The Answer Up Front
Take ISC2 CC first if you have little or no IT experience, want the lower exam price, or want a structured foundation before an applied exam. Take CompTIA Security+ first if your target postings name Security+, you already understand networking and systems, or you want an exam that includes performance-based questions.
Do not choose Security+ solely because an old comparison says CC is not recognized under DoD 8140. That claim is now wrong. Both CC and Security+ are approved under DoDM 8140.03, but approval is tied to a specific DoD Cyber Workforce Framework work role and proficiency level. The correct compliance question is not which badge is generally approved; it is which qualification the exact position accepts.
Two other 2026 updates change the decision. ISC2's One Million Certified in Cybersecurity program closed to new public enrollments on May 20, 2026, so CC is no longer a universally free option. Also, CC uses computerized adaptive testing and will change outlines on September 1, 2026. Security+ remains SY0-701 on CompTIA's current page; CompTIA has not published a successor code or firm retirement date.
Current CC vs Security+ Comparison
| Decision factor | ISC2 CC | CompTIA Security+ SY0-701 |
|---|---|---|
| Intended starting point | Entry or junior level; no work experience required | Early-career security; Network+ and two years in security or systems administration are recommended, not required |
| Current US exam price | US$199 in ISC2's listed US-dollar regions | $439 for the US voucher currently listed by CompTIA |
| Current format | CAT, 100–125 multiple-choice and advanced items, two hours | Up to 90 multiple-choice and performance-based questions, 90 minutes |
| Passing score | 700 out of 1000 | 750 on a 100–900 scale |
| Current outline | October 1, 2025 outline through August 31, 2026 | SY0-701, launched November 7, 2023 |
| Announced change | New five-domain outline effective September 1, 2026 | No public successor code or firm retirement date; current page says retirement is estimated in 2026 |
| DoDM 8140.03 | Approved; verify role and level | Approved for listed DCWF roles; verify role and level |
| Renewal | 45 CPE credits per three years plus $50 AMF annually | Valid three years; 50 CEUs or another approved route; CEU route has a $150 cycle fee |
Prices are current US-facing vendor listings as checked August 10, 2026. Regional prices, taxes, training bundles, retakes, and discounts can differ, so confirm the checkout page before paying.
What Changed Since Earlier 2026 Comparisons
1. The free CC enrollment window has closed
ISC2 concluded new public enrollment in the One Million Certified in Cybersecurity program on May 20, 2026. Its conclusion notice says people with unexpired program exam codes may schedule and take the exam through December 31, 2026. Existing course access remains available until its own expiration, and completing that course is not required to sit the exam.
That distinction matters:
- No program code: budget the regular CC exam price, currently US$199 in ISC2's listed US-dollar regions.
- Valid 1MCC exam code: use it before its expiration and no later than December 31, 2026.
- Already certified: the program's closure does not cancel your credential; normal CC maintenance rules apply.
ISC2 reported that more than one million people in 178 countries received program access and more than 65,000 earned CC. Those numbers describe the concluded initiative, not a current free-enrollment offer.
2. CC is DoD 8140 approved
ISC2's current CC page labels the certification U.S. DoDM 8140.03 approved, and ISC2's published mapping says CC appears across 20 work roles. The earlier statement that CC was not a DoD baseline confused the retired DoD 8570 approach with the role-based 8140 marketplace.
Security+ also remains approved. CompTIA's current framework page lists it for roles including Technical Support Specialist (411), Network Operations Specialist (441), System Administrator (451), Cyber Defense Analyst (511), Cyber Defense Incident Responder (531), Vulnerability Assessment Analyst (541), and others.
These lists do not mean every CC or Security+ holder qualifies for every DoD job. A position is coded to a DCWF role and proficiency level, and a certification can be one foundational qualification option. Before buying either exam for compliance, ask the employer for the role code and level, then check the current official qualification matrix.
