ISC2 CC Exam Update: What Changed on September 1 and How to Study for the New Version

ISC2 updated the CC exam on September 1, 2026. See the five domains, reported new weights, the new governance domain, AI topics, and a study plan for old-outline students.

ISC2 CC exam update
On this page
  1. Quick Facts
  2. What ISC2 Confirms, and What It Does Not
  3. Old Outline vs New Outline: The Gap Table
  4. The weight spread
  5. Domain by Domain: What to Relearn
  6. Domain 1: Security Principles (reported 24%)
  7. Domain 2: Security Governance (reported 17.3%)
  8. Domain 3: Identity and Access Management Concepts (reported 20%)
  9. Domain 4: Networking and Cloud Security Concepts (reported 21.3%)
  10. Domain 5: Security Operations and Incident Response (reported 17.3%)
  11. AI Across the Whole Outline
  12. Format and Cost
  13. Where Sources Disagree
  14. Who Should Take CC, and Who Should Skip It
  15. The Four Gaps: What Old-Outline Students Must Add
  16. A Four to Six Week Study Plan
  17. Five practice prompts built from the new outline
  18. Common Mistakes
  19. Career Value
  20. What We Don’t Know Yet
  21. FAQS

Guide overview

What this article covers

TL;DR: ISC2 updated its Certified in Cybersecurity (CC) exam outline effective September 1, 2026. ISC2’s outline page confirms the new date and lists five domains: Security Principles, Security Governance, Identity and Access Management (IAM) Concepts, Networking and Cloud Security Concepts, and Security Operations and Incident Response. The headline change is that governance became its own domain, and artificial intelligence topics now run through the whole outline. Several study-guide sites report the new weights as 24%, 17.3%, 20%, 21.3% and 17.3%, which flattens the old spread, where the biggest domain carried 26% and the smallest 10%. We could not read the weights on ISC2’s own page, so we label them as reported. The exam is adaptive, scored out of 1,000 with 700 to pass, and one source says the exam now costs $199. This guide compares the old and new outlines, lists what to relearn, gives a four to six week plan, and flags every place where sources disagree or ISC2 has not said.

If you started studying for CC before September, or you bought a course last spring, this is the post for you. The exam you will sit is not the exam your older notes describe.

Quick Facts

ItemWhat the sources say
ExamISC2 Certified in Cybersecurity (CC)
Outline effective dateSeptember 1, 2026 (stated on ISC2’s outline page)
Number of domains5 (named on ISC2’s outline page)
Reported new weightsSecurity Principles 24%, Security Governance 17.3%, IAM Concepts 20%, Networking and Cloud Security Concepts 21.3%, Security Operations and Incident Response 17.3% (reported by several study-guide sites)
Reported old weightsSecurity Principles 26%, Business Continuity, Disaster Recovery and Incident Response 10%, Access Controls Concepts 22%, Network Security 24%, Security Operations 18%
FormatComputerized adaptive testing (CAT), reported as 100 to 125 items in 2 hours
Passing score700 out of 1,000 (reported)
Reported fee$199 USD in most regions, plus a $50 annual maintenance fee after passing
Experience requiredNone. ISC2 describes CC as entry level with no work experience required
LanguagesReported as English, Chinese, Japanese, German and Spanish

Items marked “reported” come from third-party summaries we could not match to a page that ISC2 made readable. Check ISC2’s outline and exam pages for the final numbers before you pay.

What ISC2 Confirms, and What It Does Not

The most useful way to read this update is to split it into three buckets.

BucketItems
Confirmed on ISC2’s outline pageEffective date of September 1, 2026. Five domains with the names listed above. AI woven through the outline
Reported consistently by several third-party sourcesThe new domain weights. The five-domain mapping from old to new. 700 out of 1,000 passing score. CAT format
Reported by only one source, or in conflictExact question count (100 versus 100 to 125). The free exam program closing on May 20, 2026. The direction of a few weight changes

ISC2 also published an article in August 2026 titled “What’s New for Entry-Level Cybersecurity,” which describes the update as emphasizing governance, cloud security and threat intelligence. We could read its description but not its body, so we treat it as support for the direction of travel rather than a source for numbers.

Old Outline vs New Outline: The Gap Table

This is the part to print and tape to your monitor. It shows each old domain and where its content most likely went.

