Skip to content

(ISC)² Certified in Cybersecurity (CC) - Exam Facts Reference

(ISC)² Certified in Cybersecurity (CC) — Exam Facts Reference

Section titled “(ISC)² Certified in Cybersecurity (CC) — Exam Facts Reference”

Compiled: 27 August 2026, ahead of an exam sitting the next day. Scope: Verifiable ground truth only. No study advice, no motivational padding. Confidence convention: Every numeric fact cites an official PDF or newsroom post. Where a fact is internal to (ISC)² and not publicly disclosed, the document says so explicitly.

Critical framing for this sitting. The user is taking the exam one day before a major (ISC)² outline change. The exam the user will sit is governed by the Exam Outline Effective October 1, 2025. A new outline takes effect on September 1, 2026 (four days after this sitting) with renamed domains and an AI-aware content refresh. Every domain name, weight, and topic cited below refers to the current October 1, 2025 outline, which is what will appear on screen.


1. Current exam format (effective October 1, 2025)

Section titled “1. Current exam format (effective October 1, 2025)”
Attribute Value Source
Format Computerized Adaptive Testing (CAT) — replaced the prior 100-question linear format on October 1, 2025 ISC2 Newsroom press release, 1 Oct 2025
Item count Minimum 100, maximum 125 CC Exam Outline (Oct 1, 2025), ISC2 PDF
Time limit 2 hours (120 minutes) for the full 100–125 items Candidate Information Bulletin, 1 Oct 2025
Item types Multiple-choice and advanced item types (the previous “4 choices, multiple choice” line is replaced by “multiple choice and advanced item types” in the CAT outline) CC Exam Outline, 1 Oct 2025
Pretest (unscored) items 25 of the first 100 items are pretest — they do not count toward the score but are not identified to the candidate Candidate Information Bulletin, 1 Oct 2025
Passing grade 700 out of 1,000 (scaled; NOT a raw percentage) CC Exam Outline, 1 Oct 2025
Item review Not permitted. Once an answer is submitted, it cannot be changed Candidate Information Bulletin, 1 Oct 2025
How the exam ends The CAT engine stops at 100 items if 95% confidence is reached either way, or at 125 items, or at the 2-hour time limit, whichever comes first Candidate Information Bulletin, 1 Oct 2025
Item weighting All operational items contribute to ability estimate; the algorithm targets ~50% correct on each item presented (candidates should “expect to find each item challenging”) Candidate Information Bulletin, 1 Oct 2025
Languages English, Chinese (Simplified), Japanese, German, Spanish (Modern) CC Exam Outline, 1 Oct 2025

On the “700 = ~70%” misconception. A study pack used by many candidates phrases the bar as “70% accuracy to pass” (CC Study Pack, ISC2 PDF). ISC2 itself states only the scaled 700/1000 number; the Study Pack’s 70% gloss is rounded marketing copy, not a stated conversion. The number of correct operational answers required to clear 700 is not publicly disclosed.

On the “100 multiple choice” claim. This is outdated. Up to September 30, 2025, the CC was a 100-item linear multiple-choice exam. Since October 1, 2025, it is 100–125 CAT items with advanced item types (ISC2 press release, 1 Oct 2025). Old blog posts and study guides stating “100 multiple choice” refer to the pre-October 2025 format.


2. The five domains and their weights (current Oct 1, 2025 outline)

Section titled “2. The five domains and their weights (current Oct 1, 2025 outline)”

The exam is divided into five domains. Domain weighting is published as “Average Weight” — these are the targets the CAT engine uses to allocate items across the exam, not strict per-item weights (CC Exam Outline, 1 Oct 2025).

# Domain Weight Subtasks in the official outline
1 Security Principles 26% 1.1 Security concepts of information assurance (CIA + AuthN, non-repudiation, privacy); 1.2 Risk management; 1.3 Security controls; 1.4 (ISC)² Code of Ethics; 1.5 Governance elements
2 Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts 10% 2.1 Business continuity; 2.2 Disaster recovery; 2.3 Incident response
3 Access Controls Concepts 22% 3.1 Physical access controls; 3.2 Logical access controls
4 Network Security 24% 4.1 Network concepts; 4.2 Network threats and attacks; 4.3 Network infrastructure; 4.4 Securing network communications
5 Security Operations 18% 5.1 Data security; 5.2 Asset management; 5.3 Logging and monitoring; 5.4 Encryption; 5.5 Configuration management; 5.6 Security policies

Sources: CC Exam Outline, 1 Oct 2025 and CC Study Pack, ISC2 PDF. The two sources agree on the weights.

