Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Certified in Cybersecurity (CC)
Certification Explained.

Everything you need to know about ISC2's entry-level certification as of 2026, built around the refreshed exam outline that took effect September 1, 2026. The five domains and their new weights, the adaptive exam format, why there is no experience requirement, the jobs it opens, DoD 8140 status, and how CC compares to Security+ and SSCP.

CC_FAST_FACTS
Issuer: ISC2
Exam: 100 to 125 questions, 2 hours
Passing Score: 700 / 1000
Experience: None required
DoD 8140 Approved
5 CC Domains NO Experience Required 100-125 Exam Questions 2-HOUR Adaptive Exam SINCE 2022 ISC2 Issued
OUTLINE EFFECTIVE SEPT 1, 2026
Overview

What Is the Certified in Cybersecurity (CC)?

CC is ISC2's entry-level certification, launched in August 2022 for people who want into cybersecurity and have no security experience to show yet.

It is the only ISC2 credential with no work experience requirement and no endorser. Every other ISC2 certification, CISSP and SSCP included, needs a sponsor who is already an ISC2 member to vouch for your experience. For CC you sit the exam, complete the application yourself, agree to the ISC2 Code of Ethics, and you are certified. That is the whole point of it: the barrier is the exam, not your resume.

The exam outline changed on September 1, 2026, the first content refresh since launch. It still has five domains, but three of them were renamed and rebuilt: governance replaced business continuity, access controls widened into identity and access management, and cloud security joined the networking domain. AI concepts now run through all five. The credential is ANAB-accredited under ISO/IEC 17024 and approved under DoD 8140. CC is issued and maintained by ISC2.

2022 First Administered
5 Domains
None Experience
The CC Domains

Five Domains, Effective September 1, 2026

01

Security Principles

CIA triad, AAA, risk management, governance and the Code of Ethics. The heaviest domain at 24%.

02

Security Governance

GRC planning, business continuity and disaster recovery, awareness, and security metrics. 17.3% of the exam.

03

Identity and Access Management

Identity lifecycle, least privilege, separation of duties and access control models. 20% of the exam.

04

Networking and Cloud Security

OSI and TCP/IP, firewalls, segmentation, zero trust, and the cloud shared security model. 21.3% of the exam.

05

Security Operations and IR

Data handling, encryption, monitoring, threat intelligence, incident response and testing. 17.3% of the exam.

Why CC Matters

Why Is CC So Widely Recognized?

Four reasons a two-year-old entry-level credential got taken seriously as fast as it did.

No Experience, No Endorser

Every other ISC2 certification makes you find a sponsor who is already certified to attest to your work history. CC does not. There is no experience minimum and no Associate of ISC2 waiting room, because there is nothing to wait for. You pass, you attest to the Code of Ethics, you are a certified ISC2 member. For someone with no security job yet, that removes the one obstacle they cannot study their way past.

The ISC2 Name Behind It

CC comes from the body that runs the CISSP. That matters at the point where a hiring manager skims a resume: the issuer is already familiar. It also puts a beginner inside the ISC2 membership and CPE system from day one, on the same track that leads to SSCP and later CISSP.

Rebuilt for 2026

The September 1, 2026 outline swapped in governance, identity management and cloud security, and folded AI concepts into every domain. A four-year-old syllabus became a current one, which is the difference between a credential employers trust and one they discount.

DoD 8140 Approved

ISC2 lists CC as approved by the Department of Defense under DoD Manual 8140.03. That is unusual for an entry-level credential, and it is why CC turns up in contractor job postings that would otherwise ask for Security+.

Which DCWF work roles CC satisfies, and at what proficiency, is set by the DoD qualification matrix rather than by ISC2, and the matrix is revised periodically. We are not quoting a role count here for that reason. Check the current version at the DoD Cyber Exchange before relying on CC for a specific position.

DoDM 8140.03 Approved ANAB Accredited ISO/IEC 17024
Fast Facts

What Are the Key Facts About CC?

The certification, the exam, and what it takes to keep CC current, all against the outline ISC2 administers today.

01

The Certification

Certification Name
Certified in Cybersecurity (CC)
Issued By
ISC2
Exam Outline
Effective September 1, 2026
First Administered
August 2022
Prerequisites
None
Experience Required
None
Endorsement
No endorser; Code of Ethics attestation only
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Approved under DoDM 8140.03
02

Exam & Maintenance

Exam Format
Computerized Adaptive Testing (CAT)
Number of Items
100 to 125 questions
Item Types
Multiple choice plus advanced items
Exam Duration
2 hours maximum
Passing Score
700 out of 1000
Exam Cost
$199 USD (Americas)
Validity
3 years
CPE Requirement
45 CPEs over 3 years
Maintenance
$50 annual maintenance fee to ISC2

Exam pricing and tax vary by the region you test in. ISC2 delivers CC at Pearson VUE test centers in English, Chinese, Japanese, German and Spanish.

