CC Certification Training — a 20-Hour ISC2 Course Built on the 2026 Exam Outline
From 1 September 2026 the Certified in Cybersecurity exam runs on a new outline — five renamed domains, a 17.3% governance domain, cloud and IAM pulled into the syllabus. If your study material was written for the old outline, you’re preparing for an exam that no longer exists. This programme is built on the new one.
Already enrolled? Go to your dashboard.
Get Your Personalised CC Study Plan
Tell us your background and our team will map your 20 hours, your batch dates and the fee for your region.
CISSP Batch 56 Starting 28 June 2026
Entry-level does not mean easy. It means broad.
Most people fail the CC exam for two reasons that have nothing to do with intelligence: the breadth of five domains with no single one to hide in, and the adaptive format that never lets you go back. Since 1 September 2026 there is a third — studying from material written for the 2022 outline.
You do not need to be a network engineer to pass CC. You need the vocabulary and the why across five different areas, and you need it at the same time. In a normal linear exam you can be weak in one domain and make it up in another. In CAT, the engine finds your weak domain and stays there. The first fifteen questions settle its opinion of you; a shaky start costs more than a shaky finish, and there is no back button.
The second problem is newer. Nearly every free resource — the YouTube playlists, the shared notes, the old free ISC2 course — teaches the outline that expired on 31 August 2026. Business continuity is no longer a domain. Governance is. Cloud, zero trust, identity lifecycle, threat intelligence and incident-response exercises are now in the syllabus. If your study plan does not have those words in it, you are preparing for a different exam.
This course fixes both problems in the same 20 hours: coverage weighted the way the 2026 exam is weighted, and timed adaptive-style mocks so exam day is not the first time you meet the format.
What is the ISC2 Certified in Cybersecurity (CC) certification?
Certified in Cybersecurity (CC) is ISC2’s entry-level credential, launched in August 2022 for people entering cybersecurity without direct IT experience. It has no prerequisite, grants full ISC2 membership on passing, is approved under U.S. DoDM 8140.03, and sits below SSCP, CCSP, CGRC and CISSP on the ISC2 ladder.
ISC2 is the body behind the CISSP — the most recognised security certification in the world — and CC is its front door. It is a knowledge and judgement exam, not a hands-on lab exam, which is exactly why it suits a career switcher, a final-year student or an IT support engineer who wants to move across. Two things make it different from every other ISC2 certification. First, there is no experience requirement — you pass, you complete the application, you are a certified member. Second, the exam fee is US$199, the lowest in the ISC2 catalogue.
Register
No prerequisite — anyone can book the exam.
Pass
Score 700 / 1000 on the adaptive exam.
Certified member
Apply within 9 months + US$50 annual fee.
Official reference: ISC2 Certified in Cybersecurity page.
What changed in the CC exam on 1 September 2026
On 1 September 2026 ISC2 replaced the CC exam outline for the first time since launch. The exam keeps five domains, but four were renamed and all were re-weighted — and foundational AI concepts now run through every domain.
| 2025 outline (to 31 Aug 2026) | Weight | 2026 outline (from 1 Sep 2026) | Weight |
|---|---|---|---|
| Security Principles | 26% | Security Principles | 24% |
| Business Continuity, DR & Incident Response | 10% | Security Governance | 17.3% |
| Access Controls Concepts | 22% | Identity and Access Management (IAM) Concepts | 20% |
| Network Security | 24% | Networking and Cloud Security Concepts | 21.3% |
| Security Operations | 18% | Security Operations and Incident Response | 17.3% |
Why did ISC2 do this? Because the job changed. The old Business Continuity, DR and Incident Response domain (10%) became Security Governance (17.3%): GRC, security culture, metrics, key risk indicators, dashboards and reports. BC and DR did not disappear; they moved under redundancy concepts, and incident response moved into Domain 5.
