Fast Track Bootcamps
 Crafted For Career-Ready Skills

ISC2 CC Updated Version: What’s New in the Latest Exam?

Quick Insights:

The updated ISC2 CC exam took effect on September 1, 2026, and still covers five domains, with Security Principles carrying the highest weight at 24%. The refreshed outline places greater emphasis on GRC, IAM, cloud security, Zero Trust, incident response, security testing, and modern security operations. Foundational AI security concepts are now integrated across all five domains. The exam continues to use Computerized Adaptive Testing (CAT), with 100–125 items to be completed in two hours, and no prior cybersecurity work experience is required.

Cybersecurity fundamentals have not disappeared, but what counts as a “fundamental” has changed.

A few years ago, an entry-level cybersecurity professional could build a strong foundation around networking, access controls, security principles, business continuity, and basic security operations. Today, the same profession is entering environments shaped by cloud infrastructure, identity-first security, Zero Trust, AI-enabled threats, automated security operations, and increasingly formal governance requirements.

ISC2 CC Updated Version What’s New in the Latest Exam

That shift is now reflected in the ISC2 Certified in Cybersecurity (CC) certification. Effective September 1, 2026, ISC2 introduced the first major exam outline/content update to the CC certification since its launch. The certification still has five domains, but the subjects inside them and their weightings have been significantly reorganized and modernized.

So, what exactly changed in the updated ISC2 CC exam?

What Changed in the ISC2 CC Exam in 2026?

The updated ISC2 CC exam still contains five domains, but their scope has changed considerably. The refreshed exam places stronger emphasis on:

  • Security governance and GRC
  • Identity lifecycle management
  • Cloud security
  • Zero Trust
  • Security event triage
  • Cyber threat intelligence
  • Incident response
  • Security testing
  • Asset lifecycle management
  • AI-related cybersecurity risks and controls

Old ISC2 CC vs. Updated ISC2 CC: Exam Domains and Weightage

Previous CC Exam Structure Weight Updated CC Exam Structure Weight
Security Principles 26% Security Principles 24%
Business Continuity, Disaster Recovery & Incident Response Concepts 10% Security Governance 17.3%
Access Controls Concepts 22% Identity and Access Management (IAM) Concepts 20%
Network Security 24% Networking and Cloud Security Concepts 21.3%
Security Operations 18% Security Operations and Incident Response 17.3%

The percentage changes matter, but the change in scope matters even more.

Several domains have effectively grown from individual security topics into broader professional capabilities.

Domain 1. Security Principles Gets a Modern Refresh

Security Principles remains the largest domain in the updated CC exam. Candidates still need a strong understanding of foundational ideas such as confidentiality, integrity, availability, privacy, and non-repudiation.

But the updated domain goes further. One notable change is the explicit inclusion of Authentication, Authorization and Accounting (AAA). Risk management also moves toward a broader understanding of the risk management lifecycle and processes. Governance receives more attention too, with frameworks and guidelines now sitting alongside laws, regulations, policies, standards, and procedures. Professional conduct has also been expanded to include due care and due diligence, alongside the ISC2 Code of Ethics.

Domain 2. Business Continuity Becomes Security Governance

This is one of the biggest structural changes in the entire CC update. The previous Business Continuity, Disaster Recovery & Incident Response Concepts domain has been replaced by: Security Governance.

Instead of treating governance as a supporting topic, ISC2 now gives it a dedicated domain. Candidates need foundational knowledge of Governance, Risk and Compliance (GRC), including its purpose, importance, frameworks and tools. Business Continuity (BC) and Disaster Recovery (DR) remain in the syllabus, but they now appear within the broader topic of redundancy. There is also increased emphasis on:

  • Security awareness
  • Organizational security culture
  • Security leadership
  • Social engineering
  • Phishing
  • Cybersecurity metrics
  • Key Risk Indicators (KRIs)
  • Dashboards
  • Scorecards
  • Reports

Domain 3. Access Controls Expands into Identity and Access Management

The previous exam had an Access Controls Concepts domain. The updated exam replaces that with Identity and Access Management (IAM) Concepts. That is more than a terminology change.

Modern security does not stop at deciding whether someone should have access. Organizations must manage identities throughout their entire lifecycle. The updated CC exam now covers role definition, provisioning, access reviews, deprovisioning, IAM frameworks, and IAM tools. Traditional access-control principles remain important, including the Principle of Least Privilege (PoLP), Separation of Duties (SoD), and access-control models.

