CFCP logo
Focused certification exam prep
Start practice

CFCP Exam Domains 2026: Complete Guide to All 22 Content Areas

TL;DR
  • The 22 content areas come from the FISMA Center's FISMA101 course outline: 11 under Day 1 and 11 under Day 2.
  • These 22 subjects are unweighted course topics, not an official scored blueprint; the issuer has not published domain weights.
  • The exam is 100 multiple-choice and true/false questions with a 170-minute limit, per the issuer's current page.
  • The seven RMF steps are a risk-management process, not a map of CFCP exam domains.

What the 22 Content Areas Really Are

The Certified FISMA Compliance Practitioner (CFCP) credential is administered by the FISMA Center. When candidates search for "CFCP domains," they usually land on a list of 22 subjects. Those subjects come from the issuer's recommended FISMA101 preparation curriculum, a two-day course with 11 subjects published under Day 1 and 11 under Day 2. That is the most accurate way to describe them: a course outline, not a weighted exam blueprint like those published by some other certification bodies.

This distinction matters for how you study. The issuer's certification page describes an assessment centered on defining and testing security controls, interpreting test results, and recommending risk-based corrective action. The 22 course subjects map onto that mission well, but the issuer has not published how many questions come from each subject, and exhaustive exam coverage remains unverified. Treat every area as fair game and avoid trusting anyone who claims to know exact percentages. For a broader orientation, see our overview of what CFCP certification is.

Why "domain" is a loose term here: This guide uses "domain" because it is the common shorthand, but the FISMA Center presents these as course subjects. No official percentage weights exist in the sources reviewed. Any site quoting per-domain weightings for this credential is inventing them.

Exam Format and What Is Still Unverified

The issuer's current examination page specifies 100 multiple-choice and true/false questions with a 170-minute (two hours fifty minutes) time limit. That works out to well over a minute and a half per question on average, which suggests the exam rewards careful reading of scenarios rather than speed. You should confirm the offered appointment and registration arrangements directly with the issuer at fismacenter.com.

Exam ElementWhat the Reviewed Sources Say
Question count100 questions
Question typesMultiple-choice and true/false
Time limit170 minutes
Passing thresholdNot specified in reviewed pages
Scored vs. unscored splitNot specified in reviewed pages
Open/closed-book policyNot specified in reviewed pages
Proctoring arrangementNot specified in reviewed pages
Experience requirementOne year of FISMA compliance experience, verified after passing

The unknowns in that table are real. Rather than guess, check the issuer before test day. If you want to understand how we handle the unpublished threshold, read our page on the CFCP passing score, and for eligibility details see CFCP requirements.

Course versus exam clock: FISMA101 is a two-day course carrying six CPE credits per day, twelve in total. Those figures describe instruction time and course credits. They are not the exam timer, not exam questions, and not a renewal obligation. Do not conflate them.

Cluster 1: Terminology, Methodologies, and the RMF

The first three subjects establish vocabulary and context. Candidates who skip them to rush into hands-on topics tend to misread later scenario questions, because nearly every question assumes fluency in federal compliance language.

Domain 1: Explanation of FISMA Terminology

Expect to define and distinguish the core terms of federal information security compliance.

  • Know what FISMA is and why agencies and their contractors fall under it.
  • Be able to tell apart controls, control baselines, assessments, authorizations, and findings.
  • Practice recognizing when a question is testing definitions versus applying them.

Domain 2: FISMA Compliance Methodologies

The published curriculum surveys NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503, and FedRAMP. Several of these are historical or sector-specific approaches.

  • Understand what problem each methodology was designed to solve and who uses it.
  • Be able to compare them at a conceptual level rather than memorizing obsolete procedures.
  • Separate legacy material from current NIST and federal policy (covered in more detail below).

Domain 3: Understanding the Process and Risk Management Framework (RMF)

NIST's Risk Management Framework is essential background. Study it from the primary source at NIST's RMF page and the FISMA background page.

  • Know the purpose and flow of the RMF as a risk-management process.
  • Remember that the seven RMF steps are not the CFCP's domain structure. The exam subjects are organized differently.

Cluster 2: Program, Project, Information Types, and Inventory

Domains 4 through 7 cover the organizational scaffolding that makes compliance repeatable: the security program itself, how a FISMA effort is managed as a project, and the foundational discovery work of figuring out what you have and what it holds.

