ISC2 Certified in Cybersecurity (CC) Certification Guide (2026): Domains, Study Time & How to Pass

Is the ISC2 Certified in Cybersecurity (CC) certification worth it? Domains, study plan by experience level, exam facts, and tips to pass CC on your first try.

If you're weighing whether the ISC2 Certified in Cybersecurity (CC) certification is the right first step into security, this guide is built for you. It's written for students, career changers, IT generalists, and anyone without a security background who wants a credible, vendor-neutral credential to open the door to their first cybersecurity role. Below you'll find an honest look at whether CC is worth it, a fact sheet built only from verified ISC2 details, a domain-by-domain breakdown with study advice, a realistic week-by-week study plan by experience level, and a first-attempt pass strategy. By the end you'll have a concrete plan instead of a vague intention to 'get into security.'


Is the CC worth it?

The short answer: for the right person, yes. ISC2 designed Certified in Cybersecurity specifically as an entry point with no experience requirement, which is unusual among security certifications and makes it worth evaluating on its own terms rather than comparing it directly to experience-gated credentials.

Who CC is for

  • Students in IT, computer science, or related programs who want a credential to put on a resume before graduating
  • Career changers moving from help desk, networking, or another IT discipline into security
  • IT generalists (sysadmins, network techs, support staff) who touch security tangentially and want to formalize that knowledge
  • Non-technical professionals moving into GRC, compliance, or security-adjacent roles who need foundational vocabulary
  • Anyone considering the ISC2 certification path toward SSCP or CISSP but who currently has zero verifiable security experience

Who should wait: if you already have a year or more of hands-on security work, CC will likely feel too basic and you should look straight at SSCP practice tests or start accumulating experience toward CISSP. If your goal is a vendor-specific skill (say, AWS security or a specific SIEM), CC won't get you there directly — it's conceptual, not tool-specific.

What CC signals to employers

It signals baseline literacy. A hiring manager reading CC on a resume knows the candidate understands core vocabulary: CIA triad, risk terminology, access control models, network security basics, and incident response fundamentals — without having to take that on faith from a self-taught background.

It signals initiative and direction. For candidates without a security job history, CC is evidence that you've made a deliberate, structured investment in the field rather than just expressing interest in an interview.

Roles where it adds real value: SOC analyst (tier 1), IT support roles with security responsibilities, junior GRC or compliance assistant, cybersecurity intern, and any role posting that lists 'security fundamentals' or 'CompTIA Security+ or equivalent' as a nice-to-have.

What it does not signal: CC does not demonstrate hands-on experience, deep technical depth, or specialization. It won't substitute for SSCP or CISSP once you have a few years in the field, and it doesn't carry weight for senior or architect-level roles. Treat it as a foundation, not a ceiling.

The case for and against

The case for: it's backed by ISC2, the nonprofit behind CISSP, which lends it credibility that some newer entry-level badges lack. There's no experience gate, so you can earn it immediately. The five domains map cleanly to what an entry-level security hire is expected to know. And it plugs directly into ISC2's broader certification path, so the study habits and vocabulary you build carry forward.

The case against: it's genuinely entry-level, so on its own it may not be enough to land a job in a competitive market — it works best paired with a portfolio project, an internship, or a related credential. There's also an ongoing annual maintenance fee and CPE requirement once certified, which is a commitment beyond just passing the exam.

Where CC fits in a certification path

Career stage Typical move
No IT/security background, exploring the field Start with CC to build vocabulary and confirm interest before investing more time
IT generalist wanting to pivot into security CC first, then compare SSCP vs Security+ as your next step depending on whether you want a vendor-neutral or vendor-agnostic-but-broader credential
1+ years hands-on security experience Skip CC, aim directly at SSCP or begin accumulating experience for CISSP
Security professional with 5+ years and leadership scope CC is not relevant; CISSP or a specialized ISC2 credential (CCSP, CGRC, CSSLP) fits better

Bottom line: CC is worth it if you're genuinely new to security and want a structured, respected way to prove you know the fundamentals before you have job experience to point to. It's not a magic ticket to employment, but combined with a project or two and some networking, it's a legitimate and efficient credential to start with — and browsing the full range of LearnZapp ISC2 apps can help you see how it connects to what comes next.


