ISACA has quietly launched a new entry-level credential, and most people studying for their first cybersecurity certification have not heard of it yet. The ISACA Certified Cybersecurity Specialist, or CCS, is a vendor-neutral certification aimed squarely at early-career professionals and IT staff moving sideways into security. It is currently running as a beta programme, and applications close on 26 August 2026.
The short answer on whether it is worth it: if you are already inside the ISACA ecosystem, or you want a recognised certification at roughly half the price of a standard ISACA exam, the beta is a genuinely good deal at US$199. If you are a complete beginner with no security experience and no employer paying, ISC2 CC or CompTIA Security+ remain the safer first move purely because employers already recognise them. CCS has to earn that recognition, and that will take a year or two.
This post covers what ISACA has actually confirmed about the CCS certification, what it has not yet published, how the pricing compares to the alternatives, and who should realistically sit it.
Important: CCS is a new certification in beta. ISACA has published the domains and the beta pricing, but has not yet released the question count, exam duration, pass mark, domain weightings, or renewal requirements. This post separates confirmed facts from what is still unannounced. Do not trust any site claiming to know the CCS pass score right now.
What Is the ISACA Certified Cybersecurity Specialist (CCS)?
The Certified Cybersecurity Specialist (CCS) is ISACA's new vendor-neutral cybersecurity certification. ISACA describes the target audience as early-career professionals and IT staff transitioning into the growing cybersecurity space.
According to ISACA, the certification validates your ability to apply foundational cybersecurity concepts, incorporate secure-by-design principles, and make decisions grounded in risk management.
That last phrase matters more than it looks. ISACA is a governance and risk organisation at heart, and it has built CCS around risk-informed decision making rather than pure technical execution. This is the thread running through the whole ISACA portfolio, from CISA to CISM to CRISC. CCS is the entry point to that way of thinking.
Where CCS Sits in the ISACA Portfolio
ISACA now has an unusually crowded certification range, and it helps to see where the new one lands.
| Certification | Level | Focus |
|---|---|---|
| CCS | Entry | Foundational cyber concepts, secure by design, risk-informed decisions |
| CCOA | Early career | Hands-on cybersecurity operations and analysis |
| CISA | Mid to senior | IS audit, assurance and control |
| CISM | Senior | Information security management and governance |
| CRISC | Senior | IT risk identification and response |
| AAISM | Senior | AI security management |
CCS is the bottom rung. It is designed for people who do not yet have the years of experience that CISA and CISM demand, which is exactly the gap ISACA has struggled with historically. CCOA filled part of that gap on the technical operations side. CCS goes a step earlier and broader.
The Three CCS Exam Domains
ISACA has confirmed three domains for the Certified Cybersecurity Specialist exam. It has not yet published the percentage weighting for each one.
Domain 1: Cybersecurity Principles and Techniques
This is the foundational layer. Expect the core vocabulary and mechanics that every security role assumes you already know: the CIA triad, threat actors and their motivations, common attack types, cryptography basics, authentication and authorisation, network security fundamentals, and the standard control categories.
If you have studied for Security+ or ISC2 CC, a large chunk of this domain will be familiar territory. The ISACA framing will lean harder on why a control exists and what risk it addresses than on how to configure it.
Domain 2: Security Operations
This domain covers the day-to-day work of defending an environment. Realistically that means monitoring and logging, detecting and triaging alerts, incident response phases, vulnerability management, and the operational side of maintaining security controls.
This is the domain that overlaps most with CCOA, though CCS is pitched at a more foundational level. If you want the deeper hands-on operations content, CCOA is the stronger choice.
Domain 3: Secure By Design
This is the domain that makes CCS distinctive, and it is the one you are least likely to have covered elsewhere at entry level. Secure by design means building security into systems from the start rather than retrofitting it after deployment.
Expect content on threat modelling, security requirements gathering, secure architecture principles such as least privilege and defence in depth, secure development practices, and the governance around design decisions.
Exam Tip: Do not skim Domain 3 because it sounds abstract. Secure by design is the domain where ISACA's risk-and-governance DNA shows most clearly, and it is the one that differentiates CCS from CompTIA and ISC2 entry-level exams. It is very likely to be tested with scenario questions asking which design decision best reduces risk, not which tool you would install.
CCS Exam Cost and the Beta Programme
Here is where CCS is genuinely attractive right now.