The key takeaway

Identity has become one of the most important security boundaries in modern organizations. The refreshed CC outline reflects that reality by moving candidates from isolated permission concepts toward managing access throughout an identity’s lifecycle.

Domain 4. Network Security Expands into Cloud Security

One of the most relevant updates for today’s infrastructure is the transformation of Network Security into Networking and Cloud Security Concepts.

Core networking knowledge remains. Candidates still need to understand concepts around the OSI model, TCP/IP, IPv4, IPv6, VPNs, firewalls and ports.                                                                                  But networking is now viewed through a much more modern lens. Wireless technologies such as Wi-Fi and Bluetooth receive attention, along with embedded environments including Internet of Things (IoT) and Industrial Control Systems (ICS).

Network architecture now explicitly covers VLANs, micro-segmentation, defense in depth, and Zero Trust. And, importantly, cloud security now has dedicated coverage. Candidates are expected to understand cloud characteristics, service models, deployment models, and the shared security model, including the division of security responsibilities between an organization and its cloud provider.

Domain 5. Security Operations Now Includes Incident Response

The fifth domain may be one of the most interesting updates for candidates interested in SOC and blue-team careers. It is now called Security Operations and Incident Response.

Candidates still need data protection knowledge, including classification, encryption, hashing, and secure data handling. But the scope now extends into activities closely associated with real security operations. Candidates now encounter concepts around logging and monitoring, security event triage, prioritization, and correlation. They also need to understand threat actors and their motivations, cyber threat intelligence, and threat frameworks.

Incident response becomes much more prominent, including the Incident Response Plan and IR exercises such as tabletop exercises. Asset security has also expanded through asset lifecycle management, End-of-Life systems, configuration management, and change management.

Security testing receives dedicated coverage too, including red teaming, blue teaming, purple teaming, vulnerability scanning, static analysis, dynamic analysis, and threat modeling. Even social engineering and physical security testing concepts such as phishing, tailgating and impersonation appear in the updated outline. Data-security topics have also been modernized with concepts such as data masking, sanitization and quantum-resistant cryptography.

For an entry-level certification, this is a meaningful shift toward understanding what cybersecurity teams actually do when something suspicious happens.

AI Security Is Now Integrated Across All Five ISC2 CC Domains

One of the most timely changes is the introduction of AI-related cybersecurity concepts throughout all five CC domains. ISC2 has not created a separate “AI Security” domain. Instead, AI is integrated into existing security areas.

According to ISC2’s updated Exam Guidance for Artificial Intelligence, foundational AI security concepts are integrated across all five CC domains, covering areas such as:

  • AI data protection and integrity
  • AI governance and risk
  • Model poisoning
  • AI-related identities and service accounts
  • Behavioral authentication and anomalous login detection
  • AI-powered network monitoring and threat detection
  • AI-enhanced phishing and automated threats
  • AI-assisted security operations
  • Model drift
  • Data leakage through public AI services

This approach reflects how AI security increasingly intersects with everyday cybersecurity responsibilities rather than existing as an isolated specialty. AI-enabled environments still depend on identities, data, networks, cloud infrastructure, access permissions, monitoring, risk management, and governance.

For beginners, the expectation is not to master machine learning or become an AI security specialist. Instead, candidates should understand where AI introduces security risks, how AI can support cybersecurity operations, and how established security principles apply to AI-enabled environments.

Has the ISC2 CC Exam Format Changed?

The refreshed syllabus should not be confused with a completely new testing format. The CC exam currently uses Computerized Adaptive Testing (CAT).

Exam Duration 120 Minutes
Number of Questions 100–125
Question Format Multiple Choice and Advanced Item Types
Passing Score 700 out of 1,000
Exam Language English, Chinese, Japanese, German, Spanish
Testing Center Pearson VUE Testing Center

What Does the Updated ISC2 CC Mean for Candidates?

If you are preparing for the ISC2 CC exam after September 1, 2026, studying only from material aligned with the older outline could leave important gaps.

