ISC2 CC Exam 2026: What Changed and How to Prepare for Success
The ISC2 Certified in Cybersecurity (CC) exam is a popular starting point for individuals entering the cybersecurity industry. It validates foundational knowledge of security principles, risk management, access controls, networking, and security operations without requiring previous professional experience.
The ISC2 CC exam 2026 update, effective September 1, introduces revised domains, updated topic weightings, and greater emphasis on cloud security, governance, identity management, and incident response. Understanding these changes is essential for candidates preparing with current study materials and practice questions.
Cert Mage covers the topic with practical examples on YouTube.
What Is the ISC2 CC Certification?
The Certified in Cybersecurity certification is an entry-level credential offered by ISC2, a professional organization specializing in cybersecurity education and certifications.
It demonstrates understanding of fundamental security concepts and how organizations protect information systems, manage risks, and respond to threats.
Who Should Take the ISC2 CC Exam?
The certification is suitable for:
-
Students exploring cybersecurity careers.
-
IT beginners developing security knowledge.
-
Career changers entering information security.
-
Technical support professionals seeking specialization.
-
Aspiring security operations center analysts.
Unlike advanced ISC2 certifications, CC does not require previous professional cybersecurity experience.
What Changed in the ISC2 CC Exam in 2026?
ISC2 introduced its updated examination outline on September 1, 2026. The revision maintains five domains while reorganizing topics to reflect modern cybersecurity responsibilities.
The update places greater emphasis on security governance, identity management, cloud technologies, threat intelligence, and incident response. Foundational AI security concepts are also incorporated throughout the syllabus.
ISC2 CC Exam 2025 vs 2026 Comparison
|
Previous Exam Domain |
2025 Weight |
Updated 2026 Domain |
2026 Weight |
|
Security Principles |
26% |
Security Principles |
24% |
|
Business Continuity, Disaster Recovery and Incident Response |
10% |
Security Governance |
17.3% |
|
Access Controls Concepts |
22% |
Identity and Access Management Concepts |
20% |
|
Network Security |
24% |
Networking and Cloud Security Concepts |
21.3% |
|
Security Operations |
18% |
Security Operations and Incident Response |
17.3% |
These changes involve more than renaming domains. Candidates must understand additional concepts and updated security practices.
Understanding the Five Updated ISC2 CC Exam Domains
Domain 1: Security Principles — 24%
Security Principles covers essential cybersecurity concepts, including confidentiality, integrity, availability, authentication, and risk management.
The updated syllabus strengthens coverage of cybersecurity terminology, authentication and authorization, professional ethics, and risk management processes.
Candidates should understand how security principles influence organizational decisions.
Domain 2: Security Governance — 17.3%
Security Governance introduces a stronger focus on organizational security management.
Important topics include:
-
Governance, risk, and compliance fundamentals.
-
Security policies, standards, and procedures.
-
Cybersecurity awareness and organizational culture.
-
Security performance metrics and reporting.
-
Business continuity and resilience concepts.
Understanding how governance supports organizational security objectives is particularly important.
Domain 3: Identity and Access Management — 20%
This domain expands traditional access control concepts into identity lifecycle management.
Candidates should study authentication, authorization, least privilege, separation of duties, account provisioning, and access management frameworks.
Practical examples involving employee access and account permissions can strengthen understanding.
Domain 4: Networking and Cloud Security — 21.3%
The updated domain combines networking fundamentals with modern cloud security concepts.
Preparation should include network protocols, security devices, segmentation, cloud deployment models, shared responsibility, and Zero Trust principles.
Understanding how cloud environments differ from traditional networks is increasingly relevant.
Domain 5: Security Operations and Incident Response — 17.3%
This domain introduces expanded operational security responsibilities.
Important topics include threat intelligence, security monitoring, incident response, vulnerability management, asset protection, and security testing.
Candidates should understand how organizations identify threats, prioritize incidents, and respond to security events.
ISC2 CC Exam Format and Requirements in 2026
The updated CC examination uses Computerized Adaptive Testing (CAT), which adjusts question selection according to candidate performance.
|
Exam Detail |
2026 Information |
|
Certification |
Certified in Cybersecurity |
|
Exam duration |
2 hours |
|
Number of questions |
100–125 |
|
Question formats |
Multiple choice and advanced item types |
|
Passing score |
700 out of 1,000 |
|
Experience requirement |
None |
|
Testing provider |
Pearson VUE |
ISC2 confirms these examination details in its official certification outline.
How to Prepare for the ISC2 CC Exam in 2026
A structured preparation strategy helps beginners understand the updated objectives and develop practical cybersecurity knowledge.
-
Download the updated exam outline: Review the September 2026 syllabus and identify unfamiliar concepts.
-
Create a study schedule: Divide preparation time across all five domains, giving additional attention to weaker subjects.
-
Study cybersecurity fundamentals: Understand security principles, governance, networking, and identity management.
-
Practice real-world scenarios: Apply security concepts to access control, cloud security, and incident response situations.
-
Complete practice questions: Test your understanding using original exam-style assessments.
-
Review incorrect answers: Identify recurring mistakes and revisit official documentation.
-
Evaluate exam readiness: Complete mixed-domain assessments before scheduling your examination.
For additional preparation, candidates can explore ISC2 CC exam preparation resources from Cert Mage alongside official ISC2 learning materials.
ISC2 CC Exam Costs and Certification Benefits
The ISC2 One Million Certified in Cybersecurity initiative ended new enrollments on May 20, 2026. Previously issued, unexpired examination codes can still be used through December 31, 2026.
The standard CC examination fee is $199, and successful candidates pay a $50 annual maintenance fee.
Key Career Benefits
-
Demonstrates foundational cybersecurity knowledge.
-
Provides a structured entry into security learning.
-
Supports preparation for more advanced certifications.
-
Strengthens understanding of organizational security responsibilities.
-
Complements practical experience for entry-level IT roles.
Certification does not guarantee employment, but it can support professional development.
Common Preparation Challenges and Best Practices
The expanded syllabus may challenge candidates unfamiliar with cloud security, governance, and incident response.
Avoid relying on outdated study guides or memorizing practice answers. Instead, prioritize conceptual understanding, review explanations, and connect security principles with practical examples.
Use official documentation to verify unfamiliar concepts and regularly assess your progress across all five domains.
Conclusion
The ISC2 CC exam 2026 update introduces important changes reflecting modern cybersecurity responsibilities. Its revised domains emphasize governance, identity management, cloud security, and incident response.
Candidates who follow the updated syllabus, practice consistently, and understand foundational security concepts can approach the examination with greater confidence and readiness.
FAQs
When did the ISC2 CC exam change in 2026?
The updated ISC2 CC examination outline became effective on September 1, 2026.
Is the ISC2 CC exam difficult for beginners?
The exam targets beginners, but candidates still need a solid understanding of cybersecurity fundamentals and practical security scenarios.
How many questions are on the ISC2 CC exam?
The exam contains 100–125 questions and allows two hours for completion.
Can I take the ISC2 CC exam without experience?
Yes. ISC2 does not require previous professional cybersecurity experience for CC certification.
- Art
- Causes
- Crafts
- Dance
- Drinks
- Film
- Fitness
- Food
- Games
- Gardening
- Health
- Home
- Literature
- Music
- Networking
- Other
- Party
- Religion
- Shopping
- Sports
- Theater
- Wellness