Going Deeper

What Comes After the CC?

CC proves you understand the vocabulary and the concepts. The next credential should prove you can do the work. These three are where most CC holders go next, usually within a year.

CompTIA Security+

The most requested entry credential in security job postings, and more technical than CC. It has no prerequisite either, so it is the usual second cert. Read what Security+ covers before you book it.

ISC2 SSCP

The ISC2 practitioner credential, seven domains against CC's five, and the natural next rung inside ISC2. It needs one year of full-time experience in a domain, so it lands about a year after your first security job. See what SSCP covers.

CompTIA CySA+

If the SOC is where you land, CySA+ is the analyst credential that follows Security+. It goes deep on detection, threat hunting and incident response. See what CySA+ covers.

Certification Roadmap

Where Does CC Fit in Your Career?

CC sits at the start. Nothing is required before it, which is the point, though general IT literacy makes the networking domain much easier. Everything after it assumes you have a job in the field.

STAGE 01

Optional Groundwork

Not required, but it helps

STAGE 02 You Are Here

First Credential

The way in

PRIMARY
CC
ISC2 ยท Certified in Cybersecurity
No Waiting Room
ISC2 ยท Full member on day one, no Associate step
STAGE 03

Build On It

Once you are working

Broad Baseline
Analyst and Beyond
Decision Point

Is CC Right For You?

With CC the first question answers itself, so the real work is in the second: should you spend your first certification budget here, or somewhere else.

Q1

Do You Qualify for CC?

Everyone

Yes. There Is No Gate.

No experience, no degree, no prerequisite cert.

CC is the only ISC2 certification with no work experience requirement. You do not need an IT job, a computer science degree, or another certification first. Register, sit the exam, pass it. The exam is the only gate, and that is deliberate: ISC2 built CC specifically for people the rest of its portfolio locks out.

After You Pass

One Form, No Sponsor

Certified, not Associate.

Other ISC2 exams leave you as an Associate of ISC2 until you find an endorser and clock the experience. CC does not work that way. You complete the application yourself, agree to the ISC2 Code of Ethics and privacy policy, pay the $50 annual maintenance fee, and you hold the full certification. No sponsor to chase.

Q2

Is CC the Right Certification for Your Goals?

CC Is a Strong Fit If...

  • You are changing careers into security and have nothing security-related on your resume yet
  • You are a student or recent graduate who needs one credible line on a first application
  • You work in IT support, help desk or administration and want to signal a move toward security
  • You want the lowest-cost credible starting point, at $199 rather than $439 for Security+
  • You want to be inside the ISC2 track early, with SSCP and eventually CISSP ahead of you
  • You need a DoD 8140 approved credential and are not yet ready for Security+

Consider Alternatives If...

  • You already hold Security+, because CC sits below it and adds little to your resume
  • You already work in a hands-on security role, where SSCP proves more and is only one year away
  • Your target job postings name Security+ specifically, which many federal and contractor roles still do
  • You want a technical, hands-on exam, since CC is conceptual and has no performance-based questions
  • You have no IT background at all and no time to build one, because the networking domain is 21.3% of the exam
  • You are expecting the certification alone to produce job offers, rather than to get you past a first filter
Career Paths

What Jobs Can You Get With CC?

CC maps to the first rung. These are the roles that hire people without a security history, where the credential does its work getting a resume read rather than closing the offer.

Security Operations

SOC Analyst, Tier 1

The front line of a security operations center. You triage alerts, escalate what matters, and close what does not. Domain 5 of the CC outline is essentially the job description: logging, monitoring, event triage and incident response.

Security Analysis

Junior Cybersecurity Analyst

The generalist entry role. You support vulnerability scanning, access reviews and policy work while you learn the environment. CC is often the credential that gets a resume past the first filter when there is no security history behind it.

IT Operations

IT Support with Security Duties

Help desk and desktop support roles increasingly carry security tasks: account provisioning, patching, phishing triage. CC formalizes what those people already do and is the usual first step out of support and into security.

Governance and Risk

Junior GRC Analyst

Compliance and audit support work. The 2026 outline made this a much better fit, because Domain 2 is now Security Governance and covers GRC planning, frameworks, and how organizations measure control effectiveness.

Operations

Security Operations Technician

Hands on the tooling: managing endpoint agents, firewall rules, and access requests. The networking and cloud content in Domain 4 maps directly to the daily work, from VLANs and firewall zones to shared responsibility in cloud.

Infrastructure

Junior Systems or Network Administrator

Administration roles where security is part of the remit. CC gives an admin the vocabulary and the framework to justify controls, and it is a common stepping stone to Security+ and then SSCP.

