and reports as distinct outputs
Week 5: Security awareness and identity lifecycle
6 hours
  • 1List the common social engineering techniques and the control that counters each
  • 2Describe how organisational culture affects security outcomes
  • 3Walk the identity lifecycle from role definition to deprovisioning and note what goes wrong at each step
  • 4Learn why deprovisioning failures are a recurring audit finding
  • 5Answer 20 practice questions on Domains 2 and 3
Week 6: Access control models and logical controls
6 hours
  • 1Compare discretionary, mandatory, and role-based access control on who decides permissions
  • 2Apply least privilege and separation of duties to a payroll scenario
  • 3Learn the physical access controls the outline names, including monitoring
  • 4Explain how privileged and service accounts differ from ordinary user accounts
  • 5Draw the difference between identification, authentication, and authorization
Week 7: Networking fundamentals
6-7 hours
  • 1Learn the seven OSI layers and map the TCP/IP model onto them
  • 2Learn the common port numbers and the protocols that use them
  • 3Compare IPv4 and IPv6 addressing at a level you can describe out loud
  • 4Explain what a VPN protects and what it does not
  • 5Describe how a firewall decides to allow or block traffic
Week 8: Network architecture and wireless
6-7 hours
  • 1Explain segmentation using firewall zones, VLANs, and micro-segmentation
  • 2Describe defence in depth with at least four layers named
  • 3State the zero trust assumption in one sentence and what it replaces
  • 4Learn the security concerns specific to Wi-Fi and Bluetooth
  • 5List why industrial control systems and IoT devices are difficult to patch
Week 9: Cloud security
6-7 hours
  • 1Learn the five cloud characteristics named in the outline
  • 2Compare the cloud service models on what the customer still manages
  • 3Compare public, private, hybrid, and community deployment models
  • 4Draw the shared security model as a table and mark responsibility per row
  • 5Answer 25 practice questions on Domain 4
Week 10: Data security and cryptography
6 hours
  • 1Learn data classification and labelling, then masking and sanitisation
  • 2Compare symmetric and asymmetric encryption on key handling and speed
  • 3Explain what hashing provides that encryption does not
  • 4Read an overview of quantum-resistant cryptography and why it is now in the outline
  • 5Learn which control protects data at rest, in transit, and in use
Week 11: Security operations and threat intelligence
6 hours
  • 1Explain logging and monitoring, and what a SIEM correlates
  • 2Walk a security event through triage, prioritisation, and correlation
  • 3Learn threat actor types and their motivations
  • 4Describe what cyber threat intelligence adds to raw log data
  • 5Name one threat framework and describe what it maps
Week 12: Incident response, asset protection, and testing
6-7 hours
  • 1Learn the phases of an incident response plan in order
  • 2Explain what a tabletop exercise tests that a technical test does not
  • 3Describe asset lifecycle management and the risk of end-of-life software
  • 4Separate configuration management from change management
  • 5Compare blue, purple, and red teaming, then vulnerability scanning against penetration testing
Week 13: Full-length practice and weak-domain repair
7-8 hours
  • 1Sit a timed 125-item practice test in one sitting without pausing
  • 2Score it by domain and rank the five domains worst to best
  • 3Spend two study sessions on the weakest domain and one on the second weakest
  • 4Re-read every sub-objective in the outline and confirm you can speak to each bullet
  • 5Practise answering without going back, since the real exam does not allow item review
Week 14: Logistics and final review
5-6 hours
  • 1Confirm the first and last name on your Pearson VUE registration matches your primary ID exactly
  • 2Gather a primary photo and signature ID and a secondary signature ID
  • 3Locate the test centre and plan to arrive 30 minutes before the appointment
  • 4Sit one final practice test and review only the items you got wrong
  • 5Re-read the ISC2 Code of Ethics canons the night before

Ready to pass Certified in Cybersecurity (CC)?

Get 500+ practice questions, video walkthroughs, and a pass guarantee.

94% pass rate on first attempt
$100$50

Best Study Resources

CC Certification Exam Outline, effective September 1, 2026

Official exam outline

The eight-page PDF that defines the exam. It carries the five domain names, the weights, every sub-objective, and the CAT format details. If a study resource does not match this document, it is teaching the retired 2022 outline.

Free

Official ISC2 CC Online Self-Paced Training

Official course

ISC2's own course, sold on its own or bundled with an exam. Bundles with an exam give a 365-day exam window and one attempt, or a 180-day window and two attempts with Peace of Mind Protection.

