- What Is Actually Published About CFCP Scheduling
- Exam Format and the 170-Minute Clock
- The FISMA101 Route and Tentative 2026 Offerings
- Why the One-Year Experience Rule Affects Your Timeline
- Details You Must Confirm Directly With the Issuer
- Sequencing the 22 Content Areas Around Your Test Date
- Comparing Your Scheduling Options
- A Pre-Registration Verification Checklist
- Frequently Asked Questions
- The FISMA Center administers the CFCP exam: 100 multiple-choice and true/false questions in 170 minutes.
- The issuer's FISMA101 course advertises tentative 2026 offerings and includes an exam voucher.
- Course attendance is not mandatory; the issuer recommends it, along with its FISMA Compliance Handbook Second Edition.
- Certification requires one year of FISMA compliance experience, verified after you pass the exam.
What Is Actually Published About CFCP Scheduling
Candidates searching for CFCP exam dates usually expect a fixed calendar of testing windows with registration deadlines, like those published for many large certification programs. The Certified FISMA Compliance Practitioner credential, administered by The FISMA Center, does not appear to work that way based on the public issuer pages reviewed. What the issuer publishes is a certifications page describing the exam and a FISMA101 training page advertising tentative 2026 course offerings.
That distinction matters. A tentative course schedule is not the same thing as a published testing window, and this article will not invent either one. Instead, it separates what the issuer has stated publicly from what you must confirm directly before you commit money or vacation days. If you are still orienting yourself on the credential itself, start with What Is CFCP Certification? and then return here.
Exam Format and the 170-Minute Clock
The current issuer examination page specifies 100 multiple-choice and true/false questions with a limit of two hours fifty minutes (170 minutes). That works out to roughly one minute and forty-two seconds per question if you spread the time evenly, which is generous for true/false items and tighter for scenario-driven multiple-choice questions that require you to interpret a test result or choose a corrective action.
The assessment is oriented toward three core abilities: defining and testing security controls, interpreting test results, and recommending risk-based corrective action. Expect questions framed around federal compliance situations rather than pure vocabulary recall. For a deeper look at how demanding that style is, see How Hard Is the CFCP Exam? Complete Difficulty Guide 2026.
| Exam Detail | Published Status |
|---|---|
| Question count | 100 (specified by issuer) |
| Question types | Multiple-choice and true/false |
| Time limit | 170 minutes (specified by issuer) |
| Passing threshold | Not specified on reviewed pages |
| Scored vs. unscored split | Not specified on reviewed pages |
| Open- or closed-book policy | Not specified on reviewed pages |
| Proctoring arrangement | Not specified on reviewed pages |
Because the passing threshold is not published on the reviewed pages, be cautious about any figure you see elsewhere. Our CFCP Passing Score 2026 article tracks what is and is not verifiable on that front.
The FISMA101 Route and Tentative 2026 Offerings
The most concrete scheduling structure the issuer advertises is tied to its FISMA101 course. FISMA101 is a two-day course carrying six CPE credits per day, twelve in total. Those figures describe instructional duration and course credits only. They are not the exam timer, not a count of exam questions, and not a renewal obligation, so do not conflate them when planning.
The issuer's page advertises tentative 2026 offerings and states that the course includes an exam voucher. It also supplies a CFCP study guide to course students only; no private study guide was accessed in preparing this article, so we cannot describe its contents. The published outline splits the 22 course subjects across two days, 11 under Day 1 and 11 under Day 2. These are unweighted course subjects rather than an official weighted exam blueprint.
What the Curriculum Surveys
The published curriculum surveys NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503, and FedRAMP. Treat the older named approaches as comparative historical material, not as a claim that every method remains current policy. For present-day compliance facts, rely on current primary NIST and federal materials, including the NIST Risk Management Framework overview and the NIST FISMA background page. One caution: the seven RMF steps are a risk-management process and should not be treated as a map of CFCP scored domains.
Why the One-Year Experience Rule Affects Your Timeline
Certification requires one year of FISMA compliance experience, verified after passing the exam. That sequencing is unusual and it shapes how you think about "dates." Passing the exam is one milestone; verifying experience is a separate one that follows it. If you are early in your career, you may sit the exam first and complete the experience verification afterward, but confirm exactly how the issuer handles that sequence in your case.
For the full picture of who qualifies and how, read CFCP Requirements 2026: Eligibility, Prerequisites & How to Qualify. And if you are weighing the credential against your career goals, CFCP Jobs and Is the CFCP Certification Worth It? Complete ROI Analysis 2026 help frame the decision.
Details You Must Confirm Directly With the Issuer
Several things candidates want to know before choosing a date are simply not specified on the reviewed public pages. Rather than guess, treat each of these as a question for The FISMA Center:
- Appointment and registration arrangements: how an exam sitting is scheduled, whether it is tied to course sessions, and what lead time is needed.
- Proctoring: whether the exam is proctored, and in what manner.
- Book policy: whether reference materials are allowed during the exam.
- Passing threshold and scoring: the required score and whether any questions are unscored.
- Retake and rescheduling terms: what happens if you need to move your sitting or try again.
Key Takeaway
Email or call the issuer with the list above before you pay for anything. Get the answers in writing and keep them. A published "tentative" offering can shift, so confirm the specific session you intend to attend, along with how the exam voucher is redeemed.
