September 2026 outline

This hub follows the CC exam outline effective September 1, 2026

ISC2 is changing the Certified in Cybersecurity exam outline on September 1, 2026. This hub uses the revised five-domain structure and weights. If your exam is scheduled before that date, use ISC2's current outline instead.

At a glance

What ISC2 CC covers

Certified in Cybersecurity (CC) is an entry-level ISC2 certification for people building foundational cybersecurity knowledge. ISC2 does not require prior cybersecurity work experience or a formal degree, although basic information technology knowledge is recommended.

The September 2026 outline expands the foundation across security principles, governance, identity and access management, networking and cloud security, and security operations and incident response.

Delivery

Computerized adaptive testing (CAT)

Exam time

2 hours

Items

100 to 125

Passing score

700 out of 1000

Item format

Multiple choice and advanced item types

2026 exam update

The revised CC outline begins September 1, 2026

ISC2 states that CC exams delivered on or after September 1, 2026 use a revised outline. The revised version keeps five domains but changes their names, scope, and weights.

CertHappens CC resources follow that revised outline rather than reorganizing material written for the outgoing version.

Effective date

September 1, 2026

Domains

5

Numbered objectives

19

Candidate fit

Who ISC2 CC is built for

CC is designed for newcomers who want to demonstrate foundational knowledge for an entry- or junior-level cybersecurity role. It can fit students, career changers, IT professionals moving toward security, and learners who want a security-first starting point.

No work experience is required, but the exam still uses real security and technology concepts. Basic familiarity with computers, accounts, networks, applications, and common IT terminology gives the material useful context.

Signals that CC may fit your starting point
  • Cybersecurity is new to you, but basic IT concepts are becoming familiar.
  • You want an entry-level security certification without a work-experience prerequisite.
  • You want to build security vocabulary and reasoning before moving into broader or more advanced certifications.
  • You want a structured foundation spanning governance, identity, networking, cloud security, operations, and incident response.

Building on a foundation

How CC turns basic IT knowledge into security reasoning

ISC2 recommends basic IT knowledge but does not require professional experience. CC builds on ordinary technology concepts by asking what they mean for protection, access, resilience, and response.

Accounts and permissions

Basic IT context: Recognize users, accounts, groups, roles, and permissions in common systems.

ISC2 CC perspective: Connect identity provisioning, review, deprovisioning, least privilege, separation of duties, and access-control models to security outcomes.

Networks and cloud services

Basic IT context: Understand basic network connectivity, addresses, protocols, applications, wireless access, and hosted services.

ISC2 CC perspective: Connect network models, firewalls, segmentation, zero trust, wireless, cloud models, and shared responsibility to security design.

Operations

Basic IT context: Recognize logs, updates, configuration changes, backups, alerts, and routine system administration.

ISC2 CC perspective: Use logging, event triage, threat information, incident response, change management, and security testing as parts of an operating security program.

Governance and resilience

Basic IT context: Understand that organizations use policies, procedures, roles, reporting, and recovery plans to manage technology.

ISC2 CC perspective: Connect risk, governance, compliance, business continuity, disaster recovery, awareness, and effectiveness measures to organizational security.

Official scope

Five CC domains effective September 1, 2026

Weights are the average domain weights published by ISC2 for the revised CC outline.

Domain 1 · 24%

Security Principles

Cybersecurity concepts, risk management, governance concepts, technical, administrative, and physical controls, and professional and ethical conduct.

Open Domain 1 guide

Domain 2 · 17.3%

Security Governance

Governance, risk, and compliance planning, business continuity and disaster recovery, security awareness, and measures of cybersecurity effectiveness.

Open Domain 2 guide

Domain 3 · 20%

Identity And Access Management (IAM) Concepts

Identity lifecycle management, provisioning and deprovisioning, least privilege, separation of duties, and access-control models.

Open Domain 3 guide

Domain 4 · 21.3%

Networking and Cloud Security Concepts

Network fundamentals, firewalls, wireless and embedded systems, segmentation, defense in depth, zero trust, cloud models, and shared security responsibilities.

Open Domain 4 guide

Domain 5 · 17.3%

Security Operations and Incident Response

Data security, cryptography, monitoring and triage, threat information, incident response, asset protection, change management, and security testing.

Open Domain 5 guide

Starting point

Experience and certification path

ISC2 lists no specific prerequisites for the CC exam. Basic information technology knowledge is recommended, but cybersecurity work experience and a formal educational degree are not required.

That makes CC a practical first security credential rather than a certification that assumes an established security career. Later certification choices can depend on the work you begin doing and the areas of security you decide to deepen.

Exam policies and certification requirements can change, so confirm current registration and membership details with ISC2 before scheduling.

Exam prerequisites

None specified

Cybersecurity work experience

Not required

Recommended background

Basic IT knowledge

Study approach

A practical preparation sequence

Step 1

Start with the September 2026 outline

Use the five domains and nineteen numbered objectives as the study checklist so older CC material does not quietly steer you toward the outgoing outline.

Step 2

Fill basic IT vocabulary gaps early

Make sure accounts, permissions, IP addressing, ports, applications, wireless networks, cloud services, logs, updates, and configuration changes are not all new at once.

Step 3

Learn distinctions that drive decisions

Separate authentication from authorization and accounting, business continuity from disaster recovery, least privilege from separation of duties, and preventive controls from detective or corrective ones.

Step 4

Connect network and cloud concepts to security

Do not stop at definitions. Practice explaining why segmentation, firewalls, zero trust, shared responsibility, and secure wireless or embedded-system choices reduce specific risks.

Step 5

Practice explaining why alternatives are weaker

For each scenario, identify the requirement first, choose the control or action that best fits it, and review why plausible alternatives do not satisfy the same need.

Study resources

ISC2 CC practice and study resources

Practice with the September 2026 question bank, then use the study guide, quick reviews, acronym reference, and certification comparison to strengthen weak areas.

ISC2 CC quick review guides

Review high-value distinctions across principles, governance, identity, network trust, cloud security, operations, and incident response.

Open isc2 cc quick review guides

ISC2 CC acronyms and terms

Search key abbreviations and terms from the September 2026 outline, with plain-English meanings and domain context.

Open isc2 cc acronyms and terms

Security+ or ISC2 CC

Compare the two certifications by starting point, breadth, and technical context.

Open security+ or isc2 cc

Confirm current requirements with ISC2

The exam outline, delivery details, policies, and certification requirements can change. Check the official ISC2 sources before making registration decisions.

CertHappens is an independent study resource and is not affiliated with or endorsed by ISC2.