Certified Authorization Professional (CAP) Exam Guide: Preparing for the CGRC Exam
The Certified Authorization Professional (CAP) certification is now called Certified in Governance, Risk and Compliance (CGRC). The exam validates the ability to apply governance, risk management, security and privacy controls, assessment, authorization and compliance maintenance to information systems. It serves cybersecurity, audit, compliance, risk and system-security professionals, including people working with public- and private-sector frameworks. This guide helps former CAP candidates and new CGRC candidates decide whether they are ready to schedule the exam, what experience they need, and how to organize study time around the current outline.
What happened to the CAP certification?
CAP is the former name of the ISC2 Certified in Governance, Risk and Compliance credential. ISC2 changed the name to CGRC effective February 15, 2023; the organization stated that the change affected the certification name, not the exam, course content or qualifications for pursuing it. Search results, older study materials and workplace references may still use CAP, so candidates should match their preparation materials to the current CGRC Exam Outline rather than relying on the title alone.
The name change reflects a broader description of the work. The credential covers the integration of governance, performance management, risk management and regulatory compliance so that security and privacy decisions support organizational objectives. The original CAP credential had a strong association with authorization work and the U.S. government Risk Management Framework, while the renamed credential is intended for information-security professionals in public and private organizations working with different risk-management frameworks.
For a candidate, the practical consequence is straightforward: treat “CAP exam” and “CGRC exam” as references to the same certification lineage, but verify that any book, course or practice material maps to the current seven-domain outline. The current outline is effective June 15, 2024.
Who should use this guide?
Use this guide if you are planning the current CGRC exam under the older CAP name, comparing the credential with another ISC2 option, or deciding whether your work history is relevant enough to support an application. It is especially useful for candidates whose experience involves authorization packages, control selection, audit evidence, security assessments, compliance tracking, risk decisions or continuous monitoring.
ISC2 identifies suitable role families including cybersecurity auditor, cybersecurity compliance officer, GRC architect or manager, cybersecurity risk and compliance project manager or analyst, third-party or enterprise risk manager, GRC analyst or director, system security manager or officer, and information assurance manager. These titles are examples of where the knowledge may be applied; a job title alone does not establish the experience requirement.
What does the CGRC exam validate?
The credential is aimed at an information-security practitioner who advocates security risk management in pursuit of information-system authorization that supports an organization’s mission and operations while meeting legal and regulatory requirements. In practical terms, the exam tests whether you can connect organizational objectives, system scope, frameworks, controls, evidence, authorization decisions and ongoing compliance rather than treating them as isolated activities.
The exam outline says successful candidates are competent across seven domains: Security and Privacy Governance, Risk Management, and Compliance Program; Scope of the System; Selection and Approval of Framework, Security, and Privacy Controls; Implementation of Security and Privacy Controls; Assessment/Audit of Security and Privacy Controls; System Compliance; and Compliance Maintenance.
This is not a narrow tool certification. The work described by the domains requires judgment about ownership, boundaries, control applicability, evidence quality, residual risk and the relationship between an information system and the organization that authorizes it. Study should therefore focus on decision logic and process sequence, not only on definitions or lists of control names.
What candidates should be able to connect
A strong preparation model follows the lifecycle implied by the outline: establish governance and risk context, define the system, select and approve appropriate controls, implement them, assess and audit them, determine compliance and authorization status, and maintain that status through monitoring and change management. Questions may present one stage while testing whether you understand its dependency on an earlier or later stage.
The official outline also reflects current concerns involving artificial intelligence. Domain 1 addresses governance in the age of AI, including dedicated oversight for algorithmic transparency and ethical use of autonomous agents. Domain 2 requires identifying embedded algorithms, including algorithms hidden in commercial off-the-shelf software, and expands scoping methods for continuous machine-learning data pipelines. These points are reasons to study the current outline directly instead of assuming older CAP notes cover every emphasis.
What are the exam format and delivery details?
The CGRC examination is three hours long and contains 125 items. It uses multiple-choice and advanced item types, has a passing score of 700 out of 1,000 points, and is available in English. ISC2 lists Pearson VUE Testing Centers as the testing-center delivery option. Review the official registration policies and procedures before booking because scheduling rules and candidate instructions should be confirmed at the time of registration.
