Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Certified in Governance, Risk and Compliance (CGRC)
Certification Explained.

Everything you need to know about ISC2's authorization and compliance certification as of 2026, covering the seven domains, exam format, the two-year experience requirement, the CAP name change, career paths, DoD 8140 status, and how CGRC compares to CISSP and CISA. A complete reference guide for anyone weighing the CGRC or trying to work out what it actually tests.

CGRC_FAST_FACTS
Issuer: ISC2
Exam: 125 questions, 3 hours
Passing Score: 700 / 1000
Experience: 2 years in the domains
DoD 8140 Approved
7 CGRC Domains 2 YRS Experience Required 125 Exam Questions 3-HOUR Linear Exam SINCE 2005 ISC2 Issued
UPDATED 2026
Overview

What Is the Certified in Governance, Risk and Compliance (CGRC)?

CGRC is ISC2's certification for the people who authorize information systems and keep them compliant. It launched in 2005 and passed 5,000 holders worldwide in January 2026.

CGRC used to be called CAP. ISC2 renamed the Certified Authorization Professional to Certified in Governance, Risk and Compliance effective February 16, 2023, and said at the time that the exam outline and the exam domains were not affected. So CAP and CGRC are the same credential under two names, and plenty of job postings still ask for the old one. That is the whole of the change: no new domains, no new experience requirement, no reissue needed.

What it tests is a process, not a technology. The seven domains walk the full authorization lifecycle: scope the system, categorize it, select and tailor a control baseline, implement the controls, assess them, package the result for an authorizing official, then monitor it continuously once the authorization is granted. Anyone who has run a NIST Risk Management Framework package will recognize every step. It also covers ISO 27001, FedRAMP and COBIT, so it is not purely a federal credential, but federal and contractor work is where it is strongest.

The credential is ANAB-accredited under ISO/IEC 17024 and approved by the Department of Defense under DoDM 8140.03. It asks for two years of experience, the lowest bar of any ISC2 professional certification. CGRC is issued and maintained by ISC2.

2005 First Administered
7 Domains
2 Yr Experience
The CGRC Domains

Seven Domains of Authorization

01

Governance, Risk and Compliance Program

GRC principles, frameworks, the SDLC, and who owns which compliance task. 16% of the exam.

02

Scope of the System

Boundaries, information types, and system categorization. The smallest domain at 10%.

03

Selection and Approval of Controls

Choosing the framework, tailoring the baseline, and getting it approved. 14% of the exam.

04

Implementation of Controls

Putting controls in place and documenting them. The heaviest domain at 17%.

05

Assessment and Audit of Controls

Assessment planning, testing, and reporting the findings. 16% of the exam.

06

System Compliance

The authorization package, residual risk, and the ATO decision. 14% of the exam.

07

Compliance Maintenance

Continuous monitoring, change tracking, and decommissioning. 13% of the exam.

Why CGRC Matters

Why Is CGRC So Widely Recognized?

Four reasons the credential keeps showing up in federal and contractor job postings, twenty years after it launched.

It Names the Authorization Job

Most security certifications describe a discipline. CGRC describes a workflow: categorize, select, implement, assess, authorize, monitor. If your week is spent building or reviewing an authorization package, this is the one credential whose exam outline matches your task list step for step, whether the framework in play is NIST RMF, FedRAMP or ISO 27001.

Two Years, Not Five

CGRC asks for two years of cumulative experience in one or more of its domains. CISSP and CCSP both ask for five. That makes CGRC the most reachable of ISC2's professional certifications for someone two years into compliance or assessment work, without it being an entry-level credential.

Steady Demand in GRC Pay

Governance and risk roles sit in the upper half of security pay, and cleared authorization work sits higher still. Our look at the highest paying IT certifications in 2026 puts the numbers in context, including how to read them.

