ISC2 certification practice Updated for 2026

ISC2 CAP Certified Authorization Professional

Build exam-day confidence with verified questions, detailed explanations, timed simulator sessions, and flexible download formats.

399 questions September 03, 2026 90 days free updates Instant access
Expert verified Save
$80.99
Complete preparation pack

CAP PDF & Test Engine Bundle

The most complete path from first review to final simulator run.

  • 399 verified questions and answers
  • Premium PDF and exam simulator files
  • Detailed explanations for every answer
  • Free updates for 90 days
$133.98 75% off
$52.99

20 learners downloaded this file in the last 7 days

Choose your format

Practice the way you learn best.

Every format includes the current question set and 90 days of updates.

PDF Only

Printable Premium PDF only

45% off
$62.99 $34.99

Test Engine Only

Test Engine File for 3 devices and Web Test Engine

45% off
$70.99 $39.99
Question coverage

A complete map of the current exam.

Use the breakdown to plan review sessions around the highest-volume domains.

Question types

399total
  • Single Choices 334
  • Multiple Choices 64
  • Simulations 1
Learn from every answer Every answer includes an explanation.

Exam topics

01 Information Security Risk Management Program 165 questions
02 Scope of the Information System 19 questions
03 Selection and Approval of Security and Privacy Controls 28 questions
04 Implementation of Security and Privacy Controls 38 questions
05 Assessment/Audit of Security and Privacy Controls 51 questions
06 Authorization/Approval of Information System 30 questions
07 Continuous Monitoring 16 questions
08 Mix Questions 52 questions
Last month

Preparation that translates into results.

37learners passed ISC2 CAP
87.1%average reported exam score
88.8%question similarity reported
Know the exam

Everything you need before scheduling.

Introduction of ISC2 CAP Exam!

The purpose of the Certified Authorization Professional credential is to validate governance, risk and compliance capability for information-system authorization. ISC2 now calls the certification Certified in Governance, Risk and Compliance (CGRC), a name introduced on February 15, 2023. The change reflects the broader knowledge and skills covered; ISC2 stated that it did not change the exam, course content or qualifications to pursue the credential. The certification is designed for practitioners who connect security risk management with organizational objectives, legal requirements and regulatory needs. In practical terms, it signals competence in helping stakeholders make informed security and privacy risk decisions, not merely familiarity with one authorization framework.

What is the Duration of ISC2 CAP Exam?

The exam duration is 3 hours. ISC2’s current CGRC Examination Outline identifies the former Certified Authorization Professional examination as a three-hour test. Plan your preparation around sustained concentration rather than short memorization sessions, because the available time must cover 125 items and both multiple-choice and advanced item types. During study, practise reading a governance, risk or authorization scenario, identifying the requirement, and selecting the most defensible response without becoming stuck on one detail. Exam policies, accommodations and any delivery-specific timing rules should be checked on the official ISC2 registration and exam-information pages before booking, since administrative conditions can change even when the published examination outline remains the main reference.

What are the Number of Questions Asked in ISC2 CAP Exam?

The number of questions is 125 items. This count comes from the current ISC2 CGRC Examination Outline, which is the relevant successor to the CAP exam information. The items assess seven connected areas, so preparation should not treat the test as a collection of isolated definitions. Build familiarity with the sequence from governance and system scope through control selection, implementation, assessment, authorization and continuing compliance. Since ISC2 also identifies advanced item types, practise applying principles to workplace situations rather than relying only on recall. Confirm the latest outline before scheduling, because ISC2 can revise examination specifications through its job-task-analysis process.

What is the Passing Score for ISC2 CAP Exam?

The passing score is 700 out of 1,000 points. ISC2 publishes this as the CGRC examination passing grade, and the credential is the current name for the former Certified Authorization Professional certification. A scaled score should not be treated as a simple percentage of correctly answered items, so candidates should avoid estimating readiness from a homemade pass-rate calculation. Use the official domain outline to identify weak areas, then review why an answer is appropriate in its governance or risk context. Registration policies and score-reporting details belong to ISC2’s current exam-information pages and should be checked before test day.

What is the Competency Level required for ISC2 CAP Exam?

