ISC2 CGRC Certification Guide 2026: Exam, Cost & Career
Updated August 2, 202625+ min read

ISC2 CGRC Certification: Your Complete Decision Guide

Exam domains, eligibility paths, preparation strategies, costs, and career outcomes for the Certified in Governance, Risk and Compliance credential.

What you’ll learn in this article…

  • ISC2 CGRC requires two years of RMF or authorization experience or an associate path.
  • The exam costs $599 with 125 questions, a 700 passing score, and a three-hour limit.
  • BLS projects 32.7% growth for information security analysts through 2033.

Governance, risk, and compliance roles inside federal agencies and defense contractors increasingly require a credential that validates the ability to operate within the Risk Management Framework (RMF). The ISC2 Certified in Governance, Risk and Compliance (CGRC) fills that role.

Originally launched as the Certified Authorization Professional (CAP), ISC2 rebranded the credential in 2023 to better reflect its broader GRC scope, yet the exam still centers on authorization and continuous monitoring.1

The credential's associate pathway opens doors for early-career professionals, but full certification demands two years of relevant work experience. This forces many candidates to weigh the investment against immediate job placement. With federal adoption of the RMF expanding into cloud and supply chain security, CGRC holders increasingly appear on shortlists for roles that did not exist five years ago.

CGRC Credential Snapshot

Earning a governance, risk, and compliance credential before gaining deep hands-on experience versus waiting until you have years of authorization work under your belt: both paths are viable with the CGRC, because ISC2 offers an associate option alongside the full certification. The snapshot below captures every detail you need for budgeting, scheduling, and deciding whether the timeline fits your career plan.

At a Glance

  • Full name: Certified in Governance, Risk and Compliance (CGRC)
  • Issuing body: ISC2
  • Exam fee: $599
  • Exam length: 180 minutes (3 hours)
  • Total items: 125 questions (100 scored, 25 unscored pretest items)3
  • Passing score: 700 on a 1,000-point scale
  • Domains covered: 7
  • Experience requirement: 2 years of cumulative, paid work experience in one or more of the seven CGRC domains
  • Associate path available: Yes, candidates who pass the exam without the required experience have 3 years to earn it
  • Renewal cycle: Every 3 years
  • CPE credits per cycle: 603
  • Annual maintenance fee (AMF): $135
  • Delivery mode: In-person testing at Pearson VUE centers
  • Current exam outline effective date: June 15, 2024

Key Takeaways From the Snapshot

The two-year experience threshold is lower than what ISC2 requires for the CISSP (five years), making the CGRC more accessible for professionals earlier in a GRC-focused career.3 The associate path adds flexibility: you can sit for the exam while still building qualifying experience, provided you complete it within the three-year window.

Budget-wise, plan for the $599 exam fee plus $135 per year in maintenance fees once certified. Training costs sit on top of those figures and vary widely depending on whether you choose official ISC2 courseware, independent study materials, or employer-sponsored programs. A later section of this guide breaks down total cost in detail.

All specifications listed above were verified against the official ISC2 CGRC certification page1 and the current exam outline2. If ISC2 updates pricing, domains, or testing policies after this verification, onlinecybersecurity.org will reflect those changes in the exam-change tracker.

What the CGRC Validates and Why It Exists

The CGRC certification is not a general cybersecurity credential; it is a focused validation of skills in security authorization, continuous monitoring, and risk management framework (RMF) execution. Organizations that must comply with federal security standards need professionals who can translate policy into auditable controls, and the CGRC confirms exactly that capability.

From CAP to CGRC: A Rebrand That Reflects the Work

In 2023, ISC2 renamed the Certified Authorization Professional (CAP) to Governance, Risk and Compliance (CGRC) to better capture the credential's real-world scope. The change was not cosmetic. While the CAP name emphasized the authorization step, practitioners were already performing a broader set of GRC responsibilities, assessing controls, monitoring system security status, and managing compliance documentation. The CGRC title and updated exam content align more closely with how these roles function in agencies, cloud service providers, and defense contractors today.

Frameworks and Federal Alignment

The CGRC maps directly to the NIST Risk Management Framework (RMF), the Federal Risk and Authorization Management Program (FedRAMP), the Federal Information Security Modernization Act (FISMA), and Department of Defense (DoD) RMF requirements. This is heavily U.S. federal and DoD-aligned work. If your career track involves delivering authorization packages, maintaining system security plans, or performing continuous monitoring under these mandates, the CGRC validates your ability to execute those processes correctly.

