Certified Authorization Professional Exam Guide: Preparing for the Current CGRC Credential
The Certified Authorization Professional (CAP) certification is now called Certified in Governance, Risk and Compliance (CGRC). The current credential validates the ability to apply security risk management, governance, controls, assessment, authorization and compliance maintenance to information systems. It serves professionals who make or support risk and compliance decisions, including auditors, compliance officers, GRC analysts, system security managers and information assurance specialists. This guide helps you decide whether your experience fits, what to study first, how to use the exam outline and when you are ready to schedule the exam.
What happened to the CAP certification?
CAP is the former name of the ISC2 Certified in Governance, Risk and Compliance (CGRC) certification. ISC2 renamed it effective February 15, 2023, and stated that the change affected the certification name rather than the exam, course content or qualifications to pursue the credential. Candidates searching for CAP preparation should therefore use the current CGRC exam outline and experience requirements.
Use the current name when planning
Older references may describe the credential through the U.S. government authorization process or call it CAP. That background remains useful for understanding the credential’s authorization focus, but it should not replace the current outline. ISC2 says the certification was renamed to represent its governance, risk and compliance knowledge, skills and abilities more accurately and to support professionals in both public- and private-sector environments.
Do not treat the rename as a new exam
The rename is not a reason to look for a separate CAP examination blueprint. The official announcement says the exam and course content were not impacted by the name change. Build your preparation around the current CGRC outline, then confirm the policies and procedures that apply when you register.
What does the credential validate?
CGRC validates the ability to advocate for security risk management while pursuing information-system authorization in support of an organization’s mission and operations. The work connects legal and regulatory requirements with governance, risk decisions, security and privacy controls, evidence, assessment and continuing compliance. It is not limited to configuring technical safeguards.
The practical job behind the credential
A CGRC practitioner helps an organization decide how a system should be governed, what risks and requirements apply, which controls are appropriate, how those controls will be implemented and assessed, and whether the resulting evidence supports authorization. The practitioner also helps maintain that position as the system, threat environment, business purpose and regulatory obligations change.
Why framework translation matters
ISC2 reported that the most common audience response to a question about implementing GRC controls was “translating frameworks into operational controls,” selected by 33% of respondents. That finding points to an important preparation priority: learn to move from a requirement or control statement to an accountable process, an implementation decision and defensible evidence.
What the certification does not prove by itself
Passing the exam does not automatically demonstrate mastery of every organization’s framework, toolset or regulatory regime. The credential tests a defined body of knowledge. Your professional value comes from applying that knowledge carefully to the system boundary, mission, risk tolerance, control environment and evidence available in a particular organization.
Who is the exam designed for?
The credential is aimed at information technology, information security and cybersecurity professionals responsible for governance, risk and compliance activities. It is especially relevant when your work involves authorization, security and privacy risk, controls, audits, compliance evidence or system security decisions rather than only operational technology administration.
Roles that align with the exam
ISC2 identifies roles such as cybersecurity auditor, cybersecurity compliance officer, GRC architect or manager, cybersecurity risk and compliance project manager or analyst, third-party or enterprise risk manager, GRC analyst or director, system security manager or officer and information assurance manager. These titles are examples of role alignment, not a list of mandatory job titles.
A useful fit test
You are likely to benefit from this exam if your work requires you to explain why a control is needed, determine which system or data is in scope, coordinate implementation, review assessment results, support authorization or track compliance over time. If your experience is limited to memorizing control names without making or documenting those decisions, add applied study before scheduling.
People changing into GRC
A technical security professional may already understand vulnerabilities, identity, networks or cloud services but still need practice with governance language, risk acceptance, control ownership and evidence. Conversely, an auditor or compliance analyst may need to strengthen system boundaries and control implementation concepts. Start with the domains where your work gives you the fewest concrete examples.
What are the seven exam domains?
The current CGRC exam outline organizes the subject matter into seven domains: governance, risk and compliance; system scope; control selection and approval; control implementation; control assessment or audit; system compliance; and compliance maintenance. Study them as a lifecycle, because authorization work depends on links between decisions rather than isolated definitions.
Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program
This domain establishes the governing context for security, privacy, risk and compliance decisions. Prepare to connect organizational objectives, responsibilities, policies, risk management and compliance activities. The current outline also addresses AI governance, including oversight for algorithmic transparency and the ethical use of autonomous agents.
Domain 2: Scope of the System
System scope determines what the authorization and control effort actually covers. Study boundaries, system components, information, interfaces, dependencies, users and embedded technology. The current outline expands scoping to account for continuous and sprawling machine-learning data pipelines and requires identifying embedded algorithms, including those hidden in commercial off-the-shelf software.
