CGRC · ● Active · Expert · ISC2
ISC2's governance and risk certification — the standard for GRC professionals, compliance officers, and security auditors. Formerly known as CAP (Certified Authorization Professional), renamed CGRC in 2024 to reflect modern GRC scope. Aligns with NIST Risk Management Framework (RMF) and is foundational for compliance and authorization roles in regulated industries.
Exam facts
| Field | Value |
|---|---|
| Cost | $599 USD |
| Duration | 4 hours |
| Questions | 125 |
| Passing | 700/1000 scaled |
| Format | Multiple choice |
| Delivery | Pearson VUE |
| Languages | English |
| Valid | 3 years |
| Renewal | 45 CPE credits over 3 years + $100 annual maintenance fee |
| Prerequisites | 2 years professional experience in GRC/governance/compliance roles |
| Released | 2005 (as CAP); renamed CGRC 2024 |
| Retiring | N/A (CAP absorbed into CGRC brand) |
Vendor source — ISC2 CGRC Certification ↗
Official exam guide — CGRC Exam Overview ↗
Exam objectives — CGRC Exam Blueprint ↗
About
The CGRC (Certified in Governance, Risk and Compliance) is ISC2's vendor-neutral certification for professionals managing governance frameworks, enterprise risk, compliance programs, and information systems security authorization. Historically known as CAP (Certified Authorization Professional) since 2005, the credential was rebranded to CGRC in 2024 to reflect its expanding remit beyond federal NIST RMF authorization to encompass enterprise governance and compliance program design. CGRC is recognized across government, finance, healthcare, and critical infrastructure sectors and serves as the strategic counterpart to ISC2's technical security certs (CISSP, SSCP). The 2-year experience requirement is significantly lower than CISSP, making CGRC an attractive on-ramp for mid-career compliance professionals transitioning into GRC leadership.
Domain context — Audit/GRC
Governance, risk, and compliance (GRC) is the business-facing arm of information security — risk quantification, control selection, compliance assurance, and audit. CGRC sits at the expert level, validating mastery of NIST RMF, ISO 27001/27002, and enterprise risk frameworks.
Read full deep dive — Audit/GRC Domain ↗
Topics covered
CGRC exam objectives span seven core domains, aligned to NIST RMF and ISO 27001:
- Categorization of Information Systems — NIST FIPS 199 impact analysis; system boundary definition; data classification; sensitivity assessment.
- Selection of Security Controls — NIST SP 800-53 control families; baseline selection; control tailoring; risk assessment methodologies.
- Implementation of Security Controls — Technical and administrative control deployment; configuration management; evidence gathering; compliance tooling.
- Assessment of Security Controls — Testing methodologies; vulnerability scanning; control testing frameworks; assessment reporting and metrics.
- Authorization of Information Systems — Risk-based decision-making; residual risk acceptance; system authorization documentation; authority to operate (ATO) process.
- Continuous Monitoring — Monitoring and incident response; control effectiveness metrics; KPIs; automated assessment tools; trending and reporting.
- Information Security Risk Management Program — Enterprise risk governance; risk appetite; risk tolerance; risk communication; board-level reporting.
Source: ISC2 CGRC Exam Blueprint ↗
Common skills at Audit/GRC · Expert
Shared competencies across the Audit/GRC domain at expert level — not specific to CGRC, but foundational for the role.
- Risk quantification and analytics — Translate vulnerability and control gaps into financial risk metrics; present risk decisions to leadership and boards.
- Control framework mapping — Align NIST RMF, ISO 27001, CIS, COBIT, and industry-specific frameworks to organizational policy and process.
- Compliance program design — Build audit schedules, evidence management, remediation tracking, and board reporting for SOC 2, FedRAMP, HIPAA, PCI-DSS, GDPR compliance.
- System authorization and ATO process — Lead NIST RMF phases; coordinate stakeholder sign-off; manage continuous monitoring baselines and recertification.
- Audit and control testing — Design control test plans; interpret audit findings; distinguish operating effectiveness from design effectiveness; manage remediation campaigns.