During the beta programme, the CCS certification exam costs US$199, and that price includes the eBook version of the CCS review manual. You can add the CCS Questions, Answers and Explanations (QAE) database for a further US$149.
ISACA has confirmed that candidates who pass the beta exam are fully recognised as CCS certification holders. This is not a trial run that gets you a participation badge. You sit the exam at the beta price and you come out with the real certification.
Beta applications are open through 26 August 2026, and ISACA states that spots are limited.
How the Beta Price Compares
To put US$199 in context, a standard ISACA exam such as CISA or CISM costs US$575 for members and US$760 for non-members in 2026, plus a one-off US$50 application processing fee once you pass.
| Certification | Exam cost | Notes |
|---|---|---|
| ISACA CCS (beta) | US$199 | Includes eBook review manual; beta applications close 26 August 2026 |
| ISC2 CC | US$199 | Free pathway closed to new enrolments from 20 May 2026; US$50 annual maintenance fee |
| CompTIA Security+ SY0-701 | Around US$404 | Voucher price varies by region |
| ISACA CCOA | Varies by membership | Annual maintenance fee US$45 members, US$85 non-members |
| ISACA CISA / CISM | US$575 members, US$760 non-members | Plus US$50 application fee on passing |
The comparison worth noticing is CCS against ISC2 CC. Both now sit at US$199. For years, ISC2 CC was the obvious answer for a beginner because the One Million Certified in Cybersecurity programme made it free. ISC2 stopped accepting new enrolments to that programme on 20 May 2026, which levelled the field considerably. If you were counting on the free CC route and missed it, CCS at US$199 is now a directly comparable option.
What ISACA Has Not Published Yet
Being straight with you matters more than filling gaps with guesses. As of August 2026, ISACA has not published the following for CCS:
- The number of exam questions
- The exam duration
- The pass score or scoring scale
- The percentage weighting of each of the three domains
- Any experience or prerequisite requirements
- The general availability date once the beta closes
- Continuing education and renewal terms
On that last point, it is reasonable to expect CCS to follow the pattern of other ISACA credentials. CCOA holders, for example, must earn a minimum of 120 CPE hours over a three-year reporting period and pay an annual maintenance fee of US$45 for members or US$85 for non-members, due by 1 January each year. Treat that as a likely shape for CCS renewal rather than a confirmed fact.
Study Materials Status
ISACA has listed three official CCS prep resources as coming soon:
- CCS Online Review Course
- CCS Questions, Answers and Explanations database with 300 or more questions
- CCS Review Manual in digital and print versions
Beta candidates receive the eBook review manual with the exam purchase. If you sit the beta, you are studying with less material than a mature certification offers. That is the trade you make for the lower price and the first-mover advantage.
Is the ISACA CCS Worth It in 2026?
The honest answer depends entirely on which of these three people you are.
Take CCS If
- You are already an ISACA member. You know the exam style, you have the membership, and CCS at beta price is a cheap addition to your record that positions you for CCOA, CISA or CISM later.
- You work somewhere that recognises ISACA. Audit firms, banks, insurers, consultancies and heavily regulated industries take ISACA credentials seriously. In those environments, the ISACA name carries weight that CompTIA does not.
- You want the secure-by-design content. No other entry-level certification gives design and threat modelling its own domain. If you are heading towards architecture or GRC rather than a SOC, that is directly relevant.
- You like being early. The first cohort of any certification is small. Being one of a few hundred CCS holders is a genuine differentiator on a CV for the next year or two.
Take Something Else If
- You need a job in the next six months. Recruiters filter on keywords they recognise. Security+ and ISC2 CC appear in job adverts today. CCS does not yet. This is the single strongest argument against it.
- You want hands-on technical work. CCS is foundational and design-led. If you want to work in a SOC, CCOA or CySA+ get you closer to the actual job.
- You need a DoD 8140 or similar compliance-approved certification. New certifications take time to appear on approved lists. Check your specific requirement before spending anything.
- You learn best with lots of practice questions and community support. The official CCS materials are still coming, and there is no Reddit thread full of people who have sat it. Beginners who need scaffolding will struggle.
The Verdict
CCS is a well-designed certification launched at a genuinely good price, and the secure-by-design domain fills a real gap in entry-level training. The problem is not the certification, it is the calendar. Market recognition lags launch by 12 to 24 months, and a certification's value to an employer is mostly a function of whether they have heard of it.