What the user faces tomorrow, in one line. Roughly half the items come from Security Principles (26%) and Network Security (24%) combined; Access Controls (22%) brings that to 72% of the exam. Security Operations is 18%; BC/DR/IR is the lightest at 10%.

The September 1, 2026 outline change is NOT in effect for this sitting. ISC2 has already published a revised outline effective September 1, 2026 with renamed domains (Security Principles 24%, Security Governance 17.3%, Identity and Access Management 20%, Networking and Cloud Security 21.3%, Security Operations and Incident Response 17.3%) and AI-themed content threaded through each domain (CC Exam Outline effective Sept 1, 2026, ISC2 PDF; ISC2 Exam Guidance for AI, ISC2 PDF). The user is sitting four days before that change.


3. Cost and the “1 Million Certified in Cybersecurity” pathway

Section titled “3. Cost and the “1 Million Certified in Cybersecurity” pathway”
Path Cost Status as of 27 Aug 2026
One Million Certified in Cybersecurity (1MCC) — free self-paced training + free first exam voucher $0 for the first attempt if a valid voucher is in the user’s ISC2 dashboard New public enrollment CLOSED on 20 May 2026. ISC2 announced surpassing the 1-million-enrollee goal; only candidates who enrolled and received a code before 20 May 2026 retain free exam access. ISC2 Insights, April 2026 (URL returned server rejection; announcement cited via ISC2 LinkedIn, 22 Apr 2026 and corroborated by CBT Nuggets, 14 Oct 2025)
Voucher validity for existing 1MCC enrollees Use by 31 December 2026 ISC2 LinkedIn, 22 Apr 2026
Standard exam fee (no 1MCC) US $199 ISC2 CC Exam Voucher listing, Pearson VUE Government Store (lists “ISC2 CC Exam Voucher — Member price / Web price: $199.00”)
Training + exam bundle (e.g., Peace of Mind, self-paced + exam) Approximately $129–$199 historically for paid self-paced; “Peace of Mind” historically added a second attempt Per ISC2 community discussion, 2022; current pricing not retrievable from ISC2 store at this writing
Retake after a failed first attempt Full exam fee ($199 if not under 1MCC); 1MCC covers only the first attempt ISC2 community, 2022

For tomorrow specifically. If the user has a valid exam code in the ISC2 dashboard and a confirmed Pearson VUE appointment, the test-day fee is already paid (either free via 1MCC, or $199 paid at scheduling). No additional cost at the test center.

One Million pledge + Pearson VUE reschedule/cancel fees waived. The 1 Oct 2025 Candidate Information Bulletin states explicitly: “Those participating in ISC2’s One Million Pledge sitting for the Certified in Cybersecurity (CC) exam for the first time do not pay fees for rescheduling.” Paid candidates pay the standard $50 reschedule / $100 cancellation fees (Candidate Information Bulletin, 1 Oct 2025).


