ISC2 Certified in Cybersecurity (CC): a complete guide
The ISC2 Certified in Cybersecurity (CC) is an entry-level certification designed for people starting out in cybersecurity — it requires no prior experience and validates a foundational understanding of core security concepts. It comes from ISC2, the professional body behind the CISSP, which gives a genuinely beginner-friendly credential an unusually serious pedigree. The exam is 100 multiple-choice questions in two hours, delivered at Pearson VUE, with a passing score of 700 out of 1000. It is no longer free — ISC2’s well-known free-exam programme stopped taking new enrolments, and a fee now applies — but it remains one of the most accessible first steps into the security field. This guide covers what the CC tests, who it suits, how it compares to the alternatives, the logistics and ongoing maintenance, and an honest read on whether it is worth your time.
What it is and who it is for
The CC is ISC2’s answer to a long-standing gap: the organisation’s flagship credentials, most famously the CISSP, are gated behind years of professional security experience, which left newcomers with nothing from the same body to start on. The CC removes that barrier entirely — no experience requirement, no prerequisite, no endorsement process to enter. It certifies that you understand the foundational concepts of the field: how security is reasoned about, how access is controlled, how networks are defended, and how organisations respond when things go wrong.
It suits two groups particularly well. Career starters — students, recent graduates, and people in early IT roles — get a recognised credential that says they have engaged seriously with security fundamentals. Career changers moving into security from another field get the same signal, plus a structured syllabus that maps the territory before they commit further. If you already work in security, the CC is beneath you; it is deliberately a first rung, and ISC2 positions it as the start of a pathway towards its experience-gated certifications rather than a destination.
What the exam covers
The CC blueprint spans five domains, all at a foundational, conceptual level — you are tested on understanding, not hands-on configuration:
- Security principles — the core vocabulary and reasoning of the field: confidentiality, integrity and availability, risk, and the ethics and governance that frame security work.
- Business continuity, disaster recovery and incident response concepts — how organisations plan for disruption, recover from it, and respond when an incident is under way.
- Access control concepts — how systems decide who can do what: identification, authentication, authorisation, and the physical and logical controls that enforce it.
- Network security — how networks are attacked and defended: common threats, segmentation, and the defensive infrastructure that sits between systems and the outside world.
- Security operations — the day-to-day practice of keeping systems secure: data handling, hardening, logging and monitoring, and security awareness.
Where it fits in the certification landscape
The CC sits at the entry level of a crowded field, and its most common comparison is CompTIA Security+ — the classic first security certification. The short version: the CC is the lighter, cheaper, faster on-ramp, entirely multiple-choice and genuinely designed for people with no background; Security+ is broader, deeper and longer-established, but a bigger commitment in study time and cost. Our comparison of entry-level cybersecurity certifications walks through that choice in full, and neither answer is wrong — it depends on your budget, your timeline and what your target employers recognise.
Within ISC2’s own ladder, the CC is explicitly the first step: the body’s senior credentials, including the CISSP, require years of documented security experience, and the CC gives newcomers a way to join that pathway early. It also pairs naturally with cloud certifications — security work increasingly happens in cloud environments, and a CC alongside a cloud credential covers both halves of that overlap, a combination our article on cloud versus cybersecurity careers explores.
Logistics: format, fee and booking
The exam is 100 multiple-choice questions in 2 hours, delivered at Pearson VUE test centres, with a passing score of 700 out of 1000. There are no simulations or hands-on tasks — it is a knowledge exam, which is part of what makes it approachable for beginners.
On cost, the current picture matters: the CC is no longer free. ISC2’s “One Million Certified in Cybersecurity” programme, which bundled free training and a free exam attempt, stopped taking new enrolments, and the standard exam now carries a fee — about $199 at the time of writing, though check ISC2’s site for the current figure. ISC2 has historically offered free self-paced training and periodically runs free or discounted exam initiatives, so it is genuinely worth checking their site for live offers before booking. Budget for the fee, and treat anything better as a bonus.
Maintenance: the certification is ongoing, not one-off
Unlike a cert you pass once and frame, the CC is a maintained credential. It is valid for three years, and keeping it requires two things: an annual maintenance fee (AMF) paid to ISC2, and continuing professional education (CPE) credits earned over the cycle — activities like courses, webinars and professional reading that demonstrate you are keeping current. This is the standard ISC2 model, shared with the CISSP.
Factor this into the decision honestly. The headline exam fee is not the whole cost — there is a small ongoing commitment of money and attention for as long as you hold the credential. For someone genuinely pursuing a security career that is a reasonable trade: the CPE habit is one the field expects anyway, and ISC2 membership brings its own resources. For someone collecting a certificate they do not plan to use, the maintenance model is a reason to think twice. Check ISC2’s site for the current AMF amount and CPE requirements, as both are theirs to set.
Is it worth it?
As a first security credential, yes — with clear eyes about what it is. The CC is a credible, low-barrier signal from a body every security employer knows, it costs less than most alternatives, and its syllabus is a genuinely sensible map of the field for a newcomer. What it is not is a job ticket: no entry-level certification alone makes you a security professional, and employers hiring for security roles look for fundamentals — networking, operating systems, how systems fail — and hands-on evidence alongside any badge. Our guide on how to start a career in cybersecurity covers that fuller picture.
The honest framing: take the CC to structure your first serious study of security and to show commitment, pair it with practical learning you can demonstrate, and treat it as the first rung of a ladder rather than proof of arrival. Used that way, it earns its fee.
Original practice questions, timed mock exams and revision notes. No card, nothing to pay.