- What the Certified FISMA Compliance Practitioner Credential Is
- Exam Format and What Is Still Unpublished
- The 22 Subjects, Grouped by Compliance Lifecycle Stage
- RMF Steps Are Not Exam Domains
- Legacy Frameworks in the Curriculum
- FISMA101 Course, Voucher and Study Materials
- The Experience Requirement After You Pass
- Scenario Skills the Assessment Rewards
- Who Benefits From the Credential
- Sequencing Your Preparation
- Frequently Asked Questions
- The Certified FISMA Compliance Practitioner credential is administered by the FISMA Center, not by NIST or a general IT certification body.
- The published exam is 100 multiple-choice and true/false questions with a 170-minute limit.
- The reviewed pages do not state a passing score, so avoid trusting any specific cut score you see quoted elsewhere.
- Certification also requires one year of FISMA compliance experience, verified after you pass the exam.
What the Certified FISMA Compliance Practitioner Credential Is
The CFCP covered on this site is the Certified FISMA Compliance Practitioner credential, administered by the FISMA Center. It is a federal information-security compliance credential. Its assessment centers on three abilities: defining and testing security controls, interpreting the results of that testing, and recommending risk-based corrective action. If you are searching for a general explanation of the acronym, our pages on what CFCP is and what CFCP stands for cover the naming, and this article focuses on how the certification itself works.
The acronym is shared with several unrelated credentials in other industries. Everything here applies only to the FISMA credential. If you came looking for a different certification with the same letters, the exam format, fees, and content described here will not apply to it.
The FISMA Center also provides FISMA training for federal agencies, universities, and private companies, which tells you something about the intended audience. The credential is aimed at people who actually produce and evaluate compliance artifacts: security plans, assessments, contingency documents, and certification packages. It is less about memorizing vendor products and more about understanding how a federal system moves from categorization through authorization-style documentation and into ongoing remediation.
Exam Format and What Is Still Unpublished
The current public issuer exam specifications describe 100 multiple-choice and true/false questions with a 170-minute limit (two hours fifty minutes). That works out to roughly a minute and forty seconds per question on average, which is generous for true/false items and adequate for scenario-based multiple-choice items that require you to read a short system description and pick the best action.
Equally important is what the reviewed issuer pages do not say. They do not specify:
- A passing threshold or cut score
- How many questions are scored versus unscored
- Whether the exam is open-book or closed-book
- The proctoring arrangement
- Official weighted domain percentages
Treat any site claiming an exact passing percentage or domain weighting for this exam with caution unless it cites the issuer. We cover the open question in more depth on our CFCP passing score page. Registration and appointment arrangements should be confirmed directly with the issuer at fismacenter.com, since offerings are described as tentative for 2026. For scheduling logistics, see CFCP exam dates, and for pricing context see CFCP certification cost.
The 22 Subjects, Grouped by Compliance Lifecycle Stage
The issuer's FISMA101 course outline lists 22 unweighted subjects: 11 under Day 1 and 11 under Day 2. These are course subjects, not an official weighted blueprint, and the issuer's exhaustive exam coverage is not verified. Still, they are the best public indicator of what a candidate should be able to handle. Reading them as a lifecycle rather than a flat list makes them far easier to retain. For a deeper walkthrough, see our complete guide to all 22 CFCP content areas.
Foundations: terminology, methods and program setup
Explanation of FISMA Terminology; FISMA Compliance Methodologies
These two subjects establish the vocabulary and the approaches used to achieve compliance. Candidates should be fluent in the language agencies use when discussing systems, controls, and authorization artifacts.
- Be able to distinguish between terms that sound similar but mean different things in a compliance document
- Understand that multiple methodologies exist and be able to compare them
Understanding the Process and Risk Management Framework (RMF); Establishing an Information Security Program; FISMA Project Management
This group covers how compliance work is organized: the RMF process, the security program that houses it, and the project discipline needed to deliver artifacts on schedule.
