CFCP logo
Focused certification exam prep
Start practice

CFCP Passing Score 2026: Exactly What You Need to Pass

TL;DR
  • The reviewed public FISMA Center pages do not state a CFCP passing threshold, so any specific cut score you see online is unverified.
  • The exam is 100 multiple-choice and true/false questions with a 170-minute limit, roughly 1.7 minutes per question.
  • Certification also requires one year of verified FISMA compliance experience, confirmed after you pass the exam.
  • Official scored-domain weights are not published; the FISMA101 outline lists 22 unweighted subjects, so prepare broadly rather than strategically skipping...

What the Passing Score Question Really Looks Like

Search for the passing score on almost any certification and you will find a tidy number: 70 percent, 700 out of 1000, 75 percent. Candidates searching for the Certified FISMA Compliance Practitioner (CFCP) passing score expect the same. The honest answer is less satisfying but more useful: the current public issuer pages reviewed for this article do not specify a passing threshold.

That matters because the CFCP is administered by The FISMA Center, and it is a different credential from every other certification that happens to share the "CFCP" acronym. Cut scores, exam fees and pass rates you may have seen attached to a similarly abbreviated credential do not apply here. If a website quotes a precise CFCP cut score without citing the issuer, treat it with suspicion. This article sticks to what can be verified and tells you plainly where the gaps are.

Why this article exists: A page titled "passing score" that invents a number would do you real harm. You might calibrate your preparation to a threshold that does not exist. Instead, this guide shows what is known, what is unknown, and how to prepare so the exact cut line stops mattering.

What the Issuer Actually Publishes About the Exam

The current public certification page from The FISMA Center, reviewed for this article, specifies the following about the CFCP examination:

  • Question count: 100 questions
  • Question types: multiple-choice and true/false
  • Time limit: two hours fifty minutes (170 minutes)
  • Experience requirement: one year of FISMA compliance experience, verified after passing

What the reviewed pages do not specify is just as important:

  • A passing threshold (percentage, scaled score or otherwise)
  • Whether all 100 questions are scored or some are unscored
  • Whether the exam is open-book or closed-book
  • The proctoring arrangement
  • Official scored-domain weights
Exam DetailStatus in Reviewed Issuer Pages
Number of questionsPublished: 100
Question formatsPublished: multiple-choice and true/false
Time limitPublished: 170 minutes
Passing thresholdNot specified
Scored vs. unscored splitNot specified
Open/closed-book policyNot specified
Proctoring arrangementNot specified
Weighted domain blueprintNot published; course outline is unweighted

Always confirm current registration and appointment arrangements on the issuer's own site at fismacenter.com, since policies can change. For a fuller view of what the certification path involves, see our guide to CFCP requirements, eligibility and prerequisites.

Why You Should Not Chase a Magic Percentage

Even when a cut score is published, chasing the minimum is a poor strategy. With the CFCP, it is worse than poor, because you cannot know the minimum. Three practical reasons to abandon the "how little can I get away with" mindset:

  1. The threshold is unpublished. You cannot reverse-engineer a target from a number that is not on the page.
  2. Weights are unpublished. If some subjects carry more questions than others, a gap in one area could cost more than you expect. The issuer's outline lists subjects without weights, so every subject is potential exposure.
  3. Scenario questions punish shallow knowledge. The assessment addresses defining and testing security controls, interpreting test results and recommending risk-based corrective action. That means applying concepts, not just recalling definitions.

Key Takeaway

Aim for comfortable mastery of all 22 outline subjects instead of a target score. If your practice results are consistently strong across every subject area, the unknown cut line becomes someone else's problem. You can sharpen that approach in our CFCP study guide for a first-attempt pass.

Format, Question Style and Time Math

With 100 questions in 170 minutes, you have an average of about 1.7 minutes per question. That is generous for true/false items and for definitional multiple-choice questions, and tighter for scenario items where you must read a short description of a system, a test result or a finding and choose the best corrective action.

