Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Critical Controls Certification

The GIAC Critical Controls Certification (GCCC) validates a practitioner's command of the CIS Critical Security Controls, a prioritized, risk-based approach to security. It is designed for security professionals, auditors, and risk officers who implement, execute, and audit these controls. Earning GCCC demonstrates you can operationalize standards and controls to effectively manage risk and defend your enterprise.

Exam formatMultiple choice
Duration120 minutes
DeliveryGIAC
Passing score71%
Free questions872

Content last reviewed 30 July 2026 · Up to date

The certification

What GIAC Critical Controls Certification proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

7domains
18objectives
152concepts
US $479exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The GIAC Critical Controls Certification (GCCC) validates a practitioner's command of the CIS Critical Security Controls: a prioritized, risk-based approach to security. GCCC certification holders have the knowledge and skills to implement and execute the CIS Critical Controls recommended by the Center for Internet Security, and to perform audits based on the standard.

The exam covers the background, purpose, implementation, and auditing of the 18 CIS Critical Security Controls (Version 8), including defenses, implementation groups, control sensors, policies, cloud guidance, tools, automation, control measures, and standards mapping for each control. Earning GCCC sets you apart as an informed defender able to operationalize standards and controls to effectively manage risk.

Who it’s for

The GCCC certification is for security professionals, auditors, CIOs, and risk officers who need to implement and audit the CIS Critical Security Controls. It is also valuable for information assurance auditors, system implementers and administrators, network security engineers, IT administrators, Department of Defense (DoD) personnel and contractors, federal agencies and clients, and security vendors and consultants. If your role involves operationalizing security standards, managing risk, or ensuring compliance with the CIS Controls, GCCC provides a recognized validation of your expertise.

Recommended experience

Practical work experience in security operations, auditing, or risk management is recommended to ensure mastery of the skills necessary for certification. Hands-on experience implementing or auditing security controls; Familiarity with the CIS Critical Security Controls or similar frameworks; Understanding of network security, system administration, or risk management concepts

The syllabus

What you’ll learn

Every domain and objective GIAC (SANS) measures, with the weight they carry on the exam.

The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source

Foundations and Governance
  • Background on CIS Controls, Standards, and Governance
  • Service Provider Management
2 objectives · 86 free questions · 18 pages
Asset Management and Configuration
  • Inventory and Control of Enterprise Assets
  • Inventory and Control of Software Assets
  • Secure Configuration of Enterprise Assets and Software
3 objectives · 151 free questions · 31 pages
Access and Identity Management
  • Access Control Management
  • Account Management
2 objectives · 94 free questions · 20 pages
Data Protection and Recovery
  • Data Protection
  • Data Recovery
2 objectives · 96 free questions · 20 pages
Security Operations and Monitoring
  • Audit Log Management
  • Continuous Vulnerability Management
  • Network Monitoring and Defense
  • Malware Defenses
4 objectives · 194 free questions · 40 pages
Application and Network Security
  • Application Software Security
  • Email and Web Browser Protections
  • Network Infrastructure Management
3 objectives · 157 free questions · 32 pages
Incident Response and Testing
  • Incident Response Management
  • Penetration Testing
2 objectives · 94 free questions · 20 pages
On the day

The exam itself

Everything GIAC (SANS) publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationGIAC Critical Controls Certification
Exam formatMultiple choice
Duration120 minutes
Questions75 questions
Passing score71%
DeliveryGIAC
LanguagesEnglish
PricingUS $479
After you pass

Where this credential goes next

The path GIAC (SANS) lays out, how the credential is kept, and where to book.

Step-by-step path to GIAC Critical Controls Certification

GIAC Critical Controls Certification badgeCredential earnedGIAC Critical Controls Certification Certification
Renewal and maintenance

GIAC certifications must be renewed every four years by earning 36 CPE credits or retaking the exam. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. GIAC (SANS) maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by GIAC (SANS)

Exam registration

Register for the exam through GIAC, GIAC (SANS)’s authorized testing partner.

Schedule your exam

Visit the official GIAC (SANS) certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the GCCC exam relate to the CIS Controls version 8?

The GCCC exam is aligned with the current release, CIS Controls V8, and covers the background, purpose, implementation, and auditing of the 18 CIS Critical Security Controls.

Is the GCCC exam hands-on or lab-based?

The GCCC exam is a standardized assessment with 75 questions and does not include a hands-on lab component. It objectively measures knowledge and hands-on cybersecurity skills against a validated standard.

What proctoring options are available for the GCCC exam?

All GIAC certification exams are web-based and proctored. You can choose remote proctoring through ProctorU or onsite proctoring through PearsonVUE.

How long do I have to complete my GCCC certification attempt after activation?

You have 120 days from the date of activation to complete your certification attempt.

What job roles does the GCCC certification map to?

GCCC is designed for security professionals, auditors, CIOs, risk officers, information assurance auditors, system implementers and administrators, network security engineers, IT administrators, DoD personnel and contractors, federal agencies and clients, and security vendors and consultants.

Can I recertify by passing a different GIAC exam?

GIAC certifications can be renewed by retaking the same exam or by earning 36 CPE credits over four years. Passing a different GIAC exam may also contribute to renewal, but specific policies should be confirmed in your GIAC account.

Are there practice tests available for the GCCC exam?

Yes, GIAC offers practice tests that simulate the real exam, allowing you to become familiar with the test engine and style of questions. Practice tests never include actual exam questions.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 872 questions, free, no account needed.