- Executive communication — Translate compliance and risk data into business language for C-suite, boards, and regulators.
Recommended courses at Audit/GRC · Expert
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISC2 Official | CGRC Bootcamp (4 days) | $1,695 | ↗ |
| Mile2 | CGRC/CAP Mastery Course | $499–$699 | ↗ |
| IT Dojo | CGRC (CAP) Certification Course | $399–$599 | ↗ |
| Cybrary | CGRC Course (ISC2-aligned) | Free / $99/month premium | ↗ |
| Pluralsight | Governance, Risk, and Compliance | $299/year | ↗ |
Course-selection rule: ISC2's official bootcamp is comprehensive but expensive. Mile2 and IT Dojo offer well-structured, exam-focused content at lower cost. Cybrary's free tier is sufficient for foundational review; premium unlocks full practice exams.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISC2 Official | CGRC Practice Exams (2 full exams) | $50–$75 | ↗ |
| Boson | CGRC Practice Exam (adaptive) | $79–$99 | ↗ |
| Whizlabs | CGRC Practice Tests (500+ questions) | $89 | ↗ |
| IT Dojo | CGRC CAP Practice Exams | $99 | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| CGRC (CAP) Certification Study Guide | David Endler, Courtney Loh (ISC2) | Sybex | 2024 | 978-1394243761 | ↗ |
| NIST SP 800-37 Risk Management Framework | NIST / U.S. Department of Commerce | NIST | 2023 | N/A | ↗ |
| ISO/IEC 27001:2022 Information Security Management | ISO | ISO | 2022 | 978-0-580-94606-7 | ↗ |
Book rule: The Sybex CGRC Study Guide (2024) is the only official ISC2 study guide for the rebranded certification. NIST SP 800-37 and ISO 27001 are mandatory references — not textbooks, but primary source standards that the exam heavily draws from.
Typical job titles at Audit/GRC · Expert
Governance Risk & Compliance (GRC) Analyst · IT Auditor · NIST RMF Specialist · Compliance Officer · Chief Compliance Officer (CCO) · Senior Compliance Manager · Security Authorization Manager · Enterprise Risk Manager · Internal Audit Manager
(Job titles drawn from current job-board postings (LinkedIn, Indeed, Glassdoor) that list CGRC or CAP as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $85,000–$150,000+ | Glassdoor GRC Analyst ↗ · Robert Half 2024 Salary Guide ↗ · Levels.fyi Security/Compliance ↗ |
| ZAR | R900,000–R1,600,000 (annualized) | Pnet Compliance Roles ↗ · PayScale South Africa ↗ |
| GBP | £55,000–£100,000 | IT Jobs Watch Compliance ↗ · Hays Salary Report ↗ |
| EUR | €60,000–€110,000 (DE/FR/NL) | Robert Half Europe ↗ · Salary.com Europe ↗ |
| AUD | A$95,000–A$160,000 | SEEK Australia ↗ · PageUp IT Salary Report ↗ |
Salary note: CGRC-certified professionals command a 15–20% premium over non-certified peers in equivalent GRC roles, especially in regulated industries (banking, healthcare, government). Compliance Officer and RMF Specialist roles in federal contracting (GSA Schedule, FedRAMP) often mandate CGRC or CISSP. Regional data reflects 2024–2025 surveys.
Skills validated
Concrete processes, frameworks, and tools tested by the CGRC exam — distinct from general domain competencies.
- NIST Risk Management Framework (RMF) — Full lifecycle: categorize, select, implement, assess, authorize, monitor; step-by-step execution; artifact generation.
- NIST SP 800-53 Security Controls — Control families, baselines, tailoring, scoping, family-specific guidance.
- ISO/IEC 27001:2022 Information Security Management System (ISMS) — Control objectives, control implementation, ISMS lifecycle, internal/external audits.
- System authorization and ATO processes — Authority to Operate (ATO) documentation, risk acceptance decisions, residual risk reporting.
- Control testing and assessment — Audit procedures; testing matrices; operating effectiveness evaluation; control operating audits (SOC 2).
