Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification

CGRC Certification: The ISC2 Credential for ATO and Authorization Work

M
Mike McNelis Training Camp
Published
Read Time 15 min read
CGRC Certification: The ISC2 Credential for ATO and Authorization Work

Somewhere in a federal program office right now, someone is on the fourth revision of a System Security Plan, chasing a control owner for evidence that a quarterly account review actually happened, and watching a POA&M closure date slide past. Their title is probably ISSO, Security Control Assessor, or Compliance Analyst. Nobody writes LinkedIn posts about that job. It is also the job that decides whether a system gets an Authorization to Operate or sits in limbo while the mission waits.

CGRC is the certification built specifically for that work. It is the ISC2 credential formerly known as CAP, the Certified Authorization Professional, renamed Certified in Governance, Risk and Compliance on February 15, 2023. The rename caused real confusion, because “GRC” sounds broad and generic while the exam itself is anything but. This piece covers what CGRC actually tests, what it costs, who it fits, and the several kinds of professional who should spend their money elsewhere.

CGRC is the only major ISC2 certification organized around a process rather than a body of topics. Its seven domains are seven sequential steps, and that changes how you have to study for it.


What Is the CGRC Certification?

CGRC is an ISC2 certification that validates your ability to take an information system through an authorization lifecycle and keep it compliant afterward. Scope the system, categorize it, select and tailor controls, implement them, get them assessed, package the results for a risk decision, and then maintain that posture through changes and audits until the system is decommissioned. If you have worked under the NIST Risk Management Framework, you just read the RMF steps in order.

The credential has been around far longer than the current name suggests. As CAP, it was the certification federal agencies and their contractors pointed to for authorization work going back to the mid 2000s. ISC2 changed the name in February 2023 and then refreshed the exam content with a new outline that took effect on June 15, 2024. That refresh matters more than the rename, and I will come back to why.

One thing to set straight early. CGRC is not a junior CISSP, and it is not a consolation prize for people who could not pass one. The two certifications answer different questions. CISSP is a breadth credential covering security as a profession across eight domains, and it is the one that gets a resume past a screen. What CGRC validates is narrower and more operational, which is whether you can run a system through authorization without the package coming back for rework.


Who Should Get the CGRC Certification?

CGRC fits people whose calendar is full of evidence requests, control assessments, and authorization milestones. That covers Information System Security Officers and Managers, security control assessors, third party assessment organization staff working FedRAMP packages, compliance and audit liaisons on the government side, and the contractor personnel who support all of them. Anyone whose deliverable is a document that an Authorizing Official has to sign is in the target audience.

There is a second group that gets overlooked. Plenty of people doing this work came in sideways, from system administration, program management, or contracts, and learned RMF on the job by copying whatever the last package looked like. They know their agency’s local practice cold and have never seen the framework described neutrally. CGRC study fills that gap fast, because the exam forces you to learn the process as the standard defines it rather than as your program office happens to run it.

Demand for the skill set is not speculative. In ISC2’s own workforce research, respondents ranked governance, risk and compliance second among the skills most in demand for security professionals looking to advance, behind only cloud security, at 35 percent. Hiring signals in the federal contracting space back that up, particularly for cleared candidates who can walk into an ATO effort without a six month ramp.

A note on salary claims. You will find articles quoting confident CGRC salary figures. Treat them carefully. ISC2 does not publish salary data broken out by CGRC holders, and the numbers floating around are usually scraped from job boards or borrowed from adjacent titles. Compensation for authorization work tracks clearance level, agency, and contract vehicle far more than it tracks this one credential. Ask the recruiter, not the internet.


CGRC Exam Format, Cost, and Experience Requirements

The CGRC exam is a linear, fixed form test of 125 questions with a three hour limit, delivered in English at Pearson VUE test centers. Of those 125 items, 100 are scored and 25 are unscored pretest questions seeded into the exam. Passing requires a scaled score of 700 out of 1000, which does not translate to a clean percentage of questions answered correctly. The United States exam fee is $599.

📋 CGRC at a Glance
EXPERIENCE

Two years cumulative, full time work in one or more of the seven domains. Part time work and internships can count. Pass without the experience and you become an Associate of ISC2 with three years to earn it.
RETAKES

ISC2 enforces waiting periods of 30 days after a first failure, 60 after a second, and 90 after any attempt beyond that, with a maximum of four attempts in any 12 month window. Every attempt costs full price.
MAINTENANCE

Three year cycle requiring 60 CPE credits, 45 of which must be Group A domain related activity. ISC2 suggests 20 credits a year to stay on pace.
ANNUAL FEE

$135 Annual Maintenance Fee. You pay one AMF no matter how many ISC2 certifications you hold, so adding CGRC to an existing CISSP costs nothing extra in yearly fees.

That AMF detail is worth acting on. If you already hold CISSP, CCSP, or SSCP, the recurring cost of adding CGRC is zero, and Group A credits you earn for one credential automatically apply to any other credential with a relevant domain. For a lot of federal practitioners, CGRC is the cheapest second certification they will ever hold. Full fee schedules and policies live on ISC2’s maintenance fee page.


