Most ISC2 CC domain lists you will find today are out of date. The outline changed on 1 September 2026, three of the five domain names changed with it, and every weighting moved. If you are planning study time against a list that includes "Business Continuity, Disaster Recovery and Incident Response Concepts" as a 10% domain, you are planning against an exam that no longer exists.
Here are the current ISC2 CC domains, taken from the official exam outline, and what actually moved.
The Five ISC2 CC Domains and Their Weightings
These are the domains and percentages published by ISC2 in the Certified in Cybersecurity exam outline effective 1 September 2026.
| # | Domain | Weighting |
|---|---|---|
| 1 | Security Principles | 24% |
| 2 | Security Governance | 17.3% |
| 3 | Identity and Access Management (IAM) Concepts | 20% |
| 4 | Networking and Cloud Security Concepts | 21.3% |
| 5 | Security Operations and Incident Response | 17.3% |
The figures total 99.9% because ISC2 rounds each domain to one decimal place. That is worth stating plainly, because several sites currently publish CC weightings that add up to 105.3%. If a domain table you find does not total roughly 100, it is wrong.
Exam Tip: The CC exam is adaptive, so the percentages are content targets rather than fixed question counts. A 24% domain does not guarantee you exactly 24 questions. Use the weightings to apportion revision hours, not to predict your question paper.
What Changed on 1 September 2026
This was the first major content update to CC since the credential launched in August 2022. Four years of drift got corrected in one go, which is why the change is larger than the usual outline refresh.
Business continuity stopped being its own domain
The old outline gave Business Continuity, Disaster Recovery and Incident Response Concepts a domain of its own at 10%. That domain is gone. Business continuity and disaster recovery now sit inside Security Governance as a sub-topic ISC2 labels "Redundancy", and incident response moved to the other end of the outline into Domain 5.
If you studied BCDR as a discrete block, restructure it. It is now a smaller part of a governance conversation.
Governance, risk and compliance got promoted
Security Governance is a new named domain at 17.3%, built around GRC planning, the redundancy content described above, security awareness, and measuring cybersecurity effectiveness. Governance concepts still appear in Domain 1 as well, so expect the topic to come at you from two directions.
Access controls became identity and access management
Domain 3 was Access Controls Concepts at 22%. It is now Identity and Access Management (IAM) Concepts at 20%, and the sub-topics tell you why: identity lifecycle management has been added alongside logical access controls. Joiners, movers and leavers, provisioning and deprovisioning are now explicitly in scope.
Networking absorbed cloud security
Domain 4 was Network Security at 24%. It is now Networking and Cloud Security Concepts at 21.3%, covering network security, network security architecture and cloud security. Zero trust is part of the added material. The headline weighting dropped by 2.7 points while the content underneath it grew, which makes this the domain most likely to catch out anyone revising from an older guide.
Security operations widened considerably
Domain 5 is now Security Operations and Incident Response at 17.3%, and it picked up data security, asset protection, security testing and the incident response content that used to live in the old Domain 2.
AI runs through all five domains
ISC2 threaded foundational artificial intelligence topics throughout the outline rather than bolting on a sixth domain. There is no AI domain to revise. Expect AI framing inside questions about risk, data protection and security operations.
Old Outline Against New
| Old domain (pre 1 Sept 2026) | Old weight | New domain | New weight |
|---|---|---|---|
| Security Principles | 26% | Security Principles | 24% |
| Business Continuity, DR and Incident Response | 10% | Security Governance | 17.3% |
| Access Controls Concepts | 22% | Identity and Access Management (IAM) Concepts | 20% |
| Network Security | 24% | Networking and Cloud Security Concepts | 21.3% |
| Security Operations | 18% | Security Operations and Incident Response | 17.3% |
The rows line up by position, not by content. Security Governance is not a renamed BCDR domain, it is a new domain that happens to have inherited the BCDR material.
How to Split Your Study Time
The weightings are flatter than they used to be. The old outline had a 16 point spread between its largest and smallest domains. The new one has under 7. That changes how you should revise.
