ISC2 wrapped up their One Million Certified in Cybersecurity program last month and the headline reads like a small army of newly minted cybersecurity professionals just hit the workforce. A million people. Certified. Cybersecurity. Sounds incredible.
Then you look at the actual numbers and the whole thing gets a lot smaller.
Here’s what ISC2 said in their April 2026 announcement. More than one million people enrolled in the program over its run from August 2022 to May 2026. Over 570,000 actually went through the free training course. And the number that earned the CC certification at the end of all this? About 65,000.
That’s a 6.5% conversion rate from signup to actual credential. Out of every hundred people who registered, around six walked away with a cert. The rest grabbed a voucher and never finished. Life gets in the way of free things even more than paid ones, because there’s no money on the line to pull you back. I had a coworker years back, guy named Dave, who would sign up for every free training his company offered and finish maybe one out of five. The other four lived in his bookmarks bar as a kind of permanent intention. He’d talk about them at lunch like he was definitely going to get back to that AWS course any day now. The CC program ran into the Dave problem at scale.
I’m not knocking the program. Giving away a million free training seats is a real thing, and getting 65,000 newcomers a foundational cert they might never have paid for is a win. But “One Million Certified” makes it sound like there are a million CC holders walking around with the credential on their LinkedIn. There aren’t. There are about 65,000.
For some context on the scale here, ISC2’s total certified membership across every credential they offer (CISSP, SSCP, CC, CCSP, all of it) sits around 265,000 according to their April 2026 numbers. If a million people really were CC certified, the CC alone would be roughly four times the size of ISC2’s entire certified membership. Doesn’t track, right? Because it isn’t true. The math was always going to land closer to where it landed.
So what does this mean if you’re trying to break into the field and the CC is on your radar? A few things.
The CC is still a real cert. It’s accredited under ANAB ISO/IEC 17024, recognized for entry-level cybersecurity roles, and the body of knowledge actually maps to what you’d be expected to know walking into a SOC analyst or junior IT security job. None of that changes because the marketing number was inflated.
What changes is the signal. If you tell a hiring manager “I have my CC,” that person is not picturing one of a million identical resumes. The actual pool of CC holders is closer in size to a niche specialty cert population than to CompTIA A+ or Security+, both of which have credentialed populations well into the hundreds of thousands. So the CC is more distinctive than the marketing makes it sound.
The free program also closed for new enrollments on May 20, 2026. If you already got a voucher and your exam code hasn’t expired, you have until December 31, 2026 to schedule and sit. After that, the CC exam goes back to costing money like every other ISC2 credential. So if you’re sitting on a voucher and a half-finished study plan, this is your reminder that the clock is running.
If you missed the free wave entirely, the CC exam runs $199 USD plus the $50 annual maintenance fee once you pass. Not free, but not bad for an ISC2 credential when the CISSP exam alone is $749. For career changers and people with no degree trying to get past the resume filter, that math still works out.
The bigger lesson here has nothing to do with the CC specifically. Anytime you see a big round number attached to a certification program, ask what the number is actually counting. The drop from signups to course completions to passed exams is steeper than people assume. ISC2’s own survey data on this program said 65% of employed CC holders are working in cybersecurity roles and another 22% are in IT. That’s a solid placement rate. But it’s a percentage of 65,000, not a million.
For more on entry-level cybersecurity certs and how to actually use them to land a first job, cybertrainingguide.org has a deep bench of guides on this exact path. And if you want the unglamorous government data on what cybersecurity roles actually pay and where they’re growing, the Bureau of Labor Statistics page on information security analysts is the one to bookmark.
Get the CC if you’re starting out. Just don’t believe the part where you’d be joining a million other people. The real number is closer to 65,000. Which, frankly, is a better story for your resume anyway.
Big Dog Cert
Alright, lemme give it to ya straight. No sugarcoating, no corporate fluff, just the real deal. I'm Mike. Fifty years on this planet, and I've done it all. I started out in IT back when "the cloud" was just what you saw out the window, worked my way through HR (yeah, I've been the guy who had to sit across the table from people and keep a straight face), and then did a stretch in sales where I learned real quick that if you can't sell yourself, nobody's buying what you're pitching. Three careers. One guy. Zero patience for textbooks that read like they were written by robots.
