ISC2 CC
I’ll be honest with you: the ISC2 Certified in Cybersecurity (CC) certification left me with mixed feelings. It’s free to take, which sounds great on paper, but after going through the process I’m not convinced it’s the best use of your time if you’re serious about breaking into cybersecurity. Let me explain.
ISC2 launched the CC in 2022 as an entry-level certification designed to give newcomers a path into the field. The idea was to create something accessible—no experience required, free training, free exam. The problem is that “accessible” and “valuable” aren’t the same thing, and in the job market, the CC doesn’t carry the same weight as other entry-level options.
What Is ISC2 CC?
The Certified in Cybersecurity is ISC2’s entry-level certification. ISC2 is the organization behind CISSP, which is arguably the most recognized security certification in the industry. They created the CC to give people a stepping stone toward CISSP and to expand their reach into the entry-level market.
The certification covers foundational security concepts: security principles, incident response basics, access controls, network security, and security operations. It’s vendor-neutral and doesn’t require any prior experience or education. ISC2 provides a free self-paced training course, and the exam voucher is also free through their “One Million Certified in Cybersecurity” initiative.
Sounds like a no-brainer, right? Here’s where it gets complicated.
The Recognition Problem
When I talk to hiring managers and look at job postings, Security+ shows up everywhere. It’s required for DoD positions, it’s listed on most entry-level security job descriptions, and recruiters know what it means. The CC? Not so much.
The certification is still new, and ISC2’s reputation is built on CISSP, not entry-level credentials. When someone sees “CISSP” on a resume, they know exactly what that means. When they see “CC,” they might not recognize it at all, or they might view it as a participation trophy rather than a meaningful credential.
That’s not entirely fair—the CC does cover real security concepts—but perception matters in the job market. You’re not just learning for yourself; you’re building a resume that needs to get past recruiters and hiring managers who have their own biases and expectations.
What Does the Exam Cover?
The CC exam covers five domains that map loosely to the CISSP domains, just at a much more basic level:
Security Principles (26%) – Confidentiality, integrity, availability, risk management concepts, security governance, and ethics. This is the theoretical foundation.
Business Continuity, Disaster Recovery, and Incident Response (10%) – Understanding how organizations prepare for and respond to disruptions. It’s a small domain but covers important concepts.
Access Controls Concepts (22%) – Physical and logical access controls, authentication, authorization, and identity management. Who can access what, and how do you control it.
Network Security (24%) – Basic networking concepts as they relate to security. Firewalls, network attacks, wireless security, and secure network design.
Security Operations (18%) – Data security, system hardening, security awareness training, and encryption basics.
Who Should Get the CC?
The CC makes sense in a few specific situations. If you’re completely new to cybersecurity and want to test whether you find the material interesting before investing money, the free training and exam give you a risk-free way to explore. If you’re a student building a resume and want to stack multiple certifications, adding the CC doesn’t hurt. If you’re already planning to pursue CISSP eventually and want to join the ISC2 ecosystem early, the CC gets you in the door.
But if you’re choosing between the CC and Security+ for your first certification, Security+ is the stronger choice for most people. It costs more, but it’s more widely recognized, required for more jobs, and carries more weight with employers. The CC might be free, but your time isn’t—and spending two months studying for a cert that doesn’t move the needle is a real cost.
Exam Details
- Exam Code: CC
- Number of Questions: 100
- Question Types: Multiple choice
- Time Limit: 120 minutes
- Passing Score: 700 out of 1000
- Cost: Free (through ISC2 initiative)
- Annual Maintenance Fee: $50
One thing people overlook: the CC has a $50 annual maintenance fee (AMF) to keep the certification active. Security+ doesn’t have annual fees—you renew every three years through continuing education. Over three years, you’ll pay $150 to maintain the CC versus $0 for Security+. That “free” certification adds up.
How to Pass the CC
If you decide the CC is right for you, here’s how to approach it.
Start with the free ISC2 self-paced course. It’s provided through their website and covers all five domains. The material is straightforward, maybe too straightforward if you have any IT background. I finished it faster than I expected.
Supplement with other resources. The official training is surface-level, and some topics need more explanation. YouTube videos, study guides, and practice questions help fill the gaps. The NIST Special Publications are free and give you deeper context on security concepts that the exam touches on.
Take practice exams until you’re consistently passing. The CC doesn’t have as many practice resources as Security+ because it’s newer, but Pocket Prep and a few Udemy courses offer CC-specific questions. Aim for 80% or higher before scheduling your exam.
Don’t overthink it. The CC is genuinely entry-level. If you’ve spent any time in IT or have studied Security+ material, you might find it easier than expected. I know people who passed with less than two weeks of studying.
Test Day Tips
The CC exam is multiple choice only—no performance-based questions like CompTIA exams. That makes it more straightforward, but you still need to manage your time across 100 questions in 120 minutes.
Read carefully. ISC2 exams have a reputation for tricky wording. They want you to pick the “BEST” answer, not just a correct answer. Think like a manager, not a technician—ISC2 tends to favor risk-based and policy-focused responses.
Flag questions you’re unsure about and come back. With 100 questions, you’ll hit some that make you second-guess yourself. Don’t get stuck. Mark it, move on, and revisit at the end.
What Comes After the CC?
ISC2 wants you to see the CC as a stepping stone to CISSP, but that’s a big leap. CISSP requires five years of professional experience and covers material at a much deeper level. Most people won’t go straight from CC to CISSP.
A more realistic path: use the CC to get your first IT or security-adjacent job, gain experience, and then pursue Security+ or CySA+ for more recognition. If you’re staying in the ISC2 ecosystem, SSCP is a mid-level option that requires one year of experience.
The CC on its own probably won’t land you a security job. Pair it with hands-on skills, home lab experience, or other certifications to build a stronger case for employers. It’s a starting point, not a destination—and honestly, there are better starting points available.
Self-taught security pro. No degree, just certs, labs, and a lot of late nights.
Leave a Reply