DoD 8140 Approved

ISC2 lists CGRC as approved by the Department of Defense under DoD Manual 8140.03. In the DoD 8140 Approved Qualifications Matrix V2.1, it appears at the Intermediate proficiency level for Authorizing Official/Designated Representative (611), Security Control Assessor (612), Information Systems Security Manager (722), Program Manager (801) and IT Program Auditor (805). Those are the roles we can confirm in the matrix; CGRC is not listed at the Advanced level.

With element-level qualification now mandatory across the department, an approved credential is what lets someone hold an assessment or authorization billet. Current qualification matrices are published at the DoD Cyber Exchange.

Intermediate Proficiency 5 Confirmed DCWF Roles 2 Workforce Elements
Fast Facts

What Are the Key Facts About CGRC?

Everything you need to know about the certification, the exam structure, and how to maintain CGRC as of 2026. Every figure below comes from ISC2.

01

The Certification

Certification Name
Certified in Governance, Risk and Compliance (CGRC)
Former Name
CAP, renamed February 16, 2023
Issued By
ISC2
Exam Outline
Effective June 15, 2024
First Administered
2005 (as CAP)
Prerequisites
2 yrs in 1 or more of the 7 domains
Experience Waiver
None published by ISC2
No-Experience Path
Pass and hold Associate of ISC2
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Approved (5 DCWF roles, Intermediate)
02

Exam & Maintenance

Exam Format
Linear, fixed form (not adaptive)
Number of Items
125 questions
Item Types
Multiple choice plus advanced items
Exam Duration
3 hours
Passing Score
700 out of 1000
Language
English only, at Pearson VUE
Exam Cost
~$599 USD
Validity
3 years
CPE Requirement
60 CPEs over 3 years (45 Group A)
Maintenance
$135 annual maintenance fee to ISC2
Going Deeper

What Comes After the CGRC?

CGRC proves you can carry a system through authorization. From there, people either widen out into general security or go further into risk and audit. These three credentials come up most often.

CISSP (Breadth)

ISC2's flagship covers eight domains of security rather than one process. It is the natural widening move once the authorization work is second nature, and it takes five years of experience. Read what CISSP covers.

CISA (Audit)

ISACA's audit credential is the other half of the assessment conversation, and the two appear together in plenty of postings. CISA looks at controls from the auditor's chair rather than the system owner's. Read what CISA covers.

CRISC (Enterprise Risk)

ISACA's CRISC moves the frame from one system's authorization to the organization's risk portfolio: appetite, response, and reporting to the board. A common next step for people moving from assessor to risk owner.

Certification Roadmap

Where Does CGRC Fit in Your Career?

CGRC is the mid-career credential for the compliance and authorization track. It builds on general security literacy and leads either into broad security leadership or deeper into risk and audit.

STAGE 02 You Are Here

GRC Credential

The authorization specialty

PRIMARY
CGRC
ISC2 ยท Certified in Governance, Risk and Compliance
Associate of ISC2
ISC2 ยท Pass first, earn experience after
STAGE 03

Specialize

Pick your path

Broad Security
Risk and Audit
Decision Point

Is CGRC Right For You?

Two questions to answer before you commit: can you certify, and should you pursue CGRC specifically. Here's a straight answer to both.

Q1

Do You Qualify for CGRC?

Path A

2+ Years in the Domains

You can certify in full.

You have two years of cumulative work experience in one or more of the seven CGRC domains. ISC2 counts full-time work monthly at 35 hours a week or more, counts part-time work between 20 and 34 hours a week on a pro-rata basis, and accepts documented paid or unpaid internships. There is no degree-based waiver published for CGRC. Pass the exam, get endorsed, and you hold the full credential.

Path B

Under Two Years in the Field

You can still pass now.

Sit the exam without the experience, and once you pass you become an Associate of ISC2. From there you have three years to earn the two years of relevant experience and convert to full CGRC status. Associates pay a $50 annual maintenance fee and owe 15 Group A CPEs a year until they convert.

Q2

Is CGRC the Right Certification for Your Goals?

CGRC Is a Strong Fit If...

