Certified in Governance, Risk and Compliance

ISC2 · CGRC · Expert

ISC2 · ISC2

Certified in Governance, Risk and Compliance

CGRCactiveExpert
Official ISC2 source · isc2.org

CGRC · ● Active · Expert · ISC2

ISC2's governance and risk certification — the standard for GRC professionals, compliance officers, and security auditors. Formerly known as CAP (Certified Authorization Professional), renamed CGRC in 2024 to reflect modern GRC scope. Aligns with NIST Risk Management Framework (RMF) and is foundational for compliance and authorization roles in regulated industries.


Exam facts

FieldValue
Cost$599 USD
Duration4 hours
Questions125
Passing700/1000 scaled
FormatMultiple choice
DeliveryPearson VUE
LanguagesEnglish
Valid3 years
Renewal45 CPE credits over 3 years + $100 annual maintenance fee
Prerequisites2 years professional experience in GRC/governance/compliance roles
Released2005 (as CAP); renamed CGRC 2024
RetiringN/A (CAP absorbed into CGRC brand)

Vendor source — ISC2 CGRC Certification ↗

Official exam guide — CGRC Exam Overview ↗

Exam objectives — CGRC Exam Blueprint ↗


About

The CGRC (Certified in Governance, Risk and Compliance) is ISC2's vendor-neutral certification for professionals managing governance frameworks, enterprise risk, compliance programs, and information systems security authorization. Historically known as CAP (Certified Authorization Professional) since 2005, the credential was rebranded to CGRC in 2024 to reflect its expanding remit beyond federal NIST RMF authorization to encompass enterprise governance and compliance program design. CGRC is recognized across government, finance, healthcare, and critical infrastructure sectors and serves as the strategic counterpart to ISC2's technical security certs (CISSP, SSCP). The 2-year experience requirement is significantly lower than CISSP, making CGRC an attractive on-ramp for mid-career compliance professionals transitioning into GRC leadership.


Domain context — Audit/GRC

Governance, risk, and compliance (GRC) is the business-facing arm of information security — risk quantification, control selection, compliance assurance, and audit. CGRC sits at the expert level, validating mastery of NIST RMF, ISO 27001/27002, and enterprise risk frameworks.

Read full deep dive — Audit/GRC Domain ↗


Topics covered

CGRC exam objectives span seven core domains, aligned to NIST RMF and ISO 27001:

  • Categorization of Information Systems — NIST FIPS 199 impact analysis; system boundary definition; data classification; sensitivity assessment.
  • Selection of Security Controls — NIST SP 800-53 control families; baseline selection; control tailoring; risk assessment methodologies.
  • Implementation of Security Controls — Technical and administrative control deployment; configuration management; evidence gathering; compliance tooling.
  • Assessment of Security Controls — Testing methodologies; vulnerability scanning; control testing frameworks; assessment reporting and metrics.
  • Authorization of Information Systems — Risk-based decision-making; residual risk acceptance; system authorization documentation; authority to operate (ATO) process.
  • Continuous Monitoring — Monitoring and incident response; control effectiveness metrics; KPIs; automated assessment tools; trending and reporting.
  • Information Security Risk Management Program — Enterprise risk governance; risk appetite; risk tolerance; risk communication; board-level reporting.

Source: ISC2 CGRC Exam Blueprint ↗


Common skills at Audit/GRC · Expert

Shared competencies across the Audit/GRC domain at expert level — not specific to CGRC, but foundational for the role.

  • Risk quantification and analytics — Translate vulnerability and control gaps into financial risk metrics; present risk decisions to leadership and boards.
  • Control framework mapping — Align NIST RMF, ISO 27001, CIS, COBIT, and industry-specific frameworks to organizational policy and process.
  • Compliance program design — Build audit schedules, evidence management, remediation tracking, and board reporting for SOC 2, FedRAMP, HIPAA, PCI-DSS, GDPR compliance.
  • System authorization and ATO process — Lead NIST RMF phases; coordinate stakeholder sign-off; manage continuous monitoring baselines and recertification.
  • Audit and control testing — Design control test plans; interpret audit findings; distinguish operating effectiveness from design effectiveness; manage remediation campaigns.
  • Executive communication — Translate compliance and risk data into business language for C-suite, boards, and regulators.

Recommended courses at Audit/GRC · Expert

ProviderTitleCostURL
ISC2 OfficialCGRC Bootcamp (4 days)$1,695
Mile2CGRC/CAP Mastery Course$499–$699
IT DojoCGRC (CAP) Certification Course$399–$599
CybraryCGRC Course (ISC2-aligned)Free / $99/month premium
PluralsightGovernance, Risk, and Compliance$299/year

Course-selection rule: ISC2's official bootcamp is comprehensive but expensive. Mile2 and IT Dojo offer well-structured, exam-focused content at lower cost. Cybrary's free tier is sufficient for foundational review; premium unlocks full practice exams.


Practice exams

ProviderTitleCostURL
ISC2 OfficialCGRC Practice Exams (2 full exams)$50–$75
BosonCGRC Practice Exam (adaptive)$79–$99
WhizlabsCGRC Practice Tests (500+ questions)$89
IT DojoCGRC CAP Practice Exams$99

Books

TitleAuthorPublisherYearISBNURL
CGRC (CAP) Certification Study GuideDavid Endler, Courtney Loh (ISC2)Sybex2024978-1394243761
NIST SP 800-37 Risk Management FrameworkNIST / U.S. Department of CommerceNIST2023N/A
ISO/IEC 27001:2022 Information Security ManagementISOISO2022978-0-580-94606-7

Book rule: The Sybex CGRC Study Guide (2024) is the only official ISC2 study guide for the rebranded certification. NIST SP 800-37 and ISO 27001 are mandatory references — not textbooks, but primary source standards that the exam heavily draws from.


