ISC2 Certified in Cybersecurity (CC) Exam Guide
At a glance
- Time limit
- 2h
- Passing score
- 700 out of 1000 points
- Exam fee
- $199
- Governing body
- ISC2
Quick answers
How much does the ISC2 CC cost?
The ISC2 CC exam fee is $199.
What is the passing score for the ISC2 CC?
The passing score for the ISC2 CC is 700 out of 1000 points.
ISC² Certified in Cybersecurity (CC) is an entry-level credential designed for professionals building a foundation in cybersecurity fundamentals. No prior work experience is required to sit for the exam, making it accessible to career changers and early-stage practitioners. This credential signals solid knowledge of core security principles and prepares you to contribute immediately in security roles.
Overview
The CC exam spans 5 foundational domains: Security Principles, Business Continuity & Disaster Recovery & Incident Response Concepts, Access Controls Concepts, Network Security, and Security Operations. Each domain is weighted differently—Security Principles dominates at 26%, while others range from 10% to 24%—ensuring a balanced survey of essential cybersecurity concepts.
Cost and registration
The registration price for the CC exam is U.S. $199. ISC² also charges an Annual Maintenance Fee (AMF) of U.S. $50 for members who hold CC, with a 90-day grace period from the due date to pay.
Exam format
The CC exam contains 100–125 questions delivered via Computerized Adaptive Testing (CAT), which adjusts difficulty based on your performance. You have 2 hours to complete it, and the passing score is 700 out of 1000 points. The exam uses multiple choice and advanced item types, administered at Pearson VUE testing centers worldwide.
Verified facts about the ISC2 CC
18 statements, each bound to the official document it was taken from. The source link beside every line opens that document.
Requirements and rules
Fees
Numbers
What is tested
- Domain2 weight
- Domain 2 Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts is 10% of the exam%
- ISC2
- Domains list
- The five domains are Security Principles; Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts; Access Controls Concepts; Network Security; and Security Operations
- ISC2
- Exam format
- The exam uses multiple choice and advanced item types administered as Computerized Adaptive Testing (CAT)
- ISC2
How hard is the ISC2 CC?
How Hard Is the ISC2 Certified in Cybersecurity (CC) Exam?
The ISC2 Certified in Cybersecurity (CC) is an entry-level certification that bridges the gap between aspiring security professionals and industry-recognized credentials. If you're considering whether to pursue it, understanding the difficulty level requires looking at the exam structure, content coverage, passing requirements, and realistic preparation strategies.
Exam Format and Structure
The CC exam uses multiple choice and advanced item types administered as Computerized Adaptive Testing (CAT). This adaptive format means the difficulty of questions adjusts based on your performance, which can feel challenging but ultimately aims to pinpoint your true knowledge level accurately. Unlike linear exams where everyone answers the same questions in the same order, adaptive testing personalizes your experience based on demonstrated competency.
You'll face 100-125 questions during the exam, with 2 hours (120 minutes) to complete it. Adaptive testing doesn't require you to answer questions in sequence, and you may finish earlier if the exam has determined your score with confidence. The time pressure is moderate—not rushed, but requiring efficient reading and decision-making.
Content Coverage: Five Domains
The exam covers 5 domains of foundational cybersecurity knowledge: Security Principles; Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts; Access Controls Concepts; Network Security; and Security Operations. Each domain represents a distinct pillar of cybersecurity knowledge that cybersecurity practitioners must understand.
These domains are not weighted equally, and understanding the weighting is crucial for strategic preparation. Domain 1 Security Principles is 26% of the exam, making it the largest section. Domain 4 Network Security is 24% of the exam, and Domain 3 Access Controls Concepts is 22% of the exam. Domain 5 Security Operations is 18% of the exam, while Domain 2 Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts is 10% of the exam.
Understanding this weighting helps you allocate study effort strategically, focusing deeper on the domains that carry more exam weight while still ensuring you understand all five areas. This isn't permission to skip any domain—the exam will test all of them—but rather guidance on where to invest additional depth.
Passing Score and Performance Bar
The passing score is 700 out of 1000 points. Because the exam uses adaptive testing, your score reflects both the number of correct answers and the difficulty level of the questions you faced. Scoring higher on difficult questions contributes more to your overall score than scoring equally on easier questions.
This is considered a moderate bar for entry-level certification. It's achievable for those with foundational knowledge and structured preparation, but not trivial for those unfamiliar with cybersecurity concepts. The 700 threshold is not a curve—it's a fixed performance standard, meaning the certification maintains consistency across test administrations.
