Official details for Certified in Cybersecurity (CC) Certification as published by the certification body.
The Certified in Cybersecurity (CC) certification exam is one of the fastest-growing entry level cybersecurity certification options for aspiring security professionals. Developed by ISC2, the organization behind globally recognized certifications such as CISSP, the certification provides a strong foundation for individuals entering the cybersecurity field.
The official ISC2 Certified in Cybersecurity exam consists of 100 multiple-choice questions, lasts 120 minutes, requires a passing scaled score of 700 out of 1000, and costs approximately $199 USD in most regions. The examination is delivered through Pearson VUE testing centers worldwide and is available in multiple languages depending on regional availability.
The certification is specifically designed for beginners, career changers, students, IT professionals moving into security roles, and individuals seeking an internationally recognized cybersecurity certification.
The Certified in Cybersecurity certification validates foundational cybersecurity knowledge and practical understanding of key security concepts required in modern organizations.
Unlike advanced cybersecurity certifications that require years of experience, the ISC2 CC certification was developed to remove entry barriers and help organizations build their cybersecurity workforce.
The certification focuses on five core domains:
• Security Principles
• Business Continuity, Disaster Recovery, and Incident Response
• Access Controls Concepts
• Network Security
• Security Operations
These domains cover the essential knowledge required by security analysts, junior security engineers, SOC analysts, compliance specialists, and IT support professionals.
Certification Detail | Information |
|---|---|
Exam Name | Certified in Cybersecurity |
Exam Code | CC |
Provider | ISC2 |
Primary Keyword | Certified in Cybersecurity |
Cost | Approximately $199 USD |
Exam Duration | 120 Minutes |
Passing Score | 700 out of 1000 |
Number of Questions | 100 |
Question Format | Multiple Choice |
Delivery Method | Pearson VUE Testing Centers |
Certification Level | Entry Level |
Languages Available | English and selected regional languages |
Experience Requirement | No mandatory experience |
Renewal Cycle | Three Years |
Cybersecurity talent shortages continue to grow globally. Organizations across industries require professionals capable of understanding security fundamentals and supporting security operations.
The Certified in Cybersecurity certification offers several benefits:
• Globally recognized credential from ISC2.
• Strong foundation for advanced cybersecurity certifications.
• Demonstrates commitment to cybersecurity careers.
• Validates practical understanding of security concepts.
• Enhances employability for entry-level security positions.
• Helps candidates transition from IT support into cybersecurity roles.
Employers increasingly value vendor-neutral certifications because they validate broad cybersecurity knowledge rather than expertise with a single technology platform.
Candidates preparing for the Certified in Cybersecurity exam are expected to understand:
• Confidentiality, integrity, and availability principles.
• Governance, risk, and compliance concepts.
• Security awareness practices.
• Security controls and safeguards.
• Incident response processes.
• Business continuity planning.
• Disaster recovery procedures.
• Authentication methods.
• Authorization concepts.
• Identity management fundamentals.
• Network security technologies.
• Security monitoring operations.
• Threat identification techniques.
• Security event analysis.
• Security operations processes.
Security principles represent the largest domain within the exam blueprint.
Topics include:
• CIA triad.
• Security governance.
• Risk management fundamentals.
• Security policies and standards.
• Compliance requirements.
• Data classification.
• Privacy principles.
• Physical security controls.
Candidates should understand how organizations implement policies and controls to reduce cybersecurity risks.
This domain evaluates understanding of organizational resilience.
Objectives include:
• Business continuity planning.
• Disaster recovery planning.
• Recovery objectives.
• Incident response lifecycle.
• Incident handling procedures.
• Communication planning.
• Crisis management.
• Backup strategies.
• Recovery testing.
Candidates should understand the differences between continuity planning and incident response activities.
Access management remains one of the most important areas of cybersecurity.
Topics include:
• Authentication methods.
• Authorization models.
• Access control models.
• Multifactor authentication.
• Single sign-on.
