Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about ISC2's authorization and compliance certification as of 2026, covering the seven domains, exam format, the two-year experience requirement, the CAP name change, career paths, DoD 8140 status, and how CGRC compares to CISSP and CISA. A complete reference guide for anyone weighing the CGRC or trying to work out what it actually tests.
CGRC is ISC2's certification for the people who authorize information systems and keep them compliant. It launched in 2005 and passed 5,000 holders worldwide in January 2026.
CGRC used to be called CAP. ISC2 renamed the Certified Authorization Professional to Certified in Governance, Risk and Compliance effective February 16, 2023, and said at the time that the exam outline and the exam domains were not affected. So CAP and CGRC are the same credential under two names, and plenty of job postings still ask for the old one. That is the whole of the change: no new domains, no new experience requirement, no reissue needed.
What it tests is a process, not a technology. The seven domains walk the full authorization lifecycle: scope the system, categorize it, select and tailor a control baseline, implement the controls, assess them, package the result for an authorizing official, then monitor it continuously once the authorization is granted. Anyone who has run a NIST Risk Management Framework package will recognize every step. It also covers ISO 27001, FedRAMP and COBIT, so it is not purely a federal credential, but federal and contractor work is where it is strongest.
The credential is ANAB-accredited under ISO/IEC 17024 and approved by the Department of Defense under DoDM 8140.03. It asks for two years of experience, the lowest bar of any ISC2 professional certification. CGRC is issued and maintained by ISC2.
GRC principles, frameworks, the SDLC, and who owns which compliance task. 16% of the exam.
Boundaries, information types, and system categorization. The smallest domain at 10%.
Choosing the framework, tailoring the baseline, and getting it approved. 14% of the exam.
Putting controls in place and documenting them. The heaviest domain at 17%.
Assessment planning, testing, and reporting the findings. 16% of the exam.
The authorization package, residual risk, and the ATO decision. 14% of the exam.
Continuous monitoring, change tracking, and decommissioning. 13% of the exam.
Four reasons the credential keeps showing up in federal and contractor job postings, twenty years after it launched.
Most security certifications describe a discipline. CGRC describes a workflow: categorize, select, implement, assess, authorize, monitor. If your week is spent building or reviewing an authorization package, this is the one credential whose exam outline matches your task list step for step, whether the framework in play is NIST RMF, FedRAMP or ISO 27001.
CGRC asks for two years of cumulative experience in one or more of its domains. CISSP and CCSP both ask for five. That makes CGRC the most reachable of ISC2's professional certifications for someone two years into compliance or assessment work, without it being an entry-level credential.
Governance and risk roles sit in the upper half of security pay, and cleared authorization work sits higher still. Our look at the highest paying IT certifications in 2026 puts the numbers in context, including how to read them.
ISC2 lists CGRC as approved by the Department of Defense under DoD Manual 8140.03. In the DoD 8140 Approved Qualifications Matrix V2.1, it appears at the Intermediate proficiency level for Authorizing Official/Designated Representative (611), Security Control Assessor (612), Information Systems Security Manager (722), Program Manager (801) and IT Program Auditor (805). Those are the roles we can confirm in the matrix; CGRC is not listed at the Advanced level.
With element-level qualification now mandatory across the department, an approved credential is what lets someone hold an assessment or authorization billet. Current qualification matrices are published at the DoD Cyber Exchange.
Everything you need to know about the certification, the exam structure, and how to maintain CGRC as of 2026. Every figure below comes from ISC2.
CGRC proves you can carry a system through authorization. From there, people either widen out into general security or go further into risk and audit. These three credentials come up most often.
ISC2's flagship covers eight domains of security rather than one process. It is the natural widening move once the authorization work is second nature, and it takes five years of experience. Read what CISSP covers.
ISACA's audit credential is the other half of the assessment conversation, and the two appear together in plenty of postings. CISA looks at controls from the auditor's chair rather than the system owner's. Read what CISA covers.
ISACA's CRISC moves the frame from one system's authorization to the organization's risk portfolio: appetite, response, and reporting to the board. A common next step for people moving from assessor to risk owner.
CGRC is the mid-career credential for the compliance and authorization track. It builds on general security literacy and leads either into broad security leadership or deeper into risk and audit.
Build the baseline
The authorization specialty
Two questions to answer before you commit: can you certify, and should you pursue CGRC specifically. Here's a straight answer to both.
You can certify in full.
