If you are searching for an ISC2 CC study plan right now, you have picked an awkward month to do it. The Certified in Cybersecurity exam outline is being refreshed on 1 September 2026, which means most of the "how I passed CC" write-ups you will find were written against an outline that is about to be superseded. This plan is built for the exam as it will actually look on the day you sit it.
The short answer is that four weeks is realistic for CC if you can commit around eight to ten hours a week, and the refresh does not add a sixth domain or move the weights. What it does add is artificial intelligence content threaded through all five existing domains, which changes what you revise rather than how much of it there is.
Below is the domain-by-domain breakdown, what the September update actually changes, and a week-by-week schedule you can start today.
What the ISC2 CC Exam Looks Like in 2026
Get the mechanics straight before you plan a single study session, because the format dictates how you practise.
The ISC2 CC exam is 100 items delivered in a two-hour appointment, and you need 700 out of 1000 scaled points to pass. It is administered through Pearson VUE, either at a test centre or under online proctoring. The standard exam fee is US$199 in most ISC2 regions.
There is no work experience requirement. CC is deliberately the entry point to the ISC2 ladder, and it is ANAB accredited to ISO/IEC 17024 and approved by the US Department of Defense, which is why it shows up in so many junior job adverts and DoD work role mappings.
Exam Tip: ISC2 moved CC to adaptive delivery, so plan to answer each item once and move on rather than banking on flagging a long list for review at the end. Check the delivery format printed on your Pearson VUE booking confirmation before exam day.
Once you pass and complete the certification application, you pay a US$50 Annual Maintenance Fee and must earn 45 CPE credits across a three-year cycle. CC holders earn Group A credits only, so unlike CISSP there is no separate Group B professional development requirement to track.
The free voucher deadline you need to know about
ISC2 closed its One Million Certified in Cybersecurity programme to new enrolments on 20 May 2026 after passing its one million milestone. If you enrolled before that date, your free exam entitlement runs until 31 December 2026. If you did not, the US$199 fee applies.
There is one regional carve-out worth checking: ISC2's EU pledge commits to free CC courses and exams for 30,000 people across the European Union by 31 August 2026.
If you are sitting on a voucher that expires at the end of December, a four-week plan starting now is comfortable. Do not let the voucher lapse because you were waiting to feel ready.
What Changes on 1 September 2026
ISC2 refreshes credential outlines on a triennial cycle driven by a Job Task Analysis, which surveys what certification holders actually do in the role. The CC refresh is that process running its course, not a redesign of the certification.
The headline for planners is reassuring. The five domains stay, and the weights stay.
| Domain | Weight | Roughly how many of your 100 items |
|---|---|---|
| 1. Security Principles | 26% | 26 |
| 2. Business Continuity, Disaster Recovery and Incident Response | 10% | 10 |
| 3. Access Controls Concepts | 22% | 22 |
| 4. Network Security | 24% | 24 |
| 5. Security Operations | 18% | 18 |
The substantive change is AI. On 2 April 2026 ISC2 published Exam Guidance for Artificial Intelligence, mapping AI security concepts into more than 50 of its exam domains across the portfolio, including all five CC domains. From 1 September, expect AI to appear as context inside existing concepts rather than as a standalone topic block.
The confirmed additions cluster in the first three domains:
- Security Principles: applying the CIA triad to AI systems, protecting data integrity to prevent model poisoning, ethical AI, transparency, and bias in automated decision making.
- Business Continuity, Disaster Recovery and Incident Response: backing up AI model weights and training datasets as recoverable assets.
- Access Controls Concepts: authenticating and authorising AI agents, which in practice means applying least privilege to non-human identities.
For Network Security and Security Operations, treat AI as one more system you have to segment, monitor and log rather than as new networking theory. That framing will get you through most scenario wording without memorising anything extra.
Exam Tip: Pull the refreshed CC Exam Outline PDF directly from ISC2 once it publishes ahead of 1 September, not a third-party summary. The domain weights in that document are what tell you where to spend your hours.
