Certification guide
CGRCISC2 CGRC: the honest guide
Everything ISC2 publishes about CGRC, in one place: what the exam asks, how the domains are weighted, and what it takes to be ready.
This guide page is built from the registry, not written yet.
Everything below comes from CGRC’s published exam data, and every figure links to the vendor page it came from. The researched version, with study plans and the parts nobody publishes, is still being written. This page is not submitted to search engines until it is.
See everything published on CGRCWhat the exam actually asks you to do
Multiple choice and ISC2's advanced item types. There is no lab and no simulation, so the practice that matters is reading a scenario and choosing well.
Item formats
- Multiple choice
Nothing here needs a lab. Reading carefully and eliminating options is the whole skill. ISC2, CGRC exam outline ↗
Domain breakdown and official weightings
From the official ISC2 exam outlines. Implementation of Security and Privacy Controls is the heaviest domain at 17 percent, followed by Security and Privacy Governance, Risk Management, and Compliance Program at 16 percent.
- Security and Privacy Governance, Risk Management, and Compliance Program16%
- Scope of the System10%
- Selection and Approval of Framework, Security, and Privacy Controls14%
- Implementation of Security and Privacy Controls17%
- Assessment/Audit of Security and Privacy Controls16%
- System Compliance14%
- Compliance Maintenance13%
Where to focus: The seven weights sit between 10 and 17 percent, so no single domain decides the result and a weak area cannot be offset by depth elsewhere. ISC2 orders the outline around the authorization lifecycle (scope the system, select and tailor controls, implement, assess, decide, maintain), so learning which task belongs to which stage pays off more than memorizing control catalogs.
What comes after passing
CGRC is valid for 3 years. ISC2 runs a three-year certification cycle. CGRC holders must earn a required three-year total of 60 CPE credits (45 of them Group A), which ISC2 lists as 20 suggested annually, and pay the U.S. $135 annual maintenance fee on each anniversary of the certification date.
Costs across the full renewal cycle are on the CGRC cost page.
Frequently asked questions
Is CGRC the same certification that used to be called CAP?
Yes. ISC2 announced in February 2023 that the Certified Authorization Professional (CAP) certification would be renamed Certified in Governance, Risk and Compliance (CGRC), and stated the update only affects the name, not the exam or course content or the qualifications to pursue it. Existing holders had their digital certification and badge updated automatically.
How much does the CGRC exam cost?
ISC2 lists standard registration for the CGRC exam at U.S. $599 in the Americas, Asia Pacific, the Middle East and Africa, EUR 575.04 in EMEA, and GBP 485.19 in the United Kingdom. ISC2 notes that pricing and taxes are based on the location of exam administration.
What happens if I do not have the two years of experience yet?
ISC2 states that a candidate without the required experience may become an Associate of ISC2 by passing the CGRC exam, and then has three years to earn the two years of required, relevant experience.
What does it take to keep the CGRC active?
ISC2 members work on a three-year certification cycle. For CGRC the required three-year total is 60 CPE credits, of which 45 must be Group A, and ISC2 suggests 20 per year. Members holding CGRC also pay an annual maintenance fee of U.S. $135.
Keep reading
- CGRC exam overview
The format, the domain weights and the renewal terms, sourced line by line.
- CGRC passing score
The exact cut score, what kind of number it is, and the retake terms.
- How hard is CGRC?
An honest difficulty read from the format, the clock and the weights.