CFCP logo
Focused certification exam prep
Start practice

What Is CFCP Certification?

TL;DR
  • CFCP means Certified FISMA Compliance Practitioner, a credential administered by The FISMA Center.
  • The published exam format is 100 multiple-choice and true/false questions in 170 minutes.
  • Certification also requires one year of verified FISMA compliance experience after you pass the exam.
  • Passing score, proctoring and open-book policy are not specified on the reviewed issuer pages.

What the CFCP Credential Actually Is

CFCP stands for Certified FISMA Compliance Practitioner. It is a professional credential built around the Federal Information Security Modernization Act (FISMA) compliance work that federal agencies, their contractors and other regulated organizations perform. If you have seen the same four letters attached to other certifications in finance, payments or other fields, set those aside. This article, and this site, concern only the FISMA-focused credential.

The assessment centers on three practical abilities: defining and testing security controls, interpreting the results of that testing, and recommending risk-based corrective action. That emphasis tells you what kind of professional the credential is aimed at. It is not a pure policy exam and it is not a deep technical exploit exam. It sits in the middle, where an analyst has to look at a system, decide what controls apply, judge whether they work, and explain what should be fixed first.

If you are looking for shorter definitional pages, we also cover the basics in What Is CFCP?, What Does CFCP Stand For? and CFCP Meaning. This page goes further into how the credential works.

Who Issues It and What the Exam Tests

The credential is administered by The FISMA Center, which also provides FISMA training for federal agencies, universities and private companies. That dual role matters: the same organization that sets the certification examination also runs the recommended preparation course. The issuer's examination page expressly recommends its courses, its resource pages and the FISMA Compliance Handbook, Second Edition as preparation, although attending a course is not mandatory.

For background reading outside the issuer's materials, NIST publishes the authoritative public documentation on the FISMA background and the Risk Management Framework. These are useful for understanding the regulatory vocabulary, but they are background study material, not a substitute for the issuer's outline.

Scope reminder: The official scored-domain weights and exhaustive exam coverage are not published in the sources we reviewed. The 22 content areas below come from the issuer's current course outline. They are unweighted subjects, so treat them as a thorough map of what to learn rather than a statement of how many questions each topic receives.

Exam Format: What Is and Is Not Published

The current issuer examination page specifies the following:

ItemWhat the issuer publishes
Number of questions100
Question typesMultiple-choice and true/false
Time limitTwo hours fifty minutes (170 minutes)
Passing thresholdNot specified on reviewed pages
Scored vs. unscored splitNot specified on reviewed pages
Open- or closed-book policyNot specified on reviewed pages
Proctoring arrangementNot specified on reviewed pages
Post-exam requirementOne year of FISMA compliance experience, verified

A few practical observations follow from this. With 170 minutes for 100 questions, the pacing works out to well over a minute and a half per item, which is generous for true/false and standard multiple-choice formats. The mix of true/false and multiple-choice means you will see some binary statements about FISMA practice, so precision with terminology matters: a single qualifier such as "always" or "only" can flip a statement from true to false.

Because the passing score, scoring structure and proctoring details are not stated in the reviewed public pages, you should confirm them directly with the issuer before you register. We keep a dedicated page on CFCP passing score and another on exam dates and scheduling, and both are careful to separate what is confirmed from what is not. Likewise, the issuer's registration and appointment arrangements should be confirmed with the issuer rather than assumed.

The 22 Content Areas, Grouped by Work Phase

The issuer's FISMA101 course outline lists 22 subjects: 11 published under Day 1 and 11 under Day 2. Rather than memorizing them as a flat list, it helps to group them by the kind of work they represent. The full breakdown is in our complete guide to all 22 CFCP content areas; here is the practical grouping.

Foundations: terminology, methods and program structure

Domains 1-5: Foundations and Program Management

These cover Explanation of FISMA Terminology, FISMA Compliance Methodologies, Understanding the Process and Risk Management Framework (RMF), Establishing an Information Security Program, and FISMA Project Management.

  • Know the vocabulary precisely, because true/false items hinge on exact definitions.
  • Be able to explain how a compliance effort is organized as a project with roles, milestones and deliverables.
  • Understand where the RMF fits as a process without confusing it with the exam's own structure.

