Menu
CC Success Toolkit20-Hour Programme · 2026 Outline

CC Certification Training — a 20-Hour ISC2 Course Built on the 2026 Exam Outline

From 1 September 2026 the Certified in Cybersecurity exam runs on a new outline — five renamed domains, a 17.3% governance domain, cloud and IAM pulled into the syllabus. If your study material was written for the old outline, you’re preparing for an exam that no longer exists. This programme is built on the new one.

5 domains · 24 / 17.3 / 20 / 21.3 / 17.3
100–125 questions · 2 hours · 700/1000
No experience required
4.8★ Trustpilot(45)
5.0★ Google(153)
4.7★ Udemy(737)

Already enrolled? Go to your dashboard.

Get Your Personalised CC Study Plan

Tell us your background and our team will map your 20 hours, your batch dates and the fee for your region.

We respect your privacy. No spam, ever.

Next Batch

CISSP Batch 56 Starting 28 June 2026

Start Here

Entry-level does not mean easy. It means broad.

Most people fail the CC exam for two reasons that have nothing to do with intelligence: the breadth of five domains with no single one to hide in, and the adaptive format that never lets you go back. Since 1 September 2026 there is a third — studying from material written for the 2022 outline.

You do not need to be a network engineer to pass CC. You need the vocabulary and the why across five different areas, and you need it at the same time. In a normal linear exam you can be weak in one domain and make it up in another. In CAT, the engine finds your weak domain and stays there. The first fifteen questions settle its opinion of you; a shaky start costs more than a shaky finish, and there is no back button.

The second problem is newer. Nearly every free resource — the YouTube playlists, the shared notes, the old free ISC2 course — teaches the outline that expired on 31 August 2026. Business continuity is no longer a domain. Governance is. Cloud, zero trust, identity lifecycle, threat intelligence and incident-response exercises are now in the syllabus. If your study plan does not have those words in it, you are preparing for a different exam.

This course fixes both problems in the same 20 hours: coverage weighted the way the 2026 exam is weighted, and timed adaptive-style mocks so exam day is not the first time you meet the format.

The Credential

What is the ISC2 Certified in Cybersecurity (CC) certification?

Certified in Cybersecurity (CC) is ISC2’s entry-level credential, launched in August 2022 for people entering cybersecurity without direct IT experience. It has no prerequisite, grants full ISC2 membership on passing, is approved under U.S. DoDM 8140.03, and sits below SSCP, CCSP, CGRC and CISSP on the ISC2 ladder.

ISC2 is the body behind the CISSP — the most recognised security certification in the world — and CC is its front door. It is a knowledge and judgement exam, not a hands-on lab exam, which is exactly why it suits a career switcher, a final-year student or an IT support engineer who wants to move across. Two things make it different from every other ISC2 certification. First, there is no experience requirement — you pass, you complete the application, you are a certified member. Second, the exam fee is US$199, the lowest in the ISC2 catalogue.

1

Register

No prerequisite — anyone can book the exam.

2

Pass

Score 700 / 1000 on the adaptive exam.

3

Certified member

Apply within 9 months + US$50 annual fee.

Official reference: ISC2 Certified in Cybersecurity page.

2026 Outline

What changed in the CC exam on 1 September 2026

On 1 September 2026 ISC2 replaced the CC exam outline for the first time since launch. The exam keeps five domains, but four were renamed and all were re-weighted — and foundational AI concepts now run through every domain.

2025 outline (to 31 Aug 2026)Weight2026 outline (from 1 Sep 2026)Weight
Security Principles26%Security Principles24%
Business Continuity, DR & Incident Response10%Security Governance17.3%
Access Controls Concepts22%Identity and Access Management (IAM) Concepts20%
Network Security24%Networking and Cloud Security Concepts21.3%
Security Operations18%Security Operations and Incident Response17.3%

Why did ISC2 do this? Because the job changed. The old Business Continuity, DR and Incident Response domain (10%) became Security Governance (17.3%): GRC, security culture, metrics, key risk indicators, dashboards and reports. BC and DR did not disappear; they moved under redundancy concepts, and incident response moved into Domain 5.

The three other renames are additions, not replacements. Access Controls became Identity and Access Management Concepts and picked up the identity lifecycle. Network Security became Networking and Cloud Security Concepts, adding cloud service and deployment models, shared responsibility and zero trust. Security Operations became Security Operations and Incident Response, the domain that grew the most — threat intelligence, threat frameworks, red/blue/purple teaming, threat modeling, data masking, sanitisation and quantum-resistant cryptography. If you sit the exam now, all of it applies. There is no transition window.

