ISC2 CGRC
Governance, risk, and compliance work forms the foundation upon which security programs operate within regulated environments. The Certified in Governance, Risk and Compliance certification from ISC2 validates expertise in implementing and managing GRC frameworks, particularly within federal information systems. For professionals working in authorization, assessment, and continuous monitoring roles, CGRC provides targeted validation of these specialized skills.
My work supporting federal programs has demonstrated how critical proper authorization processes are to mission success. Systems cannot operate without authorization, and authorizations depend on professionals who understand risk assessment, control implementation, and the documentation that connects them. CGRC validates this capability in a way that general security certifications do not address specifically.
What Is ISC2 CGRC?
The Certified in Governance, Risk and Compliance certification, formerly known as CAP (Certified Authorization Professional), validates knowledge of the authorization process for information systems. ISC2 developed CGRC to address the specific skills required for risk management and authorization work, particularly in government contexts.
CGRC focuses on the Risk Management Framework (RMF), the authorization process that federal agencies use to approve information systems for operation. While the certification applies beyond federal systems, its strongest alignment is with government authorization requirements defined by NIST and implemented across civilian and defense agencies.
The certification requires two years of cumulative work experience in one or more of the seven CGRC domains. One year of experience can be substituted with qualifying education or credentials. This prerequisite ensures candidates have practical exposure to GRC concepts.
CGRC is recognized under DoD 8570/8140 for IAM Level II and IASAE positions. For government contractors and federal civilians involved in authorization work, CGRC satisfies workforce requirements that general certifications like CISSP may not address specifically.
What Does the Exam Cover?
The CGRC exam covers seven domains aligned with the authorization lifecycle:
Security and Privacy Governance (16%) – Governance frameworks, organizational structures, and policy development. Understanding how governance enables effective risk management.
Security and Privacy Program Management (15%) – Managing security programs, resource allocation, and program oversight. Translating governance into operational programs.
Authorization and Approval (10%) – The authorization decision process, authorization packages, and approval workflows. The culmination of assessment activities.
Risk Assessment (17%) – Identifying, analyzing, and evaluating risk. Understanding threat sources, vulnerabilities, and potential impacts.
Third-Party and Supply Chain Risk (12%) – Managing risk from external parties, supply chain considerations, and third-party assessments. Increasingly critical in interconnected environments.
Control Assessment (13%) – Evaluating control implementation and effectiveness. Assessment methodologies and evidence evaluation.
Continuous Monitoring (17%) – Ongoing security status monitoring, metrics, and reporting. Maintaining authorization through continuous visibility.
Who Should Get CGRC?
CGRC is appropriate for professionals directly involved in authorization and GRC activities. Security control assessors, authorization officials, ISSO/ISSMs, and GRC analysts working with federal systems will find CGRC directly relevant to their responsibilities.
The certification is particularly valuable for government contractors whose positions require 8570/8140 compliance for authorization-related roles. CGRC satisfies requirements that broader certifications like Security+ cannot meet for these specialized positions.
Security professionals transitioning into GRC work benefit from CGRC’s structured coverage of authorization processes. The certification provides a framework for understanding how compliance activities connect to risk management decisions.
For those working primarily in private sector security without federal compliance requirements, CGRC may provide less direct value. While the concepts translate, the certification’s strongest recognition is in government and defense contexts where RMF and authorization processes apply directly.
Exam Details
- Exam Format: Computerized Adaptive Testing (CAT)
- Number of Questions: 125
- Question Types: Multiple choice
- Time Limit: 3 hours
- Passing Score: 700 out of 1000
- Cost: $599 USD
- Experience Requirement: 2 years in CGRC domains
The adaptive testing format adjusts question difficulty based on responses. Question count is fixed at 125, but the difficulty varies. Once you answer a question, you cannot return to it.
Preparation Approach
Effective CGRC preparation requires deep familiarity with NIST publications that define the authorization process.
NIST SP 800-37 (Risk Management Framework) is essential reading. This publication defines the RMF steps that CGRC tests comprehensively. Understand each step, the activities involved, and how they connect.
NIST SP 800-53 provides the security control catalog. While you don’t need to memorize all controls, understand the control families, baseline concepts, and how controls are selected and tailored.
Review NIST SP 800-53A for assessment procedures. Understanding how controls are evaluated connects to the assessment domain that comprises 13% of the exam.
The ISC2 Official CGRC Study Guide covers all domains and provides exam-focused preparation. Use it as your primary study resource alongside NIST publications.
Practical experience with authorization packages strengthens understanding. If your work involves system security plans, security assessment reports, or POA&Ms, you’re building relevant context daily.
Test Day Considerations
CGRC tests understanding of authorization processes and risk management concepts. Questions present scenarios requiring judgment about appropriate GRC responses.
The adaptive format requires confidence in each answer since returning to previous questions is not possible. Read carefully, apply your understanding of the RMF, and commit to your answer.
Think in terms of federal authorization processes. While concepts apply broadly, CGRC’s context is primarily government systems. Understanding how federal agencies approach authorization informs correct answers.
Time management across three hours with 125 questions allows for careful consideration. Pace yourself but don’t overthink—apply your knowledge and continue.
What Comes After CGRC?
CGRC positions you for authorization specialist, GRC analyst, security control assessor, and ISSO/ISSM roles where authorization work is primary.
CISSP complements CGRC by adding broader security context. Holding both demonstrates comprehensive capability for positions requiring both general security knowledge and authorization expertise.
CISA from ISACA adds audit perspective that connects to assessment activities. Understanding both authorization and audit strengthens GRC capabilities.
For technical depth alongside GRC, certifications like Security+ or CySA+ ensure you understand the controls you’re assessing and authorizing.
Continuing professional education maintains CGRC certification. ISC2 requires annual CPE credits, ensuring ongoing engagement with evolving GRC practices and requirements.
Federal cybersecurity through a defense contractor. Cloud security, threat hunting, compliance frameworks.

Leave a Reply