- Identity Check: Which Credential This Sheet Covers
- The One-Page Fact Grid
- The Five Preparation Areas at a Glance
- Exam Format and Proctoring Facts
- Eligibility and Conduct Quick Reference
- Fees, Hours, and CPE: Three Different Numbers
- Validity, Renewal, and the Marketing Conflict
- Who Hires and What Employers Expect
- A Domain-Ordered Review Sequence
- Quick-Answer FAQ
- The exam-only listing costs $450 USD for one attempt, a one-year exam license, and a three-hour online proctored sitting.
- The stated passing threshold is 70%, delivered closed-book with on-demand AI remote proctoring.
- Five preparation areas are listed: OSINT, social media intelligence, cyber investigations, intelligence collection, and legal fundamentals.
- Training hours (55), CPE credits (50), exam-license validity, and certification validity are four separate quantities.
Identity Check: Which Credential This Sheet Covers
Several credentials in the intelligence world share similar abbreviations, so start by confirming what this cheat sheet describes. It covers Certified in Open Source Intelligence, issued and administered by McAfee Institute. The issuer styles it C|OSINT; this site uses C/OSINT as its abbreviation. If you are comparing offerings, verify the issuer name on any page before you pay for anything.
New to the credential itself? The explainers on what C/OSINT certification is and what C/OSINT stands for cover background. This page is the compressed, exam-week reference.
The One-Page Fact Grid
Everything below was checked against issuer pages on October 5, 2026. Fees and policies can change, so treat the issuer as the final authority at purchase time.
| Item | What the issuer lists |
|---|---|
| Issuer / administrator | McAfee Institute |
| Exam-only price | $450 USD, one attempt |
| Exam license | One year |
| Exam length | Three hours, online proctored |
| Passing threshold | 70% |
| Delivery | Closed-book, on-demand AI remote proctoring |
| Question types | True/false, multiple-choice, scenario-based |
| Training product | 55 instructional hours, 50 CPE credits |
| Training price at verification | $2,497 USD standard; $997 USD scholarship price |
| Renewal help article | Two-year validity, two-year extensions, 30-day post-expiration grace period |
For a deeper look at the money side, see the C/OSINT certification cost breakdown, and for the scoring bar see the C/OSINT passing score guide.
The Five Preparation Areas at a Glance
The issuer's exam product lists five preparation areas. These are unweighted preparation topics, not a verified official blueprint, and no public item counts per area were available. Do not budget study time using invented percentages. Spread effort based on your own weak spots, and use the complete guide to the five content areas for deeper treatment.
Domain 1: Open Source Intelligence
The foundation: what counts as open source information, how it becomes intelligence, and how collection is planned and documented.
- Distinguish raw information from analyzed, finished intelligence
- Know the common categories of open sources and their reliability limits
- Understand search methodology, source evaluation, and documentation habits
- Expect scenario questions asking what an investigator should do first
Domain 2: Social Media Intelligence
How platforms, profiles, and public posts serve as investigative sources, and where the risks sit.
- Attribution caution: a profile is a claim, not proof of identity
- Preservation of content before it is edited or deleted
- Operational security when viewing subjects' accounts
- Platform terms, privacy settings, and the line between public and restricted content
Domain 3: Cyber Investigations
The technical layer: digital artifacts, online infrastructure, and how cyber-enabled activity is traced.
- Digital footprints and the kinds of traces online activity leaves
- Infrastructure-related concepts such as domains and hosting at a conceptual level
- Evidence handling principles for digital material
- Recognizing how anonymity tools complicate, but rarely end, an investigation
Domain 4: Intelligence Collection
The process side: turning a requirement into a collection plan, then into usable product.
- Requirements, planning, and tasking before searching begins
- Source validation and corroboration across independent sources
- Organizing, recording, and reporting findings in defensible form
- Avoiding collection bias and confirmation bias
Domain 5: Legal Fundamentals
The boundaries: what an investigator may lawfully collect, retain, and use.
- Privacy expectations and lawful access versus unauthorized access
- Authority and scope: what your role permits
- Admissibility and chain-of-custody thinking
- Ethics, conduct, and the consequences of overstepping
Exam Format and Proctoring Facts
What is confirmed
- Three hours, taken online under proctoring
- Closed-book delivery with on-demand AI remote proctoring
- Formats described by the issuer: true/false, multiple-choice, and scenario-based
- A stated passing threshold of 70%
What is not confirmed
The institute-wide examination page gives an approximate question count for its exams generally, but that figure should not be treated as the exact number of items on the C/OSINT exam. Likewise, no public per-area weighting was retrievable. Any site quoting a precise item count or domain percentage should be treated skeptically.
Because the delivery is closed-book and remotely proctored, rehearse the logistics: a quiet room, a stable connection, acceptable identification, and a clear desk. Technical friction burns time and nerves you want for the questions. For a sense of difficulty, read how hard the C/OSINT exam is, and for outcome data see what is and is not known in the C/OSINT pass rate discussion.