Under the old outline it was rational to skim the 10% domain. Now there is no domain cheap enough to skip. A reasonable allocation across a four week plan:
- Security Principles, 24%. Roughly a quarter of your time. CIA triad, AAA, non-repudiation, privacy, risk management, governance concepts, control types, and the ISC2 Code of Ethics.
- Networking and Cloud Security Concepts, 21.3%. The second heaviest domain and the one that changed most. Do not revise this from pre-September material.
- Identity and Access Management, 20%. Logical access controls plus the new identity lifecycle content.
- Security Governance, 17.3%. GRC planning, redundancy and BCDR, security awareness, effectiveness measurement.
- Security Operations and Incident Response, 17.3%. Data security, security operations, incident response, asset protection, security testing.
Our four week ISC2 CC study plan sets out a day by day version of this, and the ISC2 CC practice questions are written against the post-September domains.
CC Exam Format and Cost
ISC2 publishes the following exam details alongside the outline.
| Detail | Value |
|---|---|
| Exam length | 2 hours |
| Number of items | 100 to 125 |
| Testing format | Computerized Adaptive Testing (CAT) |
| Item types | Multiple choice and advanced item types |
| Passing grade | 700 out of 1000 points |
| Languages | English, Chinese, Japanese, German, Spanish |
| Exam fee | US $199 |
| Annual Maintenance Fee | US $50 |
| Experience required | None |
Two points here are commonly reported wrongly. CC is adaptive, not a fixed 100 question linear paper, and the item count is a range because of that. The credential is also ANAB accredited to ISO/IEC 17024 and approved by the US Department of Defense, which matters if you need it to count toward a work role.
Exam Tip: A scaled 700 out of 1000 is not 70% of the questions. Scaled scoring accounts for item difficulty, so treat 700 as a standard you have to clear rather than a percentage you can calculate from a practice test.
Should You Restudy If You Already Started
If you began studying before September and have not yet sat the exam, you do not need to start again. Security Principles, access control theory and network security fundamentals all survived the rewrite.
What you do need to add is the cloud security and zero trust material in Domain 4, identity lifecycle management in Domain 3, and the GRC and effectiveness measurement content in Domain 2. If you studied from pre-September material, our guide to what changed in the ISC2 CC exam on 1 September 2026 sets out exactly what to add.
If you are still deciding between CC and a competing entry level credential, the ISC2 CC against CompTIA Security+ comparison covers that choice.
Frequently Asked Questions
What are the 5 domains of ISC2 CC?
Security Principles (24%), Security Governance (17.3%), Identity and Access Management (IAM) Concepts (20%), Networking and Cloud Security Concepts (21.3%), and Security Operations and Incident Response (17.3%). These took effect on 1 September 2026.
Did the ISC2 CC domains change?
Yes. Three of the five domains were renamed, the standalone business continuity and disaster recovery domain was removed, and every weighting changed. It was the first major content update since CC launched in August 2022.
Is ISC2 CC hard to pass?
CC is an entry level certification and requires no prior work experience, so the difficulty sits in the breadth rather than the depth. Five domains now fall within 7 percentage points of each other, which means there is no small domain you can safely ignore. Candidates who fail usually do so by skipping a domain rather than by misunderstanding a hard one.
Is ISC2 CC no longer free?
The One Million Certified in Cybersecurity programme, which provided free self paced training and a free exam, closed to new enrolments on 20 May 2026. If you already hold an unexpired exam code from that programme, ISC2 requires you to schedule and sit the exam by 31 December 2026. Otherwise the exam costs US $199 plus a US $50 Annual Maintenance Fee once you pass.
How many questions is the ISC2 CC exam?
Between 100 and 125 items in 2 hours. The range exists because CC uses Computerized Adaptive Testing, so the exam adjusts to your performance as you work through it.
Ready to Start Practising?
Reading the outline tells you what is on the exam. Answering questions tells you whether you know it. The CertCrush ISC2 CC course is built against the post 1 September domains, with practice questions and mock exams weighted to match the official percentages so your practice scores mean something.
When CC is done, read our guide to what to take after ISC2 CC to choose between Security+, SSCP and the specialist routes.
Create a free account and start with a domain you have not touched since the outline changed.
