How Long Does It Really Take to Prepare for CC?

ISC2 Certified in Cybersecurity CC exam facts card: 100 to 125 items, two hours, passing grade 700 out of 1000, 58 to 72 seconds per item

Before you work out how many weeks you need, check the date on what you are studying from. The CC exam outline changed on 1 September 2026, and it was not a tidy-up: an entire domain was replaced. A great deal of the free material, and a good deal of the paid material, is still teaching the previous exam.

Everything below comes from ISC2’s own pages, and is explicit where ISC2 publishes nothing. Verified 18 September 2026.

ISC2 Certified in Cybersecurity CC exam facts card: 100 to 125 items, two hours, passing grade 700 out of 1000, 58 to 72 seconds per item
CC at a glance. Figures verified on isc2.org, 18 September 2026.

The test that takes five seconds

Open your book, course or video playlist and look at the domain list. If it says Business Continuity or Access Controls Concepts, it describes the outline that ended on 31 August 2026. That is the fastest way to tell, and it is more reliable than a “2026 edition” badge on the cover.

Side by side comparison of the ISC2 CC domains before and after 1 September 2026, showing Business Continuity Disaster Recovery and Incident Response at 10 per cent replaced by Security Governance at 17.3 per cent
The domain rewrite, as ISC2 published it. Source: ISC2, Inside the Updated ISC2 CC Exam, 6 August 2026.

The biggest single move is Domain 2. Business Continuity, Disaster Recovery and Incident Response was 10% of the exam. It is gone, replaced by Security Governance at 17.3% — GRC, security awareness, organisational culture, and measuring effectiveness through metrics, key risk indicators and dashboards. BC and DR survive as “redundancy concepts” inside that domain rather than as its subject.

Can you settle a CC question in under a minute?

Timed practice against the two-hour limit, with a written explanation for every answer — so the questions you get wrong are the ones you learn from.

  • Full-length timed tests that hold you to the real two-hour limit
  • An explanation for every answer, right and wrong
  • Original questions written from ISC2’s published outline — never real exam content

On Udemy · lifetime access · 30-day refund policy applies

Straight answer before you click: our CC question bank was written against the previous exam outline and is being rebuilt for the domains that took effect on 1 September 2026. Until that is done it is useful for the fundamentals that did not change — and it does not yet cover the new governance, cloud and threat-intelligence material. We would rather tell you that here than have you find out afterwards.

Comparing entry points? CompTIA Security+ practice tests. Heading for cloud instead? AWS Solutions Architect Associate practice tests.

What you now have to learn that you did not before

  • Governance, risk and compliance as a domain in its own right, including how cybersecurity effectiveness is measured and reported.
  • Cloud security — characteristics, service models, deployment models and the shared responsibility model — now explicit in Domain 4.
  • Zero trust and micro-segmentation, alongside wireless and embedded systems such as IoT and industrial control systems.
  • Identity lifecycle management — provisioning, review, deprovisioning, role definition — not just access control models.
  • Cyber threat intelligence, threat actors and threat frameworks, plus security event triage and prioritisation.
  • Security testing including red, blue and purple teaming, application testing, threat modelling and physical penetration testing concepts.
  • Data masking, sanitisation and quantum-resistant cryptography.
  • Foundational AI topics across all five domains — identifying AI assets, automated threats, model poisoning, and model drift as a continuity risk.

That is a substantial amount of genuinely new ground, and it is weighted toward the areas people find least intuitive. Budget for it rather than assuming a refresh of old notes will do.

Study to the weights

ISC2 publishes what each domain is worth, and labels them average weights because the exam is adaptive: Security Principles 24%, Networking and Cloud Security 21.3%, IAM 20%, Security Governance 17.3%, Security Operations and Incident Response 17.3%. The spread is unusually flat — under seven points between the largest and smallest — so there is no domain you can safely skip and no single domain that decides the outcome.

Start the timer early

Two hours, 100 to 125 items. That is 72 seconds a question at best and 57.6 at worst, and you will not know which you are sitting until it ends. Practise against the tighter number. Adaptive exams also punish dithering in a particular way: you cannot return to earlier questions on a CAT exam the way you can on a fixed form, so learning to commit is part of the preparation, not a personality trait.

A readiness test you can actually observe

There is no score to chase. ISC2 does not release one, so “I am getting 85% in practice” corresponds to nothing you will ever see on exam day. Judge readiness by coverage and pace instead: you are ready when you are consistently sound across all five current domains — including the material that is new in this outline — and finishing inside two hours without rushing the closing stretch.

Where practice questions fit

Practice questions are a diagnostic, not a syllabus. Their job is to find the domain you are weak in and to train you to commit to an answer quickly, which matters more on an adaptive exam than on a fixed one. Used that way — timed, reviewed, and written from the published outline — they are the most efficient preparation available in the last few weeks.

One caution that matters more than it appears to. Sites offering “real exam questions”, brain dumps or leaked CC content are selling you a violation of the ISC2 Examination Agreement and Non-Disclosure Agreement, and ISC2 states it may revoke certifications and ban you from earning future ones. They are also stale by construction: the outline changed on 1 September 2026, so anything harvested before then describes an exam that no longer exists.

Practise under the clock, not just the syllabus.

When to book

Book when the new material is as solid as the old, not before — and remember that a failure costs 30 test-free days and another USD 199. For the full set of published parameters, see our ISC2 Certified in Cybersecurity (CC) exam guide.

Frequently asked questions

Did the ISC2 CC exam change in 2026?

Yes. A new exam outline took effect on 1 September 2026. Business Continuity, Disaster Recovery and Incident Response was replaced by a Security Governance domain, Access Controls became Identity and Access Management, and Network Security became Networking and Cloud Security Concepts.

How can I tell if my study material is out of date?

Look at the domain list. If it names ‘Business Continuity’ or ‘Access Controls Concepts’ as a domain, it was written for the outline that ended on 31 August 2026.

How long does ISC2 say you should study for CC?

ISC2 publishes no study-hour figure. What it does publish is that no work experience is required, and the full exam outline showing what is examinable.

What is new on the CC exam?

Security governance and GRC, cloud security including service and deployment models and the shared responsibility model, zero trust, identity lifecycle management, cyber threat intelligence, threat frameworks, red, blue and purple teaming, quantum-resistant cryptography, and foundational AI topics across all five domains.

Should I practise with a timer?

Yes. The exam is adaptive with 100 to 125 items in two hours, so your budget per question is between 72 and 57.6 seconds and you cannot know which in advance. Practise against the tighter figure.


Sources. All exam parameters above come from ISC2’s own CC certification page and exam outline (effective 1 September 2026), its article on the updated exam, its exam policy pages and its Annual Maintenance Fee page, accessed 18 September 2026, together with its 22 April 2026 press release on the conclusion of the One Million Certified in Cybersecurity programme. Exam parameters change; if you spot a discrepancy, check ISC2’s page and tell us so we can correct it.

Disclosure and disclaimer. FoxMedium publishes independent study material. Our practice tests are not official ISC2 content and are not endorsed by, affiliated with, or representative of ISC2 or the official certification examination. All questions are original and written from publicly published exam outlines. We do not host or distribute real exam content. Links to our courses earn us revenue if you enrol. ISC2, CC, Certified in Cybersecurity, CISSP and all related trademarks belong to their respective owners.

Scroll to Top