- Know how the RMF process fits into a broader information security program
- Understand compliance as a managed project with roles, deliverables, and milestones
Scoping the system: information types, inventory and categorization
Determining the Information Types & Sensitivity Level; Preparing the Hardware and Software Inventory; FIPS 199: Categorizing Data Sensitivity
Nearly every downstream decision depends on these three. If you misidentify information types or build an incomplete inventory, the categorization is wrong and every control choice after it inherits the error.
- Practice working from a system description to a list of information types
- Know how FIPS 199 categorization expresses impact for confidentiality, integrity, and availability
- Understand why an accurate hardware and software inventory is a prerequisite for assessment
People and operations: awareness, behavior and incidents
Security Awareness Training; Rules of Behavior; Incident Response
These subjects cover the human and operational side of compliance. Expect questions about what must be documented, who must acknowledge what, and how incidents are handled.
- Know the purpose of rules of behavior and how they differ from awareness training
- Understand incident response as a documented, repeatable capability
Testing and risk: assessments across privacy, business and system levels
Performing Security Testing; Conducting a Privacy Impact Assessment; Performing a Business Risk Assessment; Performing a System Risk Assessment
This cluster maps most directly onto the credential's stated assessment focus: defining and testing controls and interpreting the results. Note that business risk and system risk are separate assessments with different scopes.
- Practice interpreting a test result and deciding whether it indicates a finding
- Know what triggers a privacy impact assessment and what it examines
- Distinguish business-level risk from system-level risk
Planning for resilience: impact, contingency and configuration
Preparing a Business Impact Assessment; Developing an IT Contingency Plan; Developing a Configuration Management Plan
The business impact assessment feeds the contingency plan, and the configuration management plan keeps the system's documented baseline aligned with reality. Understanding these dependencies helps with scenario questions.
- Trace how a business impact assessment informs contingency priorities
- Understand why configuration control matters for continued compliance
Documenting and closing out: the plan, the package and the findings
Developing a System Security Plan; Submitting the Certification Package; Evaluating the Certification Package; Addressing Compliance Findings
The final four subjects cover the capstone artifacts and what happens after review. The credential's emphasis on risk-based corrective action shows up most clearly in remediation of findings.
- Know what a system security plan must contain and why it anchors the package
- Understand the difference between preparing a package and evaluating one
- Be prepared to recommend corrective action that is proportionate to risk
RMF Steps Are Not Exam Domains
One of the most common mistakes is assuming the exam is organized around the seven steps of NIST's Risk Management Framework. It is not. The RMF is a risk-management process; the exam subjects are listed above. The two overlap in themes, since categorization, control selection, assessment, and monitoring all appear in both, but memorizing the seven steps in order will not substitute for studying the 22 subjects.
Legacy Frameworks in the Curriculum
The published curriculum surveys NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503, and FedRAMP. Several of these are best understood as comparative or historical approaches rather than a claim that every method is current policy. That distinction matters in practice:
| Item in curriculum | How to treat it while studying |
|---|---|
| NIST | Primary source for current federal guidance and publications |
| DoD RMF | Defense-sector application of risk management; verify current policy against primary sources |
| FedRAMP | Federal cloud authorization program; check current official materials for present-day details |
| DIACAP, DCID 6/3, ICD 503 | Treat as comparative and historical context; do not assume they describe current requirements |
When a question or reference touches present-day compliance facts, rely on current primary NIST and federal materials. When it touches the older approaches, think of them as a way to understand how the field evolved and why current methods look the way they do.
FISMA101 Course, Voucher and Study Materials
The issuer's examination page recommends its courses, resource pages, and the FISMA Compliance Handbook, Second Edition as preparation. Course attendance is not mandatory. That said, the course is central to how the issuer packages the credential:
- FISMA101 is a two-day course, with six CPE credits per day and twelve in total.
- The course page advertises tentative 2026 offerings and includes an exam voucher.
- A CFCP study guide is supplied only to course students.
