Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Certified Chief Information Security Officer
Certification Explained.

Everything you need to know about EC-Council's executive security certification as of 2026, covering the five domains, exam format, eligibility paths, career outcomes, DoD 8140 status, and how CCISO compares to CISSP and CISM. A complete reference guide for anyone weighing the CCISO or trying to understand what it covers.

CCISO_FAST_FACTS
Issuer: EC-Council
Exam: 150 questions, 2.5 hours
Passing Score: Form-based, 60 to 85%
Experience: 5 years in 3 of 5 domains
DoD 8140 Approved (11 DCWF roles)
5 CCISO Domains 150 Exam Questions 2.5-HOUR Exam 11 DCWF Work Roles SINCE 2011 EC-Council Issued
UPDATED 2026
The CCISO Domains

Five Domains of the Executive Seat

01

Governance, Risk, Compliance

Governance programs, regulatory compliance, and enterprise risk. The heaviest domain at 21% alongside Domain 3.

02

Controls and Audit Management

Designing security controls and running the audit process that proves they work.

03

Program Management and Operations

Running the security program: projects, people, budget, and operations.

04

Information Security Core Competencies

The technical breadth a CISO needs, viewed from the executive level.

05

Strategy, Finance, and Third-Party Management

Budgets, procurement, and vendor risk. The material other security certs skip.

Overview

What Is the Certified Chief Information Security Officer?

CCISO is EC-Council's executive security certification, launched in 2011 as the first program built specifically to produce top-level information security executives.

It validates the skills a CISO actually uses: setting governance, managing risk and audits, running a security program, holding the technical picture together, and owning the budget, vendors, and strategy behind it all. The program was written by sitting CISOs, and the exam tests executive judgment across scenarios rather than technical recall.

The credential is ANAB-accredited under ISO/IEC 17024, approved under DoD 8140 across eleven DCWF work roles, and gated behind a verified experience requirement that keeps it firmly in executive territory. CCISO is issued and maintained by EC-Council, the body behind the Certified Ethical Hacker program.

2011 First Administered
5 Domains
5 Yr Experience
Why CCISO Matters

Why Is CCISO the Executive Security Credential?

Four things that separate CCISO from every practitioner-level security certification on the market in 2026.

Built by CISOs, for the CISO Seat

CCISO was the first certification program aimed at producing top-level security executives. Its advisory board of sitting CISOs wrote the Body of Knowledge, the exam, and the training, and the credential is ANAB-accredited under the ISO/IEC 17024 personnel certification standard.

Finance and Procurement, Not Just Firewalls

Domain 5 covers strategic planning, budgeting, procurement, and third-party management, the material boards actually grill CISOs on. No other major security certification tests it at this depth.

The Step After CISSP and CISM

Most CCISO candidates already hold a senior credential and are moving up the org chart. Our CISSP vs CISM framework maps the leadership track that leads here.

DoD 8140 Approved

CCISO is an approved qualification under DoD Manual 8140.03, mapped to eleven work roles in the DoD Cyber Workforce Framework (DCWF) at the Advanced proficiency level on ten of them, spanning the Cybersecurity, Cyberspace Enabler, and Data/AI workforce elements.

The mapped roles skew executive: Authorizing Official, Cyber Policy and Strategy Planner, Program Manager, and the portfolio and audit leadership roles. Current qualification matrices are published at the DoD Cyber Exchange.

Advanced Proficiency 11 DCWF Roles 3 Workforce Elements
Fast Facts

What Are the Key Facts About CCISO?

Everything you need to know about the certification, the exam structure, and how to maintain CCISO as of 2026.

01

The Certification

Certification Name
Certified Chief Information Security Officer (CCISO)
Issued By
EC-Council
Exam Blueprint
CCISO Exam Blueprint v2
First Administered
2011
Experience (with training)
5 yrs in 3 of 5 domains, no application fee
Experience (self-study)
5 yrs in each domain, $100 application fee
No-Experience Path
Associate CCISO program
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Approved (11 DCWF roles, Advanced on 10)
02

Exam & Maintenance

Exam Format
Scenario-based multiple choice
Number of Items
150 questions
Exam Duration
2.5 hours
Passing Score
Form-based cut score, 60 to 85%
Eligibility
Verified via Exam Eligibility Application
Exam Voucher
Bundled with authorized training
Renewal Cycle
3 years
ECE Requirement
120 ECE credits over 3 years
Maintenance
Annual continuing education fee to EC-Council
Going Deeper

What Comes After the CCISO?