CGRC vs. CISSP: Depth Versus Breadth

The CISSP covers eight broad security domains and is designed for general security management. The CGRC, in contrast, plunges deep into the authorization and controls lifecycle. It does not test general network security, identity management, or software development security at the CISSP level. Instead, it expects you to know how to select, assess, and monitor security controls; document risk determinations; and manage Plan of Action and Milestones (POA&M) items. For professionals who live inside the RMF workflow, the CGRC is the credential that speaks directly to that specialty.

Eligibility, Prerequisites, and the Associate Path

As regulatory mandates tighten around software supply chains, cloud security, and critical infrastructure, the demand for professionals who can interpret and apply frameworks like NIST risk management is growing steeply. The CGRC certification addresses precisely that need, but it comes with defined eligibility criteria that separate it from entry-level credentials. Understanding these requirements upfront helps you decide whether to pursue the certification now or plan a phased approach through the Associate of ISC2 pathway.

Experience Requirement

The formal requirement is set out in ISC2's CGRC experience requirements: a minimum of two years of cumulative, paid, full-time work experience in at least one of the seven CGRC domains. Full-time is defined as 35 hours per week. Part-time work counts if it falls between 20 and 34 hours per week; 1,040 hours of part-time experience equates to six months of full-time credit, and 2,080 hours equates to one year. The experience must be accumulated within the 10 years prior to your application, and it must be verifiable by an endorsing ISC2 certification holder or through the ISC2 endorsement process. The seven domains that qualify are: Security and Privacy Governance, Risk Management and Compliance Program; Scope of the System; Selection and Approval of Framework, Security and Privacy Controls; Implementation of Security and Privacy Controls; Assessment/Audit of Security and Privacy Controls; System Compliance; and Compliance Maintenance. You do not need experience in all seven; any combination counts as long as the work maps to at least one domain.

Degree Substitution

If you hold a four-year cybersecurity bachelor's degree (or a degree in information technology, computer science, or a closely related field), ISC2 allows you to substitute one year of the required work experience. A master's degree in a similar discipline also satisfies the one-year reduction. The degree substitution cannot be combined with other experience waivers, and the degree must be regionally accredited or equivalent. This means a candidate with a relevant bachelor's degree may only need one year of paid experience in the CGRC domains to meet the full eligibility.

Associate of ISC2 Pathway

Passing the CGRC exam without the requisite experience is permitted, and it leads to the Associate of ISC2 designation. After you pass the exam, you have three years to earn the two years of required work experience (or one year if you qualify for degree substitution). During that window, you can use the Associate title on your résumé and gain professional experience while preparing for full certification. Once the experience is accrued, you submit an endorsement application and pay the annual maintenance fee to earn full CGRC certification. This pathway is especially useful for career changers or early-career professionals who want to demonstrate knowledge early while building hands-on practice.

Recommended Background (Not a Prerequisite)

Finally, it is worth clarifying what ISC2 recommends but does not require. The CGRC exam is heavily rooted in U.S. federal standards, particularly NIST Special Publication 800-37 (Risk Management Framework) and NIST SP 800-53 (Security and Privacy Controls). Familiarity with these publications, along with an understanding of authorization and assessment processes, will substantially ease your exam preparation. However, no specific training, degrees, or certifications are mandatory before taking the exam. The official guidance simply encourages candidates to be comfortable with the language and logic of governance, risk, and compliance as practiced in regulated environments.

Exam Format, Domains, Scoring, and Testing Options

The CGRC exam tests your ability to apply governance, risk, and compliance principles across the authorization lifecycle. It is a linear, multiple-choice exam delivered through Pearson VUE, with 125 questions and a three-hour time limit. The passing score is 700 out of 1000.1 The current exam outline took effect June 15, 2024, and includes seven domains.3 Below is a detailed look at what to expect, including domain emphasis, delivery logistics, and retake rules.

Domain-by-Domain Breakdown

The exam covers seven domains, each weighted to reflect its importance in the role.1 Below is each domain's name, weight, and the core skill it assesses.