You have two years of cumulative work experience in one or more of the seven CGRC domains. ISC2 counts full-time work monthly at 35 hours a week or more, counts part-time work between 20 and 34 hours a week on a pro-rata basis, and accepts documented paid or unpaid internships. There is no degree-based waiver published for CGRC. Pass the exam, get endorsed, and you hold the full credential.
You can still pass now.
Sit the exam without the experience, and once you pass you become an Associate of ISC2. From there you have three years to earn the two years of relevant experience and convert to full CGRC status. Associates pay a $50 annual maintenance fee and owe 15 Group A CPEs a year until they convert.
CGRC maps to the federal cyber workforce more directly than most credentials. The first four cards are DCWF work roles where CGRC is a confirmed qualification at the Intermediate level. The last two are job titles ISC2 names on its own CGRC page.
Independently tests whether the controls a system claims are actually in place and working. DCWF work role 612, where CGRC qualifies at the Intermediate proficiency level. This is the role the CGRC maps to most directly.
Owns the risk decision that grants or denies an authorization to operate. DCWF work role 611, where CGRC qualifies at the Intermediate level. The credential covers the package the AO actually signs.
Runs the security program for a system or an organization and keeps its authorization current. DCWF work role 722, where CGRC qualifies at the Intermediate level.
Audits IT programs against policy, contract and regulatory requirements. DCWF work role 805, where CGRC qualifies at the Intermediate level, alongside Program Manager, work role 801.
Runs the control framework on the private-sector side: mapping requirements, tracking evidence, and keeping the organization ready for its next audit. ISC2 names both titles on the CGRC page.
Assesses the security and compliance posture of vendors and suppliers, and holds them to it through the contract. Another of the roles ISC2 lists for CGRC holders.
These three keep appearing in the same job postings, but they answer different questions: can you authorize a system, can you secure an enterprise, can you audit one. Here's how they line up.
| CGRC | CISSP | CISA | |
|---|---|---|---|
| Issuer | ISC2 | ISC2 | ISACA |
| Focus | System authorization and compliance | Broad security across 8 domains | IS audit and assurance |
| Domains | 7 | 8 | 5 |
| Exam Format | Linear, 125 items, 3 hrs | Adaptive, 100 to 150 items, 3 hrs | Linear, 150 items, 4 hrs |
| Experience | 2 yrs in 1 or more domains | 5 yrs in 2+ domains | 5 yrs IS audit, control, or security |
| Passing Score | 700 / 1000 | 700 / 1000 | 450 / 800 |
| Exam Cost | ~$599 | ~$749 | $575 member / $760 non-member |
| Renewal | 60 CPEs over 3 years | 120 CPEs over 3 years | 120 CPEs over 3 years |
| DoD 8140 Approved | Yes (Intermediate) | Yes (Advanced) | Yes (Advanced) |
| Best For | Assessors, ISSOs, GRC practitioners | Architects and senior generalists | IT auditors and assurance leads |
Pricing and renewal details vary by region and membership status. In federal and contractor work the common pairing is CGRC plus CISSP: one credential names the process you run, the other proves the breadth behind it.
Our official ISC2 CGRC boot camp covers all seven domains over five days, with your $599 exam voucher, official ISC2 courseware, and a free retake included, so practitioners already doing the work leave exam-ready.
Authorization work, the GRC certification field, DoD 8140 mapping, and what renewal costs you.
A full walkthrough of what CGRC covers, who it is for, and how it fits the authorization process. The place to start if you are weighing the credential against the work you actually do.
Where CGRC sits among CRISC, CISA, CISM and the rest of the governance and risk field, and which one matches the GRC job you are aiming at.
The work role by work role map of the DoD 8140 qualification matrix, including the roles where CGRC counts and the proficiency level it counts at.
The closest comparison to CGRC on the risk side. ISACA takes an enterprise risk angle where ISC2 takes an authorization angle, and the two credentials pull in different directions.
What renewal actually costs you in hours. CGRC sits at 60 CPEs over three years, which is the lightest cycle of any ISC2 professional certification.
Where governance and risk credentials land against the rest of the field, with a note on how to read the salary surveys everyone quotes.
CGRC and CISA overlap on assessment work and often appear in the same job posting. A read on what the audit side of that overlap pays.
The CGRC Common Body of Knowledge is organized into seven domains that follow the authorization lifecycle in order, each carrying its own weight on the exam. Click any domain for what it covers.
The principles behind governance, risk and compliance, and the frameworks that carry them: NIST publications, the Cybersecurity Framework, COBIT and ISO/IEC standards. Also the system development life cycle, the information lifecycle for each data type, and who is responsible for which compliance activity.