The exam is scored on a 1,000-point scale, so the passing grade is not a requirement to answer a particular percentage of items correctly. Do not turn the published score into a guessed question target. The safest preparation decision is to use practice results diagnostically: identify the domain or reasoning pattern behind an error, then return to the outline and source material.
Advanced item types also make passive reading a weak strategy. During preparation, explain why an answer is best, why the alternatives are weaker, what role owns the decision and which lifecycle stage the scenario represents. That exercise builds the reasoning habit needed for scenario-based questions without implying access to live exam content.
What to confirm before scheduling
Confirm four items before selecting an appointment: that your materials follow the current CGRC outline, that you can test in the listed language, that the selected Pearson VUE option suits your circumstances, and that you understand ISC2 examination policies. If you need an accommodation, use the official ISC2 process and do not assume that a third-party summary contains current instructions.
Scheduling should follow readiness evidence, not simply completion of a video course. A practical threshold is consistent performance on original, reputable practice questions across every domain, with the ability to explain the reasoning behind each answer. This is a recommendation, not an ISC2 eligibility rule or a prediction of a passing result.
Do you meet the experience requirement?
To earn the CGRC certification, candidates need a minimum of two years of cumulative full-time work experience in one or more domains of the current CGRC Exam Outline. Qualifying work is information-systems-security work performed in pursuit of information-system authorization, or work requiring security risk-management knowledge and direct application of that knowledge.
Map your work to activities, not job titles. For example, documenting system boundaries may support Scope of the System; tailoring or approving controls may support Selection and Approval of Framework, Security, and Privacy Controls; collecting assessment evidence may support Assessment/Audit; and tracking remediation or recurring reviews may support Compliance Maintenance. Keep records that show what you did, the period involved and how the activity fits a domain.
Do this mapping before buying training or booking the exam. It can reveal that your experience is concentrated in one area, that an apparently relevant project did not involve direct application of risk-management knowledge, or that documentation is missing. The official requirements—not an informal interpretation of a job description—control whether experience is accepted.
How part-time work and internships count
ISC2 says full-time experience accrues monthly: you must work a minimum of 35 hours/week for four weeks to accrue one month of work experience. Qualifying part-time work must be no less than 20 hours a week and no more than 34 hours a week. The official requirements state that 1040 hours of part-time work equals 6 months of full-time experience and 2080 hours of part-time work equals 12 months of full-time experience.
Paid or unpaid internships may count. ISC2 requires documentation on company or organization letterhead confirming the internship position; a school internship document may use the registrar’s stationery. Retain this evidence rather than waiting until after the exam, when locating an old supervisor or registrar may be harder.
If you lack the required experience, you may become an Associate of ISC2 by passing the CGRC examination. An Associate of ISC2 then has three years to obtain the required two years of relevant experience. This route changes the certification path; it does not remove the need to plan how you will gain and document qualifying work.
What happens after you pass?
Passing the exam is not the end of the ISC2 certification process when experience and endorsement steps remain. All candidates who pass an ISC2 credential examination must complete the certification application process within nine months of the exam date, and the application cannot be submitted until ISC2 notifies you that you passed.
For certifications other than Certified in Cybersecurity, ISC2 requires an endorser who is an ISC2-certified professional in good standing and can attest to your experience. If you do not know an eligible endorser, ISC2 offers an endorsement route requiring proof of employment. ISC2 may also randomly select submitted applications for audit and request additional verification.
Prepare an experience packet while studying: list employers and dates, write domain-mapped duties in clear language, identify documentation sources and confirm who could attest to the work. This is a practical recommendation designed to reduce post-exam administration; it is not a substitute for reading the official application instructions.
How should you study the seven domains?
Study in lifecycle order, but revisit domains in connected pairs. Start with governance and risk, then define scope, select and approve controls, implement them, assess them, determine system compliance and maintain compliance. This sequence gives each control decision a reason and a later validation step, which is more useful than memorizing seven disconnected headings.
