Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about EC-Council's executive security certification as of 2026, covering the five domains, exam format, eligibility paths, career outcomes, DoD 8140 status, and how CCISO compares to CISSP and CISM. A complete reference guide for anyone weighing the CCISO or trying to understand what it covers.
Governance programs, regulatory compliance, and enterprise risk. The heaviest domain at 21% alongside Domain 3.
Designing security controls and running the audit process that proves they work.
Running the security program: projects, people, budget, and operations.
The technical breadth a CISO needs, viewed from the executive level.
Budgets, procurement, and vendor risk. The material other security certs skip.
CCISO is EC-Council's executive security certification, launched in 2011 as the first program built specifically to produce top-level information security executives.
It validates the skills a CISO actually uses: setting governance, managing risk and audits, running a security program, holding the technical picture together, and owning the budget, vendors, and strategy behind it all. The program was written by sitting CISOs, and the exam tests executive judgment across scenarios rather than technical recall.
The credential is ANAB-accredited under ISO/IEC 17024, approved under DoD 8140 across eleven DCWF work roles, and gated behind a verified experience requirement that keeps it firmly in executive territory. CCISO is issued and maintained by EC-Council, the body behind the Certified Ethical Hacker program.
Four things that separate CCISO from every practitioner-level security certification on the market in 2026.
CCISO was the first certification program aimed at producing top-level security executives. Its advisory board of sitting CISOs wrote the Body of Knowledge, the exam, and the training, and the credential is ANAB-accredited under the ISO/IEC 17024 personnel certification standard.
Domain 5 covers strategic planning, budgeting, procurement, and third-party management, the material boards actually grill CISOs on. No other major security certification tests it at this depth.
Most CCISO candidates already hold a senior credential and are moving up the org chart. Our CISSP vs CISM framework maps the leadership track that leads here.
CCISO is an approved qualification under DoD Manual 8140.03, mapped to eleven work roles in the DoD Cyber Workforce Framework (DCWF) at the Advanced proficiency level on ten of them, spanning the Cybersecurity, Cyberspace Enabler, and Data/AI workforce elements.
The mapped roles skew executive: Authorizing Official, Cyber Policy and Strategy Planner, Program Manager, and the portfolio and audit leadership roles. Current qualification matrices are published at the DoD Cyber Exchange.
Everything you need to know about the certification, the exam structure, and how to maintain CCISO as of 2026.
CCISO sits near the top of the certification ladder, so the moves after it are sideways into the specialties a security executive is now expected to own: AI security governance, enterprise IT governance, and risk. All three below have their own experience prerequisites.
ISACA's Advanced in AI Security Management validates governing AI security at the program level, the question boards now put to every CISO. It requires an active CISM or CISSP, which most CCISO holders already have.
ISACA's Certified in the Governance of Enterprise IT extends the governance half of the CCISO into the full enterprise IT picture. It suits security executives whose remit is widening beyond security into technology governance.
ISACA's Certified in Risk and Information Systems Control goes deep on enterprise IT risk, the language CCISO holders use with boards daily. It requires three years of IT risk management experience across its domains.
CCISO is a destination credential, not a starting point. It sits at the top of a track that runs through the senior security and management certifications, then branches into the governance, risk, and AI specialties an executive is expected to add.
Prove the foundation
The top of the ladder
Two questions to answer before you commit: can you certify, and should you pursue CCISO specifically. Here's a straight answer to both.
You can certify with authorized training.
With EC-Council authorized training, you need five years of experience in three of the five CCISO domains, verified through the Exam Eligibility Application, and the application fee is waived. Going the self-study route instead raises the bar to five years in each of the five domains (the years can overlap) plus a $100 application fee.
You can still start now.
EC-Council's Associate CCISO program uses the same five-domain courseware and issues its own credential to candidates who don't yet meet the experience requirement. Once you've built the qualifying years, you apply for the full CCISO exam, so the training never has to wait on your title.
CCISO maps to executive and senior leadership roles across the private sector and the federal cyber workforce. Several of these are DCWF work roles verified on the DoD 8140 Matrix V2.1.
Owns security strategy, budget, and accountability at the executive level. CCISO is the credential built specifically for this seat, written by sitting CISOs for the people stepping into the role.
Holds the authority to accept risk and authorize a system to operate. DCWF work role 611, where CCISO qualifies at the Advanced proficiency level under DoD 8140.
Develops the cyber policy and strategic plans an organization or agency operates under. DCWF work role 752, mapped to CCISO at the Advanced level.
Leads major programs and holds the budget, schedule, and performance accountability. DCWF work role 801, where CCISO qualifies at the Advanced level, drawing directly on Domain 3.
Owns the security posture of a system or program. DCWF work role 722, where CCISO is approved at the Intermediate proficiency level.
Evaluates whether security controls are implemented correctly and operating as intended. DCWF work role 612, mapped to CCISO at the Advanced level.
All three are senior credentials, but they sit at different altitudes on the org chart. Here's how they line up.
| CCISO | CISSP | CISM | |
|---|---|---|---|
| Issuer | EC-Council | ISC2 | ISACA |
| Focus | Executive security leadership | Broad security across 8 domains | Security management and governance |
| Exam Format | 150 questions, 2.5 hours | Adaptive, 100 to 150 items, 3 hrs | 150 questions, 4 hours |
| Passing Score | Form-based, 60 to 85% | 700 out of 1000 | 450 out of 800 |
| Experience | 5 yrs in 3 of 5 domains (with training) | 5 yrs in 2+ domains | 5 yrs in security management |
| Renewal | 120 ECEs over 3 years | 120 CPEs over 3 years | 120 CPEs over 3 years |
| DoD 8140 Approved | Yes (11 DCWF roles) | Yes (Advanced, 11 roles) | Yes (Advanced, 13 roles) |
| Best For | CISOs and security executives | Architects and senior generalists | Security managers and governance leads |
Pricing and renewal details vary by region and membership status. Many security executives eventually hold more than one of these credentials.
