ISC2 Certified in Cybersecurity (CC)
Every other certification on this page assumes you already have something — a cloud account to click around in, a Kubernetes cluster to break, or in CISSP's case, five years of paid security work before you're even allowed to sit the exam unconditionally. The ISC2 Certified in Cybersecurity (CC) assumes none of that. It's ISC2's deliberately entry-level credential: no required experience of any kind, a five-domain outline that covers security vocabulary and fundamentals rather than any one tool or platform, and — for a stretch of its history — a promotion that made the official training and the exam itself free. This page covers what CC actually tests, what that promotion currently offers, and where CC fits if you're arriving at this course with no security background at all.
Imagine a swimming pool with a shallow end and a deep end. CISSP and CISM are the deep end — a lifeguard checks your logbook for years of practice before letting you in. CC is the shallow end, and there's no lifeguard checking anything: anyone can wade in today, learn to float, and use that as the base for swimming further out later. It was never meant to be the deep end. It's meant to get your feet wet, cheaply and honestly.
What CC is, and who it's actually for
☺ Like you're 10: This is the badge you can go earn today, with zero background, that isn't a scam — the honest, cheap starting line.
ISC2 launched Certified in Cybersecurity in 2022 as a direct response to its own long-running workforce studies, which have reported a global cybersecurity staffing gap in the millions of unfilled roles for years running. Where CISSP and CISM are built for people already deep in a security career, CC is built for people who aren't in one yet: students, career changers, IT generalists moving toward security, help-desk and sysadmin staff who need a credential their résumé can point to, and — frankly — anyone who wants to know whether security is a field worth pursuing before committing years to it. There is no minimum education, no minimum work history, and no sponsor or endorsement required to sit the exam. You register, you study, you take it.
That "no experience" detail matters more than it looks. ISC2's other certifications — CISSP, CISM's cousin at ISACA, CSSLP, CGRC — all gate full certification behind years of relevant work experience; pass the exam early and you become an "Associate of ISC2" while a clock runs toward full certification. CC has no such clock. Pass the exam and you are fully Certified in Cybersecurity that day, no waiting period, no experience to backfill later. It's the one ISC2 credential where "entry-level" is a literal, enforced fact of the program rather than a marketing description.
What it is not: a hands-on credential. Like CISSP, CC is entirely multiple-choice, testing recall and applied judgment against scenarios rather than grading you on a live terminal or a broken cluster. It doesn't touch pipeline security, SAST/DAST tooling, or anything specific to this course's CDP — it's general IT-security literacy: the vocabulary and mental models that let a newcomer read a security requirement, a job posting, or a page on this site without needing every term defined first.
CC doesn't compete with anything else on this page — it sits underneath all of it. Think of it less as "which certification should I get" and more as "what's the cheapest legitimate way to stop being a total beginner," so that CISSP, CISM, Security+, or this course's own hands-on material all land on some existing foundation instead of none.
The five domains and their weights
☺ Like you're 10: Five topics make up the whole exam, and none of them is a tool or a product — they're the ideas underneath every tool.
The domain weights below come from ISC2's published CC Exam Outline. As with every certification profiled on this site, treat the exact percentages as directional and confirm the current outline PDF before building a study plan around them — ISC2 has revised domain weights on other certifications before, and there's no reason to assume CC's are permanently fixed either.
Reordered by weight rather than by the outline's own numbering, the shape is still fairly even — nothing here dominates the way Troubleshooting dominates the CKA. Roughly what each domain covers:
- Security Principles (26%) — the CIA triad, risk terminology, governance basics, ethics, and the ISC2 Code of Ethics itself, which the exam expects you to have read.
- Network Security (24%) — network architecture and topology fundamentals, common threats and attacks, and the standard defenses (firewalls, VPNs, segmentation) at a conceptual level.
- Access Controls Concepts (22%) — authentication vs. authorization, physical vs. logical access control, and the standard access-control models (DAC, MAC, RBAC).
- Security Operations (18%) — data handling, security awareness training, logging and monitoring basics, encryption fundamentals, and configuration management.
- BC, DR & Incident Response Concepts (10%) — the vocabulary distinguishing business continuity, disaster recovery, and incident response, plus basic incident-handling steps.