  • Security and Privacy Governance, Risk Management, and Compliance Program (16%): Establishes the foundational program structure, policies, and risk appetite that guide the rest of the authorization process.
  • Scope of the System (10%): Defines the boundaries, data flows, and stakeholders for the system undergoing assessment.
  • Selection and Approval of Framework, Security, and Privacy Controls (14%): Identifies and tailors the appropriate control sets based on system categorization and organizational requirements.
  • Implementation of Security and Privacy Controls (17%): Ensures controls are correctly deployed, documented, and integrated into system operations.
  • Assessment/Audit of Security and Privacy Controls (16%): Validates control effectiveness through testing, documentation review, and evidence collection.
  • System Compliance (14%): Evaluates the overall compliance status and prepares the authorization decision package.
  • Compliance Maintenance (13%): Manages ongoing monitoring, configuration changes, and periodic re-assessment to maintain authorization.

To visualize the relative emphasis, the heaviest domains are Implementation of Security and Privacy Controls (17%), Security and Privacy Governance, Risk Management, and Compliance Program (16%), and Assessment/Audit of Security and Privacy Controls (16%). Together, these three domains account for nearly half the exam.

Exam Structure and Scoring

The CGRC exam is linear, not adaptive. You will face 125 multiple-choice questions over three hours. The passing score is a scaled 700 out of 1000. Unscored pretest questions may be included but do not affect your result. Because the exam is non-adaptive, you can flag and review questions within the allotted time.

Testing Delivery and Retake Policy

You can take the exam at a Pearson VUE test center or through online proctoring via OnVUE; our Online Cybersecurity Exams: Proctoring and Retakes guide covers what to expect with online delivery. Both options deliver identical content and timing. Ensure your testing environment meets Pearson VUE's technical and privacy requirements if you choose the online route.

If you don't pass, ISC2 enforces mandatory waiting periods: 30 days after the first attempt, 90 days after a second failure, and 180 days after a third. You are limited to three attempts per calendar year, and ISC2 does not offer score verification.2 Plan your preparation carefully with a structured Cybersecurity Certification Study Plan for Working Adults to avoid unnecessary delays.

Full Cost Breakdown: Exam, Training, and Renewal Fees

Certification budgeting has become more transparent across the industry, yet many candidates still underestimate the full financial commitment beyond the initial exam voucher. For the CGRC, understanding the full cybersecurity certification cost helps you plan your cybersecurity certification roadmaps realistically and identify where employer support or self-study strategies can reduce out-of-pocket expenses.

Exam Voucher and Regional Pricing

The CGRC exam costs $599 in the United States as of 2026.1 ISC2 offers regional pricing for international candidates: 555 EUR in the Eurozone and 479 GBP in the United Kingdom. These prices cover a single exam attempt at a Pearson VUE testing center or through online proctoring where available.

Retake fees match the original exam price. If you do not pass on your first attempt, you will pay another $599 (or regional equivalent) for each subsequent try. ISC2 does not offer discounted retakes, so thorough preparation before scheduling matters financially as well as professionally.

Annual Maintenance Fee

Once certified, you pay an Annual Maintenance Fee (AMF) to keep your credential active. For the full CGRC certification, the AMF is $135 per year.3 If you pass the exam but do not yet have the required experience, you earn the Associate of ISC2 designation, which carries a lower AMF of $50 per year3 until you meet the experience threshold and convert to full certification.

Over a three-year certification cycle, a fully credentialed CGRC holder pays $405 in maintenance fees alone.

Training Cost Tiers

Training investments vary widely based on your learning preferences and budget:

  • Official ISC2 self-paced training: ISC2 offers self-paced online courses covering the CGRC domains. Pricing for official courseware typically ranges from $1,500 to $2,500 depending on bundled materials and practice exam access.3
  • Third-party instructor-led or online courses: Providers offer CGRC preparation programs ranging from $1,000 to $3,0003. These courses vary in depth, with some including live instruction, recorded lectures, or hands-on labs.
  • Self-study with books and practice exams: The most budget-friendly approach, typically costing $100 to $300 for study guides, reference materials, and independent practice exam subscriptions.

