<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security+ or CC in Member Support</title>
    <link>https://community.isc2.org/t5/Member-Support/Security-or-CC/m-p/87874#M12173</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;I don't think you need to do a CC.&lt;!-- StartFragment  --&gt;&lt;/P&gt;&lt;P&gt;Take a look at the summary below. I hope it answers your question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security+ is the deeper, more technical certification; ISC2 CC is the lighter, foundational starting point. That’s the core difference. Everything else is nuance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;!-- StartFragment  --&gt;&lt;/P&gt;&lt;P&gt;CGRC sits above both Security+ and ISC2 CC in depth, scope, and career impact. It’s the first certification in this trio that is truly governance‑heavy, framework‑driven.&lt;/P&gt;&lt;HR /&gt;&lt;H3&gt;🧩 What CGRC actually is&lt;/H3&gt;&lt;P&gt;CGRC (Certified in Governance, Risk and Compliance) is ISC2’s certification focused on &lt;STRONG&gt;risk management frameworks&lt;/STRONG&gt;, &lt;STRONG&gt;authorization processes&lt;/STRONG&gt;, and &lt;STRONG&gt;continuous monitoring&lt;/STRONG&gt;. It’s built around NIST RMF but applies broadly to enterprise governance.&lt;/P&gt;&lt;P&gt;It validates that you can:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Interpret and apply security and privacy frameworks&lt;/LI&gt;&lt;LI&gt;Run risk assessments and categorize systems&lt;/LI&gt;&lt;LI&gt;Select, implement, and assess controls&lt;/LI&gt;&lt;LI&gt;Support audit readiness and compliance reporting&lt;/LI&gt;&lt;LI&gt;Guide organizations through governance processes&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This is the first cert in the lineup that directly maps to your day‑to‑day GRC governance work.&lt;/P&gt;&lt;HR /&gt;&lt;H3&gt;🧠 How CGRC compares to CC and Security+&lt;/H3&gt;&lt;P&gt;&lt;STRONG&gt;ISC2 CC&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Foundation-level&lt;/LI&gt;&lt;LI&gt;High-level concepts&lt;/LI&gt;&lt;LI&gt;No deep framework work&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Security+&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Technical baseline&lt;/LI&gt;&lt;LI&gt;Threats, vulnerabilities, architecture, operations&lt;/LI&gt;&lt;LI&gt;Not governance‑focused&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;CGRC&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Governance and risk specialization&lt;/LI&gt;&lt;LI&gt;Frameworks, controls, authorization, compliance&lt;/LI&gt;&lt;LI&gt;Scenario-heavy and aligned with real GRC workflows&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":direct_hit:"&gt;🎯&lt;/span&gt; Career impact&lt;/H3&gt;&lt;P&gt;CGRC signals that you can operate at a &lt;STRONG&gt;governance and compliance practitioner level&lt;/STRONG&gt;, not just understand cybersecurity basics.&lt;/P&gt;&lt;P&gt;It’s especially relevant for:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;GRC analyst / specialist&lt;/LI&gt;&lt;LI&gt;Risk analyst&lt;/LI&gt;&lt;LI&gt;Compliance analyst&lt;/LI&gt;&lt;LI&gt;Audit readiness roles&lt;/LI&gt;&lt;LI&gt;FedRAMP / NIST RMF environments&lt;/LI&gt;&lt;LI&gt;Enterprise governance teams&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;It’s also a strong differentiator for senior GRC roles because it demonstrates you can &lt;STRONG&gt;run&lt;/STRONG&gt; a governance process, not just understand it.&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;!-- EndFragment  --&gt;&lt;/P&gt;&lt;P&gt;&lt;!-- EndFragment  --&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Feb 2026 04:48:53 GMT</pubDate>
    <dc:creator>mdouble2</dc:creator>
    <dc:date>2026-02-09T04:48:53Z</dc:date>
    <item>
      <title>Security+ or CC</title>
      <link>https://community.isc2.org/t5/Member-Support/Security-or-CC/m-p/87220#M12143</link>
      <description>&lt;P&gt;I just recently passed the CompTIA Security+ exam, and I wanted to find out if I should still take the CC. I am currently a MIS student and would like to pursue a career in GRC.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 16:04:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Security-or-CC/m-p/87220#M12143</guid>
      <dc:creator>leri_R</dc:creator>
      <dc:date>2026-01-16T16:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Security+ or CC</title>
