π§© CGRC
Certified in Governance, Risk and Compliance (formerly CAP by ISCΒ²)
π Advanced certifications with a comprehensive focus on cybersecurity, risk management, policy, auditing, and governance.
π§ 1. Certification Name and Issuing Body
Full name: Certified in Governance, Risk and Compliance (CGRC)
Issuing organization: (ISC)Β²
Reputation and global recognition: Highly respected certification for professionals managing system authorization, governance, and regulatory compliance within the Risk Management Framework (RMF). Especially recognized in the U.S. federal government and defense sectors.
π 2. Curriculum and Skills Covered
Covered domains:
Information Security Risk Management Program
Scope of the Information System
Selection and Approval of Security and Privacy Controls
Implementation of Security and Privacy Controls
Assessment/Audit of Security and Privacy Controls
Authorization/Approval of Information System
Continuous Monitoring
Depth of content: Highly theoretical and compliance-focused, covering full lifecycle of NIST RMF and FISMA requirements
Technologies and tools included: Not tool-specific, but exposure to tools like eMASS, XACTA, and automated GRC platforms may be implied
Relevance in the current job market: Crucial for GRC, ISSO, and compliance roles in regulated environments
Mapping to frameworks: NIST SP 800-37, SP 800-53, FISMA, DoD 8140, FedRAMP, NICE Framework (Governance, Risk Management, and Compliance specialty areas)
π§© 3. Prerequisites and Recommended Level
Prior certifications or experience required?: 1 year of cumulative paid experience in one or more of the CGRC domains
Expected skill level: Intermediate to advanced
Required knowledge: Governance models, system authorization processes, regulatory frameworks (e.g., NIST, FISMA), security control selection
π΅ 4. Cost
Total cost: $599 USD (exam only)
Study materials or lab access included?: No; official materials are sold separately
Discounts: Available for (ISC)Β² members, students, and veterans through special programs
β³ 5. Estimated Preparation Time
Recommended study hours: 80β100 hours
Self-paced or instructor-led: Both available
Learning modes: Official self-paced course, instructor-led training, or third-party providers (e.g., InfoSec Institute, Cybrary)
π― 6. Target Roles and Career Path
Job roles: Information Systems Security Officer (ISSO), GRC Analyst, Risk Manager, Security Control Assessor (SCA), Compliance Analyst
Career goals: Perfect for professionals managing system lifecycle authorization and compliance in federal and enterprise systems
Type: Managerial, compliance-focused
π§ͺ 7. Exam Format and Difficulty
Is the exam online or in-person?: In-person at Pearson VUE centers
Theoretical, hands-on, or both?: 100% theoretical
Proctored exam or testing center?: Proctored, computer-based
Length and number of questions: 3 hours, 125 multiple-choice questions
Difficulty level or average pass rate: Moderate; pass rate around 60β70%
π 8. Validity and Renewal
Does it expire?: Yes, valid for 3 years
Renewal process: 60 CPEs over 3 years + annual maintenance fee (~$125 USD/year)
π§° 9. Study Resources Available
Official documentation: (ISC)Β² CGRC Official Study Guide, CBK
Recommended books: NIST SP 800-37, 800-53, RMF Handbook by Stephen D. Gantz
Online labs or platforms: No hands-on labs, but policy and compliance case studies available in training
YouTube channels, community guides: Some walkthroughs available; best supplemented by community forums and study groups
Online communities: (ISC)Β² Community, Reddit r/cybersecurity, LinkedIn GRC groups, Discord study servers
πΌ 10. Industry Value and Demand
Is it frequently mentioned in job postings?: Yes, especially for jobs in federal agencies, DoD contractors, and regulated sectors
Does it boost your profile with recruiters?: Definitely β critical for compliance-focused positions and RMF roles
Is it recognized by top companies or certain countries?: Strongly recognized in the U.S. government, defense, and critical infrastructure sectors
Whatβs the average salary?: $95,000β125,000 USD/year, depending on clearance, region, and responsibilities
π§ 11. Related Certifications and Progression
Is it part of a larger learning path?: Yes β often taken alongside or after Security+, CISM, or CRISC
What can you study after completing it?: CISA, CRISC (for audit/risk), CISSP (for broader leadership path)
How does it compare or complement other certs?: CGRC is more focused on U.S. RMF than CISSP; complements audit-heavy certs like CISA and risk certs like CRISC