CFCP logo
Focused certification exam prep
Start practice

CFCP Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • The Certified FISMA Compliance Practitioner credential is administered by The FISMA Center, not by ISC2 or any other body.
  • The exam is 100 multiple-choice and true/false questions with a 170-minute limit.
  • Certification requires one year of FISMA compliance experience, verified after you pass the exam.
  • FISMA101 is recommended preparation, but the issuer states course attendance is not mandatory.

What Actually Qualifies You for the CFCP

Many candidates searching for CFCP requirements expect a long list of gatekeeping prerequisites: degree minimums, mandatory training hours, endorsement letters. The Certified FISMA Compliance Practitioner credential is structured differently. The public requirements center on two things: passing the examination and demonstrating one year of FISMA compliance experience, with that experience verified after the exam is passed.

This article walks through exactly what the issuer, The FISMA Center, has published, what it has not published, and how to build a realistic path to qualification. If you are still orienting yourself, start with What Is CFCP Certification? for the credential's background, then return here for the qualification details.

Identity check: "CFCP" is an acronym shared by several unrelated credentials. This site covers only the Certified FISMA Compliance Practitioner credential from The FISMA Center. Fees, dates, and pass statistics belonging to any other CFCP do not apply here.

The Two-Part Requirement: Exam First, Experience Second

Part One: Pass the Examination

The examination is the entry point. It assesses whether you can define and test security controls, interpret test results, and recommend risk-based corrective action. That emphasis on assessment and remediation shapes what you should be able to do before sitting for it: read a control, determine how it would be tested, judge what a result means, and propose a defensible fix.

Part Two: One Year of Verified FISMA Compliance Experience

The experience requirement is notable for its sequencing. The issuer's published position is that certification requires one year of FISMA compliance experience verified after passing. In practical terms, that means:

  • You can sit for the exam without having completed the experience year.
  • Full certification depends on the experience being verified once the exam is passed.
  • The nature of qualifying experience (federal agency work, contractor work, internal compliance roles) should be confirmed directly with The FISMA Center, since the reviewed public pages do not itemize acceptable roles.

If you are early in your career, this sequencing matters. You may be able to start the credential process while accumulating the experience. If you already work in federal information-security compliance, you may be able to satisfy both parts quickly. For a look at the kinds of roles that put you in that position, see CFCP Jobs.

Why the order matters: Because experience is verified after passing, the exam is not a formality you complete at the end of a career. It is a knowledge gate you can approach while you are still building practical hours. Plan your study around the exam first, and keep records of your compliance work for the verification step.

Exam Format You Need to Plan Around

Eligibility is not just about paperwork. It is also about being prepared for the format. According to the issuer's current examination page:

  • Question count: 100 questions
  • Question types: multiple-choice and true/false
  • Time limit: two hours fifty minutes (170 minutes)

That works out to roughly one and a half minutes per question on average, which is generous for true/false items and tighter for scenario-style multiple-choice items involving categorization, risk, or findings. If you are curious how this format translates into real difficulty, see How Hard Is the CFCP Exam?.

Registration and Appointment Arrangements

The reviewed public pages advertise tentative 2026 course offerings, and the FISMA101 course includes an exam voucher. For standalone exam registration, appointment options, and any scheduling windows, confirm the current arrangements directly with The FISMA Center. For general scheduling context, our guide to CFCP exam dates covers how to approach planning. For fee-related questions, see CFCP Certification Cost, and verify any specific figures with the issuer rather than relying on secondhand numbers.

FISMA101: Recommended, Not Mandatory

A common point of confusion is whether you must take the issuer's training to qualify. The answer from the issuer's examination page is clear: it expressly recommends its courses, resource pages, and the FISMA Compliance Handbook, Second Edition as preparation, but course attendance is not mandatory.

What FISMA101 Is

  • A two-day course carrying six CPE credits per day, twelve in total.
  • The current outline lists 22 subjects: 11 under Day 1 and 11 under Day 2.
  • The page advertises tentative 2026 offerings and includes an exam voucher.
  • A CFCP study guide is supplied only to course students.
Don't confuse the numbers: The twelve CPE credits describe the course's instructional value. They are not the exam timer, not a count of exam questions, and not a renewal obligation. The exam is 100 questions in 170 minutes, and the course is a separate two-day program.

