ISC2 Certification

ISC2 CGRC Practice Test

Use the free 20-question sets to find where your CGRC preparation is thin. Five mixed tests cover all seven domains; seven focused tests let you drill one domain at a time. Each set runs at roughly the same pace as 125 items in three hours.

12Free practice tests
240Total questions
7Current CGRC domains
700Exam pass standard / 1000

Mixed Set — ISC2 CGRC Practice Tests

Twenty questions spread across the current seven-domain outline. Use these as quick benchmarks before you decide which domain needs a focused pass.

Domain Wise — CGRC Practice Tests

One domain, twenty questions. These are for the gap you have already found, not for guessing which part of the blueprint deserves your time.

Twenty questions finds the weak domain.
125 questions tests the three-hour problem.

The free sets are built for diagnosis. The full-length series is for the point where you need a complete 125-question run across all seven domains, with the same 180-minute limit as the current CGRC exam.

 Free tests on this pageFull-length practice tests
Questions20 per test125 per test
Time limit~29 minutes180 minutes
CoverageMixed seven-domain set or one-domain drillAll seven domains in every test
Score you getShort-set practice resultFull 125-question practice result
Per-domain breakdownUse the seven focused tests to isolate a domainFixed 20 / 13 / 18 / 21 / 20 / 17 / 16 domain allocation
Choose-TWOShort practice format13 Select TWO questions per test
Exam conditionsTimed short setFull 180-minute run
ReportShort-set resultQuestion bank stores a written explanation with every item
Number available12 free tests · 240 questions10 full-length tests · 1,250 questions
PriceFreeFrom $4.99₹149£3.99€4.49 per test
See All 10 Full-Length CGRC Tests → 125 questions · 180 minutes · seven-domain blueprint

How to Use These Tests in a Study Plan

Use the short tests to decide what to study. Save the full-length work for when you need to test pacing and decision quality across an entire paper.

1

Benchmark

Take two mixed sets before a heavy revision block. Look for the same type of mistake appearing twice: scoping, control selection, assessment evidence, risk acceptance, or ongoing compliance.

Start with Practice Test 1 →
2

Drill the gap

Move to the matching domain test. Twenty questions from one area makes weak process knowledge much easier to spot than another mixed set would.

Start with Domain 4 →
3

Dress rehearsal

Once the domain gaps stop moving, run a full 125-question practice test. Three hours exposes a different problem: whether your judgement stays clean after question 90.

Get Full-Length Tests →

About the ISC2 CGRC Exam

The current CGRC exam outline took effect on 15 June 2024. The exam remains a 125-item, three-hour assessment across seven domains.

What is the CGRC?

CGRC stands for Certified in Governance, Risk and Compliance. ISC2 describes the credential around security risk management and information-system authorization in support of an organization's mission, legal obligations, and regulatory requirements. The certification was previously called CAP and was renamed CGRC in February 2023.

ISC2 lists CGRC as ANAB-accredited to ISO/IEC 17024 and approved under U.S. DoDM 8140.03. The current outline reaches beyond one framework: governance, risk, privacy, compliance, system scope, control selection, implementation, assessment, system compliance, and ongoing maintenance all sit inside the seven-domain blueprint.

Exam format

Items: 125.

Time: 3 hours.

Item format: Multiple choice and advanced item types.

Passing standard: 700 out of 1000 points. ISC2 does not report a numeric exam score after the exam.

Language: English.

Delivery: Pearson Testing Center.

Standard registration: U.S. $599 in the Americas and Asia Pacific. ISC2 lists separate GBP and EUR regional pricing.

Experience and maintenance

Experience: Two years of cumulative work experience in one or more current CGRC domains. Qualifying part-time work and internships can count.

Associate path: Pass first without the required experience and you can become an Associate of ISC2, with three years to earn the two years of relevant experience.

Application: The certification application must be completed within nine months of passing. An ISC2-certified member in good standing can endorse you, or ISC2 can provide endorsement after verification.

Maintenance: CGRC requires 60 CPE credits across the three-year cycle. The current ISC2 member AMF is U.S. $135 per year.

Retakes: 30 test-free days after the first attempt, 60 after the second, then 90 after the third and later attempts. Maximum four attempts for the same certification in 12 months.

CGRC Domain Weights

The seven weights below are the current ISC2 blueprint. Domain 4 is the largest at 17%; Domain 2 is the smallest at 10%.

DomainTopicWeight
Domain 1Security and Privacy Governance, Risk Management, and Compliance Program16%
Domain 2Scope of the System10%
Domain 3Selection and Approval of Framework, Security, and Privacy Controls14%
Domain 4Implementation of Security and Privacy Controls17%
Domain 5Assessment/Audit of Security and Privacy Controls16%
Domain 6System Compliance14%
Domain 7Compliance Maintenance13%

How Our CGRC Practice Tests Are Written

Written to the current seven-domain outline. The questions are original and mapped to the CGRC blueprint effective 15 June 2024. No live exam content is reproduced.

