- What CFCP Training Actually Means
- The FISMA101 Course: Format, Credits, and What You Get
- Mapping the 22 Subjects to the Exam Domains
- Legacy Frameworks in the Curriculum: Context, Not Current Policy
- NIST Material That Reinforces the Course
- Scenario Skills the Exam Rewards
- A Domain-Sequenced Plan Around the Course
- Exam Format and Logistics to Confirm
- Who Benefits Most From the Training
- Frequently Asked Questions
- The FISMA Center's FISMA101 is a two-day course with six CPE credits per day, twelve total.
- Course attendance is recommended by the issuer but not mandatory for taking the CFCP exam.
- The published outline has 22 unweighted subjects: 11 under Day 1 and 11 under Day 2.
- The exam is 100 multiple-choice and true/false questions with a 170-minute limit.
What CFCP Training Actually Means
When people search for CFCP training, they usually want to know one thing: what should I do to prepare for the Certified FISMA Compliance Practitioner exam, and is formal instruction part of it? The credential is administered by The FISMA Center, which also provides FISMA training for federal agencies, universities, and private companies. That relationship matters, because the issuer's own course is the preparation path it explicitly recommends.
The issuer's examination page recommends its courses, its resource pages, and the FISMA Compliance Handbook, Second Edition as preparation. It does not require course attendance. Training is therefore best understood as a recommended route rather than a gate, and you can combine it with self-study using the free federal publications covered below. For a broader view of the credential itself, see our overview of CFCP certification and the explainer on what CFCP is.
The FISMA101 Course: Format, Credits, and What You Get
The issuer's recommended preparation course is FISMA101. Based on the current public training page, here is what is documented:
- Length: two days.
- Credits: six CPE credits per day, twelve in total.
- Exam voucher: the course page indicates an exam voucher is included.
- Study guide: a CFCP study guide is supplied only to course students, so its contents cannot be described here.
- Schedule: the page advertises tentative 2026 offerings, so confirm actual dates with the issuer before planning travel or leave.
One distinction is easy to miss. The two days and twelve CPE credits describe the course. They are not the exam timer, not the number of exam questions, and not a renewal obligation. Do not conflate the 12 course credits with anything about the exam or maintaining the credential.
| Item | Course (FISMA101) | Exam (CFCP) |
|---|---|---|
| Duration | Two days | 170 minutes (two hours fifty minutes) |
| Format | Instructor-led course outline of 22 subjects | 100 multiple-choice and true/false questions |
| Credits | Six CPE per day, twelve total | Not applicable |
| Required? | No, recommended | Yes, to earn the credential |
For cost questions, the course price and voucher arrangements should be confirmed directly with the issuer. Our CFCP certification cost breakdown explains how to think through the components without relying on unverified figures.
Mapping the 22 Subjects to the Exam Domains
The issuer's FISMA101 outline lists 22 subjects, with 11 published under Day 1 and 11 under Day 2. These are unweighted course subjects, not an official weighted blueprint, and exhaustive exam coverage remains unverified. Still, the outline gives you a clear, issuer-published picture of what the program teaches. The 22 domains used on this site follow the same progression, from terminology through remediation of findings. For a full walkthrough of each one, see CFCP exam domains: the complete guide to all 22 content areas.
The current official outline groups the material into these clusters: FISMA terminology and methodologies; program and project management; information types, inventory, and FIPS 199 categorization; awareness, rules, and incident response; security testing and privacy, business, and system risk assessments; business impact, contingency, and configuration planning; system security planning; submission and evaluation of certification packages; and remediation of findings.
Foundations: Domains 1-5
Explanation of FISMA Terminology, FISMA Compliance Methodologies, Understanding the Process and Risk Management Framework (RMF), Establishing an Information Security Program, and FISMA Project Management.
- Be fluent in the vocabulary before attempting scenarios; many wrong answers hinge on misreading a term.
- Understand how a security program is organized and how a compliance effort is managed as a project.
- Know the RMF as a risk-management process, but do not treat its seven steps as a map of exam domains.
