Every Exam PrepFREE EXAM PREP
Ask AI

ISC2 CC Exam Changes: New Outline Effective Sept 1, 2026

Written by Every Exam Prep Editorial TeamSource and review policyPublished August 16, 2026Updated August 19, 2026
Verified against the official exam documentation

ISC2 has published a new exam outline for Certified in Cybersecurity (CC), and it takes effect on September 1, 2026. This is not a cosmetic refresh: three of the five domains are renamed, one domain is repurposed entirely, and every weight moved. The boundary is your test date — if you sit the exam on or after September 1, 2026, you get the new outline, even if you registered or received your voucher months earlier. If you sit on or before August 31, 2026, you are tested against the outgoing outline dated October 1, 2025. The exam itself stays a 2-hour Computerized Adaptive Test (CAT) of 100–125 items scored on a 700-out-of-1000 scale.

Does this affect you?

Find your situation below. Every line is decided by the day you sit, not the day you paid.

  • Your exam is scheduled on or before August 31, 2026 — you are on the outgoing (October 1, 2025) outline. Nothing changes. Do not restructure your studying in the last two weeks.
  • Your exam is scheduled September 1, 2026 or later — you are on the new outline. This is true even if you registered in 2025 or bought your voucher long ago. ISC2 states plainly that "Effective September 1, 2026, the CC exam will be based on a new exam outline," with no carve-out for earlier registrations.
  • You are registered but have not picked a date — you are choosing your outline when you choose your slot. If you are already deep into study material built on the old five domains, scheduling before September 1 is the lower-friction path.
  • You are thinking about rescheduling — be careful. Moving a late-August date into September moves you onto the new outline. That is the most common way people will get caught out this fall.
  • You hold a free voucher from the One Million Certified in Cybersecurity program — ISC2 concluded new enrollments effective May 20, 2026, and existing codes let you "schedule and sit for the exam by December 31, 2026." Because that deadline runs past September 1, most remaining voucher holders will sit the new version unless they book in the next two weeks.
  • You are already CC-certified — an outline change governs exam delivery, not certifications already issued. ISC2 has not announced any requirement for existing CC holders to retest.
  • You failed and are inside a retake waiting period — check which side of September 1 your next eligible date falls on. Your retake is scored against whichever outline is in force the day you sit.

Before and after: what actually moved

The outgoing outline carries an effective date of October 1, 2025. The new one is stamped v01/2026 in the footer and reads "Effective Date: September 1, 2026" on the cover — use those two markers to confirm which PDF you are holding.

ItemThrough Aug 31, 2026From Sept 1, 2026
Outline effective dateOctober 1, 2025September 1, 2026
Domain 1Security Principles — 26%Security Principles — 24%
Domain 2Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts — 10%Security Governance17.3%
Domain 3Access Controls Concepts — 22%Identity And Access Management (IAM) Concepts20%
Domain 4Network Security — 24%Networking and Cloud Security Concepts21.3%
Domain 5Security Operations — 18%Security Operations and Incident Response17.3%
Number of domains55 (unchanged)
Delivery formatCAT (Computerized Adaptive Testing)CAT (unchanged)
Number of items100–125100–125 (unchanged)
Time limit2 hours2 hours (unchanged)
Passing score700 out of 1000 points700 out of 1000 (unchanged)
Item typesMultiple choice and advanced item typesUnchanged
LanguagesEnglish, Chinese, Japanese, German, SpanishUnchanged
Delivery partnerPearson VUE Testing CenterUnchanged
Credential codeCCCC (unchanged)

Read the weight changes carefully

Comparing the two tables row by row is misleading, because the Domain 2 slot was emptied and refilled with different subject matter. Here is what the numbers really mean:

  • Security Principles drops 26% to 24%, and this one is a like-for-like comparison — the domain kept its name and most of its content.
  • Domain 2 did not grow from 10% to 17.3%. The old Domain 2 was BC, DR and Incident Response. The new Domain 2 is Security Governance, built largely from material that used to live elsewhere: governance processes (old 1.5), best-practice security policies (old 5.3) and security awareness training (old 5.4), now consolidated under GRC.
  • BC and DR lost their own domain. They survive as two bullets under the new 2.2, "Understand redundancy." ISC2 does not publish sub-objective weights, so the exact share of BC/DR items on the new exam is not public — but a topic that was a named 10% domain is now a fraction of a 17.3% domain.
  • Incident Response moved out of Domain 2 and into Domain 5, which is why Domain 5 is renamed Security Operations and Incident Response.
  • Access Controls became IAM (22% to 20%) and Network Security became Networking and Cloud Security Concepts (24% to 21.3%) — renames that reflect genuinely new content, covered below.