• Role-based access control.
• Principle of least privilege.
• Identity lifecycle management.
• Account provisioning.
This domain is frequently tested in the certification exam.
Network security objectives focus on securing communications and infrastructure.
Topics include:
• Network architecture concepts.
• Firewalls.
• Intrusion detection systems.
• Intrusion prevention systems.
• VPN technologies.
• Network segmentation.
• Wireless security.
• Secure communication protocols.
• Secure network design.
Candidates should understand the role each technology plays within enterprise security.
Security operations focuses on maintaining secure environments.
Objectives include:
• Security monitoring.
• Log analysis.
• Vulnerability management.
• Security awareness programs.
• Asset management.
• Patch management.
• Threat intelligence.
• Security investigations.
• Security reporting.
This domain introduces concepts commonly used by SOC analysts.
Domain | Weight |
Security Principles | 26% |
Business Continuity, Disaster Recovery and Incident Response Concepts | 10% |
Access Controls Concepts | 22% |
Network Security | 24% |
Security Operations | 18% |
One of the biggest advantages of the ISC2 Certified in Cybersecurity certification is the absence of formal prerequisites.
Candidates do not need:
• Professional experience.
• College degrees.
• Prior certifications.
• Technical backgrounds.
This makes it ideal for:
• Students.
• Career changers.
• Recent graduates.
• Military veterans.
• Help desk professionals.
• Network administrators.
• System administrators.
Although not required, candidates benefit from:
• Basic computer literacy.
• Understanding of operating systems.
• Familiarity with networking concepts.
• Exposure to cloud computing concepts.
• Interest in cybersecurity topics.
Even individuals with no technical background can successfully pass the exam with proper preparation.
The certification opens doors to numerous entry-level roles including:
• Security Analyst.
• SOC Analyst.
• Security Operations Associate.
• Junior Information Security Analyst.
• IT Security Support Specialist.
• Cybersecurity Technician.
• Compliance Analyst.
• Governance Risk and Compliance Associate.
• Security Administrator.
• Information Assurance Specialist.
Organizations increasingly use the certification as an entry requirement for junior security positions.
Salary varies based on geography, industry, and experience.
Typical salary ranges include:
Entry-Level Security Analyst:
$55,000 to $80,000 annually.
SOC Analyst:
$60,000 to $90,000 annually.
Cybersecurity Specialist:
$70,000 to $100,000 annually.
Security Administrator:
$65,000 to $95,000 annually.
Professionals who combine the CC certification with hands-on experience often progress quickly toward advanced positions.
The ISC2 Certified in Cybersecurity credential remains valid for three years.
To maintain certification, professionals must:
• Earn Continuing Professional Education credits.
• Pay annual maintenance fees.
• Maintain ISC2 membership status.
Continuing education ensures professionals remain current with evolving threats and technologies.
The registration process includes:
Create an ISC2 account.
Purchase the exam voucher.
Select a Pearson VUE testing center.
Choose an available exam date.
Review identification requirements.
Complete the exam appointment.
Arrive at the testing center early.
Candidates should verify testing policies before exam day.
Recommended preparation resources include:
• Official ISC2 study materials.
• Exam outline documents.
• Practice assessments.
• Cybersecurity labs.
• Flashcards.
• Video learning resources.
• Study groups.
• Community discussion forums.
• Hands-on projects.
Combining theoretical learning with practical experience significantly improves exam readiness.
A proven preparation strategy includes:
Week 1:
Learn security principles.
Week 2:
Study business continuity and incident response.
Week 3:
Master access control concepts.
Week 4:
Review network security technologies.
Week 5:
Study security operations.
Week 6:
Take practice tests and identify weak areas.
Week 7:
Review objectives and terminology.
Week 8:
Complete final revision and exam simulations.
Consistency is more effective than intensive last-minute study sessions.
Candidates commonly struggle with:
• Memorizing access control models.
• Understanding recovery metrics.
