Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about ISC2's entry-level certification as of 2026, built around the refreshed exam outline that took effect September 1, 2026. The five domains and their new weights, the adaptive exam format, why there is no experience requirement, the jobs it opens, DoD 8140 status, and how CC compares to Security+ and SSCP.
CC is ISC2's entry-level certification, launched in August 2022 for people who want into cybersecurity and have no security experience to show yet.
It is the only ISC2 credential with no work experience requirement and no endorser. Every other ISC2 certification, CISSP and SSCP included, needs a sponsor who is already an ISC2 member to vouch for your experience. For CC you sit the exam, complete the application yourself, agree to the ISC2 Code of Ethics, and you are certified. That is the whole point of it: the barrier is the exam, not your resume.
The exam outline changed on September 1, 2026, the first content refresh since launch. It still has five domains, but three of them were renamed and rebuilt: governance replaced business continuity, access controls widened into identity and access management, and cloud security joined the networking domain. AI concepts now run through all five. The credential is ANAB-accredited under ISO/IEC 17024 and approved under DoD 8140. CC is issued and maintained by ISC2.
CIA triad, AAA, risk management, governance and the Code of Ethics. The heaviest domain at 24%.
GRC planning, business continuity and disaster recovery, awareness, and security metrics. 17.3% of the exam.
Identity lifecycle, least privilege, separation of duties and access control models. 20% of the exam.
OSI and TCP/IP, firewalls, segmentation, zero trust, and the cloud shared security model. 21.3% of the exam.
Data handling, encryption, monitoring, threat intelligence, incident response and testing. 17.3% of the exam.
Four reasons a two-year-old entry-level credential got taken seriously as fast as it did.
Every other ISC2 certification makes you find a sponsor who is already certified to attest to your work history. CC does not. There is no experience minimum and no Associate of ISC2 waiting room, because there is nothing to wait for. You pass, you attest to the Code of Ethics, you are a certified ISC2 member. For someone with no security job yet, that removes the one obstacle they cannot study their way past.
The September 1, 2026 outline swapped in governance, identity management and cloud security, and folded AI concepts into every domain. A four-year-old syllabus became a current one, which is the difference between a credential employers trust and one they discount.
ISC2 lists CC as approved by the Department of Defense under DoD Manual 8140.03. That is unusual for an entry-level credential, and it is why CC turns up in contractor job postings that would otherwise ask for Security+.
Which DCWF work roles CC satisfies, and at what proficiency, is set by the DoD qualification matrix rather than by ISC2, and the matrix is revised periodically. We are not quoting a role count here for that reason. Check the current version at the DoD Cyber Exchange before relying on CC for a specific position.
The certification, the exam, and what it takes to keep CC current, all against the outline ISC2 administers today.
Exam pricing and tax vary by the region you test in. ISC2 delivers CC at Pearson VUE test centers in English, Chinese, Japanese, German and Spanish.
CC proves you understand the vocabulary and the concepts. The next credential should prove you can do the work. These three are where most CC holders go next, usually within a year.
The most requested entry credential in security job postings, and more technical than CC. It has no prerequisite either, so it is the usual second cert. Read what Security+ covers before you book it.
The ISC2 practitioner credential, seven domains against CC's five, and the natural next rung inside ISC2. It needs one year of full-time experience in a domain, so it lands about a year after your first security job. See what SSCP covers.
If the SOC is where you land, CySA+ is the analyst credential that follows Security+. It goes deep on detection, threat hunting and incident response. See what CySA+ covers.
CC sits at the start. Nothing is required before it, which is the point, though general IT literacy makes the networking domain much easier. Everything after it assumes you have a job in the field.
Not required, but it helps
The way in
With CC the first question answers itself, so the real work is in the second: should you spend your first certification budget here, or somewhere else.
No experience, no degree, no prerequisite cert.
CC is the only ISC2 certification with no work experience requirement. You do not need an IT job, a computer science degree, or another certification first. Register, sit the exam, pass it. The exam is the only gate, and that is deliberate: ISC2 built CC specifically for people the rest of its portfolio locks out.
Certified, not Associate.
Other ISC2 exams leave you as an Associate of ISC2 until you find an endorser and clock the experience. CC does not work that way. You complete the application yourself, agree to the ISC2 Code of Ethics and privacy policy, pay the $50 annual maintenance fee, and you hold the full certification. No sponsor to chase.
CC maps to the first rung. These are the roles that hire people without a security history, where the credential does its work getting a resume read rather than closing the offer.
