- The Short Answer: What a CFCP Is
- Who Issues the Credential and What It Assesses
- What the Exam Looks Like
- The 22 Course Subjects Candidates Should Master
- Why the Seven RMF Steps Are Not the Exam Map
- The Experience Requirement After You Pass
- Training Path: FISMA101 and the Handbook
- Legacy Frameworks in the Curriculum
- Who Benefits From Holding a CFCP
- Sequencing Your Preparation by Domain
- Frequently Asked Questions
- CFCP means Certified FISMA Compliance Practitioner, administered by The FISMA Center, not any other credential sharing the acronym.
- The issuer's current exam page specifies 100 multiple-choice and true/false questions in 170 minutes.
- Certification also requires one year of FISMA compliance experience, verified after you pass the exam.
- Passing threshold, scored/unscored split, and proctoring rules are not stated on the reviewed public pages.
The Short Answer: What a CFCP Is
A CFCP is a Certified FISMA Compliance Practitioner: a professional who has passed an assessment on federal information-security compliance and who can show hands-on FISMA experience. The credential centers on a practical question: can you define and test security controls, interpret what the test results mean, and recommend risk-based corrective action?
That focus separates it from broad security certifications. A CFCP is not about general network defense or penetration testing. It is about the compliance lifecycle that federal agencies and their contractors live inside: categorizing systems, documenting controls, assessing them, packaging evidence, and remediating findings.
Who Issues the Credential and What It Assesses
The FISMA Center administers the CFCP. It also provides FISMA training for federal agencies, universities, and private companies, which matters for understanding how the credential is built: the exam and the training come from the same source, and the exam page itself recommends the issuer's courses, resource pages, and the FISMA Compliance Handbook, Second Edition as preparation.
According to the issuer, the assessment addresses three connected skills:
- Defining and testing security controls, including how controls are selected, documented, and verified.
- Interpreting test results, meaning you can read assessment output and understand what it says about a system's actual security posture.
- Recommending risk-based corrective action, which means prioritizing remediation by risk rather than treating every finding equally.
Official reference points for background reading include the issuer's site at fismacenter.com and NIST's pages on the Risk Management Framework and FISMA background. For the full certification picture, our page on CFCP certification is a good companion.
What the Exam Looks Like
The current public issuer exam page specifies the following format:
| Exam Attribute | What the Issuer Specifies |
|---|---|
| Question count | 100 questions |
| Question types | Multiple-choice and true/false |
| Time limit | 170 minutes (two hours fifty minutes) |
| Passing threshold | Not specified on the reviewed pages |
| Scored vs. unscored split | Not specified on the reviewed pages |
| Open/closed-book policy | Not specified on the reviewed pages |
| Proctoring arrangement | Not specified on the reviewed pages |
| Scored-domain weights | Not verified |
The unknowns in that table are deliberate. Rather than guess at a cut score or a proctoring model, treat them as items to confirm directly with the issuer before you register. Appointment and registration arrangements should also be confirmed with The FISMA Center. Our pages on the CFCP passing score and CFCP exam dates track what is and is not publicly confirmed.
With 100 questions in 170 minutes, you have roughly a minute and a half per question on average. Multiple-choice and true/false items in a compliance exam tend to reward precise reading: a single qualifier like "always," "only," or "before" can flip a true/false answer, and a multiple-choice question about a deliverable usually hinges on knowing which document comes from which step.
The 22 Course Subjects Candidates Should Master
The issuer's FISMA101 course outline lists 22 subjects, 11 under Day 1 and 11 under Day 2. These are unweighted course subjects, not an official weighted exam blueprint, and exhaustive exam coverage remains unverified. Still, they are the best published map of what a candidate is expected to know. Grouped by theme, they look like this:
Foundations: Terminology, Methodologies, Process, and Program
These subjects establish the vocabulary and structure everything else depends on.
- Explanation of FISMA Terminology: the language of authorization, controls, and assessment.
