Certified Authorization Professional Exam Guide: Understanding the Current CGRC Credential
The former Certified Authorization Professional (CAP) exam is now the ISC2 Certified in Governance, Risk and Compliance (CGRC) examination. It validates an information-security practitioner’s ability to advocate security risk management for system authorization while meeting legal and regulatory requirements. This guide helps GRC, audit, compliance, risk, and system-security professionals decide whether the current credential matches their experience, build a domain-based study plan, and organize the application steps before booking an exam.
Start with the correct credential name
Candidates looking for the Certified Authorization Professional should prepare for CGRC, the current name of the ISC2 credential. ISC2 renamed CAP to Certified in Governance, Risk and Compliance (CGRC) effective February 15, 2023; it stated that the change affected the certification name, not the exam, course content, or qualifications.
paragraphs
What CGRC is designed to validate
CGRC focuses on applying governance, risk management, security, privacy, and compliance work to support information-system authorization and organizational operations. It is not simply a vocabulary test about regulations or a narrow technical-security exam.
ISC2 describes a CGRC holder as an information-security practitioner who advocates for security risk management in pursuit of information system authorization in accordance with legal and regulatory requirements. In practical terms, the candidate needs to connect organizational objectives, risks, controls, evidence, and decisions rather than treat each as an isolated compliance exercise.
This emphasis is useful for professionals whose work involves translating expectations into operating controls and defensible records. An ISC2 discussion of GRC implementation found that “translating frameworks into operational controls” was the leading practical problem for 33% of respondents. That gap is a useful study signal: do not stop at naming a framework or control family; practice explaining what the requirement means for system scope, ownership, implementation, assessment evidence, and ongoing maintenance.
Who should consider the exam
CGRC is most relevant when your role requires you to make, document, assess, coordinate, or maintain security and privacy risk decisions across a system lifecycle. ISC2 identifies roles including cybersecurity auditor, cybersecurity compliance officer, GRC architect or manager, cybersecurity risk and compliance project manager or analyst, third-party or enterprise risk manager, GRC analyst or director, system security manager or officer, and information assurance manager.
A candidate with hands-on technical responsibilities can still find the credential relevant if they routinely turn technical conditions into risk statements, control evidence, remediation plans, or authorization inputs. Conversely, someone seeking a credential focused mainly on engineering configuration may find that the governance and authorization orientation is not their immediate priority.
Know the seven areas the exam measures
The current CGRC outline organizes competency into seven domains spanning the lifecycle from program governance through maintaining compliance. Use those domains as the structure for every study resource, note set, and practice review.
ISC2 lists these domains: Security and Privacy Governance, Risk Management, and Compliance Program; Scope of the System; Selection and Approval of Framework, Security, and Privacy Controls; Implementation of Security and Privacy Controls; Assessment/Audit of Security and Privacy Controls; System Compliance; and Compliance Maintenance.
The supplied official material does not provide the individual domain weights. Do not assume that the order of the domains indicates exam emphasis, and do not build a schedule around unofficial weight charts. Download and review the current official outline before deciding how to allocate your time.
Treat the domains as one connected workflow
A strong way to retain the material is to follow one hypothetical system through the seven domains. Begin with governance, risk appetite, responsibilities, and compliance obligations. Define what belongs inside the system boundary. Select and approve applicable frameworks and controls, then implement them. Assess whether implementation is operating as intended, assemble the information needed for compliance and authorization decisions, and maintain the result as the system changes.
This workflow prevents a frequent mistake: studying controls as a list while ignoring the decisions that make controls relevant. For every topic, ask five questions: What is the system or process? Who owns the decision? What risk or requirement is being addressed? What evidence would support the conclusion? What change would require reassessment or maintenance?
Account for AI-related updates without losing the fundamentals
The current outline adds AI governance considerations across the lifecycle, so candidates should be ready to apply familiar GRC reasoning to intelligent systems and their data pipelines. This is a context for the domains, not a reason to abandon core governance, scoping, control, assessment, authorization, and maintenance concepts.
ISC2 says Domain 1 addresses dedicated oversight boards for algorithmic transparency and the ethical use of autonomous agents. For preparation, connect governance to concrete decisions: who has authority, what information informs that authority, how accountability is recorded, and how an organization handles ethical and privacy concerns.
In Domain 2, the outline expands traditional scoping to account for modern machine-learning data pipelines and requires identification of embedded algorithms, including algorithms within commercial off-the-shelf software. Practice drawing a boundary that includes data sources, dependencies, integrations, third-party components, and the information flow that affects the system’s risk posture.
Domain 3 addresses selecting specialized overlays, such as the CSA AI Controls Matrix, alongside traditional framework baselines. Domain 4 addresses deployment of AI-native security controls in distributed machine-learning pipelines. Do not try to memorize framework names in isolation; focus on the decision logic for selecting controls that fit a system’s purpose, risks, architecture, privacy obligations, and implementation environment.
