Training course
This is a free, self-paced reading course for CGRC: Certified in Governance, Risk and Compliance, ISC2’s credential for the people who get systems authorized. Formerly CAP, it is the recognized certification for Risk Management Framework and FedRAMP work and sits on the U.S. DoD 8140 approved list. The exam does not ask you to configure anything. It asks whether you can categorize an information system, select and tailor its controls, prove they work, assemble the package that an authorizing official will sign, and keep the whole thing defensible for years afterward, which is a different skill from securing a system, and one this course is built to teach in that order.
The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. CGRC’s seven domains are unusually even, nothing is below 10% and nothing is above 17%, which means there is no domain you can safely skim, and the module weights are there to stop you from over-investing in the documentation you already write at work. The June 2024 refresh threaded AI governance through the whole outline, so the modules cover the NIST AI RMF, ISO/IEC 42001, and the EU AI Act where the outline places them rather than parking them in a separate chapter.
What the course covers
Security and Privacy Governance, Risk Management, and Compliance Program
Module 1 · 16%GRC principles and the frameworks that carry them (NIST, COBIT, ISO/IEC 27001) plus the SDLC, the information lifecycle, roles and responsibilities, and the regulatory landscape running from FISMA and HIPAA to GDPR, FedRAMP, PCI DSS, and CMMC. The 2024 refresh adds AI governance boards, the NIST AI RMF, and ISO/IEC 42001.
Scope of the System
Module 2 · 10%Describing the system and drawing its authorization boundary: information types, FIPS 199 security objectives and the high water mark, impact levels, and privacy screening. Modern scoping extends to embedded algorithms inside COTS software and to the line between model training environments and inference endpoints.
Selection and Approval of Framework, Security, and Privacy Controls
Module 3 · 14%Baselines and inherited controls, then tailoring (scoping considerations, compensating controls, organization-defined parameters, overlays, and enhancements) followed by control allocation, documentation, stakeholder agreement, and the continuous monitoring strategy that has to be written before anything is built.
Implementation of Security and Privacy Controls
Module 4 · 17%The heaviest domain: implementation strategy across resourcing, funding, timeline, and effectiveness; control types; executing selected and compensating controls; and documenting all of it, as-built system security plan descriptions, POA&M entries, risk registers, and the policies and procedures that prove a control actually fits the organization.
Assessment/Audit of Security and Privacy Controls
Module 5 · 16%Planning and conducting assessments with the interview, examine, and test methods; validating evidence; writing initial and final reports; dispositioning findings as compliant, non-compliant, or not applicable; choosing risk responses; reassessing corrected findings; and building the risk response plan.
System Compliance
Module 6 · 14%The authorization decision itself: compiling and submitting the package, determining risk posture and residual risk against acceptance criteria, securing stakeholder concurrence, and the formal outcome (ATO, denial, interim authorization, or ongoing authorization) with its terms, conditions, and notifications.
Compliance Maintenance
Module 7 · 13%Life after authorization: change management and security impact analysis, continuous monitoring, incident response and contingency exercises, security updates, evidence collection, awareness training, audits, revising the monitoring strategy as requirements shift, and eventually decommissioning the system properly.
How to use it
Read the modules in order. CGRC is one of the few exams where the published sequence is also the real-world sequence (you cannot select controls before you have scoped the boundary, and you cannot maintain compliance for a system nobody authorized) so reading out of order costs you the causal chain the questions are built on. After each module, take the matching portion of the CGRC practice exam to check whether you can apply the step rather than describe it. The page you are reading is open to everyone; the course lessons themselves open once you are signed in to a free Certifym account.
For exam logistics, the 125 items, the three-hour timer, advanced item types, the 700-of-1000 scaled pass mark, the two-year experience requirement and the Associate of ISC2 route, see the CGRC certification guide.
What CGRC Is: The RMF-Focused Practitioner Role
The Certified in Governance, Risk and Compliance (CGRC) credential validates a practitioner's ability to authorize and maintain information systems using a risk-based process aligned with the NIST Risk Management Framework (RMF). It replaced the Certified Authorization Professional (CAP) credential in 2022, retaining the same body of knowledge but with a broader name that better reflects the modern scope: governance, risk, and compliance activities across both public and private sectors.
The practitioner it targets
CGRC is aimed at people whose day job is authorizing and maintaining systems: Information System Security Officers (ISSOs), Authorizing Officials, security control assessors, GRC program managers, compliance analysts, and consultants who help organizations navigate the RMF or equivalent frameworks (FedRAMP, DoD RMF, HITRUST). Unlike CISSP, which spans eight broad security domains, CGRC concentrates on the specific life-cycle of taking a system from concept to authorized operation and keeping it there.
