Career Guide

ISC2 CC Exam Prep for the 2026 Outline: A Study Plan

EDWartens Engineering Team
10 min read
ISC2 CC Exam Prep for the 2026 Outline: A Study Plan

The short answer

ISC2 CC exam prep in 2026 means studying the five domains of the outline that took effect on 1 September 2026, practising short scenario questions, and booking the exam directly with ISC2. The Certified in Cybersecurity (CC) exam is adaptive, has 100 to 125 items, lasts two hours and needs 700 out of 1000 to pass. The free exam that made the CC popular in India has ended: ISC2 closed its One Million Certified in Cybersecurity programme to new sign-ups on 20 May 2026, so new candidates now buy the exam from ISC2. A sensible plan for a beginner is four to six weeks of steady study, weighted by the domain percentages, with original practice questions and no exam dumps.

Exam facts in this guide were checked on ISC2's pages on 11 October 2026 (October 2026). ISC2 changes outlines and terms, so check its pages again before you book.

What changed for the CC exam in 2026?

Two things changed this year, and many older blog posts and YouTube playlists in India still describe the old situation.

First, the exam outline. ISC2's CC exam outline page lists a new outline effective 1 September 2026. Security Governance is now a domain of its own, identity and access management has its own domain, and ISC2 says it has integrated foundational AI concepts across all five domains. That means questions about things like poisoned training data (an integrity problem) or AI agents that need accounts and permissions (an access problem), not a separate AI section.

Second, the free voucher. ISC2's One Million Certified in Cybersecurity page says new enrolments closed effective 20 May 2026. If you already hold an exam code from the programme and it has not expired, you must schedule and sit the exam by 31 December 2026; an expired code cannot be reactivated, and no new free seats are issued. In its 22 April 2026 announcement, ISC2 said more than a million people enrolled, more than 570,000 took the course and more than 65,000 earned the CC. From now on the exam is sold like ISC2's other exams, and the fee is paid to ISC2.

CC exam fact (ISC2, read 11 October 2026)
Value
Outline in force
Effective 1 September 2026
Format
Computerized adaptive testing (CAT)
Items
100 to 125, multiple choice and advanced item types
Time
2 hours
Passing grade
700 out of 1000 points
Languages
English, Chinese, Japanese, German, Spanish
Work experience needed
None
Free One Million CC exam
Closed to new sign-ups 20 May 2026; existing unexpired codes must be used by 31 December 2026

The five domains and how much each counts

The weights tell you where to spend your hours. A domain that is 24 percent of the exam deserves more time than one that is 17.3 percent, unless you are already strong in it.

Domain (2026 outline)
Weight
What it covers in plain words
1. Security Principles
24%
CIA triad, authentication and non-repudiation, privacy, risk, controls, ethics
2. Security Governance
17.3%
Governance, risk and compliance, business continuity, disaster recovery, awareness, metrics
3. Identity and Access Management Concepts
20%
Identity life cycle, least privilege, separation of duties, access models
4. Networking and Cloud Security Concepts
21.3%
OSI and TCP/IP, ports, firewalls, segmentation, zero trust, cloud shared responsibility
5. Security Operations and Incident Response
17.3%
Data handling, encryption, logging and monitoring, incident response, testing

ISC2 gives the total as 100 percent. The rounded figures add up to 99.9, which does not matter for planning.

Table of the five ISC2 CC domains in the 2026 outline with their weights and topics
Table of the five ISC2 CC domains in the 2026 outline with their weights and topics

A four-week ISC2 CC study plan

This plan assumes about 40 hours: roughly 10 hours a week for four weeks, which suits a student or someone studying after office hours.

Week
Focus
Practice
1
How the exam works; Domain 1 Security Principles
Risk calculations; label every control as technical, administrative or physical
2
Domain 2 Security Governance; Domain 3 IAM
RTO and RPO problems; an access review of a small team
3
Domain 4 Networking and Cloud Security
Ports, private address ranges, a cloud shared responsibility table
4
Domain 5 Security Operations and IR; full review
Alert triage, incident phases, two timed practice sets

Worked example: splitting 40 hours by weight. Multiply each weight by 40 hours:

  • Domain 1: 40 x 0.24 = 9.6 hours
  • Domain 2: 40 x 0.173 = 6.92, so 6.9 hours
  • Domain 3: 40 x 0.20 = 8.0 hours
  • Domain 4: 40 x 0.213 = 8.52, so 8.5 hours
  • Domain 5: 40 x 0.173 = 6.9 hours

That adds up to 39.9 hours, because the rounded weights add to 99.9 percent. Give the spare time, and any extra week you have, to the domain where your practice scores are lowest, not the one you enjoy most.

A worked example of a CC-style risk question

Domain 1 expects you to calculate risk in money terms. You need three formulas:

  • Single loss expectancy (SLE) = asset value x exposure factor
  • Annualised loss expectancy (ALE) = SLE x annualised rate of occurrence (ARO)
  • A control is worth buying when the fall in ALE is larger than the control's yearly cost

Scenario. A small firm's customer database server is valued at ₹20,00,000. A ransomware attack would destroy 40 percent of that value, and the firm expects one such attack every four years. A managed backup and endpoint service costing ₹75,000 a year would cut the expected rate to once in twenty years. Is the service worth it?