  • You work on authorization packages, ATOs, or continuous monitoring in a federal agency or for a contractor
  • You assess controls for a living and want a credential that names the assessment process rather than a technology
  • You need a DoD 8140 approved credential for an assessment, authorization, or security management billet
  • You have around two years of compliance experience and CISSP's five-year requirement is still out of reach
  • You keep seeing CAP or CGRC in the postings you want, which is common in cleared and federal work
  • Your organization runs NIST RMF, FedRAMP, or ISO 27001 and you own part of that process

Consider Alternatives If...

  • You want a broad security credential covering the whole field, where CISSP fits better
  • Your work is hands-on engineering, defense, or testing, where the CGRC domains would rarely come up
  • You audit systems for a living rather than authorize them, where CISA is the closer match
  • You own enterprise risk rather than system risk, where CRISC frames the work the way you do
  • You want to run a security program and manage people, where CISM is the management credential
  • You are new to security with no compliance exposure yet, where Security+ is the better first step
Career Paths

What Jobs Can You Get With CGRC?

CGRC maps to the federal cyber workforce more directly than most credentials. The first four cards are DCWF work roles where CGRC is a confirmed qualification at the Intermediate level. The last two are job titles ISC2 names on its own CGRC page.

Assessment

Security Control Assessor

Independently tests whether the controls a system claims are actually in place and working. DCWF work role 612, where CGRC qualifies at the Intermediate proficiency level. This is the role the CGRC maps to most directly.

Authorization

Authorizing Official / Designated Rep

Owns the risk decision that grants or denies an authorization to operate. DCWF work role 611, where CGRC qualifies at the Intermediate level. The credential covers the package the AO actually signs.

Security Management

Information Systems Security Manager

Runs the security program for a system or an organization and keeps its authorization current. DCWF work role 722, where CGRC qualifies at the Intermediate level.

Audit

IT Program Auditor

Audits IT programs against policy, contract and regulatory requirements. DCWF work role 805, where CGRC qualifies at the Intermediate level, alongside Program Manager, work role 801.

Governance

GRC Analyst or GRC Manager

Runs the control framework on the private-sector side: mapping requirements, tracking evidence, and keeping the organization ready for its next audit. ISC2 names both titles on the CGRC page.

Vendor Risk

Third Party Risk Manager

Assesses the security and compliance posture of vendors and suppliers, and holds them to it through the contract. Another of the roles ISC2 lists for CGRC holders.

Comparison

How Does CGRC Compare to CISSP and CISA?

These three keep appearing in the same job postings, but they answer different questions: can you authorize a system, can you secure an enterprise, can you audit one. Here's how they line up.

  CGRC CISSP CISA
Issuer ISC2 ISC2 ISACA
Focus System authorization and compliance Broad security across 8 domains IS audit and assurance
Domains 7 8 5
Exam Format Linear, 125 items, 3 hrs Adaptive, 100 to 150 items, 3 hrs Linear, 150 items, 4 hrs
Experience 2 yrs in 1 or more domains 5 yrs in 2+ domains 5 yrs IS audit, control, or security
Passing Score 700 / 1000 700 / 1000 450 / 800
Exam Cost ~$599 ~$749 $575 member / $760 non-member
Renewal 60 CPEs over 3 years 120 CPEs over 3 years 120 CPEs over 3 years
DoD 8140 Approved Yes (Intermediate) Yes (Advanced) Yes (Advanced)
Best For Assessors, ISSOs, GRC practitioners Architects and senior generalists IT auditors and assurance leads

Pricing and renewal details vary by region and membership status. In federal and contractor work the common pairing is CGRC plus CISSP: one credential names the process you run, the other proves the breadth behind it.

Ready to Get Certified?

Train for CGRC with Training Camp.

Our official ISC2 CGRC boot camp covers all seven domains over five days, with your $599 exam voucher, official ISC2 courseware, and a free retake included, so practitioners already doing the work leave exam-ready.

