0.1 ISC2 CGRC Exam Structure, Logistics & Passing Strategy
Key Takeaways
- The ISC2 CGRC exam consists of 125 items in a multiple-choice and advanced item-type format, administered over a 3-hour testing window at Pearson VUE centers.
- A passing grade of 700 out of 1,000 points is required; ISC2 reports the result as pass/fail and does not release a numeric score to candidates who pass.
- Full certification requires 2 years of cumulative, paid work experience in one or more of the 7 CGRC domains, though candidates can earn the Associate of ISC2 designation and satisfy experience within 3 years.
- The 7 exam domains map directly to the NIST Risk Management Framework lifecycle, with Domain 4 (Implementation, 17%), Domain 1 (Governance, 16%), and Domain 5 (Assessment, 16%) carrying the heaviest weights.
- Success requires adopting an Assessor/Governance mindset focused on formal risk management, role responsibilities, and procedural sequence rather than hands-on technical configuration.
ISC2 CGRC Exam Structure, Logistics & Passing Strategy
The Certified in Governance, Risk and Compliance (CGRC) credential—formerly designated as the Certified Authorization Professional (CAP)—is ISC2's premier professional certification validating expertise in information security and privacy risk management, compliance governance, and authorization lifecycles. While the legacy CAP designation historically focused on federal authorization frameworks, the rebranded CGRC reflects the broad convergence of security governance, privacy mandates, cloud compliance models (such as FedRAMP and StateRAMP), and commercial enterprise risk frameworks.
Earning the CGRC demonstrates that an information security professional possesses the advanced knowledge and practical capability to formalize, assess, authorize, and continuously monitor organizational information systems across their entire system life cycle using established frameworks—predominantly the NIST Risk Management Framework (RMF) defined in NIST Special Publication (SP) 800-37 Rev. 2.
1. Exam Logistics & Testing Format
The CGRC examination is administered exclusively through Pearson VUE computer-based testing (CBT) authorized test centers worldwide. Candidates must schedule their testing appointment in advance and complete the examination in a secure, proctored environment.
Key Examination Specifications
| Examination Parameter | Specification Details |
|---|---|
| Total Number of Items | 125 items |
| Testing Duration | 3 Hours (180 minutes) |
| Passing Standard | 700 out of 1,000 points |
| Delivery Method | Computer-Based Testing (CBT) via Pearson VUE |
| Item Format | Multiple choice and advanced item types (ISC2 official wording) |
| Exam Language | English |
| Credentialing Body | International Information System Security Certification Consortium (ISC2) |
[!NOTE] Scoring: What ISC2 Does and Does Not Publish ISC2 publishes exactly one scoring fact for the CGRC: the passing grade is 700 out of 1,000 points. It does not publish the lower bound of the scale, the number of unscored pre-test items, or a raw-to-scaled conversion table, and candidates who pass are not given a numeric score — the result is reported as pass/fail only. Candidates who fail receive a ranked list of domain proficiency levels at the test center rather than a score. Treat any specific "scaled score range" you see on third-party prep sites as unsourced: plan to master every domain rather than to reverse-engineer a points target.
2. Professional Experience & Associate Pathway
ISC2 maintains stringent experience prerequisites to ensure that certified professionals possess practical, real-world proficiency in governance, risk management, and compliance programs.
Standard Certification Path
Candidates seeking full CGRC certification must satisfy the following criteria:
- Cumulative Work Experience: Accumulate a minimum of 2 years of cumulative, paid, full-time work experience in one or more of the seven domains of the ISC2 CGRC Common Body of Knowledge (CBK).
- Part-Time Work Conversion: Part-time work is credited on a proportional basis (e.g., 20 hours per week for 2 years equals 1 year of qualifying experience).
- Formal Endorsement: Upon passing the exam, candidates must submit an online endorsement application signed by an active ISC2-certified professional in good standing who can attest to their professional experience. Endorsement must be completed within 9 months of passing the examination.
The Associate of ISC2 Pathway
If a candidate passes the CGRC examination but does not yet possess the mandatory 2 years of qualifying professional experience, they earn the designation of Associate of ISC2.
- Associates are granted a maximum of 3 years from their exam pass date to acquire the required 2 years of professional experience across the CGRC domains.
- Once the required experience is gained, the candidate submits their formal endorsement package to transition into full CGRC credential holder status without having to retake the examination.
