Certified in Cybersecurity (CC) Exam Guide: Domains, Preparation, and Scheduling Decisions
The ISC2 Certified in Cybersecurity (CC) exam validates foundational knowledge across security principles, resilience and incident response, access controls, network security, and security operations. ISC2 positions it for entry-level candidates, including IT professionals, students, recent graduates, and career changers, with no work experience required. This guide helps you decide whether your current knowledge is ready, how to sequence study across the five domains, which official resources fit your learning style, and how to avoid administrative problems when scheduling the exam.
Who the CC exam is designed for
The CC is an entry-level cybersecurity certification for candidates who want to demonstrate foundational knowledge without first accumulating cybersecurity work experience. It can suit an IT professional adding security responsibilities, a student or recent graduate, or a career changer building a structured starting point for a security role.
ISC2 describes the credential as a way to recognize people entering the cybersecurity workforce without direct IT experience. The certification is listed as ANAB-accredited to ISO/IEC Standard 17024 and approved under the U.S. Department of Defense 8140.03 framework.
The credential is not a substitute for practical experience. A sensible interpretation is that it demonstrates baseline knowledge and an aptitude to learn on the job; it does not by itself establish that a candidate has administered networks, handled a live incident, or operated a security program.
Who should consider it
The strongest candidates are people who need a defined foundation rather than a specialist credential. An IT support worker may use the domains to organize security knowledge, while a career changer can use them to identify whether concepts such as access control, network protection, and incident response are genuinely interesting before pursuing a role.
Candidates should also consider how the credential fits a longer path. ISC2 presents CC as a foundation for cybersecurity careers and as an introduction to exam formats used by advanced ISC2 certifications. Treat that as a progression option, not as a promise that one credential leads automatically to a particular job.
What the exam does not require
ISC2 states that no work experience is required for the CC. That removes an eligibility barrier, but it does not remove the need to understand the terminology and relationships in the outline. Candidates with no IT background should plan extra time for networking and systems vocabulary rather than assuming the entry-level label means the material is purely conceptual.
What the current exam measures
The current CC outline measures five connected areas: Security Principles; Business Continuity, Disaster Recovery and Incident Response Concepts; Access Controls Concepts; Network Security; and Security Operations. The domains move from security foundations to controls, infrastructure protection, resilience, and day-to-day defensive work.
The current outline is effective October 1, 2025. ISC2 states that a new CC exam outline will take effect on September 1, 2026. Your study material, exam date, and outline version should therefore agree; do not prepare from an undated summary when your appointment falls near the change.
Security Principles — 26%
Security Principles carries 26% of the CC exam and establishes the language used throughout the other domains. Study the purpose and relationship of confidentiality, integrity, availability, authentication, non-repudiation, privacy, and risk management rather than memorizing isolated definitions.
Build short decision examples for each principle. For instance, ask which security objective is affected when information is altered, exposed, or made unavailable. Then connect risk identification, assessment, treatment, priorities, and tolerance to the business decision being made. The objective is to recognize the security consequence in a scenario, not merely repeat an acronym.
Business Continuity, Disaster Recovery and Incident Response Concepts — 10%
Business Continuity, Disaster Recovery and Incident Response Concepts carries 10% of the CC exam. Prepare by separating the purpose of keeping essential business functions available, restoring technology or services after disruption, and responding to a security event.
Use a simple timeline in your notes: preparation, disruption or detection, response, recovery, and improvement. Then test whether each activity belongs to continuity, disaster recovery, or incident response. ISC2’s current outline also incorporates how AI can complicate and enhance organizational resilience, so read the current outline rather than relying only on older general definitions.
Access Controls Concepts — 22%
Access Controls Concepts carries 22% of the CC exam and focuses on controlling who or what can use resources. Organize study around the distinction between physical and logical controls, the purpose of authorization, and the consequences of granting more access than a user or system needs.
When reviewing a control, ask four questions: what asset is protected, who or what is requesting access, which decision permits or denies it, and how the decision can be reviewed later. This approach helps connect identity, permissions, accountability, and prevention without turning the topic into a list of product names.
Network Security — 24%
Network Security carries 24% of the CC exam. The official training describes this area as networking fundamentals used to assess vulnerabilities, implement preventative mechanisms, and improve an organization’s network security posture.
Study the path of traffic and the purpose of controls placed along that path. Draw a small network and annotate where segmentation, monitoring, prevention, and secure configuration would matter. The current outline also addresses how AI influences traffic monitoring and threat prevention, so include that context when using the current exam version.
Security Operations — 18%
Security Operations carries 18% of the CC exam and covers operational work such as data security concepts and policies, system hardening, security awareness training, and responding to security threats. Treat this domain as the point where principles become repeatable organizational practices.
