You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The EC-Council Associate C|CISO certification equips cybersecurity professionals with the foundational knowledge required for information security leadership. Designed for aspiring C-suite leaders, it covers the five domains of the Certified CISO program, enabling candidates to support strategic decision-making and contribute to a CISO's office. This credential is a stepping stone to the full Certified CISO title.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The Associate CCISO Program is a professional certification that equips cybersecurity professionals with the fundamental knowledge required for information security leadership. It is designed specifically for candidates aspiring to become C-suite leaders by training them in the five domains of the Certified CISO (CCISO) program, even if they fall short of meeting the minimum five years of experience in three of the Certified CISO domains.
This certification empowers emerging information security officers to understand the roles and responsibilities necessary for security executives to effectively contribute to the functioning of a CISO's office. It guides their career paths toward leadership, allowing them to collaborate with and support CISOs in strategic decision-making regarding information security and risk management. By holding the Associate CCISO certification, cybersecurity officers demonstrate their commitment to continuous professional development and their readiness to take on leadership roles within a CISO's office.
The program serves as a stepping stone to obtaining the Certified CISO title and joining the global team of certified cybersecurity leaders. Candidates access the same courseware and training programs leveraged by seasoned professionals within the Certified CISO program, ensuring a consistent and rigorous learning experience.
The Associate CCISO certification is suitable for all cybersecurity professionals who possess either a minimum of two or more years of experience in any of the Certified CISO domains or currently hold certifications such as CISA, CISM, or CISSP. It is designed for those who aspire to leadership roles and want to understand the strategic, managerial, and operational aspects of information security management. This certification is ideal for individuals who want to map a career into the C-suite leadership path and gain the knowledge and professional experience needed to progress within their current capacities as information security managers.
A minimum of two years of technical or management experience in any of the five CCISO domains, or holding a relevant certification such as CISSP, CISM, or CISA. Two or more years of experience in Governance and Risk Management; Two or more years of experience in Information Security Controls, Compliance, and Audit Management; Two or more years of experience in Security Program Management and Operations; Two or more years of experience in Information Security Core Competencies; Two or more years of experience in Strategic Planning, Finance, Procurement, and Vendor Management
Every domain and objective EC-Council measures, with the weight they carry on the exam.
The official EC-Council exam outline · checked 30 July 2026 · See the source
Everything EC-Council publishes about sitting it, and nothing we inferred.
Have at least 2 years of technical or management experience in any of the following domains: Governance and Risk Management, Information Security Controls, Compliance, and Audit Management, Security Program Management and Operations, Information Security Core Competencies, or Strategic Planning, Finance, Procurement, and Vendor Management.
The path EC-Council lays out, how the credential is kept, and where to book.
Step-by-step path to EC-Council Associate C|CISO
This certification is currently active and available. EC-Council maintains this certification to validate current skills and industry relevance.
Register for the exam through Pearson VUE, EC-Council’s authorized testing partner.
Schedule your examVisit the official EC-Council certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksThe Associate CCISO program is directly derived from the Certified CISO certification program. It uses the same courseware and training program, covering the same five domains, but is designed for candidates who do not yet meet the five years of experience required for the full CCISO. It serves as a stepping stone to obtaining the Certified CISO title.
To obtain full Certified CISO status, candidates must meet the experience requirements by having a minimum of 5 years of experience in at least 3 of the 5 CCISO domains, earned while maintaining their Associate CCISO certification. After gaining the required experience, they complete a form to indicate their eligibility, which is verified. Once approved, they take the Certified CISO examination.
The Associate CCISO exam assesses candidates across two cognitive levels: Level 1 – Knowledge-based questions, which assess the ability to recall memorized facts, and Level 2 – Application-based questions, which assess the ability to understand and apply a given concept in different scenarios.
Yes, candidates are required to take the training and then pass the exam to obtain certification. The program offers access to the same courseware and training delivered to Certified CISO candidates.
The certification prepares cybersecurity professionals for leadership roles within a CISO's office, such as information security managers, and helps them progress toward executive security leadership positions. It validates their ability to handle complex information security management system challenges and manage security programs.
Yes, candidates have the option to retake the training prior to taking the Certified CISO examination. This is recommended because core training materials can change to maintain alignment with security industry changes.
Every domain, every objective, and every concept EC-Council measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official EC-Council exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
52 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 26 objectives, 218 concepts written under them, and free questions against every one. When EC-Council changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.