CGRC is ISC2's credential for the people who own a system's full authorization lifecycle — scoping it, selecting and implementing the right security and privacy controls, then proving compliance through formal assessment and audit. It's the certification that shows an employer you can take a system from "built" to "formally authorized to operate," and keep it that way through ongoing compliance maintenance, not just defend it after the fact. That authorization authority is core to government contractors, federal agencies, and any regulated enterprise running a formal risk management framework, which is why CGRC is the credential GRC analysts and ISSOs point to when they move from supporting compliance to owning it.
Source: ISC2, CGRC Salary page (citing the ISC2 Cybersecurity Workforce Study) · 2026
Self-paced access, AI Coach on every lesson, full-length practice exams, and a free course retake if you complete the readiness gate and still don't pass your exam on the first attempt. Exam registration and voucher are purchased separately, directly through the certifying body.
See the full curriculum100% self-paced online — study on your schedule, no bootcamp seat to book.
Training a whole team on CGRC? Fund a Training Bank account for any amount, then assign any course to any employee — self-serve, published discount tiers, no sales call.
Set up your team account

