CertGrid
Security Study Guide

(ISC)² CGRC (Governance, Risk and Compliance) Study Guide

The (ISC)2 CGRC (Certified in Governance, Risk and Compliance, formerly CAP) validates the ability to manage the NIST Risk Management Framework (RMF) lifecycle: categorizing systems, selecting and implementing controls, assessing them, and authorizing systems to operate. It targets ISSOs, security control assessors, authorizing-official staff, and GRC/compliance professionals in federal, defense, and regulated environments. It is a management and process exam, not a hands-on technical or coding test.

Objective-mapped study guide, aligned to current exam objectives · Reviewed Aug 2026 · Independent practice platform.

Real exam: 125 qs · 180 min

Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program

Key concepts you must know · 118 practice questions

Domain 2: Scope of the System

Key concepts you must know · 74 practice questions

Domain 3: Selection and Approval of Framework, Security, and Privacy Controls

Key concepts you must know · 104 practice questions

Domain 4: Implementation of Security and Privacy Controls

Key concepts you must know · 126 practice questions

Domain 5: Assessment/Audit of Security and Privacy Controls

Key concepts you must know · 120 practice questions

Domain 6: System Compliance

Key concepts you must know · 103 practice questions

Domain 7: Compliance Maintenance

Key concepts you must know · 96 practice questions

(ISC)² CGRC (Governance, Risk and Compliance) exam tips

Study guide FAQ

What is the CGRC exam format?

The CGRC exam has 125 multiple-choice questions with a 180-minute time limit. You need a scaled score of 700 out of 1000 to pass. It is a linear, non-adaptive exam covering the seven domains aligned to the NIST RMF lifecycle.

Does CGRC require hands-on technical or coding skills?

No. CGRC is a management and process-focused certification. It tests your ability to manage the RMF lifecycle, roles, documentation, and risk-based decision making rather than configuring specific technologies or writing code.

What experience is required to sit for CGRC?

Candidates need at least two years of cumulative paid work experience in one or more of the seven CGRC domains. If you pass the exam without the required experience, you become an Associate of ISC2 and have up to three years to gain the experience needed for full certification.

How does CGRC relate to the NIST Risk Management Framework?

CGRC's seven domains are built directly on the NIST RMF's seven steps (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) as defined in NIST SP 800-37 Rev 2. The exam validates that you can execute each RMF step correctly, using supporting standards like FIPS 199, SP 800-60, SP 800-53/800-53B, and SP 800-53A.

Why did the exam name change from CAP to CGRC?

ISC2 renamed the Certified Authorization Professional (CAP) to Certified in Governance, Risk and Compliance (CGRC) to better reflect the certification's scope, which extends beyond system authorization to the full governance, risk management, and compliance lifecycle. The underlying RMF-based domains and exam remain the same credential continuing under a new name.

Related Security resources

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Security. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.