- Which CFCP This Cheat Sheet Covers
- Exam Facts at a Glance
- What Is Not Published (Do Not Assume)
- The 22 Domains, Grouped for Fast Review
- Concepts That Show Up Across Domains
- Terminology and Methodology Quick Hits
- Testing, Packages, and Remediation
- Legacy Frameworks: Know the History, Use Current Sources
- Sequencing Your Review by Domain
- After You Pass: Experience Verification and Career Fit
- Frequently Asked Questions
- The Certified FISMA Compliance Practitioner exam is issued by The FISMA Center: 100 multiple-choice and true/false questions in 170 minutes.
- The issuer outline lists 22 unweighted subjects; official scored-domain weights are not published, so study all 22.
- Passing score, scored/unscored split, open-book policy and proctoring details are not specified on reviewed public pages.
- The seven RMF steps are a risk-management process, not a map of CFCP exam domains.
Which CFCP This Cheat Sheet Covers
Several credentials share the acronym "CFCP." This page covers exactly one: the Certified FISMA Compliance Practitioner, administered by The FISMA Center. Everything below concerns federal information-security compliance, control assessment, and remediation. If you landed here looking for a different credential that happens to share the letters, the facts here (exam format, subject list, experience requirement) will not transfer. For a broader orientation, see What Is CFCP? or What Does CFCP Stand For?.
The assessment is oriented around three practical skills: defining and testing security controls, interpreting test results, and recommending risk-based corrective action. Keep those three verbs in mind as you review. Most questions are easier when you ask, "Which of those three activities is this scenario really about?"
Exam Facts at a Glance
| Item | What the Issuer Specifies |
|---|---|
| Issuer | The FISMA Center |
| Question count | 100 |
| Question types | Multiple-choice and true/false |
| Time limit | 170 minutes (two hours fifty minutes) |
| Experience requirement | One year of FISMA compliance experience, verified after passing |
| Recommended preparation | Issuer courses, resource pages, and the FISMA Compliance Handbook Second Edition (attendance not mandatory) |
| Related course | FISMA101: two days, six CPE credits per day, twelve total |
A little pacing arithmetic helps: 170 minutes across 100 questions leaves roughly a minute and forty seconds per question on average. That is generous for true/false items and tight enough that you should not stall on a single scenario. Mark, move on, and return.
For a deeper look at logistics, the sibling guides on CFCP requirements, certification cost, and exam dates go into registration mechanics. Always confirm current appointment and registration arrangements directly with the issuer at fismacenter.com, since the reviewed pages advertise tentative 2026 course offerings and the course includes an exam voucher.
What Is Not Published (Do Not Assume)
One of the most useful things a cheat sheet can do is mark the blank spaces. The reviewed public issuer pages do not specify:
- A passing threshold or cut score
- Whether some questions are unscored
- Whether the exam is open-book or closed-book
- The proctoring arrangement
- Official scored-domain weights
- Exhaustive exam coverage beyond the course outline
Be skeptical of any site, forum post, or study group claiming a specific percentage needed to pass or a specific weight per domain. Those figures are not on the issuer's reviewed pages. Our own article on the CFCP passing score and the pass rate data treat this honestly: where the issuer is silent, the right posture is to prepare broadly and verify with the issuer before test day.
The 22 Domains, Grouped for Fast Review
The issuer's FISMA101 outline lists 22 subjects: 11 under Day 1 and 11 under Day 2. These are unweighted course subjects, not an official weighted blueprint. Grouping them by theme makes them far easier to hold in your head. For a full walkthrough, see the complete guide to all 22 content areas.
Foundations (Domains 1-5)
The vocabulary, methods, and program structure that every later topic relies on.
- Domain 1: Explanation of FISMA Terminology
- Domain 2: FISMA Compliance Methodologies
- Domain 3: Understanding the Process and Risk Management Framework (RMF)
- Domain 4: Establishing an Information Security Program
- Domain 5: FISMA Project Management
Know Your System (Domains 6-8)
You cannot protect or categorize what you have not identified.
- Domain 6: Determining the Information Types & Sensitivity Level
- Domain 7: Preparing the Hardware and Software Inventory
- Domain 8: FIPS 199: Categorizing Data Sensitivity
People and Response (Domains 9-11)
The human and operational side of compliance.
