Back to blog
Certification Deep Dives6 min read

ISC2 CC Exam Changes 2026: What Changed on 1 September and What to Do If You Studied the Old Outline

The ISC2 CC exam changed on 1 September 2026: three domains renamed, every weighting moved, AI threaded through all five domains and an adaptive 100 to 125 item format. Here is what changed and what to add if you studied the old outline.

Tom Ashford

Tom Ashford · Security Certifications Lead

8 July 2026

Updated 26 September 2026: The new ISC2 CC exam outline went live on 1 September 2026, so this page no longer weighs up sitting before the deadline. It now covers what changed and what to do if you studied the old material.

The ISC2 CC exam changed on 1 September 2026. Every candidate now sits the new outline: three of the five domains were renamed, the standalone business continuity domain was folded into a new Security Governance domain, every weighting moved, and foundational AI topics now run through all five domains. There is no longer an old version to book.

If you studied from a pre-September guide, most of what you learned still counts. The gaps are specific and fixable, and they are set out below.

What Changed on 1 September 2026

Here is the old outline against the new one, using the figures in ISC2's official CC exam outline.

Old domain (before 1 Sept 2026)Old weightNew domainNew weight
Security Principles26%Security Principles24%
Business Continuity, DR and Incident Response10%Security Governance17.3%
Access Controls Concepts22%Identity and Access Management (IAM) Concepts20%
Network Security24%Networking and Cloud Security Concepts21.3%
Security Operations18%Security Operations and Incident Response17.3%

The rows line up by position, not by content. Business continuity and disaster recovery now sit inside Security Governance, and incident response moved into Domain 5. Our breakdown of the ISC2 CC domains and weightings goes through each domain's sub-topics in detail.

Three shifts matter more than the renaming:

  • The weightings flattened. The old outline had a 16 point gap between its largest and smallest domains. The new one has under 7. There is no longer a 10% domain you can afford to skim.
  • Cloud security arrived. Domain 4 now covers cloud security and network security architecture, including zero trust. It lost weighting while its content grew.
  • Identity lifecycle is explicit. Domain 3 adds identity lifecycle management to logical access controls, so provisioning, deprovisioning and joiner, mover and leaver processes are in scope.

How AI appears in the new outline

ISC2 did not add an AI domain. It threaded foundational AI concepts through the existing five. The outline refers to how AI-driven tools can help with the early identification and reporting of security incidents, to AI-enhanced social engineering, and to AI's role in authentication, data security and network monitoring.

Exam Tip: CC tests recognition, not engineering. You will not be asked to build or tune a model. You need to spot where AI changes a risk and which basic control addresses it.

The Exam Format You Will Face

These are the details ISC2 publishes for the current outline, with fees from ISC2's pricing pages.

DetailValue
Exam length2 hours
Number of items100 to 125
FormatComputerized Adaptive Testing (CAT)
Passing grade700 out of 1000 points
Exam feeUS $199
Annual Maintenance FeeUS $50 once certified
Renewal45 CPE credits across the three-year cycle
Experience requiredNone

Some older guides, including an earlier version of this page, describe CC as a fixed, linear 100-question paper. The current ISC2 outline states that CC uses CAT and gives a range of 100 to 125 items. Plan your pacing for up to 125.

If You Studied the Old Outline

You do not need to start again. Security principles, the CIA triad, access control models, common network attacks and incident response steps are all still tested. Add these four areas before you book:

  1. Cloud security and zero trust for Domain 4. This is the biggest content gap in pre-September material, and Domain 4 is the second heaviest at 21.3%.
  2. Identity lifecycle management for Domain 3: how accounts, including non-human and automated accounts, are created, changed and removed.
  3. Governance, risk and compliance planning, security awareness and measuring security effectiveness for Domain 2. Revise business continuity and disaster recovery here too, as governance topics rather than a standalone domain.
  4. AI framing across all five domains, as described above.

Be careful with old question banks. A bank weighted to the old percentages will over-train network security and under-train governance, and it will not test cloud or identity lifecycle at all. Your practice score will look better than your readiness is. Our 20 ISC2 CC practice questions are written against the post-September domains.

If You Hold a Free Exam Code From One Million CC

ISC2 closed new enrolments in its One Million Certified in Cybersecurity programme on 20 May 2026. If you already have a valid exam code from it, ISC2 says you must schedule and sit the exam by 31 December 2026. That exam is the new outline, so the four gaps above apply to you as well.

This is the one real deadline left in the CC calendar. A code that lapses on 1 January costs you the US $199 fee.

If You Already Passed CC

Nothing changes for you. A pass under the old outline is the same credential as a pass under the new one, on the same three-year cycle, maintained with CPE credits and the annual fee. You do not need to resit. If you are planning your next certification instead, see our guide to what to take after ISC2 CC.

How This Fits the Wider ISC2 Update

The CC refresh is part of a portfolio-wide update at ISC2. The CCSP moved to a new outline on 1 August 2026, and AI security concepts are being added across the other certifications. If you plan to progress from CC, the governance and cloud material you learn now carries forward.

If you have not yet committed to CC, our comparison of ISC2 CC vs CompTIA Security+ covers which entry-level route suits which goal.

Frequently Asked Questions

Can I still sit the old CC exam?

No. The new outline took effect on 1 September 2026 and applies to every CC exam from that date.

Is CC harder since the September 2026 change?

It is broader rather than harder. It remains an entry-level exam with no experience requirement, but the flatter weightings mean there is no small domain to skip, and cloud security is now in scope.

How many questions are on the CC exam now?

Between 100 and 125 items in 2 hours. The range exists because the exam is adaptive.

Do I need AI experience for the new CC exam?

No. The AI content is conceptual. You need to recognise AI-related risks and basic controls, not build or configure AI systems.

Start Practising Against the New Outline

The quickest way to find your gaps is to answer questions written for the exam you will actually sit. The CertCrush ISC2 CC course is built against the 1 September 2026 domains, with practice questions and mock exams weighted to the official percentages. For a day-by-day schedule, follow our four-week ISC2 CC study plan, then create a free CertCrush account and start with the domain you revised least.

ISC2 CCCertified in Cybersecurityexam changes 2026entry-level cybersecurityISC2AI security
Tom Ashford

Written by

Tom Ashford · Security Certifications Lead

Tom spent over a decade in security operations and consulting before turning to full-time exam-prep writing. He covers the big security certifications — CISSP, CISM, CISA, Security+ and the rest of the alphabet — with a soft spot for the questions everyone gets wrong. His rule for every article: if it doesn’t help you score marks, it doesn’t go in.

All articles by Tom

Practise for ISC2 CC Certified in Cybersecurity — free

10 real exam-style questions with full explanations, no account needed. Then unlock the complete bank with an exam-readiness score and a daily plan built around your exam date.