If the certification is a career accelerator on top of an existing IT job, take the beta. US$199 for a recognised ISACA credential is good value and the risk is small. If the certification is the thing that has to get you hired, take Security+ or ISC2 CC first and add CCS later once it has bedded in. That sequencing point is worth sitting with, and we have written about it in more depth in The Certification Trap.
How to Prepare for the CCS Exam
With official materials still in production, here is a realistic approach.
- Start from the domain names. Three domains, three study blocks. Build your own outline from the confirmed domain titles and fill it with content from sources you trust.
- Reuse your entry-level foundations. Domains 1 and 2 overlap heavily with Security+ and ISC2 CC material. If you have studied either, you are already most of the way through two thirds of the exam.
- Give Domain 3 disproportionate time. Secure by design is the least covered by existing entry-level material, and it is where ISACA's distinctive angle lives. Read up on threat modelling, least privilege, defence in depth and secure development lifecycle basics.
- Think in risk, not in tools. ISACA questions typically present a scenario and ask for the best or first action. The correct answer is usually the one that addresses the underlying risk or follows correct process, not the one that names the most sophisticated technology.
- Practise with scenario questions. Multiple-choice recall will not prepare you for ISACA's style. Work through applied questions until the reasoning pattern becomes automatic.
Our ISACA course range on CertCrush includes CISA, CISM and AAISM practice banks built in the same scenario-led style ISACA uses, which is useful conditioning even before CCS-specific material lands.
Frequently Asked Questions
Are ISACA certifications worth it?
Yes, in the right context. ISACA credentials are highly respected in audit, risk, governance and regulated industries, where CISA and CISM in particular are often listed as requirements rather than preferences. They carry less weight in purely technical, hands-on roles, where CompTIA, Offensive Security and GIAC certifications are more commonly requested. Match the certification body to the type of role you want.
How much does it cost to get an ISACA certification?
Standard ISACA exams such as CISA and CISM cost US$575 for members and US$760 for non-members in 2026, plus a one-off US$50 application processing fee once you pass. The new CCS is far cheaper during its beta at US$199, which includes the eBook review manual. You should also budget for annual maintenance fees, which run to US$45 for members and US$85 for non-members on CCOA, and for the CPE hours needed to keep the credential active.
What are the top 3 cybersecurity certifications?
It depends on career stage. For beginners, CompTIA Security+ and ISC2 CC are the most widely recognised entry points, with ISACA CCS now joining as a third option. For mid-career practitioners, CySA+, CCOA and OSCP are common next steps depending on whether you are defending or attacking. For senior and leadership roles, CISSP, CISM and CISA are the three that appear most often in job specifications.
Does CCS have any experience requirements?
ISACA has not published prerequisite or experience requirements for CCS. Given the certification is explicitly aimed at early-career professionals and IT staff transitioning into cybersecurity, it is unlikely to carry the multi-year experience demands that CISA and CISM impose. Confirm directly with ISACA before applying if this affects your decision.
What jobs can you get with the ISACA CCS?
CCS is pitched at foundational cybersecurity roles: junior security analyst, IT support staff moving into security, GRC analyst, and security-adjacent positions in IT operations. Because the certification is new, it will not yet appear by name in job adverts. Treat it as evidence of foundational knowledge that supports an application rather than a keyword that gets you past an automated filter.
Should I sit the CCS beta or wait for general availability?
Sit the beta if the lower price matters to you and you are comfortable studying with limited official material, because beta passers are fully recognised as CCS holders. Wait for general availability if you want the complete review manual, the online review course and the 300-plus question QAE database, all of which ISACA lists as coming soon. Applications for the beta close on 26 August 2026.
Ready to Start Practising?
CCS is new, and the official question bank is still on its way. What is not new is the reasoning style ISACA tests, and that is something you can start drilling today.
CertCrush builds exam-realistic practice questions with full explanations for the certifications that matter, including the ISACA range, CompTIA Security+, ISC2 CC and CySA+. Every question tells you not just which answer is correct but why the others are wrong, which is exactly the muscle scenario-based exams like CCS demand.
If you are still weighing up your first certification, our comparisons of ISC2 CC versus CompTIA Security+ and the best IT certifications for 2026 will help you choose before you spend anything.
Create a free CertCrush account and start practising today.