Paid, sold in 90-day and 180-day access options

ISC2 CC self-study resources hub

Official study tools

ISC2's collection of study aids for CC, including the exam outline and supporting material for candidates who prepare without a course.

Free

ISC2 supplementary references list

Official reading list

The reference list ISC2 names in the exam outline itself, pointing candidates to source material that maps to the outline's sub-objectives.

Free

ISC2 Computerized Adaptive Testing FAQ

Official policy page

Explains how the item selection algorithm works, why the exam can end anywhere between 100 and 125 items, the three scoring rules, and why no numerical score is reported. Read it before your first practice test so the format does not surprise you.

Free

ISC2 exam day guidance

Official policy page

Lists the two forms of identification required, the palm vein scan, the June 2026 infrared and metal detection screening, the three-minute non-disclosure agreement window, and the rules for arriving late.

Free

ISC2 Insights article on the updated CC exam

Official article

ISC2's own side-by-side table of the 2025 and 2026 domain names and weights, with a paragraph on what changed inside each domain. The fastest way to see what is new if you started studying before September 2026.

Free

ISC2 exam pricing page

Official pricing

Current CC fee by region, plus the reschedule fee of U.S. $50 and the cancellation fee of U.S. $100, with the sterling and euro equivalents. Pricing and tax follow the location where the exam is administered.

Free to view

ISC2 Exam Peace of Mind Protection

Exam bundle

An exam purchase with two attempts included in the price. The exam window shortens to 180 days from purchase, and both attempts must fit inside that window while still respecting the retake waiting periods.

Paid, priced above the standard exam

Common Mistakes to Avoid

Studying the 2022 domain list because a free course still teaches it

The outline changes on September 1, 2026, and from that date Business Continuity, Disaster Recovery and Incident Response is no longer a domain. Check that your material covers Security Governance and Identity and Access Management Concepts by name, and that Domain 5 includes threat intelligence and incident response.

Assuming the free One Million Certified in Cybersecurity course and exam are still available

ISC2 closed new enrolments on May 20, 2026. Only codes issued before then are still usable, and they must be used to schedule and sit an exam by December 31, 2026. A new candidate pays U.S. $199.

Planning to flag hard items and return to them

CC is adaptive and item review is not permitted. Once you finalise an answer, it is locked. Read each item completely the first time, make your decision, and move on, because there is no second pass.

Panicking because every question feels difficult

ISC2 states that the algorithm targets items you have roughly a 50 percent chance of answering correctly, so both strong and weak candidates find the later items hard. Difficulty during the exam carries no information about your result.

Rushing to finish at 100 items

The exam ends when the algorithm reaches 95 percent confidence, not when you reach a target count. Candidates who pass at exactly 100 items proved proficiency across all domains; going past 100 simply gives the algorithm more evidence. Speed does not help.

Running out of time before answering 100 items

If you do not answer 75 operational items and 25 pretest items inside the two hours, ISC2 automatically fails the exam. Breaks count against the two hours. Keep a pace of roughly 70 seconds per item and check the clock every 20 items.

Treating cloud security as optional because CC is entry level

Cloud security is a named sub-objective inside Domain 4, which carries 21.3 percent of the exam. The outline asks for cloud characteristics, service models, deployment models, and the shared security model, so learn all four lists rather than one.

Skimming the ISC2 Code of Ethics

The Code of Ethics is a named bullet in Domain 1, and you must also confirm you will abide by it to complete the certification application. Learn the four canons and their order, because questions ask which canon applies to a described situation.

Registering with a name that does not match your ID

The first and last name on your ID must exactly match your Pearson VUE registration. Names can be updated up to 48 hours before the appointment and cannot be changed at the test centre. A mismatch is recorded as a no-show and forfeits the fee.

Passing the exam and then doing nothing

Passing does not make you certified. Submit the certification application at the ISC2 endorsement portal within nine months of the exam pass date, confirm the Code of Ethics, then pay the U.S. $50 annual maintenance fee to start your membership cycle.

Exam Day Tips

  • 1

    Arrive at the test centre at least 30 minutes before your appointment; arriving within 15 minutes of the start time counts as late and you may forfeit your seat.

  • 2

    Bring two forms of identification: a primary ID with photograph and signature, and a secondary ID with a signature, both unexpired.

  • 3

    Expect a palm vein scan at check-in and again before and after every break.