Difficulty Assessment
The CC is intentionally positioned as an entry-level certification, which means it's more accessible than mid-level credentials like the CISSP or advanced specializations. However, "entry-level" doesn't mean "easy." The exam tests genuine understanding of cybersecurity principles rather than memorization of isolated facts. You can't cram your way through without foundational knowledge.
The difficulty lies primarily in three areas: breadth of coverage across five distinct domains, the application of concepts to realistic scenarios, and the adaptive nature of the exam, which prevents you from simply grinding through easy questions to pass. Candidates with no prior security experience may find the breadth challenging, while those with hands-on or educational background often report the exam as moderate in difficulty.
Preparation Approach
A solid preparation strategy focuses on understanding how to tackle the material systematically. Start by thoroughly reviewing the official ISC2 curriculum for all five domains, with emphasis on the three highest-weighted domains. Supplement this with practical application wherever possible—understanding how access control lists work in a real network, for example, is more valuable than memorizing their definition.
Practice questions are essential. They expose you to the exam's question style and help identify weak areas. Work through questions repeatedly, focusing on understanding why correct answers are correct and why incorrect options are wrong. This builds the conceptual foundation needed to handle the adaptive questions on exam day. Aim to understand the reasoning, not just get answers right.
Review weak areas after each practice session. If network security questions consistently challenge you, allocate additional time to network architecture, protocols, and threats. Readiness signals include consistently scoring well on practice tests, ability to explain domain concepts in your own words, and confidence handling scenario-based questions that ask "what should happen in this situation?" When these signals align, you're likely exam-ready.
Study materials vary widely in quality and focus. Many candidates supplement with paid courses, study guides, or instructor-led training, though these choices depend entirely on your learning style and existing knowledge base. Official ISC2 resources provide authoritative coverage, while third-party materials often offer different pedagogical approaches.
Practical Considerations
| Logistics | Details |
|---|---|
| Exam Fee | $199 |
| Test Duration | 120 minutes |
| Number of Questions | 100-125 |
| Passing Score | 700 out of 1000 |
| Testing Provider | Pearson VUE testing centers worldwide |
| Reschedule Fee | $50 |
| Cancellation Fee | $100 |
| Annual Maintenance Fee | $50 |
No prior work experience is required to sit for the CC exam, which removes a significant barrier to entry compared to many other security certifications. Anyone can register and test immediately, whether you're transitioning from another field, launching your first security role, or deepening existing knowledge. This accessibility has made the CC popular among career changers.
One often-overlooked detail: Members are given a 90-day period from the due date to pay their annual maintenance fee. This grace period can help with cash flow management if you pass and maintain the certification. Keeping your certification active requires this ongoing commitment, but the flexibility helps professionals manage timing.
Rescheduling and cancellation fees exist to manage test center capacity. Cancellation carries a steeper penalty ($100) than rescheduling ($50), so if you need to adjust your test date, rescheduling early is the more economical choice.
Is It Right for You?
The CC exam is moderately difficult but achievable. It's easier than advanced certifications and harder than basic security awareness training. The certification serves as a legitimate entry point into cybersecurity careers and builds a foundation for pursuing higher-level credentials later. Many professionals earn the CC as a stepping stone toward more advanced certifications.
If you have curiosity about cybersecurity, can dedicate focused study time, and approach the material with the goal of genuine understanding rather than memorization, the CC is within reach. The exam rewards thorough knowledge across all five domains and the ability to apply concepts to real-world scenarios. Success on this exam demonstrates that you've built a solid foundation in foundational cybersecurity principles.
Ways to prepare for the ISC2 CC
Each of these is a side-by-side on what the provider does better than we do, what it charges today, and where the free path here is enough.
Frequently asked questions
How much does the ISC2 Certified in Cybersecurity (CC) exam cost?
The registration price for the CC exam is U.S. $199. If you need to change your appointment after booking, Pearson VUE charges a reschedule fee of U.S. $50, and a cancellation fee of U.S. $100 applies if you cancel. Budget for these separately from the exam fee so a scheduling change doesn't catch you off guard.
Do I need work experience to take the CC exam, and how is the test structured?
No prior work experience is required to sit for the CC exam, which makes it a genuine entry point into cybersecurity. The exam contains 100-125 questions and gives you 2 hours (120 minutes) to complete it. It uses multiple choice and advanced item types administered as Computerized Adaptive Testing (CAT), so the difficulty of your next question adapts to how you've answered so far. To pass, you need a score of 700 out of 1000 points.
Which domains does the CC exam cover, and how should I prioritize my study time?
The CC exam covers 5 domains of foundational cybersecurity knowledge: Security Principles; Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts; Access Controls Concepts; Network Security; and Security Operations. They are not weighted equally — Security Principles is 26%, Access Controls Concepts is 22%, Network Security is 24%, Security Operations is 18%, and BC/DR & Incident Response Concepts is 10%. Because Security Principles, Network Security, and Access Controls together account for 72% of the exam, weighting your study time toward those three domains gives you the most return.