Should you sit before or after 1 September?
| Sit before 1 September 2026 | Sit on or after 1 September 2026 | |
|---|---|---|
| Outline | Current five-domain outline | Refreshed outline, same five domains and weights |
| AI content | Minimal | Woven through all five domains |
| Study material maturity | Books and courses fully aligned | Third-party material catching up for a few months |
| Best for | Anyone already two or three weeks into revision | Anyone starting now, or with a voucher running to 31 December |
If you are starting from zero today, sitting after the refresh is the better call. You will study the AI material once instead of learning the old outline and then patching it. We covered the sit-now-or-wait decision in more depth in our breakdown of the ISC2 CC exam changes taking effect on 1 September.
The 4-Week ISC2 CC Study Plan
This plan assumes eight to ten hours a week: roughly ninety minutes on five weekdays, plus a two-hour block at the weekend. Scale it to six weeks if you are working full time and new to IT, or compress it to two if you already hold Security+ and are collecting CC as a formality.
The sequencing follows domain weight, not the official domain numbering. You front-load the heaviest material while your motivation is highest, and you leave the final week free for the AI layer and full-length practice.
Week 1: Security Principles and BC/DR/IR (36% of the exam)
Domains 1 and 2 pair naturally. Both are conceptual, both are vocabulary heavy, and together they account for more than a third of your items.
- Day 1: CIA triad, authentication versus authorisation, non-repudiation, privacy. Write your own one-line definition of each term rather than copying one.
- Day 2: Risk management. Threat, vulnerability, likelihood, impact. Risk treatment options: avoid, accept, mitigate, transfer. Know which is which by example, because that is how the exam asks.
- Day 3: Security controls (technical, administrative, physical), governance documents, and the difference between a policy, a standard, a procedure and a guideline. This distinction is tested more often than candidates expect.
- Day 4: The ISC2 Code of Ethics. Four canons, in order. This is free marks and takes twenty minutes.
- Day 5: Business continuity and disaster recovery. RPO and RTO, the difference between a BCP and a DRP, and where each sits in the timeline of an outage.
- Weekend: Incident response lifecycle end to end. Then take a 30-question checkpoint quiz on domains 1 and 2 only.
Aim for 70% or better on that checkpoint. If you land lower, the gap is almost always terminology rather than comprehension, so re-read your own definitions before moving on.
Week 2: Access Controls and the first half of Network Security (34%)
- Day 1: Physical access controls. Badges, mantraps, turnstiles, CCTV, guards, and the concept of defence in depth expressed physically.
- Day 2: Logical access controls and the models. Discretionary, mandatory, role based and rule based. Be able to spot which model a scenario is describing from a single sentence.
- Day 3: Least privilege, separation of duties, need to know, and provisioning versus deprovisioning. Add authenticating and authorising AI agents here, because that is where the refreshed outline puts it.
- Day 4: The OSI and TCP/IP models. Do not skim this. Several Network Security items are layer-identification questions in disguise.
- Day 5: IP addressing, ports and protocols. Learn the common port numbers cold: 22, 23, 25, 53, 80, 143, 389, 443, 445, 3389.
- Weekend: Common network threats. Spoofing, on-path attacks, DoS and DDoS, malware categories. Checkpoint quiz on domain 3.
Week 3: Network Security completion and Security Operations (42% cumulative coverage)
- Day 1: Network infrastructure. Firewalls, IDS and IPS, routers, switches, and what each device actually does with a packet.
- Day 2: Network segmentation. VLANs, DMZ, microsegmentation, zero trust as a concept. Frame AI workloads as another asset class you would segment.
- Day 3: Secure network design and cloud basics. Service models, deployment models, and the shared responsibility principle.
- Day 4: Data handling. Classification, labelling, retention, and destruction. Know the difference between clearing, purging and destroying media.
- Day 5: Logging, monitoring and the role of a SIEM. Also cover encryption fundamentals: symmetric versus asymmetric, hashing, and what each one is actually for.
- Weekend: Security awareness training, configuration management, and patching. Checkpoint quiz on domains 4 and 5.
