Certified in Cybersecurity (CC) Exam Guide
ISC2 Certified in Cybersecurity (CC) validates foundational cybersecurity knowledge across security principles, resilience and incident concepts, access controls, network security, and security operations. It is intended for newcomers, including students, career changers, and entry-level professionals; ISC2 states that no prior work experience is required. This guide helps you decide whether CC fits your starting point, build a study plan around the current blueprint, and schedule the exam with the administrative deadlines in mind.
Decide whether CC is the right first certification
CC is an entry-level ISC2 certification for people who need to demonstrate foundational cybersecurity knowledge before they have accumulated professional security experience. It is a sensible fit when you want a structured way to learn core concepts and explain them clearly in an entry- or junior-level context.
ISC2 identifies IT professionals, career changers, college students, and recent graduates as suitable audiences. Its official self-paced training is also aimed at students, prospective employees, entry-level professionals, and career changers. That range matters: the credential is not restricted to people who already work in security, but it also is not a substitute for building practical workplace or technical capability over time.
Take CC if your main need is breadth. The current outline connects risk, security objectives, continuity and response, access, networking, and everyday security operations. A candidate moving from a nontechnical role may benefit from that shared vocabulary before choosing a more specialized direction. An IT support professional may use it to organize concepts already encountered at work and identify gaps.
Do not choose it solely because a job listing contains the word cybersecurity. Read several target roles and compare their recurring tasks with the outline. If the roles are primarily about administering a specific cloud platform, coding, penetration testing, or advanced incident investigation, make CC a foundation rather than treating it as the entire preparation plan for that role.
A practical decision test is simple: can you explain why a control exists, what risk it addresses, who operates it, and what happens when it fails? If those questions feel unfamiliar across most of the five domains, CC study has a clear purpose. If they are already routine, use the outline as a gap analysis before committing time and budget.
What the credential does and does not establish
ISC2 describes CC as evidence of foundational knowledge, skills, and abilities for an entry- or junior-level cybersecurity role. That is a useful claim to make accurately on a résumé or in an interview: present it as proof of a baseline, not as proof that you have performed every security task independently.
The official CC page also lists the certification as ANAB-accredited to ISO/IEC Standard 17024 and approved under the U.S. Department of Defense 8140.03 framework. Candidates considering employer or public-sector requirements should confirm the relevant employer policy directly rather than assuming that a framework listing automatically meets a particular vacancy requirement.
Know the five domains before selecting study materials
The current CC blueprint is organized around five domains, so the official exam outline should be the document that decides what you study and what you leave out. Start by downloading the version in your intended exam language and make it your checklist.
Security Principles carries 26% of the current CC exam and should anchor early study. ISC2 describes foundational coverage of information assurance concepts including confidentiality, integrity, availability, authentication, non-repudiation, privacy, and risk management. Build definitions, but also practise selecting the concept that best fits a short business situation.
Network Security carries 24% of the current CC exam. Treat it as more than a vocabulary exercise: connect basic networking ideas to vulnerabilities, traffic monitoring, preventative mechanisms, and the security purpose of network infrastructure. Draw simple diagrams from memory so that terms are attached to a flow of communication rather than stored as isolated flashcards.
Access Controls Concepts carries 22% of the current CC exam. ISC2’s training describes this area as differentiating physical and logical access controls. When revising, ask what a control protects, how an identity is authenticated, what permission is granted, and what evidence might show that access occurred.
Security Operations carries 18% of the current CC exam. ISC2 says the domain covers aspects of data security concepts and policies, system hardening, and security awareness training, alongside safeguarding an organization against and responding to threats. This is where candidates should connect policy language to routine operational decisions.
Business Continuity, Disaster Recovery and Incident Response Concepts carries 10% of the current CC exam. It has the smallest listed weight, but skipping it is a mistake: it requires candidates to distinguish related disciplines that are easily confused under pressure. Review each term through its objective, trigger, ownership, and desired outcome.
Use blueprint weights without becoming ruled by them
The published weights are a planning aid, not permission to neglect any domain. Allocate more first-pass time to Security Principles, Network Security, and Access Controls Concepts, then reserve a final review cycle in which every domain must meet your own readiness standard.
One workable approach is to spend the first half of your available study time on conceptual coverage and the remainder on retrieval practice, mixed-domain questions, and error review. Adjust the order if a diagnostic shows a major weakness. For example, someone with networking experience may need less initial explanation in Network Security but more deliberate work on risk and resilience terminology.
