HomeRoadmaps › ISC2 Certified in Cybersecurity
Upcoming official outline effective September 1, 2026

ISC2 Certified in Cybersecurity Roadmap

Build entry-level cyber judgment across security principles, governance, identity lifecycle, network and cloud architecture, data protection, operations, incident response, asset lifecycle, and authorized security testing.

ISC2 CC2 hoursCAT · 100–125 itemsEffective Sep 1, 20265 phases50 independent questions40 cards · 3 projects
Critical transition notice: Publication date is August 21, 2026. This package aligns to the upcoming official outline effective September 1, 2026. If the booked exam is before September 1, use the current outline effective October 1, 2025 instead. Always verify the outline attached to the booked appointment with ISC2; do not assume a study page determines the delivered form.

Upcoming ISC2 CC snapshot — effective September 1, 2026

The official upcoming outline lists a two-hour exam, 100–125 items, multiple-choice and advanced item types, a 700/1000 passing grade, Pearson VUE delivery, and CAT for listed languages. It states no specific prerequisites, cybersecurity work experience, or formal degree are required; basic IT knowledge is recommended. PrepKloud's 50-item distribution is an integer approximation of the official weights, not an official form.

24% · Bank 12Security Principles
17.3% · Bank 9Security Governance
20% · Bank 10Identity and Access Management Concepts
21.3% · Bank 11Networking and Cloud Security Concepts
17.3% · Bank 8Security Operations and Incident Response
1

Security principles, risk, controls, and ethics

Week 1

Build the vocabulary used to make every later decision.

  • Apply confidentiality, integrity, availability, authentication, authorization, accounting, non-repudiation, and privacy to simple scenarios.
  • Trace risk from context and identification through assessment, treatment, monitoring, and communication.
  • Separate regulations and laws from frameworks, policies, standards, procedures, and guidelines.
  • Classify technical, administrative, and physical controls and explain why layered controls are needed.
  • Practice due care, due diligence, professional conduct, evidence integrity, authorized disclosure, and the ISC2 Code of Ethics.
  • Reject any study method based on live, recalled, leaked, copied, or dump questions.
2

Governance, resilience, awareness, and measurement

Week 2

Connect security activity to leadership, obligations, and organizational resilience.

  • Explain the purpose and importance of Governance, Risk, and Compliance and how frameworks and tools support—not replace—accountability.
  • Distinguish business continuity, which sustains critical operations, from disaster recovery, which restores technology and data.
  • Build awareness around social engineering, phishing, password protection, reporting, and leadership-supported culture.
  • Define meaningful metrics and Key Risk Indicators with owners, sources, thresholds, quality checks, and decisions.
  • Use dashboards, scorecards, and reports to communicate effectiveness without hiding missing data or gaming measures.
  • Run discussion-only tabletop exercises in fictional scenarios with no production impact.
3

Identity lifecycle and logical access control

Week 3

Treat access as a lifecycle, not a one-time login.

  • Define roles and execute provisioning, review, role change, and deprovisioning.
  • Use frameworks and tools to automate approved policy while preserving review, exception handling, and audit.
  • Apply least privilege to people, administrators, contractors, applications, and service identities.
  • Apply separation of duties to sensitive approval and transaction paths.
  • Differentiate role-based access control, discretionary access control, mandatory access control, and other models by who sets policy and how access is decided.
  • Test successful and denied access and remove orphaned or accumulated privileges.
4

Networking, segmentation, Zero Trust, and cloud

Weeks 4–5

Reason from communication requirements and trust boundaries.

  • Review OSI and TCP/IP concepts, IPv4, IPv6, VPNs, ports, protocols, applications, and firewall decisions.
  • Identify wireless risks involving Wi-Fi and Bluetooth and the security needs of industrial, embedded, and IoT systems.
  • Use firewall zones, VLANs, and micro-segmentation to constrain paths and lateral movement.
  • Apply defense in depth so one control failure does not expose the entire environment.
  • Apply Zero Trust by evaluating identity, device, context, and least privilege instead of trusting internal location.
  • Learn cloud characteristics, IaaS/PaaS/SaaS, deployment models, and the shared security model.
5

Security operations, incident response, assets, and testing

Week 6+

Turn data and controls into defensible daily operations.

  • Classify and label data; distinguish masking and sanitization; compare symmetric, asymmetric, hashing, and planning for quantum-resistant cryptography.
  • Collect and protect logs, create event use cases, prioritize and correlate alerts, and avoid treating every alert as proof.
  • Use threat-actor context, cyber threat intelligence, and threat frameworks with explicit confidence and relevance.
  • Follow and exercise an incident response plan, including data-handling requirements and tabletop or simulation exercises.
  • Manage asset lifecycle, end-of-life technology, configuration baselines, approved changes, validation, and rollback.
  • Differentiate blue, purple, and red teaming; vulnerability scanning; static and dynamic analysis; threat modeling; and physical testing. Perform technical or human testing only with explicit authorization.
  • Complete three projects, review 40 cards, and answer the exact 12/9/10/11/8 approximation.

Three substantial defensive projects

Governance and resilience program

Create an invented risk register, policy hierarchy, control map, BC/DR priorities, awareness campaign, KRIs, dashboard, and ransomware tabletop.

Open projects

Least-privilege segmented cloud lab

Exercise identity lifecycle, roles, access models, zones, firewall flows, VPN or private administration, Zero Trust, shared responsibility, logs, and teardown.

Open projects

Defensive operations and response

Protect synthetic data, centralize logs, triage events, exercise incident response, manage EOL and changes, and compare testing methods on owned targets only.

Open projects

Use every learning surface

Official sources

Live outline page

Current exam information, current outline, and the notice and link for the September 1, 2026 transition.

ISC2 CC exam outline page
Upcoming English outline

The five domains, 24/17.3/20/21.3/17.3 weights, CAT details, and effective date.

Official September 2026 PDF
Code of Ethics

Professional obligations that inform responsible study and cybersecurity conduct.

ISC2 Code of Ethics

Frequently asked questions

Which outline does this package use?

The upcoming official ISC2 CC outline effective September 1, 2026.

What if the exam is booked before September 1?

Use the current October 1, 2025 outline and verify the blueprint attached to the appointment with ISC2. The current outline has different domain names and weights.

What is the upcoming exam format?

Two hours, 100–125 items, multiple-choice and advanced item types, and CAT as specified in the upcoming outline.

How is the 50-question bank allocated?

Exactly 12 Security Principles, 9 Security Governance, 10 IAM Concepts, 11 Networking and Cloud Security Concepts, and 8 Security Operations and Incident Response questions.

Is work experience required?

The upcoming outline states no specific prerequisites, cybersecurity work experience, or formal degree is required. Basic IT knowledge is recommended.

Do practice scores guarantee a pass?

No. The independent original practice bank is not the official 100–125-item CAT exam and cannot predict or guarantee a result.

Independence, transition, and safety disclaimer: ISC2 and CC names belong to ISC2. PrepKloud is independent and not affiliated with or endorsed by ISC2. This content targets the official outline effective September 1, 2026. Candidates testing earlier must use the current outline and verify their booked date. No dumps, recalled items, pass guarantee, job promise, or authorization to test real people or systems is provided.

Prepare with ethics, evidence, and safe practice

Combine official scope, original scenarios, spaced recall, and three defensive synthetic projects.