Scoping the system: information types, inventory and categorization

Domains 6-8: Information Types, Inventory and FIPS 199

Determining the Information Types and Sensitivity Level, Preparing the Hardware and Software Inventory, and FIPS 199: Categorizing Data Sensitivity.

  • Practice moving from an information type to a security categorization.
  • Recognize why an accurate inventory is the foundation for everything that follows.
  • Be comfortable explaining confidentiality, integrity and availability impact reasoning.

People and operations: awareness, behavior and incidents

Domains 9-11: Awareness, Rules of Behavior and Incident Response

Security Awareness Training, Rules of Behavior, and Incident Response.

  • Understand how training and behavioral rules function as controls.
  • Know the stages of a response program and what documentation it produces.

Testing and risk: assessments across business, privacy and system views

Domains 12-15 and 17: Testing and Assessments

Performing Security Testing, Conducting a Privacy Impact Assessment, Performing a Business Risk Assessment, Preparing a Business Impact Assessment, and Performing a System Risk Assessment.

  • This is where the credential's stated focus on testing controls and interpreting results shows up most directly.
  • Learn to distinguish the purpose of each assessment type, since scenario questions often hinge on picking the right one.

Planning documents: contingency, configuration and system security

Domains 16, 18 and 19: Planning Documents

Developing an IT Contingency Plan, Developing a Configuration Management Plan, and Developing a System Security Plan.

  • Know what each plan contains and which assessment feeds it.
  • The system security plan is the central document that ties the others together.

Packaging and closing out: certification and findings

Domains 20-22: Certification Package and Remediation

Submitting the Certification Package, Evaluating the Certification Package, and Addressing Compliance Findings.

  • Understand both sides of the package: preparing it and reviewing it.
  • Remediation of findings ties directly to the credential's emphasis on recommending risk-based corrective action.

The FISMA101 Course and Exam Voucher

The issuer's recommended preparation path is FISMA101, a two-day course. It carries six CPE credits per day, twelve in total. It is important not to misread those numbers: they describe the instructional duration and the course's own credits. They are not the exam timer, not a count of exam questions, and not a renewal obligation for the certification.

According to the issuer's training page, the course advertises tentative 2026 offerings, includes an exam voucher, and supplies a CFCP study guide to course students only. We did not access that private study guide, so we cannot describe its contents. If you are weighing whether the course is the right route for you, compare the options in our pieces on CFCP training and CFCP certification cost, and confirm current pricing and session dates with the issuer directly.

Course is optional, not mandatory: The issuer states that attending its courses is not required to sit the exam. That said, because the course includes a voucher and the only official study guide, many candidates will find it the most direct route. Self-study candidates should lean on the issuer's resource pages, the handbook the issuer recommends, and primary NIST publications.

The Experience Requirement After You Pass

One feature that distinguishes this credential from many exams is the sequencing of its experience requirement. Certification requires one year of FISMA compliance experience, verified after passing the exam. In other words, the exam itself is not gated behind a long prerequisite, but full certification is not complete until the experience is documented.

For career planning, that shapes who should consider taking the exam early. A professional already doing compliance work can pass and then verify experience they already have. Someone newer to the field can pass the exam as a way to build structured knowledge, then accumulate the year of experience. For a fuller discussion of eligibility, see CFCP requirements.

Why the Seven RMF Steps Are Not the Exam Blueprint

A common mistake is to assume that the seven steps of NIST's Risk Management Framework are the CFCP's scored domains. They are not. The RMF steps describe a risk-management process that organizations follow to manage security and privacy risk. The CFCP's own outline is organized around 22 course subjects covering terminology, project management, categorization, assessments, planning documents and certification packages.

The two overlap in subject matter, of course. Categorization, control selection, assessment and authorization all appear in both worlds. But if you study only the seven RMF steps, you will miss topics the course outline treats as separate subjects, such as rules of behavior, incident response and the privacy impact assessment. Use the RMF as context and the issuer's outline as your checklist.

AspectNIST RMFCFCP course outline
NatureSeven-step risk-management process22 unweighted course subjects
PurposeGuides how organizations manage system riskDefines what a candidate should learn for the credential
Use in studyBackground and vocabularyPrimary checklist for coverage

Legacy Frameworks in the Curriculum

The published curriculum surveys a range of approaches: NIST, DIACAP, DoD RMF, DCID 6/3, ICD 503 and FedRAMP. It is worth being clear-eyed about what that means. Several of these, such as DIACAP and DCID 6/3, are historical approaches that have been superseded in federal practice. They appear in the curriculum as comparative material, helping candidates understand how compliance methods evolved, not as a claim that every named method is current policy.