Where do I take the exam, and what ongoing costs come after I pass?
The CC exam is administered at Pearson VUE testing centers worldwide, so you schedule your seat through Pearson VUE. After you earn the certification, the Annual Maintenance Fee for members who only hold CC is U.S. $50, and members are given a 90-day period from the due date to pay their AMF. Mark that due date on your calendar and use the 90-day window as a buffer so your certification stays in good standing.
How hard is the ISC2 CC exam?
The CC is entry-level by design: it assumes no prior work experience and tests foundational security concepts over a 2-hour, 100–125-question adaptive exam with a passing score of 700 out of 1000. Most newcomers who put in a few weeks of structured study pass it — the candidates who struggle are usually the ones who skip the security-operations and network-security terminology rather than the concepts.
How hard is the ISC2 Certified in Cybersecurity (CC) exam?
The CC exam is designed as an entry-level test, and ISC2 states that no prior work experience is required to sit for it. You get 2 hours to answer 100–125 questions across five domains, and you need a scaled score of 700 out of 1000 points to pass. Most of the difficulty comes from breadth rather than depth — the exam samples foundational concepts across all five domains rather than probing any one of them deeply.
What is the pass rate for the ISC2 CC exam?
ISC2 does not publish an official pass rate for the Certified in Cybersecurity exam, so any percentage you see quoted online is unverified. What ISC2 does publish is the passing standard: 700 out of 1000 points on an exam delivered as Computerized Adaptive Testing (CAT), which adjusts question difficulty based on your answers. Because CAT scoring is scaled rather than a simple percentage of questions answered correctly, treat "I need 70% right" as a misreading of the 700-point standard.
How much does the ISC2 CC exam cost?
According to ISC2, the registration price for the Certified in Cybersecurity exam is U.S. $199. Beyond the exam itself, certified members who hold only CC pay an Annual Maintenance Fee of U.S. $50, with a 90-day period from the due date to pay it. Budget for schedule changes too: Pearson VUE charges a reschedule fee of U.S. $50 and a cancellation fee of U.S. $100.
How should I study for the ISC2 CC exam?
Study in proportion to the published domain weights rather than giving each domain equal time. ISC2 weights Domain 1 Security Principles at 26%, Domain 4 Network Security at 24%, Domain 3 Access Controls Concepts at 22%, Domain 5 Security Operations at 18%, and Domain 2 Business Continuity, Disaster Recovery and Incident Response Concepts at 10%. That means Security Principles and Network Security together account for half the exam, so they deserve the largest share of your review time, while Domain 2 needs solid coverage of core concepts rather than deep study.
What topics are on the ISC2 CC exam?
ISC2 says the CC exam covers five domains of foundational cybersecurity knowledge: Security Principles; Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts; Access Controls Concepts; Network Security; and Security Operations. Everything tested falls inside that outline, so the domains double as a study checklist. Because the exam is entry-level and requires no prior work experience, the questions target concepts and terminology rather than hands-on tool configuration.
Where do I take the ISC2 CC exam, and what happens if I need to change my appointment?
The CC exam is administered at Pearson VUE testing centers worldwide, delivered as a Computerized Adaptive Testing (CAT) exam with multiple choice and advanced item types. If your plans change, Pearson VUE charges a reschedule fee of U.S. $50, and a cancellation fee of U.S. $100 if you drop the appointment entirely. Since cancelling costs twice as much as moving the date, rescheduling is usually the cheaper option when you are not ready to sit.
Sources
- 1.CC Certification Exam Outline — ISC2 (accessed Jul 18, 2026)
- 2.How to Register, Schedule, Cancel, Pay For Your ISC2 Exam — ISC2 (accessed Jul 18, 2026)
- 3.Certified in Cybersecurity (CC) Certification Overview — ISC2 (accessed Jul 18, 2026)
- 4.ISC2 Annual Maintenance Fees (AMF) Overview — ISC2 (accessed Jul 18, 2026)
- 5.ISC2 Exam Pricing — ISC2 (accessed Jul 18, 2026)
Official sources
Primary documents used to verify the exam details shown on this page.
- CC Certification Exam OutlineISC2isc2.org
- How to Register, Schedule, Cancel, Pay For Your ISC2 ExamISC2isc2.org
- Certified in Cybersecurity (CC) Certification OverviewISC2isc2.org
- ISC2 Annual Maintenance Fees (AMF) OverviewISC2isc2.org
- ISC2 Exam PricingISC2isc2.org
Last verified against the official exam content outline: