Certification guide

CC

ISC2 Certified in Cybersecurity: the honest guide

Certified in Cybersecurity is ISC2's entry point, and it is exactly what it says: a first credential for someone with no security experience who wants proof they understand the vocabulary and the concepts. It asks no work experience of you, which is unusual for ISC2, whose better-known certifications gate on years in the field.

The exam is 100 multiple choice questions in 120 minutes, scored out of 1000 with 700 to pass. It is definitional by design. Questions ask what a control is, what a term means, and which concept fits a described situation, rather than handing you a log or a console and asking what you would do. That makes it more approachable than Security+ and also narrower in what it proves.

Standard pricing is $199, and ISC2 has periodically offered the exam free through its One Million Certified in Cybersecurity program. Check the certification page for a current offer before you pay, because when the program runs it includes free training as well.

Who Certified in Cybersecurity is for

A good fit if

  • You are new to cybersecurity with no professional experience and want a recognised first credential.
  • You are a student or a career changer and want something on a CV before you have work history to point at.
  • You work in IT and want a low-cost way to signal that you are moving toward security.
  • You want to start with ISC2 specifically, with a view to SSCP or CISSP once you have experience behind you.

Probably not, if

  • You already work in security or hold Security+. CC is below that level and will teach you little; put the time toward SSCP or CISSP instead.
  • You need a credential that hiring managers name in job postings. Security+ appears far more often, and for a defensive early-career role it carries more weight.
  • You want hands-on or applied skills. CC is conceptual and definitional. It does not test tools, configuration, or scenario judgement the way applied exams do.

Is Certified in Cybersecurity worth it?

For someone with no experience who wants a first step into security, yes, particularly when a free-exam offer is running. It is entry-level, it asks nothing of your work history, and passing it proves you have the base vocabulary. When ISC2 is offering it free through the One Million program, the only cost is your time and the maintenance fee once you certify.

For someone weighing it against Security+, the honest answer is that Security+ is the stronger single credential for early-career defensive work, because it is named in more job postings and goes further into applied scenarios. CC is the gentler and cheaper start. Many people take CC first and Security+ second, and that order works.

For someone already in a security role, no. CC certifies concepts you use daily and adds a $50 annual fee for the privilege. If you want an ISC2 credential, aim at CISSP, which needs five years of paid experience, or SSCP as a nearer target.

What the exam actually asks you to do

Multiple choice and multiple response only. No simulations, no labs, and nothing to configure.

Item formats

  • Multiple choice
  • Multiple response

Nothing here needs a lab. Reading carefully and eliminating options is the whole skill. ISC2, Certified in Cybersecurity exam outline

Domain breakdown and official weightings

From the official ISC2 exam outlines. Security Principles is the heaviest domain at 26 percent, followed by Network Security at 24 percent.

  • Security Principles26%
  • Business Continuity, DR, and Incident Response10%
  • Access Control Concepts22%
  • Network Security24%
  • Security Operations18%

ISC2: ISC2 exam outlines

Study plans by experience level

No IT or security background

6 to 8 weeksat 6 to 8 hours

  1. 1Weeks 1 to 2: Security Principles, which is 26 percent of the exam and the vocabulary everything else rests on. Confidentiality, integrity and availability, risk, and the control types.
  2. 2Weeks 3 to 4: Network Security at 24 percent and Access Control Concepts at 22 percent. Between them these are nearly half the exam, so give them the most time.
  3. 3Week 5: Security Operations at 18 percent. Data handling, logging, and the everyday practices that keep a system safe.
  4. 4Week 6: Business Continuity, Disaster Recovery and Incident Response at 10 percent. It is the smallest domain and mostly terminology.
  5. 5Weeks 7 to 8: full timed practice sets. Book the exam when you are consistently above 85 percent, not before.

Working in IT, new to security

3 to 4 weeksat 6 hours

  1. 1Read the exam outline and mark the terms you could not explain to a colleague. For most IT people the marked list concentrates in Security Principles and Access Control.
  2. 2Study the marked items, and skim the network security domain, which overlaps with ground you already know.
  3. 3Take a full timed practice set at the end of week two. It names the definitional gaps that familiarity hides.
  4. 4Spend the remaining time on whatever the practice set exposed, then book.

