TL;DR: ISC2 updated its Certified in Cybersecurity (CC) exam outline effective September 1, 2026. ISC2’s outline page confirms the new date and lists five domains: Security Principles, Security Governance, Identity and Access Management (IAM) Concepts, Networking and Cloud Security Concepts, and Security Operations and Incident Response. The headline change is that governance became its own domain, and artificial intelligence topics now run through the whole outline. Several study-guide sites report the new weights as 24%, 17.3%, 20%, 21.3% and 17.3%, which flattens the old spread, where the biggest domain carried 26% and the smallest 10%. We could not read the weights on ISC2’s own page, so we label them as reported. The exam is adaptive, scored out of 1,000 with 700 to pass, and one source says the exam now costs $199. This guide compares the old and new outlines, lists what to relearn, gives a four to six week plan, and flags every place where sources disagree or ISC2 has not said.
If you started studying for CC before September, or you bought a course last spring, this is the post for you. The exam you will sit is not the exam your older notes describe.
Quick Facts
| Item | What the sources say |
| Exam | ISC2 Certified in Cybersecurity (CC) |
| Outline effective date | September 1, 2026 (stated on ISC2’s outline page) |
| Number of domains | 5 (named on ISC2’s outline page) |
| Reported new weights | Security Principles 24%, Security Governance 17.3%, IAM Concepts 20%, Networking and Cloud Security Concepts 21.3%, Security Operations and Incident Response 17.3% (reported by several study-guide sites) |
| Reported old weights | Security Principles 26%, Business Continuity, Disaster Recovery and Incident Response 10%, Access Controls Concepts 22%, Network Security 24%, Security Operations 18% |
| Format | Computerized adaptive testing (CAT), reported as 100 to 125 items in 2 hours |
| Passing score | 700 out of 1,000 (reported) |
| Reported fee | $199 USD in most regions, plus a $50 annual maintenance fee after passing |
| Experience required | None. ISC2 describes CC as entry level with no work experience required |
| Languages | Reported as English, Chinese, Japanese, German and Spanish |
Items marked “reported” come from third-party summaries we could not match to a page that ISC2 made readable. Check ISC2’s outline and exam pages for the final numbers before you pay.
What ISC2 Confirms, and What It Does Not
The most useful way to read this update is to split it into three buckets.
| Bucket | Items |
| Confirmed on ISC2’s outline page | Effective date of September 1, 2026. Five domains with the names listed above. AI woven through the outline |
| Reported consistently by several third-party sources | The new domain weights. The five-domain mapping from old to new. 700 out of 1,000 passing score. CAT format |
| Reported by only one source, or in conflict | Exact question count (100 versus 100 to 125). The free exam program closing on May 20, 2026. The direction of a few weight changes |
ISC2 also published an article in August 2026 titled “What’s New for Entry-Level Cybersecurity,” which describes the update as emphasizing governance, cloud security and threat intelligence. We could read its description but not its body, so we treat it as support for the direction of travel rather than a source for numbers.
Old Outline vs New Outline: The Gap Table
This is the part to print and tape to your monitor. It shows each old domain and where its content most likely went.
| Old domain (weight) | New domain (reported weight) | What this means |
| Security Principles (26%) | Security Principles (24%) | Still the foundation, with slightly less weight |
| Business Continuity, Disaster Recovery and Incident Response (10%) | Security Governance (17.3%) | The domain was replaced and renamed. Governance is now a standalone area, and incident response moved into Security Operations |
| Access Controls Concepts (22%) | Identity and Access Management Concepts (20%) | Renamed, with identity lifecycle topics added |
| Network Security (24%) | Networking and Cloud Security Concepts (21.3%) | Renamed, with cloud and zero trust folded in |
| Security Operations (18%) | Security Operations and Incident Response (17.3%) | Renamed, with incident response now inside it |
A note on the mapping. The old-to-new arrows in the middle column come from third-party analysis. ISC2’s outline page does not, in the content we could read, say which old domain maps to which new one. The names make the mapping reasonable, but treat it as an informed reading and not an official crosswalk.
