Skip to main content
Cybersecurity

(ISC)² CGRC

ISC2 governance / risk / compliance cert (formerly CAP). Narrow but credible in federal / regulated markets.

DifficultyIntermediate
Study3–6 months
Exam (indicative)£455 member / £600 non-member
Valid3 years

Vendor record

This entry has not yet been read against the vendor's own documentation. Exam names, codes and prices shown on this page are indicative; check the vendor before booking anything.

Compare
POST verdict

Workable

Market-level call. Not personal advice.

The ISC2 GRC track, formerly CAP. Useful in FedRAMP-adjacent and federally-shaped engagements, narrow in pure UK regulated hiring.

Confidence
Medium
Signal
Low
Why this confidence
The CAP-to-CGRC rebrand muddied the signal. Hiring managers familiar with CAP recognise the lineage; newer hires often don't, and ISC2's own marketing has not closed the gap.
Why this signal strength
Strong inside US federal contracting and consultancies servicing FedRAMP, FISMA or NIST RMF engagements. Weak in pure UK private-sector GRC hiring, where CRISC and ISO 27001 lead credentials carry more weight on panels. The vendor-neutral-cloud-security-recognition-gap pattern compounds outside FedRAMP-shaped engagements where the rebrand is best known.
Who this pays off for
  • GRC analysts at UK consultancies servicing US federal contracts, FedRAMP submissions or NIST RMF-aligned engagements
  • Risk and compliance professionals in defence prime contractors where US partner work brings NIST 800-53 control mapping into scope
  • Career changers from technical backgrounds wanting an ISC2 credential adjacent to CISSP that focuses on authorisation packages and control assessment
Who walks away with nothing
  • A direct CRISC competitor. CRISC sits on UK FCA and PRA second-line risk JDs; CGRC does not in any consistent way
  • An ISO 27001 implementation credential. CGRC is RMF and assessment-shaped; ISO LA and LI sit closer to UK ISMS hiring
  • A standalone GRC career credential in UK hiring. Without CISSP or domain reps the rebrand makes the line item harder, not easier, to read on a CV
The named failure mode

The CAP-rebrand-confusion pattern. Candidates list CGRC expecting recognition, then sit interviews where the hiring manager doesn't know it's the renamed CAP and treats it as an unfamiliar GRC credential without ISACA-grade weight.

Recruiter signal, not marketing

Direct credibility on FedRAMP, NIST RMF and authorisation-package work at UK consultancies and defence primes with US-aligned scope. Sits naturally alongside CISSP for assessment-track GRC professionals. Does not substitute for CRISC in UK finance second-line risk hiring, and does not displace ISO 27001 LA or LI in UK ISMS implementation roles.

Falsifiability
  • ISC2 invests in UK market recognition for the CGRC brand to a level where private-sector hiring panels treat it as a screened credential
  • UK defence and government supplier frameworks explicitly reference CGRC competencies as part of supplier assurance requirements
  • FedRAMP-style assurance regimes spread into UK regulated cloud procurement, widening the addressable market for RMF-shaped GRC credentials

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • Federal/regulated GRC roles
  • Risk analyst shortlists
Practitioner take

CGRC (formerly CAP) is the (ISC)² governance, risk and compliance cert and its weight in the UK comes from the (ISC)² brand rather than the syllabus itself. The exam covers the NIST RMF in detail, which is genuinely useful if you're heading into US federal or FedRAMP-adjacent work and largely background reading otherwise. Take it when you're already in a GRC seat inside a regulated industry and your employer asks for an (ISC)² credential beyond CISSP. Skip it as a generalist GRC cert. ISO 27001 Lead Implementer carries further in UK-only ISMS work, and CISA carries further in audit.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • GRC or risk experience

Common misconceptions

  • (ISC)² CGRC alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Operational security roles

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.