If you searched “Certified Authorization Professional” and ended up more confused than when you started, you are not alone.
You search for CAP, land on a page calling it CGRC, and wonder if you missed a memo. You see a DoD 8570 reference and assume this is only for government workers. You clock the $599 exam fee and question whether any of it is worth it outside a federal job.
This guide answers all of it. You will learn what the Certified Authorization Professional actually is, what the name change means, who this certification fits, what the 7 domains cover in plain English, how it compares to CRISC, and whether it belongs in your certification plan.
Table of Contents
What Is the Certified Authorization Professional (CAP)?
The Certified Authorization Professional, or CAP, is an ISC2 certification that proves you can authorize and maintain information systems using the Risk Management Framework, known as the RMF.
The RMF is a structured, step-by-step process that organizations use to assess security risk across an IT system’s full lifecycle. Getting a system authorized means proving it is secure enough to operate. The CAP shows you know how to run that process, not just describe it.
The credential is vendor-neutral and confirms your knowledge of Governance, Risk and Compliance (GRC), including how to authorize and maintain information systems across various risk management frameworks.
You can verify the full credential details on the official ISC2 CGRC page.
CAP Is Now CGRC: What That Means for You
In 2023, ISC2 officially renamed the Certified Authorization Professional to the Certified in Governance, Risk and Compliance (CGRC). The domains, exam, and eligibility requirements stayed exactly the same. Only the name changed.
If you already hold the CAP, your credential is still valid. ISC2 automatically moved existing CAP holders over to the CGRC name. If you are preparing to sit the exam now, you are registering for the CGRC.
Both names are used throughout this guide since many job postings and training programs still use CAP, and both terms lead to the same certification.
Who Is the CAP/CGRC Certification Actually For?
This is an advanced-level certification built for IT professionals who authorize and maintain information systems as part of their actual job.
The people it fits best include IT security practitioners, risk officers, auditors, system owners, information system security officers, and senior system managers. If your work involves getting an IT system officially approved to operate within a regulated or government-adjacent environment, this credential was designed with your role in mind.
Do You Need to Work in Government to Benefit?
Not necessarily, but federal and government environments are where it carries the most weight.
The CAP/CGRC is the only security certification under the DoD 8570 Mandate that aligns with every step of the RMF. That mandate applies specifically to defense and federal environments, so if your work sits completely outside government, a credential like CRISC may be a better fit.
That said, private sector organizations that work with government contractors, healthcare systems, or heavily regulated financial institutions also recognize this certification. If your industry requires formal system authorization processes, CAP/CGRC speaks directly to that.
The 7 Domains of the CAP Certification, Explained Simply

Most pages just list the domain names. Here is what each one actually means in practice.
1. Information Security Risk Management Program This is the foundation. It covers how an organization builds and runs a risk management program, including the policies, roles, and overall structure that guides every risk decision.
2. Categorization of Information Systems Before protecting a system, you need to know how sensitive it is. This domain teaches you how to classify systems based on the data they hold and the potential impact if something goes wrong.
3. Selection of Security Controls Once you know a system’s risk level, you choose the right controls to protect it. This domain covers how to pick controls from NIST SP 800-53 and match the right protection level to the right system.
4. Implementation of Security Controls Selecting controls is only half the job. This domain covers how to put them in place, document them clearly, and confirm they are working as intended.
5. Assessment of Security Controls Controls need to be tested, not assumed. This domain covers how to evaluate whether the controls you implemented are actually doing their job, and how to document what you find.
6. Authorization of Information Systems This is the formal approval step. An authorizing official reviews the full security package and decides whether the system is ready to operate. This domain covers that review process from start to sign-off.
7. Continuous Monitoring Authorization is not a one-time event. This domain covers how to keep watching a system after it is authorized, catching changes that could introduce new risk over time.
CAP vs CGRC vs CRISC: What Is the Difference?

