- The Short Answer: Certified FISMA Compliance Practitioner
- Why the Acronym Causes Confusion
- What "FISMA" Is Doing in the Name
- What "Practitioner" Signals About the Exam
- Who Administers the Credential
- What the Credential Actually Tests
- Exam Format and the Experience Requirement
- RMF Steps Are Not the Exam Domains
- Legacy Frameworks in the Curriculum
- Who Pursues This Credential
- Sequencing Your Preparation Around the 22 Subjects
- Frequently Asked Questions
- CFCP here means Certified FISMA Compliance Practitioner, administered by The FISMA Center.
- The exam is 100 multiple-choice and true/false questions with a 170-minute limit.
- Certification also requires one year of FISMA compliance experience, verified after you pass.
- The seven RMF steps are a risk-management process, not a map of the exam's scored domains.
The Short Answer: Certified FISMA Compliance Practitioner
On this site, CFCP stands for Certified FISMA Compliance Practitioner. It is a credential administered by The FISMA Center, and it is built around federal information-security compliance: defining and testing security controls, interpreting the results of that testing, and recommending risk-based corrective action.
That one-line answer matters because the acronym is shared. If you arrived here from a search for "CFCP," you may have been looking for something else entirely. Everything on this page, and everything on CFCP Exam Prep, refers only to the FISMA-focused credential. If you want the broader overview of the program, our explainer on what CFCP certification is picks up where this article leaves off.
Why the Acronym Causes Confusion
Several unrelated credentials use the same four letters. That is a common problem in professional certification, where short acronyms get reused across industries. For a candidate, the practical risk is real: fees, prerequisites, exam length, and renewal rules differ between credentials, and borrowing details from the wrong one can lead to a wasted purchase or a mistaken career plan.
The safest habit is to verify the certifying body. For this credential, that is The FISMA Center. Whenever you read a claim about "the CFCP exam," ask which organization issues it. If the answer is not The FISMA Center, the claim is not about the credential discussed here. Our companion pages, what CFCP stands for and CFCP meaning, address the same question from slightly different angles.
What "FISMA" Is Doing in the Name
FISMA is the Federal Information Security Modernization Act, the statutory backbone for how U.S. federal agencies manage information-security risk. NIST publishes the supporting guidance that agencies use to carry it out, including the Risk Management Framework. NIST's own FISMA background and RMF pages are the authoritative starting points, and they are listed among the official references for this credential.
Putting "FISMA" in the credential name signals scope. This is not a general cybersecurity exam covering everything from cryptography to network engineering. It is a compliance-practice credential: how do you take a federal system from inventory and categorization through testing, documentation, authorization packaging, and remediation of what testing reveals?
What "Practitioner" Signals About the Exam
The word "Practitioner" is the most informative part of the name. It points to applied work rather than abstract theory. The assessment is described as addressing how to define and test security controls, how to interpret test results, and how to recommend risk-based corrective action. Those are verbs a working compliance analyst performs every week.
That framing has a direct effect on how you should read questions. Expect scenarios and decisions rather than pure definition recall. A question may describe a finding from a security test and ask what a practitioner should recommend, or describe a system's data and ask how it should be categorized. Memorizing vocabulary is necessary but not sufficient; you need to know what to do with it. For a closer look at how demanding that is in practice, see how hard the CFCP exam is.
Who Administers the Credential
The FISMA Center administers the credential and also provides FISMA training for federal agencies, universities, and private companies. This dual role is worth understanding. The same organization that sets the credential's expectations also runs the courses that the exam page expressly recommends as preparation.
Two points deserve emphasis:
- Course attendance is not mandatory. The issuer's exam page recommends its courses, resource pages, and the FISMA Compliance Handbook Second Edition as preparation, but attending a course is not a condition of sitting the exam.
- The FISMA101 course is a separate thing from the exam. It is a two-day course carrying six CPE credits per day, twelve in total. Those figures describe instructional duration and course credits. They are not the exam timer, not a count of exam questions, and not a renewal obligation.
The issuer's public pages advertise tentative 2026 course offerings, an included exam voucher, and a CFCP study guide supplied only to course students. We have not accessed that private study guide, so we do not describe its contents. For appointment and registration arrangements, confirm directly with the issuer at fismacenter.com. Pricing context is covered in our CFCP certification cost breakdown.
What the Credential Actually Tests
The current official outline covers a connected workflow. In plain terms, the topics run from foundations to documentation to remediation:
- FISMA terminology and methodologies
- Program and project management
- Information types, inventory, and FIPS 199 categorization
- Awareness, rules, and incident response
- Security testing, plus privacy, business, and system risk assessments
- Business impact, contingency, and configuration planning
- System security planning
- Submission and evaluation of certification packages
- Remediation of findings
This site organizes that material into 22 subjects, matching the issuer's FISMA101 course outline (11 published under Day 1 and 11 under Day 2). They are unweighted course subjects, not an official weighted blueprint, and exhaustive exam coverage remains unverified. Treat them as a study map, not a promise about question counts per topic.
The Foundations Cluster
The early subjects establish the language and the structure everything else depends on.
- Explanation of FISMA Terminology
- FISMA Compliance Methodologies
- Understanding the Process and Risk Management Framework (RMF)
- Establishing an Information Security Program
- FISMA Project Management
The System Definition Cluster
Before you can test anything, you must know what the system is and how sensitive its data is.
- Determining the Information Types & Sensitivity Level
- Preparing the Hardware and Software Inventory
- FIPS 199: Categorizing Data Sensitivity
The Operational Controls and Assessment Cluster
These subjects cover the people-and-process controls plus the testing and risk work.
