GCCC logo
Focused certification exam prep
Start practice

GCCC Passing Score 2026: Exactly What You Need to Pass

TL;DR
  • GCCC requires a 71% passing score on 75 questions within a 2-hour window.
  • All 19 objectives, including 18 CIS Controls plus governance, are fair game - there's no domain to skip.
  • A retake costs $899, so treating 71% as a bare minimum target instead of a buffer is risky.
  • Open-book access is limited to hardcopy references only - no PDFs, no browser tabs.

The 71% Number: What It Actually Means

GIAC sets the GCCC passing score at 71%. On a 75-question exam, that translates to roughly 53 correct answers out of 75 - you can miss around 22 questions and still pass. That sounds forgiving until you realize the exam draws from 19 published objectives spanning all 18 CIS Critical Security Controls plus a background/governance domain. There's no single weak area you can write off; a bad day on Network Monitoring and Defense combined with shaky recall on Data Recovery can add up fast.

Unlike some certifications where the passing threshold is buried or vague, GIAC publishes this number directly, which is useful for planning. But a published number doesn't tell you where the points are concentrated or how the exam behaves under time pressure - that's where most candidates misjudge their prep. For a broader look at how tough the exam actually feels in practice, the GCCC difficulty guide breaks down candidate experiences beyond just the score.

Quick Math: 71% of 75 questions is approximately 53.25, which GIAC rounds to a minimum of 53 correct answers. Missing 22 or fewer questions still results in a pass.

How GCCC Scoring Works

The GCCC exam is scored as a single composite percentage - there is no separate pass/fail requirement per domain. This matters strategically: a candidate who is excellent at Access Control Management and Account Management but weaker on Penetration Testing can still pass, as long as the overall percentage clears 71%. GIAC does not publish a domain-by-domain breakdown score on your results, only the composite outcome and overall performance indicators.

This composite structure means your prep time should be allocated by a combination of two factors: how heavily a domain is likely to be tested, and how unfamiliar it currently is to you. Domains you already understand from hands-on work (say, you already run vulnerability scanning tools daily) need less review time than domains that are purely conceptual to you, like Service Provider Management or governance frameworks.

Key Takeaway

Because scoring is composite, not per-domain, spend disproportionate time shoring up your weakest 3-4 domains rather than polishing domains you already know well.

Domain Weighting and Where Points Come From

GIAC does not publish exact percentage weights for each of the 19 objectives, so treat every domain as testable. The full list includes:

The 19 GCCC Objectives

  • Access Control Management
  • Account Management
  • Application Software Security
  • Audit Log Management
  • Background on CIS Controls, Standards, and Governance
  • Continuous Vulnerability Management
  • Data Protection
  • Data Recovery
  • Email and Web Browser Protections
  • Incident Response Management
  • Inventory and Control of Enterprise Assets
  • Inventory and Control of Software Assets
  • Malware Defenses
  • Network Infrastructure Management
  • Network Monitoring and Defense
  • Penetration Testing
  • Secure Configuration of Enterprise Assets and Software
  • Security Awareness and Skills Training
  • Service Provider Management

Since 18 of these map directly to the CIS Controls v8 framework and one covers background and governance, a practical approach is to group them by operational theme rather than study them in the order GIAC lists them. For example:

Asset and Software Foundations

Inventory and Control of Enterprise Assets, Inventory and Control of Software Assets, and Secure Configuration of Enterprise Assets and Software form the base layer of CIS Controls v8. Questions here often test whether you understand why asset visibility precedes every other control.

  • Know the difference between "control" and "inventory" scope in CIS language

Detection and Response Cluster

Audit Log Management, Network Monitoring and Defense, Malware Defenses, and Incident Response Management overlap conceptually. Expect scenario questions that ask you to identify which control failed when an incident occurred.

  • Understand how logging feeds into incident response timelines

For a domain-by-domain breakdown with more detail on what each objective actually tests, the complete guide to all 19 content areas is worth reviewing alongside your CIS Controls documentation.

Question Format and Why It Affects Your Score

The GCCC exam is 75 questions with a 2-hour time limit, which averages out to a bit over 90 seconds per question. That pace matters for scoring strategy: spending four minutes agonizing over one Penetration Testing question can cost you the time needed to answer three easier Account Management questions correctly. Since scoring is composite, an easy correct answer is worth exactly as much as a hard one.

GIAC's questions on this exam tend to be scenario- and application-based rather than pure definition recall - you're often asked to identify the correct control implementation given a described environment, or to sequence steps in a control's safeguard. This format rewards candidates who understand the "why" behind each CIS Control, not just its name and number.

Pacing Tip: With 75 questions in 120 minutes, aim to complete a first pass of all questions within about 90 minutes, flagging uncertain ones, leaving 30 minutes to revisit flagged items.

The Open-Book Factor

GCCC is open book, but only for hardcopy references - printed books, printed notes, and physical index cards are allowed. Electronic files, internet access, and any material that resembles actual exam questions are explicitly prohibited, whether you test remotely through ProctorU or onsite through Pearson VUE. This distinction changes how you should prepare your references compared to fully closed-book certifications.