The weight spread
| Measure | Old outline | New outline (reported) |
| Largest domain | 26% (Security Principles) | 24% (Security Principles) |
| Smallest domain | 10% (Business Continuity, Disaster Recovery and Incident Response) | 17.3% (Security Governance and Security Operations and Incident Response tie) |
| Gap between largest and smallest | 16 points | 6.7 points |
The practical meaning is simple. Under the old outline, you could treat the 10% domain as a small side topic. Under the new outline, no domain is small. Every domain carries at least 17.3% of the exam, so a weak area costs you more.
Domain by Domain: What to Relearn
The topic lists below come from third-party summaries of the updated outline. Where a topic could belong to more than one domain, we say so. Always cross-check against ISC2’s outline page.
Domain 1: Security Principles (reported 24%)
This remains the foundation: the confidentiality, integrity and availability triad, risk basics, and the principles that hold the rest of the exam together. Reported additions touch data protection, such as masking, sanitization and quantum-resistant cryptography, though sources do not all place them in this domain.
| Study move | Why |
| Re-read your notes on risk, controls and ethics | Still the heaviest domain |
| Add data protection basics | Masking and sanitization are reported in the updated content |
| Add a one-page summary of quantum-resistant cryptography at a recognition level | Reported as new. Expect recognition, not mathematics |
Domain 2: Security Governance (reported 17.3%)
This is the headline change. The old outline had no standalone governance domain, and one source says governance material was previously scattered across domains. The old domain closest in size (Business Continuity, Disaster Recovery and Incident Response) held 10%.
| Reported topic | What to know |
| Governance, risk and compliance frameworks | The purpose of policies, standards, procedures and frameworks, and how they relate |
| Compliance and regulations | Why organizations follow them, and what compliance proves |
| Business continuity and disaster recovery | Still relevant. Check where your study material places it |
| Governing emerging technology | One source says candidates must understand the basics of governing AI and other emerging technology |
If you studied only technical topics, this domain is the biggest hole in your preparation.
Domain 3: Identity and Access Management Concepts (reported 20%)
Access control remains core. The reported addition is identity lifecycle management.
| Reported topic | What to know |
| Provisioning and deprovisioning | Creating and removing access when people join and leave |
| Joiner, mover and leaver processes | What happens when someone changes roles |
| Authentication, authorization and accountability | The classic core, still testable |
| Least privilege and separation of duties | Standard principles that remain important |
Domain 4: Networking and Cloud Security Concepts (reported 21.3%)
Network security now includes cloud security. One source describes cloud security and zero trust as integrated into this domain.
| Reported topic | What to know |
| Shared responsibility model | Who secures what between provider and customer |
| Zero trust architecture | The idea of never trusting by default, and verifying every request |
| Micro-segmentation | Dividing a network into small zones to limit movement |
| Core networking | Still tested. Ports, protocols and common devices stay relevant |
Domain 5: Security Operations and Incident Response (reported 17.3%)
Incident response now sits with security operations, and several sources highlight threat-focused topics.
| Reported topic | What to know |
| Security event triage | Deciding which alerts matter |
| Incident response procedures | Detection, containment, eradication, recovery and lessons learned |
| Threat intelligence and threat actors | Who attacks and why, and how organizations use intelligence |
| Red, blue and purple team concepts | What each team does |
| Application security testing and threat modeling | Reported in the updated content |
AI Across the Whole Outline
ISC2’s outline page emphasizes AI integration throughout the certification, and every summary we read says the same thing: AI concepts appear across all five domains and not in a single chapter.
One source frames the level of knowledge well: the goal is recognition, not engineering. A CC candidate is not expected to build or secure AI systems. The reported expectations are modest.
| Expectation | What it means |
| Identify AI assets | Know that models, data and AI services are things an organization needs to protect |
| Recognize automated threats | Understand that attackers can automate attacks |
| Understand the basics of governing emerging technology | Know why policies for AI use matter |
The best way to prepare is to add one AI example to each domain in your notes. For instance, note one AI related governance issue, one AI related access control issue, and one AI related operations issue. That keeps the topic connected to the fundamentals.
