Every Exam PrepFREE EXAM PREP
Ask AI

ISC2 CC Pass Rate 2026: No Official Rate Exists

Written by Every Exam Prep Editorial TeamSource and review policyPublished August 16, 2026Updated August 19, 2026
Verified against the official exam documentation
ISC2 CC — the numbers that matter
Time limit
2h
Passing score
700 out of 1000 points
Exam fee
$199

ISC2 does not publish a pass rate for the Certified in Cybersecurity (CC) exam. There is no official first-attempt figure, no yearly breakdown, and no regional split. ISC2 goes further than most vendors here: it does not release your numeric score even when you pass. The proctor hands you an unofficial pass or fail at checkout, and ISC2 states plainly that "no scores are provided." So every percentage you have seen attached to CC is somebody's guess wearing the clothes of data. What ISC2 does publish is the standard you have to clear, and that is the only number worth planning against: a scale score of 700 out of 1,000.

How the CC exam is actually scored

CC is not a fixed 100-question paper. ISC2 says it "uses the Computerized Adaptive Testing (CAT) format for CC, CCSP, CISSP, and SSCP exams worldwide." Here is everything the vendor publishes about the current exam:

ItemOfficial value
Questions100–125 items (adaptive, so the count varies)
Time limit2 hours
FormatComputerized Adaptive Testing (CAT)
Item typesMultiple choice plus advanced item types
Passing score700 out of 1,000 — a scale score
DeliveryPearson VUE test center
LanguagesEnglish, Chinese, Japanese, German, Spanish
Exam fee$199
Result reportedPass/fail only; no numeric score released

The load-bearing phrase is scale score. ISC2's wording is: "You need a scale score of at least 700 out of a possible 1,000 points to pass." A scale score is not a percentage of questions answered correctly, and 700 out of 1,000 is not "70% right." It is a position on a 1,000-point measurement scale that has been statistically equated so that candidates who sat different sets of questions are held to the same standard.

On an adaptive exam this distinction stops being academic. The engine adjusts item difficulty as you answer, so a hard item you get right carries more evidence of competence than an easy one, and two candidates with the identical raw number of correct answers can finish on different scale scores. That is also why the item count is a range rather than a fixed number: the exam ends when the engine has enough certainty to place you on one side of the standard, somewhere between 100 and 125 items. Any page telling you "you need 70% on CC" has silently converted a scale score into a percentage, which is exactly the error that produces confident, wrong advice.

One more official mechanic is worth knowing, because it is more useful than any rumored statistic: if you fail, ISC2 says "a list of proficiency levels for each domain will be provided at the testing center." That report tells you where you actually lost the exam.

Why the pass rates you see online disagree

Search for a CC pass rate and a single results page will offer you 40%, around 60%, and "70–80%" for the same exam in the same year. They disagree because none of them are measurements. Not one of them cites ISC2, and they cannot, because ISC2 has never released the figure. Trace any of these numbers back and the trail ends at another blog post, a forum poll, or nothing at all.

The incentives point in two directions, which is why the spread is so wide. Training providers and bootcamps selling a CC course benefit from a low number: a scary pass rate is the argument for buying preparation. Providers advertising their own results benefit from a high number, but a cohort rate describes people who paid for a course and finished it, which is a heavily selected group and not a random candidate. Neither figure is about the exam. Both are about the seller.

The free-exam effect nobody accounts for

CC has a complication most certifications do not. ISC2 ran the One Million Certified in Cybersecurity program, which gave participants a free self-paced CC course and a free exam voucher. ISC2 now states the program "has surpassed its goal of enabling more than 1 million people globally to enroll in a free Certified in Cybersecurity (CC) online course and exam" and that it "has closed new enrollments." Enrollment closed on May 20, 2026, and holders of valid exam codes can still "schedule and sit for the exam by December 31, 2026."

A free exam removes the price filter, and the price filter is what normally keeps unprepared candidates out of the seat. For several years a very large share of CC sitters had nothing at stake financially and every reason to try it cold. Whatever the true rate was in that window, it describes an unusually broad and unusually casual population. It is not the rate that applies to someone paying $199 out of pocket in late 2026. Every number circulating online straddles that divide without telling you which side it came from, which by itself makes it worthless as a prediction about you. If you are holding a 1MCC code, the number that should concern you is not a pass rate at all — it is December 31, 2026.