The expected competency level is professional proficiency in governance, risk and compliance rather than entry-level security awareness. ISC2 describes CGRC holders as information-security practitioners who advocate security risk management while pursuing system authorization in support of an organization’s mission and operations. The work spans policy, risk decisions, control frameworks, evidence, assessment and ongoing compliance. Candidates should therefore be able to interpret how these activities connect and communicate their implications to stakeholders. Familiarity with organizational processes matters as much as terminology. The current outline also incorporates issues such as AI governance, so preparation should include modern system risks alongside established authorization practices.

What is the Question Format of ISC2 CAP Exam?

The question format combines multiple-choice and advanced item types. ISC2 does not describe the examination as a simple multiple-choice recall test in its current outline, so candidates should prepare to interpret information, compare plausible actions and apply governance or authorization principles. A useful study method is to explain why each option would be suitable, unsuitable or incomplete in the stated context. Practise with legitimate learning materials that resemble the published domains and objectives, while avoiding leaked material or exam dumps. Review the official ISC2 outline and examination policies for the authoritative description of item presentation and any later updates.

How Can You Take ISC2 CAP Exam?

The delivery option confirmed by ISC2 is a Pearson VUE Testing Center. The supplied official outline does not confirm an online-proctored option, so candidates should not assume that taking the exam from home is available. Check the ISC2 registration flow and Pearson VUE scheduling information for current locations, appointment availability, identification rules and accommodation procedures. Book only after confirming the correct CGRC listing, because CAP is the former certification name. Practical planning should include travel time, permitted items and the center’s check-in requirements; those operational details can vary by location and are more time-sensitive than the certification overview.

What Language ISC2 CAP Exam is Offered?

The published exam language is English. ISC2’s current CGRC Examination Outline lists English under exam-language availability and does not confirm translated versions in the supplied research. Candidates who need language-related accommodations should consult ISC2 before registering rather than relying on informal descriptions from training providers. Study resources may be offered in additional languages, but that does not establish that the examination itself is translated. Use the current official outline and registration information to verify language choices at the point of booking, particularly if ISC2 updates delivery arrangements or publishes a revised examination specification.

What is the Cost of ISC2 CAP Exam?

The exam cost is not publicly fixed in the supplied official research. Pricing can vary by region, taxes, currency, appointment arrangements or ISC2 policy, so a reliable amount should not be inferred from older CAP references or third-party listings. Check the official ISC2 registration page for the CGRC examination and review the price displayed for your location before payment. Also distinguish the examination charge from possible training costs, rescheduling charges, membership fees and the Annual Maintenance Fee that applies after certification approval. A voucher may affect how payment is made, but its availability and terms should be confirmed directly with ISC2 or an authorized provider.

What is the Target Audience of ISC2 CAP Exam?

The intended audience includes professionals responsible for governance, risk and compliance in information technology, information security and cybersecurity. ISC2 specifically identifies roles such as cybersecurity auditor, cybersecurity compliance officer, GRC architect or manager, risk and compliance project analyst, enterprise or third-party risk manager, GRC analyst or director, system security manager or officer, and information assurance manager. The credential can also suit public- and private-sector practitioners who must apply risk-management frameworks and support authorization decisions. Its scope is broader than a single government job function, reflecting the 2023 transition from the CAP name to CGRC.

What is the Average Salary of ISC2 CAP Certified in the Market?

Salary and compensation are not fixed benefits of the credential and vary by role, employer, location, sector, seniority and existing experience. The official research supplied for this FAQ does not provide a salary figure for CAP or CGRC holders, so an earnings estimate would be unreliable. Treat the certification as evidence of a defined competency set that may support applications for GRC, audit, risk, compliance or system-security roles; it does not guarantee a particular pay level. For useful market context, compare current job advertisements and reputable salary surveys using the specific role and region, then separate certification value from broader career factors.

Who are the Testing Providers of ISC2 CAP Exam?

The testing provider is Pearson VUE, with ISC2 listing Pearson VUE Testing Centers for the CGRC examination. Registration and scheduling should begin through the official ISC2 exam-registration route so that you select the current CGRC credential rather than search only for the retired CAP name. Pearson VUE appointment information can then determine available centers and dates. Before confirming, review ISC2’s examination policies, identification requirements, cancellation rules and accommodation guidance. Provider availability and booking procedures are operational details that may change, so the official ISC2 and Pearson VUE pages should take precedence over older preparation articles or community posts.