The three other renames are additions, not replacements. Access Controls became Identity and Access Management Concepts and picked up the identity lifecycle. Network Security became Networking and Cloud Security Concepts, adding cloud service and deployment models, shared responsibility and zero trust. Security Operations became Security Operations and Incident Response, the domain that grew the most — threat intelligence, threat frameworks, red/blue/purple teaming, threat modeling, data masking, sanitisation and quantum-resistant cryptography. If you sit the exam now, all of it applies. There is no transition window.
The five CC domains — and where the exam actually sits
Security Principles (24%) and Networking and Cloud Security (21.3%) together are 45% of the exam. But the adaptive engine tests all five, so no domain can be skipped.
Domain 1: Security Principles
CIA triad; authentication, authorization and accounting (AAA); non-repudiation; privacy; risk management concepts and lifecycle; technical, administrative and physical controls; governance elements — policies, standards, procedures, frameworks, guidelines, regulations and laws; ISC2 Code of Ethics with due care and due diligence.
Coach’s note: This is the vocabulary domain. Every other domain reuses these words. If you can explain the difference between a policy, a standard and a procedure to a friend in one line each, you own this domain.
Domain 2: Security Governance
Governance, Risk and Compliance (GRC); organisational security awareness and cybersecurity culture; measuring programme effectiveness with metrics, key risk indicators (KRIs), dashboards and reports; business continuity and disaster recovery, now covered as redundancy concepts.
Coach’s note: This is the domain that did not exist before September 2026 — it replaced Business Continuity, DR and Incident Response. An entry-level analyst is far more likely to be asked to update a risk dashboard or run an awareness campaign than to invoke a DR plan.
Domain 3: Identity and Access Management (IAM) Concepts
Physical and logical access controls; least privilege and segregation of duties; DAC, MAC and RBAC; identity lifecycle — provisioning, review and deprovisioning; role definitions; IAM frameworks and tools; multi-factor authentication and AI-assisted anomaly detection such as impossible-travel logins.
Coach’s note: Identity is the perimeter now. Very simple rule: every question here is asking one of three things — who are you, what may you do, or what did you do. Decide which one before you look at the options.
Domain 4: Networking and Cloud Security Concepts
OSI and TCP/IP models; IPv4 and IPv6; ports and applications; threats such as DDoS, malware, man-in-the-middle and side-channel attacks; IDS, IPS and firewalls; segmentation — DMZ, VLAN, VPN, micro-segmentation; defence in depth; NAC; zero trust; wireless; IoT and industrial control systems; cloud characteristics, service models, deployment models and the shared responsibility model.
Coach’s note: Do not memorise the seven OSI layers as a poem. Ask what breaks at each layer and what you would use to fix it — that is how the exam frames it. Cloud is new here: know who is responsible for what in IaaS, PaaS and SaaS.
Domain 5: Security Operations and Incident Response
Encryption basics — symmetric, asymmetric, hashing; data handling, classification, retention and destruction; data masking and sanitisation; quantum-resistant cryptography awareness; logging, monitoring and SIEM; security event triage and prioritisation; configuration management and hardening; security policies — AUP, BYOD, password, change management, privacy; awareness training; threat actors and motivations; cyber threat intelligence and threat frameworks; incident response planning and exercises; asset lifecycle; readiness testing with red, blue and purple teams; application security testing, threat modeling and physical penetration-testing concepts.
Coach’s note: This is the 'doing' domain and it grew the most in 2026 — incident response moved in here. If you want a SOC seat, this is the domain to over-prepare, because this is the vocabulary of your first job.
CC exam format, scoring and cost
Issuer
ISC2 (the CISSP body) · launched August 2022
Format
Computerized Adaptive Testing (CAT) at Pearson VUE
Items
100–125, multiple-choice + advanced item types
Duration
2 hours
Passing score
700 / 1000 (scaled)
Languages
English, Chinese, Japanese, German, Spanish
Prerequisite
None — no experience, degree or prior cert
Exam fee
US$199 standard (regional pricing varies)
Staying certified
US$50 annual maintenance fee · 45 CPEs per 3-year cycle
New outline
Effective 1 September 2026 · AI integrated throughout
The exam fee is paid to ISC2 at scheduling and is separate from Cybernous training fees. Figures per isc2.org and subject to change — re-verify on the ISC2 registration page before booking.
