CFCP logo
Focused certification exam prep
Start practice

CFCP Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • The Certified FISMA Compliance Practitioner exam is issued by The FISMA Center: 100 multiple-choice and true/false questions in 170 minutes.
  • The issuer outline lists 22 unweighted subjects; official scored-domain weights are not published, so study all 22.
  • Passing score, scored/unscored split, open-book policy and proctoring details are not specified on reviewed public pages.
  • The seven RMF steps are a risk-management process, not a map of CFCP exam domains.

Which CFCP This Cheat Sheet Covers

Several credentials share the acronym "CFCP." This page covers exactly one: the Certified FISMA Compliance Practitioner, administered by The FISMA Center. Everything below concerns federal information-security compliance, control assessment, and remediation. If you landed here looking for a different credential that happens to share the letters, the facts here (exam format, subject list, experience requirement) will not transfer. For a broader orientation, see What Is CFCP? or What Does CFCP Stand For?.

The assessment is oriented around three practical skills: defining and testing security controls, interpreting test results, and recommending risk-based corrective action. Keep those three verbs in mind as you review. Most questions are easier when you ask, "Which of those three activities is this scenario really about?"

Exam Facts at a Glance

ItemWhat the Issuer Specifies
IssuerThe FISMA Center
Question count100
Question typesMultiple-choice and true/false
Time limit170 minutes (two hours fifty minutes)
Experience requirementOne year of FISMA compliance experience, verified after passing
Recommended preparationIssuer courses, resource pages, and the FISMA Compliance Handbook Second Edition (attendance not mandatory)
Related courseFISMA101: two days, six CPE credits per day, twelve total

A little pacing arithmetic helps: 170 minutes across 100 questions leaves roughly a minute and forty seconds per question on average. That is generous for true/false items and tight enough that you should not stall on a single scenario. Mark, move on, and return.

Do not confuse course credits with exam facts: The twelve CPE credits belong to the FISMA101 course (six per day over two days). They describe instructional time. They are not the exam timer, not a number of exam questions, and not a renewal obligation.

For a deeper look at logistics, the sibling guides on CFCP requirements, certification cost, and exam dates go into registration mechanics. Always confirm current appointment and registration arrangements directly with the issuer at fismacenter.com, since the reviewed pages advertise tentative 2026 course offerings and the course includes an exam voucher.

What Is Not Published (Do Not Assume)

One of the most useful things a cheat sheet can do is mark the blank spaces. The reviewed public issuer pages do not specify:

  • A passing threshold or cut score
  • Whether some questions are unscored
  • Whether the exam is open-book or closed-book
  • The proctoring arrangement
  • Official scored-domain weights
  • Exhaustive exam coverage beyond the course outline

Be skeptical of any site, forum post, or study group claiming a specific percentage needed to pass or a specific weight per domain. Those figures are not on the issuer's reviewed pages. Our own article on the CFCP passing score and the pass rate data treat this honestly: where the issuer is silent, the right posture is to prepare broadly and verify with the issuer before test day.

Practical consequence: Because weights are unpublished, you cannot safely skip a subject because it looks "minor." Treat all 22 as testable and allocate extra time to the areas where your day-to-day experience is thinnest.

The 22 Domains, Grouped for Fast Review

The issuer's FISMA101 outline lists 22 subjects: 11 under Day 1 and 11 under Day 2. These are unweighted course subjects, not an official weighted blueprint. Grouping them by theme makes them far easier to hold in your head. For a full walkthrough, see the complete guide to all 22 content areas.

Foundations (Domains 1-5)

The vocabulary, methods, and program structure that every later topic relies on.

  • Domain 1: Explanation of FISMA Terminology
  • Domain 2: FISMA Compliance Methodologies
  • Domain 3: Understanding the Process and Risk Management Framework (RMF)
  • Domain 4: Establishing an Information Security Program
  • Domain 5: FISMA Project Management

Know Your System (Domains 6-8)

You cannot protect or categorize what you have not identified.

  • Domain 6: Determining the Information Types & Sensitivity Level
  • Domain 7: Preparing the Hardware and Software Inventory
  • Domain 8: FIPS 199: Categorizing Data Sensitivity

People and Response (Domains 9-11)

The human and operational side of compliance.

  • Domain 9: Security Awareness Training
  • Domain 10: Rules of Behavior
  • Domain 11: Incident Response

Testing and Risk (Domains 12-15, 17)

Assessment activities that produce the evidence a certification decision rests on.

