Breaking into cybersecurity can feel like a catch-22: employers want experience, but you need a job to get experience. ISC2 designed the Certified in Cybersecurity (CC) credential to help solve that exact problem. It shows employers you understand the fundamentals of security, and it doesn’t require any prior work experience.
In this guide, we’ll walk you through who the CC is for, how to get certified, how long to study, the careers it can support, and where to go next once you’ve earned it.
Who Should Take the ISC2 CC Exam?
ISC2 positions the CC as proof of “the foundational knowledge, skills and abilities necessary for an entry- or junior-level cybersecurity role.” It’s a strong fit if you are:
- A career changer moving into security from another field, such as customer service, the military, teaching, or finance.
- A student or recent graduate in IT, computer science, or a related program who wants a recognized credential on a first resume.
- An IT professional in help desk, desktop support, or systems or network administration who handles security tasks and wants to formalize that knowledge.
- A non-technical professional in areas like compliance, audit, project management, or HR who works closely with security teams and wants a shared vocabulary.
Who Might Choose a Different Credential?
If you already have several years of security experience, the CC may not add much to your resume. You may get more value from a more advanced credential, such as the Systems Security Certified Practitioner (SSCP) or the Certified Information Systems Security Professional (CISSP), if you meet their experience requirements.
What Are the ISC2 CC Eligibility Requirements?
The CC is one of the most accessible security certifications available. ISC2 doesn’t require work experience or formal education, although it recommends basic IT knowledge. You must be at least 16 years old to sit for an ISC2 exam.
How Do You Get Certified?
- Create an ISC2 account and choose how you want to prepare. ISC2 offers exam-only purchases and training bundles with self-paced or instructor-led options.
- Register and pay for the exam. The standard fee is U.S. $199 in the Americas and most regions, according to the ISC2 exam pricing page.
- Schedule with Pearson VUE and take the exam at a testing center.
- Pass with 700 or more out of 1,000 scaled points.
- Complete your certification application, agree to the ISC2 Code of Ethics, and pay the U.S. $50 Annual Maintenance Fee (AMF). According to the ISC2 FAQ, you must finish these steps within nine months of passing, or you’ll have to retake the exam.
A quick note on cost: ISC2’s One Million Certified in Cybersecurity program, which provided free training and a free exam, closed to new enrollments on May 20, 2026. Anyone who enrolled before then has until December 31, 2026, to sit for the exam, per the program page. If you’re starting now, plan to pay the standard fee. Policies can change, so confirm the current details on ISC2’s site before you register.
How Long Should You Study for the ISC2 CC Exam?
Most candidates need about 4 to 8 weeks of steady study at roughly 5 to 8 hours per week. ISC2 doesn’t prescribe a timeline, so adjust based on your background:
- Newcomers to IT: Plan for 8 weeks or more. Networking and cloud concepts will likely take the longest.
- IT professionals: 3 to 5 weeks is often enough. Spend most of your time on governance, risk, ethics, and incident response, which day-to-day IT work may not cover.
Sample 6-Week Study Plan
This plan follows the domain weights in the September 1, 2026, outline:
- Week 1, Security Principles (24%): Take a mixed baseline quiz. Then learn the CIA triad, AAA, non-repudiation, privacy, risk management terms, control types, and the ISC2 Code of Ethics.
- Week 2, Security Governance (17.3%): Cover GRC, policies versus standards versus procedures, business continuity and disaster recovery, security awareness, and metrics such as KRIs.
- Week 3, IAM Concepts (20%): Study the identity life cycle, least privilege, separation of duties, and DAC, MAC, and RBAC models.
- Week 4, Networking and Cloud Security (21.3%): Learn the OSI and TCP/IP models, common ports and protocols, firewalls, VPNs, segmentation, Zero Trust, and cloud service and deployment models.
- Week 5, Security Operations and Incident Response (17.3%): Focus on data classification and sanitization, encryption and hashing, logging and triage, the incident response lifecycle, change management, and security testing.
- Week 6, Review: Take a full-length mock exam, review every missed question, and use short mixed quizzes to reinforce weak areas.
What Careers Can the ISC2 CC Support?
The CC is a door-opener, not a guarantee of a specific job. It pairs well with hands-on skills, a degree, or other IT certifications. Common entry-level roles where the CC can help include:
- Security operations center (SOC) analyst (Tier 1)
- Junior cybersecurity or information security analyst
- IT support or help desk technician with security duties
- Network or systems administrator
- IT audit, GRC, or compliance associate
These roles exist across government, healthcare, finance, technology companies, managed security service providers, and consulting firms.
What Is the Salary for ISC2 CC Holders?
The U.S. Bureau of Labor Statistics (BLS) doesn’t track pay by certification, but it does track information security analysts, a common goal for CC holders. According to the BLS Occupational Outlook Handbook, the median annual pay for information security analysts was $129,180 in May 2025.
The outlook is strong. BLS projects employment of information security analysts to grow 21% from 2025 to 2035, much faster than the average for all occupations, with about 14,100 openings each year. Keep in mind that the median reflects analysts at all experience levels, and BLS notes a bachelor’s degree is the typical entry-level education. Entry-level pay is usually lower and depends on your location, employer, and background.
How Do You Maintain the ISC2 CC?
The CC runs on a three-year certification cycle. To keep it active, you must:
- Earn 45 continuing professional education (CPE) credits during each three-year cycle. ISC2 recommends earning about 15 per year.
- Pay the U.S. $50 AMF each year. This is the rate for members who hold only the CC, per the ISC2 AMF overview.
- Continue to follow the ISC2 Code of Ethics.
You can earn CPE credits through webinars, courses, conferences, and other professional development. Once you move up to another ISC2 certification, your maintenance requirements change to match that credential.
What Certifications Stack Well With the ISC2 CC?
The best next step depends on where you want to go:
- CompTIA Security+: A widely requested entry-level security certification that goes deeper into hands-on topics and is often listed in job postings, including many U.S. Department of Defense roles.
- CompTIA Network+ or Cisco CCNA: Good choices if networking was your weakest CC domain or you’re aiming for network or SOC work.
- ISC2 SSCP: A practitioner-level ISC2 credential for hands-on security roles. It requires one year of paid work experience in at least one domain.
- ISC2 CISSP: The long-term goal for many security professionals. It requires five years of cumulative paid experience in two or more of its eight domains. Candidates without the experience can pass the exam and become an Associate of ISC2 while they build it.
- ISC2 CCSP or cloud provider certifications: Logical next steps if the new cloud security objectives sparked your interest.
Start Preparing for the ISC2 CC Exam With Pocket Prep
Ready to take the first step? Pocket Prep’s ISC2 CC exam prep includes 800 practice questions with detailed explanations and a full-length mock exam, so you can check your readiness before test day. Build daily habits with Quick 10 and study reminders, then use Missed Questions to turn mistakes into points. Your cybersecurity career starts here.