Domain 5 addresses AI-powered audit tools that correlate compliance evidence across cloud environments. Domain 6 covers formal risk acceptance criteria for generative-AI uncertainty and the use of AI governance tools to automate generation and submission of large authorization packages such as System Security Plans (SSPs). Domain 7 addresses AI-driven continuous control monitoring for the rapid MLOps change lifecycle. In each case, study the evidence, oversight, and change-management implications alongside the technology.
Use the official exam facts to plan your sitting
ISC2 lists the CGRC examination as 3 hours with 125 items, including multiple-choice and advanced item types. The passing score is 700 out of 1,000 points, the available exam language is English, and ISC2 lists Pearson VUE Testing Centers as the testing-center option.
Those facts should shape rehearsal. Build comfort reading a scenario, locating the decision point, distinguishing a current condition from a desired outcome, and selecting the response that best supports risk management and authorization. A question bank can help reveal weak areas, but it cannot substitute for understanding why an action is appropriate in the lifecycle.
Schedule only after confirming the current official outline and reviewing ISC2 examination policies and procedures. Allow time before the appointment to verify identification, location, travel, and any official testing requirements directly with ISC2 and the testing provider. This guide does not establish those operational requirements because they can change.
Practice for advanced item types deliberately
Advanced item types reward careful interpretation, not rushed pattern matching. During practice, write a one-sentence rationale before checking an answer: identify the stakeholder decision, the relevant domain, the missing evidence or action, and why the other options would be premature, incomplete, or out of sequence.
Keep an error log with categories rather than only scores. For example, label misses as scope failure, unclear ownership, flawed control selection, inadequate evidence, incorrect authorization logic, or maintenance oversight. Review the category trend every few study sessions. This produces a targeted revision list instead of repeatedly retaking the same questions.
Confirm that your experience can support certification
Passing the exam is only part of the route to CGRC. ISC2 requires at least two years of cumulative full-time experience in one or more domains of the current CGRC Exam Outline, with qualifying work tied to information-system authorization or requiring direct application of security risk-management knowledge.
Map your experience before you register. Create a private record with employer, role, dates, hours where applicable, project or system context, duties, and the CGRC domain or domains demonstrated. Use precise work examples such as defining a boundary, supporting a control decision, collecting assessment evidence, maintaining a compliance record, or managing risk documentation. The purpose is accurate application preparation, not retrofitting job titles to the credential.
ISC2 says full-time experience accrues monthly when the candidate works at least 35 hours per week for four weeks. Eligible part-time work is 20 to 34 hours per week. ISC2 also states that 1040 hours of part-time work equals 6 months of full-time experience and that 2080 hours of part-time work equals 12 months of full-time experience. Paid or unpaid internships may be accepted with the required documentation.
Candidates who pass without the required experience may become Associates of ISC2 and then have three years to obtain the required two years of relevant experience. That option can make sense for an early-career candidate with a credible plan to gain domain-aligned responsibilities, but it should not replace an honest review of whether the work path is realistic.
Plan endorsement and application evidence early
For non-CC ISC2 certifications, applicants must provide an ISC2-certified professional in good standing to attest to their experience, or choose ISC2 endorsement and provide proof of employment. Identify the route and gather records before exam day rather than treating the application as an afterthought.
ISC2 requires all credential exam passers to complete the certification application process within nine months of the exam date. ISC2 also notes that a percentage of submitted applications is selected for audit and may require additional information. Keep role descriptions, employment documentation, internship documents, and a clear domain mapping organized and accurate.
ISC2 states that a qualifying post-secondary degree in computer science, information technology, or a related field, or a credential from its approved list, may satisfy up to one year of required experience. Only one year may be waived through education or certification. Confirm eligibility against the official application information rather than assuming that any degree or certification will apply.
Build a study plan around decisions, evidence, and change
A practical CGRC plan starts with a baseline assessment against all seven domains, then concentrates study on weak decision points rather than on passive reading. The goal is to explain how governance and risk work moves from requirement to control to evidence to an informed authorization or compliance decision.
First, obtain the current English CGRC Exam Outline and list every task or topic under its domain. Mark each item as confident, partial, or unfamiliar. For partial and unfamiliar items, identify the gap: terminology, process order, stakeholder responsibility, evidence, control rationale, or maintenance activity. This diagnosis determines what to study next.
Second, build a lifecycle notebook. Give each domain a page with four recurring fields: purpose, participants, inputs, and outputs. Add a fifth field for change triggers. A compact structure makes it easier to see that scope affects control selection, implementation produces evidence, assessment informs compliance decisions, and maintenance responds to system or environment changes.
Third, use scenario exercises. Choose a system such as a customer portal, shared cloud service, analytics platform, or AI-enabled internal workflow. Describe its purpose, information handled, stakeholders, dependencies, relevant risks, controls, evidence, and a proposed change. Then walk through what each domain requires. The system does not need to mirror your employer; it only needs enough detail to force connected reasoning.
