← All certifications

Certified in Governance, Risk and Compliance (CGRC)

ISC2

ISC2 certification (formerly CAP) for professionals who authorize and maintain information systems using risk management frameworks such as NIST RMF.

We have a course for this

Built from this exam's published objectives. The first module is free.

Baseline certification levels

This certification satisfies these DoD baseline levels — the IAT / IAM / IASAE / CSSP requirement many contracts still state. It's a separate question from the 8140 work roles above, and there is no official mapping between the two.

What this qualifies you for

Listed specifically for 3 work roles — up to Intermediate proficiency. Because options cascade downward, a cert listed at Advanced also satisfies Intermediate and Basic for that role.

Also listed for 14 Cyberspace Enablers roles — but so is every other certification

The Enablers matrix isn’t role-differentiated: the same certification options are listed for all 14 roles at every proficiency level. We verified that across all 14. So this is true, and it carries no information about this credential specifically — which is why it isn’t in the count above.

Renewal

3year cycle60CPE per cycle20minimum per year

Annual Maintenance Fee, USD 135/year

This is the issuer’s clock. 8140 runs a second one — 20 hours of CPD a year, at every proficiency level, which applies even if you hold no certification at all. How that works

CGRC (formerly Certified Authorization Professional, CAP) remains a linear/fixed-form exam of 125 items in 3 hours; unlike CISSP/CCSP/CC it has NOT moved to CAT as of July 2026. CGRC 3-year CPE total (60) and annual minimum (20) are the traditional ISC2 requirements; confirm current wording after the 2025 ISC2 CPE policy update in the Certification Maintenance Handbook. AMF confirmed at USD 135/year for CGRC (professional cert tier).

Source: ISC2 CGRC Certification Exam Outline · dated 2026-07-17 · checked 2026-07-17

Verifying it

ISC2 has no public lookup a third party can use on their own — verification depends on a badge URL you share.

ISC2 digital badges are issued via Credly and are independently shareable/verifiable by badge URL. ISC2 also offers a member verification service, but it requires the holder's ISC2 member ID (or identifying details).

CGRC (formerly Certified Authorization Professional, CAP) remains a linear/fixed-form exam of 125 items in 3 hours; unlike CISSP/CCSP/CC it has NOT moved to CAT as of July 2026. CGRC 3-year CPE total (60) and annual minimum (20) are the traditional ISC2 requirements; confirm current wording after the 2025 ISC2 CPE policy update in the Certification Maintenance Handbook. AMF confirmed at USD 135/year for CGRC (professional cert tier).

Source: ISC2 CGRC Certification Exam Outline · dated 2026-07-17 · checked 2026-07-17

Exam blueprint

Verified against ISC2’s published outline.

CGRC · Effective June 15, 2024

Current

125 items · 3 hours · passing score 700 of 1000

Security and Privacy Governance, Risk Management, and Compliance Program16%
Scope of the System10%
Selection and Approval of Framework, Security, and Privacy Controls14%
Implementation of Security and Privacy Controls17%
Assessment/Audit of Security and Privacy Controls16%
System Compliance14%
Compliance Maintenance13%

CGRC (formerly Certified Authorization Professional, CAP) remains a linear/fixed-form exam of 125 items in 3 hours; unlike CISSP/CCSP/CC it has NOT moved to CAT as of July 2026. CGRC 3-year CPE total (60) and annual minimum (20) are the traditional ISC2 requirements; confirm current wording after the 2025 ISC2 CPE policy update in the Certification Maintenance Handbook. AMF confirmed at USD 135/year for CGRC (professional cert tier).

Source: ISC2 CGRC Certification Exam Outline · dated 2026-07-17 · checked 2026-07-17