Is ISC2 CC worth it in 2026? For a true beginner who wants a recognised first credential and a structured syllabus, yes, at a cost of $199 plus $50 a year. For anyone who already holds Security+ or has a few years in IT, probably not. The answer changed this year because the free exam that made CC an easy yes is no longer available to new candidates.
What changed: the free exam is over
ISC2 built the Certified in Cybersecurity (CC) credential's reputation on its One Million Certified in Cybersecurity programme, which gave candidates a free course and a free exam. ISC2 has since closed new enrolments: the programme stopped accepting people on 20 May 2026.
If you already hold an exam code from the programme, you can still use it. The code must be used by 31 December 2026, and ISC2 states that expired codes cannot be reactivated.
Everyone else now pays. That turns CC from a "nothing to lose" certificate into a purchase that needs a reason.
What ISC2 CC costs now
Here are the figures ISC2 publishes.
| Cost | Amount |
|---|---|
| Exam fee | $199 |
| Annual maintenance fee (CC only) | $50 |
| Continuing education | 45 CPE credits per three-year cycle (15 a year recommended) |
| Experience required | None |
Source: ISC2's One Million Certified page and frequently asked questions.
Over a three-year cycle that is $199 plus $150 in fees, so $349, before any study material.
Check ISC2's checkout for the current price of any training bundle rather than trusting a third-party figure.
What the exam looks like
The exam outline effective from 1 September 2026 sets out the format:
- 100 to 125 items, delivered as a computer adaptive test
- 2 hours
- Pass mark of 700 out of 1,000
- In person at a Pearson test centre
- Available in English, Chinese, Japanese, German and Spanish
Domain weightings under the new outline are 24% Security Principles, 21.3% Networking and Cloud Security Concepts, 20% Identity and Access Management, 17.3% Security Governance, and 17.3% Security Operations and Incident Response. Our domains breakdown covers what sits inside each one, and the exam changes post explains what moved if you studied the old outline.
Exam Tip: ISC2 does not publish a pass rate for CC. Any site quoting one is guessing, so ignore it and judge readiness by how you score on fresh practice questions.
Who gets real value from ISC2 CC
Career changers with no IT background
CC assumes nothing. The five domains give you a vocabulary for security conversations, which helps in interviews for help desk, SOC analyst trainee and junior GRC roles. The credential tells a recruiter you chose security deliberately.
Students and graduates with no certifications
A short, recognised credential on a CV helps when you have no work history to show. At $199 it is cheaper than most alternatives.
People who need a safe first exam
CC is a reasonable way to learn how proctored certification exams feel before attempting something harder. It also sits at the bottom of the ISC2 ladder, which leads towards SSCP and CISSP.
Who should skip it
Anyone already working in IT
If you have two or more years in networking, systems or help desk, CC covers ground you mostly know. Your money is better spent on a certification employers filter on.
Anyone targeting a job advert that names Security+
Many job adverts name CompTIA Security+. CC is not a substitute when a listing names it. Our CC vs Security+ comparison goes through the cost and difficulty trade-offs in detail.
Anyone who expects CC alone to land a job
No entry-level credential does that. Employers hire for hands-on ability, and CC proves you know the concepts, not that you can work a ticket queue. We will not quote a salary uplift here because ISC2 publishes none and the figures floating around are survey guesses.
The honest verdict by situation
| Your situation | Worth it? |
|---|---|
| Career changer, no IT experience, no certs | Yes, as a first step |
| Student wanting a CV line | Yes, if budget allows |
| Holds an unexpired free exam code | Yes, use it before 31 December 2026 |
| Working in IT, wants a security job | No, go straight to Security+ |
| Job advert names Security+ | No |
| Aiming for CISSP long term | Optional, CISSP does not require CC |
How to prepare without overspending
The exam is the cost, so do not add to it. ISC2 offers self-paced training, but the syllabus is short enough to prepare with a study plan and practice questions. Our 4-week study plan is written for the 1 September 2026 outline.
When you want to test yourself under exam conditions, the ISC2 CC course on CertCrush has practice questions mapped to the current domains.
Frequently Asked Questions
Is ISC2 CC hard to pass?
It is an entry-level exam, and most people who study the syllabus for a few weeks find it manageable. The adaptive format and 700 out of 1,000 pass mark still mean you cannot guess your way through. ISC2 publishes no pass rate.
Is the ISC2 CC still free?
Not for new candidates. The One Million Certified in Cybersecurity programme closed to new enrolments on 20 May 2026. People who already hold an exam code can use it until 31 December 2026.
Which is better, CompTIA or ISC2?
For a first certification, CompTIA Security+ is more widely named in job adverts and costs more, while CC is cheaper and gentler. If a specific job requires Security+, take that. If you want a low-cost starting point and no listing demands Security+, CC is fine.
Do I need experience to take ISC2 CC?
No. ISC2 states that you do not need experience to take the exam, which is why it suits career changers.
Ready to Start Practising?
If CC fits your situation, practise before you pay for the exam. Create a free CertCrush account and work through exam-style questions on the five domains, so you book the $199 sitting once.