Process before trivia. CGRC questions make more sense when you can see where a decision belongs: scope the system, select controls, implement them, assess the evidence, make a compliance decision, then keep the system compliant as it changes. The free sets are written around that judgement.

Mixed sets and focused sets do different jobs. A mixed 20-question set gives you a fast cross-domain check. A domain test removes the noise and asks whether you actually understand one part of the lifecycle.

The short format has a limit. Twenty questions can expose a gap. It cannot reproduce the concentration load of 125 items over three hours. That is why the full-length series exists.

CGRC Exam Preparation Tips

Study strategy

Learn the seven domains as a flow. Do not study Domain 3 control selection as if it were detached from system scope, implementation evidence, assessment findings, and the eventual compliance decision. CGRC keeps asking who acts, what evidence exists, and what should happen next.

Spend time in proportion to the blueprint. Domains 1, 4 and 5 account for 49% of the outline. They deserve more study time than Domain 2 at 10%, but none of the seven can be ignored.

Know the artifacts by purpose. Policies, system descriptions, control documentation, assessment evidence, risk-response records, and compliance decisions are easier to remember when you know who needs them and at which stage.

Test-taking strategy

Do not plan on coming back later. ISC2 says candidates cannot skip a question and return to it on either linear or adaptive exams. Make your best decision while the item is in front of you.

Budget the full three hours. 180 minutes for 125 items is about 86 seconds per item on average. Some questions will be faster. The long scenario is where you need enough reserve to think instead of rushing.

Choose the answer that fits the process. Several options may sound technically reasonable. The better CGRC answer is often the one that respects scope, authority, evidence, documented risk decisions, and the correct point in the compliance lifecycle.

Frequently Asked Questions

How many items are on the current CGRC exam?+

125 items in three hours. ISC2 lists the format as multiple choice and advanced item types, and the exam is available in English at Pearson Testing Centers.

The passing standard is 700 out of 1000 points. ISC2 does not provide candidates with a numeric exam score after the exam. Candidates who do not pass receive domain proficiency information instead.

ISC2 currently lists standard CGRC registration at U.S. $599 for the Americas and Asia Pacific. Regional GBP and EUR pricing is listed separately for the UK and EMEA.

Yes. The full-length CGRC practice tests contain 125 questions in 180 minutes, with all seven domains represented in every set. There are 10 separate tests, 1,250 questions in total, and each full-length test includes 112 single-answer questions plus 13 Select TWO questions. Prices start at $4.99₹149£3.99€4.49.

Yes. The five mixed sets and seven domain-wise tests linked on this page are free, giving you 12 short practice tests and 240 questions in total.

No. ISC2 says neither its linear nor adaptive computer-based exams allow candidates to skip a question and return later. Finalize the best answer you can before moving on.

After the first attempt, wait 30 test-free days before retesting. After the second attempt, wait 60 days. After the third and later attempts, wait 90 days. ISC2 allows up to four attempts for the same certification program in a 12-month period.

You can pass the exam before meeting the experience requirement. Full CGRC certification requires two years of cumulative work experience in one or more current CGRC domains. If you pass without it, you can become an Associate of ISC2 and have three years to earn the required experience.

Domain 1 is 16%, Domain 2 is 10%, Domain 3 is 14%, Domain 4 is 17%, Domain 5 is 16%, Domain 6 is 14%, and Domain 7 is 13%. These weights come from the current outline effective 15 June 2024.

CGRC requires 60 CPE credits across a three-year certification cycle. ISC2 currently charges certified members who hold CGRC or its other professional certifications a U.S. $135 Annual Maintenance Fee.

Find the gap short. Test the full three hours when you are ready.

Start with a free 20-question mixed set. When your domain mistakes stop repeating, move to a full 125-question paper and see whether your decisions still hold together at the end of the session.

CGRC exam details reflect ISC2's current exam outline, pricing, experience, maintenance, scoring, and retake policies reviewed September 2026. Current CGRC outline effective 15 June 2024.

Authors

  • Security Practice Test Editorial Team

    Security Practice Test Editorial Team is the expert content team at SecurityPracticeTest.com dedicated to producing authoritative cybersecurity certification exam-prep resources. We create comprehensive practice tests, study materials, and exam-focused content for top security certifications including CompTIA Security+, SecurityX, PenTest+, CISSP, CCSP, SSCP, Certified in Cybersecurity (CC), CGRC, CISM, SC-900, SC-200, AZ-500, AWS Certified Security - Specialty, Professional Cloud Security Engineer, OSCP+, GIAC certifications, CREST certifications, Check Point, Cisco, Fortinet, and Palo Alto Networks exams. Our content is developed through careful review of official exam objectives, cybersecurity knowledge domains, and practical job-relevant concepts to help learners build confidence, strengthen understanding, and prepare effectively for certification success.

  • Sudhanshu Thakur - Reviewer

    Enterprise Technology and Digital Transformation Professional with 18+ years of experience in enterprise software, SaaS, industrial automation, and business consulting. Formerly associated with Rockwell Automation, Tech Mahindra, Emerson, ABB, L&T Infotech, and Hewlett Packard Enterprise.