The official exam outline does not provide a domain percentage in the supplied research snapshot, so this guide does not assign weights or recommend studying from unsupported percentages. Give attention to every domain and use the outline’s task statements to decide where your current work experience is thin. A narrow specialization in authorization or audit should not become permission to neglect governance, system scope or maintenance.
Build one working map with columns for objective, responsible role, input, decision, evidence and follow-up. Apply it to a fictional information system such as a business application handling regulated data. Keep the scenario generic and use it to practice process reasoning; do not recreate or seek actual exam questions.
Domain 1: Security and Privacy Governance, Risk Management, and Compliance Program
This domain establishes the organizational context for security and privacy decisions. Concentrate on governance structures, accountability, risk-management processes, compliance obligations, policy relationships and the way risk information supports mission and business objectives. A control is not meaningful merely because it appears in a framework; the organization must understand its purpose, ownership and acceptable risk.
The current outline adds an AI perspective: governance in the age of AI requires dedicated oversight boards for algorithmic transparency and the ethical use of autonomous agents. Treat this as an application of governance principles, not as a reason to memorize a collection of AI products.
A useful exercise is to take one proposed system change and write who authorizes it, what risk information informs the decision, which privacy concerns need escalation and which policy or regulatory obligations apply. This exposes confusion between policy ownership, technical implementation and authorization authority.
Domain 2: Scope of the System
Scope determines what the authorization and compliance effort actually covers. Practice identifying system boundaries, components, information flows, interconnections, inherited services, data types, users, environments and dependencies. An incomplete boundary can make later control implementation and assessment appear successful while leaving relevant risk outside the review.
The outline requires candidates to identify all embedded algorithms, including those hidden within commercial off-the-shelf software. It also expands traditional scoping methodologies to capture the sprawling and continuous nature of modern machine-learning data pipelines. When studying, ask what changes when a system includes vendor software, model services, training data, inference pipelines or automated updates.
Draw a boundary diagram and annotate each external connection with the information exchanged, the dependency owner and the evidence you would need. Then challenge the diagram: where are shared services, administrative paths, development environments and supplier responsibilities? This is a practical way to turn an abstract scope topic into an authorization decision.
Domain 3: Selection and Approval of Framework, Security, and Privacy Controls
This domain concerns choosing controls that fit the system, its risks, its information and the governing framework, then obtaining the required approval. Learn to distinguish a control baseline from tailoring, overlays, enhancements, compensating measures, inherited controls and organization-defined parameters. The goal is defensible selection, not the largest possible control list.
For AI systems, the current outline refers to specialized overlays such as the CSA AI Controls Matrix alongside traditional framework baselines. Study the reason for an overlay: a system may need additional treatment for model behavior, data provenance, transparency or other characteristics that a general baseline does not fully express.
Practice writing a short control-selection rationale. State the risk or requirement, the selected control approach, the responsible owner, any inherited portion, the evidence expected and the approval needed. If you cannot explain why a control applies, you are probably memorizing labels rather than understanding selection.
Domain 4: Implementation of Security and Privacy Controls
Implementation turns approved control decisions into operating procedures, technical configurations, roles and evidence. Review how control requirements are assigned, documented, communicated and tested in the environment. Pay attention to the difference between a written policy, a configured safeguard, an operating process and proof that the process is working.
The current outline says implementation addresses deployment of AI-native security controls in distributed machine-learning pipelines. That emphasis makes system context important: an implementation may involve data preparation, model development, deployment, monitoring and access across several services rather than a single server.
For each practice scenario, identify the implementation owner and the evidence that would demonstrate operation. A policy document may show intent; a configuration record, ticket, log, review record or assessment result may be needed to show execution. Avoid assuming that “implemented” means “effective” or “compliant”; those conclusions belong to later evaluation.
Domain 5: Assessment/Audit of Security and Privacy Controls
Assessment and audit require a repeatable method for determining whether controls are suitably designed, implemented and operating as intended. Study assessment objectives, evidence quality, independence, findings, corrective actions, reporting and the relationship between an assessment result and an authorization decision. A reviewer should be able to distinguish missing evidence from an ineffective control and from a control that does not apply.
