ISC2 Certified in Cybersecurity

ISC2 · CC · Entry

ISC2 · ISC2

ISC2 Certified in Cybersecurity

CCactiveEntry
Official ISC2 source · isc2.org

CC · ● Active · Entry · ISC2

Entry-level cybersecurity certification launched in 2022 with no experience requirement. ISC2 offers free training and first exam attempt through the global "1 Million Certified in Cybersecurity" program (enrollment ends May 20, 2026; testing deadline December 31, 2026). Standard exam cost $199 USD when not in the program. Computer Adaptive Testing (CAT) format effective October 2025.


Exam facts

FieldValue
Cost$199 USD standard; FREE first exam + training via 1 Million CC program
Duration120 minutes (2 hours)
Questions100–125 multiple-choice and advanced-item types
Passing700/1000 scaled score
FormatComputer Adaptive Testing (CAT) — multiple choice + advanced items
DeliveryPearson VUE testing centers
LanguagesEnglish (primary); ISC2 offers international exam delivery
Valid3 years
Renewal45 CPE credits per 3-year cycle + $50 AMF (or FREE for 1 Million CC program members)
PrerequisitesNone — no prior experience required
Released2022
RetiringN/A; active through 2026 with exam outline refresh September 1, 2026

Vendor source — ISC2 Certified in Cybersecurity ↗ Official exam guide — CC Certification Exam Outline ↗ Free training & exam vouchers — 1 Million Certified in Cybersecurity ↗


About

ISC2 Certified in Cybersecurity (CC) is the vendor's entry-level cybersecurity credential, introduced in 2022 as part of the global "1 Million Certified in Cybersecurity" initiative to grow the cybersecurity workforce. The cert requires no prior work experience and has been freely available (training + first exam attempt) to candidates enrolled in the program since launch. As of May 2026, public enrollment in the 1 Million CC program ends May 20, 2026, with testing deadline December 31, 2026. Candidates not in the program pay $199 per exam. The certification is ideal for career-changers, recent graduates, and IT professionals transitioning into security roles. ISC2 introduced Computer Adaptive Testing (CAT) for the CC effective October 2025, meaning exam difficulty adjusts based on candidate performance.


Domain context — Security

Entry-level cybersecurity foundations covering security principles, access controls, network security, incident response, and security operations. Builds on vendor-neutral entry concepts; graduates typically progress to SSCP (hands-on practitioner) or Security+ (CompTIA alternative).

Read full deep dive — ISC2 Ecosystem ↗


Topics covered

Exam blueprint effective October 1, 2025 (refresh scheduled September 1, 2026).

  • Security Principles (26%) — confidentiality, integrity, availability, authentication, authorization, accounting (AAA), cryptography basics, security posture
  • Business Continuity, Disaster Recovery & Incident Response (10%) — BC/DR planning, incident detection, response, recovery, post-incident review
  • Access Controls Concepts (22%) — identification, authentication, authorization, access control models (DAC, MAC, RBAC), physical access controls
  • Network Security (24%) — network protocols, OSI model, firewalls, intrusion detection/prevention, VPNs, wireless security, DNS, SSL/TLS
  • Security Operations (18%) — security tools, logging and monitoring, vulnerability assessment, patch management, endpoint security, threat detection

Source: ISC2 CC Exam Outline ↗


Common skills at Security · Entry

Shared foundational skills for entry-level security roles — not specific to CC.

  • Security principles (CIA triad, defense-in-depth, least privilege)
  • Authentication and authorization mechanisms
  • Basic network security concepts and protocols
  • Vulnerability identification and remediation processes
  • Incident response basics (detection, containment, eradication, recovery)
  • Compliance and policy fundamentals
  • Security awareness and user behavior concepts

Recommended courses at Security · Entry

ProviderTitleCostURL
ISC2 (official)CC Online Self-Paced TrainingFREE via 1 Million program; $129–$199 standard
UdemyThe Complete Certified in Cybersecurity CC Course ISC2 2026$15–$100
UdemyISC2 CC - Certified in Cybersecurity Exam Prep Course 2026$15–$100
PluralsightISC2 Certified in Cybersecurity (CC)Subscription

Course-selection rule: Each course listed is specifically for the CC exam code. The ISC2 official self-paced training is the vendor's primary resource and is FREE to 1 Million CC program enrollees.


Practice exams

ProviderTitleCostURL
Pocket PrepISC2 CC Exam Prep$30–$50
MeasureUpISC2 CC Practice Tests$99–$149
UdemyISC2 Certified in Cybersecurity (CC) Full Practice Exams 2026$15–$80
OpenExamPrepFree ISC2 CC Practice Exam (200+ questions with AI tutor)Free

Books

TitleAuthorPublisherYearISBNURL
CC Certified in Cybersecurity Study Guide (Sybex Study Guide)Mike ChappleSybex (Wiley)20249781394213832

Typical job titles at Security · Entry

Security Analyst · SOC Analyst (Tier 1) · Junior Cybersecurity Analyst · IT Security Support · Cybersecurity Intern · Security Operations Center (SOC) Technician · Information Security Analyst (entry-level)

(Job titles drawn from current job-board postings that list CC as required or preferred for entry-level security roles.)


Salary

RegionRangeSource
USD$60,000–$85,000Cert Empire ↗ · CrucialExams ↗
ZARNo region-specific data available — use ISC2 general security analyst role salary research
GBPNo region-specific data available — use ISC2 general security analyst role salary research

Salary note: Entry-level SOC analyst and security analyst roles paying in the USD $60–$85K range typically cite CC or Security+ as preferred. ISC2 members report 35% higher salaries on average than non-members across all ISC2 certifications. No dedicated salary surveys for ZAR or GBP entry-level CC holders exist; use general security analyst salary data for these regions.


Skills validated

Concrete technologies, protocols, and concepts this exam tests.

  • Authentication protocols (multi-factor authentication, single sign-on)
  • Cryptography fundamentals (symmetric/asymmetric encryption, hashing)
  • Network security protocols (TLS/SSL, IPsec, SSH, VPN)
  • Firewall types and configurations
  • Intrusion detection and prevention systems (IDS/IPS)
  • Access control models (DAC, MAC, RBAC)
  • Business continuity and disaster recovery planning
  • Incident response procedures and tools
  • Vulnerability assessment and scanning tools
  • Compliance frameworks and standards (GDPR, HIPAA, PCI-DSS basics)
  • Security policies, procedures, and change management

Related certifications

  • Stacks with: CompTIA Security+ ↗ (vendor-neutral alternative at entry level; similar cost and difficulty)
  • Prerequisite for: ISC2 SSCP ↗ (requires 1 year of hands-on security operations experience; SSCP is next step in ISC2 practitioner path)
  • Progression: ISC2 CC → SSCP (practitioner) → CISSP (leadership/architecture)
  • Equivalents at this level: CompTIA Security+, Cisco CCNA Security (retired; replaced by CCNA Cyber Operations)
  • Vendor overview: ISC2 Overview ↗

Sources


Last verified: 2026-05-01 Parent ecosystem: ISC2 Vendor Overview Parent domain: Security Domain Vendor overview: ISC2 Overview

Rate this cert
Was this helpful?
Comments ()
0/2000