Upcoming exam facts, effective September 1, 2026
The official upcoming outline identifies the credential as Certified in Cybersecurity. It lists two hours, 100–125 items, multiple-choice and advanced item types, a passing grade of 700 out of 1000, and Pearson VUE testing. It says CC uses Computerized Adaptive Testing for the listed languages. In CAT, candidates should focus on each presented item and pacing rather than expecting a fixed 100-item linear form.
The outline states there are no specific prerequisites. No cybersecurity work experience or formal educational degree is required, while basic IT knowledge is recommended. That makes the credential accessible, not trivial: the new outline expects conceptual distinctions across governance, IAM, cloud, operations, incident response, and testing.
The 12/9/10/11/8 allocation is an exact 50-question approximation. It follows the relative official emphasis but is not an official item distribution. Eight questions equal 16%, so the final domain is slightly under 17.3%; nine questions equal 18%, so Security Governance is slightly over 17.3%. Exact integer approximation cannot reproduce every decimal weight in only 50 questions.
What changes at the September transition
The current pre-transition outline lists Security Principles; Business Continuity, Disaster Recovery and Incident Response Concepts; Access Controls Concepts; Network Security; and Security Operations. The upcoming outline reorganizes the scope into Security Principles; Security Governance; Identity and Access Management Concepts; Networking and Cloud Security Concepts; and Security Operations and Incident Response.
The new structure creates a distinct governance domain, expands explicit identity lifecycle concepts, incorporates cloud characteristics, service and deployment models, shared responsibility, and adds details such as Zero Trust, metrics and KRIs, threat intelligence and frameworks, end-of-life assets, change management, quantum-resistant cryptography awareness, and several security-testing methods. Do not merge percentages from the old and new documents.
| Booked date | Primary outline | Action |
|---|---|---|
| Before September 1, 2026 | Current outline effective October 1, 2025 | Use current domain names and weights; verify with ISC2. |
| On or after September 1, 2026 | Upcoming outline effective September 1, 2026 | Use the five domains in this guide; verify the appointment. |
| Unclear or rescheduled | Do not guess | Check the ISC2 appointment and live outline page. |
Domain 1: Security Principles — 24%
Confidentiality prevents unauthorized disclosure. Integrity protects accuracy and proper modification. Availability supports timely reliable access. Authentication verifies identity; authorization decides permitted action; accounting records activity. Non-repudiation provides evidence so a party cannot credibly deny an action. Privacy concerns appropriate collection, use, disclosure, retention, and rights around personal information.
Risk management begins with context and objectives. Identify assets, threats, vulnerabilities, and consequences. Assess likelihood and impact with consistent criteria. Choose treatment—commonly mitigate, avoid, transfer, or accept—assign ownership, implement controls, evaluate residual risk, and monitor changes. No control guarantees zero risk.
Governance artifacts have different functions. Laws and regulations impose external obligations. Frameworks and guidelines organize or recommend practice. Policies state management intent. Standards define mandatory specifics. Procedures explain steps. Controls can be technical, administrative, or physical. Effective systems combine them.
Professional conduct is not a decorative objective. Due care means taking reasonable protective action. Due diligence means investigating, evaluating, and continually applying informed attention. Follow the ISC2 Code of Ethics, preserve evidence, respect authorization, avoid conflicts, and report through appropriate channels.
Domain 2: Security Governance — 17.3%
Governance, Risk, and Compliance connects cybersecurity to mission, leadership, accountability, risk decisions, and obligations. Frameworks and tools can organize work, but leadership remains accountable. A compliance result does not prove all material risks are controlled.
Business continuity sustains critical operations during disruption. Disaster recovery restores technology and data. Start with business impact, critical processes, dependencies, recovery priorities, alternate capabilities, backups, communications, and exercises. A technically elegant recovery order can still be wrong if it ignores the most important business service.
Security awareness should shape culture. Leadership models expected behavior. Training addresses social engineering, phishing, password protection, and safe reporting. Measure more than completion: reporting quality, repeat behavior, time to report, and role-relevant outcomes can be more useful.