By the end of week 3 you have covered 100% of the outline once. Everything after this is consolidation.
Week 4: The AI layer, full practice exams and weak-area repair
This is the week that separates a comfortable pass from a nervous one, and it is the week most people cut short.
- Day 1: Work through the AI additions domain by domain using the list earlier in this post. Ninety minutes is enough, because these are existing concepts in a new context, not new theory.
- Day 2: Full-length timed practice exam, 100 items in two hours, no notes, no pausing.
- Day 3: Review every question you got wrong and, critically, every question you guessed correctly. Guessed-right answers are hidden gaps that will not be hidden on exam day.
- Day 4: Targeted revision on your two weakest domains only. Resist the urge to re-read material you already know, because it feels productive and teaches you nothing.
- Day 5: Second full-length timed practice exam.
- Weekend: Final review of your error log, the ISC2 Code of Ethics, port numbers, and RPO versus RTO. Then stop. Sleep beats another hour of cramming.
Exam Tip: Do not sit the real exam until you are consistently scoring 80% or higher on full-length timed practice tests. Practice scores tend to drop five to ten points under real exam conditions, and 700 out of 1000 leaves less margin than it looks like it does.
The Five Mistakes That Fail CC Candidates
CC has a reputation as an easy exam, and that reputation is exactly why people fail it.
- Studying passively. Watching a video course start to finish feels like progress and produces almost no recall. Every session in the plan above ends with you writing or answering something.
- Ignoring domain weights. Network Security is 24% of the exam and Business Continuity is 10%. Candidates routinely spend equal time on both because the domains are numbered as though they matter equally.
- Skipping the Code of Ethics. It is a small number of items, it is entirely memorisable, and people leave the marks on the table.
- Treating scenario questions as definition questions. CC asks you to apply a concept, not recite it. If you can only define least privilege, you will lose the item that describes a contractor with domain admin rights.
- Booking the exam too far out. Without a date in the calendar, a four-week plan becomes a four-month plan. Book it at the start of week 2.
We went deeper into the psychology of this in why most people fail certification exams, and the fixes there apply directly to CC.
Where CC Fits After You Pass
CC proves you understand the vocabulary of security. It does not prove you can do the job, and it is not meant to.
The natural next step for most people is CompTIA Security+, which covers similar ground at greater depth and carries more weight with hiring managers. If you are weighing the two, our comparison of ISC2 CC and CompTIA Security+ breaks down which one earns you more per hour of study. The current Security+ version is SY0-801, and we have a full eight-week SY0-801 study plan ready to follow on from this one.
If you are staying in the ISC2 ecosystem, CC feeds naturally toward SSCP for hands-on operations roles, or toward CISSP once you have accumulated the required experience. Either way, the AI content you learn for the refreshed CC outline reappears at every level above it, because ISC2's April 2026 guidance mapped it across more than 50 domains portfolio-wide. Learning it properly now compounds.
Your Exam Day Checklist
- Book the appointment at the start of week 2, not the end of week 4.
- If you are testing online, read the proctoring rules carefully first. Our guide to OnVUE online proctored exams covers the check-in process and what actually gets people banned.
- Arrive or log in thirty minutes early. Rushing costs you more marks than a missed revision session.
- Answer every item. There is no penalty for a wrong answer, so an educated guess always beats a blank.
- Flag your instinct. On ambiguous items, the first reading of a scenario is right more often than the third.
Ready to Start Practising?
A study plan tells you what to cover. Practice questions tell you whether it stuck, and that gap is where most CC failures live.
CertCrush gives you exam-style questions with full explanations for every answer, so you find your weak domains in week 1 instead of discovering them at the Pearson VUE desk. Every question is mapped to the domain it tests, which means your checkpoint quizzes in this plan produce a real weighting breakdown rather than a bare score.
Create your free CertCrush account and start your first CC checkpoint quiz today, or browse the full course catalogue to see what comes after CC.
Four weeks from now, you could have the certification. Book the date.
