This CGRC cheat sheet distills the ISC2 Certified in Governance, Risk and Compliance exam into a printable rundown of the facts examiners test most across the seven NIST RMF-based domains. It's a premium cheat sheet built by Capital Prep — the one premium prep we trust — and it's yours free. Reinforce it with the rest of your free CGRC toolkit: the practice test, study guide, and flashcards.
CGRC exam at a glance
- Questions: 125 items (100 scored + 25 unscored pretest)
- Time: 3 hours
- Passing score: 700 out of 1000 (scaled)
- Cost: $249 USD (Americas); recertify every 3 years with 60 CPE credits plus a $135 annual maintenance fee
What’s on the CGRC cheat sheet
- GRC & Compliance Program (16%) — governance, risk management, frameworks and laws, and the RMF Prepare step — the foundation domain.
- Scope of the System (10%) — the authorization boundary, information types, and FIPS 199 categorization with the high-water mark.
- Selection & Approval of Controls (14%) — the FIPS 199 → FIPS 200 → 800-53B baseline → tailoring flow, plus common, compensating, and overlay controls.
- Implementation of Controls (17%) — deploying and documenting controls in the System Security Plan (SSP) — the heaviest domain.
- Assessment/Audit of Controls (16%) — the SCA, the Examine/Interview/Test methods, and the SAR feeding the POA&M.
- System Compliance (14%) — the authorization package, the RMF roles, and the ATO, ATO-with-conditions, DATO, and IATT decisions.
- Compliance Maintenance (13%) — continuous monitoring (ISCM), change management with security impact analysis, and secure decommissioning.
How to use it in your final week
- Memorize the RMF spine cold — Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor — because every domain maps to one step and many items ask for the best next step.
- Front-load Implementation (17%), the GRC program (16%), and Assessment (16%): together they are about half the exam, so drill these three before the lighter domains.
- Lock in the three high-frequency rules the morning of the exam — the FIPS 199 high-water mark, the SSP + SAR + POA&M authorization package, and the separation rule (the SCA assesses, the AO accepts the risk).
- Pair each review pass with a short timed practice set so scenario pacing across the 3-hour, 125-question window feels routine.
The cheat sheet is your review layer — your CGRC practice test drives the exam-readiness ring at the top of this page. Download it, review, then take a full practice exam (or drill with the study guide and flashcards) to see where you stand.
CGRC cheat sheet FAQ
Yes — the CGRC cheat sheet is 100% free to download as a PDF, with no sign-up required. It's part of Career Employer's free CGRC toolkit alongside the practice test, study guide, and flashcards.
The cheat sheet condenses the highest-yield facts into a quick reference: the seven NIST RMF steps, the FIPS 199 high-water mark rule, the authorization package (SSP, SAR, POA&M), the RMF roles, and the ATO/DATO/IATT decisions — organized around the seven ISC2 domains and their exam weights.
It's built from ISC2's current CGRC exam outline (effective June 15, 2024) and the NIST RMF (SP 800-37 Rev. 2), and we review it against those official sources regularly.
No — the cheat sheet is a review and last-week cram aid, not a substitute for working scenario questions. You need a scaled score of 700 out of 1000, and the CGRC tests judgment (the best next RMF step), so use the sheet to lock in facts and the practice test to build readiness.
Click the download button (or the preview card) at the top of this page to open the PDF instantly. Bookmark this page so you can find it again in your final week before the exam.
References
- 1.ISC2. “CGRC — Certified in Governance, Risk and Compliance.” isc2.org, 2026. ↑
- 2.ISC2. “CGRC Certification Exam Outline (effective June 15, 2024).” isc2.org, 2026. ↑
- 3.National Institute of Standards and Technology. “SP 800-37 Rev. 2: Risk Management Framework for Information Systems and Organizations.” csrc.nist.gov. ↑
- 4.National Institute of Standards and Technology. “FIPS 199: Standards for Security Categorization of Federal Information and Information Systems.” csrc.nist.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