Three-Year Total Cost of Ownership

Here is a realistic breakdown of what you might spend over the full certification cycle:

  • Exam fee: $599
  • AMF (Year 1, 2, 3): $405 total
  • Training (self-study): $100 to $300
  • Training (third-party course): $1,000 to $3,000
  • Training (official ISC2): $1,500 to $2,500

Total three-year investment ranges from approximately $1,100 for a disciplined self-studier to $3,500 or more for someone using official or premium third-party training.

Employer Reimbursement as a Practical Offset

Many federal contractors, government agencies, and large enterprises cover ISC2 certification costs as part of workforce development programs. If you work in a role supporting federal systems, particularly those operating under the Risk Management Framework, your employer may reimburse the exam fee, training expenses, and even the annual maintenance fee. Before paying out of pocket, check whether your organization offers certification incentives or tuition assistance programs. For candidates pursuing GRC roles in the defense or federal contracting space, employer-sponsored certification is common enough to be worth asking about during onboarding or performance reviews.

How to Prepare: Study Plan, Resources, and Difficulty

The CGRC exam rewards structured preparation that follows domain weights rather than random study sessions. Candidates who map their study hours to the seven exam domains and leverage both official and third-party resources, following approaches described in How to Prepare for a Cybersecurity Certification Exam, consistently report stronger outcomes than those who rely on a single textbook or course.

Domain-Mapped Study Plan

Allocate study time proportionally to domain weight and difficulty. Here is a recommended breakdown for a candidate with some GRC background:

  • Domain 1 (Information Security Risk Management Program, 16%): 12 to 15 hours. Start here because risk management concepts underpin every other domain.
  • Domain 2 (Scope of the Information System, 11%): 8 to 10 hours. System boundary definition requires precision but draws on foundational risk concepts.
  • Domain 3 (Selection and Approval of Security and Privacy Controls, 15%): 12 to 14 hours. Control selection aligns closely with NIST 800-53; expect detailed memorization.
  • Domain 4 (Implementation of Security and Privacy Controls, 15%): 12 to 14 hours. Hands-on implementation scenarios appear frequently.
  • Domain 5 (Assessment/Audit of Security and Privacy Controls, 16%): 14 to 16 hours. This is often cited as the most technically dense domain.
  • Domain 6 (Authorization/Approval of Information Systems, 10%): 8 to 10 hours. Authorization packages and decision processes require attention to procedural detail.
  • Domain 7 (Continuous Monitoring, 17%): 14 to 16 hours. The largest domain by weight; prioritize ongoing assessment and reporting cycles.

Total study hours for a GRC professional: 80 to 100 hours over 8 to 12 weeks.

Official ISC2 Resources

ISC2 offers an official training course delivered as an online self-paced program1. The course includes adaptive learning modules, eBooks, a glossary, flashcards, and practice tests1. ISC2 recommends supplementing official flashcards with community Quizlet sets for additional repetition1. As of 2026, an official CGRC Common Body of Knowledge book has not been confirmed as published2. Candidates should check the ISC2 website directly for updates on official study guides.

Third-Party Study Materials

Several third-party options fill gaps in official materials:

  • Practice exams: The CGRCExam question bank includes 1,000 questions3. CareerEmployer's CGRC practice test offers a free 270-question practice test with checkpoint quizzes and flashcards. Crucial Exams' CGRC practice tests provide 174 flashcards across 5 decks.
  • Comprehensive guides: The CGRC Study Guide 2026-2027 (Complete) includes 1,500 questions and 10 full-length practice tests4.
  • Online courses: Udemy, LinkedIn Learning, and Infosec Institute offer CGRC preparation courses with video instruction and lab exercises5.
  • Community resources: The CareerEmployer study guide covers exam domains with checkpoint quizzes and is available free6. Reddit communities, particularly r/isc2, share study plans, resource recommendations, and recent test-taker experiences2.

Realistic Difficulty Assessment

The CGRC is narrower than CISSP but demands deep technical knowledge of the Risk Management Framework. Compared to CISA, which emphasizes audit methodology across diverse IT environments, the CGRC focuses specifically on federal authorization processes, NIST publications, and continuous monitoring cycles. Candidates familiar with NIST 800-37, 800-53, and 800-53A will find the material more accessible. Those without direct RMF experience should expect a steeper learning curve than CISA but less breadth than CISSP (for a detailed comparison, see Compare Cybersecurity Certifications Side by Side).

