If you help defense contractors protect government information, the ISACA CMMC Certified Professional (ISACA CCP™) credential brings you into the official Cybersecurity Maturity Model Certification (CMMC) ecosystem. The exam covers a lot of ground, from federal regulations to evidence and scoping scenarios, so it’s normal to feel a little overwhelmed at first. The good news is that the blueprint spells out exactly what’s tested, and a plan built around it can get you through on your first try.

In this guide, we’ll walk you through what the CCP is, the exam format, all six blueprint domains and their weights, the official resources worth bookmarking, and the questions candidates ask most often.

What Is the ISACA CCP Exam?

The CCP is the entry-level professional credential in the CMMC program, which is run by the Department of War (DoW, formerly the Department of Defense). CMMC verifies that contractors in the Defense Industrial Base (DIB) protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) on their own networks.

CCPs often help Organizations Seeking Certification (OSCs) get ready for assessments, and they can serve as assessment team members on CMMC Level 2 certification assessments under the direction of certified assessors. The CCP is also the required first step toward the CMMC Certified Assessor (CCA).

The Cyber AB originally managed the credential as the official CMMC accreditation body. In December 2025, ISACA was authorized as the CMMC Assessor and Instructor Certification Organization (CAICO), and it now handles CCP exams, certification, and continuing education. The Cyber AB remains the accreditation body.

What Is the ISACA CCP Exam Format?

Here’s the exam at a glance, based on the ISACA CCP certification page and the CCP Exam Content Outline:

  • Questions: 170 multiple-choice questions, many built around short scenarios.
  • Time: 3.5 hours (210 minutes), or about 74 seconds per question.
  • Delivery: Computer-based through PSI, at a test center or as a remotely proctored exam.
  • Registration: Continuous. You can schedule as early as 48 hours after paying, and your registration is valid for six months.
  • Training: CCP training through a CAICO-approved training provider (ATP) is mandatory. Most candidates test right after finishing the course.
  • Scoring: Results are reported as pass or fail on a scaled score. Check the ISACA CCA/CCP exam candidate guide for the current cut score and results timeline.

Seventy-four seconds per question is workable, but not if you have to look up what a C3PAO does or which document defines CUI. Practice until the basics are automatic, so you can spend your time on the scenario questions.

What Content Outline Does the ISACA CCP Exam Use?

Here is how the 170 questions break down. The question counts are approximate and calculated from the percentages.

  • Domain 1, CMMC Ecosystem: 5% (about 8 questions)
  • Domain 2, CMMC-AB Code of Professional Conduct (Ethics): 5% (about 8 questions)
  • Domain 3, CMMC Governance and Source Documents: 15% (about 26 questions)
  • Domain 4, CMMC Model Construct and Implementation Evaluation: 35% (about 60 questions)
  • Domain 5, CMMC Assessment Process (CAP): 25% (about 42 questions)
  • Domain 6, Scoping: 15% (about 26 questions)

Domain 1: CMMC Ecosystem (5%)

This domain asks you to identify and compare the roles, responsibilities, and requirements of the organizations and people in the CMMC program. It’s small, but the roles show up again in almost every other domain.

  • The DoW CIO, which owns CMMC policy under 32 CFR Part 170.
  • The Cyber AB (accreditation body) and the CAICO (certification of assessors and instructors).
  • Certified Third-Party Assessment Organizations (C3PAOs), which conduct Level 2 certification assessments.
  • The Defense Contract Management Agency’s DIBCAC, which conducts Level 3 assessments.
  • CCPs, CCAs, Lead CCAs, instructors, and approved training providers.

Study tip: For each role, know what it decides. “Who accredits?” and “Who certifies?” have different answers.

Domain 2: CMMC-AB Code of Professional Conduct (Ethics) (5%)

This domain covers the guiding principles of the Code of Professional Conduct (CoPC), along with related ISO/IEC and DoW requirements. Expect scenario questions about objectivity, confidentiality, and conflicts of interest.

  • Principles such as professionalism, objectivity, confidentiality, proper use of methods, and information integrity.
  • Recognizing and disclosing conflicts of interest.
  • Protecting OSC and CUI information you see during an engagement.

What questions look like: A client asks you to overlook a gap “just this once.” The best answer protects the integrity of the assessment and follows the proper disclosure path.

Domain 3: CMMC Governance and Source Documents (15%)

This domain tests whether you understand FCI and CUI, who is responsible for them, and which regulations and documents drive CMMC.