- Compliance frameworks — CIS Critical Security Controls, COBIT 5, PCI-DSS, HIPAA/HITECH, GDPR/CCPA, SOX, FedRAMP, state privacy laws.
- Risk assessment methodologies — Qualitative and quantitative analysis, threat modeling, vulnerability analysis, impact assessment.
- Continuous monitoring programs — KPIs, baselining, trending, automated assessment tools (e.g., CMMC for DoD contractors).
- Executive reporting and metrics — KRIs (Key Risk Indicators), KPIs, risk dashboards, board-level communication.
Pathway and prerequisites
Standard path (2-year experience required):
- 2 years professional experience in information security, governance, compliance, audit, or risk management roles.
- Experience must include hands-on work with security controls, risk assessment, or compliance activities.
- No other certifications required; CGRC is open to mid-career professionals (unlike CISSP's 5-year requirement).
Faster path (with bachelor's degree):
- Bachelor's degree in relevant field (Information Security, Business, Accounting, IT, etc.) + 1 year equivalent experience.
Strategic stacking:
- Many professionals pursue CGRC before or after CISSP (CISSP is broader; CGRC is deeper in risk/compliance).
- CGRC often stacks with CISA (audit-focused) or CISM (management-focused) for comprehensive coverage of GRC and audit functions.
Renewal and maintenance
After certification:
- Valid for 3 years from ISC2's grant date.
- 45 CPE credits required over the 3-year cycle (average 15 CPEs/year — lower than CISSP).
- $100 annual maintenance fee (AMF) due each year to maintain active status.
- CPE sources: Training courses, conference attendance, published articles, volunteer work in compliance/audit organizations, advanced degrees, ISC2-approved webinars.
- Renewal process: At year 3, submit CPE transcript and renew AMF; ISC2 grants a new 3-year certificate.
Related certifications
- Stacks with: CISSP (ISC2) ↗ — broader security umbrella; both complement each other for C-level security + compliance roles.
- Stacks with: CISA (ISACA) ↗ — audit-focused; combines GRC + audit expertise.
- Stacks with: CISM (ISACA) ↗ — IT risk management; complements CGRC for enterprise risk governance.
- Prerequisite for: None at this time; CGRC is a terminal expert credential (no higher certs from ISC2 in GRC domain).
- Replaces: CAP (Certified Authorization Professional) — CGRC is the rebranded successor (2024); CAP exam is retired.
- Vendor overview: ISC2 Overview ↗
Career impact and trajectory
Pre-CGRC: Compliance and audit professionals typically operate at analyst/manager level without formal certification. Advancement to Chief Compliance Officer, Chief Risk Officer (CRO), or leadership in federal/regulated sectors is constrained.
At CGRC: Signals deep expertise in risk and compliance frameworks; opens doors to senior compliance roles, ATO program leadership, federal contracting, and regulated-industry positions (banking, healthcare, defense).
Post-CGRC: Common career paths include:
- CISSP or CISM — For broader executive security/risk scope.
- CISA — For deeper audit specialization (often pursued alongside CGRC).
- Chief Compliance Officer (CCO) — C-level compliance executive role.
- Compliance Program Lead — Enterprise compliance office leadership.
- FedRAMP/CMMC Program Manager — Federal compliance and authorization programs.
Sources
- ISC2 CGRC Certification Page
- ISC2 CGRC Exam Blueprint
- NIST SP 800-37 Risk Management Framework (Rev. 2)
- ISO/IEC 27001:2022 Standard
- Sybex CGRC Study Guide (2024)
- Mile2 CGRC Course
- IT Dojo CGRC Certification Course
- Boson CGRC Practice Exam
- Glassdoor GRC Analyst Salary
- Robert Half 2024 IT Salary Guide
- IT Jobs Watch UK Compliance Salary
Last verified: 2026-05-01
Parent ecosystem: ISC2 Ecosystem
Parent domain: Audit/GRC Domain
Vendor overview: ISC2 Vendor Overview