What actually separates passing from failing candidates

The domain weights are the only official statement ISC2 makes about what the exam emphasizes, and they are far more lopsided than most study plans assume:

DomainWeight
1. Security Principles26%
2. Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts10%
3. Access Controls Concepts22%
4. Network Security24%
5. Security Operations18%

Three domains — Security Principles, Network Security and Access Controls Concepts — account for 72% of the exam between them. Business continuity, disaster recovery and incident response, which is the block of memorable acronyms candidates tend to over-drill because it feels like the "real" security content, is 10%. Perfecting it moves roughly one question in ten. Being shaky on access control models or basic network concepts costs you nearly half the exam. Candidates who fail rarely do so because they missed an exotic topic; they fail because they spread effort evenly across five domains that are not weighted evenly.

Two dates matter alongside the weights. ISC2's notice reads: "Effective September 1, 2026, the CC exam will be based on a new exam outline." The weights above are the current outline, which runs through August 31, 2026, so if you are booking a seat this fall, confirm which outline your study materials were written against before you trust their emphasis. And the retake rules shape strategy more than any pass rate would: ISC2 requires 30 test-free days after a first failed attempt, 60 after a second, 90 after a third and each one after that, with a maximum of four attempts at a certification within any 12-month period. Combined with the domain proficiency report, a failure is a targeted second attempt rather than a restart — but the 30-day floor means a rushed first sitting costs you a month.

The bottom line

There is no ISC2 pass rate for CC, and there is no honest way to construct one from the outside, because ISC2 does not even report scores to the people who pass. The numbers you find online are marketing artifacts, and the free-voucher era makes them less comparable to your situation than usual. Plan against the published standard instead: 700 on a 1,000-point scale, adaptive delivery over 100 to 125 items in two hours, and five domains where three of them carry 72% of the weight. Study to the weights, sit under timed adaptive conditions so the format is not a surprise, and treat the September 1, 2026 outline change as a scheduling decision rather than a detail.

The most reliable read on your own chances is not a statistic about strangers — it is your score on full-length, weighted practice under a clock. Take a free ISC2 Certified in Cybersecurity practice test and let your own domain breakdown tell you whether you are ready.

Original source visualizations

What the cited data shows

Built from the official facts cited in this article. Missing values are omitted, not estimated.

Official fee breakdown
ItemAmountSource
Exam Cost$The registration price for the CC exam is U.S. $199ISC2
Official-source update comparison
DocumentEffective dateChecked
ISC2: CC Certification Exam OutlineNot stated2026-07-18
ISC2: ISC2 Exam PricingNot stated2026-07-18
Ready to test yourself?

Free ISC2 CC practice test — 65 questions, instant feedback. No signup required.

Start practicing →

Sources

  1. 1.CC Certification Exam OutlineISC2 (accessed Jul 18, 2026)
  2. 2.ISC2 Exam PricingISC2 (accessed Jul 18, 2026)
  3. 3.ISC2 CertificationsISC2
  4. 4.Register for an ISC2 ExamISC2
  5. 5.ISC2 Exam-Day GuidanceISC2
  6. 6.ISC2 — Certified in Cybersecurity (CC) certification pageofficial (accessed Aug 16, 2026)

Frequently asked questions

What is the pass rate for the ISC2 CC exam?

There is no published pass rate. ISC2 does not release pass rates for the Certified in Cybersecurity exam by year, attempt number, or region, and it does not even give candidates a numeric score when they pass — the result is reported as pass or fail only. Every percentage circulating online is an unsourced estimate rather than a measurement. The only official threshold ISC2 publishes is a scale score of 700 out of 1,000.

Do you need 70% to pass the ISC2 CC exam?

No. The 700 figure is a scale score out of 1,000 points, not a percentage of questions answered correctly. CC is delivered as a computerized adaptive test, so item difficulty shifts as you answer and harder items carry more weight, which means two candidates with the same number of correct answers can finish with different scale scores. There is no fixed percentage of questions that guarantees a pass.

Is the ISC2 CC exam still free in 2026?

Not for new candidates. ISC2's One Million Certified in Cybersecurity program, which included a free self-paced course and a free exam voucher, surpassed its goal and closed new enrollments on May 20, 2026. Candidates who already hold a valid exam code can still schedule and sit the exam through December 31, 2026. Everyone else pays the standard $199 exam fee.

How soon can you retake the ISC2 CC exam after failing?

After a first failed attempt you must wait 30 test-free days before retesting. A second failure requires 60 test-free days from your most recent attempt, and a third or any later failure requires 90 days. ISC2 allows a maximum of four attempts at a given certification exam within any 12-month period, and candidates who fail receive a list of proficiency levels for each domain at the test center to help target the retake.