- What Actually Qualifies You for the CFCP
- The Two-Part Requirement: Exam First, Experience Second
- Exam Format You Need to Plan Around
- FISMA101: Recommended, Not Mandatory
- Knowledge You Must Bring: The 22 Subject Areas
- Who Is a Natural Fit for This Credential
- What the Issuer Has Not Published
- Mapping Your Readiness Plan to the Domains
- Requirement Checklist at a Glance
- Frequently Asked Questions
- The Certified FISMA Compliance Practitioner credential is administered by The FISMA Center, not by ISC2 or any other body.
- The exam is 100 multiple-choice and true/false questions with a 170-minute limit.
- Certification requires one year of FISMA compliance experience, verified after you pass the exam.
- FISMA101 is recommended preparation, but the issuer states course attendance is not mandatory.
What Actually Qualifies You for the CFCP
Many candidates searching for CFCP requirements expect a long list of gatekeeping prerequisites: degree minimums, mandatory training hours, endorsement letters. The Certified FISMA Compliance Practitioner credential is structured differently. The public requirements center on two things: passing the examination and demonstrating one year of FISMA compliance experience, with that experience verified after the exam is passed.
This article walks through exactly what the issuer, The FISMA Center, has published, what it has not published, and how to build a realistic path to qualification. If you are still orienting yourself, start with What Is CFCP Certification? for the credential's background, then return here for the qualification details.
The Two-Part Requirement: Exam First, Experience Second
Part One: Pass the Examination
The examination is the entry point. It assesses whether you can define and test security controls, interpret test results, and recommend risk-based corrective action. That emphasis on assessment and remediation shapes what you should be able to do before sitting for it: read a control, determine how it would be tested, judge what a result means, and propose a defensible fix.
Part Two: One Year of Verified FISMA Compliance Experience
The experience requirement is notable for its sequencing. The issuer's published position is that certification requires one year of FISMA compliance experience verified after passing. In practical terms, that means:
- You can sit for the exam without having completed the experience year.
- Full certification depends on the experience being verified once the exam is passed.
- The nature of qualifying experience (federal agency work, contractor work, internal compliance roles) should be confirmed directly with The FISMA Center, since the reviewed public pages do not itemize acceptable roles.
If you are early in your career, this sequencing matters. You may be able to start the credential process while accumulating the experience. If you already work in federal information-security compliance, you may be able to satisfy both parts quickly. For a look at the kinds of roles that put you in that position, see CFCP Jobs.
Exam Format You Need to Plan Around
Eligibility is not just about paperwork. It is also about being prepared for the format. According to the issuer's current examination page:
- Question count: 100 questions
- Question types: multiple-choice and true/false
- Time limit: two hours fifty minutes (170 minutes)
That works out to roughly one and a half minutes per question on average, which is generous for true/false items and tighter for scenario-style multiple-choice items involving categorization, risk, or findings. If you are curious how this format translates into real difficulty, see How Hard Is the CFCP Exam?.
Registration and Appointment Arrangements
The reviewed public pages advertise tentative 2026 course offerings, and the FISMA101 course includes an exam voucher. For standalone exam registration, appointment options, and any scheduling windows, confirm the current arrangements directly with The FISMA Center. For general scheduling context, our guide to CFCP exam dates covers how to approach planning. For fee-related questions, see CFCP Certification Cost, and verify any specific figures with the issuer rather than relying on secondhand numbers.
FISMA101: Recommended, Not Mandatory
A common point of confusion is whether you must take the issuer's training to qualify. The answer from the issuer's examination page is clear: it expressly recommends its courses, resource pages, and the FISMA Compliance Handbook, Second Edition as preparation, but course attendance is not mandatory.
What FISMA101 Is
- A two-day course carrying six CPE credits per day, twelve in total.
- The current outline lists 22 subjects: 11 under Day 1 and 11 under Day 2.
- The page advertises tentative 2026 offerings and includes an exam voucher.
- A CFCP study guide is supplied only to course students.
Course or Self-Study?
Because the course is optional, qualified candidates can choose either path. Course students receive the voucher and the private study guide; self-studiers rely on the handbook, the issuer's resource pages, and NIST's public materials. We have not accessed the private study guide, so we cannot describe its contents. For self-study structure, see our CFCP study guide and the broader overview at CFCP Training.
Knowledge You Must Bring: The 22 Subject Areas
While there is no published list of prior coursework you must hold, the exam expects working command of a defined body of FISMA subject matter. The issuer's current outline spans 22 subjects. Note that these are unweighted course subjects, not an official weighted blueprint, and exhaustive examination coverage remains unverified. Official scored-domain weights have not been published in the reviewed sources.
Grouped by theme, the subjects look like this:
Foundations and Program Setup (Domains 1-5)
You need fluency in the vocabulary and structure of federal compliance before anything else makes sense.
- FISMA terminology and the methodologies used to achieve compliance
- The process and Risk Management Framework (RMF), understood as a risk-management process rather than a map of exam domains
- Establishing an information security program
- FISMA project management
Identifying and Categorizing What You Protect (Domains 6-8)
Control selection depends on knowing what the system holds and how sensitive it is.
- Determining information types and sensitivity levels
- Preparing the hardware and software inventory
- FIPS 199 categorization of data sensitivity
People, Rules, and Response (Domains 9-11)
Controls are not only technical; the human and procedural layer is examined too.
- Security awareness training
- Rules of behavior
- Incident response
Testing and Risk Assessment (Domains 12-15, 17)
This cluster reflects the credential's core purpose: defining and testing controls and interpreting what the results mean.
- Performing security testing
- Conducting a privacy impact assessment
- Performing a business risk assessment
- Preparing a business impact assessment
- Performing a system risk assessment
Planning Documents (Domains 16, 18, 19)
Compliance lives in documentation, so you must know what each plan contains.