Course or Self-Study?

Because the course is optional, qualified candidates can choose either path. Course students receive the voucher and the private study guide; self-studiers rely on the handbook, the issuer's resource pages, and NIST's public materials. We have not accessed the private study guide, so we cannot describe its contents. For self-study structure, see our CFCP study guide and the broader overview at CFCP Training.

Knowledge You Must Bring: The 22 Subject Areas

While there is no published list of prior coursework you must hold, the exam expects working command of a defined body of FISMA subject matter. The issuer's current outline spans 22 subjects. Note that these are unweighted course subjects, not an official weighted blueprint, and exhaustive examination coverage remains unverified. Official scored-domain weights have not been published in the reviewed sources.

Grouped by theme, the subjects look like this:

Foundations and Program Setup (Domains 1-5)

You need fluency in the vocabulary and structure of federal compliance before anything else makes sense.

  • FISMA terminology and the methodologies used to achieve compliance
  • The process and Risk Management Framework (RMF), understood as a risk-management process rather than a map of exam domains
  • Establishing an information security program
  • FISMA project management

Identifying and Categorizing What You Protect (Domains 6-8)

Control selection depends on knowing what the system holds and how sensitive it is.

  • Determining information types and sensitivity levels
  • Preparing the hardware and software inventory
  • FIPS 199 categorization of data sensitivity

People, Rules, and Response (Domains 9-11)

Controls are not only technical; the human and procedural layer is examined too.

  • Security awareness training
  • Rules of behavior
  • Incident response

Testing and Risk Assessment (Domains 12-15, 17)

This cluster reflects the credential's core purpose: defining and testing controls and interpreting what the results mean.

  • Performing security testing
  • Conducting a privacy impact assessment
  • Performing a business risk assessment
  • Preparing a business impact assessment
  • Performing a system risk assessment

Planning Documents (Domains 16, 18, 19)

Compliance lives in documentation, so you must know what each plan contains.

  • Developing an IT contingency plan
  • Developing a configuration management plan
  • Developing a system security plan

Packaging, Evaluation, and Remediation (Domains 20-22)

The lifecycle ends with submitting and evaluating a certification package and addressing compliance findings.

  • Submitting the certification package
  • Evaluating the certification package
  • Addressing compliance findings through risk-based corrective action

For a domain-by-domain walkthrough, read CFCP Exam Domains: Complete Guide to All 22 Content Areas.

Historical Methods Appear in the Curriculum

The published curriculum surveys NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503, and FedRAMP. Treat the named legacy approaches as comparative historical material rather than a claim that every method remains current policy. For present-day compliance facts, rely on current primary NIST and federal materials, including the NIST Risk Management Framework overview and the NIST FISMA background page. When you study, keep a mental label on each framework: current practice versus historical context.

Who Is a Natural Fit for This Credential

Because the issuer provides FISMA training for federal agencies, universities, and private companies, the credential's audience is broader than federal employees alone. Typical candidates include:

  • Federal agency staff responsible for system authorization packages, control testing, or remediation tracking.
  • Contractors supporting federal systems who produce system security plans, contingency plans, or assessment reports for agency customers.
  • Private-sector compliance and risk analysts whose organizations handle federal data or pursue federal work.
  • Students and early-career professionals in universities who intend to enter federal information-security compliance and want to begin the exam-then-experience path.

The common thread is the ability to interpret test results and recommend corrective action. If your daily work already involves reviewing scan output, evaluating evidence against a control, or writing findings, you are closer to qualification than your job title might suggest. To weigh whether the investment makes sense for your situation, see Is the CFCP Certification Worth It? and the CFCP Salary Guide, which treat earnings qualitatively rather than quoting unverified figures.

What the Issuer Has Not Published

Responsible planning means being clear about what is not on the record. The reviewed current public pages do not specify:

  • A passing threshold or cut score
  • A scored versus unscored question split
  • Whether the exam is open-book or closed-book
  • Proctoring arrangements
  • Official domain weightings

Key Takeaway

Do not accept a pass-rate or passing-score claim from a third party as fact unless it traces to The FISMA Center. Ask the issuer directly about passing score, proctoring, and reference-material rules before test day. Our pages on CFCP passing score and CFCP pass rate explain what is and is not known.