  • Domain 12: Performing Security Testing
  • Domain 13: Conducting a Privacy Impact Assessment
  • Domain 14: Performing a Business Risk Assessment
  • Domain 15: Preparing a Business Impact Assessment
  • Domain 17: Performing a System Risk Assessment

Planning and Documentation (Domains 16, 18-19)

The plans that turn assessment results into managed operations.

  • Domain 16: Developing an IT Contingency Plan
  • Domain 18: Developing a Configuration Management Plan
  • Domain 19: Developing a System Security Plan

Package and Findings (Domains 20-22)

The end of the cycle: submit, evaluate, fix.

  • Domain 20: Submitting the Certification Package
  • Domain 21: Evaluating the Certification Package
  • Domain 22: Addressing Compliance Findings

Concepts That Show Up Across Domains

Several ideas thread through the whole outline. If you internalize these, many individual questions become pattern recognition rather than recall.

Information Types Drive Everything Downstream

Identifying information types (Domain 6) feeds categorization under FIPS 199 (Domain 8), which in turn shapes the inventory scope (Domain 7), the risk assessments (Domains 14 and 17), the contingency planning (Domain 16), and the content of the system security plan (Domain 19). A scenario question that seems to be about contingency planning may really hinge on whether the system was categorized correctly in the first place.

Three Different "Assessments" With Three Different Purposes

The outline separates a privacy impact assessment, a business risk assessment, a business impact assessment, and a system risk assessment. They sound similar and are easy to blur. Distinguish them by the question each answers:

AssessmentCore Question It Answers
Privacy Impact Assessment (Domain 13)How is personal information collected, used, and protected?
Business Risk Assessment (Domain 14)What risks threaten the business mission or function?
Business Impact Assessment (Domain 15)What is the consequence of disruption, and what must be restored first?
System Risk Assessment (Domain 17)What threats and vulnerabilities affect this specific system?

Key Takeaway

When a question describes disruption and recovery priorities, think business impact assessment feeding the IT contingency plan. When it describes threats, vulnerabilities, and likelihood on a particular system, think system risk assessment. Match the scenario's verbs to the assessment's purpose.

Documents Are Evidence, Not Paperwork

In a compliance practitioner's world, the system security plan, configuration management plan, contingency plan, rules of behavior, and test results are the evidence base. The package submitted for certification (Domain 20) is only as strong as those underlying artifacts, and the evaluator (Domain 21) is judging whether they support the claims being made.

Terminology and Methodology Quick Hits

Domains 1 and 2 are where easy points are won or lost. Terminology questions reward precision: know the difference between a control and a control assessment, between a risk and a vulnerability, between a finding and a corrective action. Methodology questions ask you to recognize how different compliance approaches structure the work.

  • Know definitions exactly. True/false items often turn on a single qualifier such as "always," "only," or "must."
  • Know the sequence logic. Many methodologies are ordered; be able to say what comes before and after a given activity and why.
  • Know who does what. Distinguish the roles that prepare, test, evaluate, and authorize.
RMF is background, not a blueprint: NIST's Risk Management Framework and its supporting FISMA publications are valuable study material, and Domain 3 addresses the process and framework. But the seven RMF steps are a risk-management process. They are not a one-to-one map of the CFCP's 22 subjects, so do not organize your whole review around them. The NIST pages at csrc.nist.gov (the RMF overview and the FISMA background page) are the authoritative current references.

Testing, Packages, and Remediation

This cluster reflects the exam's own emphasis: defining and testing controls, interpreting results, and recommending risk-based corrective action. Expect scenario-style questions here.

Performing Security Testing (Domain 12)

Understand what a test is meant to demonstrate and how to read what it returns.

  • Match the test method to the control being verified
  • Distinguish a failed control from an incompletely tested one
  • Recognize when results are inconclusive and require retesting or additional evidence

Submitting and Evaluating the Certification Package (Domains 20-21)

Know what belongs in a package and how a reviewer decides whether it is sufficient.

  • Completeness: are all required artifacts present and consistent with each other?
  • Traceability: do the test results support the claims in the system security plan?
  • Residual risk: is what remains understood and documented for the decision-maker?

Addressing Compliance Findings (Domain 22)

Findings are not the end of the story; they trigger risk-based corrective action.

  • Prioritize remediation by risk, not by the order findings were discovered
  • Tie each corrective action to the specific finding and control it addresses
  • Track completion and verify that the fix actually resolved the weakness

The recurring exam instinct here is risk-based judgment. When two corrective actions seem plausible, the better answer usually addresses the higher-risk weakness first or ties the response directly to the documented risk rather than applying a blanket fix.