  • 4

    Since June 2026, Pearson may screen you with infrared and metal detection wands, so allow extra time at check-in.

  • 5

    Candidates in India must present a physical PVC Aadhaar card; laminated paper versions are refused.

  • 6

    You have three minutes at your seat to read and accept the non-disclosure agreement, and refusing it forfeits the fee.

  • 7

    Plan your pace around 100 items in 120 minutes and check the clock every 20 items, because breaks come out of the same two hours.

  • 8

    Answer each item as if it counts, since 25 of the items are unscored pretest items and you cannot tell which.

  • 9

    Ask the test administrator for earplugs if keyboard noise from nearby candidates distracts you.

  • 10

    Your proctor gives an unofficial result at checkout, and failing candidates receive proficiency levels by domain to guide a retake.

Career Paths & Salary Ranges

IT support or service desk analyst moving into security

BLS reports a May 2024 median annual wage of $61,550 for computer support specialists. CC is designed for exactly this transition, and the Security Operations domain covers the triage and logging work a service desk analyst is first asked to take on.

$61,550 median

Entry-level security operations centre analyst

BLS reports that the lowest 10 percent of information security analysts earned less than $69,660 in May 2024. Tier one SOC work is event triage, prioritisation, and escalation, which are named sub-objectives in Domain 5 of the 2026 outline.

Near the $69,660 tenth percentile for information security analysts

Network or systems administrator with security duties

BLS reports a May 2024 median annual wage of $96,800 for network and computer systems administrators. Domain 4 at 21.3 percent covers the segmentation, zero trust, and cloud shared responsibility material these roles apply daily.

$96,800 median

Information security analyst

BLS reports a May 2024 median annual wage of $124,910 for information security analysts and projects 29 percent employment growth from 2024 to 2034, against 3 percent for all occupations. CC is the on-ramp; most postings expect further certification and a few years of experience.

$124,910 median

Senior security analyst or GRC specialist

BLS reports that the highest 10 percent of information security analysts earned more than $186,420 in May 2024. The Security Governance domain added at 17.3 percent in 2026 introduces the GRC vocabulary that separates a governance track from a purely technical one.

Above the $186,420 ninetieth percentile at the top end

Prerequisites & Requirements

  • No work experience in cybersecurity is required. ISC2 states there are no specific prerequisites to take the CC exam.
  • No formal educational diploma or degree is required, though ISC2 recommends basic information technology knowledge.
  • You must be at least 16 years old to sit an ISC2 examination.
  • Candidates aged 16 or 17 must be accompanied to the test centre by a parent or guardian and must present one valid photo ID that includes their name; a school ID is acceptable as primary ID for minors.
  • Two forms of identification at the test centre: a primary ID with photograph and signature, and a secondary ID with signature, neither expired.
  • After passing, you submit a certification application within nine months of the exam pass date and confirm you will abide by the ISC2 Code of Ethics. Full endorsement by an existing ISC2 member is not required for CC.
  • You must pay the first annual maintenance fee of U.S. $50 to begin your membership cycle.

Frequently Asked Questions

How much does the ISC2 CC exam cost?

ISC2 lists standard registration at U.S. $199, EUR 191.04 across EMEA, and GBP 161.19 in the United Kingdom. Pricing and tax follow the location where the exam is administered, and Pearson VUE confirms the local currency at registration.

Is the free One Million Certified in Cybersecurity exam still available?

No. ISC2 concluded new enrolments on May 20, 2026 after the programme passed one million enrolments. Candidates who already hold an unexpired exam code may still schedule and sit the exam until December 31, 2026. Everyone else pays the standard U.S. $199 fee.

What changes on the CC exam on September 1, 2026?

The five domains are renamed and reweighted for the first time since CC launched in August 2022. Business Continuity, Disaster Recovery and Incident Response becomes Security Governance at 17.3 percent, Access Controls Concepts becomes Identity and Access Management Concepts at 20 percent, Network Security becomes Networking and Cloud Security Concepts at 21.3 percent, Security Operations becomes Security Operations and Incident Response at 17.3 percent, and Security Principles moves from 26 percent to 24 percent. Book on or before August 31, 2026 and you sit the 2022 outline instead.

What is the passing score for CC?

700 out of 1,000 points. ISC2 does not report a numerical score to candidates. You receive a pass or fail result only, and failing candidates additionally receive a proficiency level for each domain.

How many questions are on the CC exam?