What Are the Seven CGRC Domains and Their Weights?

The current outline took effect June 15, 2024 and carries these seven domains and weights.

Domain Weight What It Covers
1. Security and Privacy Governance, Risk Management, and Compliance Program 16% Framework principles, SDLC, information lifecycle, roles and responsibilities, and the regulatory set including FISMA, HIPAA, GDPR, PCI DSS, and FedRAMP.
2. Scope of the System 10% Describing the system and its boundary, identifying information types, and setting impact levels against FIPS or the equivalent international standard.
3. Selection and Approval of Framework, Security, and Privacy Controls 14% Baselines, inherited controls, overlays, tailoring, continuous monitoring strategy, and stakeholder agreement on control allocation.
4. Implementation of Security and Privacy Controls 17% Implementation strategy and funding, control types, compensating controls, and documenting residual risk in the POA&M and risk register.
5. Assessment/Audit of Security and Privacy Controls 16% Assessment planning, the interview, examine, and test methods, initial and final reporting, and assigning risk responses to findings.
6. System Compliance 14% Submitting the package for a decision, determining risk posture and residual risk, and documenting and communicating the compliance decision.
7. Compliance Maintenance 13% Change management, ongoing monitoring, incident response and contingency activity, recurring audits, and system decommissioning.

Compare that against the previous outline and the direction is clear. Domain 6, the authorization decision itself, jumped from 10 percent to 14 percent. Implementation gained a point, moving from 16 to 17. Continuous monitoring, now called Compliance Maintenance, dropped from 16 percent to 13, while scope and control selection each shed a point. ISC2 moved weight toward getting the package built and decided, and away from what happens after the signature.

The second change in that refresh is the one that catches American candidates. ISC2 rewrote the exam from a global perspective, so international terminology, frameworks, and regulations now sit alongside the federal ones. Read the official CGRC exam outline and you will find ISO/IEC standards, GDPR, PCI DSS, and CMMC named right next to FISMA and FIPS. A candidate who has spent a decade in RMF and speaks only RMF vocabulary can walk in fluent in the process and still lose points on the framing, because the question asks about a data protection impact assessment instead of a privacy impact assessment.


How Do the CGRC Domains Map to the NIST RMF?

Nearly one to one, which is the single most useful fact about studying for this exam. NIST SP 800-37 Revision 2 lays out seven RMF steps: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor. Line those up against the CGRC domains and they track in order, from Prepare at Domain 1 through Monitor at Domain 7.

Learn the framework and you have learned most of the exam blueprint. That is why studying CGRC out of order works so poorly compared to certifications where domains are independent topic buckets. Domain 5 questions assume you know what came out of Domain 3, because in real life an assessor cannot evaluate a control that was never selected or tailored. Candidates who jump around chasing weak areas tend to score worse than candidates who walk the lifecycle start to finish twice.

The distinction that decides a lot of questions. ISC2 wants you to keep the roles separate. A system owner is accountable for the system, while the ISSO runs the security work day to day. Assessors evaluate and report, and they do not fix what they find. Only the Authorizing Official accepts risk on behalf of the organization, and only that role can issue the authorization. When a scenario question feels like two answers are both technically correct, the tiebreaker is usually which role is permitted to take that action.


CGRC vs CISSP vs CRISC vs CISA: Which One Fits Your Role?

These four get compared constantly, usually by people who are actually asking which one their next employer wants to see. Here is the practical split.

Certification Body Core Question It Answers Experience
CGRC ISC2 Can you take a system through authorization and keep it compliant afterward? 2 years
CISSP ISC2 Do you understand security broadly enough to lead a program across eight domains? 5 years
CRISC ISACA Can you run enterprise IT risk and report it to the business in business terms? 3 years
CISA ISACA Can you audit IT controls and defend your findings to an audit committee? 5 years

The cleanest way to choose is to look at who reads your work product. Work that lands in front of an Authorizing Official inside a federal boundary points to CGRC. Reporting that goes to a board or an executive risk committee is CRISC territory, since that exam is built around communicating risk in business terms. For an audit committee or an external auditor, CISA is the credential they recognize on sight. CISSP sits above all three as the general credibility marker that gets you past the resume screen, which is why so many people in this space eventually hold two. Our breakdown of certifications for GRC careers goes deeper on the ISACA side of that decision.


Does CGRC Count for DoD 8140?

Yes, for specific work roles, and that qualifier carries all the weight. Under DoDM 8140.03 there is no such thing as a certification that covers you generally. Qualification is assigned per DCWF work role and per proficiency level, and CGRC appears as a foundational qualification option for roles on the governance and cyber enabler side rather than across the board. ISC2 also lists DoD 8140 approval among the things its maintenance fees support, which is why the credential stays current in the matrix.

Before you buy anything, pull your work role code off your position description and check it against the current matrix on the DoD Cyber Exchange. The matrix gets revised, and a certification that qualified at one proficiency level may not qualify at the one your contract requires. We walk through how to read that document in our DCWF work role map, and the same caution applies to contractors sorting out what their contracts actually require.


Who Should Skip CGRC?