4. AMF, renewal cycle, and CPE requirements

Section titled “4. AMF, renewal cycle, and CPE requirements”
Item Value Source
AMF for CC-only members US $50 per year ISC2 Certification Maintenance Handbook, ISC2 PDF; OpenExamPrep, 14 May 2026
AMF billing date First anniversary of membership cycle start, and the same date each year thereafter ISC2 Certification Maintenance Handbook, ISC2 PDF
Is the first year of AMF included free with the exam? No. Passing the exam does NOT include a free year. The first $50 AMF is due after passing, completing the certification application, and being approved. Some 1MCC cohorts and partner programs (e.g., Cybersafe Foundation) have historically covered the first $50 separately; this is not an ISC2 policy CrucialExams, 8 Sep 2025; LinkedIn first-pass story, Dec 2023
AMF comparison CC-only or Associate of (ISC)²: $50/yr. Members holding CISSP, CCSP, SSCP, CSSLP, CGRC, HCISPP, ISSAP, ISSEP, or ISSMP: $135/yr (single fee regardless of how many of these you hold) ISC2 Certification Maintenance Handbook, ISC2 PDF
Renewal cycle 3 years from certification activation ISC2 Certification Maintenance Handbook, ISC2 PDF
CPE credits (CC) 45 Group A CPE credits over the 3-year cycle; ~15/year suggested. Group B CPEs do NOT count for CC-only members ISC2 Certification Maintenance Handbook, ISC2 PDF
Recertification process Automatic at end of 3-year cycle if CPE + AMF are current ISC2 Certification Maintenance Handbook, ISC2 PDF
Upgrade to a higher (ISC)² cert later Pay a one-time $85 upgrade fee when converting from CC to a paid cert (CCSP, CISSP, etc.) CrucialExams, 8 Sep 2025

5. Prerequisites and post-pass endorsement

Section titled “5. Prerequisites and post-pass endorsement”
Item Value Source
Work experience required None. “There are no specific prerequisites to take the exam. It is recommended that candidates have basic information knowledge. No work experience in cybersecurity or any formal educational diploma/degree is required.” Candidate Information Bulletin, 1 Oct 2025
Minimum age 16 years old (parental presence and signature required for 16–17) Candidate Information Bulletin, 1 Oct 2025
Post-pass endorsement (CC) The CC endorsement application is not a work-experience audit. It contains only the Code of Ethics agreement and a privacy policy acknowledgment LegalClarity, 11 Jun 2026 (corroborated by OpenExamPrep, 14 May 2026)
Endorsement window 9 months from exam date to complete the online endorsement application and pay the first AMF ISC2 Member Policies (cited via ISC2 community thread, 22 Apr 2025); OpenExamPrep, 14 May 2026
Finding an endorser CC endorsement is auto-processed by (ISC)²; no external (ISC)²-certified endorser is required. The candidate attests personally OpenExamPrep, 14 May 2026
Consequence of missing the 9-month window No extension. The exam result expires; the candidate must retake the exam ISC2 NCR Chapter, endorsement demystified; ISC2 community, 22 Apr 2025
Code of Ethics Mandatory agreement; violation can lead to certification revocation by a peer review panel ISC2 Code of Ethics, ISC2 Phoenix Chapter mirror

The four canons of the (ISC)² Code of Ethics (verbatim):

  1. Protect society, the common good, necessary public trust and confidence, and the infrastructure.
  2. Act honorably, honestly, justly, responsibly, and legally.
  3. Provide diligent and competent service to principals.
  4. Advance and protect the profession.

Canon I and II complaints may be filed by any member of the public. Canon III complaints require a principal (employer or client) relationship. Canon IV complaints are limited to other (ISC)² members. In a conflict, lower-numbered canons take precedence (Nex-Arc CC Study Guide, Code of Ethics; Cyvitrix, 16 Jan 2026).


6. Test delivery and language availability

Section titled “6. Test delivery and language availability”
Item Value Source
Delivery channel Pearson VUE professional test centers only. ISC2 does not offer OnVUE online proctoring for the CC Training Camp, 24 Jul 2026; Online Cybersecurity resource, 31 Jul 2026; Certcrush, 26 Jul 2026
Why no online proctoring ISC2 ran two online-proctoring pilots in 2021. Outcomes included “irregular results, clear violations of administration rules, and verified cheating attempts”; the control group (in-person) showed no change in irregularities. ISC2 concluded the risk to credential reputation was unnecessary Training Camp, 24 Jul 2026 (paraphrasing ISC2’s published pilot findings); DestCert, 9 Aug 2023
Languages English, Simplified Chinese, Japanese, German, Spanish (Modern) in CAT format CC Exam Outline, 1 Oct 2025
Annual availability windows for CC and CCSP (2026) Jan 4 – Feb 2; Apr 1 – 30; Jul 11 – Aug 9; Oct 8 – Nov 6 Candidate Information Bulletin, 1 Oct 2025

For tomorrow. Late August 2026 falls inside the Jul 11 – Aug 9 window that ISC2 published for 2026, but the bulletin wording (“Annual Availability”) suggests these are the planned active testing windows; ISC2 does not always close the exam between them. Tomorrow’s appointment is at the user’s confirmed Pearson VUE test center.


