CISSP vs. CGRC

The CGRC (formerly CAP) is ISC2's specialist credential for governance, risk, and compliance work, built around security authorization and risk management frameworks. Same issuer as the CISSP, same membership system, sharply different scope. The comparison is really about which seat in the security organization a career occupies.

The short answer. The CISSP is ISC2's broad senior credential: eight domains, five years of experience, $749. The CGRC is ISC2's GRC specialist credential: seven domains centered on framework-based risk management and system authorization, two years of experience, $599. The CGRC dominates in federal and RMF-driven environments; the CISSP dominates everywhere senior. The CGRC also carries a one-year CISSP experience waiver.

§01

Side-by-side comparison

A quick reference of the differences in cost, requirements, exam format, and salary impact between the CISSP and the CGRC.

Attribute
CISSP ISC2
CGRC ISC2
Issuing Body
ISC2
ISC2
Exam Fee
$749 USD
$599 USD
Annual Maintenance
$135 USD AMF
$135 USD AMF
Experience Required
5 years in 2 of 8 domains
2 years in 1 of 7 domains
Exam Length
Up to 3 hours, 100–150 questions (CAT)
3 hours, 125 questions (linear)
Passing Score
700 / 1000
700 / 1000
Career Level
Mid to senior
Mid (GRC and authorization roles)
Scope
8 broad security domains
7 domains: risk management, authorization, continuous monitoring, frameworks
Associate Window
6 years to earn 5
3 years to earn 2
Average U.S. Salary
$130,000–$160,000
$100,000–$135,000
§02

Who should choose each certification?

The right choice depends on your role, your market, and where your career is heading.

CGRC Choose if
  • You work in federal, defense, or contractor environments running NIST RMF.
  • Your job is authorization packages, control assessment, and continuous monitoring.
  • You have around two years of experience and want an ISC2 credential gated accordingly.
  • You want a credential that also banks a one-year CISSP waiver for later.
§03

The detailed comparison

Section by section, how the two credentials actually differ in scope, requirements, cost, and the careers they serve.

Breadth vs. the GRC function

ISC2 positions the CISSP as its flagship across the whole discipline and the CGRC as the specialist credential for governance, risk, and compliance work: framework selection, security authorization, control implementation and assessment, and continuous monitoring.

The CGRC grew out of the CAP, which was built almost entirely around the U.S. federal authorization process. The 2023 rename and subsequent outline broadened it toward frameworks generally, but its center of gravity remains framework-driven environments, with NIST RMF first among them.

Two years and $599 vs. five years and $749

The CGRC requires two years of cumulative paid experience in one of its seven domains; the CISSP requires five years across two of eight. Both run on the same ISC2 machinery: endorsement, the $135 AMF, the code of ethics, and the Associate pathway for candidates short of the experience (three years to earn two for the CGRC).

The exams differ in format as well as breadth: the CGRC is a linear 125-question, three-hour exam, while the English CISSP is adaptive. Most dual holders describe the CGRC as the smaller undertaking, demanding in its domain but without the CISSP's integrated breadth.

The RMF world

In federal agencies, defense contractors, and the consulting practices that serve them, authorization work is a career in itself, and the CGRC is the credential built for it. It is DoD 8140 approved and reads as direct role fit for ISSO, assessor, and authorization-support positions.

Outside framework-driven environments the CGRC thins out quickly. Commercial postings rarely filter on it, and GRC roles in the private sector more often cite the CISSP, CISM, or CRISC. The credential's value is real and concentrated.

A specialist stop on the way to the flagship

The CGRC appears on ISC2's approved credential waiver list, revised April 1, 2026, so holding it removes one year from the CISSP's five-year requirement. For a GRC practitioner at two years of experience, the arithmetic is friendly: CGRC now, and a four-year effective CISSP requirement later.

ISC2's unified CPE system makes holding both inexpensive in effort: most activities count toward both credentials, and the AMF covers membership rather than stacking per certification.

Where each leads

The CGRC supports careers that deepen within GRC: senior assessor, authorization lead, GRC manager in framework-driven organizations. It certifies the function well and stops at the function's edge.

The CISSP supports careers that widen: engineering to architecture to leadership, GRC included but not bounded by it. The common long-run pattern for RMF-world practitioners is exactly the sequence the waiver suggests — CGRC in the early years, CISSP as the senior milestone.

Why the CISSP is the gold standard

If you can only hold one, choose CISSP for senior recognition and career durability.

01
The single biggest reason The CGRC certifies one function inside the security organization, and its market weight is concentrated in framework-driven environments. The CISSP certifies the whole discipline at the senior level and travels everywhere, including into GRC leadership. Same issuer, same maintenance machinery, but only one of them is the credential the broad senior market filters on.
02
Universal recognitionThe CISSP is listed as a requirement or preferred credential in more senior security postings worldwide than any other vendor-neutral certification, with 30+ years of established market value.
03
Career portabilityIts eight-domain breadth means the CISSP travels across industries, roles, and technology stacks without becoming obsolete or narrowly specialized.

The benchmark senior credential in cybersecurity since 1994.

§04

Salary comparison

Average U.S. base salary ranges for professionals holding each credential. Real compensation varies significantly by role, region, and years of experience.

CISSP

$130K – $160K

Senior security practitioner and management roles.

CGRC

$100K – $135K

GRC, ISSO, and authorization roles, strongest in federal and defense-adjacent environments.

Sources: ISC2 Cybersecurity Workforce Study, BLS, aggregated job-market data, 2026.

The bottom line

Specialist now, flagship at the milestone.

For practitioners working in RMF and authorization environments with around two years of experience, the CGRC is the right-sized purchase: role-fit credentialing at $599, ISC2 membership machinery, and a one-year waiver banked toward the CISSP. At the five-year mark (four, with the waiver), the CISSP is the move; it is the gold standard senior credential, and in ISC2's own catalog the CGRC is a stop along the way rather than a destination.

§05

Frequently asked questions

The CGRC is the renamed and broadened successor to the Certified Authorization Professional. The 2023 rename widened the framing from U.S. federal authorization specifically toward governance, risk, and compliance frameworks generally, though RMF-driven work remains its core audience.

Yes. The CGRC appears on ISC2's approved credential waiver list, revised April 1, 2026, removing one year from the CISSP's five-year requirement.

Most dual holders say yes: narrower scope, a linear exam format, and a two-year experience gate versus five. It is still a genuine ISC2 exam with a 700-out-of-1000 bar, not a formality.

Yes. Candidates who pass the CGRC exam without the two years of experience become Associates of ISC2 and have three years to earn the required experience.

The CGRC is strongest in framework-and-authorization environments, especially federal; the CRISC (ISACA) is the broader enterprise IT risk credential and carries more weight in commercial risk-management hiring. The environment doing the hiring usually decides it.