CFCP logo
Focused certification exam prep
Start practice

What Does CFCP Stand For?

TL;DR
  • CFCP here means Certified FISMA Compliance Practitioner, administered by The FISMA Center.
  • The exam is 100 multiple-choice and true/false questions with a 170-minute limit.
  • Certification also requires one year of FISMA compliance experience, verified after you pass.
  • The seven RMF steps are a risk-management process, not a map of the exam's scored domains.

The Short Answer: Certified FISMA Compliance Practitioner

On this site, CFCP stands for Certified FISMA Compliance Practitioner. It is a credential administered by The FISMA Center, and it is built around federal information-security compliance: defining and testing security controls, interpreting the results of that testing, and recommending risk-based corrective action.

That one-line answer matters because the acronym is shared. If you arrived here from a search for "CFCP," you may have been looking for something else entirely. Everything on this page, and everything on CFCP Exam Prep, refers only to the FISMA-focused credential. If you want the broader overview of the program, our explainer on what CFCP certification is picks up where this article leaves off.

Identity check: If the credential you are researching involves FISMA, control assessment, certification packages, or remediation of compliance findings, you are in the right place. If it involves a different field, the exam details here (format, curriculum, experience requirement) will not apply to it.

Why the Acronym Causes Confusion

Several unrelated credentials use the same four letters. That is a common problem in professional certification, where short acronyms get reused across industries. For a candidate, the practical risk is real: fees, prerequisites, exam length, and renewal rules differ between credentials, and borrowing details from the wrong one can lead to a wasted purchase or a mistaken career plan.

The safest habit is to verify the certifying body. For this credential, that is The FISMA Center. Whenever you read a claim about "the CFCP exam," ask which organization issues it. If the answer is not The FISMA Center, the claim is not about the credential discussed here. Our companion pages, what CFCP stands for and CFCP meaning, address the same question from slightly different angles.

What "FISMA" Is Doing in the Name

FISMA is the Federal Information Security Modernization Act, the statutory backbone for how U.S. federal agencies manage information-security risk. NIST publishes the supporting guidance that agencies use to carry it out, including the Risk Management Framework. NIST's own FISMA background and RMF pages are the authoritative starting points, and they are listed among the official references for this credential.

Putting "FISMA" in the credential name signals scope. This is not a general cybersecurity exam covering everything from cryptography to network engineering. It is a compliance-practice credential: how do you take a federal system from inventory and categorization through testing, documentation, authorization packaging, and remediation of what testing reveals?

What "Practitioner" Signals About the Exam

The word "Practitioner" is the most informative part of the name. It points to applied work rather than abstract theory. The assessment is described as addressing how to define and test security controls, how to interpret test results, and how to recommend risk-based corrective action. Those are verbs a working compliance analyst performs every week.

That framing has a direct effect on how you should read questions. Expect scenarios and decisions rather than pure definition recall. A question may describe a finding from a security test and ask what a practitioner should recommend, or describe a system's data and ask how it should be categorized. Memorizing vocabulary is necessary but not sufficient; you need to know what to do with it. For a closer look at how demanding that is in practice, see how hard the CFCP exam is.

Who Administers the Credential

The FISMA Center administers the credential and also provides FISMA training for federal agencies, universities, and private companies. This dual role is worth understanding. The same organization that sets the credential's expectations also runs the courses that the exam page expressly recommends as preparation.

Two points deserve emphasis:

  • Course attendance is not mandatory. The issuer's exam page recommends its courses, resource pages, and the FISMA Compliance Handbook Second Edition as preparation, but attending a course is not a condition of sitting the exam.
  • The FISMA101 course is a separate thing from the exam. It is a two-day course carrying six CPE credits per day, twelve in total. Those figures describe instructional duration and course credits. They are not the exam timer, not a count of exam questions, and not a renewal obligation.