Date Change Source
April 2024 CISSP went fully CAT across all languages ISC2 press release, 1 Oct 2025
May 2025 ISC2 announced CAT rollout to CC, SSCP, and CCSP ISC2 Insights, 14 May 2025 (URL returned server rejection; cited via ISC2 press release, 1 Oct 2025)
October 1, 2025 CC, SSCP, and CCSP transitioned to CAT. CC became 100–125 items, 2 hours, multiple-choice + advanced item types ISC2 press release, 1 Oct 2025; CC Exam Outline, 1 Oct 2025
April 22, 2026 ISC2 announced 1MCC surpassed 1 million enrollees; new public enrollments close on May 20, 2026; existing vouchers valid through Dec 31, 2026 ISC2 Insights, Apr 2026 (URL returned server rejection; corroborated by ISC2 LinkedIn, 22 Apr 2026)
May 20, 2026 1MCC public enrollment closes. Standard $199 fee returns for new candidates Same as above
August 6, 2026 ISC2 published an Insights article (“What’s New for Entry-Level Cybersecurity / Inside the Updated ISC2 CC Exam”) previewing the September 1, 2026 outline ISC2 Insights, 6 Aug 2026 (URL returned server rejection; existence confirmed via search results)
September 1, 2026 New CC exam outline effective: 5 domains renamed (Security Principles 24%, Security Governance 17.3%, Identity and Access Management 20%, Networking and Cloud Security 21.3%, Security Operations and Incident Response 17.3%); AI concepts integrated across all domains CC Exam Outline effective Sept 1, 2026, ISC2 PDF; ISC2 Exam Guidance for AI, ISC2 PDF
December 31, 2026 Final deadline to sit for the CC using a 1MCC voucher issued before May 20, 2026 ISC2 LinkedIn, 22 Apr 2026

No (ISC)² certifications have been retired in 2024–2026 that affect the CC’s positioning. The HCISPP, CISSP-ISSAP/ISSEP/ISSMP concentrations, and CGRC remain active. The CC remains (ISC)²’s entry-level credential.


8. Test-center policies, prohibited items, ID requirements

Section titled “8. Test-center policies, prohibited items, ID requirements”

(ISC)² requires two forms of ID at the Pearson VUE test center (Candidate Information Bulletin, 1 Oct 2025; CC Exam Ready Booklet, ISC2 PDF):

  • Primary ID — government-issued, with photo and signature, original, unexpired. Examples: passport, driver’s license, national/state ID card, military ID, permanent-resident card.
  • Secondary ID — must contain a signature. Examples: credit card with signature, debit/ATM card, Social Security card, employee/school ID, or any item on the primary list.
  • Name match is enforced character-for-character against the Pearson VUE registration. Name changes are not permitted on test day; mismatches result in being turned away and forfeiting the testing fee.
  • Digital IDs are not accepted.
  • A palm-vein scan is taken at check-in and on every re-entry (waiver possible for religious/medical reasons via examadministration@isc2.org in advance).

8.2 What you cannot bring into the testing room

Section titled “8.2 What you cannot bring into the testing room”

From Pearson VUE Professional & Regulatory Candidate Rules Agreement and ISC2 Candidate Information Bulletin, 1 Oct 2025:

  • Mobile phones and all other electronic devices (must be powered off before storage)
  • Watches (smart and analog) — strictly prohibited
  • Wallets, purses, bags, backpacks
  • Firearms or weapons
  • Hats and non-religious head coverings
  • Coats and jackets
  • Eyeglass cases
  • Pens, pencils
  • Barrettes/hair clips wider than 1/4 inch (½ cm); headbands wider than ½ inch (1 cm)
  • Removable jewelry wider than 1/4 inch (½ cm) — wedding/engagement rings exempt
  • Books, notes, study guides
  • Food, drinks, water bottles (must be left in the locker)

Allowed: layered indoor clothing (sweaters, sweatshirts, blazers), reading glasses without case, wedding/engagement ring, comfort aids/medication with TA permission.

