ISC2 Certified in Governance, Risk and Compliance (CGRC) develops the knowledge and practical skills required to manage security and privacy risk, apply regulatory and framework requirements, and support the authorization and continued operation of information systems. It is intended for professionals working in governance, risk management, compliance, assessment, and security authorization, as well as organizations responsible for demonstrating that systems meet defined security and privacy requirements.
The curriculum follows the full compliance lifecycle, from establishing a governance and risk management program through system scoping, control selection, implementation, assessment, authorization, and ongoing monitoring. Participants examine how frameworks and regulations are translated into system requirements, how security and privacy controls are tailored and documented, how assessments and audits are conducted, and how compliance is maintained as systems, threats, and organizational requirements change.
CGRC is most relevant to security and privacy officers, risk managers, compliance professionals, assessors, auditors, system owners, and others involved in information system authorization. ISC2 requires two years of relevant professional experience for certification. For organizations, the training helps establish consistent governance and assessment practices, improve the quality of authorization documentation, and strengthen coordination among technical teams, compliance functions, leadership, and other stakeholders.