Metrics need definitions, owners, reliable sources, thresholds, and decisions. Key Risk Indicators signal changing exposure. Dashboards and scorecards summarize performance but can mislead if missing data appears as zero or teams change collection to improve the chart.
Domain 3: Identity and Access Management Concepts — 20%
Identity lifecycle begins with role definition and approved need. Provision only required access. Review periodically and when risk or responsibility changes. Adjust access for movers. Deprovision leavers and expired services promptly. IAM tools automate approved policy but need controlled identities, reliable inputs, exception handling, monitoring, and governance.
Least privilege limits access to the minimum required task, scope, and duration. Separation of duties divides sensitive workflows so one actor cannot request, approve, execute, and reconcile alone. These principles apply to human users, administrators, service accounts, bots, and applications.
Role-based access control assigns permissions to roles. Discretionary access control lets authorized owners make access decisions. Mandatory access control enforces centrally defined labels and clearances. When evaluating a scenario, ask who defines policy, what attributes or labels drive decisions, whether owners can grant access, and at what scope enforcement occurs.
Domain 4: Networking and Cloud Security Concepts — 21.3%
Understand layers and addressing at a practical level. TCP provides reliable ordered transport; UDP is connectionless and lower overhead. IPv4 and IPv6 provide logical addressing and routing. VPNs create protected tunnels over untrusted networks. Firewalls enforce policy using source, destination, protocol, port, connection state, or application information.
Wi-Fi and Bluetooth introduce radio and pairing risks. Industrial control systems, embedded systems, and IoT devices may have specialized availability, patching, protocol, and lifecycle constraints. Inventory, isolate, monitor, and remove unnecessary communication rather than assuming small devices are low risk.
Segmentation separates zones and limits paths. VLANs support logical network separation; firewalls control flows between zones; micro-segmentation can apply finer workload policies. Defense in depth layers controls so one failure does not expose the whole environment. Zero Trust rejects implicit trust based solely on internal location and evaluates identity, device, context, and least privilege.
Cloud characteristics include on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. Service models include IaaS, PaaS, and SaaS. Deployment models include public, private, hybrid, and community. Shared security means provider and customer responsibilities vary by model; customers retain responsibility for data, identity, configuration, and use to differing degrees.
Domain 5: Security Operations and Incident Response — 17.3%
Data handling begins with classification and labeling. Masking obscures values for a use or audience. Sanitization removes data from media to the required assurance. Symmetric encryption uses a shared secret and is efficient for bulk data. Asymmetric cryptography uses a key pair for functions such as encryption and signatures. Hashing is one-way and useful for integrity. Quantum-resistant cryptography is a migration and inventory concern; avoid claiming an algorithm or deployment is secure merely because it has a new label.
Security operations collect and protect logs, monitor events, create use cases, prioritize alerts, and correlate evidence. Triage considers severity, asset importance, context, and confidence. An alert is not automatically an incident. Threat actors differ in capability and motivation. Cyber threat intelligence and threat frameworks provide context but must be evaluated for relevance, freshness, source, and confidence.
An incident response plan defines roles, authority, communications, evidence handling, escalation, containment, recovery, and lessons. Exercises can be discussion-based tabletop sessions or technical simulations inside authorized environments. Preserve timelines and decisions, then assign corrective actions and retest.
Asset protection includes inventory, ownership, lifecycle, end-of-life treatment, secure configuration, and change management. Unsupported assets require upgrade or retirement plans, constrained exposure, monitoring, and approved exceptions. Changes should be documented, tested, approved, validated, and reversible.
Security testing has boundaries. Blue teams defend. Red teams emulate adversaries under strict authorization. Purple teaming improves collaboration and knowledge transfer. Vulnerability scanning finds known weaknesses or exposures. Static analysis inspects code without execution; dynamic analysis tests running software; threat modeling examines design threats. Physical penetration tests and social-engineering exercises can harm people and organizations if conducted without explicit authority—study the concepts, never improvise them on real targets.
