CGRC — Certified in Governance, Risk and Compliance
ISC2's GRC certification — formerly known as CAP (Certified Authorization Professional) — covering the NIST Risk Management Framework, authorization processes, and continuous monitoring for federal systems. DoD 8140 approved and particularly recognized in US federal government and contractors operating under FISMA, FedRAMP, and RMF requirements. The name change from CAP to CGRC in 2022 broadened its positioning beyond federal authorization, but the content remains heavily US government framework oriented. Strong for practitioners in the federal civilian and defense contractor space who need to validate RMF expertise.
| Issuer | ISC2 |
| Level | expert |
| Domains | Governance, Risk & Compliance |
| Practical weight | 0% |
| Cost (USD) | 599 |
| Renewal | 3 years |
| DoD 8140 | Yes |
| Skills | risk_management_framework, authorization_process, continuous_monitoring, nist_rmf, security_assessment, governance_documentation, supply_chain_risk |
Official certification page
Browse all 426 cybersecurity certifications on EBCertMap