Want a sequenced plan instead of a list? Join the structured learning tracks

ISC2 CGRC

ISC2 Certified in Governance, Risk and Compliance (formerly CAP)

GRC Intermediate ISC2
Target job title
GRC Analyst / Authorization Officer (RMF)
Level
Intermediate. Assumes fundamentals and some hands-on time; typical first-job or first-promotion certs.
Prerequisites
2 years of paid experience in at least one of the CGRC domains.
Official page
ISC2

Recent updates

Renamed from CAP. Also listed as a qualifying credential for ISACA's AAIR.

Reviewed 2026-10-02. Source. Confirm exam details on the official page before booking.

Where it sits in GRC

  1. Intermediate CISA ISC2 CGRC ISO 27001 Lead Implementer ISO 27001 Lead Auditor CIPP/E AIGP
  2. Advanced CRISC AAIA AAIR

Natural next steps: CRISC, AAIA, AAIR.

Preparing for ISC2 CGRC?

Structured learning tracks

Membership with role- and cert-based learning tracks: roadmaps, cheat sheets, assessments, exclusive writeups and member pricing on notes.

Join the learning tracks

Coaching & cert roadmaps

One-to-one guidance and a roadmap built around your background, target role and timeline, so you stop guessing which cert comes next.

See coaching programs

Prep resources & cheat sheets

Cheat sheets, command references and exam-day extras for when you already know the material and need it fast and in one place.

Browse prep resources