Entry-level security pay varies widely by region, clearance and prior IT experience. Our Security+ salary guide covers the same band of roles and cites its figures.

Comparison

How Does CC Compare to Security+ and SSCP?

These are the three credentials people weigh at the start of a security career. They are not interchangeable: one has no gate at all, one is the industry baseline, and one wants you already working.

  CC Security+ SSCP
Issuer ISC2 CompTIA ISC2
Level Entry, conceptual Baseline, technical Practitioner, hands-on
Domains 5 5 objective areas 7
Exam Format Adaptive, 100 to 125 items, 2 hrs Linear, up to 90 items, 90 min Adaptive, 100 to 125 items, 2 hrs
Experience None required None required, 2 yrs recommended 1 yr in one or more domains
Endorsement None, ethics attestation only None ISC2 member endorser required
Passing Score 700 / 1000 750 / 900 700 / 1000
Exam Cost $199 $439 $249
Renewal 45 CPEs over 3 years 50 CEUs over 3 years 60 CPEs over 3 years
DoD 8140 Approved Yes Yes Yes
Best For Career changers with no background The most-requested first credential People already in a security job

Prices are U.S. list prices and vary by region and tax. Security+ figures reflect the current SY0-701 exam. A common sequence is CC, then Security+ once you are working, then SSCP once you have the year of experience behind you.

Ready to Get Certified?

Train for CC with Training Camp.

Our official ISC2 CC boot camp covers all five domains in a one-day intensive, using ISC2 authorized courseware. Your $199 exam voucher is bundled into tuition, and a free retake guarantee is included if the first attempt does not go your way.

View Boot Camp
Dive Deeper

CC Articles and Guides.

Choosing a first credential, breaking into the field, DoD 8140, and what the entry-level roles pay.

Featured Certification Guide

ISC2 CC Certification Guide 2026: Exam Domains, Cost, and What It Is Worth

The long-form companion to this page. What the refreshed exam covers, what it costs, how long people actually study, and an honest read on what the credential does and does not do for a job search.

Read Article โ†’
Getting Started

Entry-Level Cybersecurity Certifications for Beginners

CC against the rest of the entry-level field, including Security+ and the vendor foundational certs. Useful if you have not decided which credential to lead with.

Read Article โ†’
Career Path

Getting Started in Cybersecurity: Entry Level Certifications and Career Paths

What the first two years in security actually look like, which roles hire people without a security background, and where a credential like CC helps most.

Read Article โ†’
DoD 8140

Which Certifications Qualify for DoD 8140 Work Roles? A DCWF Map

How the DoD Cyber Workforce Framework works, what element-level qualification means in practice, and where approved credentials sit in the current matrix.

Read Article โ†’
Salary and Demand

CompTIA Security+ Salary Guide

The closest thing to a pay benchmark for the roles CC opens, since Security+ and CC compete for the same entry-level jobs. Figures and sources are in the article.

Read Article โ†’
Study Prep

The Best Cybersecurity Certification Study Resources for Every Exam Level

Where to study, and how to tell whether a resource has been updated for a current exam outline. Worth reading before you buy anything for the CC.

Read Article โ†’
Comparison

Top 15 Cyber Security Certifications

The wider map. Where CC sits relative to Security+, SSCP, CySA+ and CISSP, and roughly how long it takes to move between them.

Read Article โ†’
Curriculum

Inside the Five CC Domains.

The CC Common Body of Knowledge is organized into five domains, each carrying its own weight on the exam. These are the domains and weights from the outline effective September 1, 2026. Click any domain for what it covers.

Domains 01-03

Principles to Identity
01 Security Principles 24%

The heaviest domain. Confidentiality, integrity and availability; authentication, authorization and accounting; non-repudiation and privacy. It also carries the risk management lifecycle, governance documents such as policies and standards, the three control types, and the ISC2 Code of Ethics. AI shows up here as data integrity against model poisoning and privacy in training data.

02 Security Governance 17.3%

New in the 2026 outline, replacing the old business continuity domain. Governance, risk and compliance planning and the frameworks behind it, then redundancy in the form of business continuity and disaster recovery, security awareness and social engineering, and how organizations measure whether security is working using key metrics, key risk indicators, dashboards and scorecards.

03 Identity and Access Management (IAM) Concepts 20%

Broader than the access controls domain it replaces. Identity lifecycle management covers defining roles then provisioning, reviewing and deprovisioning accounts, including the service accounts that AI tools and bots run on. Logical access controls cover least privilege, separation of duties, the access control models, and multi-factor authentication.

Domains 04-05

Networks to Operations
04 Networking and Cloud Security Concepts 21.3%

The OSI and TCP/IP models, IPv4 and IPv6, VPNs, firewalls, ports, wireless, and embedded systems such as ICS and IoT. Then architecture: segmentation, VLANs, micro-segmentation, defense in depth and zero trust. Cloud is now explicit here, covering the five cloud characteristics, service and deployment models, and the shared security model.

