CGRC – Governance, Risk and Compliance Certification


Capitalize on the rising demand for Governance, Risk and Compliance (GRC) expertise by earning the CGRC certification. The CGRC is a proven way to demonstrate your knowledge and skills to integrate governance, performance management, risk management and regulatory compliance within your organization.
CGRC professionals utilize frameworks to integrate security and privacy within organizational objectives, better enabling stakeholders to make informed decisions regarding data security, compliance, supply chain risk management and more.
Shows advanced technical skills and knowledge to protect, authorize and maintain information systems within various risk management frameworks.
Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program
Domain 2: Scope of the System
Domain 3: Selection and Approval of Framework, Security, and Privacy Controls
Domain 4: Implementation of Security and Privacy Controls
Domain 5: Assessment/Audit of Security and Privacy Controls
Domain 6: System Compliance
Domain 7: Compliance Maintenance
The CGRC is ideal for IT, information security and information assurance practitioners who work in Governance, Risk and Compliance (GRC) roles and have a need to understand, apply and/or implement a risk management program for IT systems within an organization, including positions like:
With Official ISC2 Training, you’re guaranteed up-to-date content that aligns to the latest exam domains. Explore the training that best meets your needs and learning style, use our self-study tools or trust our training partners around the world to help you in your certification journey.
Get the inside scoop on CGRC with these resources.
.jpg?h=416&iar=0&w=416)

.jpg?h=416&iar=0&w=416)

.jpg?h=416&iar=0&w=416)





| Product | Training Access | Exam Window | Exam Attempts |
|---|---|---|---|
| Exam Only | — | 365 days | 1 |
| Exam Only with Peace of Mind Protection | — | 180 days | 2 |
| Online Instructor-Led Training | 180 days (from first session) | — | — |
| Online Instructor-Led Training + Exam | 180 days (from first session) | 365 days | 1 |
| Online Instructor-Led Training + Exam with Peace of Mind Protection | 180 days (from first session) | 180 days | 2 |
| Online Self-Paced Training (90-Day) | 90 days | — | — |
| Online Self-Paced Training (180-Day) | 180 days | — | — |
| 180-Day Online Self-Paced Training + Exam | 180 days | 365 days | 1 |
| 180-Day Online Self-Paced Training + Exam with Peace of Mind Protection | 180 days | 180 days | 2 |
| 90-Day Online Self-Paced Training + Exam | 90 days | 365 days | 1 |
| 90-Day Online Self-Paced Training + Exam with Peace of Mind Protection | 90 days | 180 days | 2 |
| Certificates, Courses, and Express Courses | 60 days | — | — |
Purchase of exam(s) only.
Access periods:
Exam code must be scheduled and administered with 365 days of purchase.
Exam-only purchase with two attempts included in the purchase price.
Applies to Online Instructor-Led Certification Education Course purchases without an exam.
Access periods:
Applies to Online Instructor-Led Certification Education Course + Exam bundles.
Access periods:
Applies to Online Instructor-Led Certification Education Course and Exam with Peace of Mind Protection bundles.
Access periods:
Available in 90-day and 180-day access options. All access periods begin from the date of purchase.
© Copyright 1996-2026. ISC2, Inc. All Rights Reserved.
All contents of this site constitute the property of ISC2, Inc. and may not be copied, reproduced or distributed without prior written permission. ISC2, CISSP, SSCP, CCSP, CGRC, CSSLP, HCISPP, ISSAP, ISSEP, ISSMP, CC, and CBK are registered marks of ISC2, Inc.