Sequencing the 22 Content Areas Around Your Test Date
Once you have a confirmed sitting, work backward from it. The current official outline covers FISMA terminology and methodologies; program and project management; information types, inventory, and FIPS 199 categorization; awareness, rules, and incident response; security testing along with privacy, business, and system risk assessments; business impact, contingency, and configuration planning; system security planning; submission and evaluation of certification packages; and remediation of findings. Official scored-domain weights remain unverified, so avoid over-investing in any single area based on rumor.
This is the one place where a time-based plan is worth outlining, because the content areas build on each other. Foundational vocabulary and categorization come first; testing and risk assessment come next; packaging and remediation come last because they depend on everything before them.
Foundations
- FISMA terminology and compliance methodologies (Domains 1-2)
- The RMF process, kept distinct from the exam domains (Domain 3)
- Security program and project management (Domains 4-5)
Categorization and Inventory
- Information types and sensitivity (Domain 6)
- Hardware and software inventory (Domain 7)
- FIPS 199 categorization practice (Domain 8)
Operational Controls and Testing
- Awareness training, rules of behavior, incident response (Domains 9-11)
- Security testing and interpreting results (Domain 12)
- Privacy impact and business risk assessments (Domains 13-14)
Planning and Packaging
- Business impact, contingency, and configuration plans (Domains 15, 16, 18)
- System risk assessment and system security plan (Domains 17, 19)
- Submitting and evaluating certification packages, then addressing findings (Domains 20-22)
Give the final block extra attention in the last stretch before your sitting, since scenario questions on interpreting test results and recommending corrective action tend to pull from several earlier areas at once. A full walkthrough of each content area is in CFCP Exam Domains 2026: Complete Guide to All 22 Content Areas, and a step-by-step plan lives in CFCP Study Guide 2026: How to Pass on Your First Attempt.
Domain 12: Performing Security Testing
This area underpins the exam's emphasis on interpreting results. Candidates should be comfortable moving from a test finding to a risk-based recommendation.
- Distinguish what a test result shows from what it merely suggests
- Connect findings to the affected system and its FIPS 199 impact level
- Recommend corrective action proportionate to risk, not just severity labels
Domain 22: Addressing Compliance Findings
Remediation closes the loop on the whole compliance process and is a natural capstone topic for your final review days.
- Prioritize findings using risk rather than ease of fix
- Understand how corrective actions feed back into the certification package
- Recognize how unresolved findings affect evaluation decisions
Comparing Your Scheduling Options
Because the issuer recommends but does not require its course, you effectively have two paths. The comparison below reflects only what is publicly stated; anything marked "confirm" needs direct verification.
| Factor | FISMA101 Course Route | Self-Study Route |
|---|---|---|
| Schedule basis | Tentative 2026 course offerings advertised by the issuer | Confirm exam arrangements directly with the issuer |
| Exam voucher | Included with the course | Confirm how registration works |
| CFCP study guide | Supplied to course students only | Not available through this route as stated |
| Instruction | Two days, 22 subjects, 12 CPE credits | Issuer recommends its resource pages and FISMA Compliance Handbook Second Edition |
| Flexibility | Tied to offered course dates (tentative) | Confirm with the issuer |
Neither route is inherently superior, and your choice should depend on your existing FISMA background and budget. If you want to rehearse the question style before committing to a date, the CFCP practice tests let you measure readiness against scenario-based items without waiting on a course session.
A Pre-Registration Verification Checklist
Before you lock in any date, walk through this sequence. It keeps you from relying on secondhand claims about CFCP scheduling.
- Visit the issuer's certifications page and the FISMA101 training page for the latest posted information.
- Confirm which 2026 course sessions are actually scheduled, since the published offerings are described as tentative.
- Ask how the exam voucher is redeemed and whether the exam is taken during the course or arranged separately.
- Request written clarification on proctoring, reference-material rules, and the passing threshold.
- Verify how the one-year experience requirement is documented after you pass.
- Check the pricing picture in CFCP Certification Cost 2026 and compare against your employer's training budget.
Finally, avoid mixing this credential up with others that share the acronym. The Certified FISMA Compliance Practitioner credential from The FISMA Center is its own program; for the naming question, see What Does CFCP Stand For?. If you need a quick refresher on must-know facts as your date approaches, the CFCP Cheat Sheet 2026 condenses the essentials, and CFCP Training covers instructional options in more depth.
Frequently Asked Questions
The reviewed public issuer pages do not publish a fixed testing-window calendar. They advertise tentative 2026 FISMA101 course offerings instead. Confirm appointment and registration arrangements directly with The FISMA Center before planning around any specific date.
The issuer's examination page specifies 100 multiple-choice and true/false questions with a time limit of 170 minutes, which is two hours and fifty minutes.
No. The issuer recommends its courses, resource pages, and FISMA Compliance Handbook Second Edition, but course attendance is not mandatory. The course does include an exam voucher, so confirm how registration works if you choose to self-study.
No. FISMA101 carries six CPE credits per day over two days, twelve total, but that describes the course only. It is not the exam timer, not a question count, and not a renewal obligation.
Certification requires one year of FISMA compliance experience, verified after you pass the exam. Confirm with the issuer exactly how that verification is handled in your situation, and see our CFCP requirements guide for more detail.
Because so many scheduling specifics are unconfirmed in public sources, your best preparation is twofold: verify arrangements with the issuer early, and build real familiarity with the 22 content areas so your readiness does not depend on any single date. You can pressure-test that readiness anytime on the main practice test site.