Item Value Source
Arrival window Arrive 30 minutes before appointment Pearson VUE Exam Check-in Process PDF
Late arrival Arriving more than 15 minutes late may forfeit the seat and the fee Pearson VUE Exam Check-in Process PDF
Breaks No scheduled breaks for the CC; the 2-hour timer does not pause for an unscheduled break Candidate Information Bulletin, 1 Oct 2025; Pearson VUE rules
Pre-exam tutorial A short Pearson VUE tutorial plays before the timed exam; it does not count against the 2 hours Online Cybersecurity, 31 Jul 2026
NDA A non-disclosure agreement is presented on screen at the start of the exam and must be accepted before items appear CC Exam Ready Booklet, ISC2 PDF
On-screen tools An on-screen calculator and an erasable note board (provided by the test center) are available. The note board must be returned at the end Pearson VUE rules
Action Fee Window Source
Reschedule $50 (waived for 1MCC first-attempt candidates) Online at least 48 hours before the appointment, or by phone at least 24 hours before Candidate Information Bulletin, 1 Oct 2025
Cancel $100 (waived for 1MCC first-attempt candidates) Same 48-hour online / 24-hour phone window Same
No reschedule inside 24 hours “Exams cannot be rescheduled once you are within 24 hours of your appointment time” Same
Name change Allowed up to 48 hours before the appointment via ISC2 account; no changes on test day Same
365-day voucher expiry Once scheduled, you have 365 days to sit before the exam fee is forfeited Same
Technical issues at the test center If the center’s equipment is delayed more than 30 minutes after scheduled start (or the exam starts then stalls with a 30+ minute delay), the candidate may continue, reschedule at no extra cost, or get a refund Same

Two independent rules apply (Candidate Information Bulletin, 1 Oct 2025; ISC2 NCR Chapter):

Attempt Minimum waiting period from previous attempt
First → second 30 test-free days
Second → third 60 test-free days
Third → fourth and beyond 90 test-free days
Annual cap Maximum 4 attempts per 12-month period per certification

Retake fee = full standard exam fee ($199). The free 1MCC voucher covers only the first attempt (ISC2 community, 2022).

Common internet claim that conflicts with official policy. Some prep blogs still cite “30 days → 90 days → 180 days” for (ISC)² retakes. This is outdated. The current and accurate policy is 30 → 60 → 90, with the 4-attempt/12-month cap (Training Camp, 24 Jul 2026).


ISC2 does not publish CC pass rates. ISC2 has not released first-attempt, all-attempt, or lifetime pass-rate statistics for the CC at any point in the credential’s history (the program began in 2022). For the CISSP, the same is true: “ISC2 has never published one, not in 2026 and not at any point in the exam’s history” (Training Camp, 11 Jun 2026).

Unofficial estimates floating around the web cluster around ~70% first-attempt pass for the CC (e.g., Tech Jacks Solutions, 15 Mar 2026). These are educated guesses from training providers and community self-reports, not (ISC)² data, and should be treated as rumor. The commonly cited “20% pass rate” for the CISSP has no traceable source and is widely regarded as internet folklore (Training Camp, 11 Jun 2026).

The only (ISC)²-issued pass-rate-adjacent stat: roughly 65,000 people earned the CC through the 1MCC program, with the program reaching “more than 1 million” enrolled participants as of April 2026 (ISC2 LinkedIn, 22 Apr 2026). This is a count of certified members, not a pass-rate denominator.


10. Candidate agreement / code of conduct — what gets candidates in trouble

Section titled “10. Candidate agreement / code of conduct — what gets candidates in trouble”

The (ISC)² Code of Ethics Preamble states: “Strict adherence to this Code is a condition of certification.” Violations are reviewed by a peer-review panel and can result in revocation of certification (ISC2 Code of Ethics, ISC2 Phoenix Chapter mirror).