Format and Cost
| Item | Report |
| Testing method | Computerized adaptive testing (CAT) |
| Items | 100 to 125 reported by most sources. One source says 100 |
| Time | 2 hours |
| Passing score | 700 out of 1,000 |
| Fee | $199 USD in most regions, plus a $50 annual maintenance fee after passing |
| One report on the free program | The earlier program that made the exam and training free through ISC2’s One Million Certified in Cybersecurity effort reportedly closed to new enrollments on May 20, 2026 |
Two cautions. First, the item count differs between sources, and adaptive exams commonly use a range, so 100 to 125 looks more likely than a flat 100. Second, the free program closure comes from one source. If you were counting on a free attempt, confirm with ISC2 before you plan.
A reminder about adaptive tests: the exam adjusts to your answers, so you cannot skip questions and return later. Practice answering one question at a time and moving on.
Where Sources Disagree
| Topic | One report | Another report |
| Question count | 100 | 100 to 125 |
| Direction of some weight changes | One summary describes IAM as “up from 22%” when 20% is lower | Others list it as a decrease |
| Whether weights are official | Study guide sites list exact figures | The ISC2 outline page, as we could read it, did not show weights |
| Mapping of old to new domains | Several sites present a clean old-to-new table | ISC2’s page does not present one in the content we could read |
For the weights, four independent sites printed the same numbers, which gives us reasonable confidence. It is still not the same as reading them on ISC2’s page. Before you build a study plan around exact percentages, check ISC2’s outline.
Who Should Take CC, and Who Should Skip It
| Your situation | Suggestion | Why |
| New to cybersecurity with no experience | CC is a sensible first step | ISC2 positions it as entry level with no work experience required |
| Switching careers from IT support | CC can work as a first credential, but compare it with other entry-level options | See our best cybersecurity certifications ranking |
| Already working in security with 2 or more years | You may want a higher credential | Look at CISSP vs CISM or CISSP vs CEH |
| Interested in cloud security | CC is a start, then consider a cloud credential | See CCSK vs CCSP and CCSP vs AWS Security Specialty |
| Interested in risk and governance | CC now has a governance domain, which is a taste of that path | See CRISC vs CISM |
| Student wanting a resume line | CC fits | The exam fee and annual maintenance fee are worth weighing |
If you already started studying, do not panic. The core ideas carry over. Most of your work is in four gaps, covered in the next section.
The Four Gaps: What Old-Outline Students Must Add
If you studied the previous outline, these are the topics most likely to be new or heavier.
| Gap | What to add | Time estimate |
| Governance | Frameworks, policies, compliance basics, continuity | The largest gap. Plan the most time here |
| Cloud and zero trust | Shared responsibility, zero trust, segmentation | A focused few sessions |
| Identity lifecycle | Provisioning, deprovisioning, joiner, mover, leaver | Short, but easy to forget |
| AI concepts | One AI example per domain | A light layer across your notes |
We deliberately do not give hour counts here. Study time depends on your background, and a made-up number would be false precision.
A Four to Six Week Study Plan
This plan assumes you are starting from scratch or refreshing older notes.
| Week | Focus | Goal |
| 1 | Security Principles | Master the triad, risk, controls and ethics. Add data protection basics |
| 2 | Security Governance | Learn policy hierarchy, frameworks, compliance and continuity |
| 3 | IAM Concepts and Networking and Cloud Security | Authentication, authorization, lifecycle, shared responsibility, zero trust |
| 4 | Security Operations and Incident Response | Triage, response steps, threat intelligence, team colors |
| 5 | Practice questions, one question at a time | Build adaptive test habits. Review every miss |
| 6 | Weak spots and rest | Revisit the lowest scoring domain. Book the exam |
If you have only four weeks, combine weeks 5 and 6, and keep the governance week intact. If you want extra practice, the CC practice questions page can supplement your own notes, as long as you check each topic against ISC2’s current outline.
Five practice prompts built from the new outline
These are study prompts, not real exam questions. Answer them from memory, then check your notes.
| # | Prompt | Domain it touches |
| 1 | Explain the difference between a policy, a standard and a procedure, and give one example of each | Security Governance |
| 2 | An employee changes departments. List what should happen to their access, and name the process | IAM Concepts |
| 3 | A company moves a server to a cloud provider. State who is responsible for the operating system patches, and why this matters | Networking and Cloud Security Concepts |
| 4 | A security tool raises 40 alerts. Describe how you would decide which to look at first | Security Operations and Incident Response |
| 5 | A team wants to use an AI tool with customer data. List two governance questions to ask first | Security Governance and Security Principles |
Prompt 3 depends on the model your provider uses, so the point is the reasoning about shared responsibility and not a single memorized answer.