CCISO sits near the top of the certification ladder, so the moves after it are sideways into the specialties a security executive is now expected to own: AI security governance, enterprise IT governance, and risk. All three below have their own experience prerequisites.

AAISM (AI Security)

ISACA's Advanced in AI Security Management validates governing AI security at the program level, the question boards now put to every CISO. It requires an active CISM or CISSP, which most CCISO holders already have.

CGEIT (IT Governance)

ISACA's Certified in the Governance of Enterprise IT extends the governance half of the CCISO into the full enterprise IT picture. It suits security executives whose remit is widening beyond security into technology governance.

CRISC (Risk)

ISACA's Certified in Risk and Information Systems Control goes deep on enterprise IT risk, the language CCISO holders use with boards daily. It requires three years of IT risk management experience across its domains.

Certification Roadmap

Where Does CCISO Fit in Your Career?

CCISO is a destination credential, not a starting point. It sits at the top of a track that runs through the senior security and management certifications, then branches into the governance, risk, and AI specialties an executive is expected to add.

STAGE 02 You Are Here

Executive Credential

The top of the ladder

PRIMARY
CCISO
EC-Council · Certified Chief Information Security Officer
Associate CCISO
EC-Council · Same domains, earn experience after
STAGE 03

Specialize

Widen the remit

AI Leadership
Governance
Risk
Decision Point

Is CCISO Right For You?

Two questions to answer before you commit: can you certify, and should you pursue CCISO specifically. Here's a straight answer to both.

Q1

Do You Qualify for CCISO?

Path A

5+ Years Across Three Domains

You can certify with authorized training.

With EC-Council authorized training, you need five years of experience in three of the five CCISO domains, verified through the Exam Eligibility Application, and the application fee is waived. Going the self-study route instead raises the bar to five years in each of the five domains (the years can overlap) plus a $100 application fee.

Path B

Not Yet at the Executive Level

You can still start now.

EC-Council's Associate CCISO program uses the same five-domain courseware and issues its own credential to candidates who don't yet meet the experience requirement. Once you've built the qualifying years, you apply for the full CCISO exam, so the training never has to wait on your title.

Q2

Is CCISO the Right Certification for Your Goals?

CCISO Is a Strong Fit If...

  • You're a CISO, deputy CISO, or security director who owns strategy, budget, and vendor decisions
  • You hold CISSP or CISM and the next move on your ladder is the executive seat
  • You need to prove financial, procurement, and third-party management skills no practitioner cert covers
  • You work federal or contractor roles where a DoD 8140 approved credential on executive DCWF roles matters
  • You brief boards on security posture and need the governance vocabulary to do it credibly
  • You keep seeing CISO and director postings that list executive-level credentials as preferred

Consider Alternatives If...

  • You're a hands-on practitioner who wants technical depth, where CEH or CISSP serves you better
  • You're early in your security career, start with Security+ and build from there
  • You manage a security program but aren't headed for the C-suite, where CISM is the tighter fit
  • Your work centers on audit and assurance rather than running the program, where CISA fits
  • Your focus is enterprise IT risk specifically, where CRISC goes deeper
  • You can't yet document five years across three domains and want a full credential now rather than the Associate path
Career Paths

What Jobs Can You Get With CCISO?

CCISO maps to executive and senior leadership roles across the private sector and the federal cyber workforce. Several of these are DCWF work roles verified on the DoD 8140 Matrix V2.1.

Executive Leadership

Chief Information Security Officer

Owns security strategy, budget, and accountability at the executive level. CCISO is the credential built specifically for this seat, written by sitting CISOs for the people stepping into the role.

Authorization

Authorizing Official

Holds the authority to accept risk and authorize a system to operate. DCWF work role 611, where CCISO qualifies at the Advanced proficiency level under DoD 8140.

Strategy

Cyber Policy and Strategy Planner

Develops the cyber policy and strategic plans an organization or agency operates under. DCWF work role 752, mapped to CCISO at the Advanced level.

Program Management

Program Manager

Leads major programs and holds the budget, schedule, and performance accountability. DCWF work role 801, where CCISO qualifies at the Advanced level, drawing directly on Domain 3.