Old domain (weight)New domain (reported weight)What this means
Security Principles (26%)Security Principles (24%)Still the foundation, with slightly less weight
Business Continuity, Disaster Recovery and Incident Response (10%)Security Governance (17.3%)The domain was replaced and renamed. Governance is now a standalone area, and incident response moved into Security Operations
Access Controls Concepts (22%)Identity and Access Management Concepts (20%)Renamed, with identity lifecycle topics added
Network Security (24%)Networking and Cloud Security Concepts (21.3%)Renamed, with cloud and zero trust folded in
Security Operations (18%)Security Operations and Incident Response (17.3%)Renamed, with incident response now inside it

A note on the mapping. The old-to-new arrows in the middle column come from third-party analysis. ISC2’s outline page does not, in the content we could read, say which old domain maps to which new one. The names make the mapping reasonable, but treat it as an informed reading and not an official crosswalk.

The weight spread

MeasureOld outlineNew outline (reported)
Largest domain26% (Security Principles)24% (Security Principles)
Smallest domain10% (Business Continuity, Disaster Recovery and Incident Response)17.3% (Security Governance and Security Operations and Incident Response tie)
Gap between largest and smallest16 points6.7 points

The practical meaning is simple. Under the old outline, you could treat the 10% domain as a small side topic. Under the new outline, no domain is small. Every domain carries at least 17.3% of the exam, so a weak area costs you more.

Domain by Domain: What to Relearn

The topic lists below come from third-party summaries of the updated outline. Where a topic could belong to more than one domain, we say so. Always cross-check against ISC2’s outline page.

Domain 1: Security Principles (reported 24%)

This remains the foundation: the confidentiality, integrity and availability triad, risk basics, and the principles that hold the rest of the exam together. Reported additions touch data protection, such as masking, sanitization and quantum-resistant cryptography, though sources do not all place them in this domain.

Study moveWhy
Re-read your notes on risk, controls and ethicsStill the heaviest domain
Add data protection basicsMasking and sanitization are reported in the updated content
Add a one-page summary of quantum-resistant cryptography at a recognition levelReported as new. Expect recognition, not mathematics

Domain 2: Security Governance (reported 17.3%)

This is the headline change. The old outline had no standalone governance domain, and one source says governance material was previously scattered across domains. The old domain closest in size (Business Continuity, Disaster Recovery and Incident Response) held 10%.

Reported topicWhat to know
Governance, risk and compliance frameworksThe purpose of policies, standards, procedures and frameworks, and how they relate
Compliance and regulationsWhy organizations follow them, and what compliance proves
Business continuity and disaster recoveryStill relevant. Check where your study material places it
Governing emerging technologyOne source says candidates must understand the basics of governing AI and other emerging technology

If you studied only technical topics, this domain is the biggest hole in your preparation.

Domain 3: Identity and Access Management Concepts (reported 20%)

Access control remains core. The reported addition is identity lifecycle management.

Reported topicWhat to know
Provisioning and deprovisioningCreating and removing access when people join and leave
Joiner, mover and leaver processesWhat happens when someone changes roles
Authentication, authorization and accountabilityThe classic core, still testable
Least privilege and separation of dutiesStandard principles that remain important

Domain 4: Networking and Cloud Security Concepts (reported 21.3%)

Network security now includes cloud security. One source describes cloud security and zero trust as integrated into this domain.

Reported topicWhat to know
Shared responsibility modelWho secures what between provider and customer
Zero trust architectureThe idea of never trusting by default, and verifying every request
Micro-segmentationDividing a network into small zones to limit movement
Core networkingStill tested. Ports, protocols and common devices stay relevant

Domain 5: Security Operations and Incident Response (reported 17.3%)

Incident response now sits with security operations, and several sources highlight threat-focused topics.

Reported topicWhat to know
Security event triageDeciding which alerts matter
Incident response proceduresDetection, containment, eradication, recovery and lessons learned
Threat intelligence and threat actorsWho attacks and why, and how organizations use intelligence
Red, blue and purple team conceptsWhat each team does
Application security testing and threat modelingReported in the updated content

AI Across the Whole Outline

ISC2’s outline page emphasizes AI integration throughout the certification, and every summary we read says the same thing: AI concepts appear across all five domains and not in a single chapter.

One source frames the level of knowledge well: the goal is recognition, not engineering. A CC candidate is not expected to build or secure AI systems. The reported expectations are modest.

ExpectationWhat it means
Identify AI assetsKnow that models, data and AI services are things an organization needs to protect
Recognize automated threatsUnderstand that attackers can automate attacks
Understand the basics of governing emerging technologyKnow why policies for AI use matter

The best way to prepare is to add one AI example to each domain in your notes. For instance, note one AI related governance issue, one AI related access control issue, and one AI related operations issue. That keeps the topic connected to the fundamentals.

