Top of Page
 

CAP to CGRC Name Change FAQ

Q:
Why is the CAP exam name changing and what is it changing to?
 
A:

The Certified Authorization Professional (CAP) is changing to Certified in Governance, Risk and Compliance (CGRC). Only the name is changing. 

This change better represents the knowledge, skills and abilities required to earn and maintain this certification. The subject matter is broader and more inclusive to frameworks used around the world. 

Certified in Governance, Risk and Compliance (CGRC) cybersecurity professionals have the knowledge and skills to integrate governance, performance management, risk management and regulatory compliance within the organization while helping the organization achieve objectives, address uncertainty and act with integrity. CGRC professionals align IT goals with organizational objectives as they manage cyber risks and achieve regulatory needs. They utilize frameworks to integrate security and privacy with the organization’s overall objectives, allowing stakeholders to make informed decisions regarding data security and privacy risks.

Q:
When will CAP change its name to CGRC?
 
A:
It will officially change on February 15, 2023.
Q:
What are the required domains for the CGRC
 
A:
Current Domains Weight
Domain 1: Information Security Risk Management Program 16%
Domain 2: Scope of the Information System 11%
Domain 3: Selection and Approval of Security and Privacy Controls 15%
Domain 4: Implementation of Security and Privacy Controls 16%
Domain 5: Assessment/Audit of Security and Privacy Controls 16%
Domain 6: Authorization/Approval of Information System 10%
Domain 7: Continuous Monitoring 16%
  100%

Please refer to the Exam Outline for details.

The content of the exam last changed on August 15, 2021. More information about the previous content change can be found on the blog.

Q:
If I already hold the CAP certification, what do I need to do?
 
A:
Your digital certificate will update in your account. You will be sent an email from Credly to accept a new version of the digital badge representing the change to CGRC.
Q:
In what language will the CGRC exam be available?
 
A:
The CGRC exam has the same format and language availability as the CAP has at this time. It is available in English in the linear fixed form format.
Q:
Will this name change impact the number of items or the time required to take the CGRC exam?
 
A:
No. The name update will not impact the number of items on the CGRC exam, which is 125 items within a three-hour limit.
Q:
If I have been studying for the CAP exam with material that focuses on the current domains, will I be sufficiently prepared to take the new exam without additional study?
 
A:
Yes, this change is to only the name of the exam. All (ISC)² exams are experiential and include experience-based items that cannot be learned by studying alone. If you already have the required experience in the domains and believe that you have sufficient proficiency in those domains, you should feel confident that you can pass the CGRC exam and meet the experience requirements for full certification.
Q:
Do these updates affect the experience requirement for the CGRC?
 
A:

No. For the CGRC, you are required to have a minimum of two years of cumulative work experience in one or more of the seven domains of the CGRC.

  • Information Security Risk Management Program
  • Scope of the Information System
  • Selection and Approval of Security and Privacy Controls 
  • Implementation of Security and Privacy Controls
  • Assessment/Audit of Security and Privacy Controls
  • Authorization/Approval of Information Systems
  • Continuous Monitoring
Q:
What impact do these changes have on (ISC)² training materials?
 
A:
The Official (ISC)² CGRC Training Course (online-instructor led) will be available in January 2023. The current CAP CBK book can still be used, and training content material is not changing aside from a name change. Student guides will be available with the purchase of an online instructor training course.
Q:
What type of roles and professional experiences are ideal for the CGRC?
 
A:

The CGRC is ideal for IT, information security and cybersecurity professionals responsible for governance, risk and compliance within an organization. Roles include:

  • Authorizing Official
  • Cyber GRC Manager
  • Cybersecurity Auditor
  • Cybersecurity Compliance Officer
  • GRC Architect
  • GRC Information Technology Manager
  • GRC Manager
  • Cybersecurity Risk & Compliance Project Manager 
  • Cybersecurity Risk & Controls Analyst
  • Cybersecurity Third Party Risk Manager
  • Enterprise Risk Manager
  • GRC Analyst
  • GRC Director
  • GRC Security Analyst
  • System Security Manager
  • System Security Officer
  • Information Assurance Manager
Q:
Will this impact my AMF (Annual Maintenance Fee) or CPE (Continuing Professional Education) credits?
 
A:
The AMF and CPE requirements will remain the same. To maintain CGRC, you must earn and submit 60 CPE credits during your three-year certification cycle and pay an AMF of U.S. $125 upon the anniversary of the original certification date.
Q:
I have been studying for CAP, can I still take the CAP exam?
 
A:
You can still take the CAP exam on or before February 14, 2023. Should you pass, your certification will be changed to CGRC automatically on February 15, 2023.
Q:
As a current CAP certification holder, I would like a new CGRC certificate, can I order and purchase one?
 
A:
You may access your profile to download a copy of your CGRC certificate to print after February 15, 2023. Candidates who pass the CGRC exam after February 15, 2023, will receive a certificate by mail. Yes, you may also order and purchase through the member support team at https://www.isc2.org/contact-us.
Q:
How do I connect with others who have this certification?
 
A:
Connect and network with others who already hold the certification at: https://community.isc2.org/t5/CAP-Group/gh-p/CAP.
Q:
How can I connect with others studying for this new certification?
 
A:
Connect and prepare with others for the certification at:  https://community.isc2.org/t5/CAP-Study-Group/gh-p/CAP_StudyGroup.
Q:
How can I prepare for the CGRC exam?
 
A:
Trainings, seminars and courseware directly from (ISC)² or one of our many Official Training Providers help you get ready for the CGRC exam by reviewing relevant domains and topics. Visit www.isc2.org/Training to register for the course that best meets your needs. Private on-site and online instructor-led trainings are also available.
Q:
How do I register for the CGRC exam?
 
A:

Beginning January 1, 2023, you can visit Pearson VUE home.pearsonvue.com/isc2 and click to register for CGRC at an exam location of your choice on or after February 15, 2023. Prior to 2023, the exam will remain listed under the CAP name.

Q:
What is the cost of the CGRC certification?
 
A:

The price of the exam is U.S. $599 (EUR 555, GBP 479). This cost does not include training. 

Ok