Domain 3: Selection and Approval of Framework, Security, and Privacy Controls
This domain concerns choosing and approving a suitable framework and the security and privacy controls that address the system’s requirements and risks. Learn to justify a baseline, tailor it to context, document control ownership and obtain the appropriate approval. The outline also references specialized AI overlays such as the CSA AI Controls Matrix.
Domain 4: Implementation of Security and Privacy Controls
Implementation turns approved control decisions into operating safeguards, procedures, responsibilities and evidence. Study how controls are deployed, documented and coordinated across system components and service providers. The current outline includes AI-native security controls in distributed machine-learning pipelines, so avoid preparing only with conventional, static infrastructure examples.
Domain 5: Assessment or Audit of Security and Privacy Controls
Assessment determines whether controls are suitably designed, implemented and operating as intended, using evidence that supports a defensible conclusion. Prepare to distinguish assessment planning, evidence collection, findings, remediation and reporting. The outline also addresses AI-powered audit tools that correlate compliance evidence across large cloud environments.
Domain 6: System Compliance
System compliance brings together the system’s control posture, assessment results, authorization evidence, risk decisions and formal compliance or authorization outcome. Study how unresolved risk is communicated and accepted under defined criteria. The outline addresses the uncertainty of generative AI, AI risk acceptance criteria and AI governance tools that can automate large authorization packages such as SSPs.
Domain 7: Compliance Maintenance
Compliance maintenance keeps an authorized or compliant system aligned with changing technology, threats, controls, requirements and organizational conditions. Study continuous monitoring, change management, reassessment, remediation tracking and reporting. For AI systems, the outline describes AI-driven continuous control monitoring that can accommodate the rapid lifecycle of MLOps.
How to handle blueprint weights
The supplied official research identifies the seven domains but does not provide the percentage weight for each domain. Do not build a schedule from unattributed percentages or compare bare percentages. Use the current ISC2 exam outline for any published domain weighting, and always name the associated domain beside a percentage when recording your own study plan.
What are the exam format and delivery details?
The CGRC examination is three hours long and contains 125 items. ISC2 describes the item format as multiple-choice and advanced item types, with a passing score of 700 out of 1,000 points. The exam is available in English, and ISC2 lists Pearson VUE Testing Centers as the testing-center delivery option.
Turn the format into a pacing decision
A three-hour session with 125 items requires deliberate pacing rather than extended time on one difficult scenario. Practice reading the question’s decision point first, identifying the role and system context, eliminating answers that act too early or ignore governance, then selecting the answer that best fits the stated authorization or compliance objective.
Prepare for advanced item types
Do not study as though every item will be a simple definition question. The official format includes advanced item types. Your practice should therefore include prioritization, sequencing, control-selection and scenario-based decisions. Use practice material as a reasoning exercise, not as a source of live or memorized examination content.
Confirm policies before registering
ISC2 recommends reviewing its examination policies and procedures before registration. Check the current official registration information for scheduling, identification, accommodation, rescheduling and other administrative rules because those details may change and are not fully established by the supplied research.
Do you meet the experience requirement?
ISC2 requires at least two years of cumulative, full-time experience in one or more domains of the current CGRC exam outline. Qualifying work involves information-systems security performed in pursuit of authorization or work requiring security risk management knowledge and its direct application. Passing the exam and satisfying the experience requirement are separate parts of the certification process.
Map your work to the domains
Create a role-by-role record of projects, dates, responsibilities and outcomes. Label each activity against one or more of the seven domains. Strong examples include defining system scope, selecting or tailoring controls, coordinating implementation, assessing controls, preparing authorization evidence, managing risk decisions and maintaining compliance. Keep descriptions factual and specific enough for an endorser to evaluate.
How part-time work is counted
ISC2 states that full-time experience accrues monthly at a minimum of 35 hours per week for four weeks. Qualifying part-time work must be 20 to 34 hours per week. The official page states that 1040 hours of part-time work equals 6 months of full-time experience and 2080 hours of part-time work equals 12 months of full-time experience.
Internships and documentation
Paid or unpaid internships may count. ISC2 requires documentation on company or organization letterhead confirming the intern position; a school internship document may be on the registrar’s stationery. Collect this evidence before applying rather than assuming a transcript or informal manager statement will be sufficient.
If you do not yet have two years
Candidates who pass the CGRC examination without the required experience may become Associates of ISC2. The official experience page states that an Associate then has three years to obtain the required two years of relevant experience. This route lets a candidate separate exam readiness from the later experience milestone, but it does not remove the experience requirement for the certification.
What happens after passing?