Format and Cost

ItemReport
Testing methodComputerized adaptive testing (CAT)
Items100 to 125 reported by most sources. One source says 100
Time2 hours
Passing score700 out of 1,000
Fee$199 USD in most regions, plus a $50 annual maintenance fee after passing
One report on the free programThe earlier program that made the exam and training free through ISC2’s One Million Certified in Cybersecurity effort reportedly closed to new enrollments on May 20, 2026

Two cautions. First, the item count differs between sources, and adaptive exams commonly use a range, so 100 to 125 looks more likely than a flat 100. Second, the free program closure comes from one source. If you were counting on a free attempt, confirm with ISC2 before you plan.

A reminder about adaptive tests: the exam adjusts to your answers, so you cannot skip questions and return later. Practice answering one question at a time and moving on.

Where Sources Disagree

TopicOne reportAnother report
Question count100100 to 125
Direction of some weight changesOne summary describes IAM as “up from 22%” when 20% is lowerOthers list it as a decrease
Whether weights are officialStudy guide sites list exact figuresThe ISC2 outline page, as we could read it, did not show weights
Mapping of old to new domainsSeveral sites present a clean old-to-new tableISC2’s page does not present one in the content we could read

For the weights, four independent sites printed the same numbers, which gives us reasonable confidence. It is still not the same as reading them on ISC2’s page. Before you build a study plan around exact percentages, check ISC2’s outline.

Who Should Take CC, and Who Should Skip It

Your situationSuggestionWhy
New to cybersecurity with no experienceCC is a sensible first stepISC2 positions it as entry level with no work experience required
Switching careers from IT supportCC can work as a first credential, but compare it with other entry-level optionsSee our best cybersecurity certifications ranking
Already working in security with 2 or more yearsYou may want a higher credentialLook at CISSP vs CISM or CISSP vs CEH
Interested in cloud securityCC is a start, then consider a cloud credentialSee CCSK vs CCSP and CCSP vs AWS Security Specialty
Interested in risk and governanceCC now has a governance domain, which is a taste of that pathSee CRISC vs CISM
Student wanting a resume lineCC fitsThe exam fee and annual maintenance fee are worth weighing

If you already started studying, do not panic. The core ideas carry over. Most of your work is in four gaps, covered in the next section.

The Four Gaps: What Old-Outline Students Must Add

If you studied the previous outline, these are the topics most likely to be new or heavier.

GapWhat to addTime estimate
GovernanceFrameworks, policies, compliance basics, continuityThe largest gap. Plan the most time here
Cloud and zero trustShared responsibility, zero trust, segmentationA focused few sessions
Identity lifecycleProvisioning, deprovisioning, joiner, mover, leaverShort, but easy to forget
AI conceptsOne AI example per domainA light layer across your notes

We deliberately do not give hour counts here. Study time depends on your background, and a made-up number would be false precision.

A Four to Six Week Study Plan

This plan assumes you are starting from scratch or refreshing older notes.

WeekFocusGoal
1Security PrinciplesMaster the triad, risk, controls and ethics. Add data protection basics
2Security GovernanceLearn policy hierarchy, frameworks, compliance and continuity
3IAM Concepts and Networking and Cloud SecurityAuthentication, authorization, lifecycle, shared responsibility, zero trust
4Security Operations and Incident ResponseTriage, response steps, threat intelligence, team colors
5Practice questions, one question at a timeBuild adaptive test habits. Review every miss
6Weak spots and restRevisit the lowest scoring domain. Book the exam

If you have only four weeks, combine weeks 5 and 6, and keep the governance week intact. If you want extra practice, the CC practice questions page can supplement your own notes, as long as you check each topic against ISC2’s current outline.

Five practice prompts built from the new outline

These are study prompts, not real exam questions. Answer them from memory, then check your notes.

#PromptDomain it touches
1Explain the difference between a policy, a standard and a procedure, and give one example of eachSecurity Governance
2An employee changes departments. List what should happen to their access, and name the processIAM Concepts
3A company moves a server to a cloud provider. State who is responsible for the operating system patches, and why this mattersNetworking and Cloud Security Concepts
4A security tool raises 40 alerts. Describe how you would decide which to look at firstSecurity Operations and Incident Response
5A team wants to use an AI tool with customer data. List two governance questions to ask firstSecurity Governance and Security Principles

Prompt 3 depends on the model your provider uses, so the point is the reasoning about shared responsibility and not a single memorized answer.