Candidates with a GRC background who commit 10 to 12 hours weekly can realistically prepare in 8 to 12 weeks. Career changers should extend the timeline to 16 weeks or longer, prioritizing foundational NIST documentation before tackling domain-specific content.

CGRC Salary and Job-Role Alignment

The CGRC certification maps directly to roles embedded in formal risk management and authorization workflows, particularly within federal agencies, defense contractors, and FedRAMP cloud service providers. While role-specific salary data tied exclusively to CGRC holders is not publicly reported by ISC2 or federal labor sources, the Bureau of Labor Statistics provides a useful baseline through the Information Security Analysts occupation, which encompasses many of the positions CGRC holders fill. The national median annual wage for this occupation was $124,910 as of the most recent BLS data, with top-quartile earners exceeding $159,600.

Job TitleScope of PracticeTypical Employer TypesBLS Occupation AlignmentNational Median Salary (BLS)
Information System Security Officer (ISSO)RMF control implementation, continuous monitoring, POA&M management, ATO supportFederal agencies, defense contractors, cleared facilitiesInformation Security Analysts$124,910
Security Control AssessorControl assessments, security audits, RMF and FedRAMP evaluationsThird-party assessment organizations (3PAOs), federal agencies, consulting firmsInformation Security Analysts$124,910
GRC AnalystPolicy maintenance, risk registers, evidence collection, control mapping, audit supportDefense contractors, regulated enterprises, managed security providersInformation Security Analysts$124,910
Compliance AnalystRegulatory framework compliance, control assurance across FedRAMP, HIPAA, SOX, and CMMCHealthcare systems, financial institutions, cloud service providersInformation Security Analysts$124,910
Authorization OfficialSystem authorization decisions, risk acceptance, oversight of security posture documentationFederal civilian and DoD agenciesInformation Security Analysts$124,910

Top-Paying States for Information Security Analysts

Geographic location has a significant impact on information security analyst salaries. The table below ranks the ten highest-paying states by median annual wage, based on 2024 data from the Bureau of Labor Statistics Occupational Employment and Wage Statistics program. States with large federal and defense contractor footprints, major tech hubs, or high costs of living consistently top the list, which is worth factoring into your career planning alongside remote work availability.

StateTotal EmploymentMedian Annual Wage25th Percentile Wage75th Percentile WageMean Annual Wage
Washington6,830$142,920$117,040$169,350$144,140
California15,800$140,660$105,150$178,090$152,640
Maryland8,770$140,480$105,230$175,390$145,450
New Jersey4,730$135,390$108,320$168,240$141,130
Delaware630$134,050$105,310$154,060$130,860
New Mexico1,760$133,780$101,940$166,300$131,220
Virginia18,670$132,460$101,610$166,510$136,680
New York8,860$131,100$98,320$170,220$139,540
Colorado5,840$130,570$102,350$164,010$135,980
Connecticut1,160$130,500$95,260$152,410$127,740
Did You Know?

The Bureau of Labor Statistics projects a 32.7% growth for Information Security Analysts from 2023 to 2033, translating to about 16,000 annual openings. The CGRC credential specializes in governance, risk, and compliance, directly linking to this demand. Federal initiatives like CMMC and FedRAMP expansion further amplify the need for authorization-focused professionals.

Renewal, CPE Requirements, and Expiration Rules

Maintaining a CGRC certification demands consistent effort; some professionals prefer to log a steady stream of CPEs throughout the year, while others find themselves scrambling in the final months of the three-year cycle. A little upfront planning, along with resources like our Cybersecurity Certifications and Online Training: The Complete Guide, makes the process painless.

The Three-Year Cycle and CPE Requirements

Your CGRC credential is valid for three years. To renew, you must earn a total of 60 Continuing Professional Education credits, with at least 45 coming from Group A activities, those directly related to the exam domains, and up to 15 from Group B activities, which cover broader professional development1. ISC2 recommends spreading the workload evenly by completing around 20 CPEs each year, including about 15 Group A credits annually2. This keeps you current without a last-minute crunch.

Annual Maintenance Fee and Grace Periods

An Annual Maintenance Fee of $135 is required to keep your certification active. This is separate from CPE submission and is billed each year on your certification anniversary date. If you hold Associate status, the fee is lower at $50 per year1. ISC2 provides a 90-day grace period for both CPE completion3 and AMF payment4. If you miss the deadline, your certification goes into suspension4. During suspension you must stop using the credential, but you can still reinstate it by meeting the missing requirements and paying any late fees. After a longer period of inactivity, you may need to reapply and pass the current exam to regain the certification.