Legacy Frameworks: Know the History, Use Current Sources

The published curriculum surveys a range of approaches: NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503, and FedRAMP. Treat the older names as comparative historical material. Their appearance in a course outline does not mean every method remains current policy.

ApproachHow to Treat It When Studying
NISTPrimary source for current FISMA and RMF guidance; verify against current NIST publications
DIACAPHistorical context; useful for understanding how DoD approaches evolved
DoD RMFCompare with the NIST RMF to understand shared structure and differences
DCID 6/3 and ICD 503Intelligence-community approaches; understand them comparatively and in historical context
FedRAMPFederal cloud authorization program; know its purpose relative to agency compliance
Rule of thumb: For any present-day compliance fact, rely on current primary NIST and federal materials. Use the legacy frameworks to answer "how do these approaches compare?" questions, not to assert what current policy requires.

Sequencing Your Review by Domain

You do not need a generic study system; you need an order that respects how the domains depend on each other. Here is one CFCP-specific sequence, built around the dependency chain described above. The broader CFCP study guide expands on resources and pacing.

Week 1

Vocabulary and Frame (Domains 1-5)

  • Lock down terminology first; every later domain assumes it
  • Read the NIST RMF and FISMA background pages for context
  • Note which legacy frameworks you can compare and which you cannot
Week 2

Identify and Categorize (Domains 6-8)

  • Practice information-type identification and FIPS 199 categorization
  • Connect inventory scope to categorization outcomes
Week 3

People, Response, Testing (Domains 9-12)

  • Review awareness training, rules of behavior, and incident response
  • Spend extra time on testing and interpreting results, the exam's core skill
Week 4

Assessments and Plans (Domains 13-19)

  • Drill the differences between the four assessments
  • Trace how the impact assessment feeds contingency planning and the security plan
Week 5

Package and Findings (Domains 20-22), then Full Review

  • Practice evaluating a package for completeness and traceability
  • Work remediation scenarios using risk-based prioritization
  • Finish with timed mixed sets using the CFCP practice tests

If you have prior federal compliance experience, compress the weeks you already know and spend the savings on domains you rarely touch at work, such as the privacy impact assessment or the business impact assessment. Candidates who live in testing and assessment often underestimate how much of the outline is documentation and planning.

After You Pass: Experience Verification and Career Fit

Passing is not the final gate. Certification also requires one year of FISMA compliance experience, verified after passing. Plan for that documentation early: keep records of the systems you supported, the artifacts you produced, and who can attest to your role. The CFCP requirements article covers eligibility in more detail.

The credential's subject matter points to roles in federal information-security compliance: agencies, contractors supporting agencies, universities, and private companies subject to federal security requirements. The issuer itself provides FISMA training for those audiences. For role examples, see CFCP jobs; for compensation and value questions, the salary guide and the ROI analysis take a measured look rather than promising specific figures.

Before you commit, it is also worth reading how hard the CFCP exam really is to calibrate expectations, and the CFCP training overview if you are weighing the issuer's FISMA101 course. Course attendance is recommended but not mandatory, and the course supplies a CFCP study guide only to enrolled students.

Key Takeaway

Build your final-week review around the exam's three core skills: defining and testing controls, interpreting results, and recommending risk-based corrective action. Test yourself with scenarios on the practice test site and verify every logistical detail with the issuer.

Frequently Asked Questions

How many questions are on the CFCP exam and how long do I have?

The current issuer examination page specifies 100 multiple-choice and true/false questions with a 170-minute (two hours fifty minutes) limit. Confirm appointment and registration arrangements with The FISMA Center before scheduling.

What score do I need to pass?

The reviewed public issuer pages do not specify a passing threshold, so any specific percentage you see elsewhere should be treated as unverified. Ask the issuer directly and prepare across all 22 subjects.

Are the 22 domains weighted on the exam?

Official scored-domain weights are not published. The 22 subjects come from the issuer's FISMA101 course outline (11 on Day 1, 11 on Day 2) and are unweighted, so avoid skipping any of them.

Do the seven RMF steps match the CFCP exam domains?

No. The seven RMF steps are a risk-management process from NIST. They are useful background, especially for Domain 3, but they are not a map of the CFCP's scored domains.

Do I need work experience to earn the credential?

Yes. Certification requires one year of FISMA compliance experience, verified after you pass the exam. Keep documentation of your role and the systems you supported.

Ready to pass your CFCP exam?

Put this into practice with free CFCP questions across every exam domain.