Because you can't search a PDF or ctrl+F your notes during the exam, the organization of your printed materials directly affects your effective time budget. A well-indexed binder organized by the 19 objectives - with tabs matching domain names like Data Protection, Email and Web Browser Protections, and Network Infrastructure Management - will save you real minutes compared to a generic printout of the CIS Controls document.

Key Takeaway

Build your index/cheat sheet around the exact 19 objective names so you can flip to the right tab in seconds during the exam. A prebuilt reference like the one-page review of must-know facts can serve as a starting template.

A Domain-Ordered Study Plan

You have a 120-day attempt window from registration, which is generous but disappears quickly if you don't map domains to weeks early. Below is a sample sequencing that groups related domains together rather than studying them in random or alphabetical order.

Weeks 1-2

Foundations and Governance

  • Background on CIS Controls, Standards, and Governance
  • Inventory and Control of Enterprise Assets
  • Inventory and Control of Software Assets
Weeks 3-4

Access and Identity

  • Access Control Management
  • Account Management
  • Secure Configuration of Enterprise Assets and Software
Weeks 5-6

Detection, Data, and Recovery

  • Audit Log Management
  • Continuous Vulnerability Management
  • Data Protection
  • Data Recovery
Weeks 7-8

Network and Endpoint Defense

  • Network Infrastructure Management
  • Network Monitoring and Defense
  • Malware Defenses
  • Email and Web Browser Protections
Weeks 9-10

Application, Human, and Third-Party Risk

  • Application Software Security
  • Security Awareness and Skills Training
  • Service Provider Management
  • Penetration Testing
  • Incident Response Management
Weeks 11-12

Full Review and Timed Practice

  • Rebuild your hardcopy index by objective
  • Run timed practice sets to build 90-second-per-question pacing
  • Revisit your weakest 3-4 domains identified in earlier weeks

This sequencing spreads familiar operational topics (asset inventory, access control) early, when motivation is highest, and saves the more scenario-heavy domains like Penetration Testing and Incident Response Management for once you've built the underlying vocabulary. For a more detailed week-by-week methodology, see the study guide for passing on your first attempt.

Retake Math: Cost of Missing 71%

The financial structure around GCCC makes the 71% threshold worth taking seriously beyond just the accomplishment itself. A certification attempt costs $999, and a retake costs $899 - nearly the same as starting fresh. A GIAC practice exam runs $399 if you want an official gauge of readiness before test day. Falling a few points short of 71% doesn't just cost time; it costs another several hundred dollars.

ItemCost
Certification Attempt$999
Retake Attempt$899
GIAC Practice Exam$399
Renewal (per 4-year cycle)$499

Given this, many candidates treat the $399 official practice exam as insurance rather than an optional extra - it's a way to validate readiness before committing to the full $999 attempt. If you want a full picture of every fee involved, including renewal and CPE maintenance costs, the complete pricing breakdown lays it out. And if you're still deciding whether the investment makes sense for your career stage, the ROI analysis is a useful companion read.

Aim Above the Minimum: Because scoring is pass/fail with no partial credit for "almost passing," build your study plan to target comfortably above 71% - not exactly at it. A buffer protects against exam-day anxiety, unfamiliar phrasing, or fatigue in the final 15 minutes.

It's also worth checking how this passing bar compares to outcomes other candidates report. The GCCC pass rate data gives context on how the 71% threshold plays out across the broader candidate pool, and combined with practice testing on our GCCC practice test platform, you can get a realistic sense of where you stand before spending exam-day money.

FAQ

What is the exact GCCC passing score?

GIAC sets the GCCC passing score at 71%. On the 75-question exam, that means approximately 53 correct answers are needed to pass.

Is the GCCC passing score the same across all 19 domains?

Scoring is composite across the full exam, not domain-by-domain. You need an overall 71%, so strength in one domain can offset weakness in another, as long as the total clears the threshold.

How many questions can I miss on the GCCC exam?

With 75 total questions and a 71% passing score, you can miss roughly 22 questions and still pass, since you need about 53 correct answers.

Does GIAC allow electronic references during the GCCC exam?

No. The exam is open book for hardcopy references only. Electronic files, internet access, and any materials resembling exam questions are prohibited during both ProctorU remote and Pearson VUE onsite delivery.

What happens if I don't reach 71% on my first attempt?

You would need to schedule a retake, which costs $899. Reviewing your weakest domains and considering the $399 official practice exam before a retake can help avoid a second missed attempt.

Understanding the 71% threshold is only half the equation - knowing exactly which of the 19 objectives to prioritize, how the eligibility and registration process works, and what roles actually value this credential rounds out the picture. For more on that side of the certification, see the eligibility and prerequisites guide, the GCCC jobs overview, or start practicing directly on the GCCC practice test homepage.

Ready to pass your GCCC exam?

Put this into practice with free GCCC questions across every exam domain.