Avoid trying to predict the exact number or wording of questions from domain percentages. The exam uses Computerized Adaptive Testing and the outline gives average domain weights. Your preparation should therefore aim for reliable understanding across the blueprint, not a calculation based on a fixed item total.
Plan for the current outline and the upcoming change
ISC2 states that the current CC exam outline is effective October 1, 2025, and that a new outline takes effect September 1, 2026. Your study materials must match the outline that applies to your scheduled exam rather than merely the newest resource you find.
Before buying a course, booking the appointment, or spending weeks with a guide, download the applicable official outline and check its effective date. Repeat that check when your study window crosses the announced change date. This is especially important for candidates who purchase an exam and then postpone study.
The official outline is available in English, Chinese, Japanese, German, and Spanish. ISC2 lists the same languages for the CC exam. Use the language-specific outline as the control document for terms and domain labels, particularly if you study with translated notes from several sources.
The outline also notes that Domain 1 introduces how AI affects confidentiality, integrity, and availability; Domain 2 addresses how AI can complicate and enhance resilience; Domain 4 covers AI influences on traffic monitoring and threat prevention; and Domain 5 considers day-to-day security work alongside AI. Treat such references as part of the stated blueprint, but do not let fashionable AI content displace the underlying security concepts.
Build a personal objective checklist
Turn each outline objective into a short prompt you can answer without notes. A useful format is: define the term, distinguish it from a close alternative, identify its purpose, and apply it to a brief scenario. This exposes the difference between recognizing a phrase and understanding it.
Maintain three labels beside each objective: secure, uncertain, and missed. Move an objective to secure only after you can answer it correctly on separate occasions and explain why competing answers would not fit. This produces a much more actionable review list than repeatedly rereading highlighted pages.
Choose a preparation route that fits your starting point
Choose one primary learning path and use the official outline to govern it; then add a small number of tools that make recall and review easier. Mixing many courses at the start often creates duplicate notes and leaves too little time for applying concepts.
ISC2 provides official CC self-study resources, including the exam outline and official flash cards. These are a practical baseline for an independent learner because they keep the stated domains visible throughout preparation. Use flash cards for terminology and relationships, not as your only method of study.
ISC2’s official online self-paced CC training has no prerequisites. It includes assessments, knowledge checks, end-of-domain quizzes, study sheets, flash cards, a glossary, and learner-progress tools. The official training is available with 90-day and 180-day access options, with access beginning on the purchase date. Select the shorter option only if you have already protected regular study time on your calendar.
ISC2 says its adaptive version is available only in English, while other language versions use a linear format. That is a planning distinction, not a measure of quality. A candidate using a linear version can create a manual adaptation loop by logging missed concepts, revisiting the relevant lesson, and retesting several days later.
The official self-paced course requires learners to complete and pass each domain with a score of 70% or higher, including knowledge checks and the end-of-domain assessment, and to pass the final assessment with a score of 70% or higher. Those course requirements are not presented as the CC exam passing score, so do not equate a course result with exam readiness.
When self-study is enough
Self-study is often appropriate when you can set a recurring schedule, work carefully from the outline, and diagnose your own weak areas. Begin with a short baseline quiz or self-test, but use the result only to prioritize study. A low score is a starting measurement, not evidence that you cannot pursue the certification.
Use a simple study log after every session. Record the domain, objectives studied, one idea you could explain well, one uncertainty, and the next retrieval task. This reduces the common problem of finishing content while retaining no evidence of what needs review.
When structured training is worth considering
Structured training can be useful when you need an ordered curriculum, feedback, or a fixed access period to create momentum. ISC2’s self-paced offering includes feedback, knowledge checks, and a dashboard, which may help candidates who struggle to identify gaps from reading alone.
Make the purchase decision around your study capacity rather than marketing claims. Compare the access period with your work, school, caregiving, and travel commitments. Since the stated training access starts from purchase, delay purchase until you can begin promptly.
Follow a practical study roadmap
A strong CC plan moves from mental models to controlled recall and then to mixed application. Do not postpone practice until every page of a course is complete; early practice reveals misunderstandings while there is still time to correct them.
First, establish the information-security foundation. Study the security objectives and related concepts in Security Principles, then connect them to risk identification, assessment, treatment, tolerance, and priorities. Write plain-language examples of an asset, a threat, a vulnerability, a control, and a remaining risk. The goal is to explain relationships without relying on identical textbook wording.
Second, study Access Controls Concepts with Security Principles still visible. Compare physical and logical controls and connect authentication to authorization in your own notes. For each control, state the actor, protected resource, decision point, and expected evidence. This prevents the frequent mistake of treating every access term as interchangeable.