10.1 Exam-day NDA and candidate agreement violations

Section titled “10.1 Exam-day NDA and candidate agreement violations”

These are the behaviors Pearson VUE and (ISC)² most commonly cite as terminable:

  • Possessing a prohibited device during the exam — phones, smartwatches, or any electronic device discovered in the testing room. Pearson VUE explicitly states: “If a prohibited device is found during screening, you’ll be asked to leave the test center and may forfeit your exam fees” (Pearson VUE Exam Check-in Process PDF).
  • Refusing to empty pockets, roll up sleeves, or pull back hair for the TA’s visual inspection (Pearson VUE rules).
  • Accessing personal items (phone, notes) during a break. Only comfort aids, medication, drinks, and food may be accessed during a break without TA permission; phones and study materials may not be accessed at any time during a break (Pearson VUE rules).
  • Reading questions aloud or mumbling at a test center (less relevant for in-person; more relevant had the exam been online) — see CompTIA/OnVUE equivalents cited in Training Camp, 24 Jul 2026.
  • Name mismatch on ID at check-in results in being turned away as a no-show and forfeiting the fee (Candidate Information Bulletin, 1 Oct 2025).
  • Communicating with another candidate during the exam.

10.2 Post-certification Code of Ethics violations most often adjudicated

Section titled “10.2 Post-certification Code of Ethics violations most often adjudicated”

Per Cyvitrix, 16 Jan 2026 and Nex-Arc CC Study Guide:

  • Concealing a public danger to protect an employer — violates Canon I even if the employer requests silence.
  • Failing to report an observed Code breach by another (ISC)² member — Canon IV itself is breached by the failure to report.
  • Operating outside documented scope during a penetration test and exploiting a finding without authorization — Canon III (competent service to principals).
  • Inflating or fabricating work experience on the endorsement application (for higher certs; for CC this is moot, but the principle applies to any later ISC2 application) — LegalClarity, 11 Jun 2026.
  • Misrepresenting certification status on a resume or LinkedIn before official activation (i.e., before AMF is paid and the credential flips from “provisional pass” to “active”) — OpenExamPrep, 14 May 2026 (community guidance; not an (ISC)²-issued rule).

Summary table — what changes between today’s outline and Sept 1, 2026

Section titled “Summary table — what changes between today’s outline and Sept 1, 2026”
Item Current (Oct 1, 2025) — what the user sits tomorrow Effective Sept 1, 2026
Domain 1 Security Principles — 26% Security Principles — 24% (now also covers “governance concepts”)
Domain 2 Business Continuity, DR & Incident Response — 10% Security Governance — 17.3% (new dedicated domain)
Domain 3 Access Controls Concepts — 22% Identity and Access Management (IAM) Concepts — 20% (renamed, expanded)
Domain 4 Network Security — 24% Networking and Cloud Security Concepts — 21.3% (renamed, cloud added)
Domain 5 Security Operations — 18% Security Operations and Incident Response — 17.3% (renamed, IR merged in)
AI content Not in the Oct 2025 outline AI concepts integrated across all 5 domains
Format CAT, 100–125 items, 2 hrs, 700/1000 Same — format unchanged

Sources: CC Exam Outline, 1 Oct 2025 and CC Exam Outline effective Sept 1, 2026, ISC2 PDF.


