ISC2 CC Study Plan: 30, 60, and 90 Days

ISC2 CC 30-, 60-, and 90-day study plan with topic order, review loops, and final-week priorities.

Current exam scope checkpoint

As of May 24, 2026, ISC2 lists the current CC outline as effective October 1, 2025. ISC2 also notes that a new CC outline becomes effective September 1, 2026, so verify the resources page before scheduling an exam close to that date.

Current domain weights:

Domain Weight
Security Principles 26%
Business Continuity, Disaster Recovery, and Incident Response Concepts 10%
Access Controls Concepts 22%
Network Security 24%
Security Operations 18%

Thirty-day route

Phase Days Focus Output
Foundation 1-5 Security Principles one-page CIA, risk, control, ethics, and governance rule sheet
Response and resilience 6-8 BC, DR, and Incident Response sequence notes for BIA, BCP, DRP, RTO/RPO, and incident phases
Access control 9-13 Access Controls physical/logical access comparison table
Network security 14-20 Network Security attack-to-control map for DDoS, malware, MITM, IDS/IPS, segmentation, VPN, NAC, and cloud models
Operations 21-25 Security Operations data handling, hardening, policy, logging, and awareness checklist
Mixed review 26-30 Cheat Sheet, Sample Questions, Glossary miss log with tested domain, wrong-answer reason, and corrected rule

Seven-day route

Day Focus What to do
Day 1 Orientation and current scope Read the exam root and official outline. Note CAT format, current weights, and the September 1, 2026 outline-change notice.
Day 2 Security principles Study CIA, authentication, non-repudiation, privacy, risk, controls, ethics, and governance.
Day 3 BC, DR, and incident response Learn the difference between BIA, BCP, DRP, RTO, RPO, and incident-response sequence.
Day 4 Access controls Separate physical access, logical access, least privilege, separation of duties, DAC, MAC, RBAC, MFA, and lifecycle management.
Day 5 Network security Review OSI/TCP/IP basics, ports, DDoS, malware, MITM, IDS/IPS, firewalls, segmentation, VPN, NAC, cloud, and hybrid concepts.
Day 6 Security operations Study data handling, encryption, hashing, logging, hardening, patching, policies, awareness, and safe AI-tool behavior.
Day 7 Mixed review and scheduling decision Run a timed practice block, review explanations, update a one-page rule sheet, and verify current ISC2 facts before scheduling.

If you only have 48 hours

  1. Read the cheat sheet twice: once before practice and once after reviewing misses.
  2. Drill one mixed block and write a one-line reason for every wrong answer.
  3. Spend the next block only on your weakest two lanes.
  4. Recheck the current official vendor page before scheduling or buying an exam attempt.

Readiness signals

  • You can explain why each wrong answer fails the stem constraint.
  • You can map each scenario to one of the five current ISC2 domains without looking at notes.
  • You can state the verification evidence you would expect after the chosen action.
  • You have checked the current official exam page for live status and requirements.
Revised on Monday, June 15, 2026