Common Mistakes
| Mistake | Why it hurts |
| Studying only from pre-September material | You will miss the governance and cloud emphasis |
| Treating governance as a small domain | It is reported at 17.3%, close to the largest domains |
| Assuming a 10% domain exists to skip | The old 10% domain is gone, and the new spread has no small domain |
| Memorizing AI details beyond recognition level | Sources describe recognition, not engineering |
| Skipping adaptive test practice | You cannot return to earlier questions |
| Trusting one article for exact percentages | Confirm weights on ISC2’s outline |
| Planning around a free exam | One source says the free program closed on May 20, 2026 |
| Forgetting the annual maintenance fee | Reported at $50 per year after passing |
Career Value
CC is an entry-level credential that shows you understand security fundamentals. ISC2 describes it as requiring no work experience, which makes it a common first step for students, career changers and people in adjacent IT roles.
We have not included salary figures in this post. Entry-level security pay varies enormously by country, city and role, and we could not find a figure that separates people holding CC from everyone else in a similar job. If you want a wider view of what different security credentials can lead to, our best cybersecurity certifications ranking compares them by return on investment.
A practical view: CC will not replace hands-on experience, but it gives you a shared vocabulary and a signal that you took the basics seriously. The new governance and cloud content also makes it a more realistic preview of how modern security teams work.
What We Don’t Know Yet
| Open question | Why it matters |
| The official weights on ISC2’s page | We rely on four third-party sources that agree with each other |
| The exact item count | 100 versus 100 to 125 |
| Whether the free exam program has closed | One source says yes, as of May 20, 2026 |
| Whether ISC2 will publish an official old-to-new crosswalk | Would remove guesswork from the mapping |
| Whether candidates who failed under the old outline get any transition option | We found no statement |
| How the pass rate changes under the new outline | No data published |
| The body of ISC2’s August 2026 article | We could read only its summary |
FAQS
When did the ISC2 CC exam change?
The updated outline took effect on September 1, 2026, according to ISC2’s outline page.
What are the five domains of the updated CC exam?
Security Principles, Security Governance, Identity and Access Management Concepts, Networking and Cloud Security Concepts, and Security Operations and Incident Response.
What are the new domain weights?
Study-guide sites report 24%, 17.3%, 20%, 21.3% and 17.3% in that order. We could not read the weights on ISC2’s page, so confirm them in ISC2’s outline.
What changed the most?
Governance became its own domain at a reported 17.3%, cloud security and zero trust were folded into the networking domain, identity lifecycle was added, incident response moved into security operations, and AI concepts appear across all domains.
Is the CC exam harder now?
ISC2 has not published a difficulty rating or pass rate for the new outline. The weights are more even, so there is no longer a small domain you can skip, but that is not the same as saying the exam is harder.
How many questions are on the CC exam?
Most sources report 100 to 125 items in 2 hours using computerized adaptive testing. One source says 100.
What is the passing score?
700 out of 1,000, according to the sources we read.
How much does the CC exam cost?
One source reports $199 USD in most regions plus a $50 annual maintenance fee after passing. Check ISC2’s current pricing before you book.
Is the CC exam still free?
One source says the free exam and training program through ISC2’s One Million Certified in Cybersecurity effort closed to new enrollments on May 20, 2026. We could not confirm that from ISC2’s pages, so check before you rely on a free attempt.
Do I need experience to take CC?
No. ISC2 describes CC as entry level with no work experience required.
I studied the old outline. What should I add?
Four things: governance, cloud security and zero trust, identity lifecycle management, and AI concepts at a recognition level. Your fundamentals carry over.
How much AI do I need to know?
Recognition level. Sources describe identifying AI assets, recognizing automated threats and understanding the basics of governing emerging technology. They do not describe building or securing AI systems.
What should I take after CC?
It depends on your goal. For broader security leadership, look at CISSP or CISM. For cloud, look at CCSK or CCSP. For risk, look at CRISC. Our linked comparison guides cover each path.