The Syllabus

The five CC domains — and where the exam actually sits

Security Principles (24%) and Networking and Cloud Security (21.3%) together are 45% of the exam. But the adaptive engine tests all five, so no domain can be skipped.

Domain 1: Security Principles

24%

CIA triad; authentication, authorization and accounting (AAA); non-repudiation; privacy; risk management concepts and lifecycle; technical, administrative and physical controls; governance elements — policies, standards, procedures, frameworks, guidelines, regulations and laws; ISC2 Code of Ethics with due care and due diligence.

Coach’s note: This is the vocabulary domain. Every other domain reuses these words. If you can explain the difference between a policy, a standard and a procedure to a friend in one line each, you own this domain.

Domain 2: Security Governance

17.3%

Governance, Risk and Compliance (GRC); organisational security awareness and cybersecurity culture; measuring programme effectiveness with metrics, key risk indicators (KRIs), dashboards and reports; business continuity and disaster recovery, now covered as redundancy concepts.

Coach’s note: This is the domain that did not exist before September 2026 — it replaced Business Continuity, DR and Incident Response. An entry-level analyst is far more likely to be asked to update a risk dashboard or run an awareness campaign than to invoke a DR plan.

Domain 3: Identity and Access Management (IAM) Concepts

20%

Physical and logical access controls; least privilege and segregation of duties; DAC, MAC and RBAC; identity lifecycle — provisioning, review and deprovisioning; role definitions; IAM frameworks and tools; multi-factor authentication and AI-assisted anomaly detection such as impossible-travel logins.

Coach’s note: Identity is the perimeter now. Very simple rule: every question here is asking one of three things — who are you, what may you do, or what did you do. Decide which one before you look at the options.

Domain 4: Networking and Cloud Security Concepts

21.3%

OSI and TCP/IP models; IPv4 and IPv6; ports and applications; threats such as DDoS, malware, man-in-the-middle and side-channel attacks; IDS, IPS and firewalls; segmentation — DMZ, VLAN, VPN, micro-segmentation; defence in depth; NAC; zero trust; wireless; IoT and industrial control systems; cloud characteristics, service models, deployment models and the shared responsibility model.

Coach’s note: Do not memorise the seven OSI layers as a poem. Ask what breaks at each layer and what you would use to fix it — that is how the exam frames it. Cloud is new here: know who is responsible for what in IaaS, PaaS and SaaS.

Domain 5: Security Operations and Incident Response

17.3%

Encryption basics — symmetric, asymmetric, hashing; data handling, classification, retention and destruction; data masking and sanitisation; quantum-resistant cryptography awareness; logging, monitoring and SIEM; security event triage and prioritisation; configuration management and hardening; security policies — AUP, BYOD, password, change management, privacy; awareness training; threat actors and motivations; cyber threat intelligence and threat frameworks; incident response planning and exercises; asset lifecycle; readiness testing with red, blue and purple teams; application security testing, threat modeling and physical penetration-testing concepts.

Coach’s note: This is the 'doing' domain and it grew the most in 2026 — incident response moved in here. If you want a SOC seat, this is the domain to over-prepare, because this is the vocabulary of your first job.

The Exam

CC exam format, scoring and cost

Issuer

ISC2 (the CISSP body) · launched August 2022

Format

Computerized Adaptive Testing (CAT) at Pearson VUE

Items

100–125, multiple-choice + advanced item types

Duration

2 hours

Passing score

700 / 1000 (scaled)

Languages

English, Chinese, Japanese, German, Spanish

Prerequisite

None — no experience, degree or prior cert

Exam fee

US$199 standard (regional pricing varies)

Staying certified

US$50 annual maintenance fee · 45 CPEs per 3-year cycle

New outline

Effective 1 September 2026 · AI integrated throughout

The exam fee is paid to ISC2 at scheduling and is separate from Cybernous training fees. Figures per isc2.org and subject to change — re-verify on the ISC2 registration page before booking.

Free Programme

Is the free ISC2 CC programme still available?

No — public enrolment in ISC2’s One Million Certified in Cybersecurity programme (free training plus a free exam) closed on 20 May 2026. Candidates holding unexpired exam codes may still schedule and test until 31 December 2026. Everyone else pays the standard US$199 exam fee.

I have a code

Book your date now, not in December — and know that the free code does not freeze the syllabus. Any exam sat on or after 1 September 2026 is on the new outline, so governance, cloud, identity lifecycle and incident response are gaps to close before you sit.

I don’t have a code

Nothing is lost. US$199 for an ISC2 credential with no prerequisite is still the best-value entry ticket in the field. The question is not whether to pay for the exam; it is whether to pay for it once.