The front line of a security operations center. You triage alerts, escalate what matters, and close what does not. Domain 5 of the CC outline is essentially the job description: logging, monitoring, event triage and incident response.
The generalist entry role. You support vulnerability scanning, access reviews and policy work while you learn the environment. CC is often the credential that gets a resume past the first filter when there is no security history behind it.
Help desk and desktop support roles increasingly carry security tasks: account provisioning, patching, phishing triage. CC formalizes what those people already do and is the usual first step out of support and into security.
Compliance and audit support work. The 2026 outline made this a much better fit, because Domain 2 is now Security Governance and covers GRC planning, frameworks, and how organizations measure control effectiveness.
Hands on the tooling: managing endpoint agents, firewall rules, and access requests. The networking and cloud content in Domain 4 maps directly to the daily work, from VLANs and firewall zones to shared responsibility in cloud.
Administration roles where security is part of the remit. CC gives an admin the vocabulary and the framework to justify controls, and it is a common stepping stone to Security+ and then SSCP.
Entry-level security pay varies widely by region, clearance and prior IT experience. Our Security+ salary guide covers the same band of roles and cites its figures.
These are the three credentials people weigh at the start of a security career. They are not interchangeable: one has no gate at all, one is the industry baseline, and one wants you already working.
| CC | Security+ | SSCP | |
|---|---|---|---|
| Issuer | ISC2 | CompTIA | ISC2 |
| Level | Entry, conceptual | Baseline, technical | Practitioner, hands-on |
| Domains | 5 | 5 objective areas | 7 |
| Exam Format | Adaptive, 100 to 125 items, 2 hrs | Linear, up to 90 items, 90 min | Adaptive, 100 to 125 items, 2 hrs |
| Experience | None required | None required, 2 yrs recommended | 1 yr in one or more domains |
| Endorsement | None, ethics attestation only | None | ISC2 member endorser required |
| Passing Score | 700 / 1000 | 750 / 900 | 700 / 1000 |
| Exam Cost | $199 | $439 | $249 |
| Renewal | 45 CPEs over 3 years | 50 CEUs over 3 years | 60 CPEs over 3 years |
| DoD 8140 Approved | Yes | Yes | Yes |
| Best For | Career changers with no background | The most-requested first credential | People already in a security job |
Prices are U.S. list prices and vary by region and tax. Security+ figures reflect the current SY0-701 exam. A common sequence is CC, then Security+ once you are working, then SSCP once you have the year of experience behind you.
Our official ISC2 CC boot camp covers all five domains in a one-day intensive, using ISC2 authorized courseware. Your $199 exam voucher is bundled into tuition, and a free retake guarantee is included if the first attempt does not go your way.
Choosing a first credential, breaking into the field, DoD 8140, and what the entry-level roles pay.
The long-form companion to this page. What the refreshed exam covers, what it costs, how long people actually study, and an honest read on what the credential does and does not do for a job search.
CC against the rest of the entry-level field, including Security+ and the vendor foundational certs. Useful if you have not decided which credential to lead with.
What the first two years in security actually look like, which roles hire people without a security background, and where a credential like CC helps most.
How the DoD Cyber Workforce Framework works, what element-level qualification means in practice, and where approved credentials sit in the current matrix.
The closest thing to a pay benchmark for the roles CC opens, since Security+ and CC compete for the same entry-level jobs. Figures and sources are in the article.
Where to study, and how to tell whether a resource has been updated for a current exam outline. Worth reading before you buy anything for the CC.
The wider map. Where CC sits relative to Security+, SSCP, CySA+ and CISSP, and roughly how long it takes to move between them.
The CC Common Body of Knowledge is organized into five domains, each carrying its own weight on the exam. These are the domains and weights from the outline effective September 1, 2026. Click any domain for what it covers.
The heaviest domain. Confidentiality, integrity and availability; authentication, authorization and accounting; non-repudiation and privacy. It also carries the risk management lifecycle, governance documents such as policies and standards, the three control types, and the ISC2 Code of Ethics. AI shows up here as data integrity against model poisoning and privacy in training data.
New in the 2026 outline, replacing the old business continuity domain. Governance, risk and compliance planning and the frameworks behind it, then redundancy in the form of business continuity and disaster recovery, security awareness and social engineering, and how organizations measure whether security is working using key metrics, key risk indicators, dashboards and scorecards.