Typical job titles at Audit/GRC · Expert

Governance Risk & Compliance (GRC) Analyst · IT Auditor · NIST RMF Specialist · Compliance Officer · Chief Compliance Officer (CCO) · Senior Compliance Manager · Security Authorization Manager · Enterprise Risk Manager · Internal Audit Manager

(Job titles drawn from current job-board postings (LinkedIn, Indeed, Glassdoor) that list CGRC or CAP as required or preferred.)


Salary

Salary note: CGRC-certified professionals command a 15–20% premium over non-certified peers in equivalent GRC roles, especially in regulated industries (banking, healthcare, government). Compliance Officer and RMF Specialist roles in federal contracting (GSA Schedule, FedRAMP) often mandate CGRC or CISSP. Regional data reflects 2024–2025 surveys.


Skills validated

Concrete processes, frameworks, and tools tested by the CGRC exam — distinct from general domain competencies.

  • NIST Risk Management Framework (RMF) — Full lifecycle: categorize, select, implement, assess, authorize, monitor; step-by-step execution; artifact generation.
  • NIST SP 800-53 Security Controls — Control families, baselines, tailoring, scoping, family-specific guidance.
  • ISO/IEC 27001:2022 Information Security Management System (ISMS) — Control objectives, control implementation, ISMS lifecycle, internal/external audits.
  • System authorization and ATO processes — Authority to Operate (ATO) documentation, risk acceptance decisions, residual risk reporting.
  • Control testing and assessment — Audit procedures; testing matrices; operating effectiveness evaluation; control operating audits (SOC 2).
  • Compliance frameworks — CIS Critical Security Controls, COBIT 5, PCI-DSS, HIPAA/HITECH, GDPR/CCPA, SOX, FedRAMP, state privacy laws.
  • Risk assessment methodologies — Qualitative and quantitative analysis, threat modeling, vulnerability analysis, impact assessment.
  • Continuous monitoring programs — KPIs, baselining, trending, automated assessment tools (e.g., CMMC for DoD contractors).
  • Executive reporting and metrics — KRIs (Key Risk Indicators), KPIs, risk dashboards, board-level communication.

Pathway and prerequisites

Standard path (2-year experience required):

  • 2 years professional experience in information security, governance, compliance, audit, or risk management roles.
  • Experience must include hands-on work with security controls, risk assessment, or compliance activities.
  • No other certifications required; CGRC is open to mid-career professionals (unlike CISSP's 5-year requirement).

Faster path (with bachelor's degree):

  • Bachelor's degree in relevant field (Information Security, Business, Accounting, IT, etc.) + 1 year equivalent experience.

Strategic stacking:

  • Many professionals pursue CGRC before or after CISSP (CISSP is broader; CGRC is deeper in risk/compliance).
  • CGRC often stacks with CISA (audit-focused) or CISM (management-focused) for comprehensive coverage of GRC and audit functions.

Renewal and maintenance

After certification:

  • Valid for 3 years from ISC2's grant date.
  • 45 CPE credits required over the 3-year cycle (average 15 CPEs/year — lower than CISSP).
  • $100 annual maintenance fee (AMF) due each year to maintain active status.
  • CPE sources: Training courses, conference attendance, published articles, volunteer work in compliance/audit organizations, advanced degrees, ISC2-approved webinars.
  • Renewal process: At year 3, submit CPE transcript and renew AMF; ISC2 grants a new 3-year certificate.

Related certifications

  • Stacks with: CISSP (ISC2) ↗ — broader security umbrella; both complement each other for C-level security + compliance roles.
  • Stacks with: CISA (ISACA) ↗ — audit-focused; combines GRC + audit expertise.
  • Stacks with: CISM (ISACA) ↗ — IT risk management; complements CGRC for enterprise risk governance.
  • Prerequisite for: None at this time; CGRC is a terminal expert credential (no higher certs from ISC2 in GRC domain).
  • Replaces: CAP (Certified Authorization Professional) — CGRC is the rebranded successor (2024); CAP exam is retired.
  • Vendor overview: ISC2 Overview ↗

Career impact and trajectory

Pre-CGRC: Compliance and audit professionals typically operate at analyst/manager level without formal certification. Advancement to Chief Compliance Officer, Chief Risk Officer (CRO), or leadership in federal/regulated sectors is constrained.

At CGRC: Signals deep expertise in risk and compliance frameworks; opens doors to senior compliance roles, ATO program leadership, federal contracting, and regulated-industry positions (banking, healthcare, defense).

Post-CGRC: Common career paths include:

  • CISSP or CISM — For broader executive security/risk scope.
  • CISA — For deeper audit specialization (often pursued alongside CGRC).
  • Chief Compliance Officer (CCO) — C-level compliance executive role.
  • Compliance Program Lead — Enterprise compliance office leadership.
  • FedRAMP/CMMC Program Manager — Federal compliance and authorization programs.

Sources


Last verified: 2026-05-01
Parent ecosystem: ISC2 Ecosystem
Parent domain: Audit/GRC Domain
Vendor overview: ISC2 Vendor Overview

Rate this cert
Was this helpful?
Comments ()
0/2000