• Differentiating IDS and IPS technologies.
• Understanding governance terminology.
• Learning risk management concepts.
• Interpreting security operations scenarios.
Focused revision can significantly improve performance in these areas.
Based on candidate feedback and exam objectives, frequently tested topics include:
• CIA triad.
• Risk management.
• Multifactor authentication.
• Least privilege.
• Role-based access control.
• Business continuity.
• Disaster recovery.
• Incident response lifecycle.
• Firewalls.
• IDS and IPS technologies.
• VPN concepts.
• Security monitoring.
• Vulnerability management.
• Data classification.
• Security awareness.
Successful candidates often follow these strategies:
• Arrive 30 minutes early.
• Bring valid identification.
• Read every question carefully.
• Eliminate incorrect answers first.
• Manage time effectively.
• Avoid spending too long on difficult questions.
• Review flagged questions before submission.
• Stay calm throughout the exam.
After earning the Certified in Cybersecurity certification, candidates frequently pursue:
• Systems Security Certified Practitioner (SSCP)
• Certified Information Systems Security Professional (CISSP)
• CompTIA Security+
• Certified Ethical Hacker (CEH)
• CompTIA CySA+
• Certified Cloud Security Professional (CCSP)
These certifications support progression toward specialized cybersecurity roles.
ISC2 continues to update exam objectives to reflect evolving cybersecurity threats and technologies.
Recent focus areas include:
• Cloud security fundamentals.
• Security operations center processes.
• Identity management improvements.
• Emerging threat landscapes.
• Security governance enhancements.
Candidates should always review the latest official exam outline before scheduling their examination.
A typical career progression path includes:
Certified in Cybersecurity
Security Analyst
SOC Analyst
Security Engineer
Senior Security Engineer
Security Architect
Security Manager
Chief Information Security Officer
The certification serves as the first step in long-term cybersecurity career development.
Global cybersecurity spending continues to increase as organizations face rising cyber threats.
Industries actively recruiting certified professionals include:
• Financial services.
• Healthcare.
• Government.
• Retail.
• Manufacturing.
• Technology companies.
• Consulting organizations.
Cybersecurity remains one of the fastest-growing technology sectors worldwide.
Certified professionals contribute to:
• Monitoring security alerts.
• Responding to incidents.
• Managing user access.
• Performing compliance activities.
• Conducting vulnerability assessments.
• Supporting audits.
• Maintaining security documentation.
• Implementing security controls.
These activities form the foundation of enterprise security operations.
Employers increasingly seek candidates with certifications even for entry-level roles.
Current hiring trends emphasize:
• Practical skills.
• Security awareness.
• Incident response knowledge.
• Cloud security understanding.
• Governance knowledge.
• Communication abilities.
The Certified in Cybersecurity credential demonstrates readiness for these expectations.
Certification | Level | Vendor Neutral | Experience Required |
ISC2 Certified in Cybersecurity | Entry | Yes | No |
CompTIA Security+ | Entry | Yes | Recommended |
SSCP | Intermediate | Yes | One Year |
CISSP | Advanced | Yes | Five Years |
The ISC2 CC certification offers one of the lowest barriers to entry among globally recognized cybersecurity certifications.
Many professionals have used the certification to:
• Transition from help desk to security roles.
• Move from networking into cybersecurity.
• Enter cybersecurity after university graduation.
• Secure internships.
• Obtain junior analyst positions.
• Begin security consulting careers.
The certification has become a popular pathway into the cybersecurity industry.
The Certified in Cybersecurity certification from ISC2 represents one of the best options for professionals seeking an entry level cybersecurity certification. The certification validates foundational knowledge in security principles, access controls, network security, incident response, and security operations.
For candidates searching for a globally recognized cybersecurity certification exam that does not require previous experience, the Certified in Cybersecurity credential offers an excellent starting point and creates a strong foundation for future certifications and career growth.
Same exams as Featured on home
Explore exam
Explore exam