Certified in Governance, Risk and Compliance (CGRC)
ISC2
ISC2 certification (formerly CAP) for professionals who authorize and maintain information systems using risk management frameworks such as NIST RMF.
We have a course for this
Built from this exam's published objectives. The first module is free.
Baseline certification levels
This certification satisfies these DoD baseline levels — the IAT / IAM / IASAE / CSSP requirement many contracts still state. It's a separate question from the 8140 work roles above, and there is no official mapping between the two.
What this qualifies you for
Listed specifically for 3 work roles — up to Intermediate proficiency. Because options cascade downward, a cert listed at Advanced also satisfies Intermediate and Basic for that role.
Also listed for 14 Cyberspace Enablers roles — but so is every other certification
The Enablers matrix isn’t role-differentiated: the same certification options are listed for all 14 roles at every proficiency level. We verified that across all 14. So this is true, and it carries no information about this credential specifically — which is why it isn’t in the count above.
Renewal
Annual Maintenance Fee, USD 135/year
This is the issuer’s clock. 8140 runs a second one — 20 hours of CPD a year, at every proficiency level, which applies even if you hold no certification at all. How that works
CGRC (formerly Certified Authorization Professional, CAP) remains a linear/fixed-form exam of 125 items in 3 hours; unlike CISSP/CCSP/CC it has NOT moved to CAT as of July 2026. CGRC 3-year CPE total (60) and annual minimum (20) are the traditional ISC2 requirements; confirm current wording after the 2025 ISC2 CPE policy update in the Certification Maintenance Handbook. AMF confirmed at USD 135/year for CGRC (professional cert tier).
Source: ISC2 CGRC Certification Exam Outline · dated 2026-07-17 · checked 2026-07-17
Verifying it
ISC2 has no public lookup a third party can use on their own — verification depends on a badge URL you share.
ISC2 digital badges are issued via Credly and are independently shareable/verifiable by badge URL. ISC2 also offers a member verification service, but it requires the holder's ISC2 member ID (or identifying details).
CGRC (formerly Certified Authorization Professional, CAP) remains a linear/fixed-form exam of 125 items in 3 hours; unlike CISSP/CCSP/CC it has NOT moved to CAT as of July 2026. CGRC 3-year CPE total (60) and annual minimum (20) are the traditional ISC2 requirements; confirm current wording after the 2025 ISC2 CPE policy update in the Certification Maintenance Handbook. AMF confirmed at USD 135/year for CGRC (professional cert tier).
Source: ISC2 CGRC Certification Exam Outline · dated 2026-07-17 · checked 2026-07-17
Exam blueprint
Verified against ISC2’s published outline.
CGRC · Effective June 15, 2024
Current125 items · 3 hours · passing score 700 of 1000
CGRC (formerly Certified Authorization Professional, CAP) remains a linear/fixed-form exam of 125 items in 3 hours; unlike CISSP/CCSP/CC it has NOT moved to CAT as of July 2026. CGRC 3-year CPE total (60) and annual minimum (20) are the traditional ISC2 requirements; confirm current wording after the 2025 ISC2 CPE policy update in the Certification Maintenance Handbook. AMF confirmed at USD 135/year for CGRC (professional cert tier).
Source: ISC2 CGRC Certification Exam Outline · dated 2026-07-17 · checked 2026-07-17