The outline notes that auditing in an AI-driven environment shifts from manual inspections toward AI-powered audit tools that can correlate compliance evidence across broad cloud landscapes. The tool does not replace accountability or professional judgment; it changes how evidence may be collected and correlated.
Use a mock assessment table with requirement, test procedure, evidence, result, deficiency and remediation owner. Include contradictory evidence and stale evidence. Then decide whether the issue affects a single control, a shared service, the system boundary or the authorization decision. This practice develops the distinctions scenario questions often require.
Domain 6: System Compliance
System compliance brings together control status, assessment results, risk acceptance, documentation and the formal decision about whether the system may operate under stated conditions. Review authorization roles, authorization packages, findings, residual risk, conditions, approval records and the relationship between system compliance and organizational mission.
The current outline states that authorization of an AI system involves navigating the uncertainties of generative AI through formal risk-acceptance criteria. It also integrates AI governance tools that can automate the generation and submission of massive compliance authorization packages, such as System Security Plans. Automation may improve scale and consistency, but the underlying responsibility for accurate information, review and approval remains a governance matter.
Create a miniature authorization package from your mock system. Include a system description, boundary, applicable controls, implementation evidence, assessment findings, residual risks and a proposed decision. Mark every assumption. The exercise is valuable because it reveals whether you can move from individual control facts to an authorization recommendation.
Domain 7: Compliance Maintenance
Compliance maintenance is the continuing work required after an authorization or compliance decision. Study continuous monitoring, changes to systems and controls, recurring assessments, issue tracking, reporting, reauthorization triggers and evidence retention. The central question is whether the organization can detect when a previous decision no longer reflects the system’s actual risk.
For AI systems, the outline describes a transition to AI-driven Continuous Control Monitoring that can handle the rapid change lifecycle of MLOps. Connect this to practical questions: what changed, who reviews the change, what evidence is refreshed, which risk assumptions are invalidated and when the authorizing official must be informed.
Build a change log for your study scenario. Add a new supplier, a changed data source, a model update and a control failure. For each event, decide whether monitoring, assessment, remediation, escalation or authorization review is required. Explain the decision rather than treating every change as automatically requiring the same response.
How can you turn the outline into a study plan?
A practical plan should move from orientation to application to timed review. First establish the vocabulary and lifecycle; next work through a single system scenario across all seven domains; then test individual weak areas; finally rehearse the exam format and your decision process. Set the schedule around your available study sessions and experience gaps rather than copying an arbitrary calendar.
Use the official exam outline as the control document for your preparation. ISC2 encourages candidates to supplement education and experience with relevant resources and to identify areas needing additional attention. Keep a source log showing which resource supports each concept, because older CAP material may use former domain names or omit current AI-related emphasis.
Do not measure readiness by hours spent or by the number of notes produced. Measure it by whether you can explain a decision, identify its owner, choose the evidence needed and place it correctly in the authorization lifecycle.
Stage 1: Establish your baseline
Before studying deeply, read the current outline and mark each task as confident, familiar or unfamiliar. Separately map your work experience to the seven domains and flag any domain supported only by reading. This baseline tells you whether your main problem is terminology, process sequencing, framework application, assessment reasoning or documentation.
Create a glossary in your own words for terms that control decision logic: system boundary, inherited control, tailoring, assessment evidence, residual risk, authorization, continuous monitoring and remediation. Add a short example for each. If two terms seem interchangeable, write the distinction explicitly and check it against the official material.
Stage 2: Build one end-to-end scenario
Choose a fictional organization and information system with a meaningful business purpose, sensitive information, a supplier dependency and at least one privacy concern. Work through governance, scope, control selection, implementation, assessment, compliance and maintenance using the same scenario. Continuity prevents the domains from becoming isolated memorization exercises.
At each stage, answer five questions: what decision is being made, who is accountable, what information is required, what evidence is produced and what happens next? Record unresolved assumptions. A candidate who can identify missing information is better prepared for questions where the tempting answer acts before scope, authority or evidence is established.