- Security Awareness Training
- Rules of Behavior
- Incident Response
- Performing Security Testing
- Conducting a Privacy Impact Assessment
- Performing a Business Risk Assessment
- Performing a System Risk Assessment
The Planning and Documentation Cluster
Here the work turns into the artifacts an authorizing official reviews.
- Preparing a Business Impact Assessment
- Developing an IT Contingency Plan
- Developing a Configuration Management Plan
- Developing a System Security Plan
The Package and Remediation Cluster
The closing subjects cover the end of the cycle.
- Submitting the Certification Package
- Evaluating the Certification Package
- Addressing Compliance Findings
For a subject-by-subject walkthrough, see our complete guide to all 22 CFCP content areas.
Exam Format and the Experience Requirement
The current issuer examination page specifies the following:
| Item | What the Issuer Specifies |
|---|---|
| Question count | 100 questions |
| Question types | Multiple-choice and true/false |
| Time limit | Two hours fifty minutes (170 minutes) |
| Experience requirement | One year of FISMA compliance experience, verified after passing |
| Passing threshold | Not specified on the reviewed pages |
| Scored/unscored split | Not specified on the reviewed pages |
| Open- or closed-book policy | Not specified on the reviewed pages |
| Proctoring arrangement | Not specified on the reviewed pages |
We deliberately leave the unknowns unknown. The reviewed pages do not state a passing score, so any specific number you see quoted elsewhere should be treated with suspicion until confirmed with the issuer. Our passing score page tracks what is and is not established, and the pass rate discussion explains why no reliable figure should be assumed.
On timing, 170 minutes for 100 questions works out to a generous allowance per question, which suggests scenario-style items that reward careful reading. Scheduling specifics belong with the issuer; our exam dates guide covers how to approach that.
RMF Steps Are Not the Exam Domains
One of the most common mistakes candidates make is assuming the exam is organized around the seven steps of the NIST Risk Management Framework and that each step is a scored domain. It is not. The RMF is a risk-management process. The CFCP outline is a set of subjects a practitioner must master, and while the two overlap heavily in concept, they are not the same structure.
Key Takeaway
Use NIST's RMF and FISMA publications as background reading to understand why each activity exists, but study to the issuer's subject outline for what to expect on the exam. Do not map seven RMF steps onto seven exam sections; the official scored-domain weights remain unverified.
The primary sources for the process itself are NIST's pages on the Risk Management Framework and FISMA background. They are the right place to confirm present-day federal practice.
Legacy Frameworks in the Curriculum
The published curriculum surveys several approaches: NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503, and FedRAMP. A sensible reading of this list is comparative. Some of these methods are historical, and the curriculum's inclusion of them does not mean every one remains current policy.
The practical advice is to separate two questions as you study:
- What does the curriculum expect me to recognize? Be able to describe how these approaches relate to and differ from one another.
- What is current federal practice? For that, rely on current primary NIST and federal materials, not on older course framing.
Keeping those two questions apart protects you from carrying outdated assumptions into real-world compliance work after you earn the credential.
Who Pursues This Credential
Because FISMA drives how federal agencies manage security, the people drawn to this credential tend to work where federal compliance happens: agency security staff, contractors supporting federal systems, and consultants who prepare or review authorization documentation. The issuer also trains personnel at universities and private companies, which reflects that FISMA-aligned practices reach beyond agencies themselves.
If you are weighing whether it fits your path, our pages on CFCP jobs, the CFCP salary guide, and the worth-it analysis take up the career questions. We avoid quoting specific salary or hiring numbers here because none are established in the issuer's public materials.
Sequencing Your Preparation Around the 22 Subjects
Generic study advice is plentiful, so this section keeps to the one idea that is specific to this credential: the subjects build on each other, so order matters. A candidate who studies incident response before understanding categorization will memorize facts without seeing where they fit. The issuer's curriculum itself flows from definitions to system scoping to assessment to documentation to remediation, and your schedule can follow it.
Vocabulary and Program Structure
- FISMA terminology, methodologies, and the RMF process
- Information security program and project management
- Why first: every later subject assumes this language
Scoping the System
- Information types and sensitivity levels
- Hardware and software inventory
- FIPS 199 categorization practice
Controls, Testing, and Risk
- Awareness training, rules of behavior, incident response
- Security testing and interpreting results
- Privacy, business, and system risk assessments
Plans, Package, and Findings
- BIA, contingency plan, configuration management plan, system security plan
- Submitting and evaluating the certification package
- Addressing compliance findings with risk-based recommendations
Finish with timed practice that mirrors the real format: 100 mixed multiple-choice and true/false items in one sitting. You can build that stamina with the CFCP practice tests. For a fuller plan, read the CFCP study guide, and keep the cheat sheet handy for last-pass review.
Frequently Asked Questions
On this site, CFCP stands for Certified FISMA Compliance Practitioner, a credential administered by The FISMA Center. The acronym is shared with unrelated credentials, so always confirm the certifying body before relying on any exam details.
The current issuer examination page specifies 100 multiple-choice and true/false questions with a limit of two hours fifty minutes, which is 170 minutes. Confirm appointment and registration arrangements with the issuer.
Yes. Certification also requires one year of FISMA compliance experience, and that experience is verified after you pass the exam. Passing alone does not complete the certification.
No. The seven RMF steps are a risk-management process, not a map of the exam's scored domains. Official scored-domain weights and exhaustive exam coverage remain unverified, so study to the issuer's published subject outline instead.
No. The issuer recommends its courses, resource pages, and the FISMA Compliance Handbook Second Edition, but course attendance is not mandatory. FISMA101 is a two-day course worth twelve CPE credits in total; those are course credits, not exam features.