The smallest domain and the one everything else depends on. Describing the system, drawing the authorization boundary, identifying the information types it handles, and categorizing the system so the right control baseline applies.
Picking the framework and the control baseline, tailoring that baseline to the system in front of you, allocating controls to components and inherited services, and getting the resulting set approved by the right authority.
The heaviest domain. Putting the selected controls in place and documenting how each one is actually implemented, in enough detail that an assessor can test the claim rather than take your word for it.
Preparing for assessment, building the assessment plan, running the testing, and writing up findings and recommended remediation. This is the domain that separates people who write control language from people who verify it.
Compiling the authorization package, reviewing and reporting residual risk, and supporting the authorizing official through the risk decision that produces an authorization to operate.
What happens after the ATO. Continuous monitoring, tracking and assessing changes to the system, ongoing reporting on security and privacy posture, and decommissioning the system properly at the end of its life.
Domains and weights reflect the ISC2 CGRC Certification Exam Outline effective June 15, 2024, the version ISC2 administers today.
The questions candidates ask most often when researching the Certified in Governance, Risk and Compliance certification.
CGRC is ISC2's governance, risk and compliance certification. It covers the work of authorizing an information system and keeping it compliant, across seven domains that run from scoping a system through control selection, implementation, assessment, authorization and continuous monitoring.
Yes. ISC2 renamed the Certified Authorization Professional (CAP) to Certified in Governance, Risk and Compliance (CGRC), effective February 16, 2023. ISC2 stated at the time that the exam outline and exam domains were not affected by the name change, so CAP and CGRC refer to the same credential. Job postings and resumes still use the old name.
CGRC fits people whose work touches system authorization and compliance: security control assessors, ISSOs, GRC analysts, compliance officers and risk managers. It is strongest in federal and contractor environments where the NIST Risk Management Framework drives the process. It is a poor fit for hands-on engineering and defensive operations roles.
The CGRC exam costs approximately $599 USD as of 2026, set by ISC2 and varying slightly by region. The fee covers the exam itself, not training or study materials. Many boot camps fold the exam voucher into the course price, so check what is included before you pay separately.
The CGRC exam is linear rather than adaptive: 125 items over a maximum of three hours, in English, at a Pearson VUE test center. ISC2 lists the item format as multiple choice plus advanced item types. You need a scaled score of 700 out of 1000 to pass.
CGRC requires two years of cumulative work experience in one or more of the seven CGRC domains, which is the lowest experience bar of any ISC2 professional certification. Part-time work counts on a pro-rata basis and paid or unpaid internships count with documentation. ISC2 does not publish a degree-based waiver for CGRC.
Yes. You can sit and pass the exam before you have the experience and become an Associate of ISC2. From there you have three years to earn the two years of relevant experience needed to convert to full CGRC status.
The seven CGRC domains are Security and Privacy Governance, Risk Management, and Compliance Program; Scope of the System; Selection and Approval of Framework, Security, and Privacy Controls; Implementation of Security and Privacy Controls; Assessment/Audit of Security and Privacy Controls; System Compliance; and Compliance Maintenance. Implementation of Security and Privacy Controls carries the heaviest weight at 17 percent.
CGRC is valid for three years. To renew, you earn 60 Continuing Professional Education (CPE) credits across the cycle, at least 45 of which must be Group A domain-related credits, and you pay the ISC2 annual maintenance fee of $135. ISC2 suggests 20 credits a year to stay on pace, and members pay a single maintenance fee no matter how many ISC2 certifications they hold.
Yes. ISC2 lists CGRC as approved by the Department of Defense under DoDM 8140.03. In the DoD 8140 Approved Qualifications Matrix V2.1, CGRC is listed at the Intermediate proficiency level for Authorizing Official/Designated Representative (611), Security Control Assessor (612), Information Systems Security Manager (722), Program Manager (801) and IT Program Auditor (805). See the full DoD 8140 work role paths.
CISSP is the broad credential, eight domains wide, aimed at people who design and run security programs. CGRC is narrow and deep on one process: authorizing a system and keeping it compliant. CISSP asks for five years of experience, CGRC asks for two. People doing RMF and ATO work often end up holding both, with CGRC as the credential that names their actual job.
The outline in force took effect June 15, 2024. It sets the seven domains and their weights, 125 items, three hours, and a 700 out of 1000 passing grade. ISC2 has not published a replacement outline as of September 2026, so study material aligned to the June 2024 outline is the current version. Check the effective date printed on anything you buy.
Whether you're weighing the certification, working out funding, or planning training for an assessment team, tell us where you are and we'll help you map out the right path.