ISC2 CC study guide
ISC2's Certified in Cybersecurity (CC) is an entry-level credential for career changers, students, and IT professionals moving into security. No work experience is required.
Details below were checked in October 2026 against official and widely cited sources. Exams, prices, and requirements change, so confirm with the certifying body before you register.
New outline: ISC2 updated the CC exam on September 1, 2026, its first major content update since launch. Three domains were renamed and rebuilt, and AI topics now appear throughout.
Eligibility
- No experience required. Candidates must agree to the ISC2 Code of Ethics.
- After passing, you pay an annual maintenance fee and earn continuing professional education credits to stay certified.
- ISC2 has periodically offered free online training and exam vouchers for CC. Check ISC2 for current offers.
Exam format & cost
| Length | Reported as 100–125 questions, 2 hours (adaptive) |
|---|---|
| Passing score | 700 out of 1000 |
| Exam fee | Check ISC2 (free-voucher programs have been offered) |
| Maintenance | ISC2 annual maintenance fee plus CPE credits each three-year cycle |
Domains
| Domain | Weight |
|---|---|
| 1. Security Principles | 24% |
| 2. Security Governance | 17.3% |
| 3. Identity and Access Management (IAM) Concepts | 20% |
| 4. Networking and Cloud Security Concepts | 21.3% |
| 5. Security Operations and Incident Response | 17.3% |
Weights published by ISC2 for the September 2026 outline. The site's exam simulation rounds them to whole numbers.
How to study
- Focus on core vocabulary: CIA triad, risk terms, control types, and authentication factors.
- Know basic network concepts: common ports, segmentation, firewalls, and cloud shared responsibility.
- Understand incident response, business continuity, and backup basics.
- Questions are conceptual, so you don't need hands-on tool experience.
Ready to test yourself on ISC2 CC?
Start ISC2 CC practice