Who It’s For

Who should take CC?

Career switchers with no IT background — CC assumes no prior experience.

Students and freshers — the line that gets the security interview, not the generic IT one.

IT support, networking or sysadmin staff moving across — you already know half of Domain 4.

Aspiring SOC analysts — Domain 5 is your job description: triage, SIEM, threat intel, IR.

Holders of a free 1MCC exam code that expires on 31 December 2026.

Not for you if… you already hold Security+, SSCP or CISSP — go to the CISSP or CISM toolkits instead.

Your 20 Hours

How the 20 hours are spent

BlockHoursExam weightWhat you finish with
D1 · Security Principles4 h24%The vocabulary, AAA, control types, policy vs standard vs procedure, risk lifecycle, the Code of Ethics.
D2 · Security Governance3 h17.3%GRC, security culture, metrics and KRIs, BC/DR as redundancy.
D3 · IAM Concepts3.5 h20%Identity lifecycle, DAC/MAC/RBAC, least privilege, MFA, IAM tools.
D4 · Networking and Cloud Security3.5 h21.3%OSI by "what breaks here", segmentation, zero trust, cloud service and deployment models, shared responsibility.
D5 · Security Operations and Incident Response + the AI layer3 h17.3%Triage, SIEM, threat intel, IR playbooks, hardening, data handling, how AI touches each domain.
Final exam sprint3 hFull-length timed CAT-style mocks, review of misses, exam booking and application walkthrough.

Domains 1 and 4 are 45% of the exam, so they get the most hours, and the final block is mocks — because exam day must not be the first time you sit 120 adaptive questions against a clock.

What’s Included

Everything in the CC Success Toolkit

20 hours of live coaching, recorded for replay

The 20-hour structured plan, weighted to the 2026 exam

Smart notes for all five domains, written for the 2026 outline

An old-versus-new outline map — what moved, appeared or disappeared

A CC-format question bank with explanations that teach the why

Full-length timed CAT-style mocks (100–125 items, 2 hours, no back-navigation)

Domain revision days for consolidation

The Confusion Clinic — policy vs standard, DAC/MAC/RBAC, IDS vs IPS, symmetric vs asymmetric

1:1 mentorship when a concept will not land

Exam booking and application walkthrough (Pearson VUE, the 9-month application, the AMF)

A career next-step session (CC → SOC / GRC → SSCP → CISSP)

LMS access plus the alumni community

Inside the Platform

Everything runs inside one LMS

Notes, questions, mocks, session replays, progress tracking and mentor chat in one place — no Telegram groups, no PDFs in five folders. The plan tells you what today is; the dashboard tells you which domain is dragging your mock score.

Your Coach

Led by Karthick AR

Lead instructor — Karthick AR

The Cybernous CC programme is led by Karthick AR — Certified Ethical Hacker (CEH), CPISI, and ISC2 Certified in Cybersecurity (CC) — with 6+ years of cybersecurity experience across SOC analysis, risk and compliance engineering, and security training delivery, including CCSP, CISSP, CISM, CISA and CEH training at organisations such as Knowledge Academy and SISA Institute. Karthick teaches every cohort personally, walks through every domain on the 2026 outline, and reviews each student’s mock results individually.

Choosing

CC, Security+ or SSCP — which one is yours?

CompTIA Security+

Also entry-level and vendor-neutral, but more technical and hands-on; CompTIA recommends prior networking and IT-admin exposure. Holding CC makes Security+ easier later.

Security+ course

SSCP (ISC2)

ISC2's administrator-level credential; needs one year of paid experience. The natural second step after CC once you are in a role.

Read on SSCP

The clean sequence for a beginner is CC → a role → Security+ or SSCP → CISSP at five years. Don’t start at the middle of the ladder.

What Comes Next

After CC — the ISC2 ladder and your next 12 months

SOC analyst (Tier 1)

IT security support

IAM administration

GRC / compliance associate

What keeps you climbing is the ladder: SSCP after one year, CISSP after five, CISM towards management, CCSP when your work goes to cloud. Read the SOC analyst starter guide and top cybersecurity certifications for 2026.

The Method, Proven

2,000+ professionals, coached the same way

CC is a new Cybernous programme, so we publish no CC pass-rate data yet — and we will not invent one. What we can show you is the coaching method behind it: the same live-coached, mock-driven approach that Cybernous founder Manoj Sharma (CISSP, ISC² #557313) built over 29+ years and used to certify 812 CISSP professionals at a 98.3% first-attempt pass rate. Karthick AR delivers CC using that method.

