The upcoming Certified in Cybersecurity (CC) Exam Outline, effective September 1, 2026, represents the first major content update to the certification since its launch in August 2022. While the exam content has continued to evolve through regular item updates and maintenance, those changes remained aligned to the original outline. During this period, the exam also transitioned from its initial linear testing format to Computerized Adaptive Testing (CAT). The revised exam outline reflects the ongoing evolution of cybersecurity practices and the knowledge and skills expected of today’s entry-level cybersecurity professionals.

The CC certification prepares individuals entering the cybersecurity field to understand essential security concepts, including those related to AI. Foundational AI topics are integrated throughout the examination outline, ensuring new professionals can identify AI assets, recognize automated threats, and support secure governance of emerging technologies.

While the exam retains its five-domain structure, several domains have been renamed, reorganized and expanded to place greater emphasis on governance, identity management, cloud security, threat intelligence and incident response. These revisions reflect the latest Job Task Analysis (JTA), part of the established exam refresh cycle that aligns the certification with current industry practices and employer expectations.

New CC Domain Structure and Weightings

The upcoming Certified in Cybersecurity Certification Exam Outline introduces significant changes to domain names and exam weightings. The most notable shift is the expansion of governance and risk-related topics, which now comprise a dedicated domain worth 17.3% of the exam. Incident response, previously a standalone concept within Domain 2, has become a major component of Domain 5.  

2025 Exam Outline Domains

Weight

2026 Exam Outline Domains

Weight

Security Principles

26%

Security Principles

24%

Business Continuity (BC), Disaster Recovery (DR)
& Incident Response Concepts

10%

Security Governance

17.3%

Access Controls Concepts

22%

Identity and Access Management (IAM) Concepts

20%

Network Security

24%

Networking and Cloud Security Concepts

21.3%

Security Operations

18%

Security Operations and Incident Response

17.3%

Domain 1: Security Principles Becomes More Governance-Focused

Domain 1 maintains its foundational focus, but modernizes terminology and broadens concepts. "Information assurance" has been replaced with "cybersecurity concepts," introducing Authentication, Authorization and Accounting (AAA) as a core concept. Risk management has been updated from understanding the risk management process to understanding risk management concepts, including the risk management lifecycle and processes. Governance-related topics have been expanded to include frameworks and guidelines alongside regulations, laws, policies, standards and procedures. The domain also adds due care and due diligence to the ethics section, reinforcing professional responsibility. 

Domain 2: Business Continuity Evolves into Security Governance

One of the most significant revisions is the replacement of the Business Continuity, Disaster Recovery and Incident Response domain with Security Governance. Rather than focusing primarily on continuity planning concepts, the new domain emphasizes Governance, Risk and Compliance (GRC), organizational security awareness, cybersecurity culture and measurement of program effectiveness through metrics, key risk indicators (KRIs), dashboards and reports. Business continuity and disaster recovery remain important topics but are now covered under redundancy concepts rather than serving as the primary focus of the domain. 

Domain 3: Identity and Access Management Expands Beyond Access Controls

The former Access Controls Concepts domain has been transformed into Identity and Access Management (IAM) Concepts. While core access control principles such as least privilege and separation of duties remain, the updated outline broadens coverage to include identity lifecycle management, provisioning and deprovisioning processes, role definitions and IAM frameworks and tools. The revision reflects the growing importance of identity as a security perimeter in modern environments. 

Domain 4: Greater Emphasis on Cloud Security and Zero Trust

The previous Network Security domain has expanded into Networking and Cloud Security Concepts. Traditional networking topics remain, but the outline now introduces dedicated cloud security coverage, including cloud characteristics, deployment models, service models and the shared responsibility model. The updated domain also adds zero trust and modern segmentation approaches while increasing attention to wireless technologies and embedded systems such as IoT and industrial control systems. 

Domain 5: Security Operations Expands to Include Threat Intelligence and Incident Response

Perhaps the most substantial content expansion occurs in Domain 5. The previous focus on data security, system hardening, security policies and awareness training evolves into a broader Security Operations and Incident Response domain. New topics include:

  • Security event triage and prioritization
  • Threat actors and motivations
  • Cyber threat intelligence
  • Threat frameworks
  • Incident response planning and exercises
  • Asset lifecycle management
  • Security readiness testing, including red, blue and purple teaming
  • Application security testing and threat modeling
  • Physical penetration testing concepts

The domain also modernizes data security coverage by adding data masking, sanitization and quantum-resistant cryptography. 

ISC2’s Commitment to Candidates

These changes help ensure candidates develop foundational knowledge that aligns with modern cybersecurity operations and the skills organizations increasingly seek in early-career professionals. As the cybersecurity landscape continues to evolve, the updated CC exam outline reinforces ISC2’s commitment to preparing entry-level professionals with relevant, practical knowledge they can apply from the start of their careers. For candidates, the refreshed outline offers a clearer path to building confidence, credibility and readiness for today’s cybersecurity roles.