Create a control-maintenance checklist for each study topic: define the policy or objective, configure or apply the control, monitor its condition, record evidence, and respond when it fails. The current outline describes the final domain as the day-to-day work of a security professional working alongside AI, which makes judgment and responsible use more useful study targets than tool memorization.
How to choose a preparation route
Start with the official exam outline, then choose one main learning route and one way to verify understanding. ISC2 provides the outline, official flash cards, and self-study resources; its official online self-paced course adds adaptive learning, assessments, knowledge checks, study sheets, and a progress dashboard.
Do not buy several overlapping resources before identifying a gap. If you can explain a concept but cannot apply it to a short scenario, you need practice and correction. If the term itself is unfamiliar, you need instruction or reference reading first. This distinction prevents practice questions from becoming a substitute for learning.
Using the official outline as the control document
Download the current outline in your preferred supported language and turn every domain heading into a checklist. Mark each item as unfamiliar, understood, or applicable. Revisit the outline after each study cycle so that an interesting side topic does not displace an assessed topic.
ISC2 encourages candidates to supplement education and experience with relevant resources and identify areas needing additional attention. Supplement selectively: every external explanation should map back to an outline item, and conflicting terminology should be checked against the official material.
When official self-paced training is useful
ISC2’s online self-paced CC training has no prerequisites and uses adaptive learning. It includes a personalized learning journey, data-driven progress analytics, pre- and post-course assessments, knowledge checks, end-of-domain quizzes, interactive content, domain study sheets, flash cards, a glossary, email support, and 24/7/365 chat technical support.
The training is available in 90-day and 180-day access options, with access starting at purchase. Adaptive training is available only in English; the other listed content versions use a linear format. Choose the access period based on the time you can reliably study, not on an optimistic completion date.
When self-study is enough
Self-study can be a practical choice when you can read the outline independently, explain basic IT and networking terms, and maintain a study schedule without external deadlines. The official self-study page points candidates to the exam outline and official CC flash cards. Use flash cards for retrieval, then explain each answer in your own words and attach it to a domain objective.
A practical study roadmap
Use a sequence that establishes concepts before asking you to integrate them. Begin with a baseline against the five domains, learn the foundational language, apply it through scenarios and diagrams, and finish with mixed review. Set a target completion date before purchasing training or an exam so the 365-day exam window does not become an excuse to postpone.
The roadmap below is a planning model, not an ISC2 requirement. Adjust the pace to your starting knowledge and use the official outline to decide what deserves more review.
Stage 1: Establish the baseline
Read the current outline once without trying to memorize it. For each domain, write what you already know, what you can explain with an example, and what you cannot distinguish from a related concept. Complete an official assessment or knowledge check if your chosen training includes one, but record why an answer was wrong rather than only recording the score.
At this stage, schedule the exam only if you already understand the vocabulary and have enough time for a second pass. Otherwise, finish the baseline first and select a realistic study window.
Stage 2: Build the foundation
Study Security Principles first because its concepts recur in risk, access, network, and operations questions. Define each principle, then write one consequence of ignoring it. Follow with Access Controls Concepts, where you can connect identities, permissions, physical safeguards, logical safeguards, and accountability.
Keep a running glossary, but do not let glossary work consume the whole session. After learning a term, use it in a short explanation of a security decision. Retrieval followed by explanation exposes shallow recognition quickly.
Stage 3: Add infrastructure and resilience
Move to Network Security after the access-control foundation. Sketch how systems communicate, where vulnerabilities may appear, and which preventative or monitoring mechanisms address them. Then study Business Continuity, Disaster Recovery and Incident Response Concepts using timelines and responsibility-based notes.
At the end of this stage, combine domains. Ask how a network event affects availability, how access records support an investigation, and how a continuity plan differs from technical restoration. These links are more valuable than studying each domain as a sealed chapter.
Stage 4: Consolidate operations
Study Security Operations last in the first pass because it draws on principles and controls already introduced. Organize notes around policies, data protection, hardening, awareness, monitoring, and response. For each practice, state its objective, the risk it reduces, and what evidence might show that it is being maintained.
Now complete mixed practice rather than another domain-by-domain quiz. Review every uncertain answer, including correct guesses. A correct answer reached for the wrong reason is a future weakness.
Stage 5: Final readiness check
Before scheduling or sitting the exam, explain all five domains aloud or in writing without opening your notes. You should be able to distinguish neighboring concepts, interpret a short scenario, and justify why one control or response fits better than another.
Use the final review to close specific gaps, not to reread everything. Recheck the current outline version, confirm your appointment details, verify identification information, and stop adding new resources once review becomes fragmented.
How to study the five domains efficiently
Efficient preparation alternates input, retrieval, application, and correction. Read a small topic, close the material, explain it, apply it to a simple situation, and record the remaining uncertainty. Repeat this cycle across the five domains instead of spending all study time highlighting or watching lessons.