A practical sequence for the seven domains
Begin with Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program. Establish the organizational purpose, responsibility structure, decision authority, risk-management approach, and compliance context. This is the foundation for interpreting later scenarios.
Move to Domain 2: Scope of the System before studying controls in depth. Practice identifying boundaries, interfaces, assets, data paths, people, services, suppliers, and dependencies. A poorly scoped system produces unreliable control decisions and incomplete evidence.
Then study Domain 3: Selection and Approval of Framework, Security, and Privacy Controls, followed by Domain 4: Implementation of Security and Privacy Controls. Work from applicable requirements and risk to an appropriate control approach, then to implemented measures and implementation evidence. Do not confuse a proposed control with proof that it operates.
Continue with Domain 5: Assessment/Audit of Security and Privacy Controls and Domain 6: System Compliance. Focus on how assessment results, deficiencies, evidence, risk decisions, and authorization-related material support a credible compliance position. This is where candidates should be especially alert to the difference between observing, testing, documenting, accepting risk, and approving a decision.
Finish the first pass with Domain 7: Compliance Maintenance. Revisit every earlier domain through the lens of change. A control environment is not static: changes to systems, data, dependencies, processes, threats, or obligations can require renewed scope analysis, assessment, evidence collection, or decision-making.
Use a realistic weekly rhythm
A useful study rhythm alternates learning, application, and review. Avoid spending every session consuming material and postponing questions until the end. Regular retrieval and scenario reasoning reveal gaps earlier and make revision more efficient.
In an early phase, work through the official outline and lifecycle notebook, using official supplementary references where they address a specific gap. ISC2 encourages candidates to supplement education and experience by reviewing relevant resources and identifying areas that need more attention. Keep notes in your own words; copied definitions are harder to use in a scenario.
In a middle phase, pair two connected domains in each review cycle: scope with control selection, implementation with assessment, and system compliance with compliance maintenance. For each pair, create a short scenario and identify the appropriate output of each stage. This exposes sequencing errors that single-domain flashcards often miss.
In a final phase, complete timed mixed practice and use the error log to choose review topics. Revisit core concepts after every practice set, including areas you answered correctly by guesswork. Reserve the last review sessions for official outline alignment, weak-domain remediation, and exam-day logistics—not for adding a large new resource.
Avoid preparation mistakes that distort your results
The most costly mistakes are usually process mistakes: learning isolated definitions, treating every control as universally applicable, skipping system scope, and ignoring the ongoing maintenance work that follows an authorization or compliance decision. Correct them with structured scenario practice.
Do not rely on recalled or purported live exam content. It creates an unreliable picture of readiness and does not build the judgment needed for multiple-choice and advanced item types. Use legitimate practice materials as diagnostic tools, then verify concepts against the current official outline and relevant references.
Do not let an attractive score on one practice set decide your readiness. Check whether you can articulate the rationale without options in front of you. If you cannot explain what evidence is needed, who makes the decision, or what comes before and after an action, the underlying concept still needs work.
Another common error is treating compliance as a one-time documentation event. The outline’s Compliance Maintenance domain makes ongoing change and continued alignment part of the competency model. Whenever you study a control or assessment result, ask what would cause it to be revisited.
Finally, do not wait until after passing to examine your experience record and endorsement route. Candidates often know they have relevant work but struggle to describe it against the seven domains. A concise evidence map built in advance reduces avoidable application pressure.
Make the registration decision with a short readiness check
Register when you can explain the full CGRC lifecycle, apply it to unfamiliar scenarios, perform consistently under time constraints, and have a credible plan for the certification application. Registration should follow evidence of readiness, not replace it.
Before booking, confirm that you are preparing from the current outline, which ISC2 identifies as effective June 15, 2024. Review the official examination policies and procedures, confirm the listed testing-center option, and check the current scheduling details directly with ISC2 or Pearson VUE.
Before the exam, complete three final checks. First, explain all seven domains without notes and describe how the outputs of one domain inform another. Second, review your error log and address the recurring cause, not only the individual question. Third, organize your experience and endorsement information so that a successful result can move promptly into the application process.
After passing, ISC2 states that you must complete the certification application process within nine months of the exam date. Once the application is approved, ISC2 states that the final membership step is payment of the first Annual Maintenance Fee. Verify the current process and requirements on ISC2’s official pages when you reach that stage.
Conclusion
The CAP name remains useful when searching legacy material, but the current ISC2 credential and exam are CGRC. Prepare around the seven-domain lifecycle, not disconnected control terminology; validate your readiness with scenario-based practice; and document experience and endorsement evidence before the exam. The official outline, experience requirements, and application rules should be the final authority for both study scope and certification decisions.
Related exams
- Certified Information Systems Security Professional (CISSP)
- HCISPP exam — HealthCare Information Security and Privacy Practitioner
- SSCP exam — Systems Security Certified Practitioner