ISC2 CC Exam Prep for the 2026 Outline: A Study Plan

The short answer
ISC2 CC exam prep in 2026 means studying the five domains of the outline that took effect on 1 September 2026, practising short scenario questions, and booking the exam directly with ISC2. The Certified in Cybersecurity (CC) exam is adaptive, has 100 to 125 items, lasts two hours and needs 700 out of 1000 to pass. The free exam that made the CC popular in India has ended: ISC2 closed its One Million Certified in Cybersecurity programme to new sign-ups on 20 May 2026, so new candidates now buy the exam from ISC2. A sensible plan for a beginner is four to six weeks of steady study, weighted by the domain percentages, with original practice questions and no exam dumps.
Exam facts in this guide were checked on ISC2's pages on 11 October 2026 (October 2026). ISC2 changes outlines and terms, so check its pages again before you book.
What changed for the CC exam in 2026?
Two things changed this year, and many older blog posts and YouTube playlists in India still describe the old situation.
First, the exam outline. ISC2's CC exam outline page lists a new outline effective 1 September 2026. Security Governance is now a domain of its own, identity and access management has its own domain, and ISC2 says it has integrated foundational AI concepts across all five domains. That means questions about things like poisoned training data (an integrity problem) or AI agents that need accounts and permissions (an access problem), not a separate AI section.
Second, the free voucher. ISC2's One Million Certified in Cybersecurity page says new enrolments closed effective 20 May 2026. If you already hold an exam code from the programme and it has not expired, you must schedule and sit the exam by 31 December 2026; an expired code cannot be reactivated, and no new free seats are issued. In its 22 April 2026 announcement, ISC2 said more than a million people enrolled, more than 570,000 took the course and more than 65,000 earned the CC. From now on the exam is sold like ISC2's other exams, and the fee is paid to ISC2.
CC exam fact (ISC2, read 11 October 2026) | Value |
|---|---|
Outline in force | Effective 1 September 2026 |
Format | Computerized adaptive testing (CAT) |
Items | 100 to 125, multiple choice and advanced item types |
Time | 2 hours |
Passing grade | 700 out of 1000 points |
Languages | English, Chinese, Japanese, German, Spanish |
Work experience needed | None |
Free One Million CC exam | Closed to new sign-ups 20 May 2026; existing unexpired codes must be used by 31 December 2026 |
The five domains and how much each counts
The weights tell you where to spend your hours. A domain that is 24 percent of the exam deserves more time than one that is 17.3 percent, unless you are already strong in it.
Domain (2026 outline) | Weight | What it covers in plain words |
|---|---|---|
1. Security Principles | 24% | CIA triad, authentication and non-repudiation, privacy, risk, controls, ethics |
2. Security Governance | 17.3% | Governance, risk and compliance, business continuity, disaster recovery, awareness, metrics |
3. Identity and Access Management Concepts | 20% | Identity life cycle, least privilege, separation of duties, access models |
4. Networking and Cloud Security Concepts | 21.3% | OSI and TCP/IP, ports, firewalls, segmentation, zero trust, cloud shared responsibility |
5. Security Operations and Incident Response | 17.3% | Data handling, encryption, logging and monitoring, incident response, testing |
ISC2 gives the total as 100 percent. The rounded figures add up to 99.9, which does not matter for planning.

A four-week ISC2 CC study plan
This plan assumes about 40 hours: roughly 10 hours a week for four weeks, which suits a student or someone studying after office hours.
Week | Focus | Practice |
|---|---|---|
1 | How the exam works; Domain 1 Security Principles | Risk calculations; label every control as technical, administrative or physical |
2 | Domain 2 Security Governance; Domain 3 IAM | RTO and RPO problems; an access review of a small team |
3 | Domain 4 Networking and Cloud Security | Ports, private address ranges, a cloud shared responsibility table |
4 | Domain 5 Security Operations and IR; full review | Alert triage, incident phases, two timed practice sets |
Worked example: splitting 40 hours by weight. Multiply each weight by 40 hours:
- Domain 1: 40 x 0.24 = 9.6 hours
- Domain 2: 40 x 0.173 = 6.92, so 6.9 hours
- Domain 3: 40 x 0.20 = 8.0 hours
- Domain 4: 40 x 0.213 = 8.52, so 8.5 hours
- Domain 5: 40 x 0.173 = 6.9 hours
That adds up to 39.9 hours, because the rounded weights add to 99.9 percent. Give the spare time, and any extra week you have, to the domain where your practice scores are lowest, not the one you enjoy most.
A worked example of a CC-style risk question
Domain 1 expects you to calculate risk in money terms. You need three formulas:
- Single loss expectancy (SLE) = asset value x exposure factor
- Annualised loss expectancy (ALE) = SLE x annualised rate of occurrence (ARO)
- A control is worth buying when the fall in ALE is larger than the control's yearly cost
Scenario. A small firm's customer database server is valued at ₹20,00,000. A ransomware attack would destroy 40 percent of that value, and the firm expects one such attack every four years. A managed backup and endpoint service costing ₹75,000 a year would cut the expected rate to once in twenty years. Is the service worth it?
- SLE = 20,00,000 x 0.40 = ₹8,00,000
- ALE now = 8,00,000 x 0.25 = ₹2,00,000 a year
- ALE with the control = 8,00,000 x 0.05 = ₹40,000 a year
- Saving = 2,00,000 - 40,000 = ₹1,60,000 a year, against a cost of ₹75,000
- Net benefit = 1,60,000 - 75,000 = ₹85,000 a year
Yes, the control is worth it. The exam itself uses short scenarios rather than long sums, but if you can do this calculation and then say which treatment it is (risk reduction), you understand what Domain 1 is testing.
How to read a CC scenario question
Most wrong options in a CC question are not silly. They are things a person might do, but not the best thing for the role described. Use four steps:
- Role. You are usually an entry-level practitioner. You follow policy, protect people first and escalate.
- Goal. What must be protected or achieved: confidentiality of payroll data, keeping a shop online, evidence for a case.
- Qualifier. FIRST, BEST, MOST, LEAST and NOT change the answer. FIRST usually means the earliest correct step, often reporting or following the documented procedure.
- Best answer. Two options may be true. Pick the one a manager would expect from someone in that role.
Because the exam is adaptive, its length varies between 100 and 125 items and it ends once it is confident of your result. Pace yourself at about a minute an item.