CC exam at a glance

Exam fact Detail
Vendor ISC2 (the nonprofit behind CISSP, SSCP, CCSP, CGRC, CSSLP, ISSAP, ISSEP, and ISSMP)
Experience required None — CC is ISC2's entry-level certification
Number of domains 5
Question count 100 to 125 questions
Format Computerized Adaptive Testing (CAT) with multiple-choice and advanced item types; some questions are unscored research items
Duration 2 hours
Passing score 700 on a 1,000-point scale
Exam fee $199 USD (ISC2 Americas pricing, October 2026)
Delivery Pearson VUE testing centers; registration through the ISC2 website
Before the exam starts A terms-agreement screen with its own three-minute timer
Retake wait times 30 days after a first fail, 60 days before a third attempt, 90 days before a fourth; up to four attempts per 12 months
Ongoing maintenance $50 annual fee ($125 if you hold another ISC2 credential, covering all your ISC2 certifications) plus 45 CPE credits per three-year cycle

By weighting, Security Principles carries the most weight at 24%, so it's the single domain worth the most dedicated study time.


CC exam domains explained

Domain Weight
1. Security Principles 24%
2. Security Governance 17.3%
3. Identity and Access Management (IAM) Concepts 20%
4. Networking and Cloud Security Concepts 21.3%
5. Security Operations and Incident Response 17.3%

Domain 1: Security Principles (24%)

This is the largest domain and the conceptual backbone of the whole exam — everything else builds on it. Expect questions that test whether you understand core security thinking, not just definitions.

  • Understand cybersecurity concepts (confidentiality, integrity, availability, and related foundational ideas)
  • Understand risk management concepts (risk identification, assessment, treatment, and terminology)
  • Understand governance concepts (policies, procedures, standards, and how they relate)
  • Understand cybersecurity controls (preventive, detective, corrective, and their practical application)
  • Maintain professional and ethical conduct (the ISC2 Code of Ethics and professional responsibility)

Study advice: Because this domain is 24% of the exam and conceptually dense, don't rush it. Build a glossary of terms as you go (risk vs. threat vs. vulnerability vs. impact trips up a lot of first-time candidates) and make sure you can explain the CIA triad and control types out loud, not just recognize them on a multiple-choice list.

Domain 2: Security Governance (17.3%)

This domain covers the organizational scaffolding around security — the policies and continuity planning that keep a security program functioning, not just the technical controls themselves.

  • Plan governance, risk, and compliance (GRC) activities
  • Understand redundancy concepts for business continuity and disaster recovery
  • Understand security awareness programs and their role in reducing human-factor risk
  • Measure cybersecurity effectiveness (metrics, reporting, and continuous improvement)

Study advice: GRC concepts can feel abstract if you haven't worked in a formal organization. Anchor each concept to a concrete scenario — for example, picture how a company would measure whether its security awareness training actually reduced phishing click rates — to make the material stick.

Domain 3: Identity and Access Management (IAM) Concepts (20%)

IAM is the third-largest domain (behind Security Principles and Networking and Cloud Security Concepts) and covers how organizations control who can access what, and how that access is managed over time.

  • Understand identity life cycle management (provisioning, review, and deprovisioning of accounts)
  • Understand logical access controls (authentication methods, authorization models, and access control mechanisms)

Study advice: This domain rewards precision. Be able to distinguish authentication from authorization, and know the practical differences between access control models (like role-based versus discretionary approaches) well enough to apply them to a short scenario question, not just recite a definition.

Domain 4: Networking and Cloud Security Concepts (21.3%)

This is the most technically hands-on domain on the exam, covering how networks are secured and how those principles extend into cloud environments.

