ISC2 CC 30-, 60-, and 90-day study plan with topic order, review loops, and final-week priorities.
As of May 24, 2026, ISC2 lists the current CC outline as effective October 1, 2025. ISC2 also notes that a new CC outline becomes effective September 1, 2026, so verify the resources page before scheduling an exam close to that date.
Current domain weights:
| Domain | Weight |
|---|---|
| Security Principles | 26% |
| Business Continuity, Disaster Recovery, and Incident Response Concepts | 10% |
| Access Controls Concepts | 22% |
| Network Security | 24% |
| Security Operations | 18% |
| Phase | Days | Focus | Output |
|---|---|---|---|
| Foundation | 1-5 | Security Principles | one-page CIA, risk, control, ethics, and governance rule sheet |
| Response and resilience | 6-8 | BC, DR, and Incident Response | sequence notes for BIA, BCP, DRP, RTO/RPO, and incident phases |
| Access control | 9-13 | Access Controls | physical/logical access comparison table |
| Network security | 14-20 | Network Security | attack-to-control map for DDoS, malware, MITM, IDS/IPS, segmentation, VPN, NAC, and cloud models |
| Operations | 21-25 | Security Operations | data handling, hardening, policy, logging, and awareness checklist |
| Mixed review | 26-30 | Cheat Sheet, Sample Questions, Glossary | miss log with tested domain, wrong-answer reason, and corrected rule |
| Day | Focus | What to do |
|---|---|---|
| Day 1 | Orientation and current scope | Read the exam root and official outline. Note CAT format, current weights, and the September 1, 2026 outline-change notice. |
| Day 2 | Security principles | Study CIA, authentication, non-repudiation, privacy, risk, controls, ethics, and governance. |
| Day 3 | BC, DR, and incident response | Learn the difference between BIA, BCP, DRP, RTO, RPO, and incident-response sequence. |
| Day 4 | Access controls | Separate physical access, logical access, least privilege, separation of duties, DAC, MAC, RBAC, MFA, and lifecycle management. |
| Day 5 | Network security | Review OSI/TCP/IP basics, ports, DDoS, malware, MITM, IDS/IPS, firewalls, segmentation, VPN, NAC, cloud, and hybrid concepts. |
| Day 6 | Security operations | Study data handling, encryption, hashing, logging, hardening, patching, policies, awareness, and safe AI-tool behavior. |
| Day 7 | Mixed review and scheduling decision | Run a timed practice block, review explanations, update a one-page rule sheet, and verify current ISC2 facts before scheduling. |