Security Management

Information Systems Security Manager

Owns the security posture of a system or program. DCWF work role 722, where CCISO is approved at the Intermediate proficiency level.

Risk and Assessment

Security Control Assessor

Evaluates whether security controls are implemented correctly and operating as intended. DCWF work role 612, mapped to CCISO at the Advanced level.

Comparison

How Does CCISO Compare to CISSP and CISM?

All three are senior credentials, but they sit at different altitudes on the org chart. Here's how they line up.

  CCISO CISSP CISM
Issuer EC-Council ISC2 ISACA
Focus Executive security leadership Broad security across 8 domains Security management and governance
Exam Format 150 questions, 2.5 hours Adaptive, 100 to 150 items, 3 hrs 150 questions, 4 hours
Passing Score Form-based, 60 to 85% 700 out of 1000 450 out of 800
Experience 5 yrs in 3 of 5 domains (with training) 5 yrs in 2+ domains 5 yrs in security management
Renewal 120 ECEs over 3 years 120 CPEs over 3 years 120 CPEs over 3 years
DoD 8140 Approved Yes (11 DCWF roles) Yes (Advanced, 11 roles) Yes (Advanced, 13 roles)
Best For CISOs and security executives Architects and senior generalists Security managers and governance leads

Pricing and renewal details vary by region and membership status. Many security executives eventually hold more than one of these credentials.

Ready to Get Certified?

Train for CCISO with Training Camp.

Our EC-Council CCISO boot camp covers all five domains over five days, with official EC-Council courseware and your exam voucher included, so senior professionals leave exam-ready with the application fee waived.

View Boot Camp
Dive Deeper

Security Leadership Articles and Guides.

Leadership-track strategy, credential comparisons, and the governance topics landing on every CISO's desk.

Featured Leadership Track

CISSP vs CISM: Which One Should I Get First?

The question every security leader hits on the way up: the technical flagship or the management credential first. A straight framework for deciding based on where you are and where you want to land.

Read Article →
Comparison

CISM vs CISSP: Which Security Certification is Best for You in 2025

A head-to-head look at the two credentials most often weighed against each other for senior security roles, from exam structure and cost to the careers each one actually serves.

Read Article →
Comparison

CISA vs CISM: Which ISACA Cert Should You Pursue First?

One credential audits the security program, the other builds and owns it. How to pick your first ISACA certification based on the work you actually do.

Read Article →
Career Guide

Best Certifications for GRC Careers in 2026

Governance, risk, and compliance roles list wildly different credential requirements. A tier-by-tier map of which certifications move a GRC career and in what order.

Read Article →
Career Decision

Is CRISC Worth It? Breaking Down the ROI for Risk Professionals

The salary math, the experience requirements, and an honest read on who gains from the risk management credential many security executives add to their stack.

Read Article →
AI Governance

What is AI Governance?

AI governance has moved from a best practice to a board-level expectation, and CISOs are being handed the problem. What the discipline covers and which credentials address it.

Read Article →
AI Security

AAISM vs AAIA vs AAIR: Which ISACA AI Certification Fits Your Role?

ISACA split AI into three specialty credentials that bolt onto existing certifications. How security leaders, auditors, and risk professionals each pick their lane.

Read Article →
Curriculum

Inside the Five CCISO Domains.

The CCISO Body of Knowledge is organized into five domains, each carrying its own weight on the exam. Click any domain for what it covers.

Domains 01-03

Governance to Operations
01 Governance, Risk, Compliance 21%

Information security governance programs, legal and regulatory compliance, and enterprise risk management. This is where the exam tests whether you can set direction for a security program and answer for it to a board.

02 Information Security Controls and Audit Management 20%

Designing, deploying, and managing security controls, plus running the audit management process that proves those controls work. Covers control frameworks, audit planning, and remediation.

03 Security Program Management and Operations 21%

The operational side of the CISO seat: program and project management, staffing and resource allocation, and keeping day-to-day security operations aligned with program goals.

Domains 04-05

Core Skills to Strategy
04 Information Security Core Competencies 19%

The technical breadth a CISO has to hold: access control, network and endpoint defense, cryptography, incident response, and physical security, all viewed from the executive level rather than the keyboard.

05 Strategic Planning, Finance, Procurement, and Third-Party Management 19%

The domain no other major security cert covers this deeply: security strategy, budgeting and financial planning, vendor procurement, and third-party risk. The material that separates a CISO from a senior engineer.