Common Mistakes

MistakeWhy it hurts
Studying only from pre-September materialYou will miss the governance and cloud emphasis
Treating governance as a small domainIt is reported at 17.3%, close to the largest domains
Assuming a 10% domain exists to skipThe old 10% domain is gone, and the new spread has no small domain
Memorizing AI details beyond recognition levelSources describe recognition, not engineering
Skipping adaptive test practiceYou cannot return to earlier questions
Trusting one article for exact percentagesConfirm weights on ISC2’s outline
Planning around a free examOne source says the free program closed on May 20, 2026
Forgetting the annual maintenance feeReported at $50 per year after passing

Career Value

CC is an entry-level credential that shows you understand security fundamentals. ISC2 describes it as requiring no work experience, which makes it a common first step for students, career changers and people in adjacent IT roles.

We have not included salary figures in this post. Entry-level security pay varies enormously by country, city and role, and we could not find a figure that separates people holding CC from everyone else in a similar job. If you want a wider view of what different security credentials can lead to, our best cybersecurity certifications ranking compares them by return on investment.

A practical view: CC will not replace hands-on experience, but it gives you a shared vocabulary and a signal that you took the basics seriously. The new governance and cloud content also makes it a more realistic preview of how modern security teams work.

What We Don’t Know Yet

Open questionWhy it matters
The official weights on ISC2’s pageWe rely on four third-party sources that agree with each other
The exact item count100 versus 100 to 125
Whether the free exam program has closedOne source says yes, as of May 20, 2026
Whether ISC2 will publish an official old-to-new crosswalkWould remove guesswork from the mapping
Whether candidates who failed under the old outline get any transition optionWe found no statement
How the pass rate changes under the new outlineNo data published
The body of ISC2’s August 2026 articleWe could read only its summary

FAQS

When did the ISC2 CC exam change?

The updated outline took effect on September 1, 2026, according to ISC2’s outline page.

What are the five domains of the updated CC exam?

Security Principles, Security Governance, Identity and Access Management Concepts, Networking and Cloud Security Concepts, and Security Operations and Incident Response.

What are the new domain weights?

Study-guide sites report 24%, 17.3%, 20%, 21.3% and 17.3% in that order. We could not read the weights on ISC2’s page, so confirm them in ISC2’s outline.

What changed the most?

Governance became its own domain at a reported 17.3%, cloud security and zero trust were folded into the networking domain, identity lifecycle was added, incident response moved into security operations, and AI concepts appear across all domains.

Is the CC exam harder now?

ISC2 has not published a difficulty rating or pass rate for the new outline. The weights are more even, so there is no longer a small domain you can skip, but that is not the same as saying the exam is harder.

How many questions are on the CC exam?

Most sources report 100 to 125 items in 2 hours using computerized adaptive testing. One source says 100.

What is the passing score?

700 out of 1,000, according to the sources we read.

How much does the CC exam cost?

One source reports $199 USD in most regions plus a $50 annual maintenance fee after passing. Check ISC2’s current pricing before you book.

Is the CC exam still free?

One source says the free exam and training program through ISC2’s One Million Certified in Cybersecurity effort closed to new enrollments on May 20, 2026. We could not confirm that from ISC2’s pages, so check before you rely on a free attempt.

Do I need experience to take CC?

No. ISC2 describes CC as entry level with no work experience required.

I studied the old outline. What should I add?

Four things: governance, cloud security and zero trust, identity lifecycle management, and AI concepts at a recognition level. Your fundamentals carry over.

How much AI do I need to know?

Recognition level. Sources describe identifying AI assets, recognizing automated threats and understanding the basics of governing emerging technology. They do not describe building or securing AI systems.

What should I take after CC?

It depends on your goal. For broader security leadership, look at CISSP or CISM. For cloud, look at CCSK or CCSP. For risk, look at CRISC. Our linked comparison guides cover each path.

Put this guide into practice

Practice the exams in this guide

Start with free exam-style questions and explanations, then move to the full practice set when you are ready.

About this guide

This article is intended to help readers make a practical certification or career decision. It was published on October 8, 2026. No external references are included in this article, so confirm time-sensitive policies, prices, and requirements directly with the relevant provider.

Report a correction or outdated detail

Reader discussion

Questions, context, or corrections?

Share a relevant question or point out a detail that may need another look. Comments are moderated for usefulness.

Leave a Comment

Your email address will not be published. Required fields are marked *


Continue exploring

View all IT Certification Comparisons
Scroll to Top