ISC2 entry-level certification covering foundational cybersecurity concepts and best practices.
Who it's for
Entry-level IT/security professionals and career changers seeking a foundational cybersecurity credential — ISC2 explicitly designed CC as a low-barrier entry point into the field, including a program offering free training and a free exam attempt to qualifying candidates as part of ISC2's push to grow the cybersecurity workforce.
What's covered
- Security principles
- Business continuity, disaster recovery, and incident response concepts
- Access control concepts
- Network security
- Security operations
What to expect
As an entry-level credential, expect foundational, definition-and-concept-oriented questions rather than the applied performance-based items seen on more advanced security exams — the goal is confirming you understand core security vocabulary and principles.
How to prepare
ISC2 offers free official self-paced training for CC through its website (part of its workforce initiative), along with an official practice test; because the exam is intentionally foundational, candidates with even limited IT/security exposure can typically prepare in a shorter timeframe than more advanced credentials in this space.
Certification details
- Certifying body: ISC2 (International Information System Security Certification Consortium).
- Eligibility: No formal prerequisites — designed as an entry-level credential for those new to cybersecurity.
- Exam format: 100 multiple-choice questions, 2-hour time limit, computer-based testing at Pearson VUE test centers.
- Content outline: Security principles, business continuity/disaster recovery/incident response concepts, access control concepts, network security, and security operations.
- Recertification: Every 3 years, via continuing professional education (CPE) credits and annual membership fee.
