If you’re taking your first real step into cybersecurity, ISC2’s Certified in Cybersecurity (CC) credential is built for you. It’s an entry-level certification with no work experience requirement, but the exam still covers a lot of ground, from risk management and access control to cloud security and incident response. That breadth can feel overwhelming at first. The good news is that ISC2 publishes exactly what it tests, and a plan built around that blueprint will help you pass on your first try.

In this guide, we’ll walk you through the exam format, the five domains in the new outline that took effect on September 1, 2026, the official resources worth using, and the questions candidates ask most often.

What Is the ISC2 CC Exam?

ISC2 is the nonprofit organization behind well-known security credentials such as the CISSP and CCSP. According to the official exam outline, the CC “will prove to employers you have the foundational knowledge, skills and abilities necessary for an entry- or junior-level cybersecurity role.”

The exam targets career changers, students, recent graduates, and IT professionals who want to add security to their skill set. No specific work experience or formal education is required, although ISC2 recommends basic IT knowledge. Questions test whether you understand core concepts well enough to apply them, such as picking the right control for a risk or recognizing the correct step in an incident, rather than only reciting definitions.

What Is the ISC2 CC Exam Format?

Here is the exam at a glance, based on the ISC2 CC Certification Exam Outline (effective September 1, 2026) and the ISC2 FAQ page:

  • Questions: 100 to 125 items.
  • Format: Computerized adaptive testing (CAT). The exam adjusts to your performance, so the number of questions you see varies.
  • Question types: Multiple-choice and advanced item types.
  • Time: 2 hours (120 minutes).
  • Passing score: 700 out of 1,000 scaled points.
  • Delivery: Pearson VUE testing centers.
  • Languages: English, Chinese, Japanese, German, and Spanish.
  • Results: You receive a preliminary pass or fail result at the test center when you finish. ISC2 follows up by email with official results.
  • Fee: U.S. $199 for standard registration in the Americas and most regions, per the ISC2 exam pricing page.

Even at the maximum of 125 questions, two hours gives you just under a minute per item. Most CC questions are short, so time is rarely the main problem. Accuracy on scenario wording is.

What Changed in the September 2026 Outline?

ISC2 released a new CC outline effective September 1, 2026, so any exam you take today follows it. The exam still has five domains, and the format, time limit, and passing score stayed the same. What changed is the content. ISC2 describes the update as placing more emphasis on governance, cloud security, and threat intelligence, and its outline page notes that artificial intelligence concepts now appear across all five domains.

The biggest structural shifts are a new Security Governance domain, a dedicated identity and access management (IAM) domain, cloud security folded into networking, and incident response moving into security operations. Business continuity and disaster recovery didn’t disappear. They now sit under governance as “redundancy.” If your study guide or video course was published before 2026, it was written for the previous outline, so use this breakdown to fill the gaps.

What Is on the ISC2 CC Exam?

Here are the five domains and their official weights:

  • Domain 1, Security Principles: 24%
  • Domain 2, Security Governance: 17.3%
  • Domain 3, Identity and Access Management (IAM) Concepts: 20%
  • Domain 4, Networking and Cloud Security Concepts: 21.3%
  • Domain 5, Security Operations and Incident Response: 17.3%

Domain 1: Security Principles (24%)

This is the largest domain and the foundation for everything else. It covers the vocabulary of security, how organizations think about risk, and the professional standards ISC2 expects of its members.

  • Cybersecurity concepts: confidentiality, integrity, availability, authentication, authorization, and accounting (AAA), non-repudiation, and privacy.
  • Risk management concepts, including the risk management lifecycle and processes.
  • Governance concepts: regulations and laws, frameworks and guidelines, and the difference between policies, standards, and procedures.
  • Technical, administrative, and physical security controls.
  • Professional and ethical conduct, including due care, due diligence, and the ISC2 Code of Ethics.

Study tip: Know the four ISC2 Code of Ethics canons in order. When an ethics question asks what you should do, the answer that protects society and the common good usually wins.

Domain 2: Security Governance (17.3%)

This is the new domain in the 2026 outline. It asks how an organization directs and measures its security program, and how it stays resilient when things go wrong.

  • Planning governance, risk, and compliance (GRC): its purpose, importance, frameworks, and tools.
  • Redundancy through business continuity and disaster recovery.
  • Security awareness and organizational culture, including social engineering, phishing, and password protection.
  • Measuring cybersecurity effectiveness with key metrics, key risk indicators (KRIs), dashboards, scorecards, and reports.

What questions look like: Expect scenarios such as choosing which metric best shows that phishing training is working, or identifying which plan restores business operations after a site outage.