When you need present-day facts, such as which publications currently govern control selection or assessment, go to current primary NIST and federal materials, not to any single course outline. A good habit while studying is to label each fact in your notes as either "current requirement" or "historical context." That habit protects you on exam day and on the job.

Who Benefits From This Credential

The issuer trains personnel at federal agencies, universities and private companies, and that mix points to the audiences for the credential:

  • Federal agency staff who prepare or review authorization documentation and need a shared vocabulary for FISMA work.
  • Contractors supporting federal systems who must produce compliant documentation for their customers.
  • University and research personnel handling federally regulated information.
  • Private-sector compliance and risk analysts who work with federal customers or adopt federal-style control programs.

Specific roles vary, so rather than quote unverified numbers, we suggest browsing real postings and reading our overview of CFCP jobs. For the economics, our salary guide and ROI analysis discuss what can and cannot be said responsibly about earnings without inventing figures. If you are gauging effort, how hard the exam is and what the pass-rate data does and does not show are worth reading before you commit.

Sequencing Your Preparation Around the Domains

Because the 22 areas build on one another, the order in which you study them matters more than the total number of hours. A sensible sequence follows the logic of a real compliance engagement, which is also how the documents depend on each other:

Week 1

Vocabulary and scoping

  • Domains 1-5: terminology, methodologies, RMF context, program and project management.
  • Why first: every later topic assumes you can use the terms precisely.
Week 2

Categorization and inventory

  • Domains 6-8: information types, inventory and FIPS 199 categorization.
  • Why here: categorization drives which controls and how much testing apply later.
Week 3

People, incidents and assessments

  • Domains 9-15 and 17: awareness, rules of behavior, incident response, security testing and the privacy, business and system risk assessments.
  • Why here: this is the core of the credential's testing and risk focus, so give it the most time.
Week 4

Plans, packages and findings

  • Domains 16, 18-22: contingency, configuration and security plans, then certification package submission, evaluation and remediation.
  • Why last: these documents pull together everything studied earlier.

Adjust the pacing to your background. Someone with hands-on assessment experience may compress Week 3, while a newcomer may stretch Week 1. For a fuller plan, see our CFCP study guide, and keep the one-page cheat sheet handy for last-minute review. When you are ready to test yourself on scenario-style questions, try the free practice questions on the main practice test site.

Key Takeaway

Study the documents in the order they depend on each other: terms, then categorization and inventory, then assessments, then plans, then the certification package and findings. Note the cause-and-effect links between them, because scenario questions tend to test those links rather than isolated definitions.

Frequently Asked Questions

What does CFCP stand for?

On this site, CFCP stands for Certified FISMA Compliance Practitioner, a credential administered by The FISMA Center. Other credentials elsewhere use the same acronym, but this article concerns only the FISMA-focused one. See also What Is CFCP Certification? and CFCP Certification.

How many questions are on the exam and how long do I get?

The issuer's current examination page specifies 100 multiple-choice and true/false questions with a time limit of two hours fifty minutes, which is 170 minutes.

What is the passing score?

The reviewed public issuer pages do not specify a passing threshold, a scored/unscored split, an open- or closed-book policy, or a proctoring arrangement. Confirm these details with the issuer before registering rather than relying on third-party claims.

Do I need experience before taking the exam?

Certification requires one year of FISMA compliance experience that is verified after you pass the exam. The experience requirement is therefore part of completing certification, not a published gate to sitting the test.

Is the FISMA101 course required?

No. The issuer recommends its courses, resource pages and the FISMA Compliance Handbook, Second Edition, but states that course attendance is not mandatory. The two-day FISMA101 course carries twelve CPE credits in total, includes an exam voucher, and provides a study guide only to course students.

Are the seven RMF steps the same as the CFCP exam domains?

No. The RMF steps are a risk-management process. The CFCP course outline is a separate list of 22 unweighted subjects, and official scored-domain weights are not published in the sources we reviewed.

Ready to pass your CFCP exam?

Put this into practice with free CFCP questions across every exam domain.