  • Understand network security (common threats, network security devices, and defensive concepts)
  • Understand network security architecture (network segmentation, zones, and design principles)
  • Understand cloud security (cloud service and deployment models, and shared responsibility)

Study advice: If networking is new to you, don't skip building basic mental models of how traffic flows through a network and where a firewall or segmentation boundary sits — abstract cloud security concepts make a lot more sense once you have that picture in your head.

Domain 5: Security Operations and Incident Response (17.3%)

This domain covers the day-to-day and worst-day operations of a security team — protecting data and assets, running operations, and responding when something goes wrong.

  • Understand data security (classification, handling, and protection of data)
  • Understand security operations (day-to-day activities that keep a security program running)
  • Understand incident response (IR) (the incident response lifecycle and roles within it)
  • Understand asset protection (physical and logical asset management)
  • Understand security testing (the purpose and types of security testing activities)

Study advice: Learn the incident response lifecycle as a sequence you can walk through from memory (preparation through lessons learned), since scenario questions in this domain often ask you to identify which phase a described activity belongs to.

Allocating study time by domain

Using a 100-hour study budget as a baseline, here's a reasonable split that roughly mirrors each domain's exam weighting while giving slightly more room to the two most technically involved domains:

Domain Hours (out of 100)
1. Security Principles 24
2. Security Governance 17
3. Identity and Access Management (IAM) Concepts 20
4. Networking and Cloud Security Concepts 22
5. Security Operations and Incident Response 17

How long to study for the CC

How long you need depends heavily on how much IT or security exposure you already have. Here's a realistic range by profile:

Experience profile Recommended weeks Total study hours
Complete beginner (no IT background) 10–12 weeks 100–120 hours
IT generalist with some exposure to security topics 6–8 weeks 70–90 hours
Career changer with a related cert (e.g., Security+) 4–6 weeks 50–60 hours
Experienced IT professional brushing up before the exam 2–3 weeks 25–35 hours

Your study materials stack

  • The official Sybex CC study guide (2nd edition, 2026), which is organized into 24 chapters grouped by domain and includes a chapter specifically on artificial intelligence
  • ISC2's own official training materials and self-paced courses, if you prefer a structured curriculum over self-study
  • A domain-by-domain notes document or flashcard deck to build your own glossary of terms as you go
  • Timed ISC2 CC practice tests to check retention and get used to the question style before exam day
  • A study group or accountability partner, especially useful if you're new to structured self-study

Week-by-week study plan (8-week version, ~80 hours)

Week Focus Checkpoint
1–2 Domain 1: Security Principles — concepts, risk, governance, controls, ethics Can explain the CIA triad and control types without notes
3 Domain 2: Security Governance — GRC, continuity, awareness, metrics Can describe a basic business continuity plan structure
4–5 Domain 3: IAM Concepts — identity lifecycle, logical access controls Can compare access control models and identity lifecycle stages
6–7 Domain 4: Networking and Cloud Security Concepts Can sketch a basic network security architecture and explain shared responsibility in cloud
8 Domain 5: Security Operations and Incident Response, plus full review Score consistently above your target on full-length practice tests

To compress this into 4–6 weeks, combine adjacent domains (1+2, then 3, then 4+5) and cut review time to a focused weekend before the exam rather than a full week. To expand it toward 10–12 weeks, add a dedicated week of nothing but practice questions and error review after each domain, and insert a full-length practice test every two weeks rather than only at the end.


How to pass the CC on your first attempt

Build the plan around a diagnostic

Before committing to a fixed study schedule, take a diagnostic practice test to see where you actually stand across the five domains. Because Security Principles (24%) and Networking and Cloud Security Concepts (21.3%) carry the most weight, a diagnostic that shows weakness in either should shift more of your study hours there immediately, rather than studying every domain equally by default.

