Every Exam PrepFREE EXAM PREP
Ask AI

ISC2 CC Exam Changes: New Outline Live Since Sept 1, 2026

Since September 1, 2026 the ISC2 CC exam has run on a new outline: five renamed domains, new weights, IAM and cloud added. What moved, and the gap list old study material will not cover.

Written by Every Exam Prep Editorial TeamUpdated September 2, 2026
Published August 16, 2026Verified against ISC2's official sources Source and review policy

ISC2 has published a new exam outline for Certified in Cybersecurity (CC), and it took effect on September 1, 2026. This is not a cosmetic refresh: three of the five domains are renamed, one domain is repurposed entirely, and every weight moved. The boundary was your test date, never your registration date, so every exam sat from September 1 onward runs on the new outline however long ago the voucher was bought. Anyone who sat on or before August 31, 2026 was tested against the previous outline dated October 1, 2025; that version is no longer in use. The exam itself stays a 2-hour Computerized Adaptive Test (CAT) of 100–125 items scored on a 700-out-of-1000 scale.

Does this affect you?

Every line below is decided by the day you sit, not the day you paid — and now that the boundary has passed, the answer for anyone still to sit is the same one: you are on the new outline.

  • You have not sat the exam yet — you are on the new outline, whatever your study material was written for. Go straight to the gap list below; those additions are the part no older resource covers.
  • You registered long before the change — it makes no difference. ISC2 stated plainly that "Effective September 1, 2026, the CC exam will be based on a new exam outline," with no carve-out for earlier registrations, and none was added before the date arrived.
  • You are registered but have not picked a date — your slot no longer decides your outline, so pick the date your preparation justifies. If you are deep into material built on the old domains, close the gaps below first rather than hurrying the booking.
  • You are thinking about rescheduling — there is no longer any outline risk in moving your date. The only thing to verify is that the material you are revising from is the current version.
  • You hold a free voucher from the One Million Certified in Cybersecurity program — ISC2 concluded new enrollments effective May 20, 2026, and existing codes let you "schedule and sit for the exam by December 31, 2026." Because that deadline runs to the end of the year while the outline changed on September 1, every remaining voucher holder will sit the new version.
  • You are already CC-certified — an outline change governs exam delivery, not certifications already issued. ISC2 has not announced any requirement for existing CC holders to retest.
  • You failed and are inside a retake waiting period — check which side of September 1 your next eligible date falls on. Your retake is scored against whichever outline is in force the day you sit.

Before and after: what actually moved

The previous outline carries an effective date of October 1, 2025. The new one is stamped v01/2026 in the footer and reads "Effective Date: September 1, 2026" on the cover — use those two markers to confirm which PDF you are holding.

ItemUntil Aug 31, 2026Now (since Sept 1, 2026)
Outline effective dateOctober 1, 2025September 1, 2026
Domain 1Security Principles — 26%Security Principles — 24%
Domain 2Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts — 10%Security Governance — 17.3%
Domain 3Access Controls Concepts — 22%Identity And Access Management (IAM) Concepts — 20%
Domain 4Network Security — 24%Networking and Cloud Security Concepts — 21.3%
Domain 5Security Operations — 18%Security Operations and Incident Response — 17.3%
Number of domains55 (unchanged)
Delivery formatCAT (Computerized Adaptive Testing)CAT (unchanged)
Number of items100–125100–125 (unchanged)
Time limit2 hours2 hours (unchanged)
Passing score700 out of 1000 points700 out of 1000 (unchanged)
Item typesMultiple choice and advanced item typesUnchanged
LanguagesEnglish, Chinese, Japanese, German, SpanishUnchanged
Delivery partnerPearson VUE Testing CenterUnchanged
Credential codeCCCC (unchanged)

Read the weight changes carefully

Comparing the two tables row by row is misleading, because the Domain 2 slot was emptied and refilled with different subject matter. Here is what the numbers really mean:

  • Security Principles drops 26% to 24%, and this one is a like-for-like comparison — the domain kept its name and most of its content.
  • Domain 2 did not grow from 10% to 17.3%. The old Domain 2 was BC, DR and Incident Response. The new Domain 2 is Security Governance, built largely from material that used to live elsewhere: governance processes (old 1.5), best-practice security policies (old 5.3) and security awareness training (old 5.4), now consolidated under GRC.
  • BC and DR lost their own domain. They survive as two bullets under the new 2.2, "Understand redundancy." ISC2 does not publish sub-objective weights, so the exact share of BC/DR items on the new exam is not public — but a topic that was a named 10% domain is now a fraction of a 17.3% domain.
  • Incident Response moved out of Domain 2 and into Domain 5, which is why Domain 5 is renamed Security Operations and Incident Response.
  • Access Controls became IAM (22% to 20%) and Network Security became Networking and Cloud Security Concepts (24% to 21.3%) — renames that reflect genuinely new content, covered below.