What is the Recommended Experience for ISC2 CAP Exam?

The recommended experience is at least two years of cumulative full-time work in one or more domains of the current CGRC Exam Outline. ISC2 says qualifying work involves information-systems security performed in pursuit of authorization or work requiring direct application of security-risk-management knowledge. The experience may cover any of seven domains, from governance and system scope to control implementation, assessment, system compliance and maintenance. Part-time work and internships can count under ISC2’s rules: full-time accrual uses a minimum of 35 hours/week for four weeks, while part-time work is 20 to 34 hours/week. Keep documentation that clearly connects duties to the domains.

What are the Prerequisites of ISC2 CAP Exam?

The formal prerequisite is two years of relevant cumulative full-time experience, although candidates may sit the examination without yet meeting it. A person who passes without the required experience can become an Associate of ISC2 and has three years to obtain the two years of relevant experience. ISC2 also permits certain education or approved certifications to waive up to one year of experience, with only one year waived through either route. After passing, the certification application requires an endorser or ISC2 endorsement process, and all credential exam passers must complete that application within nine months of the exam date.

What is the Expected Retirement Date of ISC2 CAP Exam?

The CAP certification was renamed Certified in Governance, Risk and Compliance (CGRC) effective February 15, 2023, so candidates should use CGRC when looking for the active credential. ISC2 stated that the change affected the name, not the exam, course content or qualifications to pursue it. Existing CAP holders’ digital certification and badge were updated to CGRC. This is therefore a replacement-name issue rather than evidence that the underlying certification disappeared. Before registering, verify the current CGRC page and examination outline; older CAP references can still be useful for history, but they may contain outdated booking or exam details.

What is the Difficulty Level of ISC2 CAP Exam?

A practical roadmap starts with the current ISC2 CGRC Examination Outline, then maps each of its seven domains to your work experience and study resources. First, identify gaps in governance, system scoping, framework and control selection, implementation, assessment, system compliance and maintenance. Next, study authoritative references recommended by ISC2 and build a small glossary of related terms and decision points. Apply the concepts to a sample system by tracing risks, controls, evidence, authorization and monitoring. Finish with timed practice using legitimate materials, review errors by domain, and read ISC2 examination policies before scheduling. Keep the current outline beside your plan so revisions are not missed.

What is the Roadmap / Track of ISC2 CAP Exam?

The topics measured cover seven domains: security and privacy governance, risk management and compliance program governance; system scope; selection and approval of frameworks and security and privacy controls; implementation; assessment and audit; system compliance; and compliance maintenance. The outline also reflects current concerns, including AI governance, embedded algorithms, machine-learning data pipelines, AI-native controls, AI-supported audit evidence, authorization of generative-AI systems and continuous control monitoring for MLOps. Study the relationships among these areas rather than memorizing domain titles. ISC2’s outline is the controlling source for detailed objectives, weighting and any future content changes.

What are the Topics ISC2 CAP Exam Covers?

Official practice guidance begins with ISC2’s current exam outline and its supplementary-reference recommendations; the supplied research does not provide an official sample question or fixed official practice-test format. Use practice questions to rehearse applying a control, risk or authorization concept to the facts given, then explain why competing options fail. Include scenario-style exercises that require evidence evaluation and stakeholder judgment, not just terminology recall. Avoid dumps, leaked questions and materials claiming guaranteed results. Compare any commercial mock exam with the official domains and item-format description, and verify that its content reflects the current CGRC outline rather than an obsolete CAP version build-up - wait 125 items, three hours, English, Pearson VUE.

What are the Sample Questions of ISC2 CAP Exam?

The difficulty is best described as professionally challenging because the examination tests judgment across governance, risk, controls, assessment and continuing compliance. ISC2 does not publish a universal difficulty rating, and individual experience will change how demanding the material feels. Candidates who know only technical security may need extra work on policy interpretation, authorization evidence, risk communication and regulatory alignment. Those from compliance backgrounds should strengthen system and control concepts. The current outline also addresses AI-related governance and compliance issues, making the scope contemporary rather than purely historical. Use domain-based practice and review explanations instead of measuring readiness by question volume alone.