Is the free ISC2 CC programme still available?
No — public enrolment in ISC2’s One Million Certified in Cybersecurity programme (free training plus a free exam) closed on 20 May 2026. Candidates holding unexpired exam codes may still schedule and test until 31 December 2026. Everyone else pays the standard US$199 exam fee.
I have a code
Book your date now, not in December — and know that the free code does not freeze the syllabus. Any exam sat on or after 1 September 2026 is on the new outline, so governance, cloud, identity lifecycle and incident response are gaps to close before you sit.
I don’t have a code
Nothing is lost. US$199 for an ISC2 credential with no prerequisite is still the best-value entry ticket in the field. The question is not whether to pay for the exam; it is whether to pay for it once.
Who should take CC?
Career switchers with no IT background — CC assumes no prior experience.
Students and freshers — the line that gets the security interview, not the generic IT one.
IT support, networking or sysadmin staff moving across — you already know half of Domain 4.
Aspiring SOC analysts — Domain 5 is your job description: triage, SIEM, threat intel, IR.
Holders of a free 1MCC exam code that expires on 31 December 2026.
How the 20 hours are spent
| Block | Hours | Exam weight | What you finish with |
|---|---|---|---|
| D1 · Security Principles | 4 h | 24% | The vocabulary, AAA, control types, policy vs standard vs procedure, risk lifecycle, the Code of Ethics. |
| D2 · Security Governance | 3 h | 17.3% | GRC, security culture, metrics and KRIs, BC/DR as redundancy. |
| D3 · IAM Concepts | 3.5 h | 20% | Identity lifecycle, DAC/MAC/RBAC, least privilege, MFA, IAM tools. |
| D4 · Networking and Cloud Security | 3.5 h | 21.3% | OSI by "what breaks here", segmentation, zero trust, cloud service and deployment models, shared responsibility. |
| D5 · Security Operations and Incident Response + the AI layer | 3 h | 17.3% | Triage, SIEM, threat intel, IR playbooks, hardening, data handling, how AI touches each domain. |
| Final exam sprint | 3 h | — | Full-length timed CAT-style mocks, review of misses, exam booking and application walkthrough. |
Domains 1 and 4 are 45% of the exam, so they get the most hours, and the final block is mocks — because exam day must not be the first time you sit 120 adaptive questions against a clock.
Everything in the CC Success Toolkit
20 hours of live coaching, recorded for replay
The 20-hour structured plan, weighted to the 2026 exam
Smart notes for all five domains, written for the 2026 outline
An old-versus-new outline map — what moved, appeared or disappeared
A CC-format question bank with explanations that teach the why
Full-length timed CAT-style mocks (100–125 items, 2 hours, no back-navigation)
Domain revision days for consolidation
The Confusion Clinic — policy vs standard, DAC/MAC/RBAC, IDS vs IPS, symmetric vs asymmetric
1:1 mentorship when a concept will not land
Exam booking and application walkthrough (Pearson VUE, the 9-month application, the AMF)
A career next-step session (CC → SOC / GRC → SSCP → CISSP)
LMS access plus the alumni community
Built on the outline you will actually sit.
Live coaching, a 2026-outline question bank, timed CAT-style mocks and 1:1 mentoring — in one place.
Everything runs inside one LMS
Notes, questions, mocks, session replays, progress tracking and mentor chat in one place — no Telegram groups, no PDFs in five folders. The plan tells you what today is; the dashboard tells you which domain is dragging your mock score.
Led by Karthick AR
Lead instructor — Karthick AR
The Cybernous CC programme is led by Karthick AR — Certified Ethical Hacker (CEH), CPISI, and ISC2 Certified in Cybersecurity (CC) — with 6+ years of cybersecurity experience across SOC analysis, risk and compliance engineering, and security training delivery, including CCSP, CISSP, CISM, CISA and CEH training at organisations such as Knowledge Academy and SISA Institute. Karthick teaches every cohort personally, walks through every domain on the 2026 outline, and reviews each student’s mock results individually.