Continuing Professional Education (CPE) & Maintenance
To maintain the CGRC credential in good standing across the 3-year certification cycle, credential holders must:
- Earn and report a minimum of 60 Continuing Professional Education (CPE) credits over the 3-year cycle (with a recommended minimum of 20 CPEs per year).
- Adhere strictly to the ISC2 Code of Ethics.
- Pay the required Annual Maintenance Fee (AMF) of US$135 per year directly to ISC2. The AMF is charged once per member, not once per certification, so holding additional ISC2 credentials does not increase it.
3. The 7 CGRC Domains & Weightings
The CGRC CBK is structured across seven comprehensive domains that mirror the life cycle phases of enterprise risk management and system authorization. The table below outlines the domains, their exact percentage weights on the examination, and their functional scope.
| Domain # | Domain Title | Exam Weight | Core Conceptual Focus |
|---|---|---|---|
| 1 | Security and Privacy Governance, Risk Management, and Compliance Program | 16% | Enterprise governance frameworks, multi-tier risk management (SP 800-39), regulatory drivers (FISMA, Privacy Act, OMB A-130), privacy governance (FIPPs, PIA, SORN), organizational roles, and ISC2 ethics. |
| 2 | Scope of the System | 10% | System boundary definition, architectural context (GSS, Major Applications, Cloud), FIPS 199 / SP 800-60 categorization, high-water mark rule, and system registration in compliance repositories. |
| 3 | Selection and Approval of Framework, Security, and Privacy Controls | 14% | NIST SP 800-53 Rev. 5 control catalogs, baseline selection, control inheritance (Common, Hybrid, System-Specific), tailoring, scoping, overlays, and continuous monitoring strategy approval. |
| 4 | Implementation of Security and Privacy Controls | 17% | System Security and Privacy Plan (SSP/SSPP) authoring, Control Implementation Statements (CIS), secure systems engineering (SP 800-160), configuration hardening (STIGs, CIS Benchmarks), and DevSecOps / supply chain risk (SP 800-161). |
| 5 | Assessment/Audit of Security and Privacy Controls | 16% | Security Assessment Plan (SAP) formulation, assessor independence, assessment methods (Examine, Interview, Test per SP 800-53A), vulnerability testing, and Security Assessment Report (SAR) production. |
| 6 | System Compliance | 14% | Assembly of the core authorization package (SSP, SAR, POA&M), Plan of Action and Milestones (POA&M) management, Authorizing Official (AO) risk acceptance, and formal authorization decisions (ATO, ATO with Conditions, IATT, DATO). |
| 7 | Compliance Maintenance | 13% | Information Security Continuous Monitoring (ISCM per SP 800-137), configuration change control (CCB & SIA per SP 800-128), remediation tracking, annual FISMA reviews, event-driven reauthorization, and secure decommissioning (SP 800-88). |
Domain Weight Distribution Analysis:
-------------------------------------------------------------
Domain 4: Control Implementation [17%] █████████████████
Domain 1: Governance & Risk Program [16%] ████████████████
Domain 5: Control Assessment / Audit [16%] ████████████████
Domain 3: Control Selection & Approval [14%] ██████████████
Domain 6: System Compliance (Auth) [14%] ██████████████
Domain 7: Compliance Maintenance (ISCM) [13%] █████████████
Domain 2: System Scope & Categorization [10%] ██████████
-------------------------------------------------------------
Total: 100% | 125 Items
[!IMPORTANT] Weight Concentration Strategy Notice that Domain 4 (Implementation - 17%), Domain 1 (Governance - 16%), and Domain 5 (Assessment - 16%) collectively constitute 49% of the entire examination. Mastering the structural authoring of the System Security Plan (SSP), organizational governance hierarchies, and assessment methodologies in NIST SP 800-53A is non-negotiable for passing.
4. Exam Mindset: Governance & Assessor vs. Technical Implementer
The single most common reason technically proficient security engineers fail the CGRC examination is adopting an engineering/tactical mindset rather than a governance/assessor mindset.
