If the ISC2 Certified in Cybersecurity (CC) exam is your way into the field, there is a date you need on your radar. ISC2 states plainly that "effective September 1, 2026, the CC exam will be based on a new exam outline." That is about four weeks away. The CC is the entry-level credential that requires no work experience, so it draws a lot of first-time candidates, and first-time candidates are exactly the ones most likely to be studying from materials that are about to fall out of date. Here is what is confirmed, what to double-check, and how to prepare for the exam as it stands.
What the CC is, and what is changing
The CC is ISC2's foundational cybersecurity certification. Its selling point is accessibility: it is entry-level and requires no prior work experience, which makes it a common first step for career changers, students and IT staff moving towards security.
An exam outline is the syllabus: the domains covered and how heavily each is weighted. A new outline does not rewrite the subject, but it refreshes the tasks and knowledge beneath each domain and can shift the emphasis between them. That is enough to matter when you are deciding where to spend your revision time.
The CC continues to be built on five domains:
- Security Principles
- Business Continuity, Disaster Recovery and Incident Response Concepts
- Access Controls Concepts
- Network Security
- Security Operations
The domain names carry over, so the shape of the exam stays familiar. What can move under a new outline is the weighting of each domain and the detail within it.
The one thing to verify before you sit it
Here is the honest caveat, and it is the same trap that catches people on every outline change. ISC2 publishes weightings for the CC, and at the time of writing they read: Security Principles 26 per cent, Access Controls 22 per cent, Network Security 24 per cent, Security Operations 18 per cent, and Business Continuity, Disaster Recovery and Incident Response 10 per cent. Those are the figures currently shown. What is not yet clear is whether the 1 September outline keeps them exactly or adjusts them.
So do this before you rely on any percentage, including the ones above: open the current CC exam outline directly on the ISC2 site and study to that document for your exam date. Any blog quoting confident new weightings today is either repeating the current numbers or guessing. Study to the source.
The exam format you are preparing for
Format and outline are different things. ISC2's published format for the CC is:
- Computerized Adaptive Testing (CAT)
- 100 to 125 items, multiple choice and advanced item types
- 2 hours
- Passing score of 700 out of 1000 points
The word to sit up at is adaptive. In a CAT exam the questions adjust to your performance as you go, and you cannot flag a question and return to it later. For an entry-level candidate that has three practical consequences: you must commit to each answer and move on, your early answers help calibrate the difficulty you then face, and there is no end-of-paper review to fall back on. Rehearsing under those conditions matters as much as knowing the content.
A note on cost
ISC2 has, through its wider pledge to expand the cybersecurity workforce, previously offered the CC exam and self-paced training free of charge to a large number of candidates. Whether that offer is still open, and on what terms, changes over time, so check current availability on the ISC2 site rather than assuming. It is worth two minutes before you pay.
How to prepare from here
- Study to the live outline, verified today. Confirm the current domain weightings on ISC2's page and weight your revision to match. Do not trust a cached percentage.
- Rehearse the adaptive format, not just the facts. Full, timed practice where you commit and move on builds the decision discipline CAT demands, which is often what trips up first-time candidates rather than the content itself.
- Give Network Security and Access Controls their due. On the current weightings they are among the heaviest domains; Security Operations rewards understanding processes over rote definitions.
- Check the date on every resource. A guide written before 1 September 2026 is not worthless, but its emphasis may be slightly off. Confirm it against the current outline.
Practice under real exam conditions
Because the CC is adaptive and gives you no second pass at a question, the quality of your practice is what turns nervous knowledge into a confident pass. Full, timed mock exams that force a decision on every item train the exact behavior the format requires, and scoring by domain shows you which of the five areas is costing you marks before it matters. Candidates Prep's simulator runs timed, domain-scored practice so you can rehearse the format as well as the content, and trainers running entry-level cybersecurity cohorts can see readiness across a whole group.
The bottom line
The CC's structure is stable: five domains, an adaptive format, a 700-out-of-1000 bar, and no experience required to sit it. What changes on 1 September 2026 is the outline beneath it. The single smartest thing you can do is study to ISC2's current published outline rather than any second-hand summary, rehearse the adaptive format, and treat the change as a detail to manage rather than a reason to worry.
Starting out in cybersecurity, or training a cohort? Rehearse under timed, adaptive-style conditions, or book a demo to see domain-level analytics for your group.