Third, cover Network Security through diagrams and cause-and-effect questions. Sketch a basic network communication path, then identify where monitoring, segmentation, preventative mechanisms, or other protections fit. If a term cannot be placed on a diagram or connected to a security outcome, return to the source material before adding more terminology.
Fourth, study Business Continuity, Disaster Recovery and Incident Response Concepts as a connected set. Create a comparison table that separates the objective of keeping critical activity available, restoring after disruption, and handling an incident. Then test yourself with changing scenarios: an outage, suspected malicious activity, unavailable systems, or a need to communicate and recover.
Fifth, finish the first pass with Security Operations. Link data security, policies, hardening, awareness, and response activities to the earlier domains. A security operation is easier to remember when you can identify the risk it reduces, the people involved, and the evidence that the activity occurred.
Finally, shift to interleaved review. Mix domains in each session, use questions to retrieve rather than merely recognize answers, and devote the largest share of review time to your documented misses. Revisit secure topics periodically so that earlier material does not fade while you study later domains.
A six-stage calendar you can adapt
Stage 1 is orientation: obtain the applicable outline, list every objective, choose resources, and set study sessions. Stage 2 is Security Principles and initial risk vocabulary. Stage 3 combines Access Controls Concepts and Network Security. Stage 4 covers Business Continuity, Disaster Recovery and Incident Response Concepts, followed by Security Operations.
Stage 5 is consolidation. Use mixed practice, update the error log, redraw diagrams, and explain distinctions aloud without notes. Stage 6 is exam readiness and administration: revisit repeated weaknesses, confirm the correct exam outline, review official policies, and verify account and identification information. The stages matter more than the number of calendar days; extend any stage that exposes unresolved conceptual gaps.
Candidates with little IT background should spend extra time in Stages 2 through 4. Candidates with existing support or networking experience should still test the conceptual areas they may dismiss too quickly, especially risk, privacy, continuity, recovery, and incident terminology.
Use practice questions ethically and productively
Use questions to discover reasoning gaps, not to collect remembered answer letters. After every missed question, identify the tested concept, why your selected answer seemed plausible, what fact changes the decision, and which outline objective needs review. Then create one new scenario in your own words.
Avoid sources that claim to provide live, leaked, or guaranteed exam questions. They are not a sound basis for learning, can conflict with examination rules, and encourage memorization without the transferable understanding CC is designed to assess. Official resources and legitimate study materials should support learning the published domains rather than reproducing protected exam content.
Understand the exam appointment and delivery facts
The current CC exam is delivered through Pearson VUE testing centers, uses Computerized Adaptive Testing, and is scheduled for 2 hours. ISC2 lists 100-125 items, multiple-choice and advanced item types, and a passing grade of 700 out of 1000 points.
ISC2 lists the exam languages as English, Chinese, Japanese, German, and Spanish. The outline notes that Chinese-language CC exams are available only during select appointment windows, so candidates seeking that language should check availability before making a study deadline depend on a preferred date.
After purchasing an exam, ISC2 says candidates have up to 365 days to schedule and sit for it. This is a maximum window, not a recommendation to delay. A better practical choice is to schedule once you have a realistic study plan, while leaving sufficient room to move the appointment if needed under the applicable rules.
To schedule, ISC2 directs candidates to log in, go to Courses and Exams, and select Schedule after purchase. The process then leads to Pearson VUE to finalize the appointment. Enter account information exactly as it appears on the identification you will present at the testing center: ISC2 says a mismatch means you cannot test and will not be reimbursed for fees paid.
Rescheduling and cancellation decisions
ISC2 says examinations cannot be rescheduled within 24 hours of the appointment. Its pricing page lists a U.S. $50 rescheduling fee and a U.S. $100 cancellation fee, while regional currencies and charges can vary. Confirm the current terms and your region’s price before changing an appointment.
For rescheduling, ISC2 instructs candidates to open Courses and Exams in their ISC2 account, select Reschedule beside the exam, review the Exam Account Information form, then use the Pearson VUE dashboard to select Reschedule or Cancel. Do not wait until the final day to check an appointment conflict.
If you do not sit for the exam within 365 days of the purchase date, ISC2 states that the exam fee will not be refunded. Put that deadline, your planned readiness checkpoint, and any appointment-change deadline in one calendar as soon as you purchase.