How to Think About Pacing

  • Quick-answer items: Terminology, FIPS 199 impact-level recall and true/false statements about roles and documents should go fast. Banking time here pays off later.
  • Interpretation items: Questions about security test results, risk assessments or certification-package evaluation deserve slower, careful reading.
  • Flagging: If the testing arrangement allows you to revisit questions (confirm this with the issuer), mark uncertain items and return after finishing the first pass.
Don't confuse course time with exam time: The FISMA101 course is a two-day class carrying six CPE credits per day, twelve in total. Those are instructional hours and course credits. They are not the exam timer, and they are not a renewal obligation. The exam clock is the 170 minutes.

If you want a sense of how the difficulty feels relative to preparation effort, our breakdown of how hard the CFCP exam is goes into depth, and the CFCP pass rate article explains why no verified pass-rate figure should be assumed.

What the Questions Cover: The 22-Subject Outline

The issuer's current official outline spans FISMA terminology and methodologies; program and project management; information types, inventory and FIPS 199 categorization; awareness, rules and incident response; security testing and privacy, business and system risk assessments; business impact, contingency and configuration planning; system security planning; submission and evaluation of certification packages; and remediation of findings.

The FISMA101 course breaks this into 22 unweighted subjects, 11 under Day 1 and 11 under Day 2. The issuer's examination page recommends its courses, resource pages and the FISMA Compliance Handbook, Second Edition as preparation, though course attendance is not mandatory. The subjects are:

Foundations: Subjects 1 to 3

Explanation of FISMA Terminology, FISMA Compliance Methodologies, and Understanding the Process and Risk Management Framework (RMF).

  • Know the vocabulary precisely; terminology questions are often the easiest points to win or lose.
  • The published curriculum surveys NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503 and FedRAMP. Treat the legacy approaches as comparative historical material, and use current NIST and federal sources for present-day policy.
  • The seven RMF steps are a risk-management process. They are not a map of the exam's scored domains.

Program, Inventory and Categorization: Subjects 4 to 8

Establishing an Information Security Program, FISMA Project Management, Determining the Information Types and Sensitivity Level, Preparing the Hardware and Software Inventory, and FIPS 199: Categorizing Data Sensitivity.

  • Be able to move from information types to a defensible impact categorization.
  • Understand why an accurate inventory underpins every later compliance activity.

Awareness, Rules and Response: Subjects 9 to 11

Security Awareness Training, Rules of Behavior, and Incident Response.

  • Expect questions on who must be trained and what user-facing rules should address.
  • Know the stages and documentation expectations of an incident response capability.

Testing and Risk Assessment: Subjects 12 to 15 and 17

Performing Security Testing, Conducting a Privacy Impact Assessment, Performing a Business Risk Assessment, Preparing a Business Impact Assessment, and Performing a System Risk Assessment.

  • Practice reading a described test result and choosing the finding or corrective action it implies.
  • Distinguish privacy, business and system-level risk views and what each produces.

Planning Documents: Subjects 16, 18 and 19

Developing an IT Contingency Plan, Developing a Configuration Management Plan, and Developing a System Security Plan.

  • Know what each plan contains and how the business impact assessment feeds contingency planning.
  • Understand how the system security plan consolidates control descriptions for the system.

Package and Findings: Subjects 20 to 22

Submitting the Certification Package, Evaluating the Certification Package, and Addressing Compliance Findings.

  • These are the capstone subjects. They test whether you can follow a package from submission through evaluation to remediation.
  • Risk-based corrective action is the recurring theme: which finding to fix first, and why.

For a deeper walk through each area, read our complete guide to all 22 CFCP content areas.

Passing vs. Becoming Certified

One detail that surprises many candidates: certification requires one year of FISMA compliance experience, verified after you pass. Passing the exam is therefore one milestone, not the finish line. If you are new to the field, that sequencing means you can sit the exam while still accumulating experience, but you will not hold the full credential until the experience is verified.