Why you should never use exam dumps
Sites that sell "real CC questions" are common, and some appear high in search results. Using them breaks ISC2's exam rules and can cost you the certification, and the adaptive format means memorised items rarely help anyway. Practise on original questions written to the published outline, then read the explanation for every wrong answer. That habit is what actually raises your score.
Is the ISC2 CC worth it for freshers in India?
The CC is an entry-level credential, and ISC2's CC certification page says no work experience is required and names IT professionals, career changers and students as the people it is meant for. For a fresher aiming at a SOC analyst, junior security analyst or IT support role with security duties, it shows an employer that you know the vocabulary and the basics. It does not replace hands-on practice: pair it with a home lab, a networking course and, later, a role-based certification. If you are heading towards plants and control systems rather than offices, read our guide to SCADA cybersecurity and IEC 62443 basics, and see why attackers now target production in factory cyberattacks in 2026.
A free course mapped to the 2026 outline
The free ISC2 Certified in Cybersecurity (CC) Exam Prep course follows the five domains of the 1 September 2026 outline in twelve teaching modules, with lessons from ThorTeaches.com, IBM Technology and other educators, original EDWartens notes, worked problems like the ones above, and 148 original practice questions. It is a free course with a verifiable certificate of completion: the certificate has a unique number and a QR code, and anyone can check it on our verification page.
It is preparation only. ISC2, CC and Certified in Cybersecurity are ISC2's marks; EDWartens is not affiliated with ISC2, and the CC itself is earned only by passing ISC2's exam. If you want a broader base first, our free Cybersecurity Fundamentals and Computer Networking and CCNA Prep courses fit before it. When you are ready, start the ISC2 CC exam prep course.
For classroom practice, our PLC course in Bangalore: syllabus and duration sets out what is taught and for how long.
Frequently asked questions
Q: How do I prepare for the ISC2 CC exam in 2026?
A: Study the five domains of the outline effective 1 September 2026, weighting your time by their percentages (24, 17.3, 20, 21.3 and 17.3), practise scenario questions with a role, goal and qualifier method, and book the exam with ISC2. Four to six weeks of steady study is typical for a beginner.
Q: Is the ISC2 CC exam still free?
A: Not for new candidates. ISC2 closed its One Million Certified in Cybersecurity programme to new enrolments on 20 May 2026. People who hold an unexpired exam code from it must schedule and sit the exam by 31 December 2026; everyone else buys the exam from ISC2.
Q: How many questions are on the CC exam and what is the passing score?
A: The exam uses computerized adaptive testing with 100 to 125 items in two hours, and the passing grade is 700 out of 1000 points, according to ISC2's exam outline page read on 11 October 2026.
Q: Does the 2026 CC exam have an AI domain?
A: No. ISC2 says foundational AI concepts are integrated across all five domains, for example data poisoning as an integrity threat and AI agents as identities that need managed access.
Q: Do I need work experience for the ISC2 CC?
A: No. ISC2 states that no work experience is required, which is why the CC is a common first certification for students, freshers and career changers.
Q: Is there a free ISC2 CC prep course with a certificate?
A: Yes. EDWartens' ISC2 Certified in Cybersecurity (CC) Exam Prep is a free course with a verifiable certificate of completion, mapped to the 2026 outline with original practice questions. It is not the ISC2 certification, which only ISC2 awards after its exam.
Learn this, free
The courses that teach this
Every lesson, the written notes and the practice are free with an account. Only the certificate is optional and paid.