  1. SLE = 20,00,000 x 0.40 = ₹8,00,000
  2. ALE now = 8,00,000 x 0.25 = ₹2,00,000 a year
  3. ALE with the control = 8,00,000 x 0.05 = ₹40,000 a year
  4. Saving = 2,00,000 - 40,000 = ₹1,60,000 a year, against a cost of ₹75,000
  5. Net benefit = 1,60,000 - 75,000 = ₹85,000 a year

Yes, the control is worth it. The exam itself uses short scenarios rather than long sums, but if you can do this calculation and then say which treatment it is (risk reduction), you understand what Domain 1 is testing.

How to read a CC scenario question

Most wrong options in a CC question are not silly. They are things a person might do, but not the best thing for the role described. Use four steps:

  1. Role. You are usually an entry-level practitioner. You follow policy, protect people first and escalate.
  2. Goal. What must be protected or achieved: confidentiality of payroll data, keeping a shop online, evidence for a case.
  3. Qualifier. FIRST, BEST, MOST, LEAST and NOT change the answer. FIRST usually means the earliest correct step, often reporting or following the documented procedure.
  4. Best answer. Two options may be true. Pick the one a manager would expect from someone in that role.

Because the exam is adaptive, its length varies between 100 and 125 items and it ends once it is confident of your result. Pace yourself at about a minute an item.

Steps for ISC2 CC exam preparation, from checking the outline to booking with ISC2
Steps for ISC2 CC exam preparation, from checking the outline to booking with ISC2

Why you should never use exam dumps

Sites that sell "real CC questions" are common, and some appear high in search results. Using them breaks ISC2's exam rules and can cost you the certification, and the adaptive format means memorised items rarely help anyway. Practise on original questions written to the published outline, then read the explanation for every wrong answer. That habit is what actually raises your score.

Is the ISC2 CC worth it for freshers in India?

The CC is an entry-level credential, and ISC2's CC certification page says no work experience is required and names IT professionals, career changers and students as the people it is meant for. For a fresher aiming at a SOC analyst, junior security analyst or IT support role with security duties, it shows an employer that you know the vocabulary and the basics. It does not replace hands-on practice: pair it with a home lab, a networking course and, later, a role-based certification. If you are heading towards plants and control systems rather than offices, read our guide to SCADA cybersecurity and IEC 62443 basics, and see why attackers now target production in factory cyberattacks in 2026.

A free course mapped to the 2026 outline

The free ISC2 Certified in Cybersecurity (CC) Exam Prep course follows the five domains of the 1 September 2026 outline in twelve teaching modules, with lessons from ThorTeaches.com, IBM Technology and other educators, original EDWartens notes, worked problems like the ones above, and 148 original practice questions. It is a free course with a verifiable certificate of completion: the certificate has a unique number and a QR code, and anyone can check it on our verification page.

It is preparation only. ISC2, CC and Certified in Cybersecurity are ISC2's marks; EDWartens is not affiliated with ISC2, and the CC itself is earned only by passing ISC2's exam. If you want a broader base first, our free Cybersecurity Fundamentals and Computer Networking and CCNA Prep courses fit before it. When you are ready, start the ISC2 CC exam prep course.

For classroom practice, our PLC course in Bangalore: syllabus and duration sets out what is taught and for how long.

Frequently asked questions

Q: How do I prepare for the ISC2 CC exam in 2026?
A: Study the five domains of the outline effective 1 September 2026, weighting your time by their percentages (24, 17.3, 20, 21.3 and 17.3), practise scenario questions with a role, goal and qualifier method, and book the exam with ISC2. Four to six weeks of steady study is typical for a beginner.

Q: Is the ISC2 CC exam still free?
A: Not for new candidates. ISC2 closed its One Million Certified in Cybersecurity programme to new enrolments on 20 May 2026. People who hold an unexpired exam code from it must schedule and sit the exam by 31 December 2026; everyone else buys the exam from ISC2.

Q: How many questions are on the CC exam and what is the passing score?
A: The exam uses computerized adaptive testing with 100 to 125 items in two hours, and the passing grade is 700 out of 1000 points, according to ISC2's exam outline page read on 11 October 2026.

Q: Does the 2026 CC exam have an AI domain?
A: No. ISC2 says foundational AI concepts are integrated across all five domains, for example data poisoning as an integrity threat and AI agents as identities that need managed access.

Q: Do I need work experience for the ISC2 CC?
A: No. ISC2 states that no work experience is required, which is why the CC is a common first certification for students, freshers and career changers.

Q: Is there a free ISC2 CC prep course with a certificate?
A: Yes. EDWartens' ISC2 Certified in Cybersecurity (CC) Exam Prep is a free course with a verifiable certificate of completion, mapped to the 2026 outline with original practice questions. It is not the ISC2 certification, which only ISC2 awards after its exam.

Learn this, free

The courses that teach this

Every lesson, the written notes and the practice are free with an account. Only the certificate is optional and paid.

Start Your Engineering Career at EDWartens

Join as a Junior Engineer at Wartens Automation Pvt Ltd. Learn PLC and SCADA in our Electronic City classroom on wired PLC panels, and earn a Wartens Experience Certificate. Job guarantee or programme fee refunded (conditions apply). It runs for the six months after you complete the programme. See the placement policy.