  • If you already have a year or more of FISMA work: Plan your documentation of that experience alongside your exam prep so verification is smooth.
  • If you are early in your career: Passing can still be a valuable signal, but understand the credential is not complete until the experience condition is met. See CFCP requirements for the full picture.

The financial side deserves its own look. The FISMA101 course page advertises tentative 2026 offerings and includes an exam voucher, and a CFCP study guide is supplied only to course students; no private study guide was accessed for this article. Our CFCP certification cost breakdown covers how to think about the pricing, and the ROI analysis helps you decide whether it fits your career plan.

What to Verify With the Issuer Before Exam Day

Because the public pages leave several scoring and delivery questions open, send the issuer a short, specific email or ask during registration. A well-prepared list:

  1. Is there a published passing threshold, and how is it expressed (percentage or scaled)?
  2. Are all 100 questions scored, or are some unscored?
  3. Is the exam open-book or closed-book, and are any reference materials permitted?
  4. How is the exam proctored, and what are the technical or location requirements?
  5. Can I flag and return to questions within the 170 minutes?
  6. When are results released, and what is the retake policy?
  7. How and when is the one-year experience requirement verified?
Write down the answers: Policies change. Keep the date and the name of whoever confirmed each answer, and prefer written confirmation. Scheduling details are covered further in our guide to CFCP exam dates and scheduling.

A Domain-Sequenced Prep Plan

Since the exam rewards breadth and application, sequence your study so that each stage builds on the last. This is one possible six-week arrangement built around the outline, not an official schedule.

Weeks 1-2

Vocabulary, Methods and Categorization

  • Terminology, methodologies, and the RMF as a process.
  • Information types, inventory and FIPS 199 categorization. Do these early because later plans depend on them.
  • Read NIST's RMF overview and FISMA background pages for current context.
Weeks 3-4

Operational Controls, Testing and Risk

  • Awareness training, rules of behavior, incident response.
  • Security testing, then privacy, business and system risk assessments. Practice interpreting results.
Week 5

Planning Documents

  • Business impact assessment, contingency plan, configuration management plan and system security plan, studied as a connected set.
Week 6

Packages, Findings and Full Review

  • Certification package submission and evaluation, then remediation of findings.
  • Timed mixed practice and a weak-area sweep across all 22 subjects. Use the CFCP practice tests to simulate the pacing.

Once you are comfortable with the material, a condensed reference like our CFCP cheat sheet is useful for final review, and the main practice test site lets you rehearse the 100-question rhythm.

Frequently Asked Questions

What is the CFCP passing score?

The reviewed public pages from The FISMA Center do not specify a passing threshold. Confirm directly with the issuer before relying on any number you find elsewhere, and be cautious of figures that come from credentials sharing the CFCP acronym.

How many questions are on the CFCP exam and how long do I have?

The current issuer page specifies 100 multiple-choice and true/false questions with a time limit of two hours fifty minutes, or 170 minutes.

Is the CFCP exam open-book?

The reviewed pages do not state an open-book or closed-book policy, nor the proctoring arrangement. Ask The FISMA Center to confirm both when you register.

Do I need experience before taking the exam?

Certification requires one year of FISMA compliance experience, which is verified after you pass the exam. Passing and being fully certified are separate milestones.

Are the exam domains weighted?

Official scored-domain weights have not been verified. The FISMA101 course outline lists 22 unweighted subjects, so study all of them rather than guessing which carry more questions. See the domains guide for each subject in detail.

The bottom line: you cannot prepare for a number that has not been published, but you can prepare for the exam that has been. Master the 22 subjects, practice applying them to testing results and findings, and get the scoring and delivery details confirmed in writing from the issuer.

Ready to pass your CFCP exam?

Put this into practice with free CFCP questions across every exam domain.