System Characterization: Domains 6-8
Determining the Information Types and Sensitivity Level, Preparing the Hardware and Software Inventory, and FIPS 199: Categorizing Data Sensitivity.
- Practice identifying information types and assigning impact levels to confidentiality, integrity, and availability.
- Understand why an accurate inventory underpins every later activity.
- Be ready to justify a categorization decision, not only recall the standard.
Operational Safeguards: Domains 9-11
Security Awareness Training, Rules of Behavior, and Incident Response.
- Distinguish the purpose of awareness training from the purpose of rules of behavior.
- Know the phases and responsibilities of incident response at a conceptual level.
Testing and Risk Assessment: Domains 12-17
Performing Security Testing, Conducting a Privacy Impact Assessment, Performing a Business Risk Assessment, Preparing a Business Impact Assessment, Developing an IT Contingency Plan, and Performing a System Risk Assessment.
- This cluster is the heart of the exam's emphasis on defining and testing controls and interpreting results.
- Learn how a business impact assessment feeds contingency planning.
- Be able to tell privacy, business, and system risk assessments apart.
Documentation, Submission, and Remediation: Domains 18-22
Developing a Configuration Management Plan, Developing a System Security Plan, Submitting the Certification Package, Evaluating the Certification Package, and Addressing Compliance Findings.
- Understand what belongs in a system security plan and a certification package.
- Practice the reviewer's perspective when evaluating a package.
- Be ready to recommend corrective action for findings in a risk-based order.
Legacy Frameworks in the Curriculum: Context, Not Current Policy
One unusual feature of the published FISMA101 curriculum is that it surveys several approaches: NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503, and FedRAMP. Some of these are historical. Treat the legacy items as comparative context that shows how federal certification and accreditation thinking evolved, not as a statement that every named method remains current policy.
A practical habit: when you take notes on a framework, label each one "current," "historical," or "comparative." That small discipline prevents the common mistake of importing an outdated requirement into a scenario answer. It also connects directly to the exam's first two areas, FISMA terminology and compliance methodologies, which is where our CFCP cheat sheet is most useful as a quick refresher.
NIST Material That Reinforces the Course
Alongside the course, NIST's public material provides relevant background. The Risk Management Framework pages and the FISMA background pages at csrc.nist.gov are free and authoritative. They are best used to deepen understanding of the process you meet in the course, particularly the vocabulary and the logic of risk-based control selection and assessment.
Keep one caution in mind: the seven RMF steps are a risk-management process, not a CFCP exam-domain map. A candidate who organizes their study strictly by RMF step may under-prepare on topics the exam outline treats separately, such as security awareness training, rules of behavior, or the privacy impact assessment. Use the RMF for conceptual grounding and the issuer's 22-subject outline for coverage.
How to Use Federal Publications Productively
- Read for definitions first, then for the relationships between documents and activities.
- Pair each publication with the matching course subject, for example FIPS 199 with categorization.
- Note where a publication describes a process and where it prescribes an artifact such as a plan or report.
Scenario Skills the Exam Rewards
The issuer describes the assessment as addressing three practical capabilities: defining and testing security controls, interpreting test results, and recommending risk-based corrective action. That framing suggests the exam rewards judgment applied to realistic situations, not memorization of lists. The question formats are multiple-choice and true/false, so precision in reading matters.
Defining and Testing Controls
Be able to explain what a control is meant to accomplish and what evidence would show that it works.
- Connect each control to the system's categorization and risk.
- Distinguish a control's design from its implementation and operation.
Interpreting Test Results
Be able to read a finding and judge what it implies for the system's risk posture.
- Separate an isolated weakness from a systemic one.
- Understand how results flow into the certification package and its evaluation.
Recommending Risk-Based Corrective Action
Be able to prioritize remediation by risk rather than by convenience.
- Match the corrective action to the severity and the system's sensitivity level.
- Understand how findings are tracked to closure.
If you are weighing how demanding this style of question will feel, our guide on how hard the CFCP exam is discusses difficulty without relying on invented statistics.