The seven-domain structure
The exam is organized around the RMF life cycle, with a governing program layer on top:
- Information Security Risk Management Program (16%) — the governance and program context inside which all authorization work happens.
- Scope of the System (10%) — determining what is being authorized (RMF: Categorize).
- Selection and Approval of Security and Privacy Controls (15%) — picking the right controls (RMF: Select).
- Implementation of Security and Privacy Controls (15%) — making those controls operate (RMF: Implement).
- Assessment/Audit of Security and Privacy Controls (15%) — verifying they work (RMF: Assess).
- Authorization/Approval of Information System (13%) — the risk-based decision to operate (RMF: Authorize).
- Continuous Monitoring (16%) — sustaining the authorization (RMF: Monitor).
Notice that domains 2 through 7 map cleanly to RMF steps Categorize, Select, Implement, Assess, Authorize, and Monitor. Domain 1 covers the Prepare step and the surrounding governance context. Learning the mapping is the fastest way to organize your study.
Why the framework focus matters
Where CISSP asks “is this the strongest control?”, CGRC asks “is this control appropriate for the categorized risk, documented in the SSP, tested by the assessor, and accepted by the AO?” The framework mindset is the exam's defining feature: the correct answer is almost always the one that follows the documented process, not the one that produces the strongest technical outcome in isolation.
The exam-relevant consequence: when a scenario describes a technically better control that skips a required step (an ISSO who patches without a Security Impact Analysis, an assessor who tests scope not in the plan, an AO who authorizes without a POA&M for known findings), the process-compliant answer wins even when it sounds slower.
What this course covers
This course walks the RMF life cycle in the order the CGRC exam tests it, with practitioner-focused explanations of each step. By the end you will be able to:
- Name every RMF step and its outputs.
- Explain the roles — Authorizing Official, ISO, ISSO, Common Control Provider, Assessor — and who owns each decision.
- Read a categorization, control selection, or assessment result and identify what goes into the authorization package.
- Distinguish continuous monitoring activities from ad hoc security operations, and describe what an ongoing authorization posture requires.
- Handle the exam's process-compliance questions with confidence.
Exam format
CGRC is a 125-question, three-hour exam using ISC2's Computerized Adaptive Testing (CAT) engine. Questions are multiple-choice and multiple-response. The pass mark is scaled to 700 out of 1000. Candidates need two years of paid, cumulative work experience in one or more of the seven CGRC domains; a relevant four-year degree or additional credential can substitute for one year. Endorsement by an existing ISC2 member is required after passing.
Recertification is annual through CPE credits (60 over the three-year cycle), consistent with ISC2's other credentials.
How to use this course
The material is dense but organized to be studied in order. Each lesson ends with key terms — if you can recall these without the lesson in front of you, you have the exam-tested vocabulary. Pair the course with the CGRC practice-exam sets (Certifym has ten, 1,250 questions total) once you have covered the whole curriculum once; the exams are calibrated to the same domain weights and vocabulary this course establishes.
Frequently asked questions about the CGRC training course
Is the CGRC training course free?
Yes. The course costs nothing to read. Opening the lessons requires a free Certifym account, and nothing beyond that, no payment, no trial. It is funded by the practice-exam catalogue it sits alongside.
How is the course structured?
One module per official CGRC domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. Within each module the material is broken into short lessons, followed by key terms and further reading.
Does this replace ISC2’s official training?
No. ISC2 publishes the authoritative exam outline and sells its own official training; this course is an independent study companion, written to be read quickly and to slot alongside practice questions. Download the current outline from isc2.org and treat it as the source of truth.
Do I need the two years of experience before studying?
No. The experience requirement applies to certification, not to study, and candidates who sit the exam without it enter as an Associate of ISC2 until they earn it. What does help before you start is having seen a real authorization package, an SSP, or a POA&M. The material lands differently once you have.
What should I do after finishing the course?
Move to the CGRC practice exam and work until you are clearing 70% consistently across all seven domains. Because the CGRC weights are so even, a strong score in Implementation will not carry a weak score in Scope of the System. Then book with Pearson VUE.
Is the course current?
The course is built against the outline refreshed effective June 15, 2024, the seven domains and the weights of 16%, 10%, 14%, 17%, 16%, 14%, and 13% published on the CGRC certification guide. That refresh is the one that embedded AI governance throughout the outline, so material written for the pre-2024 CAP or CGRC syllabus is out of date. ISC2 can revise the outline at any time; verify the current version at isc2.org before you schedule.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CGRC®, CISSP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The CGRC exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam format, domain weights, and eligibility criteria are set by ISC2 and may change; always verify current details at isc2.org before scheduling your exam.