- Domain 9: Security Awareness Training
- Domain 10: Rules of Behavior
- Domain 11: Incident Response
Testing and Risk (Domains 12-15, 17)
Assessment activities that produce the evidence a certification decision rests on.
- Domain 12: Performing Security Testing
- Domain 13: Conducting a Privacy Impact Assessment
- Domain 14: Performing a Business Risk Assessment
- Domain 15: Preparing a Business Impact Assessment
- Domain 17: Performing a System Risk Assessment
Planning and Documentation (Domains 16, 18-19)
The plans that turn assessment results into managed operations.
- Domain 16: Developing an IT Contingency Plan
- Domain 18: Developing a Configuration Management Plan
- Domain 19: Developing a System Security Plan
Package and Findings (Domains 20-22)
The end of the cycle: submit, evaluate, fix.
- Domain 20: Submitting the Certification Package
- Domain 21: Evaluating the Certification Package
- Domain 22: Addressing Compliance Findings
Concepts That Show Up Across Domains
Several ideas thread through the whole outline. If you internalize these, many individual questions become pattern recognition rather than recall.
Information Types Drive Everything Downstream
Identifying information types (Domain 6) feeds categorization under FIPS 199 (Domain 8), which in turn shapes the inventory scope (Domain 7), the risk assessments (Domains 14 and 17), the contingency planning (Domain 16), and the content of the system security plan (Domain 19). A scenario question that seems to be about contingency planning may really hinge on whether the system was categorized correctly in the first place.
Three Different "Assessments" With Three Different Purposes
The outline separates a privacy impact assessment, a business risk assessment, a business impact assessment, and a system risk assessment. They sound similar and are easy to blur. Distinguish them by the question each answers:
| Assessment | Core Question It Answers |
|---|---|
| Privacy Impact Assessment (Domain 13) | How is personal information collected, used, and protected? |
| Business Risk Assessment (Domain 14) | What risks threaten the business mission or function? |
| Business Impact Assessment (Domain 15) | What is the consequence of disruption, and what must be restored first? |
| System Risk Assessment (Domain 17) | What threats and vulnerabilities affect this specific system? |
Key Takeaway
When a question describes disruption and recovery priorities, think business impact assessment feeding the IT contingency plan. When it describes threats, vulnerabilities, and likelihood on a particular system, think system risk assessment. Match the scenario's verbs to the assessment's purpose.
Documents Are Evidence, Not Paperwork
In a compliance practitioner's world, the system security plan, configuration management plan, contingency plan, rules of behavior, and test results are the evidence base. The package submitted for certification (Domain 20) is only as strong as those underlying artifacts, and the evaluator (Domain 21) is judging whether they support the claims being made.
Terminology and Methodology Quick Hits
Domains 1 and 2 are where easy points are won or lost. Terminology questions reward precision: know the difference between a control and a control assessment, between a risk and a vulnerability, between a finding and a corrective action. Methodology questions ask you to recognize how different compliance approaches structure the work.
- Know definitions exactly. True/false items often turn on a single qualifier such as "always," "only," or "must."
- Know the sequence logic. Many methodologies are ordered; be able to say what comes before and after a given activity and why.
- Know who does what. Distinguish the roles that prepare, test, evaluate, and authorize.
Testing, Packages, and Remediation
This cluster reflects the exam's own emphasis: defining and testing controls, interpreting results, and recommending risk-based corrective action. Expect scenario-style questions here.
Performing Security Testing (Domain 12)
Understand what a test is meant to demonstrate and how to read what it returns.
- Match the test method to the control being verified
- Distinguish a failed control from an incompletely tested one
- Recognize when results are inconclusive and require retesting or additional evidence
Submitting and Evaluating the Certification Package (Domains 20-21)
Know what belongs in a package and how a reviewer decides whether it is sufficient.
- Completeness: are all required artifacts present and consistent with each other?
- Traceability: do the test results support the claims in the system security plan?
- Residual risk: is what remains understood and documented for the decision-maker?
Addressing Compliance Findings (Domain 22)
Findings are not the end of the story; they trigger risk-based corrective action.