  • Understand FCI and CUI in nonfederal unclassified networks.
  • Determine the roles, responsibilities, and authority for FCI and CUI, such as the National Archives CUI Registry and the contracting agency’s role in marking.
  • Know the source and supplementary documents: FAR 52.204-21, DFARS 252.204-7012, -7019, -7020, and -7021, 32 CFR Part 2002, NIST SP 800-171 and 800-171A, and the CMMC Assessment and Scoping Guides.

Study tip: Build a one-page map that shows which document says what. Many questions ask which source is authoritative for a given rule.

Domain 4: CMMC Model Construct and Implementation Evaluation (35%)

This is the largest domain. It covers how the CMMC model is built and how you evaluate whether an organization has actually implemented its practices.

  • Apply CMMC source documents to evaluate how practices are implemented.
  • Apply the assessment criteria and methodology: the examine, interview, and test methods, and findings of MET, NOT MET, or NOT APPLICABLE.
  • Analyze the adequacy and sufficiency of evidence, including where it comes from, how it was collected, its quality, and how it’s used.
  • Know the structure: Level 1’s 15 requirements, Level 2’s 110 requirements in 14 families, and Level 2’s 320 assessment objectives.

What questions look like: You’re shown a policy, a screenshot, and an interview summary for one practice, and you must decide whether the evidence satisfies every assessment objective.

Domain 5: CMMC Assessment Process (CAP) (25%)

This domain focuses on the CCP’s role across the four phases of an official assessment.

  • Phase 1, Plan and Prepare the Assessment: supporting development of the assessment plan.
  • Phase 2, Conduct the Assessment: working as an assessment team member.
  • Phase 3, Report Assessment Results: contributing to the assessment report.
  • Phase 4, Evaluation of Outstanding POA&M Items: supporting review of Plan of Action and Milestones close-out.
  • Choosing the right phase and step for a given scenario.

Study tip: Know where an activity belongs. A readiness review happens in Phase 1, not in the middle of evidence collection.

Domain 6: Scoping (15%)

Scoping decides which assets an assessment covers. The CCP blueprint focuses on high-level scoping as described in the CAP and on generating an appropriate scope for FCI assets.

  • Understand high-level scoping concepts from the CAP.
  • Given a scenario, analyze an organization’s environment to scope FCI assets for Level 1.
  • Recognize out-of-scope assets and specialized assets, and know how Level 2 asset categories differ.

What questions look like: A small machine shop stores contract drawings on one file server and uses a separate guest Wi-Fi network. You’ll decide which assets process, store, or transmit FCI.

How Should You Use the CCP Blueprint to Build a Study Plan?

Treat the blueprint as your checklist. Here’s how to turn it into a plan:

  1. Take a baseline. Answer a mixed set of practice questions before reviewing so you know where you stand.
  2. Weight your time. Domains 4 and 5 make up 60% of the exam. Put most of your hours there, then scoping and governance.
  3. Don’t skip the 5% domains. Ecosystem and ethics questions are often quick points if you know the roles cold, and the roles help you answer CAP questions too.
  4. Map every miss. Label wrong answers by domain and by source document. Patterns show up fast.
  5. Finish with timed, mixed practice. In the final weeks, practice at exam pace so scenario stems don’t slow you down.

What Official Resources Should You Use?

Frequently Asked Questions About the ISACA CCP Exam

How many questions are on the CCP exam, and how long is it?
There are 170 questions, and you have 3.5 hours (210 minutes).

Who administers the CCP exam?
ISACA, as the CAICO, handles CCP exams and certification, with testing through PSI. The Cyber AB remains the CMMC accreditation body.

Do I have to take training first?
Yes. CCP training through an approved training provider is mandatory to earn the credential, and most candidates sit for the exam right after the course.

What is the passing score?
The exam uses a scaled score. Confirm the current cut score in the ISACA candidate guide rather than relying on unofficial figures.

How do I maintain the CCP once I earn it?
Earn at least 120 continuing professional education (CPE) hours every three years, with at least 20 each year, pay the annual maintenance fee, and follow ISACA’s Code of Professional Ethics.

Start Preparing for the ISACA CCP Exam With Pocket Prep

Pocket Prep’s ISACA CCP™ practice questions give you 500 exam-style questions across all six domains, each with a detailed answer explanation that ties the right choice back to CMMC source documents. Use Weakest Subject quizzes to target Domains 4 and 5, then build exam stamina with Timed Quiz sessions. With consistent daily practice, you’ll walk into the testing center with confidence.