Updated 26 September 2026: The new ISC2 CC exam outline went live on 1 September 2026, so this page no longer weighs up sitting before the deadline. It now covers what changed and what to do if you studied the old material.
The ISC2 CC exam changed on 1 September 2026. Every candidate now sits the new outline: three of the five domains were renamed, the standalone business continuity domain was folded into a new Security Governance domain, every weighting moved, and foundational AI topics now run through all five domains. There is no longer an old version to book.
If you studied from a pre-September guide, most of what you learned still counts. The gaps are specific and fixable, and they are set out below.
What Changed on 1 September 2026
Here is the old outline against the new one, using the figures in ISC2's official CC exam outline.
| Old domain (before 1 Sept 2026) | Old weight | New domain | New weight |
|---|---|---|---|
| Security Principles | 26% | Security Principles | 24% |
| Business Continuity, DR and Incident Response | 10% | Security Governance | 17.3% |
| Access Controls Concepts | 22% | Identity and Access Management (IAM) Concepts | 20% |
| Network Security | 24% | Networking and Cloud Security Concepts | 21.3% |
| Security Operations | 18% | Security Operations and Incident Response | 17.3% |
The rows line up by position, not by content. Business continuity and disaster recovery now sit inside Security Governance, and incident response moved into Domain 5. Our breakdown of the ISC2 CC domains and weightings goes through each domain's sub-topics in detail.
Three shifts matter more than the renaming:
- The weightings flattened. The old outline had a 16 point gap between its largest and smallest domains. The new one has under 7. There is no longer a 10% domain you can afford to skim.
- Cloud security arrived. Domain 4 now covers cloud security and network security architecture, including zero trust. It lost weighting while its content grew.
- Identity lifecycle is explicit. Domain 3 adds identity lifecycle management to logical access controls, so provisioning, deprovisioning and joiner, mover and leaver processes are in scope.
How AI appears in the new outline
ISC2 did not add an AI domain. It threaded foundational AI concepts through the existing five. The outline refers to how AI-driven tools can help with the early identification and reporting of security incidents, to AI-enhanced social engineering, and to AI's role in authentication, data security and network monitoring.
Exam Tip: CC tests recognition, not engineering. You will not be asked to build or tune a model. You need to spot where AI changes a risk and which basic control addresses it.
The Exam Format You Will Face
These are the details ISC2 publishes for the current outline, with fees from ISC2's pricing pages.
| Detail | Value |
|---|---|
| Exam length | 2 hours |
| Number of items | 100 to 125 |
| Format | Computerized Adaptive Testing (CAT) |
| Passing grade | 700 out of 1000 points |
| Exam fee | US $199 |
| Annual Maintenance Fee | US $50 once certified |
| Renewal | 45 CPE credits across the three-year cycle |
| Experience required | None |
Some older guides, including an earlier version of this page, describe CC as a fixed, linear 100-question paper. The current ISC2 outline states that CC uses CAT and gives a range of 100 to 125 items. Plan your pacing for up to 125.
If You Studied the Old Outline
You do not need to start again. Security principles, the CIA triad, access control models, common network attacks and incident response steps are all still tested. Add these four areas before you book:
- Cloud security and zero trust for Domain 4. This is the biggest content gap in pre-September material, and Domain 4 is the second heaviest at 21.3%.
- Identity lifecycle management for Domain 3: how accounts, including non-human and automated accounts, are created, changed and removed.
- Governance, risk and compliance planning, security awareness and measuring security effectiveness for Domain 2. Revise business continuity and disaster recovery here too, as governance topics rather than a standalone domain.
- AI framing across all five domains, as described above.
Be careful with old question banks. A bank weighted to the old percentages will over-train network security and under-train governance, and it will not test cloud or identity lifecycle at all. Your practice score will look better than your readiness is. Our 20 ISC2 CC practice questions are written against the post-September domains.
If You Hold a Free Exam Code From One Million CC
ISC2 closed new enrolments in its One Million Certified in Cybersecurity programme on 20 May 2026. If you already have a valid exam code from it, ISC2 says you must schedule and sit the exam by 31 December 2026. That exam is the new outline, so the four gaps above apply to you as well.
This is the one real deadline left in the CC calendar. A code that lapses on 1 January costs you the US $199 fee.
If You Already Passed CC
Nothing changes for you. A pass under the old outline is the same credential as a pass under the new one, on the same three-year cycle, maintained with CPE credits and the annual fee. You do not need to resit. If you are planning your next certification instead, see our guide to what to take after ISC2 CC.
How This Fits the Wider ISC2 Update
The CC refresh is part of a portfolio-wide update at ISC2. The CCSP moved to a new outline on 1 August 2026, and AI security concepts are being added across the other certifications. If you plan to progress from CC, the governance and cloud material you learn now carries forward.
If you have not yet committed to CC, our comparison of ISC2 CC vs CompTIA Security+ covers which entry-level route suits which goal.
Frequently Asked Questions
Can I still sit the old CC exam?
No. The new outline took effect on 1 September 2026 and applies to every CC exam from that date.
Is CC harder since the September 2026 change?
It is broader rather than harder. It remains an entry-level exam with no experience requirement, but the flatter weightings mean there is no small domain to skip, and cloud security is now in scope.
How many questions are on the CC exam now?
Between 100 and 125 items in 2 hours. The range exists because the exam is adaptive.
Do I need AI experience for the new CC exam?
No. The AI content is conceptual. You need to recognise AI-related risks and basic controls, not build or configure AI systems.
Start Practising Against the New Outline
The quickest way to find your gaps is to answer questions written for the exam you will actually sit. The CertCrush ISC2 CC course is built against the 1 September 2026 domains, with practice questions and mock exams weighted to the official percentages. For a day-by-day schedule, follow our four-week ISC2 CC study plan, then create a free CertCrush account and start with the domain you revised least.