CC, Security+ or SSCP — which one is yours?
CC (ISC2)
No prerequisite. Full ISC2 membership on passing. US$199. Knowledge and judgement across five domains — the right first move for a switcher, student or helpdesk engineer.
CompTIA Security+
Also entry-level and vendor-neutral, but more technical and hands-on; CompTIA recommends prior networking and IT-admin exposure. Holding CC makes Security+ easier later.
Security+ courseSSCP (ISC2)
ISC2's administrator-level credential; needs one year of paid experience. The natural second step after CC once you are in a role.
Read on SSCPThe clean sequence for a beginner is CC → a role → Security+ or SSCP → CISSP at five years. Don’t start at the middle of the ladder.
After CC — the ISC2 ladder and your next 12 months
SOC analyst (Tier 1)
IT security support
IAM administration
GRC / compliance associate
What keeps you climbing is the ladder: SSCP after one year, CISSP after five, CISM towards management, CCSP when your work goes to cloud. Read the SOC analyst starter guide and top cybersecurity certifications for 2026.
2,000+ professionals, coached the same way
CC is a new Cybernous programme, so we publish no CC pass-rate data yet — and we will not invent one. What we can show you is the coaching method behind it: the same live-coached, mock-driven approach that Cybernous founder Manoj Sharma (CISSP, ISC² #557313) built over 29+ years and used to certify 812 CISSP professionals at a 98.3% first-attempt pass rate. Karthick AR delivers CC using that method.
Rajesh Kumar
Senior Security Analyst, TCS
“Cybernous training helped me clear CISSP in my first attempt. The hands-on labs and mentoring made all the difference.”
Priya Sharma
CISO, Tech Startup
“The corporate training program transformed our security team. Highly professional and results-driven.”
Ahmed Hassan
Cybersecurity Consultant
“Best investment in my career. The practical approach and exam strategies were invaluable.”
Coached in your timezone, priced for your region
India
Live sessions in IST, fees in INR — the credential campus recruiters name first for freshers.
Gulf
Weekend sessions aligned to GST — a first step for IT staff moving into national-framework roles.
APAC
Sessions timed for SGT/AEST cohorts; English exam, local test centres.
Americas
DoDM 8140.03 approval — a recognised baseline for U.S. defence and contractor roles.
Still Deciding? Request a Callback
Tell us your background and we will map your 20 hours, your batch dates and the fee for your region — no pressure.
CC certification — frequently asked questions
Getting started in cybersecurity
Start Your CC Certification Training
The exam changed on 1 September 2026. Your preparation should have too. Twenty hours, coached live, built on the outline you will actually sit.
In short
The ISC2 Certified in Cybersecurity (CC) is the entry-level ISC2 certification: no experience prerequisite, 100–125 adaptive questions in 2 hours, 700 out of 1000 to pass, US$199 exam fee. From 1 September 2026 it covers five domains — Security Principles (24%), Security Governance (17.3%), IAM Concepts (20%), Networking and Cloud Security Concepts (21.3%), Security Operations and Incident Response (17.3%) — with AI concepts across all five. Cybernous prepares you for exactly that outline: a 20-hour live-coached course led by Karthick AR, with a question bank, timed CAT-style mocks and 1:1 mentoring. CC is a new Cybernous programme with no CC outcome data yet; the outcomes cited — 812 CISSP-certified professionals at a 98.3% first-attempt pass rate — are from its CISSP programme using the same coaching method.
ISC2, CISSP and Certified in Cybersecurity (CC) are trademarks of ISC2. This course is independent preparation and is not affiliated with or endorsed by ISC2. Exam facts verified against isc2.org; re-verify the exam fee, CC outline and One Million CC programme status on isc2.org before booking.