Certification guideCC

ISC2 Certified in Cybersecurity: the honest guide

Everything ISC2 publishes about CC, in one place: what the exam asks, how the domains are weighted, and what it takes to be ready.

This guide page is built from the registry, not written yet.

Everything below comes from Certified in Cybersecurity’s published exam data, and every figure links to the vendor page it came from. The researched version, with study plans and the parts nobody publishes, is still being written. This page is not submitted to search engines until it is.

Practise Certified in Cybersecurity questions in the meantime

What the exam actually asks you to do

Multiple choice and multiple response only. No simulations, no labs, and nothing to configure.

  • Multiple choice
  • Multiple response

Nothing here needs a lab. Reading carefully and eliminating options is the whole skill. ISC2, Certified in Cybersecurity exam outline

Domain breakdown and official weightings

From the official ISC2 exam outlines. Security Principles is the heaviest domain at 26 percent, followed by Network Security at 24 percent.

  • Security Principles26%
  • Business Continuity, DR, and Incident Response10%
  • Access Control Concepts22%
  • Network Security24%
  • Security Operations18%

Official Certified in Cybersecurity exam objectives ↗

What comes after passing

CC lasts three years and needs 45 CPE credits plus the annual maintenance fee each year of the cycle.

Where people go next

Costs across the full renewal cycle are on the Certified in Cybersecurity cost page.

Frequently asked questions

Is the ISC2 CC exam free?

ISC2 has periodically offered the CC exam free through its One Million Certified in Cybersecurity program; standard pricing is $199. Check ISC2's site for current offers. Annual maintenance fees apply after certification.

Is CC easier than Security+?

Yes, CC is deliberately entry-level with no experience requirement, covering concepts at a definitional depth. Security+ goes further into applied scenarios and tooling.

What comes after CC?

Common paths: Security+ for a broader early-career credential, then SSCP or CISSP as experience accumulates (CISSP requires five years of paid work in its domains).

Keep reading

Every guide and cost breakdown, by vendor

Practise Certified in Cybersecurity for free while you decide

Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.

Start free Certified in Cybersecurity questions