Between 100 and 125 items, including 25 unscored pretest items. The exam ends as soon as the algorithm can place your ability estimate above or below the pass point with 95 percent confidence, which is why the count varies by candidate.

How long is the CC exam?

Two hours maximum. There is no minimum administration time, so candidates may finish sooner. ISC2 does not limit breaks, but every break is counted inside the two hours.

What happens if I fail the CC exam?

You may retest after 30 test-free days following a first attempt, after 60 test-free days following a second, and after 90 test-free days following a third and every attempt after that. You may attempt an ISC2 exam up to four times in a 12-month period for each certification programme, and you pay the fee again unless you bought Peace of Mind Protection.

Can I take the CC exam online at home?

No. ISC2 exams are available exclusively through Pearson Professional Centers and ISC2-authorised Pearson VUE Select Test Centers. The exam outline lists Pearson VUE Testing Center as the only delivery channel.

What identification do I need on exam day?

Two unexpired forms: a primary ID containing a photograph and a signature, and a secondary ID containing a signature. The first and last name must exactly match your Pearson VUE registration. Candidates in India must present a physical PVC Aadhaar card rather than a laminated paper one.

What can I take into the exam room?

Nothing. The ISC2 Exam Agreement prohibits phones, recording devices, and other electronic devices. Since June 2026 Pearson has run additional screening with infrared and metal detection wands to detect covert recording devices. Personal belongings are stored outside the testing room.

Can I change an answer after I submit it?

No. Because the difficulty of each item depends on your previous responses, item review is not permitted on a CAT exam. Once you finalise an answer it cannot be reviewed or changed.

How do I request exam accommodations?

ISC2 handles accommodations through Pearson VUE and states that exceptions to the maximum administration time are provided only to candidates with medical accommodations pre-approved by ISC2. Request accommodations before scheduling rather than at the test centre.

When do I get my result?

Immediately after finishing. The Pearson VUE proctor gives an unofficial result at checkout and ISC2 emails the official result. ISC2 warns that where test volumes are low for a form, results can be delayed roughly six to eight weeks while the psychometric analysis is completed.

Do I need to be endorsed like a CISSP candidate?

No. ISC2 states that CC does not require the full endorsement process. You still submit a certification application within nine months of the exam pass date and confirm that you will abide by the ISC2 Code of Ethics.

How do I keep the certification active?

Earn 45 CPE credits across your three-year certification cycle and pay the annual maintenance fee. For members who hold only CC, the fee is U.S. $50 a year, due on the anniversary of achieving the credential.

What happens if I miss CPE credits or the maintenance fee?

The certification is suspended, and ISC2 gives a 90-day grace period from the end of the certification cycle to submit outstanding CPE credits and past-due fees. Suspension can last up to two consecutive years; after that membership is terminated and reinstatement requires retaking and passing the exam.

What is the CC pass rate?

ISC2 does not publish a pass rate for CC or for any of its certification exams. ISC2 has published participation numbers for the One Million Certified in Cybersecurity programme, reporting more than 570,000 people using the course and more than 65,000 earning the certification, but it has never released a pass percentage.

How does CC compare to CompTIA Security+?

Both target entry-level candidates and both are ISO/IEC 17024 accredited. CC costs U.S. $199, runs adaptively for up to two hours with 100 to 125 items at Pearson VUE test centres only, and is maintained with 45 CPE credits over three years plus a U.S. $50 annual fee. Compare those specifics against the CompTIA figures at the time you book, since CompTIA revises both price and exam version on its own cycle.

How does CC compare to SSCP and CISSP?

CC has no experience requirement and costs U.S. $199. SSCP costs U.S. $249 and requires one year of paid work experience in one or more of its domains. CISSP costs U.S. $749 and requires five years of paid work experience in two or more of its eight domains. All three now use adaptive testing.

In which languages is the CC exam offered?

English, Chinese, Japanese, German, and Spanish, all in adaptive format. ISC2 notes that Chinese-language CC exams are only available during selected appointment windows, so check availability before planning a date.

50% OFF

Pass Certified in Cybersecurity (CC) — Guaranteed

94% pass rate on first attempt

500+ Real QuestionsUpdated weekly
Video Walkthroughs20+ hours
Pass or Full RefundGuaranteed
Lifetime AccessFree updates
SAVE $50
$50
$10050% OFF

One-time • Lifetime access

Secure Instant
4.9/5 (2,847 reviews)
30-Day Guarantee — Pass or get 100% refund