Notice what's absent from all five: no domain names a specific SIEM, cloud provider, or scripting language. That's by design — CC is testing whether you'd recognize these ideas in the wild, not whether you can configure any particular product.
The exam-fee promotion — and what to verify before you count on it
☺ Like you're 10: For a while, ISC2 gave this one away for free to get a million new people into the field — but "for a while" is doing a lot of work in that sentence.
In April 2022, ISC2 launched the "One Million Certified in Cybersecurity" pledge: free access to the official self-paced CC training course, plus a single free exam voucher, offered to newcomers worldwide on a first-come, first-served basis, with the explicit goal of certifying a million people and putting a dent in ISC2's own reported workforce gap. It was popular well beyond ISC2's own projections, and the company extended the pledge's window more than once rather than let it lapse on the original schedule — which is exactly the pattern worth internalizing here: this is a promotional program, not a permanent price, and its terms have already changed since launch.
Do not assume the free-voucher pledge is still open, still first-come-first-served, still bundled with free training, or still shaped the way it was described above. Go to ISC2's own Certified in Cybersecurity page and confirm the current status directly before you register for anything or tell someone else it's free — this is one of the specific facts on this page most likely to be stale by the time you're reading it. If the promotion isn't running, or you don't qualify, the standalone exam has historically been list-priced around USD $199 — still the cheapest exam fee of any certification on this page by a wide margin, promotion or not.
Either way, the underlying economics are worth keeping straight: even at full list price, CC costs roughly a quarter of what CISSP costs to sit, with zero experience required to unlock it. The free-voucher pledge, when it's running, is a bonus on top of an already cheap entry point — not the only reason CC is worth considering.
Format, prerequisites, and the price tag — before and after you pass
☺ Like you're 10: Passing the exam is only step one — like every ISC2 badge, staying certified means keeping your membership current every year after.
The details below are what ISC2 generally publishes and what candidates consistently report. As with every certification page on this site, treat this as planning information, not something to quote back at anyone — question counts, fees, and membership requirements have all changed on ISC2's certifications before, CC included.
| Item | What is generally published |
|---|---|
| Format | Multiple choice, computer-based, delivered via Pearson VUE (test center or online proctored) |
| Question count | 100 questions |
| Duration | 2 hours |
| Passing score | A scaled score of 700 out of 1000 — the same scale CISSP uses |
| Prerequisites | None. No experience, no endorsement, no sponsor — the point of the credential |
| Price (list, when not promotional) | Historically around USD $199; regional pricing is common |
| Certification on passing | Immediate — no "Associate" holding pattern, unlike CISSP, CISM, or CSSLP |
| Ongoing membership | An Annual Maintenance Fee (AMF) — historically well below CISSP's, reflecting the entry-level tier — plus adherence to the ISC2 Code of Ethics |
| Continuing education | Annual Continuing Professional Education (CPE) credits, on a lighter cadence than CISSP's; ISC2 publishes the exact annual and 3-year totals |
The membership piece is the part people miss: passing the exam gets you certified, but staying certified — like every ISC2 credential — means paying the AMF and logging CPEs every year after, or the certification lapses. It's a real, recurring, if modest, cost of holding the badge long-term, not a one-time fee you pay once and forget. Confirm the current AMF amount and CPE totals on ISC2's own CC page before you commit — these numbers move with ISC2's broader membership pricing, not on any schedule tied to this site.
↗ ISC2 official Certified in Cybersecurity page
Where it overlaps this course, CISSP, and Security+ — and where it doesn't
☺ Like you're 10: It shares almost no territory with this course's hands-on material — but it's a genuinely useful ladder rung underneath the certifications that do.