Domains and weights reflect the EC-Council CCISO Exam Blueprint v2. EC-Council updates the blueprint on a regular cycle.

Frequently Asked Questions

Common Questions About CCISO.

The questions candidates ask most often when researching the Certified Chief Information Security Officer certification.

What is the CCISO certification?

CCISO is EC-Council's executive-level security certification, the Certified Chief Information Security Officer. It validates the governance, program management, financial, and strategic skills required to run an organization's security program from the top seat, and it was developed by sitting CISOs for current and aspiring CISOs.

Who should get the CCISO?

CCISO fits senior security professionals moving into or already holding executive roles: CISOs, deputy CISOs, security directors, and senior managers who own budgets, vendors, and strategy. It isn't a technical practitioner certification. If you're building toward the executive track without the experience yet, the Associate CCISO program is the starting point.

What is the CCISO exam like?

The exam has 150 multiple choice questions delivered over 2.5 hours. Questions are scenario-based and test executive judgment across the five CCISO domains rather than technical recall, so expect situations about budgets, board communication, and program decisions, not packet captures.

What is the CCISO passing score?

There's no fixed number. EC-Council delivers the exam in multiple forms and sets a cut score per form based on its difficulty, ranging from 60 to 85 percent. Third-party sites quoting a specific figure like 72 percent are describing one exam form, not the policy.

What experience do you need for the CCISO?

With EC-Council authorized training, five years of experience in three of the five CCISO domains, with the application fee waived. Without authorized training, five years in each of the five domains (the years can overlap) plus a $100 application fee. Either way, experience is verified through the CCISO Exam Eligibility Application before you can sit.

Can you take the CCISO exam without the experience?

Not the full exam, but there's a path. Candidates who don't yet qualify can earn the Associate CCISO certification using the same five-domain courseware, then apply for the full CCISO exam once they've built the qualifying experience.

What are the five CCISO domains?

They are Governance, Risk, Compliance at 21 percent, Information Security Controls and Audit Management at 20 percent, Security Program Management and Operations at 21 percent, Information Security Core Competencies at 19 percent, and Strategic Planning, Finance, Procurement, and Third-Party Management at 19 percent, per the CCISO Exam Blueprint v2.

How much does the CCISO cost?

It depends on your path. Candidates who go through authorized training pay no application fee, and boot camps typically bundle the exam voucher into the course price. Self-study candidates pay a $100 application fee with their eligibility application plus the exam voucher. Maintaining the credential adds an annual continuing education fee to EC-Council.

How do I maintain the CCISO certification?

You earn 120 EC-Council Continuing Education (ECE) credits across a three-year cycle and pay an annual continuing education fee. Credits come from training, conferences, publishing, teaching, and similar activities, submitted through the EC-Council Aspen portal.

Is CCISO approved for DoD 8140?

Yes. CCISO appears on the DoD 8140 Approved Qualifications Matrix V2.1 mapped to eleven DCWF work roles, at the Advanced proficiency level on ten of them, including Authorizing Official, Cyber Policy and Strategy Planner, and Program Manager, and at the Intermediate level for Information Systems Security Manager. See the full DoD 8140 work role paths.

What is the difference between CCISO and CISSP?

CISSP proves broad security knowledge across eight domains and is aimed at senior practitioners and architects. CCISO sits a level up the org chart: it tests governance, budgeting, procurement, and strategy, the material a CISO uses daily that CISSP barely touches. Many security executives hold both, earning CISSP first and adding CCISO when they move into leadership.

What is the difference between CCISO and CISM?

Both target security management, but at different altitudes. CISM from ISACA validates managing an information security program across four domains. CCISO goes further up into the executive seat, adding financial management, procurement, and third-party strategy that CISM doesn't cover in depth. CISM suits security managers; CCISO is built for the C-suite.

Is CCISO worth it in 2026?

For senior professionals moving into or already holding executive security roles, yes. CCISO is the only major credential purpose-built for the CISO seat, it satisfies DoD 8140 across eleven DCWF work roles, and its finance and strategy content maps directly to what boards now expect from security leadership. It's the wrong choice for hands-on practitioners, who are better served by technical credentials first.

Get In Touch

Have Questions About CCISO?

Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    EC-Council CCISO Boot Camp 5 Days · Exam Voucher Included
    View Boot Camp