3. CC is adaptive, not a fixed 100-question multiple-choice exam
ISC2's current outline and CAT guidance specify 100–125 items in two hours, using multiple-choice and advanced item types. The CAT system changes question difficulty based on responses. At least 100 items are administered, including 25 unscored pretest items that candidates cannot identify.
You cannot treat CC as a simple fixed-form recognition test. Its content is foundational, but the adaptive delivery and best-answer scenarios reward consistent understanding across all domains.
4. Current Security+ pricing is $439
CompTIA's current US product data lists the Security+ voucher at $439, not the $404 or $425 figures still repeated by older comparisons. A retake bundle and official learning products cost more. If price drives the decision, compare the actual cart total rather than an old article.
Which CC Outline Applies to Your Test Date?
Your appointment date determines what to study.
Testing through August 31, 2026
The October 1, 2025 CC outline uses these weights:
- Security Principles: 26%
- Business Continuity, Disaster Recovery and Incident Response Concepts: 10%
- Access Controls Concepts: 22%
- Network Security: 24%
- Security Operations: 18%
Testing September 1, 2026 or later
The redesigned outline uses:
- Security Principles: 24%
- Security Governance: 17.3%
- Identity and Access Management Concepts: 20%
- Networking and Cloud Security Concepts: 21.3%
- Security Operations and Incident Response: 17.3%
The new outline also integrates foundational AI-security concepts across the domains. Do not mix two blueprints by accident. Download the official outline for your appointment date, then map every study resource and practice result to those domain names and weights.
The exam mechanics remain two hours, 100–125 items, multiple-choice and advanced item types, and a 700-of-1000 passing score.
Security+ Transition: What Is Confirmed and What Is Rumor
As of August 10, 2026, CompTIA's official Security+ page still identifies SY0-701 as the current series. It lists a November 7, 2023 launch and says retirement is usually three years after launch, with 2026 shown only as an estimate. It does not publish a successor exam code or a firm retirement date.
That means claims about an exact SY0-801 launch or SY0-701 retirement are not official facts yet. Use this rule:
- If you are preparing now, study the current SY0-701 objectives.
- Before buying or scheduling, recheck the official Security+ page for an announced overlap or retirement date.
- If a successor appears, compare its objectives and the last date SY0-701 can be taken before choosing.
- Do not postpone a ready attempt because of an unconfirmed version rumor.
Passing SY0-701 earns the Security+ certification. The credential is valid for three years; an eventual exam update does not shorten an already-earned certification cycle.
Cost and Maintenance: Compare the Whole Cycle
ISC2 CC
The current standard exam fee is US$199 for the Americas and other regions in ISC2's US-dollar table. After passing and completing the application, a CC holder pays the first $50 Annual Maintenance Fee. The same fee is due each year on the certification anniversary. CC holders also need 45 CPE credits during the three-year cycle; ISC2 recommends 15 per year.
A simple three-year planning figure is the exam fee plus three annual maintenance payments, before training, a retake, taxes, or regional differences. Do not describe the first-year price as the entire cost of keeping CC active.
CompTIA Security+
CompTIA currently lists a standalone US Security+ voucher at $439. Security+ is valid for three years. The multiple-activity renewal route requires 50 CEUs and CompTIA's current help center lists a $150 total CE fee for the three-year period.
CompTIA also lists single-activity renewal options. Depending on eligibility, passing the latest exam release, earning a qualifying higher certification, or completing the appropriate CertMaster CE course can renew Security+ without the separate CE fee. Check the current rules before assuming one route is cheapest; course and exam purchases have their own costs.
Budget verdict: CC costs less to attempt and suits a lower-risk first step. Security+ costs more, but the higher price can be justified when a target posting explicitly asks for it or its applied format better matches your next role.
How the Exams Test Different Readiness
CC is explicitly designed for newcomers and has no work-experience requirement. It covers security principles, governance or resilience concepts, access control or IAM, networking and cloud concepts, and security operations. Its CAT format tests whether your foundational knowledge stays reliable as item difficulty changes.