05 Security Operations and Incident Response 17.3%

Expanded well beyond the old operations domain. Data handling and encryption, including quantum resistant cryptography. Logging, monitoring, event triage, threat actors, cyber threat intelligence and threat frameworks. Incident response planning and tabletop exercises. Asset lifecycle and configuration management. Security testing from red, blue and purple teaming through vulnerability scanning and threat modeling.

Domains and weights reflect the ISC2 Certified in Cybersecurity Exam Outline effective September 1, 2026, the version ISC2 administers today. It replaced the outline CC launched with in August 2022, so study material that lists Business Continuity or Access Controls as a domain name is out of date.

Frequently Asked Questions

Common Questions About CC.

The questions candidates ask most often when researching the ISC2 Certified in Cybersecurity certification.

What is the ISC2 CC certification?

CC, or Certified in Cybersecurity, is ISC2's entry-level credential. It covers five domains of foundational security knowledge and is the only ISC2 certification with no work experience requirement, which makes it the one built for people who are not in security yet. ISC2 launched it in August 2022.

Who should get the CC?

CC is aimed at career changers, students and recent graduates, and IT people moving toward security. If you have zero security background, this is the credential designed for you. If you already work in a hands-on security role, SSCP or Security+ will do more for you than CC will.

Do you need experience to take the CC exam?

No. CC has no work experience requirement, and it does not need an endorser. Every other ISC2 certification requires a sponsor who is an ISC2 member in good standing to attest to your experience. For CC you complete the application yourself and agree to the ISC2 Code of Ethics and privacy policy, then you are certified.

How much does the CC exam cost in 2026?

ISC2 lists the CC exam at $199 USD in the Americas. Pricing and tax vary by the region you test in. On top of the exam you pay a $50 annual maintenance fee to ISC2 once you are certified. The exam fee does not include training or study materials, though boot camps commonly bundle the voucher into tuition.

Is the CC exam still free through One Million Certified in Cybersecurity?

No. ISC2 closed new enrollments in the One Million Certified in Cybersecurity program on May 20, 2026 after it passed its one million goal. If you were issued an exam code before that date and it has not expired, ISC2 says you can still sit the exam through December 31, 2026. For anyone starting now, CC is a paid exam at $199.

What is the CC exam like?

CC uses Computerized Adaptive Testing, with 100 to 125 items in a maximum of two hours. Expect multiple choice plus advanced item types. You need a scaled score of 700 out of 1000 to pass. The exam is delivered at Pearson VUE test centers and is available in English, Chinese, Japanese, German and Spanish.

What are the five CC domains?

Under the outline effective September 1, 2026 the five domains are Security Principles at 24 percent, Security Governance at 17.3 percent, Identity and Access Management (IAM) Concepts at 20 percent, Networking and Cloud Security Concepts at 21.3 percent, and Security Operations and Incident Response at 17.3 percent. Security Principles is the heaviest.

Which CC exam outline is current?

The outline in force took effect September 1, 2026. It is the first content refresh since CC launched in August 2022. Domain 2 changed from business continuity to Security Governance, Domain 3 widened from access controls to identity and access management, Domain 4 added cloud security, and Domain 5 absorbed incident response. AI concepts run through all five domains. Study material written for the older outline will not match what you sit.

How do I maintain my CC certification?

CC runs on a three-year cycle. You earn 45 Continuing Professional Education credits across the cycle, which ISC2 suggests spreading as 15 a year, and you pay a $50 annual maintenance fee on the anniversary of your certification date.

Is CC approved for DoD 8140?

Yes. ISC2 lists CC as approved by the Department of Defense under DoD Manual 8140.03. Which specific DoD Cyber Workforce Framework work roles it satisfies, and at what proficiency level, is set by the DoD 8140 qualification matrix rather than by ISC2, so check the current matrix at the DoD Cyber Exchange before you rely on it for a particular role.

What is the difference between CC and CompTIA Security+?

CC is lighter, cheaper and more conceptual. Security+ is broader, more technical and more widely demanded in job postings, particularly on the defense side. CC costs $199 against $439 for Security+, and it assumes no background at all where Security+ assumes about two years of IT. A common route is CC first to prove you are serious, then Security+ within the year.

Is CC worth it in 2026?

It is worth it if you are trying to get into security and have nothing on your resume yet. It is cheap, it has no gatekeeping, and it carries the ISC2 name. It is not worth it if you already hold Security+ or already work in security, because it sits below where you are. Treat CC as the first step, not the destination.

Get In Touch

Have Questions About CC?

Whether you're weighing your first certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    ISC2 CC Boot Camp 1-Day Boot Camp ยท Exam Voucher Included
    View Boot Camp