If you work in a federal or DoD environment and your job involves security packages, control assessments, or getting systems authorized, you have probably run into the CGRC certification. It sits in an unusual spot in the certification landscape. It is not a hands-on technical credential, it is not a management credential in the way CISM is, and it is not the broad survey that CISSP has become. It is something narrower and, for the right person, considerably more useful.
Here is what CGRC actually covers, what the exam looks like, and who should seriously consider it.
What CGRC Is
CGRC stands for Certified in Governance, Risk and Compliance. It is issued by ISC2, the same organization behind CISSP. If the name does not ring a bell, the old one probably does: until 2023 this certification was called CAP, the Certified Authorization Professional.
That history matters. CAP was built almost entirely around the NIST Risk Management Framework. It was, in practical terms, the “I know how to get a system authorized” certification. When ISC2 rebranded it to CGRC and refreshed the exam outline, the stated goal was to widen the appeal beyond federal authorization work and speak to governance, risk, and compliance professionals generally.
The rebrand changed the packaging more than the contents. Look at the seven domains and the RMF lifecycle is still sitting right there in the middle of them. If you already understand RMF, you are most of the way to understanding what CGRC tests.
It remains a comparatively small credential. ISC2 announced in early 2026 that CGRC had crossed 5,000 holders worldwide. For context, CISSP has well over 150,000. That scarcity cuts both ways, and I will come back to it.
The Seven Domains
The current exam outline covers seven domains, and the sequence tracks the life of a system from cradle to disposal:
Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program. The organizational layer. Policy, roles, risk tolerance, and how a GRC program is stood up and run.
Domain 2: Scope of the System. Defining the system boundary and categorizing it based on the information it holds and the impact of losing that information. This maps to RMF Prepare and Categorize.
Domain 3: Selection and Approval of Framework, Security, and Privacy Controls. Choosing the control baseline, tailoring it, and documenting the selection. RMF Step 2.
Domain 4: Implementation of Security and Privacy Controls. Putting controls in place and, just as importantly, documenting the implementation so an assessor can follow it. RMF Step 3.
Domain 5: Assessment and Audit of Security and Privacy Controls. Building the assessment plan, executing it, and documenting findings and residual risk. RMF Step 4.
Domain 6: System Compliance. The authorization decision. Risk posture, remediation, and the security package itself. RMF Step 5.
Domain 7: Compliance Maintenance. Continuous monitoring through the operational life of the system and into disposal. RMF Step 6.
If that reads like a description of an RMF course, it is because the overlap is close to total for domains 2 through 7. Our RMF for DoD IT curriculum walks the same lifecycle, which is why students who have been through it tend to find the CGRC exam outline familiar rather than foreign.
Exam Format and Requirements
The exam is 125 multiple choice questions delivered over 180 minutes. Roughly 100 of those are scored and the remainder are unscored pretest items that ISC2 uses to validate future questions. You will not know which is which. The passing score is 700 out of 1000 on a scaled scoring model, and the registration fee is $599 in the United States.
The experience requirement is two years of cumulative, paid work experience in one or more of the seven domains. Part-time work and qualifying internships can count on a prorated basis. If you pass the exam without the experience, ISC2 lets you become an Associate of ISC2 and gives you three years to earn it.
After certification you maintain the credential with continuing professional education credits on a three year cycle, plus an annual maintenance fee to ISC2. Endorsement by an existing ISC2 member is also part of the process, as it is with CISSP.
Who Should Pursue It
ISSOs and ISSMs. If your day is spent maintaining POA&Ms, feeding eMASS, tracking control compliance, and shepherding packages toward an ATO, CGRC is closer to your actual job than almost any other certification on the market. It validates exactly what you do.
Security control assessors and validators. Domains 5 and 6 are your workday. A credential that maps to the assessment and authorization process is easier to defend on a resume than a general security cert.
Contractors supporting federal A&A work. Contract requirements increasingly name specific certifications, and under DoD 8140 the GRC-flavored work roles frequently list CGRC alongside options like CISA. If you are competing for that work, having it is a differentiator precisely because so few people hold it.
Career changers moving from technical to compliance roles. If you have a technical foundation from something like Security+ or CISSP and want to move toward policy and authorization work, CGRC is a credible signal of that pivot.
Who Should Probably Skip It
If you work in the private sector outside regulated industries, the return is thin. CGRC’s vocabulary is federal, and hiring managers at a commercial software company are unlikely to recognize it. CISA travels better in audit-heavy commercial environments, and CISM travels better if you are heading toward security management.
If you are early in your career and do not yet have a baseline certification, start with Security+ instead. It is the more common contract requirement and the more common HR filter.
And if you are a hands-on defender or engineer, this is not your certification. Look at CySA+ or PenTest+ instead. CGRC will not teach you to detect anything.
The Practical Preparation Path
Because CGRC is small, the third-party study material for it is thin compared to CISSP. The most reliable preparation is not a CGRC-branded bootcamp but genuine depth in the RMF lifecycle plus the NIST publications that underpin it: SP 800-37 for the framework, SP 800-53 for the control catalog, and SP 800-53A for assessment procedures.
That is why many candidates take an RMF course before sitting for the exam. You are not buying exam questions, you are building the working knowledge the exam is testing.
How IT Dojo Can Help
If you need training in RMF and the governance, risk, and compliance work that CGRC covers, IT Dojo can help. Our RMF for DoD Information Technology course walks the full authorization lifecycle that makes up the bulk of the CGRC exam outline, including how DISA STIGs map to security controls and how continuous monitoring keeps a package current after the ATO. You can see the full lineup on our RMF training page.
All IT Dojo courses are live remote online with real instructors and small class sizes, so you can attend from anywhere. Training is employer sponsored, for federal agencies, DoD commands, the contractors that support them, and corporate clients.
Contact IT Dojo to talk through which courses fit your team’s certification goals and upcoming authorization work.