Breadth vs. the GRC function
ISC2 positions the CISSP as its flagship across the whole discipline and the CGRC as the specialist credential for governance, risk, and compliance work: framework selection, security authorization, control implementation and assessment, and continuous monitoring.
The CGRC grew out of the CAP, which was built almost entirely around the U.S. federal authorization process. The 2023 rename and subsequent outline broadened it toward frameworks generally, but its center of gravity remains framework-driven environments, with NIST RMF first among them.