Stage 3: Test weak reasoning, not just recall
Use practice questions only as learning instruments. For every missed or guessed item, record the tested domain, the lifecycle stage, the words that changed the scenario and the reason your chosen answer failed. Then return to the relevant source and write a corrected principle. Avoid collecting answer letters or memorizing explanations without understanding the underlying decision.
Mix domains after targeted review. Real governance work crosses boundaries, and an item about assessment may depend on scope or control ownership. Once a weak area improves, pair it with a stronger area and solve comparison scenarios. This reduces the risk of being comfortable only when questions are grouped under obvious headings.
Stage 4: Rehearse the appointment
Before scheduling, complete a timed practice session using original or authorized preparation material and simulate the concentration required for three hours. Review errors after the session rather than interrupting every question to consult notes. This rehearsal is a practical recommendation; it does not reproduce the actual exam or guarantee a result.
At the appointment, apply a consistent reading method: identify the lifecycle stage, locate the decision owner, separate facts from assumptions, eliminate answers that act outside the stated authority, and choose the response that best fits the question’s scope. Do not infer that a familiar acronym is the answer merely because it appears in the scenario.
Which study mistakes create avoidable risk?
The most damaging mistakes are usually process mistakes: studying an obsolete outline, confusing implementation with assessment, ignoring system boundaries, treating compliance as a one-time event and failing to document experience. Correct these before adding more resources. More material cannot compensate for a flawed mental model of authorization and risk management.
CAP’s former name creates a specific trap. A search may return older CAP books, forum posts or domain labels. Older material can provide background, but compare it with the current CGRC Exam Outline and pay particular attention to current AI-related statements. The official 2023 announcement says the exam and course content were not changed by the name update, but the current outline is the authority for preparation.
Another trap is overfitting to one framework or one employer’s process. Frameworks organize requirements; organizations still need to determine scope, ownership, tailoring, evidence and acceptable risk. Practice transferring the same reasoning to a different system and organizational context.
Do not use leaked questions, exam dumps or memorized answer keys. They do not establish understanding, may be unreliable or unauthorized, and cannot make a candidate competent to evaluate risk, controls or evidence. Use legitimate study resources and the official outline instead.
When should you postpone scheduling?
Postpone if you cannot explain the authorization lifecycle, have not checked your experience evidence, or consistently miss questions because you misread the responsible role or system boundary. Postponing is also sensible when your resources use unexplained former terminology and you have not reconciled them with the current outline.
A low practice result alone does not diagnose the problem. Review the error pattern. If mistakes are spread across every domain, rebuild the lifecycle model. If they cluster around assessment, study evidence and findings. If they cluster around scope, practice boundaries, dependencies and embedded components. Schedule when the weakness has a clear correction plan and your results show stable improvement.
What should you do next?
Start with the current CGRC Exam Outline, confirm the examination information and write a domain-by-domain baseline. Then verify your two-year experience position, assemble documentation, choose resources that support the outline, and build one end-to-end system scenario. Only after those steps should you select a testing appointment and complete the registration process.
If you pass without the required experience, follow the Associate of ISC2 route and track the relevant work needed within the stated three-year period. If you pass with the experience requirement, complete the application within nine months of the exam date and prepare for endorsement or ISC2 endorsement with proof of employment as applicable.
Use the official pages for the final checks: exam policies before registration, experience rules before claiming eligibility, and endorsement instructions after passing. The most reliable preparation decision is not to chase a predicted question list; it is to demonstrate that you can make and defend governance, risk, control, assessment and compliance decisions across the complete system lifecycle.
Conclusion
The CAP name now points candidates toward the CGRC credential, but the preparation challenge remains practical: understand how governance and risk decisions become scoped systems, approved controls, evidence, authorization and maintained compliance. Verify eligibility, study from the current outline, test your reasoning across every domain and complete the post-exam application steps on time. That approach gives you a defensible basis for deciding when to schedule rather than relying on outdated labels or unsupported shortcuts.
Related exams
- Certified Information Systems Security Professional (CISSP)
- HCISPP exam — HealthCare Information Security and Privacy Practitioner
- SSCP exam — Systems Security Certified Practitioner