- GCCC is a GIAC certification built on 19 objectives mapped to CIS Controls v8.
- The exam has 75 questions, a 2-hour limit, and requires a 71% score to pass.
- Certification attempts cost $999, with a 120-day access window and remote or onsite testing.
- Certification lasts four years; renewal needs 36 CPEs or a retake plus a $499 fee.
GCCC Certification Overview
The GIAC Critical Controls Certification (GCCC) is a vendor-neutral credential issued by GIAC, LLC that validates a practitioner's ability to implement, assess, and audit the CIS Critical Security Controls. Unlike broad cybersecurity certifications that survey dozens of unrelated topics, GCCC is deliberately narrow: it exists to prove you understand a specific, widely adopted defensive framework and can apply it in a real enterprise environment.
If you're asking "what is GCCC certification" for the first time, the short answer is this: it's a technical, controls-focused credential that sits at the intersection of security engineering and security governance. For a deeper dive into naming and background context, see our companion pieces on what is GCCC, GCCC meaning, and what does GCCC stand for.
Who Issues the GCCC and Why It Exists
GIAC (Global Information Assurance Certification) is the certifying body behind GCCC, and it maintains a reputation for exams that emphasize practical, job-ready skills rather than pure memorization. GCCC was created specifically to certify professionals against the CIS Critical Security Controls - a prioritized set of defensive actions originally developed by the Center for Internet Security and now maintained through community consensus.
Because CIS Controls v8 consolidated and reorganized earlier versions of the framework, GIAC updated the GCCC objectives to match. Anyone researching what is a GCCC credential holder should understand that the certification isn't just "know the controls" - it's "know how to implement, measure, and defend the rationale for each control inside an organization."
Exam Format and Registration Mechanics
The GCCC exam consists of 75 questions delivered in a 2-hour window, with a required passing score of 71%. Once you register, you receive a 120-day period to schedule and complete your attempt - this window matters for planning your study schedule, since it's a hard deadline, not a suggestion.
Testing can be completed two ways:
- Remote delivery via ProctorU, from a private space that meets GIAC's proctoring requirements.
- Onsite delivery via Pearson VUE testing centers, for candidates who prefer a controlled testing environment.
The exam is open book, but only for hardcopy references - printed books, printed notes, and tabbed course material. Electronic devices, PDFs, searchable files, internet access, and any material that closely resembles actual exam questions are explicitly prohibited. This detail changes how you should prepare: building a well-organized, indexed binder of notes is arguably as valuable as the studying itself. Our GCCC cheat sheet resource is designed with this exact open-book format in mind.
Key Takeaway
Because the exam is open-book for paper materials only, invest early in building a tabbed, indexed reference binder organized by domain - it will save you minutes per question during the timed exam.
For a complete walkthrough of eligibility and prerequisite expectations, see GCCC requirements, and for a precise breakdown of what the 71% threshold means in practice, check GCCC passing score.
The 19 GCCC Domains Explained
GIAC publishes 19 certification objectives for GCCC. Eighteen map directly to the CIS Critical Security Controls, and the nineteenth covers background, standards, and governance context. Understanding each domain's scope - not just its name - is the single most important part of preparing for this exam.
Domain 1: Access Control Management
Covers how organizations grant, restrict, and monitor access to systems and data.
- Least-privilege principles and access review cadence
Domain 2: Account Management
Focuses on lifecycle management of user, admin, and service accounts.
- Dormant account identification and deprovisioning
Domain 3: Application Software Security
Addresses secure development practices and vulnerability handling in software.
- Secure coding lifecycle and third-party software risk
Domain 4: Audit Log Management
Covers collection, retention, and review of audit logs across the enterprise.
- Centralized logging and time synchronization
Domain 5: Background on CIS Controls, Standards, and Governance
Explains the history, structure, and governance model behind CIS Controls v8.
- Implementation Groups (IG1/IG2/IG3) and how they scope controls
Domain 6: Continuous Vulnerability Management
Covers ongoing scanning, prioritization, and remediation of vulnerabilities.
- Risk-based patching timelines
Domain 7: Data Protection
Focuses on classifying, encrypting, and controlling sensitive data.
- Data flow mapping and retention policy alignment
Domain 8: Data Recovery
Covers backup strategy, testing, and recovery validation.
- Recovery time/point objectives in practice
Domain 9: Email and Web Browser Protections
Addresses hardening of the two most exploited client-side attack surfaces.
- DNS filtering and browser extension governance
Domain 10: Incident Response Management
Covers building and exercising a formal incident response capability.
- Roles, communication plans, and post-incident review
Domain 11: Inventory and Control of Enterprise Assets
Focuses on knowing what hardware exists on the network at all times.
- Asset discovery methods and unauthorized device detection
Domain 12: Inventory and Control of Software Assets
Parallel to Domain 11, but for authorized and unauthorized software.
- Allowlisting strategies
Domain 13: Malware Defenses
Covers anti-malware architecture and detection/response workflows.
- Behavioral vs. signature-based detection tradeoffs
Domain 14: Network Infrastructure Management
Focuses on secure configuration of routers, switches, and firewalls.