- FISMA Compliance Methodologies: how different approaches to compliance compare.
- Understanding the Process and Risk Management Framework (RMF)
- Establishing an Information Security Program
- FISMA Project Management: treating a compliance effort as a managed project with milestones and deliverables.
Scoping the System: Information Types, Inventory, and Categorization
Everything downstream depends on correctly scoping what you are protecting.
- Determining the Information Types & Sensitivity Level
- Preparing the Hardware and Software Inventory: an incomplete inventory undermines every later assessment.
- FIPS 199: Categorizing Data Sensitivity: the standard for categorizing information and systems by impact.
People and Operations: Awareness, Behavior, and Incidents
- Security Awareness Training
- Rules of Behavior
- Incident Response
Testing and Risk Assessment
This cluster maps most directly to the issuer's stated emphasis on testing controls and interpreting results.
- Performing Security Testing
- Conducting a Privacy Impact Assessment
- Performing a Business Risk Assessment
- Performing a System Risk Assessment
- Preparing a Business Impact Assessment
Planning Documents
- Developing an IT Contingency Plan
- Developing a Configuration Management Plan
- Developing a System Security Plan: the central document describing a system and its controls.
Packaging, Review, and Remediation
- Submitting the Certification Package
- Evaluating the Certification Package
- Addressing Compliance Findings: the remediation step where risk-based corrective action comes into play.
For a deeper treatment of each area, read our complete guide to all 22 CFCP content areas.
Why the Seven RMF Steps Are Not the Exam Map
A common mistake is to assume the CFCP exam is organized around the seven steps of NIST's Risk Management Framework. It is not. The RMF steps describe a risk-management process that systems move through; the CFCP's subject list is a different structure that happens to touch RMF concepts, among many other things.
Studying the RMF is still valuable. It is relevant background, and the process shows up under "Understanding the Process and Risk Management Framework (RMF)." But if you build your whole study plan around seven steps, you will under-prepare for subjects like Rules of Behavior, the Privacy Impact Assessment, the Business Impact Assessment, or Configuration Management planning, which do not sit neatly as one-per-step topics.
Key Takeaway
Use NIST's RMF and FISMA publications as background, but build your study plan from the 22 course subjects. The RMF process is a lens for some topics, not the organizing principle of the exam.
The Experience Requirement After You Pass
One feature that distinguishes this credential is how experience is handled. Certification requires one year of FISMA compliance experience, verified after you pass the exam. In other words, the exam and the experience verification are separate hurdles, and the sequencing differs from credentials that require experience before you may sit for the test.
Practically, that means a candidate early in a compliance career can attempt the assessment while still accumulating qualifying experience. Details about what documentation the issuer accepts and how verification works should be confirmed with The FISMA Center. Our CFCP requirements guide collects what is publicly known about eligibility and prerequisites.
Training Path: FISMA101 and the Handbook
The issuer's recommended preparation centers on its FISMA101 course. Key facts from the published course page:
- It is a two-day course with six CPE credits per day, twelve in total.
- Those CPE credits and the two-day duration describe the course itself. They are not the exam timer, the number of exam questions, or a renewal obligation.
- The page advertises tentative 2026 offerings and states that an exam voucher is included.
- A CFCP study guide is supplied only to course students; no private study guide was accessed in preparing this article.
- Course attendance is not mandatory. The exam page recommends the issuer's courses, resource pages, and the FISMA Compliance Handbook, Second Edition, but does not require them.
If you are weighing whether to take the course or self-study, our pages on CFCP training, CFCP certification cost, and the CFCP study guide walk through the options. Confirm current pricing and voucher terms directly with the issuer, since offerings and arrangements can change.