Passing the examination is followed by the ISC2 certification application process. All candidates who pass an ISC2 credential examination must complete that process within nine months of the exam date, and an application cannot be submitted until ISC2 has notified the candidate of a pass. Prepare your experience record and endorsement information before the exam so administration does not become an avoidable delay.
Plan for endorsement
For certifications other than Certified in Cybersecurity, ISC2 requires an endorser who is an ISC2-certified professional in good standing and can attest to the claimed experience. The application requires the endorser’s ISC2 member ID and surname. If you do not know an eligible endorser, ISC2 offers an endorsement route that requires proof of employment.
Check possible experience waivers
ISC2 says a post-secondary bachelor’s or master’s degree in computer science, information technology or a related field may satisfy up to one year of required experience. A credential from the ISC2-approved list may also satisfy up to one year. Only one year may be waived through education or certification, so verify eligibility rather than subtracting both.
Keep application evidence consistent
Use the same employment dates, role descriptions and domain mapping in your preparation record and application. Avoid broad claims such as “handled compliance” when you can identify the system, control activity, assessment responsibility or authorization deliverable involved. The endorsement process is intended to confirm that your assertions about professional experience are accurate.
Understand the final membership step
After the certification application is approved, ISC2 states that the final step is payment of the first Annual Maintenance Fee. Existing ISC2 certification holders do not pay an additional Annual Maintenance Fee for the latest certification. Review the current ISC2 terms for the applicable fee and maintenance obligations rather than relying on third-party figures.
How should you study the domains?
Study in the order that authorization work happens, then revisit the domains in mixed scenarios. Begin with governance and system scope, move through control selection and implementation, then assessment, system compliance and maintenance. This sequence builds a decision chain and exposes gaps that a glossary-only approach tends to hide.
Build a control-decision notebook
For every major topic, record five things: the organizational objective, the system or data in scope, the risk or requirement, the responsible party and the evidence that would support the decision. Add a sixth item when relevant: what changes would trigger reassessment or monitoring. This format turns passive reading into authorization reasoning.
Use one fictional system consistently
Choose a neutral study system, such as a business application that processes sensitive information and depends on cloud services. Walk it through all seven domains. Define its boundary, identify interfaces and algorithms, select and tailor controls, assign owners, assess evidence, document residual risk and establish maintenance activities. The scenario is a learning tool, not a prediction of exam content.
Separate similar decisions
Candidates often blend scope, control selection, assessment and authorization into one activity. Keep them distinct. Scoping says what is included; selection says what should address the risk; implementation says how the control operates; assessment says what the evidence demonstrates; authorization says how the remaining risk is handled; maintenance says how the position stays current.
Study AI as a governance extension
The current outline incorporates AI considerations across the domains. Do not treat AI as a detached technology chapter. Ask how algorithms are discovered, how machine-learning pipelines affect scope, how AI controls are selected, how evidence is correlated, how generative-AI uncertainty affects acceptance and how MLOps changes continuous monitoring.
Use official references to close gaps
ISC2 encourages candidates to supplement education and experience with relevant resources and to identify areas needing additional attention. Start with the current exam outline, follow its supplementary references, and keep a version-controlled list of concepts that remain unclear. This is more reliable than collecting disconnected summaries with unknown currency.
What study mistakes should you avoid?
The most damaging mistake is memorizing terminology without understanding the order and authority of decisions. Other common problems include studying an obsolete CAP outline, ignoring experience documentation, treating all controls as equally relevant, overlooking privacy and system boundaries, and relying on dumps. A sound plan tests judgment, evidence handling and lifecycle relationships.
Mistake: using CAP material without checking its date
The CAP name is still common in search results and older training resources. Compare any material with the current CGRC outline, which is identified as effective June 15, 2024 in the supplied official research. Retain useful authorization concepts, but replace outdated domain labels, omissions and assumptions with the current outline.
Mistake: treating a control catalogue as a checklist
A control is not automatically appropriate merely because it appears in a framework. Practice explaining the system context, requirement, risk, tailoring decision, owner, implementation evidence and assessment method. A candidate who can defend the selection is better prepared than one who can only recite a control family name.
Mistake: studying assessment without evidence
Assessment questions are easier to reason through when you can distinguish a policy statement, a procedure, a configuration record, an interview response, a test result and an operating record. For each control in your practice scenario, ask what evidence would demonstrate design, implementation and ongoing operation, and what limitation would weaken the conclusion.
Mistake: postponing the application paperwork
Waiting until after the exam to identify an endorser, employment evidence or internship documentation creates unnecessary uncertainty. Prepare a private evidence file now. It should contain domain mapping, role dates, contact details for a potential endorser and notes about any education or certification waiver that may apply.