Note that the new weights are labeled "Average Weight," as they were before. On a CAT exam these describe the target composition of your test, not a fixed item count you can plan around.

What to study differently

The honest headline: roughly two-thirds of the material is the same, but several topics are genuinely new to the outline and nothing written for the old version will cover them. Prioritize the additions.

Topics that are new or newly explicit

  • Zero Trust (ZT) and Defense in Depth under 4.2, network security architecture. Zero Trust does not appear anywhere in the outgoing outline.
  • Cloud security as a first-class topic (4.3): the five NIST-style characteristics — broad network access, rapid elasticity, measured service, on-demand self-service, resource pooling — plus service models, deployment models, and the shared security model. The old outline mentioned cloud only as a bullet listing SaaS/IaaS/PaaS, SLAs and MSPs.
  • Identity life cycle management (3.1): roles definition, provision, review, deprovision. This is the biggest single addition to Domain 3 and the reason it is now called IAM.
  • Threat intelligence and triage (5.2): security event triage, threat actors and motivations, cyber threat intelligence, threat frameworks.
  • Security testing (5.5): blue/purple/red teaming, vulnerability scanning, static and dynamic analysis, threat modeling, and physical penetration testing including phishing, tailgating and impersonation. Entirely new.
  • Asset protection (5.4): asset lifecycle management, End Of Life (EOL) software and devices, configuration and change management.
  • Quantum resistant cryptography, named in the 5.1 encryption bullet alongside symmetric, asymmetric and hashing.
  • Measuring cybersecurity effectiveness (2.4): key metrics, Key Risk Indicators (KRI), dashboards, score cards and reports.
  • AAA — the new 1.1 lists "Authentication, Authorization, Accounting (AAA)" where the old outline listed authentication methods and MFA.
  • Named frameworks: the new 1.3 explicitly cites ISO and the Center for Internet Security (CIS); the old outline referenced policies and standards generically.
  • Due care and due diligence, added to the ethics objective (1.5).

Topics that shrank or dropped out of the outline

  • Physical access controls lost its objective. The old 3.1 covered badge systems, gate entry, environmental design, CCTV, security guards, alarm systems and authorized-versus-unauthorized personnel. In the new outline, "Physical controls" is a single bullet under 1.4. Do not spend a week here.
  • The network threats and attacks objective is gone. Old 4.2 named DDoS, virus, worm, Trojan, MITM, side-channel, IDS/HIDS/NIDS, antivirus and IPS. The new Domain 4 has no equivalent objective, and IDS and IPS are not named anywhere in the new outline. Threat material now surfaces as threat actors and threat intelligence in Domain 5.
  • On-premises facilities content is gone — power, data center closets, HVAC, fire suppression, MOU/MOA.
  • DAC, MAC and RBAC are no longer named. The new 3.2 says only "Access control models." Still learn them; just note ISC2 stopped enumerating them.
  • The named policy list is gone — password policy, Acceptable Use Policy (AUP), BYOD and privacy policy were spelled out in old 5.3. Change management survives inside 5.4.
  • Wording shifts worth knowing: "Segregation of duties" is now "Separation of Duties (SoD)," and "Principle of least privilege" is now "Principle of Least Privilege (PoLP)."

On study materials for the new version

Very little new-outline material exists yet, and you should plan around that rather than hunt for it. As of mid-August 2026, most published CC books, video courses and question banks are built on the outgoing structure. There is a fast way to check any resource: look at its Domain 2. If the table of contents says "Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts," it was written for the outgoing outline. If it says "Security Governance," it has been updated. Material built on the old outline is still worth using for the roughly two-thirds of content that carried over — just pair it with the new outline PDF and self-study the additions listed above, which no old resource will contain.

