Certified in Governance, Risk and Compliance
Capitalise on the rising demand for GRC expertise. The CGRC is a proven way to demonstrate your skills to integrate governance, performance management, risk management and regulatory compliance within your organisation.
Capitalise on the rising demand for Governance, Risk and Compliance (GRC) expertise by earning the CGRC certification. The CGRC is a proven way to demonstrate your knowledge and skills to integrate governance, performance management, risk management and regulatory compliance within your organisation.
CGRC professionals use frameworks to integrate security and privacy within organisational objectives, better enabling stakeholders to make informed decisions regarding data security, compliance, supply chain risk management and more.
Download the complete guide to the CGRC certification, exam and training pathways.
Guide to CGRC (PDF)Shows advanced technical skills and knowledge to protect, authorise and maintain information systems within various risk management frameworks.
Learners who don't pass the exam on their first attempt may access the same training again at no cost within one year from the end of the initial training. The guarantee covers the cost of the second course.
The CGRC exam covers seven domains.
The CGRC is ideal for IT, information security and information assurance practitioners in Governance, Risk and Compliance roles who need to understand, apply or implement a risk management program for IT systems — including those in roles such as:
To qualify, you must pass the exam and have at least two years of cumulative, paid work experience in one or more of the seven domains of the ISC2 CGRC Exam Outline.
With self-paced or online instructor-led training, there's an option to fit your schedule and learning style — reviewing the relevant domains and topics to prepare you for the rigorous CGRC exam.
Official ISC2 online self-paced CGRC training uses artificial intelligence to customise your learning journey — pinpointing the areas that need additional focus and guiding your exam prep in a way that's truly personalised. It covers the skills and knowledge for integrating governance, performance management, risk management and regulatory compliance within an organisation.
A Validation of Completion is issued on completion and remains valid for three years from the issue date. It may be used to prepare for professional certification, but does not demonstrate competency, establish expertise or imply licensing or accreditation in any field. To earn the CGRC certification, you must pass the exam and meet the experience requirements.
Live virtual learning led by an ISC2 Authorized Instructor — a CGRC-certified expert who brings the content to life through meaningful dialogue, real-world scenarios and integrated practice questions. Explore concepts and connect theory to real-world applications as you build the expertise required to design, implement and manage a best-in-class cybersecurity program.
*Access one week in advance of live virtual training to prepare.
Choose the schedule that works best for you — full-time (5 days) or part-time (7 weeks).
Applies to instructor-led purchases without an exam.
"Demonstrate your GRC expertise and help your organisation make informed, risk-based decisions with confidence."