Key Takeaway
Scenario questions test judgment, not trivia. Practice reading a situation and asking three things in order: what is lawful, what is documented, and what is the most defensible next step. That habit maps to all five preparation areas.
Eligibility and Conduct Quick Reference
The exam page describes three experience pathways:
| Education level | Relevant investigative or intelligence experience listed |
|---|---|
| Bachelor's degree or higher | Zero years required |
| Associate degree | Two years |
| High school or equivalent | Three years |
Read that table with a caveat. The same page also describes candidates as currently employed full-time in paid investigative or intelligence work. That means the zero-experience degree route should not be assumed to grant unrestricted entry; it needs issuer eligibility review. Criminal-history disclosure and a conduct review also apply under the issuer's eligibility and conduct policy.
The practical move: contact the issuer with your education and work history before paying, and keep their answer in writing. The C/OSINT requirements guide walks through how to approach that conversation.
Fees, Hours, and CPE: Three Different Numbers
One of the most common sources of confusion is mixing up quantities that sound related but are not.
- Exam fee: $450 USD for the exam-only listing, which includes one attempt and a one-year exam license. The institute-wide exam page also lists $450 USD for the examination and retake license.
- Course length: 55 instructional hours in the separate training product.
- CPE credits: 50 awarded by the training product. This is a credit award, not a verified renewal quota.
- Exam-license validity: one year, which governs how long you have to test.
- Certification validity: a different matter entirely, covered next.
The training product shows $2,497 USD standard tuition and a $997 USD scholarship price as of verification, and advertises lifetime course access. Lifetime access to course material is not the same as lifetime validity of the credential. For the full economic picture, including whether the investment pays off, see whether the certification is worth it.
Validity, Renewal, and the Marketing Conflict
The issuer's current renewal help article specifies two-year validity, two-year extensions, and a 30-day grace period after expiration. However, an issuer blog dated June 15, 2026 promotes non-expiring credentials, which contradicts that help article.
Until the issuer clarifies, the safe approach is:
- Treat the help article's two-year terms as the working assumption
- Request written, credential-specific confirmation of renewal terms for Certified in Open Source Intelligence
- Do not assume the course's 50 CPE award satisfies any renewal requirement; the CPE policy (updated January 1, 2026) should be read for how credits are actually counted
- Calendar your own expiration date once you earn the credential
Who Hires and What Employers Expect
The eligibility language itself signals the target audience: people in paid investigative or intelligence roles. Practically, that points toward environments where open source research supports decisions:
- Law enforcement and public-safety investigative units
- Corporate security, brand protection, and threat intelligence teams
- Fraud, loss-prevention, and insurance investigation functions
- Private investigation and risk-consulting firms
- Government-adjacent analysis and compliance roles
Employers in these settings tend to value defensible methodology and documented process as much as search skill, which is why the legal and collection areas matter. No reliable public figure ties this credential to a specific salary, so treat any dollar claim with caution; the C/OSINT salary guide discusses what can and cannot be said, and C/OSINT jobs covers the role landscape.
A Domain-Ordered Review Sequence
If you want one structured pass through the five areas, sequence them so that early material supports later material. This is a suggestion, not an official schedule, and the weeks can be compressed or stretched.
Open Source Intelligence and Legal Fundamentals
- Lock in vocabulary and the information-versus-intelligence distinction
- Start the legal area early so it frames every later topic
Social Media Intelligence
- Practice attribution caution and preservation habits
- Review operational security and platform-boundary scenarios
Cyber Investigations and Intelligence Collection
- Cover digital footprints and evidence-handling principles
- Work through requirements, planning, corroboration, and reporting
Mixed Scenario Practice
- Take timed mixed sets under closed-book conditions
- Revisit missed items and re-read the legal area last
For a fuller plan, the C/OSINT study guide goes deeper, and the practice test site offers timed question sets that mirror the closed-book, mixed-format experience.
Quick-Answer FAQ
The stated passing threshold is 70%. The exam is closed-book, runs three hours, and is delivered online with AI remote proctoring.
The exam-only listing is $450 USD for one attempt with a one-year exam license. Training is a separate product priced at $2,497 USD standard or $997 USD at the scholarship price at the time of verification.
No exact item count for this credential was verified. The issuer describes true/false, multiple-choice, and scenario-based formats, but an approximate figure from the institute-wide page should not be treated as the C/OSINT count.
The renewal help article describes two-year validity with two-year extensions and a 30-day grace period, while a June 2026 issuer blog promotes non-expiring credentials. Get written confirmation specific to this credential before relying on either claim.
Not necessarily. The 50 CPE credits are what the training awards, not a verified renewal requirement. Check the issuer's CPE policy and request written confirmation of what renewal actually requires.