Legacy Frameworks in the Curriculum
The published curriculum surveys several compliance approaches: NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503, and FedRAMP. Some of these are historical or sector-specific, and a candidate should read them as comparative material rather than assuming every method reflects current policy.
| Approach | How to Treat It When Studying |
|---|---|
| NIST (RMF and FISMA publications) | Primary current federal material; use official NIST sources for present-day facts |
| DoD RMF | Defense-sector application of risk management; verify current DoD policy before relying on specifics |
| FedRAMP | Cloud-focused authorization program; check current program documentation |
| DIACAP | Historical comparative material |
| DCID 6/3 | Historical comparative material |
| ICD 503 | Intelligence-community approach; treat as comparative context and confirm current status |
The practical lesson: understand why these approaches differ and what concepts they share, but when a question or a real-world task turns on current requirements, defer to current primary NIST and federal sources.
Who Benefits From Holding a CFCP
The credential fits people whose daily work touches federal information-security compliance. Typical environments include:
- Federal agencies, where system owners, ISSOs, and compliance staff prepare and review authorization documentation.
- Contractors supporting federal systems, who must produce evidence packages that meet agency expectations.
- Universities handling federal data or research systems, which fall under similar compliance expectations.
- Private companies seeking to sell into the federal market and needing staff fluent in the compliance process.
Roles that map naturally include compliance analysts, security control assessors, ISSOs, and project managers who coordinate certification packages. We discuss the hiring side in CFCP jobs, and the earnings and return-on-investment questions in the CFCP salary guide and our ROI analysis. No salary figures are quoted here because none are verified for this credential.
Sequencing Your Preparation by Domain
If you plan your own study schedule, order matters more than volume. Because the subjects build on one another, a logical sequence follows the lifecycle of a compliance effort. One simple way to lay it out:
Vocabulary and Framing
- Terminology, methodologies, and the RMF process (Domains 1-3)
- Why first: every later subject assumes you speak the language
Scoping the System
- Security program, project management, information types, inventory, and FIPS 199 (Domains 4-8)
- Why here: categorization drives which controls and assessments apply later
Operations and Assessment
- Awareness training, rules of behavior, incident response, security testing (Domains 9-12)
- Why here: testing and interpreting results is the issuer's stated core skill
Risk and Planning Documents
- PIA, business and system risk assessments, BIA, contingency and configuration plans, SSP (Domains 13-19)
Packaging and Remediation
- Submit and evaluate the certification package, then address findings (Domains 20-22)
- Finish with timed practice across all 22 areas
This is a sketch, not a prescription; adjust the pace to your experience. Someone who already writes system security plans daily can compress Week 4 and spend more time on terminology and legacy-framework comparisons. For a reusable review aid, our CFCP cheat sheet condenses the must-know facts, and you can test yourself with the CFCP practice tests.
Key Takeaway
Because there are no verified scored-domain weights, do not over-invest in any one area. Aim for even working knowledge across all 22 subjects, then shore up weak spots using practice questions rather than guesses about which topics "count more."
Frequently Asked Questions
It stands for Certified FISMA Compliance Practitioner, a credential administered by The FISMA Center. The acronym is shared by other unrelated credentials, so confirm the issuer when researching. See also What Is CFCP? and CFCP Meaning.
The current public issuer exam page specifies 100 multiple-choice and true/false questions with a 170-minute (two hours fifty minutes) limit. Confirm appointment and registration arrangements with the issuer.
The reviewed public pages do not specify a passing threshold, a scored/unscored split, an open/closed-book policy, or a proctoring arrangement. Ask The FISMA Center directly, and check our passing score page for updates.
Certification requires one year of FISMA compliance experience, but that experience is verified after you pass the exam rather than before you sit for it. Confirm the verification process with the issuer.
No. Course attendance is not mandatory, though the issuer recommends its courses, resource pages, and the FISMA Compliance Handbook, Second Edition. The two-day course carries twelve CPE credits and advertises an included exam voucher; those credits are course credits, not an exam timer or renewal obligation.
Whether you are new to federal compliance or formalizing years of experience, the CFCP rewards candidates who understand the full lifecycle from categorization through remediation. Build your plan around the 22 subjects, lean on current NIST sources for present-day requirements, and use practice questions to find the gaps before the real exam does.