Budget with current official figures only
For the Americas and other regions not separately listed, ISC2 lists the standard CC exam registration price as U.S. $199, with pricing and taxes based on the exam location. The official pricing page also lists separate regional prices, so use Pearson VUE registration information to confirm the amount applicable to your appointment.
ISC2 offers an exam option with Peace of Mind Protection that includes two attempts in the bundle price. ISC2 states that candidates have 180 days from purchase to sit both attempts, with a 30-day waiting period between attempts. Consider this only after checking the current offer terms and deciding whether two attempts fit your actual preparation and budget plan.
Prepare for the adaptive format without guessing at it
Computerized Adaptive Testing means your best preparation is consistent command of the published content, not an attempt to infer performance from individual questions. Read each item for the decision it asks you to make, use the stated facts, and avoid allowing one difficult item to disrupt the next one.
Practise answering scenario prompts in a disciplined sequence: identify the security objective or operational goal, note the relevant asset or event, separate closely related terms, and select the response that directly addresses the stated requirement. This approach helps across Security Principles, access controls, resilience concepts, networking, and operations.
During revision, deliberately contrast concepts that candidates commonly blend together. For example, separate authentication from authorization, a policy from a technical control, an incident response activity from disaster recovery, and confidentiality from privacy. The value is not in memorizing a list of differences; it is in recognizing which difference changes the correct action in context.
Do not make practice-test score thresholds your sole scheduling rule. The published passing grade is 700 out of 1000 points, while third-party practice scoring may use a different scale, different question design, and different coverage. Schedule based on broad outline coverage, repeatable explanation of objectives, and a shrinking error log.
Common preparation mistakes to correct early
Mistake one is treating the biggest domains as the only domains. Correct it by maintaining a checklist that requires some review of all five domains every week during the later stages. Mistake two is taking notes without retrieval. Correct it by closing the material and explaining or diagramming the idea from memory.
Mistake three is booking the exam before checking the applicable outline date and available test-center appointment. Correct it by checking both first, especially around the announced September 1, 2026 outline change. Mistake four is confusing course completion requirements with the certification exam result. Keep those measures separate in your tracking sheet.
Mistake five is forgetting administration until the appointment is near. Correct it by verifying the name in your ISC2 account against your required identification when you schedule, then reviewing the official candidate policies and appointment instructions again before test day.
Complete certification and plan maintenance after passing
Passing the CC exam is followed by ISC2’s Certification Application process. ISC2 says candidates who pass an ISC2 credential examination must complete the application within nine months of the exam date, and that the application can be submitted after notification of a successful pass is received.
For CC specifically, ISC2 states there is no work-experience requirement in the endorsement application. The application includes questions and agreements about adherence to the ISC2 Code of Ethics and privacy policy. This distinguishes CC from ISC2 credentials that require an endorser to attest to professional experience.
Once the certification application is approved, ISC2 says the final step is payment of the first Annual Maintenance Fee. ISC2 states that the CC Annual Maintenance Fee is U.S. $50 per year. The CC page also states that maintaining the certification requires 45 CPE credits during the three years of the certification cycle, along with the U.S. $50 annual fee.
Build the maintenance habit early. Keep a record of qualifying learning activities, dates, and evidence as you begin using the certification. The practical benefit is administrative: you will not need to reconstruct several years of professional development at the end of the cycle. Check current ISC2 maintenance rules before relying on any activity for credit.
Your next five actions
Download the current official CC exam outline in your intended language and confirm whether your planned appointment falls before or after the September 1, 2026 outline change. Then list each objective in a tracker and identify your weakest domain from an honest baseline assessment.
Choose one primary study route, set recurring sessions, and decide whether the official 90-day or 180-day self-paced access period matches your availability if you want structured training. Begin with Security Principles, but schedule all five domains before you start.
Check Pearson VUE test-center availability in your preferred language before setting a final target date. When purchasing and scheduling, ensure the name in your ISC2 account exactly matches the identification you will present. Finally, put the 365-day exam deadline and any appointment-change deadlines in your calendar.
Conclusion
CC is best approached as a foundation credential: study the published objectives deeply enough to distinguish related concepts and apply them to basic security situations. Use the current outline as the source of truth, plan around the announced outline change, and treat scheduling, identification, and post-pass application steps as part of the certification project. A measured plan, an error log, and repeated mixed-domain review will provide a more reliable basis for readiness than speed or memorized answers.
Related exams
- CSSLP exam — Certified Secure Software Lifecycle Professional
- ISSAP Information Systems Security Architecture Professional
- ISSEP Information Systems Security Engineering Professional
- Information Systems Security Management Professional (ISSMP) Exam