What Is CGRC, and What Does It Prove?
CGRC (Certified in Governance, Risk and Compliance) is the ISC2 credential formerly called CAP, the Certified Authorization Professional. It proves you understand how an information system gets scoped, how controls get selected and implemented, how they get assessed, and how the system stays compliant after it is authorized.
The seven domains, per the ISC2 exam outline effective June 15, 2024: governance, risk management, and compliance program; scope of the system; selection and approval of framework, security, and privacy controls; implementation of controls; assessment and audit of controls; system compliance; and compliance maintenance. Read that list and the RMF lifecycle is obvious. That is the strength of CGRC and also its limit.
How Much Does CGRC Cost?
USD, from ISC2's published fees as of September 2026. EMEA and UK candidates pay in local currency.
| Line item | Cost | Notes |
|---|---|---|
| Exam registration | $599 | Americas price. One attempt. |
| Retake | $599 | Full fee again. ISC2 requires 30 days before a second attempt, 60 before a third, 90 after that. |
| Reschedule or cancel | $50 or $100 | Charged by Pearson VUE. No reschedules inside 24 hours. |
| Annual maintenance fee | $135 per year | First one is due at certification. One fee covers all ISC2 certs. |
| Associate of ISC2 fee | $50 per year | Only if you pass before you have the two years of experience. |
| Study materials or course | $0 to $2,000+ | Books and practice questions are cheap. Instructor-led courses are not. |
| First-year total | $750 to $3,000 | Exam and first AMF at the low end, a paid course at the high end. |
One detail works in CGRC's favor: ISC2 charges a single $135 annual fee no matter how many ISC2 certifications you hold. If you already have CISSP or plan to get it, CGRC adds no ongoing fee. For every other cert's price, see GRC certification costs.
Who Should Get CGRC, and Who Should Skip It?
Get it if
- You are an ISSO, ISSM, or security control assessor on federal systems.
- You work at a federal contractor or on FedRAMP authorization packages.
- You already hold an ISC2 cert, so the $135 annual fee is sunk.
- You want a GRC credential with a two-year experience bar instead of five.
Skip it, for now, if
- Your work is SOC 2, ISO 27001, or HIPAA at commercial companies.
- You want an IT audit career, where CISA is the default signal.
- You are moving toward GRC engineering and need to show you can build.
- You have no GRC experience yet and want a credential you can hold this year.
Weighing it against ISACA's audit credential? Read CISA vs CGRC. Working on federal authorization today? The FedRAMP compliance guide pairs well with CGRC study.
Does CGRC Raise Your Salary?
We are not going to quote a CGRC salary number, because there is no credible public survey that isolates it, and the figures that circulate online rarely name a source. What we can say: CGRC appears most often in federal and federal-contractor postings for authorization and assessment roles, where it can be listed as a preferred or required credential. To size the value in your market, filter current postings for CGRC, then compare pay ranges with similar roles that do not ask for it. That tells you more than any national average.
A Cheaper First Step for Commercial GRC
If the RMF focus does not match your job, the GRC Engineering Club is a lower-cost place to start. Membership includes the CGE-P, CGE-AUD, and CGE-AZ, with hands-on labs in AWS and Azure. An honest caveat: these credentials are newer, and they do not have CGRC's history with federal hiring managers. They do give you working artifacts to show, and they stack well with CGRC later.
What $70 a year gets you, CGRC candidate or not
Club membership is $70 per year, or $9.99 a month. Every certification in the Training Academy is included. Bought one at a time, the three current certifications are $350 each, so $1,050 of credentials come with a membership that costs less than most single exam vouchers.
- CGE-P, CGE-AUD, CGE-AZ: training, labs, exam, and certificate, no exam fee
- Hands-on AWS and Azure compliance labs you build in your own account
- Weekly private podcast and live Q&A with working GRC engineers
- Mock interviews, playbooks, and live builder sessions
- Local chapters and a Slack of 1,300+ GRC professionals
- Self-reported CPE hours for ISACA, ISC2, and IAPP renewals
Frequently Asked Questions
Is CGRC worth it?
CGRC is worth it if you work in or want to move into federal GRC, where the job is authorizing systems under the NIST Risk Management Framework. The exam content maps directly to that work. For commercial SOC 2 and ISO 27001 roles, CISA, CRISC, or a hands-on credential usually carries more weight for the same money.
How much does CGRC cost?
The CGRC exam costs $599 in the Americas as of September 2026. After you pass and are endorsed, ISC2 charges a $135 annual maintenance fee, which covers all of your ISC2 certifications. A realistic first-year total is about $750 self-study and up to $3,000 with a paid course.
What are the CGRC requirements?
CGRC requires two years of cumulative work experience in one or more of the seven CGRC domains. You can take the exam without the experience and become an Associate of ISC2, which gives you three years to earn it. To maintain CGRC you earn 60 CPE credits every three years, with at least 20 each year.
What is the CGRC exam format?
The CGRC exam has 125 items, multiple choice and advanced item types, with a three-hour limit. The passing score is 700 out of 1,000. The current exam outline took effect June 15, 2024 and covers seven domains, from governance and scoping through control assessment and compliance maintenance.
What is the CGRC salary?
There is no reliable public salary survey for CGRC holders specifically, so treat any single number with caution. CGRC shows up most often in federal and federal-contractor postings for ISSO, ISSM, and security control assessor roles. The best way to size it is to filter current job postings in your area for CGRC and compare them with similar postings that do not ask for it.
Is CGRC the same as CAP?
Yes. CGRC is the renamed ISC2 Certified Authorization Professional (CAP). The new name, Certified in Governance, Risk and Compliance, signals a broader GRC scope, and the exam keeps its roots in system authorization and the NIST Risk Management Framework.