CC's overlap with this course's own material is thin, honestly — the same way CISSP's is. Its five domains are general IT-security fundamentals, not pipeline security; nothing in CC touches SAST, SCA, container signing, or policy-as-code. Where it earns its place on this page is as groundwork: the vocabulary CC teaches — access control models, network-security basics, the CIA triad — is exactly the vocabulary this course's foundations material assumes you already have on day one.
| ISC2 CC | CompTIA Security+ | This course's CDP | |
|---|---|---|---|
| Experience required | None | None required (CompTIA recommends ~2 years IT admin experience with a security focus, but doesn't enforce it) | None required, but assumes pipeline/CI-CD familiarity |
| Format | Multiple choice | Multiple choice + performance-based simulation items | Performance-based, live environment |
| Scope | General security fundamentals, 5 domains | Broader general security, 5 domains, includes some governance and cryptography depth CC doesn't | Narrow and deep — pipeline security tooling specifically |
| List price (approx.) | $199 | ~$392 | See the CDP exam guide |
| DoD 8570/8140 recognition | Not on the approved baseline | Yes, at multiple IAT/IAM levels | Not applicable — vendor-neutral site credential |
| Best next step | Security+, or straight into this course's foundations | CISSP or CISM once experience accrues | Deeper pipeline specialization — CKS, cloud security certs |
Security+ is CC's closest sibling and its natural next step for anyone who wants one more general-security credential — broader in places, DoD 8570/8140-recognized where CC currently is not, and pricier — but it still isn't pipeline-specific, so it doesn't replace anything in this course either. And CISSP already names CC directly as its own recommended starting point for readers without the five years of experience CISSP demands: this page is that pointer's destination.
Who should sit it, and what to do next
☺ Like you're 10: If you're starting from zero, this is worth your time and $199. If you're not starting from zero, it probably isn't.
Sit CC if you genuinely have no security background and want a structured, honest, inexpensive way to acquire the field's basic vocabulary before tackling anything harder — this course's own foundations included. It's also a reasonable move if you're aiming at CISSP or CISM eventually but don't yet have the five years of experience either demands: CC gives you a credential to hold and a curriculum to learn from while that clock runs, rather than nothing at all. Students and career changers are exactly who ISC2 built this for.
Skip it, without any guilt, if you already hold Security+ or have hands-on IT/security experience — CC's five domains will feel like a review of things you already know, and your time is better spent going straight at this course's CDP or a more specific credential like CKS or one of the cloud security-engineer certs profiled elsewhere on this page. CC is a floor. If you're already standing well above it, there's no need to walk back down to it.
Foxy: Free training, free exam, no experience needed — what's the catch?
Professor Owl: No catch on the content — but "free" was a limited-time pledge, not the permanent price. Confirm today's terms before you assume anything.
Master Panda: And even at full price, it's a fraction of what CISSP costs. Cheap either way — that's the actual point, not just "free."
Timmy the Turtle: Does it get you anywhere near this course's material, though? SAST gates, secrets scanning?
Professor Owl: Barely. It's vocabulary, not pipeline skill. It's the floor everything else in this course assumes you're already standing on.
Remy the Rabbit: So it's basically a warm-up round for the flashcards.
Master Panda: A calm, honest one. Finish it properly before you chase the next five badges.
1. What's the single biggest structural difference between CC and CISSP in terms of who is eligible to sit each exam? 2. What happened to CC's "One Million Certified in Cybersecurity" pledge after it launched in April 2022, and what does that history tell you about trusting its current terms? 3. Name the five CC domains from largest to smallest weight. 4. What does a candidate become immediately upon passing CC, and how does that differ from passing CISSP without the required experience? 5. If someone already holds Security+, is CC still a good use of their time — and why or why not?
Check your answers
- CC has no experience requirement at all — anyone can sit it. CISSP requires five years of paid experience across two or more of its eight domains to certify unconditionally.
- It was extended beyond its original window because uptake outpaced ISC2's plans. The lesson is that this is a promotional program whose terms have already changed at least once, so its current status must be verified directly on ISC2's own page rather than assumed from anything written here.
- Security Principles (26%), Network Security (24%), Access Controls Concepts (22%), Security Operations (18%), BC, DR & Incident Response Concepts (10%).
- A candidate who passes CC is fully certified immediately, with no waiting period. A candidate who passes CISSP without the experience requirement becomes an Associate of ISC2 and has up to six years to complete the experience and convert to full CISSP.
- Generally not a strong use of time — Security+ already covers similar general-security ground at comparable or greater depth, so CC's five domains would mostly be review. Time is better spent moving toward a more specific or advanced credential.