The issuer's public pages advertise tentative 2026 course offerings, an included exam voucher, and a CFCP study guide supplied only to course students. We have not accessed that private study guide, so we do not describe its contents. For appointment and registration arrangements, confirm directly with the issuer at fismacenter.com. Pricing context is covered in our CFCP certification cost breakdown.

What the Credential Actually Tests

The current official outline covers a connected workflow. In plain terms, the topics run from foundations to documentation to remediation:

  • FISMA terminology and methodologies
  • Program and project management
  • Information types, inventory, and FIPS 199 categorization
  • Awareness, rules, and incident response
  • Security testing, plus privacy, business, and system risk assessments
  • Business impact, contingency, and configuration planning
  • System security planning
  • Submission and evaluation of certification packages
  • Remediation of findings

This site organizes that material into 22 subjects, matching the issuer's FISMA101 course outline (11 published under Day 1 and 11 under Day 2). They are unweighted course subjects, not an official weighted blueprint, and exhaustive exam coverage remains unverified. Treat them as a study map, not a promise about question counts per topic.

The Foundations Cluster

The early subjects establish the language and the structure everything else depends on.

  • Explanation of FISMA Terminology
  • FISMA Compliance Methodologies
  • Understanding the Process and Risk Management Framework (RMF)
  • Establishing an Information Security Program
  • FISMA Project Management

The System Definition Cluster

Before you can test anything, you must know what the system is and how sensitive its data is.

  • Determining the Information Types & Sensitivity Level
  • Preparing the Hardware and Software Inventory
  • FIPS 199: Categorizing Data Sensitivity

The Operational Controls and Assessment Cluster

These subjects cover the people-and-process controls plus the testing and risk work.

  • Security Awareness Training
  • Rules of Behavior
  • Incident Response
  • Performing Security Testing
  • Conducting a Privacy Impact Assessment
  • Performing a Business Risk Assessment
  • Performing a System Risk Assessment

The Planning and Documentation Cluster

Here the work turns into the artifacts an authorizing official reviews.

  • Preparing a Business Impact Assessment
  • Developing an IT Contingency Plan
  • Developing a Configuration Management Plan
  • Developing a System Security Plan

The Package and Remediation Cluster

The closing subjects cover the end of the cycle.

  • Submitting the Certification Package
  • Evaluating the Certification Package
  • Addressing Compliance Findings

For a subject-by-subject walkthrough, see our complete guide to all 22 CFCP content areas.

Exam Format and the Experience Requirement

The current issuer examination page specifies the following:

ItemWhat the Issuer Specifies
Question count100 questions
Question typesMultiple-choice and true/false
Time limitTwo hours fifty minutes (170 minutes)
Experience requirementOne year of FISMA compliance experience, verified after passing
Passing thresholdNot specified on the reviewed pages
Scored/unscored splitNot specified on the reviewed pages
Open- or closed-book policyNot specified on the reviewed pages
Proctoring arrangementNot specified on the reviewed pages
Read the experience rule carefully: The one-year FISMA compliance experience requirement is described as verified after passing. That means certification is the combination of passing the exam and having the experience verified, not the exam alone. Our CFCP requirements guide goes deeper on who qualifies and how.

We deliberately leave the unknowns unknown. The reviewed pages do not state a passing score, so any specific number you see quoted elsewhere should be treated with suspicion until confirmed with the issuer. Our passing score page tracks what is and is not established, and the pass rate discussion explains why no reliable figure should be assumed.

On timing, 170 minutes for 100 questions works out to a generous allowance per question, which suggests scenario-style items that reward careful reading. Scheduling specifics belong with the issuer; our exam dates guide covers how to approach that.

RMF Steps Are Not the Exam Domains

One of the most common mistakes candidates make is assuming the exam is organized around the seven steps of the NIST Risk Management Framework and that each step is a scored domain. It is not. The RMF is a risk-management process. The CFCP outline is a set of subjects a practitioner must master, and while the two overlap heavily in concept, they are not the same structure.