Security+ lists no formal prerequisite, but CompTIA recommends Network+ and two years in a security or systems-administrator role. SY0-701 includes performance-based questions as well as multiple choice. Those questions make it important to practice interpreting configurations, incidents, controls, and operational scenarios rather than memorizing definitions alone.
No authoritative source publishes a universal pass rate or a study-hour requirement for either exam. Avoid plans built on a promised number of hours. Use objective-level diagnostics instead:
- Can you explain why each wrong option is wrong?
- Can you answer unfamiliar scenarios rather than repeated question wording?
- For Security+, can you complete configuration and analysis tasks under time pressure?
- Are your results stable across every current domain, not only your favorite topics?
That approach is more defensible than calling one exam easy or guaranteeing a pass after a fixed schedule.
Choose by Situation
Take CC first when
- You are starting without networking, systems-administration, or security experience.
- The $199 exam price fits your budget better than a $439 Security+ voucher.
- You want a current, accredited foundation before attempting applied performance-based questions.
- A specific employer or DCWF role accepts CC at the required proficiency level.
- You plan to continue along the ISC2 certification path and want early exposure to ISC2-style judgment questions.
Take Security+ first when
- The actual job descriptions you will apply to name Security+.
- You already have networking and operating-system fundamentals.
- You want performance-based questions to be part of the assessment.
- The exact DCWF work role and level list Security+ as the appropriate qualification for your position.
- You would otherwise take CC only because an outdated page called it free.
Take CC and then Security+ when
The sequence makes sense if CC fills a real knowledge gap and Security+ is a later job requirement. After CC, compare the two official outlines, identify only the remaining Security+ objectives, and add hands-on work for performance-based questions. Do not restart from page one of a generic course merely to collect a second badge.
Skip the second certification when
Your current credential already meets the target role's requirement and the second exam would mostly duplicate proof you already have. A lab portfolio, help-desk or systems work, scripting, cloud administration, or a role-specific credential may add more evidence than another broad foundation exam.
A Five-Step Decision Process
- Collect ten realistic job postings. Record which certifications are required, preferred, or absent. Do not substitute national anecdotes for the roles in your location and sector.
- For DoD work, obtain the DCWF role code and proficiency level. Verify the current qualification matrix instead of relying on an old 8570 table or a vendor slogan.
- Check your appointment date. CC changes outlines September 1, 2026. Security+ remains SY0-701 until CompTIA publishes otherwise.
- Price the full cycle. Include the exam, likely training or retake costs, and the maintenance route you will actually use.
- Test both skill profiles. Use CC practice questions for foundational judgment and Security+ practice questions before committing to the more expensive exam.
This process produces a decision tied to evidence: your jobs, current vendor rules, current outlines, and your measured gaps.
Verdict
For a true beginner, CC is the cleaner first step: no experience requirement, a lower current exam price, and a foundation that can expose gaps before a more applied test. For someone with IT fundamentals whose target jobs explicitly request it, Security+ is the more direct choice because it includes performance-based items and is named in many current pathways.
For DoD candidates, neither credential wins automatically. Both are DoDM 8140.03 approved. Choose the one accepted for the exact work role and proficiency level, and remember that a certification is only one part of role qualification.
The time-sensitive action is not chasing a free CC enrollment that has already closed. It is using an existing 1MCC code by December 31, choosing the correct CC outline for your test date, and checking CompTIA's official page before acting on Security+ transition rumors.
free CC practice questionsPractice questions with detailed explanations
Official Sources
- ISC2 CC certification page
- ISC2 CC current and September 2026 exam outlines
- ISC2 computerized adaptive testing guidance
- ISC2 exam pricing
- ISC2 CC maintenance FAQ
- ISC2 One Million Certified program conclusion
- ISC2 CC DoD 8140 mapping announcement
- CompTIA Security+ certification and current products
- CompTIA DoDM 8140.03 framework alignment
- CompTIA renewal options
- CompTIA continuing-education fees
- DoD 8140 qualification matrices

