Hands organizing papers on a desk

Is the ISC2 Certified in Cybersecurity (CC) Worth It? An Honest Look at the Free Cert

The short answer changed in 2026. The ISC2 Certified in Cybersecurity was worth taking when it was free, and the free window is closed. ISC2 stopped new enrollments in the One Million Certified in Cybersecurity program on 20 May 2026 after it passed the one million mark, and people who already hold a free exam code have until 31 December 2026 to sit. After that the CC is a $199 exam with a $50 annual maintenance fee. At $199 it is a harder recommendation, because CC and Security+ are not competing for the same slot on a resume and only one of them opens DoD doors on its own. The CC still has real uses. They are narrower than the internet suggests.

What Happened to the Free Program

ISC2 launched One Million Certified in Cybersecurity as a workforce development pledge, bundling free self-paced training with a free exam attempt. It ran for roughly three years and hit its target, which ISC2 announced in April 2026. New enrollments closed 20 May 2026. If you enrolled before that date, your coursework remains accessible until it expires and your exam code is valid through 31 December 2026. Expired codes are not being reactivated and no new free seats are being issued.

So there are two audiences reading this. If you have a code sitting in your ISC2 account, stop reading and go schedule the exam, because a free certification you did not claim is the cheapest regret available. If you do not have a code, keep reading, because the math is different at $199.

What the CC Exam Actually Is

The CC is an entry-level exam with no work experience requirement, which is its whole point. ISC2 positions it as the on-ramp to the associate track, and it is approved by the Department of Defense under DoDM 8140.03.

  • Format: 100 multiple-choice questions in a two-hour window. You cannot go back and review a question once you answer it.
  • Passing score: 700 out of 1000 on a scaled scoring system.
  • Domains: Security Principles at 26 percent, Network Security at 24 percent, Access Controls Concepts at 22 percent, Security Operations at 18 percent, and Business Continuity, Disaster Recovery and Incident Response at 10 percent.
  • Cost as of 2026: $199 per attempt, plus a $50 annual maintenance fee once you are certified.
  • Maintenance: 45 CPE credits across a three-year cycle, plus the annual fee.

Difficulty is genuinely low relative to Security+. The CC tests vocabulary and concepts. It does not ask you to reason through a scenario with four defensible answers. Two to four weeks of evening study is a realistic timeline for someone with no background, and a week for someone who has already studied Security+ material.

The Honest Case For It

  • It is the cheapest ISC2 credential, and it puts you in the ISC2 membership system. If your five-year plan ends at CISSP, you learn the portal, the CPE tracker, and the AMF cycle on a low-stakes credential instead of a high-stakes one.
  • It has DoD 8140 recognition, which matters if you are trying to get past an automated qualification screen on a contract requirement.
  • No experience requirement and no work verification. Nothing to endorse, nothing to wait on.
  • It is a legitimate answer to “what have you done in the last three months” for someone changing careers, and it demonstrates you can sit and pass a proctored exam.
  • The domain list is a serviceable map of foundational security vocabulary, which makes it a decent structured first pass before harder material.

The Honest Case Against It

  • At $199 plus $50 a year, the three-year cost of holding it is around $349. Security+ costs roughly $439 for the voucher as of 2026 and unlocks far more job requisitions.
  • Very few job postings name the CC as a requirement. It is recognized, not demanded.
  • The $50 annual maintenance fee never stops, and 45 CPEs over three years is real administrative work for a credential you will likely outgrow within 18 months.
  • It teaches nothing a decent Security+ course does not also teach, in more depth, on an exam employers actually screen for.
  • Free certifications get discounted by whoever reads the resume. That is not fair and it is not defensible, but I have watched it happen to my own applications, and the CC carried the free label for three years.

The bigger risk is the one nobody names: collecting entry certs feels like progress and is not. Two certificates and no lab, no project, and no story about what you built will lose to one certificate and a documented home lab every time.

CC Compared to the Other Entry Options

Against Security+, this is not close for anyone aiming at DoD or cleared work. Security+ satisfies more 8140 work roles, appears in vastly more requisitions, and is the cert that hiring systems filter on. If you can only afford one exam this year, buy the Security+ voucher and work a structured plan like the eight-week Security+ schedule rather than warming up with the CC.

Against the Google Cybersecurity Certificate, the comparison is closer and the two do different jobs. The Google program is a training course with a completion credential; the CC is a proctored exam from an accredited body. I wrote a longer take on whether the Google certificate is worth it and the same conclusion applies here: the credential is worth what the work behind it was worth.

Against doing nothing while you wait for a clearance sponsor, the CC wins. Momentum has value, and a proctored pass on the record beats three months of intending to study.

If you want the full ranking against everything else in the entry tier, the breakdown of entry-level certifications ranked by job demand rather than hype puts the CC where it belongs relative to Security+, Network+, and the vendor options.

Who Should Actually Buy It at $199

Four situations make the CC a reasonable purchase.

  1. You already hold Security+ and you want an ISC2 credential on the record while you build toward CISSP. The CC gets you into ISC2 membership and starts the CPE habit early.
  2. Your employer or a workforce program is paying, in which case the cost objection disappears entirely and the only question is time.
  3. You are in a non-security role inside a cleared organization, such as help desk or system administration, and you need a defensible signal that you are moving toward security work. The CC is fast enough not to interfere with the day job.
  4. You have a free exam code from the One Million program and it expires 31 December 2026. Sit the exam.

Everyone else should skip it and put the $199 toward a Security+ voucher, a year of lab hosting, or an exam retake fund. And if the actual goal is a first cleared security seat rather than a longer cert list, the path there runs through targeted applications and a portfolio, which is what the guide to getting your first ISSO job without a clearance or experience is built around.

If You Do Take It, Pass It Fast

There is no reason to spend two months on the CC. The exam rewards breadth over depth, so the efficient approach is to cover all five domains lightly and then drill questions until the vocabulary is automatic.

Use the ISC2 self-paced course if you have access to it, since it is written to the exact objectives. Otherwise any Security+ foundations course covers the same ground with room to spare. Spend the bulk of your time in a question bank, and pay attention to the two domains that carry nearly half the weight together: Security Principles at 26 percent and Network Security at 24 percent. Business continuity, disaster recovery, and incident response is only 10 percent, so a shallow pass over that material is a rational allocation.

Remember the exam mechanics. You cannot revisit a question once you answer it, so there is no flag-and-return strategy. Read carefully the first time, commit, and move on. Two hours for 100 questions is roughly 72 seconds each, which is comfortable if you are not second-guessing.

The Verdict

The ISC2 CC was an easy yes at zero dollars and it is a conditional yes at $199. It is a real, accredited, DoD-recognized credential that proves foundational vocabulary and nothing more. It will not get you hired by itself. It will not substitute for Security+. It will make sense if you are already inside a cleared organization, already hold Security+, or have somebody else paying.

What it will not do is fix the part of the job hunt that is actually broken, which is almost never the certification list. The candidates who stall out have the certs and no way to talk about them. If that is where you are, Zero to Hired is the system I put together for turning a cert stack into interviews, and it starts with the resume and the story rather than the next exam voucher.

Babux, active DoD ISSO and author of RMF Insider

From a working DoD ISSO

Trying to break into cybersecurity?

Zero to Hired is the week-by-week 6-month plan I give people who ask me how to get their first cyber job. Already in the field? The RMF Checklist is the tool I use on real ATO packages.


Get the free RMF Quick Reference

All 7 RMF steps on one page — free when you subscribe to the weekly ISSO Insider.

Leave a Reply

Discover more from RMFInsider

Subscribe now to keep reading and get access to the full archive.

Continue reading