Our EC-Council CCISO boot camp covers all five domains over five days, with official EC-Council courseware and your exam voucher included, so senior professionals leave exam-ready with the application fee waived.
Leadership-track strategy, credential comparisons, and the governance topics landing on every CISO's desk.
The question every security leader hits on the way up: the technical flagship or the management credential first. A straight framework for deciding based on where you are and where you want to land.
A head-to-head look at the two credentials most often weighed against each other for senior security roles, from exam structure and cost to the careers each one actually serves.
One credential audits the security program, the other builds and owns it. How to pick your first ISACA certification based on the work you actually do.
Governance, risk, and compliance roles list wildly different credential requirements. A tier-by-tier map of which certifications move a GRC career and in what order.
The salary math, the experience requirements, and an honest read on who gains from the risk management credential many security executives add to their stack.
AI governance has moved from a best practice to a board-level expectation, and CISOs are being handed the problem. What the discipline covers and which credentials address it.
ISACA split AI into three specialty credentials that bolt onto existing certifications. How security leaders, auditors, and risk professionals each pick their lane.
The CCISO Body of Knowledge is organized into five domains, each carrying its own weight on the exam. Click any domain for what it covers.
Information security governance programs, legal and regulatory compliance, and enterprise risk management. This is where the exam tests whether you can set direction for a security program and answer for it to a board.
Designing, deploying, and managing security controls, plus running the audit management process that proves those controls work. Covers control frameworks, audit planning, and remediation.
The operational side of the CISO seat: program and project management, staffing and resource allocation, and keeping day-to-day security operations aligned with program goals.
The technical breadth a CISO has to hold: access control, network and endpoint defense, cryptography, incident response, and physical security, all viewed from the executive level rather than the keyboard.
The domain no other major security cert covers this deeply: security strategy, budgeting and financial planning, vendor procurement, and third-party risk. The material that separates a CISO from a senior engineer.
Domains and weights reflect the EC-Council CCISO Exam Blueprint v2. EC-Council updates the blueprint on a regular cycle.
The questions candidates ask most often when researching the Certified Chief Information Security Officer certification.
CCISO is EC-Council's executive-level security certification, the Certified Chief Information Security Officer. It validates the governance, program management, financial, and strategic skills required to run an organization's security program from the top seat, and it was developed by sitting CISOs for current and aspiring CISOs.
CCISO fits senior security professionals moving into or already holding executive roles: CISOs, deputy CISOs, security directors, and senior managers who own budgets, vendors, and strategy. It isn't a technical practitioner certification. If you're building toward the executive track without the experience yet, the Associate CCISO program is the starting point.
The exam has 150 multiple choice questions delivered over 2.5 hours. Questions are scenario-based and test executive judgment across the five CCISO domains rather than technical recall, so expect situations about budgets, board communication, and program decisions, not packet captures.
There's no fixed number. EC-Council delivers the exam in multiple forms and sets a cut score per form based on its difficulty, ranging from 60 to 85 percent. Third-party sites quoting a specific figure like 72 percent are describing one exam form, not the policy.
With EC-Council authorized training, five years of experience in three of the five CCISO domains, with the application fee waived. Without authorized training, five years in each of the five domains (the years can overlap) plus a $100 application fee. Either way, experience is verified through the CCISO Exam Eligibility Application before you can sit.
Not the full exam, but there's a path. Candidates who don't yet qualify can earn the Associate CCISO certification using the same five-domain courseware, then apply for the full CCISO exam once they've built the qualifying experience.
They are Governance, Risk, Compliance at 21 percent, Information Security Controls and Audit Management at 20 percent, Security Program Management and Operations at 21 percent, Information Security Core Competencies at 19 percent, and Strategic Planning, Finance, Procurement, and Third-Party Management at 19 percent, per the CCISO Exam Blueprint v2.
It depends on your path. Candidates who go through authorized training pay no application fee, and boot camps typically bundle the exam voucher into the course price. Self-study candidates pay a $100 application fee with their eligibility application plus the exam voucher. Maintaining the credential adds an annual continuing education fee to EC-Council.
You earn 120 EC-Council Continuing Education (ECE) credits across a three-year cycle and pay an annual continuing education fee. Credits come from training, conferences, publishing, teaching, and similar activities, submitted through the EC-Council Aspen portal.
Yes. CCISO appears on the DoD 8140 Approved Qualifications Matrix V2.1 mapped to eleven DCWF work roles, at the Advanced proficiency level on ten of them, including Authorizing Official, Cyber Policy and Strategy Planner, and Program Manager, and at the Intermediate level for Information Systems Security Manager. See the full DoD 8140 work role paths.
CISSP proves broad security knowledge across eight domains and is aimed at senior practitioners and architects. CCISO sits a level up the org chart: it tests governance, budgeting, procurement, and strategy, the material a CISO uses daily that CISSP barely touches. Many security executives hold both, earning CISSP first and adding CCISO when they move into leadership.
Both target security management, but at different altitudes. CISM from ISACA validates managing an information security program across four domains. CCISO goes further up into the executive seat, adding financial management, procurement, and third-party strategy that CISM doesn't cover in depth. CISM suits security managers; CCISO is built for the C-suite.
For senior professionals moving into or already holding executive security roles, yes. CCISO is the only major credential purpose-built for the CISO seat, it satisfies DoD 8140 across eleven DCWF work roles, and its finance and strategy content maps directly to what boards now expect from security leadership. It's the wrong choice for hands-on practitioners, who are better served by technical credentials first.
Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.