- Developing an IT contingency plan
- Developing a configuration management plan
- Developing a system security plan
Packaging, Evaluation, and Remediation (Domains 20-22)
The lifecycle ends with submitting and evaluating a certification package and addressing compliance findings.
- Submitting the certification package
- Evaluating the certification package
- Addressing compliance findings through risk-based corrective action
For a domain-by-domain walkthrough, read CFCP Exam Domains: Complete Guide to All 22 Content Areas.
Historical Methods Appear in the Curriculum
The published curriculum surveys NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503, and FedRAMP. Treat the named legacy approaches as comparative historical material rather than a claim that every method remains current policy. For present-day compliance facts, rely on current primary NIST and federal materials, including the NIST Risk Management Framework overview and the NIST FISMA background page. When you study, keep a mental label on each framework: current practice versus historical context.
Who Is a Natural Fit for This Credential
Because the issuer provides FISMA training for federal agencies, universities, and private companies, the credential's audience is broader than federal employees alone. Typical candidates include:
- Federal agency staff responsible for system authorization packages, control testing, or remediation tracking.
- Contractors supporting federal systems who produce system security plans, contingency plans, or assessment reports for agency customers.
- Private-sector compliance and risk analysts whose organizations handle federal data or pursue federal work.
- Students and early-career professionals in universities who intend to enter federal information-security compliance and want to begin the exam-then-experience path.
The common thread is the ability to interpret test results and recommend corrective action. If your daily work already involves reviewing scan output, evaluating evidence against a control, or writing findings, you are closer to qualification than your job title might suggest. To weigh whether the investment makes sense for your situation, see Is the CFCP Certification Worth It? and the CFCP Salary Guide, which treat earnings qualitatively rather than quoting unverified figures.
What the Issuer Has Not Published
Responsible planning means being clear about what is not on the record. The reviewed current public pages do not specify:
- A passing threshold or cut score
- A scored versus unscored question split
- Whether the exam is open-book or closed-book
- Proctoring arrangements
- Official domain weightings
Key Takeaway
Do not accept a pass-rate or passing-score claim from a third party as fact unless it traces to The FISMA Center. Ask the issuer directly about passing score, proctoring, and reference-material rules before test day. Our pages on CFCP passing score and CFCP pass rate explain what is and is not known.
Mapping Your Readiness Plan to the Domains
Generic study advice has limited value here, so tie your preparation to the exam's actual structure. The sequencing below follows the logic of the compliance lifecycle: vocabulary and categorization first, because later domains depend on them; testing and risk next; documents and packaging last. Adjust the timeline to your own schedule.
Terminology, Methodologies, and the RMF
- Domains 1-3: lock down FISMA vocabulary first, since every later question assumes it
- Separate current NIST practice from legacy methods (DIACAP, DCID 6/3, ICD 503)
- Remember the RMF steps are a process, not a domain list
Program, Project, and Categorization
- Domains 4-8: security program, project management, information types, inventory, FIPS 199
- Practice assigning impact levels, because categorization drives everything downstream
Awareness, Behavior, Response, and Testing
- Domains 9-12: awareness training, rules of behavior, incident response, security testing
- Focus on reading test results, the credential's core skill
Assessments and Planning Documents
- Domains 13-19: privacy, business risk, business impact, contingency, system risk, configuration management, system security plan
- Know what each document contains and what question each assessment answers
Package and Findings, Then Full Review
- Domains 20-22: submit and evaluate the certification package, address findings
- Run timed practice at roughly 100 questions per 170 minutes to rehearse pacing
When you are ready to test your recall under realistic conditions, the CFCP practice tests let you drill domain by domain and then simulate a full-length sitting. A one-page recap helps in the final days; see the CFCP cheat sheet.
Requirement Checklist at a Glance
| Requirement | What the Issuer Publishes | Your Action |
|---|---|---|
| Certifying body | The FISMA Center | Use only issuer-confirmed information |
| Exam format | 100 multiple-choice and true/false questions | Practice both question styles |
| Time limit | 170 minutes (two hours fifty minutes) | Rehearse pacing with timed sets |
| Experience | One year of FISMA compliance experience, verified after passing | Document your compliance work |
| Training | FISMA101 recommended; attendance not mandatory | Choose course or self-study |
| Passing threshold | Not specified in reviewed pages | Confirm with the issuer |
| Proctoring and book policy | Not specified in reviewed pages | Confirm with the issuer |
| Domain weights | Unweighted course subjects only | Study all 22 areas evenly |
For a broader orientation to the credential and its terminology, see What Is CFCP? and What Does CFCP Stand For?. The main credential overview lives at CFCP Certification, and you can begin hands-on preparation at the main practice test site.
Frequently Asked Questions
According to the issuer, certification requires one year of FISMA compliance experience verified after passing the exam. That indicates experience is part of final certification rather than a precondition for sitting the test. Confirm current eligibility rules with The FISMA Center.
No. The issuer's examination page recommends its courses, resource pages, and FISMA Compliance Handbook, Second Edition, but states that course attendance is not mandatory. The course does include an exam voucher and a study guide for enrolled students.
The issuer specifies 100 multiple-choice and true/false questions with a time limit of two hours fifty minutes, which is 170 minutes. The twelve CPE credits attached to FISMA101 are a course feature and unrelated to the exam timer.
The reviewed current public pages do not specify a passing threshold, scored/unscored question split, open- or closed-book policy, or proctoring arrangement. Ask The FISMA Center directly and treat any unsourced figure with caution.
No. The RMF steps are a risk-management process. The CFCP outline covers 22 subject areas, from FISMA terminology through addressing compliance findings, and official scored-domain weights have not been published. Study both, but do not treat them as interchangeable.