Studying alongside Security+ material

2 to 3 weeksat 5 hours

  1. 1If you are already preparing for Security+, most of CC is a subset you have covered. Read the CC exam outline to confirm that rather than assuming it.
  2. 2Focus on the framing differences. CC asks for definitions where Security+ asks for application, so practise recognising the concept rather than reasoning through a scenario.
  3. 3Take a CC practice set to confirm the overlap holds for you, and drill any domain that scores low.
  4. 4Sit CC first if a free-exam offer is running, since it is the cheaper of the two to clear on the way to Security+.

Common mistakes

Treating it like Security+
CC is definitional, not applied. Preparing with scenario-heavy material aimed at Security+ over-prepares you for the format and can leave you second-guessing straightforward definition questions.
Paying for the exam without checking the offer
ISC2 has repeatedly run CC free through the One Million Certified in Cybersecurity program, with training included. Buying the $199 voucher without checking the certification page for a current offer is the most common avoidable cost on this certification.
Forgetting the annual maintenance fee
The exam is the visible cost, but holding CC means $50 a year and 45 CPE credits across the three-year cycle. People who budget only for the exam are surprised by the recurring line.
Skipping the two largest domains
Network Security and Access Control Concepts are 24 and 22 percent of the exam. They are nearly half of it, and they are where a general reader has the most to learn. Studying the domains in numbered order leaves them for last while you are least fresh.
Expecting it to produce a job on its own
CC gets your application read and proves the fundamentals. It is a first step, and hiring managers read it as one. Pair it with a Security+ plan or something demonstrable rather than expecting it to carry an application by itself.

What comes after passing

CC is valid for three years and renews with 45 CPE credits across the cycle plus the $50 annual maintenance fee. The fee is charged for every ISC2 certification you hold, so plan for it from the day you pass rather than the month it is due.

The natural next step is Security+, which is the broader early-career credential and is named in more job postings. It goes further into applied scenarios than CC does, and taking CC first is a reasonable on-ramp to it.

Inside the ISC2 line, SSCP is the nearer target and CISSP the longer one. CISSP needs five years of paid work in its domains before it will certify you, so it is a goal to accrue experience toward rather than a next exam. The CPE credits you earn maintaining CC count toward the habit of continuing education those credentials assume.

Where people go next

Costs across the full renewal cycle are on the Certified in Cybersecurity cost page.

Frequently asked questions

Is the ISC2 CC exam free?

Standard pricing is $199. ISC2 has periodically offered CC free through its One Million Certified in Cybersecurity program, which includes free self-paced training, so check the certification page for a current offer before you pay. Annual maintenance fees apply once you certify.

Is CC easier than Security+?

Yes. CC is deliberately entry-level, asks no work experience, and covers concepts at a definitional depth. Security+ goes further into applied scenarios and tooling. Many people take CC first and Security+ second.

Do I need experience to take CC?

No. CC requires no work experience, which is what sets it apart from other ISC2 certifications. It is built for people entering the field.

How much does CC cost to hold?

The exam is $199 at standard pricing, and once you certify ISC2 charges a $50 annual maintenance fee for each certification you hold. CC also needs 45 CPE credits across its three-year cycle, which most people earn through training and further study at no direct cost.

What comes after CC?

Security+ is the common next step for a broader early-career credential. Inside ISC2, SSCP is the nearer target and CISSP the longer one, since CISSP requires five years of paid work in its domains before it certifies you.

What score do I need to pass CC?

700 on a scale of 1000, across 100 multiple choice questions in 120 minutes. The five domains are weighted, with Security Principles at 26 percent and Network Security at 24 percent carrying the most, so weight your study the same way.

Keep reading

Every guide and cost breakdown, by vendor

Practise Certified in Cybersecurity for free while you decide

Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.

Start free Certified in Cybersecurity questions