- Network segmentation rationale
Domain 15: Network Monitoring and Defense
Covers detection capabilities layered on top of infrastructure controls.
- Baseline traffic analysis and alert tuning
Domain 16: Penetration Testing
Covers structured testing programs that validate the other 17 controls.
- Purple team exercises and remediation validation
Domain 17: Secure Configuration of Enterprise Assets and Software
Focuses on hardening baselines across devices, servers, and applications.
- Configuration drift detection
Domain 18: Security Awareness and Skills Training
Covers building organization-wide human risk reduction programs.
- Role-based training design
Domain 19: Service Provider Management
Focuses on third-party and vendor risk across the security lifecycle.
- Contractual security requirements and ongoing vendor assessment
Because the exam blends questions across all 19 areas rather than isolating them, candidates often underestimate how interconnected these domains are - a scenario question might touch asset inventory, secure configuration, and vulnerability management simultaneously. Our GCCC exam domains guide breaks down weighting and study sequencing in far more depth than is possible here.
Who Hires GCCC Holders
GCCC tends to attract attention from organizations that have formally adopted or are migrating toward CIS Controls v8 as their security baseline - commonly regulated industries, government contractors, managed security service providers, and mid-to-large enterprises building out GRC or security engineering functions. Typical roles include security analyst, security engineer, compliance/GRC specialist, vulnerability management lead, and security program manager.
Because the certification proves fluency in a specific, auditable framework, it's often valued in roles where a candidate needs to speak directly to control implementation status during audits or assessments - not just describe security concepts abstractly. For a role-by-role look at where this credential shows up in job postings, see GCCC jobs, and for a broader discussion of career impact, read GCCC salary guide and is the GCCC certification worth it.
Cost Breakdown
GCCC pricing follows GIAC's standard structure:
| Item | Cost |
|---|---|
| Certification attempt | $999 |
| Retake attempt | $899 |
| GIAC practice exam | $399 |
| Renewal fee (with CPEs) | $499 |
These figures matter for planning: a single practice exam purchase adds meaningfully to your total spend, so many candidates treat their practice test preparation as a critical checkpoint before committing to the real attempt. For a full pricing breakdown including bundled training options, see GCCC certification cost.
Certification Validity and Renewal
GCCC certification is valid for four years from the date earned. To maintain it, holders must either accumulate 36 CPEs (continuing professional education credits) within that period or retake the current exam, and in either case pay the $499 renewal fee. This structure encourages holders to stay current as CIS Controls versions evolve - someone certified under an older objective set will eventually need to demonstrate familiarity with the latest version through renewal activity.
Planning CPE activity early (conference attendance, relevant training, or teaching) is far less stressful than scrambling in year four.
A Domain-Aligned Prep Timeline
Generic study techniques only go so far with a domain-heavy exam like this. What actually moves the needle is sequencing your review around domain difficulty and interdependence - asset inventory and account management concepts, for example, underpin several later domains.
Foundational Domains
- Inventory and Control of Enterprise Assets, Inventory and Control of Software Assets, Account Management, Access Control Management
Technical Defense Domains
- Secure Configuration, Malware Defenses, Network Infrastructure Management, Network Monitoring and Defense
Program and Governance Domains
- Continuous Vulnerability Management, Data Protection, Data Recovery, Background on CIS Controls, Standards, and Governance
Response, Assurance, and Full Review
- Incident Response Management, Penetration Testing, Service Provider Management, Security Awareness and Skills Training, plus full-length practice exams
This sequencing isn't arbitrary - it mirrors how the controls build on one another in real environments. For a more detailed, week-by-week study plan with source recommendations, read the full GCCC study guide, and if you're still weighing how challenging this exam actually is relative to other GIAC certs, see how hard is the GCCC exam.
Key Takeaway
Study foundational asset and account domains first - nearly every later domain assumes you already understand what's on the network and who has access to it.
Running timed practice sets that mimic the 75-question, 2-hour format is one of the most reliable ways to gauge readiness before exam day. Working through a full-length practice test under real time constraints exposes pacing issues long before they cost you points on the actual GCCC exam. If you want a broader look at how outcomes trend across candidates, our GCCC pass rate article discusses what the available data actually shows, without inflating numbers GIAC hasn't published.
Frequently Asked Questions
GCCC stands for GIAC Critical Controls Certification, a credential focused on the CIS Critical Security Controls. See our dedicated explainer on what does GCCC mean for more context.
The GCCC exam has 75 questions and must be completed within a 2-hour time limit, with a 71% score required to pass.
Yes, but only hardcopy references. Electronic files, internet access, and any materials resembling actual exam questions are prohibited.
GCCC is valid for four years. Renewal requires 36 CPEs or an exam retake, plus a $499 renewal fee.
You can test remotely through ProctorU or onsite at a Pearson VUE testing center, whichever fits your schedule and comfort level.
Whether you're just starting to research what is GCCC certification or you're deep into domain review, understanding the exact mechanics - the 19 objectives, the open-book rules, the fee structure, and the renewal cycle - gives you a realistic foundation for planning your attempt.