A Domain-Sequenced Plan Around the Course
Rather than generic scheduling advice, sequence your preparation around the course and the way the domains build on one another. Early domains supply vocabulary, middle domains build the system's risk picture, and late domains test your ability to document and remediate. The timeline below is a suggestion you can compress or stretch to fit your calendar.
Read ahead on terminology
- Skim Domains 1-3 vocabulary and the NIST RMF overview pages.
- Label each framework as current, historical, or comparative.
Attend both FISMA101 days
- Take notes against the 22-subject outline.
- Flag any subject where the instructor's examples felt unfamiliar.
Categorization and inventory
- Rework Domains 6-8 with a sample system of your own.
- Practice assigning confidentiality, integrity, and availability impact levels.
Assessments and planning
- Compare the privacy, business, and system risk assessments side by side.
- Trace how a business impact assessment drives the contingency plan.
Package and findings
- Review Domains 18-22, then practice evaluating a package as a reviewer would.
- Draft risk-based remediation recommendations for sample findings.
For a fuller approach to pacing and resources, see the CFCP study guide. When you are ready to test retention, use the CFCP practice tests to find which domains need another pass.
Key Takeaway
Schedule the scenario-heavy clusters, security testing, risk assessments, the certification package, and remediation, closest to your exam date. They depend on the vocabulary and categorization work from earlier domains, so they benefit most from being reviewed last.
Exam Format and Logistics to Confirm
Based on the current public issuer pages, the exam is 100 multiple-choice and true/false questions with a time limit of two hours fifty minutes, which is 170 minutes. Beyond that, several details are not specified on the reviewed pages, and you should confirm them with The FISMA Center rather than assume:
- The passing threshold (see our note on the CFCP passing score for how we handle this unknown).
- Whether the questions are all scored or include unscored items.
- Whether the exam is open-book or closed-book.
- Whether and how proctoring is arranged.
- Appointment and registration arrangements, including timing relative to the course.
Scheduling questions are covered in CFCP exam dates, and the broader qualification picture is in CFCP requirements. A key point: certification requires one year of FISMA compliance experience, and that experience is verified after you pass the exam. Passing the exam and earning the credential are therefore separate milestones.
Who Benefits Most From the Training
FISMA training serves a wide audience, since the issuer delivers it to federal agencies, universities, and private companies. The people most likely to gain from it are those who work with or around federal information-security compliance: security analysts supporting authorization packages, system owners and ISSOs, contractors serving federal customers, auditors and assessors, and program managers who need to speak the language of controls and findings.
If you are weighing the return on the investment, our analysis of whether the CFCP is worth it frames the decision, and CFCP jobs covers the kinds of roles where the credential is relevant. We deliberately avoid quoting salary numbers that the issuer has not published; for earnings context, see the CFCP salary guide.
Frequently Asked Questions
No. The issuer's examination page recommends its courses, resource pages, and the FISMA Compliance Handbook, Second Edition, but course attendance is not mandatory. You can prepare through self-study if you prefer.
FISMA101 is a two-day course with six CPE credits per day, twelve in total. These figures describe the course only. They are not the exam timer, the number of exam questions, or a renewal requirement.
The current issuer page specifies 100 multiple-choice and true/false questions with a 170-minute limit. The reviewed pages do not state a passing threshold, a scored/unscored split, an open- or closed-book policy, or proctoring details, so confirm those with The FISMA Center.
The published curriculum surveys NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503, and FedRAMP. Some of these are historical, so treat them as comparative context and use current primary NIST and federal materials for present-day compliance facts.
Yes. Certification requires one year of FISMA compliance experience, which is verified after you pass the exam. See CFCP requirements for how to think about qualifying experience.
Whether you take the two-day course, study independently, or combine both, the strongest preparation ties each of the 22 subjects to a concrete scenario: categorize a system, test a control, read a finding, and recommend a risk-based fix. For more on the credential's identity and scope, revisit what CFCP certification is, and for broader background on the program, the CFCP training resources on this site, then check your readiness with the practice test.