These credentials overlap in the GRC space but serve different environments. Here is how they compare side by side:
| Feature | CAP/CGRC (ISC2) | CRISC (ISACA) |
| Issuing body | ISC2 | ISACA |
| Core focus | System authorization within the RMF, federal and government context | Enterprise IT risk management and control |
| Best suited for | Government contractors, federal IT professionals, DoD environments | Risk managers, IT auditors, enterprise GRC professionals |
| Experience required | 2 years in at least 1 of 7 CAP domains | 3 years in risk management and IS control |
| Exam cost (US) | $599 | $575 to $760 depending on ISACA membership |
| DoD 8570 approved | Yes | No |
If your work involves authorizing IT systems for government or federal use, CAP/CGRC is the clearer fit. If your work is in enterprise risk management outside federal environments, CRISC covers that ground better.
Still mapping out which credential belongs where? Our cybersecurity certification roadmap breaks down the full sequence, so you spend money on the right exam at the right time.
CAP Certification Requirements and Exam Details
Experience Requirements
You need at least two years of cumulative, full-time, paid work experience in one or more of the seven CAP domains before you can apply for the certification.
If you do not have that experience yet, you can still sit the exam and earn the Associate of ISC2 designation while you work toward the full requirement.
Exam Cost and Format
The exam costs $599 in the US and the Americas. It covers all seven domains and tests your ability to apply RMF concepts practically, not just recall definitions from memory.
Most candidates spend eight to twelve weeks preparing, depending on how much hands-on RMF experience they bring in. Official ISC2 study materials and practice exams are the most reliable starting point.
Is the Certified Authorization Professional Certification Worth It in 2026?
If you work in federal IT, government contracting, or DoD environments, yes. This certification carries real weight in those spaces, and employers in those sectors actively look for it when filling system authorization roles.
If you work entirely outside government, the value depends on whether your organization runs formal RMF-style authorization processes. Some regulated industries do. If yours does not, a broader GRC certification like CRISC may be a better use of your time and $599.
The most honest advice here: check the job postings in your target market first. If CAP or CGRC appears in the requirements or preferred qualifications of roles you want, pursue it. If it does not appear at all, put that energy toward a credential that does.
Our free GRC analyst training roadmap covers the foundation worth building before you sit any GRC certification exam, including this one.
Final Thoughts
The Certified Authorization Professional certification, now called CGRC, is a focused credential for professionals who work with formal system authorization. It was never meant to be a general cybersecurity certification, and that specificity is exactly what makes it valuable in the right environment.
If your career sits in government contracting, federal IT, or DoD-adjacent work, this credential is one of the most relevant you can hold. If it does not match your environment yet, the right starting point is still building a solid GRC foundation first.
Build the Right GRC Certification Path
The right certification depends on where you work, where you are headed, and what the job postings you actually want require.
Book a one-on-one cybersecurity career session with Tolulope Michael and leave knowing exactly which certification belongs next on your list, before you spend $599 finding out the hard way.
One conversation saves months of second-guessing.
Is CAP certification worth it?
Yes, if your work involves federal IT systems, government contracting, or DoD environments. The CAP, now officially called CGRC, is recognized under the DoD 8570 mandate and carries real weight in those spaces. If your work sits entirely outside government, a broader GRC certification like CRISC may give you better return on that $599 exam fee.
Which security certification pays the most?
CISSP consistently ranks among the highest-paying cybersecurity certifications, with senior holders often earning well into six figures. CISM and CISA also command strong salaries, particularly in risk management and audit roles. Pay depends more on your experience, industry, and location than the certification alone, but these three appear most often at the top of salary surveys.
Which certification is best for cybersecurity?
There is no single best certification since the right one depends on your specialty and career stage. CompTIA Security+ is the strongest starting point for most beginners. From there, the best path branches by specialty, CGRC or CRISC for GRC, CySA+ for SOC work, OSCP for penetration testing, and CISSP for senior security leadership.
What is the highest security certification?
CISSP is widely considered the most prestigious general cybersecurity certification, requiring at least five years of paid work experience across two or more security domains plus a passing exam score. For GRC specifically, CGRC and CRISC sit at the advanced level. The “highest” depends on which area of security you work in.
How hard is the CAP/CGRC exam?
It is considered a challenging exam, not because the concepts are impossibly complex, but because it tests your ability to apply RMF principles practically rather than just recall definitions. Most candidates recommend at least eight to twelve weeks of consistent preparation, with hands-on RMF experience making a noticeable difference in how quickly the material clicks.
1 Comment
Aina
August 17, 2026Thank you for this.