Advanced

GIAC Critical Controls Certification (GCCC)

Validates practical knowledge and skills in implementing and auditing the CIS Critical Security Controls.

LevelAdvancedDuration24 hoursAssessment1 proctored exam — 75 questions — minimum passing score 71%LanguageEnglish
Professional learning for GIAC Critical Controls Certification (GCCC)
About this certification

Build a credential that gives your experience greater visibility

The GIAC Critical Controls Certification (GCCC) validates a practitioner's knowledge and skills in implementing and executing the CIS Critical Security Controls. The certification covers the 18 CIS Critical Security Controls Version 8, including implementation, auditing, defenses, policies, cloud guidance, automation, control measures, and standards mapping. It is designed for cybersecurity professionals, auditors, IT administrators, security engineers, risk officers, consultants, and other professionals responsible for protecting enterprise systems and information. GIAC describes GCCC as a Practitioner Certification aligned with CIS Controls Version 8.

Use the guided application to bring your profile, identity documents and qualification evidence together. You can save your progress, return later and follow the review from your applicant dashboard.

What this can add to your profile

  • ✓ Validates practical knowledge of the CIS Critical Security Controls
  • ✓ Demonstrates ability to implement and execute CIS Controls
  • ✓ Develops skills for auditing security controls
  • ✓ Covers all 18 CIS Critical Security Controls Version 8
  • ✓ Builds practical cybersecurity risk-management capabilities
  • ✓ Demonstrates knowledge of security controls, policies, automation, and standards mapping
  • ✓ Supports professional development for cybersecurity and information assurance roles
  • ✓ Provides a GIAC-recognized cybersecurity credential upon successful certification

Who should apply

  • ✓ No formal prerequisites are required to purchase or begin a GIAC certification attempt.
  • ✓ Basic understanding of information security concepts and technologies is recommended.
  • ✓ Familiarity with common security tools and IT infrastructure is recommended.
  • ✓ Candidates should have an understanding of networks, servers, applications, and cybersecurity controls.

Documents to prepare

  • ✓ Government-issued ID card
  • ✓ Passport photograph
  • ✓ Highest education certificate — may be uploaded after application