ZETLAN TECHNOLOGIES
Course Categories 172+
Cloud & Infrastructure 7
Networking 8
Virtualisation 5
IT Security 10
CyberSecurity & Mgmt 14
Software Development 16
Web Dev & Database 27
Data Science & AI 14
Mobile, Testing & Games 22
Design & Creative 49
Navigation
Home Business About Us Contact Us All Courses FAQ & Help
Contact Us
+91 8680961847 +91 8680961847 (WhatsApp) info@zetlantechnologies.com
Browse by Domain
Cloud & Infrastructure 7
Networking 8
Virtualisation 5
IT Security 10
CyberSecurity & Mgmt 14
Software Development 16
Web Dev & Database 27
Data Science & AI 14
Mobile, Testing & Games 22
Design & Creative 49
2000+ Courses · 15+ Technology Domains
Microsoft Cisco AWS EC-Council View All Courses
Home  /  ISC2 Certifications  /  CGRC
🔥 Trending Certification · 2025

ISC2 Certified in Governance
Risk and Compliance (CGRC)

Demonstrate your expertise in integrating governance, risk management and compliance programmes with the ISC2 CGRC — the benchmark credential for GRC professionals.

Governance Risk Compliance FISMA NIST RMF 2 Years Experience GRC Professional Risk Frameworks Compliance Management
Enroll Now
Risk ManagementEnterprise risk frameworks
Control SelectionNIST SP 800-53 controls
Security AssessmentTesting & audit activities
Continuous MonitoringOngoing risk & compliance oversight
125
Exam Questions
3 Hrs
Duration
2 Years
Experience Req.
7
Domains
Why It's Trending

The Gold Standard for GRC Professionals

CGRC is the benchmark credential for professionals integrating governance, risk and compliance into enterprise security programmes worldwide.

Trending
$11.3B
GRC Market Size
The global GRC market is growing rapidly driven by regulatory demands and digital risk.
+45%
Salary Uplift
GRC professionals earn significantly above average IT salaries globally.
Trending
FISMA/RMF
Government Demand
CGRC is especially valued in US federal government, DoD and defence-related roles.
Rising
Regulatory Pressure
GDPR, HIPAA, SOX and other regulations are driving explosive demand for GRC experts.
Certification

ISC2 Certified in Governance, Risk and Compliance (CGRC)

CGRC — Certified in Governance, Risk and Compliance

The ISC2 CGRC (formerly CAP) demonstrates expertise in authorizing and maintaining information systems within the Risk Management Framework (RMF). It is the gold standard for professionals responsible for integrating governance, risk and compliance programmes into their organization.

Exam: CGRC Certified in Governance, Risk and Compliance. Prerequisites: Two years of cumulative paid work experience in one or more of the 7 CGRC domains. Associate path: Candidates without experience may take the exam and become an Associate of ISC2.

Exam Overview

CGRC — Certified in Governance, Risk and Compliance Exam Details

Language
English
Duration
180 Minutes
Total Questions
125
Passing Score
700 out of 1000
Format
Multiple Choice / Multiple Select
Experience
2 Years in 1+ CGRC Domain

Exam details may change. Refer to the official ISC2 website for the latest information on pricing and policies.

Course Content

Complete CGRC Curriculum

Click any domain to expand and explore the topics covered in detail.

01
Information Security Risk Management Program
5 Topics
Understand risk management frameworks (NIST RMF, ISO 31000)
Understand governance structures and organizational roles
Apply legal, regulatory and contractual requirements to risk programs
Develop and maintain security and privacy policies and standards
Understand risk communication, reporting and escalation processes
02
Scope of the Information System
4 Topics
Categorize information systems based on impact (FIPS 199 / NIST SP 800-60)
Define system boundaries and establish system ownership
Identify interconnections and data flows between systems
Document the system description, architecture and environment
03
Selection and Approval of Security and Privacy Controls
4 Topics
Select security and privacy controls from NIST SP 800-53
Apply control baselines and overlays for specific environments
Develop system security and privacy plans (SSP)
Obtain approval for selected controls from authorizing officials
04
Implementation of Security and Privacy Controls
4 Topics
Implement security and privacy controls per the approved plan
Document control implementation details and evidence
Develop plan of action and milestones (POA&M) for gaps
Integrate security controls into the system development lifecycle
05
Assessment/Audit of Security and Privacy Controls
4 Topics
Develop and execute security assessment plans (SAP)
Apply assessment methods (examine, interview, test)
Analyze assessment findings and document results
Develop security assessment reports (SAR) with recommendations
06
Authorization/Approval of Information System
3 Topics
Compile and review authorization packages (SSP, SAR, POA&M)
Perform risk acceptance and authorization decision
Communicate authorization outcomes to stakeholders
07
Continuous Monitoring
5 Topics
Define and implement an information security continuous monitoring (ISCM) strategy
Perform ongoing assessments and reporting of security status
Manage configuration changes and their security impact
Conduct reviews, audits and compliance reporting
Plan and execute system decommissioning activities
FAQs

Frequently Asked Questions

What is the ISC2 CGRC?
The CGRC (Certified in Governance, Risk and Compliance), formerly known as CAP, is an ISC2 certification that validates expertise in integrating governance, risk management and compliance programmes. It is particularly focused on the NIST Risk Management Framework (RMF).
Who should pursue CGRC?
CGRC is ideal for information assurance practitioners, security officers, compliance analysts, risk managers and IT auditors — especially those working in or with US federal agencies, DoD contractors or regulated industries.
What experience is required?
Two years of cumulative paid work experience in one or more of the 7 CGRC domains is required. Without experience, you can take the exam and become an Associate of ISC2.
What is the FISMA connection?
CGRC strongly aligns with the Federal Information Security Modernization Act (FISMA) and NIST guidelines, making it the preferred credential for roles requiring FISMA compliance in US government environments.
How is CGRC different from CISA?
While CISA (from ISACA) focuses broadly on IS audit and control, CGRC is specifically focused on the RMF authorization process, ongoing compliance and risk management — particularly within NIST-based frameworks.
Is CGRC accepted globally?
Yes — although CGRC has strong applicability in US government and federal sectors, its risk management and compliance coverage is recognised globally by enterprises subject to GRC regulations.
Get Started

Master Governance, Risk and Compliance with CGRC

Join Zetlan Technologies' CGRC programme and become the GRC professional that government agencies and enterprises need to navigate today's complex regulatory landscape.

Zetlan Technologies
Online — Replies in minutes
👋 Hi! Welcome to Zetlan Technologies.

Interested in CGRC — ISC2 Certified in Governance, Risk and Compliance? Ask us anything!
Just now
Course Fee? Batch Timings? Exam Details
Open WhatsApp Chat
Your info is safe with us
💬 Chat with us!