      <link>https://community.isc2.org/t5/Member-Support/Security-or-CC/m-p/87874#M12173</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;I don't think you need to do a CC.&lt;!-- StartFragment  --&gt;&lt;/P&gt;&lt;P&gt;Take a look at the summary below. I hope it answers your question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security+ is the deeper, more technical certification; ISC2 CC is the lighter, foundational starting point. That’s the core difference. Everything else is nuance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;!-- StartFragment  --&gt;&lt;/P&gt;&lt;P&gt;CGRC sits above both Security+ and ISC2 CC in depth, scope, and career impact. It’s the first certification in this trio that is truly governance‑heavy, framework‑driven.&lt;/P&gt;&lt;HR /&gt;&lt;H3&gt;🧩 What CGRC actually is&lt;/H3&gt;&lt;P&gt;CGRC (Certified in Governance, Risk and Compliance) is ISC2’s certification focused on &lt;STRONG&gt;risk management frameworks&lt;/STRONG&gt;, &lt;STRONG&gt;authorization processes&lt;/STRONG&gt;, and &lt;STRONG&gt;continuous monitoring&lt;/STRONG&gt;. It’s built around NIST RMF but applies broadly to enterprise governance.&lt;/P&gt;&lt;P&gt;It validates that you can:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Interpret and apply security and privacy frameworks&lt;/LI&gt;&lt;LI&gt;Run risk assessments and categorize systems&lt;/LI&gt;&lt;LI&gt;Select, implement, and assess controls&lt;/LI&gt;&lt;LI&gt;Support audit readiness and compliance reporting&lt;/LI&gt;&lt;LI&gt;Guide organizations through governance processes&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This is the first cert in the lineup that directly maps to your day‑to‑day GRC governance work.&lt;/P&gt;&lt;HR /&gt;&lt;H3&gt;🧠 How CGRC compares to CC and Security+&lt;/H3&gt;&lt;P&gt;&lt;STRONG&gt;ISC2 CC&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Foundation-level&lt;/LI&gt;&lt;LI&gt;High-level concepts&lt;/LI&gt;&lt;LI&gt;No deep framework work&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Security+&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Technical baseline&lt;/LI&gt;&lt;LI&gt;Threats, vulnerabilities, architecture, operations&lt;/LI&gt;&lt;LI&gt;Not governance‑focused&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;CGRC&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Governance and risk specialization&lt;/LI&gt;&lt;LI&gt;Frameworks, controls, authorization, compliance&lt;/LI&gt;&lt;LI&gt;Scenario-heavy and aligned with real GRC workflows&lt;/LI&gt;&lt;/UL&gt;&lt;HR /&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":direct_hit:"&gt;🎯&lt;/span&gt; Career impact&lt;/H3&gt;&lt;P&gt;CGRC signals that you can operate at a &lt;STRONG&gt;governance and compliance practitioner level&lt;/STRONG&gt;, not just understand cybersecurity basics.&lt;/P&gt;&lt;P&gt;It’s especially relevant for:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;GRC analyst / specialist&lt;/LI&gt;&lt;LI&gt;Risk analyst&lt;/LI&gt;&lt;LI&gt;Compliance analyst&lt;/LI&gt;&lt;LI&gt;Audit readiness roles&lt;/LI&gt;&lt;LI&gt;FedRAMP / NIST RMF environments&lt;/LI&gt;&lt;LI&gt;Enterprise governance teams&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;It’s also a strong differentiator for senior GRC roles because it demonstrates you can &lt;STRONG&gt;run&lt;/STRONG&gt; a governance process, not just understand it.&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;!-- EndFragment  --&gt;&lt;/P&gt;&lt;P&gt;&lt;!-- EndFragment  --&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 04:48:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Security-or-CC/m-p/87874#M12173</guid>
      <dc:creator>mdouble2</dc:creator>
      <dc:date>2026-02-09T04:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Security+ or CC</title>
      <link>https://community.isc2.org/t5/Member-Support/Security-or-CC/m-p/87885#M12174</link>
      <description>&lt;P&gt;Thank you for the detailed reply. gave me the answer to my question plus more!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 13:23:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Security-or-CC/m-p/87885#M12174</guid>
      <dc:creator>leri_R</dc:creator>
      <dc:date>2026-02-09T13:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Security+ or CC</title>
      <link>https://community.isc2.org/t5/Member-Support/Security-or-CC/m-p/87894#M12175</link>
      <description>Great to hear. If you like my response, please give it a kudos.</description>
      <pubDate>Mon, 09 Feb 2026 16:57:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/Security-or-CC/m-p/87894#M12175</guid>
      <dc:creator>mdouble2</dc:creator>
      <dc:date>2026-02-09T16:57:59Z</dc:date>
    </item>
  </channel>
</rss>