Domain 4: Establishing an Information Security Program

Focus on how an agency or contractor structures governance, roles, and responsibilities.

  • Understand how program-level policy flows down to system-level controls.
  • Know who typically owns which responsibilities in a federal compliance effort.

Domain 5: FISMA Project Management

Compliance work is delivered as a project with scope, schedule, and deliverables.

  • Be ready for questions on sequencing compliance tasks and managing dependencies.
  • Understand how deliverables from one subject feed the next, such as inventory feeding categorization.

Domain 6: Determining the Information Types and Sensitivity Level

You cannot protect or categorize what you have not identified. This subject leads directly into FIPS 199.

  • Practice identifying the information types a system processes, stores, or transmits.
  • Understand how information type drives sensitivity decisions.

Domain 7: Preparing the Hardware and Software Inventory

An accurate inventory is the backbone of scoping, testing, and configuration management.

  • Know what an inventory should capture and why completeness matters.
  • Recognize how inventory gaps surface later as assessment findings.

Cluster 3: FIPS 199 Categorization

Domain 8: FIPS 199: Categorizing Data Sensitivity

This is one of the most concrete, testable subjects in the list. FIPS 199 is the federal standard for categorizing information and information systems by potential impact.

  • Know the three security objectives: confidentiality, integrity, and availability.
  • Know the impact levels of low, moderate, and high, and how they apply per objective.
  • Understand the high-water-mark concept for a system holding multiple information types.
  • Practice working scenarios where you must assign a categorization and justify it.

Key Takeaway

Categorization is a gateway skill. Mistakes at the FIPS 199 stage propagate into control selection, contingency planning, and risk assessment. Drill categorization scenarios until the reasoning is automatic. Our practice test platform is a good place to rehearse this style of question.

Cluster 4: Awareness, Rules of Behavior, and Incident Response

Domains 9 through 11 cover the human and operational layer of compliance. These subjects tend to be scenario-heavy: a situation is described, and you choose the compliant response.

Domain 9: Security Awareness Training

  • Understand why awareness training is a required program element, not an optional extra.
  • Know who must be trained, when, and how completion is documented as evidence.

Domain 10: Rules of Behavior

  • Know the purpose of rules of behavior and how they set expectations for system users.
  • Understand how acknowledgment and enforcement are documented.

Domain 11: Incident Response

  • Be able to describe the lifecycle of an incident from detection through recovery and lessons learned.
  • Understand reporting expectations in a federal context and how incident handling ties to the security plan.

Cluster 5: Testing and the Four Assessments

This cluster sits at the heart of the credential's stated focus: defining and testing security controls and interpreting results. It spans Domains 12 through 15 and Domain 17, which together cover testing plus the privacy, business, and system risk analyses.

Domain 12: Performing Security Testing

  • Know the difference between examining, interviewing, and testing as assessment methods.
  • Practice interpreting test results: is a result a pass, a partial implementation, or a finding?
  • Understand how to document evidence so conclusions are defensible.

Domain 13: Conducting a Privacy Impact Assessment

  • Know when a privacy impact assessment is warranted and what it evaluates.
  • Understand how handling of personally identifiable information influences categorization and controls.

Domain 14: Performing a Business Risk Assessment

  • Understand risk from the mission and business perspective, not only the technical one.
  • Be able to connect business objectives to the systems that support them.

Domain 15: Preparing a Business Impact Assessment

  • Know how a business impact assessment identifies critical functions and tolerable downtime.
  • Understand that its outputs feed directly into contingency planning.

Domain 17: Performing a System Risk Assessment

  • Practice identifying threats, vulnerabilities, likelihood, and impact for a specific system.
  • Know how to distinguish the system-level assessment from the business-level one in Domain 14.
Don't blur the assessments: The curriculum lists a privacy impact assessment, a business risk assessment, a business impact assessment, and a system risk assessment as separate subjects. Questions often test whether you can tell which one a scenario calls for. Build a one-line purpose statement for each and quiz yourself.

Cluster 6: Contingency, Configuration, and the Security Plan

Domain 16: Developing an IT Contingency Plan

  • Understand how the business impact assessment drives recovery priorities.
  • Know the components of a contingency plan and how it is tested and maintained.

Domain 18: Developing a Configuration Management Plan

  • Know why baselines and change control matter for security posture.
  • Understand how the hardware and software inventory from Domain 7 supports configuration management.