A useful notebook has four columns: outline concept, plain-language meaning, example or consequence, and unresolved question. The last column determines the next session. This turns a broad entry-level syllabus into a visible queue of decisions.
Use comparisons to prevent confusion
Many foundational security terms are learned together and then confused. Create paired notes for concepts that answer different questions: business continuity versus disaster recovery, authentication versus authorization, physical versus logical access controls, and prevention versus detection. For each pair, write the purpose, timing, and example of each term.
Do not treat every similar word as interchangeable. In a scenario, first identify the objective and the stage of activity, then select the concept that matches both.
Practice scenario reasoning
Practice questions should be used to test reasoning, not to predict or reproduce live exam content. After each item, identify the domain, underline the decisive facts, eliminate choices that solve a different problem, and explain why the selected answer fits the stated objective.
Avoid exam dumps, leaked questions, or memorization schemes. They do not provide a reliable or appropriate way to learn the knowledge represented by the outline, and memorization alone cannot guarantee a passing result.
Use diagrams for network and response topics
A diagram can expose gaps faster than a page of notes. Draw users, devices, services, data, controls, and an event path. Annotate where access is granted, where traffic is monitored, what could affect availability, and which activity belongs to response or recovery.
Redraw the diagram from memory later. If you cannot explain why a control sits at a particular point, return to the relevant outline objective before moving on.
Exam format and delivery details
The CC exam uses Computerized Adaptive Testing for all exams, lasts 2 hours, contains 100-125 items, and has a passing grade of 700 out of 1,000 points. ISC2 lists multiple choice and advanced item types, with delivery at Pearson VUE testing centers.
ISC2 lists English, Chinese, Japanese, German, and Spanish as exam languages. Chinese-language CC exams are available only during select appointment windows, so candidates who need Chinese should check appointment availability before committing to a date.
What the format means for preparation
A computerized adaptive format makes careful reading and consistent decision-making important. Do not build a plan around answering a fixed number of questions in a fixed order. Instead, practice identifying the requirement in each item, choosing the best-supported response, and moving on without allowing one uncertain concept to consume the session.
The published passing grade is 700 out of 1,000 points, but the outline does not turn that figure into a simple percentage of items. Use the official score information as stated and avoid treating a practice percentage as an equivalent prediction.
Where the appointment is delivered
ISC2 states that exams are offered at Pearson VUE testing centers worldwide, and its exam outline identifies Pearson VUE Testing Center as the testing location. Availability is global, but particular sites, dates, languages, and appointment windows vary, so verify the options shown during registration rather than assuming a nearby center has an immediate opening.
Registering and protecting the appointment
After purchasing the exam, log in to your ISC2 account, open Courses and Exams, and select Schedule. You will complete the ISC2 Exam Account Information form before being redirected to Pearson VUE to finalize the appointment.
Enter your name and other information exactly as it appears on the identification you will present. ISC2 warns that a mismatch can prevent you from taking the test and can result in no reimbursement of fees paid. Treat this administrative check as part of exam preparation.
Plan around the purchase window
Candidates have up to 365 days from exam purchase to schedule and sit for the exam. If you do not sit within 365 days of the purchase date, the exam fee will not be refunded. Record the purchase date and set an earlier personal deadline for completing study and booking the appointment.
A long eligibility window is not automatically a reason to delay. Choose a date that creates accountability while leaving enough time to correct weak domains. Candidates using a training bundle must also check its separate training and attempt-access terms.
Know the change and cancellation rules
Exams cannot be rescheduled within 24-hours of the appointment. ISC2 lists a rescheduling fee of U.S. $50 and a cancellation fee of U.S. $100; pricing and applicable taxes can depend on the exam location.
To reschedule, log into the ISC2 account, visit Courses and Exams, select Reschedule next to the exam, review the account information, and continue to Pearson VUE. From the Pearson VUE dashboard, select the exam, then choose Reschedule or Cancel on the Exam Appointment Details screen.
Check current pricing at registration
ISC2 lists the standard CC exam registration price for the Americas and other regions not separately listed as U.S. $199, while currencies and taxes vary by exam location. Confirm the amount displayed at registration because pricing is location-based and can change.
If comparing an exam-only purchase with Peace of Mind Protection, read the current product terms carefully. ISC2 describes that option as including two exam attempts in the purchase price; the training page states that candidates have 180 days from purchase to sit both attempts, with a 30-day waiting period between attempts.
What happens after passing
Passing the exam is followed by an ISC2 certification application, not an assumption that the credential is complete immediately. All candidates who pass an ISC2 credential examination must complete the certification application within nine months of the exam date, and the application cannot be submitted until ISC2 sends notification of the passing result.