Broader than the access controls domain it replaces. Identity lifecycle management covers defining roles then provisioning, reviewing and deprovisioning accounts, including the service accounts that AI tools and bots run on. Logical access controls cover least privilege, separation of duties, the access control models, and multi-factor authentication.
The OSI and TCP/IP models, IPv4 and IPv6, VPNs, firewalls, ports, wireless, and embedded systems such as ICS and IoT. Then architecture: segmentation, VLANs, micro-segmentation, defense in depth and zero trust. Cloud is now explicit here, covering the five cloud characteristics, service and deployment models, and the shared security model.
Expanded well beyond the old operations domain. Data handling and encryption, including quantum resistant cryptography. Logging, monitoring, event triage, threat actors, cyber threat intelligence and threat frameworks. Incident response planning and tabletop exercises. Asset lifecycle and configuration management. Security testing from red, blue and purple teaming through vulnerability scanning and threat modeling.
Domains and weights reflect the ISC2 Certified in Cybersecurity Exam Outline effective September 1, 2026, the version ISC2 administers today. It replaced the outline CC launched with in August 2022, so study material that lists Business Continuity or Access Controls as a domain name is out of date.
The questions candidates ask most often when researching the ISC2 Certified in Cybersecurity certification.
CC, or Certified in Cybersecurity, is ISC2's entry-level credential. It covers five domains of foundational security knowledge and is the only ISC2 certification with no work experience requirement, which makes it the one built for people who are not in security yet. ISC2 launched it in August 2022.
CC is aimed at career changers, students and recent graduates, and IT people moving toward security. If you have zero security background, this is the credential designed for you. If you already work in a hands-on security role, SSCP or Security+ will do more for you than CC will.
No. CC has no work experience requirement, and it does not need an endorser. Every other ISC2 certification requires a sponsor who is an ISC2 member in good standing to attest to your experience. For CC you complete the application yourself and agree to the ISC2 Code of Ethics and privacy policy, then you are certified.
ISC2 lists the CC exam at $199 USD in the Americas. Pricing and tax vary by the region you test in. On top of the exam you pay a $50 annual maintenance fee to ISC2 once you are certified. The exam fee does not include training or study materials, though boot camps commonly bundle the voucher into tuition.
No. ISC2 closed new enrollments in the One Million Certified in Cybersecurity program on May 20, 2026 after it passed its one million goal. If you were issued an exam code before that date and it has not expired, ISC2 says you can still sit the exam through December 31, 2026. For anyone starting now, CC is a paid exam at $199.
CC uses Computerized Adaptive Testing, with 100 to 125 items in a maximum of two hours. Expect multiple choice plus advanced item types. You need a scaled score of 700 out of 1000 to pass. The exam is delivered at Pearson VUE test centers and is available in English, Chinese, Japanese, German and Spanish.
Under the outline effective September 1, 2026 the five domains are Security Principles at 24 percent, Security Governance at 17.3 percent, Identity and Access Management (IAM) Concepts at 20 percent, Networking and Cloud Security Concepts at 21.3 percent, and Security Operations and Incident Response at 17.3 percent. Security Principles is the heaviest.
The outline in force took effect September 1, 2026. It is the first content refresh since CC launched in August 2022. Domain 2 changed from business continuity to Security Governance, Domain 3 widened from access controls to identity and access management, Domain 4 added cloud security, and Domain 5 absorbed incident response. AI concepts run through all five domains. Study material written for the older outline will not match what you sit.
CC runs on a three-year cycle. You earn 45 Continuing Professional Education credits across the cycle, which ISC2 suggests spreading as 15 a year, and you pay a $50 annual maintenance fee on the anniversary of your certification date.
Yes. ISC2 lists CC as approved by the Department of Defense under DoD Manual 8140.03. Which specific DoD Cyber Workforce Framework work roles it satisfies, and at what proficiency level, is set by the DoD 8140 qualification matrix rather than by ISC2, so check the current matrix at the DoD Cyber Exchange before you rely on it for a particular role.
CC is lighter, cheaper and more conceptual. Security+ is broader, more technical and more widely demanded in job postings, particularly on the defense side. CC costs $199 against $439 for Security+, and it assumes no background at all where Security+ assumes about two years of IT. A common route is CC first to prove you are serious, then Security+ within the year.
It is worth it if you are trying to get into security and have nothing on your resume yet. It is cheap, it has no gatekeeping, and it carries the ISC2 name. It is not worth it if you already hold Security+ or already work in security, because it sits below where you are. Treat CC as the first step, not the destination.
Whether you're weighing your first certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.