Domain 19: Developing a System Security Plan

The system security plan is the central compliance document. It describes the system, its categorization, and how each control is implemented.

  • Know what content belongs in the plan and how it traces to categorization and risk assessment.
  • Recognize that nearly every earlier subject contributes input to this document.

Cluster 7: Certification Package and Findings

The final three subjects cover the back end of the compliance lifecycle: assembling the package, reviewing it, and acting on what the review reveals. This is where the credential's emphasis on risk-based corrective action becomes most visible.

Domain 20: Submitting the Certification Package

  • Know which artifacts typically make up a certification package and who submits it.
  • Understand quality checks to perform before submission.

Domain 21: Evaluating the Certification Package

  • Practice reviewing a package for completeness, consistency, and supported conclusions.
  • Be able to spot mismatches, such as a categorization that does not align with the described information types.

Domain 22: Addressing Compliance Findings

  • Know how to prioritize findings by risk rather than by ease of fix.
  • Understand the structure of a corrective action plan and how remediation is tracked.
  • Be ready for scenarios that ask you to recommend the most appropriate risk-based response.

Scheduling the Domains Across Your Prep

Because the 22 subjects build on one another, sequencing matters more than total hours. Here is one way to order them. For a fuller plan, see our CFCP study guide.

Week 1

Vocabulary and Frameworks

  • Domains 1 to 3: terminology, methodologies, RMF background from NIST.
  • Why first: every later scenario assumes this language.
Week 2

Scoping and Categorization

  • Domains 4 to 8: program, project, information types, inventory, FIPS 199.
  • Why here: categorization feeds everything downstream.
Week 3

People, Response, and Assessments

  • Domains 9 to 15 and 17: awareness, rules of behavior, incident response, testing, and the four assessments.
  • Why here: these are the most scenario-heavy subjects.
Week 4

Planning, Package, and Findings

  • Domains 16 and 18 to 22: contingency, configuration, security plan, package, and remediation.
  • Finish with full-length timed practice using 100 questions in 170 minutes.

If you are unsure how demanding this will feel, our guide to how hard the CFCP exam is sets realistic expectations, and the CFCP cheat sheet is useful for last-pass review.

Legacy Frameworks Versus Current Policy

The published curriculum names DIACAP, DoD RMF, DCID 6/3, and ICD 503 alongside NIST and FedRAMP. Treat the older approaches as comparative and historical material. Do not assume every method named in the course remains current policy. When a question or your own work depends on present-day requirements, anchor your understanding in current primary NIST and federal materials rather than in the course outline alone.

ApproachHow to Treat It When Studying
NIST RMF and FISMA publicationsPrimary current reference for present-day compliance facts
FedRAMPStudy as a federal cloud authorization program with its own process
DoD RMFCompare against the NIST approach; note where it is DoD-specific
DIACAP, DCID 6/3, ICD 503Comparative and historical context; do not present as current policy

Key Takeaway

When the course outline and current NIST guidance seem to differ, trust the current primary source for how things work today, and use the outline to understand what topics the issuer expects you to know.

Frequently Asked Questions

Are the 22 CFCP domains officially weighted?

No weights have been published. The 22 subjects are the unweighted FISMA101 course outline, with 11 under Day 1 and 11 under Day 2. Official scored-domain weights and exhaustive exam coverage remain unverified, so prepare across all subjects.

Do the seven RMF steps equal the CFCP domains?

No. The RMF steps are a risk-management process from NIST. The CFCP's 22 subjects are organized differently. RMF knowledge is valuable background, but it is not a map of the exam.

How many questions and how much time does the exam allow?

The issuer's current page specifies 100 multiple-choice and true/false questions with a 170-minute limit. Confirm appointment and registration arrangements with the FISMA Center directly. See CFCP exam dates for scheduling context.

Is attending the FISMA101 course mandatory?

No. The issuer recommends its courses, resource pages, and the FISMA Compliance Handbook Second Edition, but course attendance is not mandatory. The course does include an exam voucher and supplies a CFCP study guide only to students. Review CFCP certification cost for pricing considerations.

What experience does certification require?

One year of FISMA compliance experience, verified after you pass the exam. The reviewed pages do not specify a passing threshold, scored/unscored split, open/closed-book policy, or proctoring arrangement, so confirm those details with the issuer before test day.

Ready to pass your CFCP exam?

Put this into practice with free CFCP questions across every exam domain.