Your preparation should now give greater attention to:

  • GRC, security metrics and KRIs
  • Identity lifecycle management and IAM
  • Cloud security and shared responsibility
  • Zero Trust and micro-segmentation
  • Threat actors and cyber threat intelligence
  • Security event triage and incident response
  • Red, blue, and purple teaming concepts
  • Application security testing and threat modeling
  • Modern data protection concepts
  • Foundational AI security across cybersecurity domains

At the same time, don’t abandon the fundamentals.

The refreshed CC is still an entry-level cybersecurity certification with no work experience requirement. ISC2 continues to position it as a pathway for newcomers, career changers, students, and professionals looking to establish cybersecurity fundamentals.

The difference is that those fundamentals are now much better aligned with the cybersecurity environments candidates are likely to encounter in 2026 and beyond.

Key Takeaways

  • The updated CC exam reflects a broader definition of entry-level cybersecurity knowledge
  • Candidates should give greater attention to governance, identity, cloud, and security operations
  • AI security should now be studied as part of core cybersecurity rather than as a separate topic
  • Older study resources can still support foundational concepts but may leave gaps in newer areas
  • Preparation should be aligned with the current ISC2 CC exam outline rather than the previous domain structure

Conclusion

The 2026 ISC2 CC update shows how the definition of entry-level cybersecurity is evolving. Candidates are no longer expected to understand security concepts only in isolation; they also need to see how identity, cloud, governance, security operations, incident response, and emerging technologies such as AI connect in modern environments.

For aspiring cybersecurity professionals, this means building a foundation that is both fundamental and current. The updated CC exam reflects the knowledge beginners are increasingly expected to bring into today’s security roles, making it a stronger starting point for understanding how modern cybersecurity actually works.

Ready to Prepare for the Updated ISC2 CC Exam?

Preparing for the updated ISC2 CC requires more than memorizing cybersecurity definitions. You need to understand how security principles, governance, IAM, cloud security, and security operations connect in real-world environments.

With InfosecTrain’s ISC2 CC Certification Training, you can build structured knowledge across the updated CC domains, strengthen your cybersecurity fundamentals, and prepare confidently for the current ISC2 Certified in Cybersecurity exam.

Build the foundation. Understand modern cybersecurity. Prepare for ISC2 CC with InfosecTrain.

Certified in Cybersecurity CC Certification Training Blog Footer

Frequently Asked Questions

When did the updated ISC2 CC exam become effective?

The updated ISC2 Certified in Cybersecurity exam outline became effective on September 1, 2026.

Is this a completely new ISC2 CC certification?

No. The Certified in Cybersecurity certification remains the same credential, but its exam content and domain structure have been substantially updated.

How many domains are in the updated ISC2 CC exam?

There are still five domains: Security Principles, Security Governance, Identity and Access Management Concepts, Networking and Cloud Security Concepts, and Security Operations and Incident Response.

Is Zero Trust covered in the updated CC exam?

Yes. Zero Trust is included within the Networking and Cloud Security Concepts domain along with segmentation, micro-segmentation, and Defense in Depth.

Does the updated ISC2 CC exam include cloud security?

Yes. Cloud security now receives dedicated coverage within the Networking and Cloud Security Concepts domain, including cloud service models, deployment models, characteristics and the shared security model.

Does the updated ISC2 CC exam cover AI security?

Yes. Foundational AI security concepts are integrated throughout all five domains rather than being isolated in a separate AI domain.

Is IAM now part of the ISC2 CC exam?

Yes. The previous Access Controls Concepts domain has been expanded into Identity and Access Management (IAM) Concepts, including identity lifecycle management, provisioning, reviews and deprovisioning.

Do I need new study material for the September 2026 ISC2 CC exam?

If you are taking the ISC2 CC exam on or after September 1, 2026, your study material should be aligned with the updated exam outline. Older resources may still be useful for core cybersecurity fundamentals, but they may not fully cover newer topics such as GRC, identity lifecycle management, cloud security, Zero Trust, security event triage, incident response, security testing, and AI security.

Can I still use old ISC2 CC study material?

Older material may still be useful for unchanged foundational concepts, but candidates taking the current exam should compare their resources against the September 2026 exam outline to identify missing or outdated topics.

Do I need cybersecurity work experience to earn ISC2 CC?

No. ISC2 CC remains an entry-level certification with no work experience requirement, making it suitable for students, graduates, career changers, and professionals beginning their cybersecurity journey.

Operationalizing-DPDPA-Enforcement-Readiness-Auditable-Compliance
TOP