A six-week study plan
Week 1: Apply CIA, AAA, privacy, non-repudiation, risk lifecycle, governance artifacts, control types, due care, due diligence, and ethics to original scenarios.
Week 2: Build a fictional GRC charter, risk register, BC/DR priorities, awareness program, metrics, KRI dashboard, and tabletop outline.
Week 3: Model joiner, mover, reviewer, and leaver workflows. Compare RBAC, DAC, and MAC. Practice least privilege and separation of duties.
Week 4: Review TCP/IP, addressing, ports, firewalls, VPNs, wireless, ICS and IoT, segmentation, defense in depth, and Zero Trust.
Week 5: Compare cloud characteristics, service and deployment models, shared security, data handling, cryptography, logging, triage, and threat context.
Week 6: Exercise incident response, EOL assets, change management, and testing methods. Complete three projects, 40 cards, and the exact 12/9/10/11/8 independent question allocation. Recheck the outline for the booked date.
Defensive projects that build evidence
The governance and resilience project creates a risk register, policies, control map, BC/DR strategy, awareness campaign, KRIs, and a fictional ransomware tabletop.
The IAM and segmented cloud project exercises invented joiners, movers, leavers, roles, access models, network zones, exact firewall flows, private or VPN administration, Zero Trust decisions, shared responsibility, and teardown.
The defensive operations project classifies synthetic data, demonstrates cryptographic purposes, centralizes invented logs, triages events, follows an incident plan, manages EOL and changes, and compares authorized testing methods on isolated owned systems.
CAT and question strategy
Read the outcome before the technology. If the requirement is stopping disclosure, think confidentiality. Preventing unauthorized modification points to integrity. Keeping service accessible points to availability. Identity proof is authentication; permission is authorization; recordkeeping is accounting.
When options all sound useful, choose the one that addresses the stated layer. A firewall does not deprovision a leaver. Encryption does not make unavailable systems available. A dashboard does not repair bad source data. A VPN does not prove the endpoint is trustworthy. A policy does not execute a technical recovery procedure.
In CAT, do not attempt to infer difficulty or scoring from item wording. Answer the presented question using the best-supported principle. Pace for the official two-hour window and up to 125 items, review ISC2's live CAT policies, and do not depend on memorized recalled questions.
Readiness checklist
You are approaching readiness when you can define every outline bullet, distinguish adjacent concepts, and apply them to unfamiliar scenarios. Explain why a control fits, what it cannot do, who owns it, what evidence proves it works, and how it fails safely.
Use the five-phase roadmap, the 50 original questions, the 40 flashcards, and the three defensive projects. Independent practice does not reproduce the 100–125-item CAT exam and no score guarantees a pass.
Official references
- ISC2 Certified in Cybersecurity exam outline page
- Official CC outline effective September 1, 2026
- Current CC outline effective before the September transition
- ISC2 Computerized Adaptive Testing
- ISC2 Code of Ethics
- ISC2 examination policies and registration
Continue preparing
- Five-phase ISC2 CC roadmap
- 50 original practice questions
- 40 ISC2 CC flashcards
- Three defensive projects
- CISSP roadmap
- PrepKloud editorial policy
Frequently asked questions
Which outline does this guide use?
The official upcoming ISC2 CC outline effective September 1, 2026.
What should candidates testing before September 1 study?
Use the current October 1, 2025 outline and verify the blueprint tied to the booked exam. Do not use the upcoming weights for an earlier appointment.
What is the upcoming assessment format?
Two hours, 100–125 items, multiple-choice and advanced item types, and CAT as specified by ISC2.
How is the independent bank allocated?
Exactly 12 Security Principles, 9 Security Governance, 10 IAM, 11 Networking and Cloud Security, and 8 Security Operations and Incident Response questions.
Is cybersecurity experience required?
No. The upcoming outline says no cybersecurity work experience, specific prerequisites, or formal degree is required; basic IT knowledge is recommended.
Are these dumps or a pass guarantee?
No. All questions and labs are original independent content grounded in public official sources. There are no official, live, recalled, copied, leaked, or dump items, and no practice score guarantees a pass.