Certification guide
Certified in Governance, Risk and Compliance (CGRC) is ISC2’s credential for the people who get systems authorized, the practitioners who carry an information system through categorization, control selection, implementation, assessment, and the formal risk-acceptance decision, then keep it compliant for the rest of its life. Formerly known as CAP, it is the recognized certification for Risk Management Framework (RMF) and FedRAMP work, and it holds a place on the U.S. DoD 8140 approved list, which makes it a career staple for federal, defense-contractor, and regulated-industry GRC roles.
The exam was refreshed effective June 15, 2024, and the update matters: ISC2 embedded AI governance throughout the outline. Alongside the classic RMF material (FIPS 199 categorization, NIST SP 800-53 baselines and tailoring, assessment methods, authorization packages, continuous monitoring) today’s CGRC expects you to reason about the NIST AI RMF, ISO/IEC 42001, the EU AI Act, model training versus inference boundaries, and treating ML weight updates as formal system changes. Our practice questions reflect that current outline, not the pre-2024 one.
Security and Privacy Governance, Risk Management, and Compliance Program
Domain 1 · 16%GRC principles and the frameworks that carry them (NIST, COBIT, ISO/IEC 27001) plus the SDLC, the information lifecycle, roles and responsibilities, and the regulatory landscape from FISMA and HIPAA to GDPR, FedRAMP, PCI DSS, and CMMC. The AI refresh adds governance boards, the NIST AI RMF, and ISO/IEC 42001.
Scope of the System
Domain 2 · 10%Describing the system and drawing its authorization boundary: information types, FIPS 199 security objectives and the high water mark, impact levels, and privacy screening. Modern scoping includes embedded algorithms in COTS software and the line between model training environments and inference endpoints.
Selection and Approval of Framework, Security, and Privacy Controls
Domain 3 · 14%Baselines and inherited controls, then tailoring (scoping considerations, compensating controls, organization-defined parameters, overlays, and enhancements) followed by control allocation, documentation, stakeholder agreement, and the continuous monitoring strategy that gets written before anything is built.
Implementation of Security and Privacy Controls
Domain 4 · 17%The heaviest domain: implementation strategy (resourcing, funding, timeline, effectiveness), control types, executing selected and compensating controls, and documenting everything, as-built SSP descriptions, POA&M entries, risk registers, and the policies and procedures that prove controls fit the organization.
Assessment/Audit of Security and Privacy Controls
Domain 5 · 16%Planning and conducting assessments with the interview-examine-test methods, validating evidence, writing initial and final reports, dispositioning findings as compliant / non-compliant / not applicable, choosing risk responses, reassessing corrected findings, and building the risk response plan.
System Compliance
Domain 6 · 14%The authorization decision itself: compiling and submitting the package, determining risk posture and residual risk against acceptance criteria, stakeholder concurrence, and the formal decision (ATO, denial, interim authorizations, ongoing authorization) with its terms, conditions, and notifications.
Compliance Maintenance
Domain 7 · 13%Life after authorization: change management and security impact analysis, continuous monitoring, incident response and contingency exercises, security updates, evidence collection, awareness training, audits, revising the monitoring strategy as requirements shift, and, eventually, decommissioning the system properly.
Our CGRC practice exams mirror the real thing: 125 questions per attempt, a three-hour timer, and domain weighting matched to the official outline, with a plain-language explanation behind every question. ISC2 scores the live exam on a 700-out-of-1000 scale; we set the pass mark at 70% as the honest raw-score equivalent, so a passing run here means genuine coverage across all seven domains, not luck in the heavy ones.
CGRC Training
The RMF life cycle for the ISC2 CGRC exam, one lesson at a time.
Subscribe to startISC2 CGRC — Practice Exam A
Full-length CGRC practice exam — 125 original questions weighted to the official ISC2 exam outline (effective June 15, 2024): Governance, Risk Management & Compliance Program 16%…
Subscribe to startFrequently asked questions about CGRC
What is the CGRC certification?
Certified in Governance, Risk and Compliance is ISC2’s credential for practitioners who get information systems authorized, carrying a system through categorization, control selection, implementation, assessment, and the formal risk-acceptance decision, then keeping it compliant for the rest of its life. It was formerly known as CAP, and it is the recognized certification for Risk Management Framework (RMF) and FedRAMP work.
How many questions are on the CGRC exam and how long is it?
The exam contains 125 items and runs for three hours. Items are a mix of multiple choice and advanced item types.
What is the passing score for CGRC?
ISC2 scores the live exam on a scaled system and the passing mark is 700 out of 1000. Because a scaled score is not a raw percentage, Certifym sets the pass mark on its practice exams at 70% as the honest raw-score equivalent.
What experience do I need before taking CGRC?
Two years of experience is the stated requirement. Candidates who do not yet have it can sit the exam and enter as an Associate of ISC2 instead.
Where do I take the CGRC exam?
The exam is delivered through Pearson VUE.
What domains does CGRC cover and how are they weighted?
Seven domains: Security and Privacy Governance, Risk Management, and Compliance Program (16%), Scope of the System (10%), Selection and Approval of Framework, Security, and Privacy Controls (14%), Implementation of Security and Privacy Controls (17%), Assessment/Audit of Security and Privacy Controls (16%), System Compliance (14%), and Compliance Maintenance (13%). Implementation is the heaviest domain, with Domains 1 and 5 close behind.
What changed in the June 2024 CGRC exam update?
The exam was refreshed effective June 15, 2024, and ISC2 embedded AI governance throughout the outline. Alongside the classic RMF material, today’s CGRC expects you to reason about the NIST AI RMF, ISO/IEC 42001, the EU AI Act, the boundary between model training and inference, and treating ML weight updates as formal system changes. Domain 1 also picks up governance boards, and Domain 2 picks up embedded algorithms in COTS software.
How hard is the CGRC exam?
It is a documentation-and-judgment exam rather than a technical configuration exam, and its difficulty comes from breadth: FIPS 199 categorization, NIST SP 800-53 baselines and tailoring, assessment methods, authorization packages, and continuous monitoring all sit alongside a regulatory landscape running from FISMA and HIPAA to GDPR, FedRAMP, PCI DSS, and CMMC, plus the post-2024 AI governance material. The two-year experience expectation reflects that breadth.
How do I prepare for CGRC?
Work from the current, post-June-2024 outline rather than pre-2024 material, and drill across all seven domains rather than only the heavy ones. Certifym’s CGRC practice exams mirror the live format (125 questions per attempt, a three-hour timer, and domain weighting matched to the official outline) with a plain-language explanation behind every question.
How does CGRC compare with other ISC2 certifications?
CGRC is the ISC2 credential aimed squarely at the authorization lifecycle (the governance, risk and compliance work of getting a system through RMF or FedRAMP and keeping it compliant afterwards) and it carries a place on the U.S. DoD 8140 approved list. ISC2’s other credentials target different bodies of knowledge, so the practical way to choose is to compare the seven CGRC domains above against the published outline for the other exam and pick the one that matches the work you actually do.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CGRC®, CISSP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certifications for which our independent practice materials are designed. The CGRC exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.
All questions, answers, and explanations on Certifym are original content created for practice purposes. They are not actual ISC2 examination questions and are not represented as such. Practicing with these materials does not guarantee a passing result on any live certification exam.