Domain 3: Identity and Access Management (IAM) Concepts (20%)

This domain moves beyond basic access control to the full life cycle of a user’s identity, from the day an account is created to the day it’s removed.

  • Identity life cycle management: role definition, provisioning, access reviews, deprovisioning, and IAM frameworks and tools.
  • Logical access controls, including the principle of least privilege and separation of duties.
  • Access control models such as discretionary (DAC), mandatory (MAC), and role-based (RBAC).

Study tip: Watch for “privilege creep” scenarios, where an employee changes roles and keeps old access. Periodic access reviews and prompt deprovisioning are the usual fixes.

Domain 4: Networking and Cloud Security Concepts (21.3%)

This domain combines networking fundamentals with modern architecture and cloud. Newcomers often find it the most technical area.

  • Network security basics: the OSI and TCP/IP models, IPv4 and IPv6, VPNs, firewalls, wireless, and embedded systems, industrial control systems (ICS), and IoT.
  • Network security architecture: segmentation, VLANs, micro-segmentation, defense in depth, and Zero Trust.
  • Cloud security: cloud characteristics, service models (IaaS, PaaS, SaaS), deployment models, and the shared security model.

What questions look like: You might be asked who is responsible for patching the operating system in an IaaS deployment (the customer) or which architecture assumes no user or device is trusted by default (Zero Trust).

Domain 5: Security Operations and Incident Response (17.3%)

This domain covers the day-to-day work of protecting data and systems and responding when something goes wrong.

  • Data security: data handling, classification, labeling, masking, and sanitization, plus encryption types and quantum-resistant cryptography.
  • Security operations: logging and monitoring, security event triage, threat actors, cyber threat intelligence, and threat frameworks.
  • Incident response: data handling policy, implementing an incident response plan, and IR exercises such as tabletop tests.
  • Asset protection: asset lifecycle management, end-of-life software and devices, and configuration and change management.
  • Security testing: red, blue, and purple teaming, vulnerability scanning, static and dynamic analysis, threat modeling, and physical tests such as tailgating and impersonation.

Study tip: Know the difference between symmetric and asymmetric encryption and hashing, and when each is used. These show up often and in many disguises.

How Should You Use the ISC2 CC Blueprint?

Treat the outline as your master checklist. A simple process works well:

  1. Start with a mixed baseline. Answer a set of questions across all five domains before you study in depth, so you know where you actually stand.
  2. Weight your time. Security Principles and Networking and Cloud Security together make up about 45% of the exam. Weakness there costs the most.
  3. Map every miss to an objective. Tag each missed question with its outline number (for example, 4.3 cloud security), so patterns become obvious.
  4. Close the new-content gaps. If you’re using older materials, add focused time for GRC, metrics, identity life cycle, cloud, threat intelligence, and security testing.
  5. Return to mixed practice. Because the exam is adaptive, you need steady performance across domains, not just strength in one.

What Official Resources Should You Use?

Commonly used ISC2 CC study textbooks:

  • Certified in Cybersecurity (CC℠) Study Guide, 2nd Edition (ISBN 978-1394454891)
  • Certified in Cybersecurity All-in-One Exam Guide, 1st Edition (ISBN 978-1265203818)

Frequently Asked Questions About the ISC2 CC Exam

What score do I need to pass the ISC2 CC exam?
You need 700 out of 1,000 scaled points. Because the exam is adaptive, the scaled score reflects the difficulty of the questions you answered, not a simple percentage correct.

Do I need work experience to take the CC?
No. ISC2 doesn’t require work experience or a degree. You must be at least 16 years old to sit for an ISC2 exam.

When do I get my results?
You get a preliminary pass or fail at the test center right after the exam. Official results follow by email from ISC2.

What happens after I pass?
You complete a certification application, agree to the ISC2 Code of Ethics, and pay the U.S. $50 Annual Maintenance Fee. ISC2 says this must be done within nine months of passing, or you’ll need to retake the exam.

What if I don’t pass?
You can retake the exam, but you pay the full fee for each attempt unless you bought a voucher with ISC2’s Peace of Mind Protection. Waiting periods apply between attempts, so check the current rules on the ISC2 exam registration and policies page before you schedule.

Start Preparing for the ISC2 CC Exam With Pocket Prep

Pocket Prep’s ISC2 CC exam prep gives you 800 practice questions, each with a detailed explanation, plus a full-length mock exam to test your readiness under timed conditions. Use the Weakest Subject quiz to zero in on the domains that need the most work, and Question of the Day to keep your streak going. You’ve got this, one question at a time.