Document URL
CC Exam Outline (effective Oct 1, 2025) https://edge.sitecorecloud.io/internationf173-xmc4e73-prodbc0f-9660/media/Project/ISC2/Main/Media/documents/exam-outlines/MAR-EXAMS-CC-Exam_Outline-English---10012025---FINAL.pdf
CC Exam Outline (effective Sept 1, 2026) https://edge.sitecorecloud.io/internationf173-xmc4e73-prodbc0f-9660/media/Project/ISC2/Main/Media/documents/exam-outlines/2026/EXAMS-CC_Exam_Outline-English-Revised-01-2026-Final.pdf
Candidate Information Bulletin (1 Oct 2025) https://edge.sitecorecloud.io/internationf173-xmc4e73-prodbc0f-9660/media/Project/ISC2/Main/Media/documents/exams/Candidate-Information-Bulletin-10012025-ENU502628.pdf
ISC2 Exam Guidance for AI (Sept 2026 update) https://edge.sitecorecloud.io/internationf173-xmc4e73-prodbc0f-9660/media/Project/ISC2/Main/Media/exam-guidance/ISC2-Exam-Guidance.pdf
CC Study Pack (ISC2 PDF) https://edge.sitecorecloud.io/internationf173-xmc4e73-prodbc0f-9660/media/Project/ISC2/Main/Media/landing/entry-level-cybersecurity/MAR-CC-Study-Pack-(2).pdf
CC Exam Ready Booklet (ISC2 PDF) https://edge.sitecorecloud.io/internationf173-xmc4e73-prodbc0f-9660/media/Project/ISC2/Main/Media/landing/entry-level-cybersecurity/MAR-CC-Exam-Ready-Booklet-(5).pdf
Certification Maintenance Handbook (ISC2 PDF) https://edge.sitecorecloud.io/internationf173-xmc4e73-prodbc0f-9660/media/Project/ISC2/Main/Media/documents/members/MEM-Certification-Maintenance-Handbook-Digital.pdf
ISC2 Press Release — CC/SSCP/CCSP go CAT (1 Oct 2025) https://www.prnewswire.com/news-releases/isc2-advances-exam-precision-security-and-experience-for-three-more-in-demand-cybersecurity-certifications-302571959.html
ISC2 LinkedIn — 1MCC surpasses 1 million (22 Apr 2026) https://www.linkedin.com/posts/isc2_isc2-provided-1-million-people-globally-with-activity-7452711274112684032-uIVr
Pearson VUE Professional & Regulatory Candidate Rules https://www.pearsonvue.com/content/dam/VUE/vue/global/documents/candidate-rules/professional-regulatory-candidate-rules-agreement.pdf
Pearson VUE Exam Check-in Process PDF https://www.pearsonvue.com/content/dam/VUE/vue/en/documents/pearson-professional-center-exam-check-in-process.pdf
ISC2 CC Voucher (Pearson VUE Government Store) https://govstore.pearsonvue.com/shop/isc2
ISC2 Code of Ethics (mirror) https://isc2chapter-phoenix.org/index.php/membership/isc-2-code-of-ethics
ISC2 Insights — Inside the Updated ISC2 CC Exam (6 Aug 2026) https://www.isc2.org/Insights/2026/08/inside-the-updated-isc2-cc-exam (URL returned server rejection at fetch time)
ISC2 Insights — 1MCC Conclusion (April 2026) https://www.isc2.org/Insights/2026/04/one-million-certified-cyber-conclusion (URL returned server rejection at fetch time)

Several (ISC)² Insights and certification pages returned server rejections (“Request Rejected / Support ID: …”) during the fetch attempts for this document. The corresponding content was retrieved instead from the source PDFs hosted on edge.sitecorecloud.io (ISC2’s own CMS) and from the press release on PRNewswire. The Insights URLs are included above for completeness; if they remain inaccessible at re-fetch, the underlying facts are still confirmed by the PDFs and the PRNewswire press release.


  • Exact pretest-item placement. The 25 pretest items are mixed into the first 100; the Candidate Information Bulletin states they are not flagged to the candidate, but does not specify their order. Treat as uniform.
  • Number of correct answers required to hit 700 scaled. Not disclosed by (ISC)². The Study Pack’s “70% accuracy” claim is marketing simplification, not an official threshold.
  • Test-day availability for late-August 2026. The bulletin lists 2026 windows (Jan 4 – Feb 2, Apr 1 – 30, Jul 11 – Aug 9, Oct 8 – Nov 6). Aug 28 sits between the Jul–Aug window and the Oct–Nov window. ISC2 does not appear to close the CC between windows in practice, but the bulletin’s exact wording is “Annual Availability” without specifying whether the exam is gated to those exact dates or merely recommended.
  • Pass rate. Not publicly disclosed by (ISC)². The ~70% figure circulating online is a community/training-provider estimate, not an official statistic.
  • Reschedule / cancellation fees for paid (non-1MCC) candidates during the 1MCC wind-down. The bulletin states 1MCC first-attempt candidates do not pay the $50/$100 fees. The standard fees still apply to paid candidates ($50 reschedule, $100 cancel).