What did not change

This part matters as much as the diff, because it tells you what your existing preparation is still good for.

  • The exam mechanics are identical. Still CAT, still 100–125 items, still 2 hours, still 700 out of 1000 to pass, still multiple choice plus advanced item types. Any practice you have done on pacing and adaptive-test strategy transfers intact.
  • Still five domains, and Domain 1 is still Security Principles.
  • The CIA triad core is untouched — confidentiality, integrity, availability, non-repudiation and privacy all remain in 1.1.
  • Risk management remains in Domain 1, reframed as lifecycle and processes rather than identification/assessment/treatment, but the underlying concepts are the same.
  • The ISC2 Code of Ethics is still examinable, in 1.5.
  • Controls typing is unchanged — technical, administrative, physical.
  • Networking fundamentals survive: OSI model, TCP/IP, IPv4, IPv6, VPN, firewalls, ports, VLANs, segmentation, IoT and ICS are all still in Domain 4, joined by wireless (Wi-Fi, Bluetooth).
  • Logging and monitoring, encryption and data handling remain in Domain 5.
  • No prerequisite change. Still no work experience or degree required; ISC2 still recommends basic IT knowledge.
  • Same languages, same delivery. English, Chinese, Japanese, German and Spanish at Pearson VUE, with CAT across all five.
  • Accreditation is unchanged — ANAB, ISO/IEC 17024.

If you can sit before September 1, the simplest move is to book now and study the outline you already know. If your date falls after, download the September 2026 PDF from ISC2 directly, treat the new Domain 2 and the cloud, IAM lifecycle and security testing additions as your gap list, and use everything else you already own. Either way you can pressure-test your recall with our free ISC2 Certified in Cybersecurity practice test before you walk in.

Ready to test yourself?

Free ISC2 CC practice test — 65 questions, instant feedback. No signup required.

Start practicing →

Sources

  1. 1.CC Certification Exam OutlineISC2 (accessed Jul 18, 2026)
  2. 2.ISC2 CertificationsISC2
  3. 3.Register for an ISC2 ExamISC2
  4. 4.ISC2 Exam PricingISC2
  5. 5.ISC2 Exam-Day GuidanceISC2
  6. 6.CC - Certified in CybersecurityISC2 (accessed Aug 16, 2026)

Frequently asked questions

When does the new ISC2 CC exam outline take effect?

September 1, 2026. ISC2 states that "Effective September 1, 2026, the CC exam will be based on a new exam outline." The outgoing outline carries an effective date of October 1, 2025 and applies to exams sat on or before August 31, 2026.

I registered months ago. Do I get the old CC exam or the new one?

Whichever outline is in force on the day you sit. The change is keyed to your test date, not your registration date or when you bought your voucher, and ISC2 has published no carve-out for earlier registrations. If you sit on or before August 31, 2026 you get the outgoing outline; from September 1, 2026 you get the new one. Rescheduling a late-August date into September moves you onto the new version.

What are the new CC domain weights?

Security Principles 24%, Security Governance 17.3%, Identity And Access Management (IAM) Concepts 20%, Networking and Cloud Security Concepts 21.3%, and Security Operations and Incident Response 17.3%. These replace the outgoing weights of 26%, 10%, 22%, 24% and 18%. Do not read the Domain 2 jump from 10% to 17.3% as growth in business continuity content — that slot was repurposed from BC/DR to Security Governance, and BC/DR is now two bullets under "Understand redundancy."

Is the new CC exam harder, and do current study materials still work?

ISC2 has not said the new version is harder or easier, and the format is identical — still CAT, 100 to 125 items, 2 hours, 700 out of 1000 to pass — so "different" is the accurate word. Most existing books and question banks still target the outgoing outline and remain useful for the large overlap, but they will not cover the genuinely new topics such as Zero Trust, cloud service and deployment models, identity life cycle management, threat intelligence, security testing and quantum resistant cryptography. To check any resource quickly, look at its Domain 2: "Security Governance" means updated, "Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts" means it predates the change.