View Boot Camp
Dive Deeper

CGRC Articles and Guides.

Authorization work, the GRC certification field, DoD 8140 mapping, and what renewal costs you.

Featured Complete Guide

CGRC Certification: The ISC2 Credential for ATO and Authorization Work

A full walkthrough of what CGRC covers, who it is for, and how it fits the authorization process. The place to start if you are weighing the credential against the work you actually do.

Read Article โ†’
Comparison

Best Certifications for GRC Careers in 2026

Where CGRC sits among CRISC, CISA, CISM and the rest of the governance and risk field, and which one matches the GRC job you are aiming at.

Read Article โ†’
DoD 8140

Which Certifications Qualify for DoD 8140 Work Roles? A DCWF Map

The work role by work role map of the DoD 8140 qualification matrix, including the roles where CGRC counts and the proficiency level it counts at.

Read Article โ†’
Decision Guide

Is CRISC Worth It? Breaking Down the ROI for Risk Professionals

The closest comparison to CGRC on the risk side. ISACA takes an enterprise risk angle where ISC2 takes an authorization angle, and the two credentials pull in different directions.

Read Article โ†’
Maintenance

CPE Requirements by Certification Body: A Complete Comparison

What renewal actually costs you in hours. CGRC sits at 60 CPEs over three years, which is the lightest cycle of any ISC2 professional certification.

Read Article โ†’
Salary and Demand

The Highest Paying IT Certifications in 2026

Where governance and risk credentials land against the rest of the field, with a note on how to read the salary surveys everyone quotes.

Read Article โ†’
Audit Careers

CISA Salary in 2026: What IT Auditors Actually Earn

CGRC and CISA overlap on assessment work and often appear in the same job posting. A read on what the audit side of that overlap pays.

Read Article โ†’
Curriculum

Inside the Seven CGRC Domains.

The CGRC Common Body of Knowledge is organized into seven domains that follow the authorization lifecycle in order, each carrying its own weight on the exam. Click any domain for what it covers.

Domains 01-04

Program to Implementation
01 Security and Privacy Governance, Risk Management, and Compliance Program 16%

The principles behind governance, risk and compliance, and the frameworks that carry them: NIST publications, the Cybersecurity Framework, COBIT and ISO/IEC standards. Also the system development life cycle, the information lifecycle for each data type, and who is responsible for which compliance activity.

02 Scope of the System 10%

The smallest domain and the one everything else depends on. Describing the system, drawing the authorization boundary, identifying the information types it handles, and categorizing the system so the right control baseline applies.

03 Selection and Approval of Framework, Security, and Privacy Controls 14%

Picking the framework and the control baseline, tailoring that baseline to the system in front of you, allocating controls to components and inherited services, and getting the resulting set approved by the right authority.

04 Implementation of Security and Privacy Controls 17%

The heaviest domain. Putting the selected controls in place and documenting how each one is actually implemented, in enough detail that an assessor can test the claim rather than take your word for it.

Domains 05-07

Assessment to Maintenance
05 Assessment/Audit of Security and Privacy Controls 16%

Preparing for assessment, building the assessment plan, running the testing, and writing up findings and recommended remediation. This is the domain that separates people who write control language from people who verify it.

06 System Compliance 14%

Compiling the authorization package, reviewing and reporting residual risk, and supporting the authorizing official through the risk decision that produces an authorization to operate.

07 Compliance Maintenance 13%

What happens after the ATO. Continuous monitoring, tracking and assessing changes to the system, ongoing reporting on security and privacy posture, and decommissioning the system properly at the end of its life.

Domains and weights reflect the ISC2 CGRC Certification Exam Outline effective June 15, 2024, the version ISC2 administers today.

Frequently Asked Questions

Common Questions About CGRC.

The questions candidates ask most often when researching the Certified in Governance, Risk and Compliance certification.

What is the CGRC certification?