Mistake: using dumps as a preparation strategy
Exam dumps, leaked questions and memorized answer lists are not a legitimate substitute for learning the body of knowledge, and memorization does not guarantee a pass. They can also train the wrong reasoning pattern. Use the official outline and lawful study resources, then practice making the best decision from the facts in an unfamiliar scenario.
What is a practical study roadmap?
A useful roadmap has four phases: eligibility and scope, domain foundation, integrated application and readiness review. Move forward when you can explain decisions rather than when you have merely completed a number of pages or questions. Keep the schedule adjustable because your starting knowledge, work exposure and access to study time will differ.
Phase one: establish your starting point
Read the current outline once without trying to memorize it. Record the seven domains, exam format, language and testing-center information. Then map your professional work to the domains and identify the two weakest areas. Confirm whether you already meet the experience requirement or should plan for the Associate of ISC2 route.
Phase two: learn the lifecycle
Study Domains 1 through 3 first: governance and risk context, system scope, and selection and approval of controls. For each topic, write a short explanation using your fictional system. Do not advance after reading alone; test yourself by explaining why a boundary, framework, baseline or tailoring decision is appropriate.
Phase three: connect implementation to evidence
Study Domains 4 and 5 together. For each selected control, describe implementation responsibilities, expected evidence, assessment procedures, possible findings and remediation. Add privacy considerations and dependencies. This phase should make clear why an assessment conclusion cannot be stronger than the evidence and scope supporting it.
Phase four: practise authorization and maintenance
Study Domains 6 and 7 as the decision and lifecycle end of the process. Work through risk acceptance, authorization evidence, compliance status, changes, continuous monitoring and reassessment. Include an AI-enabled system in at least one exercise so you practise the current outline’s AI governance and MLOps-related considerations.
Final review before scheduling
Return to the outline and mark every task as explain, apply or revisit. Use mixed practice rather than studying one domain in isolation. Review why each answer is right and why the alternatives are weaker. Schedule only after you can maintain a consistent reasoning process across unfamiliar scenarios and can manage the official exam format without rushing.
How can you make practice questions useful?
Practice questions should reveal reasoning gaps, not provide a list of phrases to memorize. After each item, identify the decision owner, the lifecycle stage, the governing objective, the strongest evidence and the risk created by each alternative. Record the concept behind the error and revisit the relevant outline domain.
Use a four-part review method
For an incorrect or guessed answer, write: what the question actually asked; which facts controlled the decision; why the selected answer was weak; and what rule or relationship you will apply next time. If you cannot explain the answer without seeing the options, your understanding is not yet stable.
Practise prioritization
Scenario items may present several reasonable actions. Train yourself to identify whether the question asks for the first action, the best action, the most appropriate evidence or the decision that requires approval. Prefer answers that respect governance, scope, risk and authority rather than answers that jump directly to a technical fix.
Do not infer the real exam from unofficial material
Third-party practice items can be useful for timing and reasoning, but they do not establish the wording, coverage or sequence of the live examination. Treat them as exercises. The current ISC2 outline is the source for objectives, while ISC2 examination policies govern the administrative process.
What should you do next?
Start with the current CGRC exam outline, not a CAP-labelled dump or an undated summary. Confirm your experience path, create a seven-domain gap map, gather application evidence and build a study scenario that follows the authorization lifecycle. Then use official registration and endorsement information to verify the administrative steps before choosing an exam date.
A short action checklist
Download or review the current outline and note its effective date. List your work against Domains 1 through 7. Identify missing documentation for employment, part-time work or internships. Select lawful study resources from the official supplementary references. Create a control-and-evidence notebook. Practise mixed lifecycle decisions. Review exam policies before registering.
When to revisit your plan
Rework the schedule if your practice errors cluster in one domain, if you cannot explain why evidence supports a conclusion, or if your experience record remains ambiguous. Also recheck the official sources before scheduling if the outline, registration instructions or endorsement requirements have changed. Currency matters more than preserving a plan built from old CAP material.
Conclusion
The CAP-to-CGRC name change does not alter the central preparation task: understand how governance, scope, controls, assessment, authorization and maintenance form one risk-management process. Use the current seven-domain outline, verify the three-hour, 125-item English examination details before registering, and separate exam readiness from certification eligibility. A candidate who builds evidence-based decisions, documents experience early and studies the lifecycle will have a more dependable preparation plan than one based on recalled labels or exam dumps.
Related exams
- Certified Information Systems Security Professional (CISSP)
- HCISPP exam — HealthCare Information Security and Privacy Practitioner
- SSCP exam — Systems Security Certified Practitioner