CGRC: (ISC)² CGRC
Browse certifications
Exam Resources
Official learning paths, exam details, skills measured, and community resources to supplement your study.
About the CGRC Exam
Master the governance, risk, and compliance lifecycle
The (ISC)² Certified in Governance, Risk and Compliance (CGRC) certification — formerly CAP — validates the ability to integrate governance, risk management, and compliance within an organisation using the NIST Risk Management Framework, FIPS 199/200, and SP 800-53 controls.
Who Should Take This Exam?
The CGRC is designed for IT professionals with some hands-on experience. 6-12 months of hands-on experience recommended.
Typical study time: 4-8 weeks of focused study
Exam Quick Facts
| Detail | Value |
|---|---|
| Exam Code | CGRC |
| Title | (ISC)² CGRC |
| Duration | 180 minutes |
| Questions | 125 |
| Pass Score | 700 / 1000 |
| Cost | $599 USD |
| Provider | Pearson VUE |
| Validity | 3 years (CPE required) |
| Question Types | Multiple choice, Advanced innovative |
Exam Domains & Weights
The CGRC exam covers 7 domains. Focus your study time based on the weights below — higher-weighted domains have more exam questions.
| Domain | Weight | Practice Qs |
|---|---|---|
| Security and Privacy Governance, Risk Management, and Compliance Program | 16% | 40 |
| Scope of the System | 10% | 27 |
| Selection and Approval of Framework, Security, and Privacy Controls | 14% | 35 |
| Implementation of Security and Privacy Controls | 17% | 41 |
| Assessment/Audit of Security and Privacy Controls | 16% | 39 |
| System Compliance | 14% | 35 |
| Compliance Maintenance | 13% | 33 |
| Total | 100% | 250 |
💡 Study tip: Implementation of Security and Privacy Controls carries the most weight (17%) — start there. Scope of the System has the least (10%), but don’t skip it — exam questions can come from any domain.
Practice Exam — 250 Questions
Prepare for the CGRC with our 250-question practice exam covering all 7 exam domains. Every question includes detailed explanations and maps to official exam objectives.
What you get:
- ✅ Exam simulation mode with timer
- ✅ Spaced repetition for weak areas
- ✅ Detailed explanations for every question
- ✅ Progress tracking across domains
- ✅ 20 free questions — no account needed
ISC² Certification Path
Start with CC (Certified in Cybersecurity) for entry-level, then SSCP for technical security, then CISSP for management. CISSP concentrations (ISSAP, ISSEP, ISSMP) come after CISSP.
Related ISC² Certifications
If you’re studying for the CGRC, you might also be interested in these ISC² certifications:
- CC: (ISC)² Certified in Cybersecurity — 250 practice questions
- CCSP: (ISC)² CCSP — 250 practice questions
- CISSP-ISSAP: (ISC)² CISSP-ISSAP — 250 practice questions
- CISSP-ISSEP: (ISC)² CISSP-ISSEP — 250 practice questions
- CISSP-ISSMP: (ISC)² CISSP-ISSMP — 250 practice questions
Study Tips
- Start with the heaviest domain — focus your time where the exam focuses its questions
- Use our practice exam — try the 20 free questions first to gauge your readiness
- Review explanations — don’t just check if you got it right; read why each answer is correct
- Simulate exam conditions — use the timed exam mode to practice under pressure
Frequently asked questions
The CGRC questions I hear most often — usually ‘is this still the CAP cert?’ and ‘do I need a GRC role to take it?’