Note that the new weights are labeled "Average Weight," as they were before. On a CAT exam these describe the target composition of your test, not a fixed item count you can plan around.

What to study differently

The honest headline: roughly two-thirds of the material is the same, but several topics are genuinely new to the outline and nothing written for the old version will cover them. Prioritize the additions.

Topics that are new or newly explicit

  • Zero Trust (ZT) and Defense in Depth under 4.2, network security architecture. Zero Trust does not appear anywhere in the outgoing outline.
  • Cloud security as a first-class topic (4.3): the five NIST-style characteristics — broad network access, rapid elasticity, measured service, on-demand self-service, resource pooling — plus service models, deployment models, and the shared security model. The old outline mentioned cloud only as a bullet listing SaaS/IaaS/PaaS, SLAs and MSPs.
  • Identity life cycle management (3.1): roles definition, provision, review, deprovision. This is the biggest single addition to Domain 3 and the reason it is now called IAM.
  • Threat intelligence and triage (5.2): security event triage, threat actors and motivations, cyber threat intelligence, threat frameworks.
  • Security testing (5.5): blue/purple/red teaming, vulnerability scanning, static and dynamic analysis, threat modeling, and physical penetration testing including phishing, tailgating and impersonation. Entirely new.
  • Asset protection (5.4): asset lifecycle management, End Of Life (EOL) software and devices, configuration and change management.
  • Quantum resistant cryptography, named in the 5.1 encryption bullet alongside symmetric, asymmetric and hashing.
  • Measuring cybersecurity effectiveness (2.4): key metrics, Key Risk Indicators (KRI), dashboards, score cards and reports.
  • AAA — the new 1.1 lists "Authentication, Authorization, Accounting (AAA)" where the old outline listed authentication methods and MFA.
  • Named frameworks: the new 1.3 explicitly cites ISO and the Center for Internet Security (CIS); the old outline referenced policies and standards generically.
  • Due care and due diligence, added to the ethics objective (1.5).

Topics that shrank or dropped out of the outline

  • Physical access controls lost its objective. The old 3.1 covered badge systems, gate entry, environmental design, CCTV, security guards, alarm systems and authorized-versus-unauthorized personnel. In the new outline, "Physical controls" is a single bullet under 1.4. Do not spend a week here.
  • The network threats and attacks objective is gone. Old 4.2 named DDoS, virus, worm, Trojan, MITM, side-channel, IDS/HIDS/NIDS, antivirus and IPS. The new Domain 4 has no equivalent objective, and IDS and IPS are not named anywhere in the new outline. Threat material now surfaces as threat actors and threat intelligence in Domain 5.
  • On-premises facilities content is gone — power, data center closets, HVAC, fire suppression, MOU/MOA.
  • DAC, MAC and RBAC are no longer named. The new 3.2 says only "Access control models." Still learn them; just note ISC2 stopped enumerating them.
  • The named policy list is gone — password policy, Acceptable Use Policy (AUP), BYOD and privacy policy were spelled out in old 5.3. Change management survives inside 5.4.
  • Wording shifts worth knowing: "Segregation of duties" is now "Separation of Duties (SoD)," and "Principle of least privilege" is now "Principle of Least Privilege (PoLP)."

On study materials for the new version

Very little new-outline material exists yet, and you should plan around that rather than hunt for it: the outline changed faster than the publishing cycle around it, so most CC books, video courses and question banks in circulation are still built on the previous structure. There is a fast way to check any resource: look at its Domain 2. If the table of contents says "Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts," it was written for the previous outline. If it says "Security Governance," it has been updated. Material built on the previous outline is still worth using for the roughly two-thirds of content that carried over — just pair it with the new outline PDF and self-study the additions listed above, which no old resource will contain.