The Mindset Contrast
┌─────────────────────────────────────────┐ ┌─────────────────────────────────────────┐
│ TECHNICAL / TACTICAL MINDSET │ │ GOVERNANCE / ASSESSOR MINDSET │
│ (Avoid on the Exam) │ │ (Adopt for Success) │
├─────────────────────────────────────────┤ ├─────────────────────────────────────────┤
│ • "Let me log into the firewall and │ │ • "Does the proposed change trigger a │
│ modify the access control list." │ vs. │ Security Impact Analysis (SIA)?" │
│ • "Let me immediately deploy a script │ │ • "Is this action formally authorized in│
│ to patch this server vulnerability." │ │ the System Security Plan (SSP)?" │
│ • "I should fix the broken control │ │ • "What is the residual risk, and does │
│ myself right now." │ │ the Authorizing Official accept it?" │
└─────────────────────────────────────────┘ └─────────────────────────────────────────┘
On the CGRC exam, you are evaluating systems from the perspective of an Information System Security Officer (ISSO), a Security Control Assessor (SCA), or an advisor to the Authorizing Official (AO). Your primary concerns are:
- Due Process & Governance: Did the action follow established organizational policy, RMF sequencing, and configuration change control?
- Documentation Integrity: Is every control allocation, inheritance determination, tailoring decision, and risk acceptance explicitly documented in the SSP, SAR, or POA&M?
- Separation of Duties & Independence: Are assessors impartial? Are roles executing their defined responsibilities without operational conflicts of interest?
- Risk-Based Decision Making: Security is not absolute. Controls must balance mission necessity, organizational risk tolerance, and cost-effectiveness.
5. Deconstructing Scenario-Based Questions & Keywords
CGRC questions frequently present realistic organizational scenarios where multiple answer choices appear technically plausible. Identifying the single best answer requires isolating the RMF life cycle step, the active role, and the critical qualifying keyword.
Critical Qualifying Keywords
FIRST/INITIAL: Demands the immediate chronological prerequisite in the RMF process. For example, before selecting controls (Select), the system must be categorized (Categorize). Before modifying a production baseline, a Security Impact Analysis (SIA) must be conducted.BEST/MOST EFFECTIVE: Requires selecting the option that provides the most comprehensive, defensible, and risk-aligned solution according to NIST guidelines, rather than a quick tactical workaround.PRIMARY/MOST IMPORTANT: Asks for the overarching objective or primary accountability. For example, the primary reason for continuous monitoring is to maintain ongoing situational awareness of security posture, not merely to produce audit paperwork.LEAST/NOT/EXCEPT: Requires identifying the negative exception, the least appropriate action, or an incorrect statement.
Strategic Scenario Analysis Process
When evaluating a scenario question, apply this 4-step framework:
Step 1: Identify the RMF Phase
└── Is the system in Prepare, Categorize, Select, Implement, Assess, Authorize, or Monitor?
Step 2: Identify the Acting Role
└── Are you acting as the AO, SCA, ISSO, System Owner, SAOP, or Common Control Provider?
Step 3: Pinpoint the Decision Boundary
└── Does the action require Authorizing Official sign-off, or is it an operational task?
Step 4: Eliminate Procedural Violations
└── Discard options that bypass change management, ignore residual risk, or violate assessor independence.
6. Time Management & Pacing Strategy
With 125 questions and 180 minutes, candidates have approximately 86.4 seconds (1 minute 26 seconds) per question.
Total Time Available: 180 Minutes (3.0 Hours)
Total Questions: 125 Items
Average Pacing: ~86 Seconds per Item
Checkpoint Milestones:
• Question 40 completed -> 120 Minutes Remaining (Hour 1)
• Question 80 completed -> 60 Minutes Remaining (Hour 2)
• Question 125 completed -> 0-15 Minutes Remaining (Review Time)
Recommended Examination Tactics
- First Pass Velocity: Read each question carefully, eliminate obviously flawed options, and answer immediately if confident. If an item requires deep architectural deliberation, select your best tentative choice, flag the question, and move forward.
- Do Not Leave Blanks: There is no negative marking or penalty for incorrect guesses. Ensure every item has a selected response before time expires.
- Avoid Over-Analyzing Common Control Scenarios: When questions discuss inherited controls, focus strictly on whether the responsibility belongs to the Common Control Provider (CCP) or the system-specific owner.
A cybersecurity professional passes the ISC2 CGRC examination but currently possesses only one year of qualifying professional experience across the CGRC domains. What designation does the candidate receive, and what is the timeframe allowed to satisfy the remaining experience requirement?
An enterprise Information System Security Officer (ISSO) is preparing for the CGRC examination. Which three domains collectively represent nearly half (49%) of the total exam weight?
During a routine system operational review, a system administrator proposes installing a major security software suite to replace an existing endpoint protection agent. From a governance and assessor perspective, what is the FIRST action that must occur prior to making this configuration change?