RK

Rajesh Kumar

Senior Security Analyst, TCS

Cybernous training helped me clear CISSP in my first attempt. The hands-on labs and mentoring made all the difference.

PS

Priya Sharma

CISO, Tech Startup

The corporate training program transformed our security team. Highly professional and results-driven.

AH

Ahmed Hassan

Cybersecurity Consultant

Best investment in my career. The practical approach and exam strategies were invaluable.

Your Region

Coached in your timezone, priced for your region

India

Live sessions in IST, fees in INR — the credential campus recruiters name first for freshers.

Gulf

Weekend sessions aligned to GST — a first step for IT staff moving into national-framework roles.

APAC

Sessions timed for SGT/AEST cohorts; English exam, local test centres.

Americas

DoDM 8140.03 approval — a recognised baseline for U.S. defence and contractor roles.

Still Deciding? Request a Callback

Tell us your background and we will map your 20 hours, your batch dates and the fee for your region — no pressure.

We respect your privacy. No spam, ever.

Have Questions?

CC certification — frequently asked questions

Certified in Cybersecurity, usually shortened to CC, is the entry-level certification from ISC2 — the same body that runs the CISSP. ISC2 launched it in August 2022 specifically for people entering cybersecurity without direct IT experience: career switchers, students, and IT support staff moving into security. It proves to an employer that you understand the foundational vocabulary and concepts across five domains — security principles, governance, identity and access management, networking and cloud security, and security operations and incident response — and that you can learn on the job. It sits at the bottom of the ISC2 ladder, below SSCP, CCSP, CGRC and CISSP, and it is approved under U.S. DoDM 8140.03. It is not a hands-on technical certification; it is a knowledge and judgement certification, which is exactly why it suits a beginner.
No. CC is the only major ISC2 certification with no work-experience requirement, no degree requirement and no prerequisite certification. Anyone can register, sit the exam and — on passing — become a full certified member after completing the ISC2 application and agreeing to the Code of Ethics. That is different from SSCP and CISSP, where you pass first and then serve as an Associate of ISC2 until you have the required years. Please understand one thing very clearly, though: no prerequisite does not mean no preparation. The exam is broad, it is adaptive, and you cannot go back to change an answer. Candidates with an IT background usually find it moderate; candidates with none find the breadth the hard part. Structured study over four to six weeks closes that gap for most people.
The CC exam is delivered as Computerized Adaptive Testing (CAT) at Pearson VUE test centres. You get 2 hours and between 100 and 125 items — multiple-choice plus some advanced item types — and you need a scaled score of 700 out of 1000 to pass. Because it is adaptive, the engine chooses your next question based on how you answered the last one, two candidates never see the same set, and you cannot return to an earlier question. Your early answers carry more weight in settling the engine's estimate of your ability, so a shaky first fifteen minutes costs more than a shaky last fifteen. The exam is offered in English, Chinese, Japanese, German and Spanish. You find out whether you passed before you leave the test centre; ISC2 does not release your numeric score.
On 1 September 2026 ISC2 moved the CC exam to a new outline — the first major content update since the certification launched in 2022. The exam keeps five domains, but four were renamed and all were re-weighted. Security Principles drops from 26% to 24%. The old Business Continuity, Disaster Recovery and Incident Response domain (10%) is replaced by Security Governance at 17.3%, covering GRC, security culture, metrics and key risk indicators. Access Controls Concepts (22%) becomes Identity and Access Management (IAM) Concepts at 20%, adding identity lifecycle and provisioning. Network Security (24%) becomes Networking and Cloud Security Concepts at 21.3%, adding cloud service and deployment models, shared responsibility and zero trust. Security Operations (18%) becomes Security Operations and Incident Response at 17.3%, absorbing incident response and adding threat intelligence, threat frameworks, red, blue and purple teaming, threat modeling, data masking and quantum-resistant cryptography. Foundational AI concepts run through all five domains. Any exam sat on or after 1 September 2026 uses the new outline.
The exam itself is US$199 in most regions; regional pricing and taxes vary, so check the ISC2 exam registration page for your country. After you pass, you complete the ISC2 certification application within nine months and pay an Annual Maintenance Fee of US$50 per year, which keeps you a member in good standing. To renew without re-testing you earn 45 CPE credits over each three-year cycle — roughly 15 a year, which webinars, chapter meetings and continued study cover easily. There is no endorsement requirement for CC. Cybernous training fees are separate from all of this and are paid to us, not to ISC2; the exam fee is always paid directly to ISC2 when you schedule at Pearson VUE. Budget for one exam attempt done properly rather than two attempts done in a hurry.