CGRC is ISC2's governance, risk and compliance certification. It covers the work of authorizing an information system and keeping it compliant, across seven domains that run from scoping a system through control selection, implementation, assessment, authorization and continuous monitoring.

Is CGRC the same as the CAP certification?

Yes. ISC2 renamed the Certified Authorization Professional (CAP) to Certified in Governance, Risk and Compliance (CGRC), effective February 16, 2023. ISC2 stated at the time that the exam outline and exam domains were not affected by the name change, so CAP and CGRC refer to the same credential. Job postings and resumes still use the old name.

Who should get the CGRC?

CGRC fits people whose work touches system authorization and compliance: security control assessors, ISSOs, GRC analysts, compliance officers and risk managers. It is strongest in federal and contractor environments where the NIST Risk Management Framework drives the process. It is a poor fit for hands-on engineering and defensive operations roles.

How much does the CGRC exam cost in 2026?

The CGRC exam costs approximately $599 USD as of 2026, set by ISC2 and varying slightly by region. The fee covers the exam itself, not training or study materials. Many boot camps fold the exam voucher into the course price, so check what is included before you pay separately.

What is the CGRC exam like?

The CGRC exam is linear rather than adaptive: 125 items over a maximum of three hours, in English, at a Pearson VUE test center. ISC2 lists the item format as multiple choice plus advanced item types. You need a scaled score of 700 out of 1000 to pass.

What experience do you need for the CGRC?

CGRC requires two years of cumulative work experience in one or more of the seven CGRC domains, which is the lowest experience bar of any ISC2 professional certification. Part-time work counts on a pro-rata basis and paid or unpaid internships count with documentation. ISC2 does not publish a degree-based waiver for CGRC.

Can you take the CGRC exam without experience?

Yes. You can sit and pass the exam before you have the experience and become an Associate of ISC2. From there you have three years to earn the two years of relevant experience needed to convert to full CGRC status.

What are the seven CGRC domains?

The seven CGRC domains are Security and Privacy Governance, Risk Management, and Compliance Program; Scope of the System; Selection and Approval of Framework, Security, and Privacy Controls; Implementation of Security and Privacy Controls; Assessment/Audit of Security and Privacy Controls; System Compliance; and Compliance Maintenance. Implementation of Security and Privacy Controls carries the heaviest weight at 17 percent.

How do I maintain my CGRC certification?

CGRC is valid for three years. To renew, you earn 60 Continuing Professional Education (CPE) credits across the cycle, at least 45 of which must be Group A domain-related credits, and you pay the ISC2 annual maintenance fee of $135. ISC2 suggests 20 credits a year to stay on pace, and members pay a single maintenance fee no matter how many ISC2 certifications they hold.

Is CGRC approved for DoD 8140?

Yes. ISC2 lists CGRC as approved by the Department of Defense under DoDM 8140.03. In the DoD 8140 Approved Qualifications Matrix V2.1, CGRC is listed at the Intermediate proficiency level for Authorizing Official/Designated Representative (611), Security Control Assessor (612), Information Systems Security Manager (722), Program Manager (801) and IT Program Auditor (805). See the full DoD 8140 work role paths.

What is the difference between CGRC and CISSP?

CISSP is the broad credential, eight domains wide, aimed at people who design and run security programs. CGRC is narrow and deep on one process: authorizing a system and keeping it compliant. CISSP asks for five years of experience, CGRC asks for two. People doing RMF and ATO work often end up holding both, with CGRC as the credential that names their actual job.

Which CGRC exam outline is current?

The outline in force took effect June 15, 2024. It sets the seven domains and their weights, 125 items, three hours, and a 700 out of 1000 passing grade. ISC2 has not published a replacement outline as of September 2026, so study material aligned to the June 2024 outline is the current version. Check the effective date printed on anything you buy.

Get In Touch

Have Questions About CGRC?

Whether you're weighing the certification, working out funding, or planning training for an assessment team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    ISC2 CGRC Boot Camp 5-Day Boot Camp ยท Exam Voucher Included
    View Boot Camp