Skip to content
CertMapCertMap

CGRCISC2 Certified in Governance, Risk and Compliance

ISC2Personnel certification (ISO 17024)GRC

Created per CertMap methodology · About the editorial team · Official page

Jump to …4 sections

What is CGRC?

The ISC2 CGRC validates competence in governance, risk and compliance for information systems. Its focus is the risk management framework used to authorise systems and keep them in operation. Until February 2023 the certification was called Certified Authorization Professional, or CAP; the exam content was unaffected by the rename. The exam has 125 items over three hours and is offered in English only. Two years of relevant work experience in at least one of the seven knowledge domains are required; candidates without it can sit the exam as an Associate of ISC2 and supply the experience later.

Suitable for

IT Auditor
Compliance Officer
GRC Manager
GRC Analyst
Risk Manager

Quick facts

AccreditationISO/IEC 17024 by ANAB
Languages
RecognitionGlobal

Cost, prerequisites, exam & renewal

Cost over 5 years

Exam fee (acquisition)€551
AMF (5 years)€621
CPE time value (5 years)€8,000
5-year total€9,172
CPE effort: 20 h per year · 100 h over 5 years · Valued at 80 €/h.
How is TCO calculated?

CertMap score and matching roles

Rating

Market recognition
0/3
Scheme quality
3/3
Practice evidence
1/3
Maintenance
2/3

Matching NICE roles

Oversee and GovernSystems Security Management
Oversee and GovernSecurity Control Assessment
Design and DevelopCybersecurity Architecture
Design and DevelopEnterprise Architecture
Design and DevelopTechnology Research and Development
Design and DevelopOperational Technology (OT) Cybersecurity Engineering
Implement and OperateData Analysis
Implement and OperateDatabase Administration
Implement and OperateKnowledge Management
Implement and OperateNetwork Operations

What are NICE roles? The framework explained

More certifications

CGRCView in quadrant