For CC specifically, there is no work-experience requirement in the endorsement application. Applicants must address adherence to the ISC2 Code of Ethics and privacy-policy requirements.
Budget for maintenance
ISC2 states that the CC Annual Maintenance Fee is U.S. $50 per year. Candidate policies also state that ISC2 Candidates pay annual dues of U.S. $50 beginning in the candidate’s second year and continuously while candidate status is held. Check your account and the current policy to understand which payment applies to your situation.
Once certified, ISC2 states that maintaining the certification requires 45 CPE credits during the three-year certification cycle as well as the Annual Maintenance Fee of U.S. $50 each year. These are post-certification maintenance obligations, not prerequisites for sitting the exam.
Prepare the application before exam day
Read the endorsement requirements before the exam so that the post-pass process is not a surprise. Since CC does not require work experience, focus on the application questions and agreements concerning the Code of Ethics and privacy policy, then follow the passing notification for submission and payment instructions.
Do not submit an early application expecting it to finalize before the result. ISC2 says applications cannot be submitted until notification of successfully passing the exam is received.
Mistakes that weaken otherwise good preparation
Most avoidable problems come from misaligned materials, passive study, or rushed administration. The remedy is simple: anchor every study activity to the current outline, require yourself to explain answers, and complete scheduling checks well before the appointment.
A candidate can know individual definitions and still struggle to choose the best response in context. Use the mistakes below as a final audit of your plan.
Using an outdated outline
The current outline is effective October 1, 2025, and ISC2 has announced a new outline effective September 1, 2026. Candidates near that transition should verify which outline applies to the appointment and obtain study material aligned with that version. Do not mix domain descriptions from different versions without checking the official source.
Overweighting a favorite domain
Technical learners often spend too long on networks, while policy-oriented learners may avoid networking fundamentals. The official weights are distributed across all five domains: Security Principles 26%, Business Continuity, Disaster Recovery and Incident Response Concepts 10%, Access Controls Concepts 22%, Network Security 24%, and Security Operations 18%. Use the labels with the percentages when setting study priorities, and still cover the complete outline.
Confusing recognition with competence
Recognizing a flash-card answer is weaker than explaining when the concept applies. Convert each flash card into a question about purpose, risk, timing, or consequence. If you cannot answer without seeing the choices, add an explanation exercise before moving to more practice.
Ignoring administrative details
A wrong name on the exam account, an appointment changed within 24-hours, or an untracked 365-day purchase window can create avoidable cost and scheduling problems. Verify identification details during registration, save appointment information, and set reminders for the personal study deadline and the official eligibility deadline.
A final decision checklist
Book the exam when your preparation evidence shows consistent understanding across all five domains, not merely confidence in one area. Before paying or scheduling, confirm the outline version, language, testing-center availability, purchase window, and your ability to complete the application after a pass.
Use this checklist as a practical handoff from study to administration.
Knowledge decision
Can you explain the five domains in plain language? Can you distinguish continuity, disaster recovery, and incident response? Can you apply access-control and network-security concepts to a short situation? Can you connect security operations to policy, hardening, awareness, protection, monitoring, and response? Any no answer identifies a review task.
Scheduling decision
Have you checked the current ISC2 outline and the language offered for your appointment? Is your ISC2 account information an exact match for your identification? Have you recorded the purchase date and reviewed Pearson VUE availability? If you may need to change the appointment, have you read the 24-hour restriction and applicable fees?
Post-pass decision
Have you read the endorsement instructions, noted the nine-month application period, and understood that CC has no work-experience requirement? Have you planned for the Annual Maintenance Fee and the 45 CPE credits required during the three-year certification cycle? These steps keep the exam from becoming an isolated study milestone.
Recommended next actions
Begin with the official CC exam outline and mark your weakest domain. Then select either the official self-study materials or a structured training path, create a study calendar, and set a review date before scheduling. Once the five-domain checklist is complete, use mixed practice to test application rather than memorization.
After passing, wait for the ISC2 passing notification, complete the CC certification application within the stated period, and review the maintenance obligations. Keep the official pages bookmarked because pricing, policies, and future outline details are time-sensitive.
Conclusion
The CC is best approached as a foundation exam with a clear administrative sequence: study the current outline, build understanding across every domain, verify readiness through explanation and scenario practice, schedule through ISC2 and Pearson VUE with accurate account details, and complete the endorsement process after receiving the passing notification. Candidates who make those decisions deliberately are better positioned to use the credential as a starting point for entry-level cybersecurity work and continued development.
Related exams
- CSSLP exam — Certified Secure Software Lifecycle Professional
- ISSAP Information Systems Security Architecture Professional
- ISSEP Information Systems Security Engineering Professional
- Information Systems Security Management Professional (ISSMP) Exam