Skip to content
CertMapCertMap

GCCCGIAC Critical Controls Certification

GIACSpecialty certificateAudit
Official certification page

Created per CertMap methodology · About the editorial team

Jump to …5 sections

What is GCCC?

The GCCC certifies knowledge of implementing and auditing the CIS Critical Security Controls. The exam covers the background, purpose, implementation, and audit of the 18 controls in version 8, plus safeguards, implementation groups, control sensors, policies, cloud guidance, tools, automation, and mapping to other standards. It is aligned with the SANS course SEC566. According to GIAC it addresses security professionals, auditors, CIOs, risk officers, information assurance auditors, system implementers, network security engineers, IT administrators, Department of Defense personnel and contractors, federal agencies, and vendors and consultants.

Quick facts

Languages
RecognitionGlobal

Cost, prerequisites, exam & renewal

Cost over 5 years

Exam fee (acquisition)€8,762
Renewal fees (5 years)€459
5-year total€9,221
How is TCO calculated?

CertMap score and matching roles

Rating

Market recognition
1/3
Scheme quality
2/3
Practice evidence
2/3
Maintenance
2/3

Matching NICE roles

Oversee and GovernTechnology Program Auditing
Oversee and GovernSecurity Control Assessment

What are NICE roles? The framework explained

More certifications

Daniel Heessel, CISO of the Year 2026

Personal consulting

Not sure what's next? Ask someone who knows.

Personal strategy instead of weeks of self-research. Vendor-independent, with auditable recommendations and transparent sources.

Open consulting
GCCCView in quadrant