Key Takeaway

Use NIST's RMF and FISMA publications as background reading to understand why each activity exists, but study to the issuer's subject outline for what to expect on the exam. Do not map seven RMF steps onto seven exam sections; the official scored-domain weights remain unverified.

The primary sources for the process itself are NIST's pages on the Risk Management Framework and FISMA background. They are the right place to confirm present-day federal practice.

Legacy Frameworks in the Curriculum

The published curriculum surveys several approaches: NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503, and FedRAMP. A sensible reading of this list is comparative. Some of these methods are historical, and the curriculum's inclusion of them does not mean every one remains current policy.

The practical advice is to separate two questions as you study:

  1. What does the curriculum expect me to recognize? Be able to describe how these approaches relate to and differ from one another.
  2. What is current federal practice? For that, rely on current primary NIST and federal materials, not on older course framing.

Keeping those two questions apart protects you from carrying outdated assumptions into real-world compliance work after you earn the credential.

Who Pursues This Credential

Because FISMA drives how federal agencies manage security, the people drawn to this credential tend to work where federal compliance happens: agency security staff, contractors supporting federal systems, and consultants who prepare or review authorization documentation. The issuer also trains personnel at universities and private companies, which reflects that FISMA-aligned practices reach beyond agencies themselves.

If you are weighing whether it fits your path, our pages on CFCP jobs, the CFCP salary guide, and the worth-it analysis take up the career questions. We avoid quoting specific salary or hiring numbers here because none are established in the issuer's public materials.

Sequencing Your Preparation Around the 22 Subjects

Generic study advice is plentiful, so this section keeps to the one idea that is specific to this credential: the subjects build on each other, so order matters. A candidate who studies incident response before understanding categorization will memorize facts without seeing where they fit. The issuer's curriculum itself flows from definitions to system scoping to assessment to documentation to remediation, and your schedule can follow it.

Week 1

Vocabulary and Program Structure

  • FISMA terminology, methodologies, and the RMF process
  • Information security program and project management
  • Why first: every later subject assumes this language
Week 2

Scoping the System

  • Information types and sensitivity levels
  • Hardware and software inventory
  • FIPS 199 categorization practice
Week 3

Controls, Testing, and Risk

  • Awareness training, rules of behavior, incident response
  • Security testing and interpreting results
  • Privacy, business, and system risk assessments
Week 4

Plans, Package, and Findings

  • BIA, contingency plan, configuration management plan, system security plan
  • Submitting and evaluating the certification package
  • Addressing compliance findings with risk-based recommendations

Finish with timed practice that mirrors the real format: 100 mixed multiple-choice and true/false items in one sitting. You can build that stamina with the CFCP practice tests. For a fuller plan, read the CFCP study guide, and keep the cheat sheet handy for last-pass review.

Frequently Asked Questions

What does CFCP stand for?

On this site, CFCP stands for Certified FISMA Compliance Practitioner, a credential administered by The FISMA Center. The acronym is shared with unrelated credentials, so always confirm the certifying body before relying on any exam details.

How many questions are on the CFCP exam, and how long do I have?

The current issuer examination page specifies 100 multiple-choice and true/false questions with a limit of two hours fifty minutes, which is 170 minutes. Confirm appointment and registration arrangements with the issuer.

Do I need experience to become certified?

Yes. Certification also requires one year of FISMA compliance experience, and that experience is verified after you pass the exam. Passing alone does not complete the certification.

Is the CFCP exam organized by the seven RMF steps?

No. The seven RMF steps are a risk-management process, not a map of the exam's scored domains. Official scored-domain weights and exhaustive exam coverage remain unverified, so study to the issuer's published subject outline instead.

Do I have to take the FISMA101 course to sit the exam?

No. The issuer recommends its courses, resource pages, and the FISMA Compliance Handbook Second Edition, but course attendance is not mandatory. FISMA101 is a two-day course worth twelve CPE credits in total; those are course credits, not exam features.

Ready to pass your CFCP exam?

Put this into practice with free CFCP questions across every exam domain.