For most people, no. ISC2's One Million Certified in Cybersecurity programme — free self-paced training plus a free exam voucher — closed to new public enrolment on 20 May 2026. If you already hold an unexpired exam code from that programme, ISC2 has said you can still schedule and sit the exam until 31 December 2026, so book it now rather than in December. Everyone else pays the standard US$199 exam fee, exactly like any other ISC2 exam. One thing voucher-holders must understand very clearly: the free code does not freeze the syllabus. Any exam taken on or after 1 September 2026 is on the new outline, so if your free training was the 2022–2025 material, you need to fill the governance, cloud, IAM and incident-response gaps before you sit.
Most candidates need four to six weeks of structured study; ISC2 does not publish a required number of hours. Someone already working in IT support or networking can compress this; someone with no IT background should give it the full run and not skip Domain 4. The Cybernous course is 20 hours of live coaching, spread across sessions that fit around a working day or a college timetable rather than study leave, with the final block reserved for full-length timed CAT-style mocks and revision. Between sessions you work the question bank in the LMS, which is where the score actually moves. The biggest time-waster we see is passive reading: watching videos and highlighting notes feels like progress and is not. Reading a domain once, then answering questions on it until the explanations make sense, is what moves your score.
Very simple: if you have no experience and want the fastest, cheapest credible proof that you understand security, take CC. It has no prerequisite, it is the only ISC2 certification that grants full membership on passing, and the exam is US$199. Security+ is also entry-level and vendor-neutral, but its questions are more technical and hands-on, and CompTIA recommends prior networking and IT-administration exposure. On the other side, SSCP is ISC2's administrator-level credential and requires one year of paid experience in one of its domains — pass without it and you are an Associate of ISC2 until you have the year. A clean path for a beginner is CC first, then Security+ or SSCP once you are in a role, then CISSP when you reach five years of experience. Many employers list Security+ and CC as equivalent 'or' options on entry-level job descriptions; holding CC does not close the Security+ door later.
For a beginner, yes — with the honest caveat that no entry-level certificate gets you hired on its own. What CC does is remove the first objection: it tells a hiring manager you understand the vocabulary, the CIA triad, access control, networking, cloud basics and incident response well enough to be trained. It carries ISC2’s name, which recruiters recognise from CISSP, and it is approved under DoDM 8140.03 for U.S. defence roles. In 2026 the credential is more useful than it was two years ago, not less: the new outline covers governance, cloud, zero trust, threat intelligence and AI — the things entry-level analysts are actually asked about in interviews. Pair it with a lab project, a home SOC setup or an internship and it becomes a real conversation starter. Treat it as a foundation to build on, not a finish line.
The ISC2 self-paced course is a decent reference, and a disciplined candidate can pass with it plus practice questions. Where self-study breaks down is in three places. First, breadth — five domains with nobody telling you where you are weak, so you keep re-reading the domain you already like. Second, the format — CAT punishes early mistakes and offers no going back, and very few self-study candidates ever sit a timed adaptive-style mock before the real thing. Third, the outline change — most free material still teaches the 2022 syllabus. Cybernous runs a live-coached 20-hour course built on the 2026 outline, with a CC-format question bank, full-length timed mocks, an old-versus-new outline map, and 1:1 mentoring when a concept will not land. You study the same number of hours; you just stop spending them on the wrong things.
Start Your CC Journey

Start Your CC Certification Training

The exam changed on 1 September 2026. Your preparation should have too. Twenty hours, coached live, built on the outline you will actually sit.

In short

The ISC2 Certified in Cybersecurity (CC) is the entry-level ISC2 certification: no experience prerequisite, 100–125 adaptive questions in 2 hours, 700 out of 1000 to pass, US$199 exam fee. From 1 September 2026 it covers five domains — Security Principles (24%), Security Governance (17.3%), IAM Concepts (20%), Networking and Cloud Security Concepts (21.3%), Security Operations and Incident Response (17.3%) — with AI concepts across all five. Cybernous prepares you for exactly that outline: a 20-hour live-coached course led by Karthick AR, with a question bank, timed CAT-style mocks and 1:1 mentoring. CC is a new Cybernous programme with no CC outcome data yet; the outcomes cited — 812 CISSP-certified professionals at a 98.3% first-attempt pass rate — are from its CISSP programme using the same coaching method.

ISC2, CISSP and Certified in Cybersecurity (CC) are trademarks of ISC2. This course is independent preparation and is not affiliated with or endorsed by ISC2. Exam facts verified against isc2.org; re-verify the exam fee, CC outline and One Million CC programme status on isc2.org before booking.