What did not change

This part matters as much as the diff, because it tells you what your existing preparation is still good for.

  • The exam mechanics are identical. Still CAT, still 100–125 items, still 2 hours, still 700 out of 1000 to pass, still multiple choice plus advanced item types. Any practice you have done on pacing and adaptive-test strategy transfers intact.
  • Still five domains, and Domain 1 is still Security Principles.
  • The CIA triad core is untouched — confidentiality, integrity, availability, non-repudiation and privacy all remain in 1.1.
  • Risk management remains in Domain 1, reframed as lifecycle and processes rather than identification/assessment/treatment, but the underlying concepts are the same.
  • The ISC2 Code of Ethics is still examinable, in 1.5.
  • Controls typing is unchanged — technical, administrative, physical.
  • Networking fundamentals survive: OSI model, TCP/IP, IPv4, IPv6, VPN, firewalls, ports, VLANs, segmentation, IoT and ICS are all still in Domain 4, joined by wireless (Wi-Fi, Bluetooth).
  • Logging and monitoring, encryption and data handling remain in Domain 5.
  • No prerequisite change. Still no work experience or degree required; ISC2 still recommends basic IT knowledge.
  • Same languages, same delivery. English, Chinese, Japanese, German and Spanish at Pearson VUE, with CAT across all five.
  • Accreditation is unchanged — ANAB, ISO/IEC 17024.

The move now is the same one for everybody: download the September 2026 PDF from ISC2 directly, treat the new Domain 2 and the cloud, IAM lifecycle and security testing additions as your gap list, and keep using what you already own for the two-thirds that carried over. Either way you can pressure-test your recall with our free ISC2 Certified in Cybersecurity practice test before you walk in.

Ready to test yourself?

Free ISC2 CC practice test — 150 questions, instant feedback. No signup required.

Start practicing →

Sources

  1. 1.CC Certification Exam Outline — ISC2 (accessed Jul 18, 2026)
  2. 2.How to Register, Schedule, Cancel, Pay For Your ISC2 Exam — ISC2 (accessed Jul 18, 2026)
  3. 3.Certified in Cybersecurity (CC) Certification Overview — ISC2 (accessed Jul 18, 2026)
  4. 4.ISC2 Annual Maintenance Fees (AMF) Overview — ISC2 (accessed Jul 18, 2026)
  5. 5.ISC2 Exam Pricing — ISC2 (accessed Jul 18, 2026)

Frequently asked questions

When did the new ISC2 CC exam outline take effect?

September 1, 2026. ISC2 states that "Effective September 1, 2026, the CC exam will be based on a new exam outline." The previous outline carried an effective date of October 1, 2025 and applied to exams sat on or before August 31, 2026.

I registered months ago. Do I get the old CC exam or the new one?

Whichever outline is in force on the day you sit. The change is keyed to your test date, not your registration date or when you bought your voucher, and ISC2 has published no carve-out for earlier registrations. Exams sat on or before August 31, 2026 used the previous outline; every exam from September 1, 2026 onward uses the new one, so every candidate still to sit is on the new version regardless of when they registered.

What are the new CC domain weights?

Security Principles 24%, Security Governance 17.3%, Identity And Access Management (IAM) Concepts 20%, Networking and Cloud Security Concepts 21.3%, and Security Operations and Incident Response 17.3%. These replace the outgoing weights of 26%, 10%, 22%, 24% and 18%. Do not read the Domain 2 jump from 10% to 17.3% as growth in business continuity content — that slot was repurposed from BC/DR to Security Governance, and BC/DR is now two bullets under "Understand redundancy."

Is the new CC exam harder, and do current study materials still work?

ISC2 has not said the new version is harder or easier, and the format is identical — still CAT, 100 to 125 items, 2 hours, 700 out of 1000 to pass — so "different" is the accurate word. Most existing books and question banks still target the previous outline and remain useful for the large overlap, but they will not cover the genuinely new topics such as Zero Trust, cloud service and deployment models, identity life cycle management, threat intelligence, security testing and quantum resistant cryptography. To check any resource quickly, look at its Domain 2: "Security Governance" means updated, "Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts" means it predates the change.