Earning CPEs: Activities and Limits

Most CPE activities are credited at a rate of 1 CPE per hour of engagement. Here are examples of qualifying activities with their approximate credit values and any caps:

  • Instructor-led CGRC training: Completing the official ISC2 course can earn up to 40 CPEs at once, a significant head start on your cycle1.
  • Webinars and conferences: Attending live or recorded sessions earns 1 CPE per hour. ISC2 itself offers many free webinars2.
  • Self-study: Reading books, magazines, or whitepapers counts but has caps. Books and magazines are capped at 5 CPEs each per cycle, while whitepapers are limited to 1 CPE per paper2.
  • Publishing and presenting: Authoring articles, blog posts, or delivering conference talks can earn credits, subject to a single-submission cap of 40 CPEs2.
  • Volunteer work and education: Teaching, mentoring, or completing relevant college courses also qualify2.

All submissions must be documented and retained in case of an audit. By mixing activities you can meet both the Group A and Group B requirements while genuinely advancing your expertise, and the All Cybersecurity Certifications Directory can guide you toward your next credential.

CGRC Vs. CISA Vs. CRISC: Which GRC Cert Fits You?

Selecting the right GRC credential is less about brand recognition and more about which daily work you want to own: authorization packages, audit reports, or risk registers. CGRC from ISC2, CISA and CRISC from ISACA each validate distinct expertise, and the differences in experience requirements, exam design, and maintenance costs will guide you to the one that aligns with your career stage.

Core Focus and Typical Role

The CGRC, formerly known as CAP, is built for governance, risk, and compliance analysts who spend their days assessing security controls, managing RMF lifecycles, and supporting systems authorization. It fits roles like information system security officer, compliance analyst, and authorization specialist. The CISA, on the other hand, is the definitive IT audit certification (CISA Certification Guide), designed for professionals who evaluate controls, conduct audits, and report on IT systems assurance. CRISC targets risk management practitioners, people who identify risk, design and implement controls, and own enterprise risk management (see the CRISC Certification Guide). Choose CGRC for compliance authorization, CISA for audit, and CRISC for hands-on risk management.

Experience and Entry Points

Work experience requirements set these certs apart sharply. The CGRC has no mandatory work experience4; candidates can sit for the exam and earn the full credential once they document the required practical experience, making it more accessible for early-career GRC professionals than certifications with strict cybersecurity certification work experience requirements. CISA demands 5 years of professional IS audit, control, or security experience2, and CRISC requires 3 years of relevant work in IT risk management3, with both ISACA certifications allowing some experience substitutions. If you are newer to the field, the CGRC gives you a direct path to recognized status.

Exam Format, Cost, and Renewal

The CGRC exam consists of 125 questions delivered over 3 hours, with a passing score of 700 out of 1000 and an exam fee of $599.1 Both CISA2 and CRISC3 use 150 questions over 4 hours, scoring on an 800-point scale with a 450 passing mark; exam fees fall between $575 and $760 depending on membership status. Annual maintenance also differs: CGRC holders pay $135 per year and need 60 CPE credits every 3 years.1 ISACA certifications require 120 CPE credits over the same 3-year cycle but charge a lower annual maintenance fee, typically $45 to $85.1 This means the CGRC carries a higher yearly cost but a lighter continuing education load.

Deciding Factor: Your Career Target

If you work within NIST frameworks, RMF, and security control assessments, the CGRC is the most precise fit. CISA is the standard for anyone moving into IT auditing or assurance consulting. CRISC is the credential for those managing risk registers, control design, and enterprise risk strategy. Your current or desired role title (auditor, risk manager, or compliance/authorization specialist) will tell you which exam to study for. All three hold strong recognition across government, finance, and technology sectors, and each helps you build your career as a cybersecurity professional.

Editorial Verdict by Learner Profile

Governance, risk, and compliance has moved from a back-office function to a frontline cybersecurity discipline, and that shift is reshaping which credentials genuinely open doors.