Mapping Your Readiness Plan to the Domains

Generic study advice has limited value here, so tie your preparation to the exam's actual structure. The sequencing below follows the logic of the compliance lifecycle: vocabulary and categorization first, because later domains depend on them; testing and risk next; documents and packaging last. Adjust the timeline to your own schedule.

Week 1

Terminology, Methodologies, and the RMF

  • Domains 1-3: lock down FISMA vocabulary first, since every later question assumes it
  • Separate current NIST practice from legacy methods (DIACAP, DCID 6/3, ICD 503)
  • Remember the RMF steps are a process, not a domain list
Week 2

Program, Project, and Categorization

  • Domains 4-8: security program, project management, information types, inventory, FIPS 199
  • Practice assigning impact levels, because categorization drives everything downstream
Week 3

Awareness, Behavior, Response, and Testing

  • Domains 9-12: awareness training, rules of behavior, incident response, security testing
  • Focus on reading test results, the credential's core skill
Week 4

Assessments and Planning Documents

  • Domains 13-19: privacy, business risk, business impact, contingency, system risk, configuration management, system security plan
  • Know what each document contains and what question each assessment answers
Week 5

Package and Findings, Then Full Review

  • Domains 20-22: submit and evaluate the certification package, address findings
  • Run timed practice at roughly 100 questions per 170 minutes to rehearse pacing

When you are ready to test your recall under realistic conditions, the CFCP practice tests let you drill domain by domain and then simulate a full-length sitting. A one-page recap helps in the final days; see the CFCP cheat sheet.

Requirement Checklist at a Glance

RequirementWhat the Issuer PublishesYour Action
Certifying bodyThe FISMA CenterUse only issuer-confirmed information
Exam format100 multiple-choice and true/false questionsPractice both question styles
Time limit170 minutes (two hours fifty minutes)Rehearse pacing with timed sets
ExperienceOne year of FISMA compliance experience, verified after passingDocument your compliance work
TrainingFISMA101 recommended; attendance not mandatoryChoose course or self-study
Passing thresholdNot specified in reviewed pagesConfirm with the issuer
Proctoring and book policyNot specified in reviewed pagesConfirm with the issuer
Domain weightsUnweighted course subjects onlyStudy all 22 areas evenly

For a broader orientation to the credential and its terminology, see What Is CFCP? and What Does CFCP Stand For?. The main credential overview lives at CFCP Certification, and you can begin hands-on preparation at the main practice test site.

Frequently Asked Questions

Do I need FISMA experience before I can take the CFCP exam?

According to the issuer, certification requires one year of FISMA compliance experience verified after passing the exam. That indicates experience is part of final certification rather than a precondition for sitting the test. Confirm current eligibility rules with The FISMA Center.

Is the FISMA101 course required to become a Certified FISMA Compliance Practitioner?

No. The issuer's examination page recommends its courses, resource pages, and FISMA Compliance Handbook, Second Edition, but states that course attendance is not mandatory. The course does include an exam voucher and a study guide for enrolled students.

How long is the CFCP exam and how many questions does it have?

The issuer specifies 100 multiple-choice and true/false questions with a time limit of two hours fifty minutes, which is 170 minutes. The twelve CPE credits attached to FISMA101 are a course feature and unrelated to the exam timer.

What is the passing score for the CFCP?

The reviewed current public pages do not specify a passing threshold, scored/unscored question split, open- or closed-book policy, or proctoring arrangement. Ask The FISMA Center directly and treat any unsourced figure with caution.

Are the seven RMF steps the same as the CFCP exam domains?

No. The RMF steps are a risk-management process. The CFCP outline covers 22 subject areas, from FISMA terminology through addressing compliance findings, and official scored-domain weights have not been published. Study both, but do not treat them as interchangeable.

Ready to pass your CFCP exam?

Put this into practice with free CFCP questions across every exam domain.