- Prioritize remediation by risk, not by the order findings were discovered
- Tie each corrective action to the specific finding and control it addresses
- Track completion and verify that the fix actually resolved the weakness
The recurring exam instinct here is risk-based judgment. When two corrective actions seem plausible, the better answer usually addresses the higher-risk weakness first or ties the response directly to the documented risk rather than applying a blanket fix.
Legacy Frameworks: Know the History, Use Current Sources
The published curriculum surveys a range of approaches: NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503, and FedRAMP. Treat the older names as comparative historical material. Their appearance in a course outline does not mean every method remains current policy.
| Approach | How to Treat It When Studying |
|---|---|
| NIST | Primary source for current FISMA and RMF guidance; verify against current NIST publications |
| DIACAP | Historical context; useful for understanding how DoD approaches evolved |
| DoD RMF | Compare with the NIST RMF to understand shared structure and differences |
| DCID 6/3 and ICD 503 | Intelligence-community approaches; understand them comparatively and in historical context |
| FedRAMP | Federal cloud authorization program; know its purpose relative to agency compliance |
Sequencing Your Review by Domain
You do not need a generic study system; you need an order that respects how the domains depend on each other. Here is one CFCP-specific sequence, built around the dependency chain described above. The broader CFCP study guide expands on resources and pacing.
Vocabulary and Frame (Domains 1-5)
- Lock down terminology first; every later domain assumes it
- Read the NIST RMF and FISMA background pages for context
- Note which legacy frameworks you can compare and which you cannot
Identify and Categorize (Domains 6-8)
- Practice information-type identification and FIPS 199 categorization
- Connect inventory scope to categorization outcomes
People, Response, Testing (Domains 9-12)
- Review awareness training, rules of behavior, and incident response
- Spend extra time on testing and interpreting results, the exam's core skill
Assessments and Plans (Domains 13-19)
- Drill the differences between the four assessments
- Trace how the impact assessment feeds contingency planning and the security plan
Package and Findings (Domains 20-22), then Full Review
- Practice evaluating a package for completeness and traceability
- Work remediation scenarios using risk-based prioritization
- Finish with timed mixed sets using the CFCP practice tests
If you have prior federal compliance experience, compress the weeks you already know and spend the savings on domains you rarely touch at work, such as the privacy impact assessment or the business impact assessment. Candidates who live in testing and assessment often underestimate how much of the outline is documentation and planning.
After You Pass: Experience Verification and Career Fit
Passing is not the final gate. Certification also requires one year of FISMA compliance experience, verified after passing. Plan for that documentation early: keep records of the systems you supported, the artifacts you produced, and who can attest to your role. The CFCP requirements article covers eligibility in more detail.
The credential's subject matter points to roles in federal information-security compliance: agencies, contractors supporting agencies, universities, and private companies subject to federal security requirements. The issuer itself provides FISMA training for those audiences. For role examples, see CFCP jobs; for compensation and value questions, the salary guide and the ROI analysis take a measured look rather than promising specific figures.
Before you commit, it is also worth reading how hard the CFCP exam really is to calibrate expectations, and the CFCP training overview if you are weighing the issuer's FISMA101 course. Course attendance is recommended but not mandatory, and the course supplies a CFCP study guide only to enrolled students.
Key Takeaway
Build your final-week review around the exam's three core skills: defining and testing controls, interpreting results, and recommending risk-based corrective action. Test yourself with scenarios on the practice test site and verify every logistical detail with the issuer.
Frequently Asked Questions
The current issuer examination page specifies 100 multiple-choice and true/false questions with a 170-minute (two hours fifty minutes) limit. Confirm appointment and registration arrangements with The FISMA Center before scheduling.
The reviewed public issuer pages do not specify a passing threshold, so any specific percentage you see elsewhere should be treated as unverified. Ask the issuer directly and prepare across all 22 subjects.
Official scored-domain weights are not published. The 22 subjects come from the issuer's FISMA101 course outline (11 on Day 1, 11 on Day 2) and are unweighted, so avoid skipping any of them.
No. The seven RMF steps are a risk-management process from NIST. They are useful background, especially for Domain 3, but they are not a map of the CFCP's scored domains.
Yes. Certification requires one year of FISMA compliance experience, verified after you pass the exam. Keep documentation of your role and the systems you supported.