Use practice tests effectively

Don't save practice questions for the final week. Use them throughout your study plan to identify weak domains early, then go back to the material rather than just memorizing answers. In the final two weeks, shift to full, timed simulations of the 100–125 question, 2-hour format so you build stamina and get comfortable with the pacing the adaptive test requires. Review every wrong answer and understand why the correct option is right, not just which letter it was.

Pitfalls that cause first-attempt failures

  1. Treating CC like a memorization exercise instead of building conceptual understanding — the exam tests whether you can apply ideas to short scenarios, not just recall definitions.
  2. Under-preparing on Networking and Cloud Security Concepts because it feels more technical and intimidating than the governance-style domains.
  3. Ignoring the unscored research items and getting rattled when a question feels unusually unfamiliar — stay calm and answer your best guess, then move on.
  4. Skipping timed practice, then running out of composure (not necessarily time) during the actual 2-hour session.
  5. Not reading the terms-agreement screen instructions carefully, wasting part of its own three-minute timer figuring out what to do.
  6. Studying all five domains equally instead of weighting effort toward Security Principles and Networking and Cloud Security Concepts, which together make up over 45% of the exam.

Exam day

The CC is delivered at a Pearson VUE testing center after registering through the ISC2 website, using Computerized Adaptive Testing with multiple-choice and advanced item types. Arrive early, bring the required identification, and expect the session to open with a terms-agreement screen that runs its own three-minute timer — read it promptly so you don't burn time before the real exam even starts. Once inside, pace yourself across the 100 to 125 questions within the two-hour window; because it's adaptive, don't waste energy trying to guess which questions are scored versus unscored research items — just answer each one as carefully as the last. Mentally, treat it like a checkpoint of what you've already learned rather than a surprise test, and trust the plan you built around your diagnostic and domain weightings.


FAQ

Do I need any experience to take the CC exam? No. Certified in Cybersecurity is explicitly designed as ISC2's entry-level certification with no prior cybersecurity experience required, which makes it one of the more accessible ways to start with a recognized security credential.

How is the CC exam scored? It's scored on a 1,000-point scale, and you need 700 to pass. The exam uses Computerized Adaptive Testing, so the specific questions you see adjust based on your responses, and some items are unscored research questions that don't count toward your result.

How many questions are on the CC exam and how long do I have? You'll answer between 100 and 125 questions in a two-hour session, delivered as multiple-choice and advanced item types through Pearson VUE testing centers.

What happens if I fail the CC exam? You can retake it, but ISC2 enforces waiting periods: 30 days after a first failed attempt, 60 days before a third attempt, and 90 days before a fourth, with a maximum of four attempts allowed in any 12-month period.

Is there an ongoing cost after I pass? Yes. Certified members pay an annual maintenance fee of $50 (or $125 if you hold another ISC2 credential, which covers all your ISC2 certifications), and you'll need to earn 45 CPE credits over each three-year cycle to keep the certification active.

How does CC compare to CompTIA Security+? Both are considered entry-level, vendor-neutral security credentials, and either can be a reasonable starting point depending on which ecosystem you want to build toward. If you're also weighing SSCP vs Security+, it's worth reading that comparison alongside this guide before deciding which path fits your goals.

What should I study after passing the CC? Most people follow up with SSCP once they have some hands-on security experience, and eventually CISSP once they meet its experience requirements. The ISC2 certification path guide lays out how CC, SSCP, and CISSP connect, and SSCP practice tests are a natural next stop once you're ready.

Which study guide should I use for CC? The official Sybex study guide (2nd edition, 2026) is organized into 24 chapters grouped by the five domains, including a dedicated chapter on artificial intelligence, and pairs well with structured practice testing to reinforce each domain as you go.


Ready to see where you stand? Take a free ISC2 CC practice test from LearnZapp — no signup required — and use your results to sharpen this study plan before exam day.

Contact Us

Have a question or feedback? We typically respond within 24 hours.

We'll reply to your email address. No spam, ever.