Be careful with the CPE figures. The twelve CPE credits describe the course's instructional value; they are not the exam timer, a count of exam questions, or a renewal obligation. We have not accessed the private study guide, so any claims about its contents should be verified with the issuer. For an overview of preparation options, see our CFCP training page and the broader CFCP study guide.
The Experience Requirement After You Pass
Certification requires one year of FISMA compliance experience, verified after passing the exam. This sequencing is unusual and worth planning around. Passing the exam is not the final step; the credential is conferred once the experience is verified. Candidates who are early in their careers should understand that their path to the full credential may extend beyond exam day. Our CFCP requirements guide goes into eligibility and qualification details, and you should confirm the current verification process with the issuer.
Scenario Skills the Assessment Rewards
Because the credential emphasizes defining and testing controls, interpreting results, and recommending risk-based corrective action, expect questions that ask you to reason rather than recall. Practice thinking through situations like these:
- A test result is ambiguous. What additional evidence would you gather before declaring a finding?
- A system's information types change. Which downstream artifacts need revisiting: categorization, the security plan, the contingency plan?
- A finding is low-impact but widespread. How does risk-based thinking shape the corrective action you recommend?
- A certification package arrives incomplete. What are you evaluating, and what do you send back?
Key Takeaway
Prepare to justify recommendations in terms of risk, not just rule-following. The best answer to a remediation scenario usually ties the corrective action to the system's categorization and the actual exposure, rather than applying the strictest possible response everywhere.
If you want to gauge your readiness against this kind of reasoning, work through scenario-style questions on the CFCP practice test site, and read our difficulty guide for a realistic sense of what to expect.
Who Benefits From the Credential
The credential is most relevant to people who work where federal information-security requirements apply: federal agencies, contractors supporting them, universities handling federally regulated data, and private companies that need to meet FISMA-aligned expectations. Typical roles involve preparing security plans, supporting assessments, managing compliance projects, and tracking remediation. We discuss how this translates to the job market in our CFCP jobs article. We do not cite salary figures here because we have no verified data to support them; our salary guide and ROI analysis take a more careful look at the question.
Sequencing Your Preparation
Because the 22 subjects build on one another, study them in lifecycle order rather than alphabetically or by what feels easiest. One workable arrangement over four weeks:
Foundations and scoping
- Terminology, methodologies, the RMF process, program and project management
- Information types, inventory, and FIPS 199 categorization
People, operations and testing
- Awareness training, rules of behavior, incident response
- Security testing and the privacy, business, and system risk assessments
Planning and documentation
- Business impact assessment, contingency plan, configuration management plan
- System security plan, drawing on everything from Weeks 1 and 2
Packages, findings and review
- Submitting and evaluating the certification package; addressing findings
- Full-length timed practice across all subjects, then targeted review of weak spots
This order matters because categorization informs the security plan, the business impact assessment informs contingency planning, and everything feeds the package. For a printable summary, see the CFCP cheat sheet, and for broader context on the credential's reputation, read our look at the pass rate question, where we explain why no verified figure is available.
Frequently Asked Questions
The FISMA Center administers the Certified FISMA Compliance Practitioner credential. This is distinct from other credentials that happen to share the CFCP acronym.
The current issuer page specifies 100 multiple-choice and true/false questions with a 170-minute limit. Confirm registration and appointment arrangements with the issuer directly.
The reviewed current public pages do not specify a passing threshold. They also do not state the scored versus unscored split, open or closed-book policy, or proctoring arrangement, so confirm these with the issuer.
No. The issuer recommends its courses, resource pages, and handbook, but attendance is not mandatory. The course does include an exam voucher and a study guide available only to students.
No. The RMF steps describe a risk-management process. The issuer's course outline lists 22 subjects, and official scored-domain weights remain unverified, so study all of them rather than just the RMF sequence.
For a broader introduction to the credential, you can also revisit our main CFCP certification overview, and when you are ready to test yourself, head to the practice exams.