For Career Changers with No IT Background

The CGRC is not a suitable starting point. It assumes working knowledge of authorization processes, security control frameworks, and organizational risk management that someone new to technology simply does not have. Pursuing it without at least a year of hands-on GRC exposure will likely lead to frustration and a failed exam attempt. Instead, build foundational technical literacy with CompTIA Security+ Certification or ISC2's entry-level ISC2 Certified in Cybersecurity (CC). Once you have secured a compliance-adjacent role, such as junior policy analyst, audit support, or IT governance coordinator, then return to the CGRC as a natural step after 1, 2 years of experience.

For Early IT Professionals (1, 3 Years)

If you are already working in a federal, defense, or highly regulated environment where you touch RMF steps, security controls, or continuous monitoring, the CGRC becomes a realistic and career-accelerating target. The Associate of ISC2 path removes the immediate experience barrier: you can pass the exam now, earn the associate designation, and gain the required work experience while holding that status. This route is especially practical for system administrators, IT auditors, and junior security analysts who see their career trajectory bending toward compliance and authorization work.

For Working Cybersecurity Practitioners

When your current role already includes tasks such as supporting Authority to Operate (ATO) packages, conducting security control assessments, or managing Plan of Action and Milestones (POA&M) items, the CGRC directly validates that expertise. It carries particular weight in federal contracting and consulting, where the credential often appears as a contractual requirement. For SOC analysts or incident responders looking to broaden into risk management, the CGRC offers a structured way to signal competence in governance without pivoting entirely away from technical work.

For Experienced Managers and CISOs

At this level, the CGRC is less about breaking into the field and more about proving specialized depth that complements a broad credential like CISSP. If your responsibilities include overseeing ATO processes, cloud service provider authorization under FedRAMP, or internal control assessment programs, the CGRC tells auditors, regulators, and employers that you possess focused, verifiable knowledge in authorization and continuous monitoring, not just general security management. It is a resume differentiator for senior leaders who need to speak the detailed language of compliance while setting strategic direction.

Frequently Asked Questions About the CGRC Certification

Below are the most common questions prospective candidates ask before investing in the CGRC. Each answer reflects the latest publicly available information from ISC2 as of 2026.

The CGRC, or Certified in Governance, Risk and Compliance, is a vendor-neutral certification issued by ISC2 and accredited by ANAB to the ISO/IEC 17024 standard.1 It is designed for practitioners who authorize and maintain information systems, assess security controls, and manage governance, risk, and compliance workflows. Common holders include security control assessors, authorization officials, and GRC analysts working in federal or regulated environments.

Yes. ISC2 rebranded the CAP (Certified Authorization Professional) as the CGRC to better reflect the credential's broader scope across governance, risk, and compliance. The exam content was updated during the transition, but candidates who held an active CAP were automatically transitioned to the CGRC designation without needing to retest.1

You can sit for the exam without meeting the experience requirement. If you pass, ISC2 grants you the Associate of ISC2 designation. You then have three years3 to earn the required professional experience and complete the full certification endorsement process.1 During the associate period, you pay a reduced annual maintenance fee of $50.2

The exam fee is $5993, paid at registration through Pearson VUE. If you need to reschedule, expect an additional $50 fee2; cancellation costs $1002. Once certified, you also pay an annual maintenance fee of $1352 to keep your credential active. Factor in optional training courses and study materials, which can range from a few hundred dollars for self-study to over $2,000 for instructor-led prep.

The CGRC exam contains 125 questions with a three-hour time limit3 and requires a scaled score of 700 out of 1,000 to pass.4 It is narrower in scope than the CISA, focusing heavily on authorization frameworks, control assessment, and continuous monitoring. Many candidates find it more approachable than the CISA if they already work within RMF or similar compliance frameworks, though it demands deep, specific knowledge in those areas.

You need a minimum of two years of cumulative, paid work experience in at least one of the CGRC exam domains.3 Qualifying roles include security control assessment, risk management framework implementation, authorization support, and compliance monitoring. A four-year degree or an approved ISC2 credential can substitute for one year of the requirement.1

CGRC holders must earn 60 Continuing Professional Education (CPE) credits over each three-year certification cycle3, with a minimum of 20 credits submitted per year. Qualifying activities include attending conferences, completing training, publishing research, or volunteering in cybersecurity.1 You must also pay the $135 annual maintenance fee each year to keep your certification in good standing.2

Recent Articles

In this article

Follow us