Hands on engineers and analysts with no authorization work in their future. If your day is spent tuning detections, running scans, building pipelines, or responding to incidents, CGRC will feel like a documentation exam because that is largely what it is. The credential validates process discipline, not technical depth, and nothing on it will make you better at the console.

People early in a career should also wait. Two years of experience is the requirement for a reason, and the Associate of ISC2 path, while legitimate, puts a clock on you. Commercial sector professionals with no federal exposure are the third group to think twice. If your organization runs on ISO 27001 and SOC 2 and has never touched an ATO, the ISACA credentials or an ISO auditor track will carry more recognition with the people making hiring decisions around you. Recognition varies sharply by sector here, which is not something certification bodies advertise.


How to Study for the CGRC Exam

Start with SP 800-37 Revision 2 itself rather than a summary of it. Read the task descriptions inside each step, not just the step names, because the exam questions live at task level. Then read the current exam outline beside it and note every place ISC2 uses a term that is not the federal term you are used to. That reconciliation list becomes your highest value study asset, and most candidates never build one.

Next, work through one system end to end. Use one you support if you can, or construct a simple fictional one if you cannot, and write out the artifacts in sequence. Categorization memo. Control selection with a documented tailoring rationale. Implementation statements for a handful of controls in different families. Then an assessment plan with methods assigned, a POA&M entry carrying a realistic milestone, and a recommendation to the Authorizing Official. Doing this once teaches more than a hundred practice questions, because it forces you to notice how each artifact depends on the one before it, which is exactly what the scenario questions test. Practice questions are still useful afterward for pacing and for spotting where the ISC2 framing differs from yours. Most working practitioners need somewhere in the range of six to ten weeks at a few hours a week. Someone new to the framework should plan on considerably more.

If you want the compressed version of that with an instructor, our CGRC boot camp runs the same lifecycle sequence. Self study works fine for this exam, though, more so than for CISSP, because the source material is public and free.

One scheduling caution. ISC2 evaluates its exams on a three year cycle, and the current CGRC outline dates to June 2024. Check the outline page before you book rather than trusting any study guide, including this article, on the specifics.

🎯 The Short Version

CGRC is a narrow credential and that is its strength. It proves you can run the authorization lifecycle, which is a specific job that a lot of federal agencies and defense contractors need filled and struggle to fill well. Two years of experience, $599, seven domains that mirror the RMF steps in order, and a $135 annual fee you are probably already paying if you hold another ISC2 certification. For anyone whose work product ends with an Authorizing Official’s signature, it is the most direct credential available. Everyone else should spend the money somewhere closer to what they actually do. Check your DCWF work role code first, read SP 800-37 before any study guide, and confirm the current exam outline on ISC2’s site before you schedule.


Frequently Asked Questions About CGRC

Is CGRC the same as CAP?

Yes. ISC2 renamed the Certified Authorization Professional to Certified in Governance, Risk and Compliance on February 15, 2023. Anyone who held CAP holds CGRC, with no additional exam required. The exam content was later refreshed under a new outline effective June 15, 2024.

How much does the CGRC exam cost?

The United States exam fee is $599, with pricing varying by region. Beyond the exam, holders pay a $135 Annual Maintenance Fee, which covers every ISC2 certification you hold rather than each one separately.

Can I take the CGRC exam without two years of experience?

You can sit the exam without the experience. Passing makes you an Associate of ISC2, and you then have three years to accumulate the two years of cumulative full time work in one or more of the seven CGRC domains before the full certification is awarded.

Is CGRC harder than CISSP?

CGRC is narrower and generally considered less difficult than CISSP for candidates who work in authorization, because the scope is one process rather than eight domains. Candidates without hands on RMF experience often find it harder than expected, since the questions test sequence and role authority rather than definitions.

How many CPEs does CGRC require?

CGRC requires 60 CPE credits across a three year cycle, with 45 of those coming from Group A domain related activity. ISC2 suggests 20 credits per year to stay on pace, and Group A credits automatically apply across any other ISC2 certifications you hold with a relevant domain.

Does CGRC help outside the federal sector?

Less than it helps inside it. The June 2024 outline broadened the exam to cover ISO/IEC standards, GDPR, PCI DSS, and other international requirements, which improves its relevance in commercial compliance work. Name recognition among commercial hiring managers still trails ISACA credentials, so weigh it against CRISC or CISA if federal work is not in your plans.

What happens if I fail the CGRC exam?

ISC2 requires a 30 day wait after a first failed attempt, 60 days after a second, and 90 days after any attempt beyond that, capped at four attempts within any 12 month period. Each retake costs the full exam fee, so the waiting period is better spent rebuilding weak domains than rescheduling immediately.

Mike McNelis

CMO & Certification Guru | Training Camp

Mike McNelis is the CMO at Training Camp, where he combines a passion for technology with a hands-on approach to leadership. Beyond overseeing marketing strategy, Mike is actively involved in the technical side of the business — collaborating with clients, shaping learning solutions, and staying connected to the fast-changing world of IT and cybersecurity. He works closely with companies, government agencies, and individuals to help them achieve meaningful certification and workforce development goals.