C/OSINT logo
Focused certification exam prep
Start practice

C/OSINT Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • The exam-only listing costs $450 USD for one attempt, a one-year exam license, and a three-hour online proctored sitting.
  • The stated passing threshold is 70%, delivered closed-book with on-demand AI remote proctoring.
  • Five preparation areas are listed: OSINT, social media intelligence, cyber investigations, intelligence collection, and legal fundamentals.
  • Training hours (55), CPE credits (50), exam-license validity, and certification validity are four separate quantities.

Identity Check: Which Credential This Sheet Covers

Several credentials in the intelligence world share similar abbreviations, so start by confirming what this cheat sheet describes. It covers Certified in Open Source Intelligence, issued and administered by McAfee Institute. The issuer styles it C|OSINT; this site uses C/OSINT as its abbreviation. If you are comparing offerings, verify the issuer name on any page before you pay for anything.

New to the credential itself? The explainers on what C/OSINT certification is and what C/OSINT stands for cover background. This page is the compressed, exam-week reference.

The One-Page Fact Grid

Everything below was checked against issuer pages on October 5, 2026. Fees and policies can change, so treat the issuer as the final authority at purchase time.

ItemWhat the issuer lists
Issuer / administratorMcAfee Institute
Exam-only price$450 USD, one attempt
Exam licenseOne year
Exam lengthThree hours, online proctored
Passing threshold70%
DeliveryClosed-book, on-demand AI remote proctoring
Question typesTrue/false, multiple-choice, scenario-based
Training product55 instructional hours, 50 CPE credits
Training price at verification$2,497 USD standard; $997 USD scholarship price
Renewal help articleTwo-year validity, two-year extensions, 30-day post-expiration grace period

For a deeper look at the money side, see the C/OSINT certification cost breakdown, and for the scoring bar see the C/OSINT passing score guide.

The Five Preparation Areas at a Glance

The issuer's exam product lists five preparation areas. These are unweighted preparation topics, not a verified official blueprint, and no public item counts per area were available. Do not budget study time using invented percentages. Spread effort based on your own weak spots, and use the complete guide to the five content areas for deeper treatment.

Domain 1: Open Source Intelligence

The foundation: what counts as open source information, how it becomes intelligence, and how collection is planned and documented.

  • Distinguish raw information from analyzed, finished intelligence
  • Know the common categories of open sources and their reliability limits
  • Understand search methodology, source evaluation, and documentation habits
  • Expect scenario questions asking what an investigator should do first

Domain 2: Social Media Intelligence

How platforms, profiles, and public posts serve as investigative sources, and where the risks sit.

  • Attribution caution: a profile is a claim, not proof of identity
  • Preservation of content before it is edited or deleted
  • Operational security when viewing subjects' accounts
  • Platform terms, privacy settings, and the line between public and restricted content

Domain 3: Cyber Investigations

The technical layer: digital artifacts, online infrastructure, and how cyber-enabled activity is traced.

  • Digital footprints and the kinds of traces online activity leaves
  • Infrastructure-related concepts such as domains and hosting at a conceptual level
  • Evidence handling principles for digital material
  • Recognizing how anonymity tools complicate, but rarely end, an investigation

Domain 4: Intelligence Collection

The process side: turning a requirement into a collection plan, then into usable product.

  • Requirements, planning, and tasking before searching begins
  • Source validation and corroboration across independent sources
  • Organizing, recording, and reporting findings in defensible form
  • Avoiding collection bias and confirmation bias

Domain 5: Legal Fundamentals

The boundaries: what an investigator may lawfully collect, retain, and use.

  • Privacy expectations and lawful access versus unauthorized access
  • Authority and scope: what your role permits
  • Admissibility and chain-of-custody thinking
  • Ethics, conduct, and the consequences of overstepping
Why Legal Fundamentals deserves respect: Candidates with strong technical backgrounds sometimes skim this area. Scenario-based questions often reward the cautious, lawful, well-documented answer over the clever technical one, so give the legal area real study time even if it feels less exciting.

Exam Format and Proctoring Facts

What is confirmed

  • Three hours, taken online under proctoring
  • Closed-book delivery with on-demand AI remote proctoring
  • Formats described by the issuer: true/false, multiple-choice, and scenario-based
  • A stated passing threshold of 70%

What is not confirmed

The institute-wide examination page gives an approximate question count for its exams generally, but that figure should not be treated as the exact number of items on the C/OSINT exam. Likewise, no public per-area weighting was retrievable. Any site quoting a precise item count or domain percentage should be treated skeptically.

Because the delivery is closed-book and remotely proctored, rehearse the logistics: a quiet room, a stable connection, acceptable identification, and a clear desk. Technical friction burns time and nerves you want for the questions. For a sense of difficulty, read how hard the C/OSINT exam is, and for outcome data see what is and is not known in the C/OSINT pass rate discussion.

Key Takeaway

Scenario questions test judgment, not trivia. Practice reading a situation and asking three things in order: what is lawful, what is documented, and what is the most defensible next step. That habit maps to all five preparation areas.

Eligibility and Conduct Quick Reference

The exam page describes three experience pathways:

Education levelRelevant investigative or intelligence experience listed
Bachelor's degree or higherZero years required
Associate degreeTwo years
High school or equivalentThree years

Read that table with a caveat. The same page also describes candidates as currently employed full-time in paid investigative or intelligence work. That means the zero-experience degree route should not be assumed to grant unrestricted entry; it needs issuer eligibility review. Criminal-history disclosure and a conduct review also apply under the issuer's eligibility and conduct policy.

The practical move: contact the issuer with your education and work history before paying, and keep their answer in writing. The C/OSINT requirements guide walks through how to approach that conversation.

Fees, Hours, and CPE: Three Different Numbers

One of the most common sources of confusion is mixing up quantities that sound related but are not.

  • Exam fee: $450 USD for the exam-only listing, which includes one attempt and a one-year exam license. The institute-wide exam page also lists $450 USD for the examination and retake license.
  • Course length: 55 instructional hours in the separate training product.
  • CPE credits: 50 awarded by the training product. This is a credit award, not a verified renewal quota.
  • Exam-license validity: one year, which governs how long you have to test.
  • Certification validity: a different matter entirely, covered next.
Check your SKU: The exam-only page excludes training, the manual, and review quizzes in its package description, yet a later generic benefits section appears to include them. Before checkout, confirm in writing exactly what your purchased SKU contains. Do not assume the manual or quizzes are bundled with the $450 listing.

The training product shows $2,497 USD standard tuition and a $997 USD scholarship price as of verification, and advertises lifetime course access. Lifetime access to course material is not the same as lifetime validity of the credential. For the full economic picture, including whether the investment pays off, see whether the certification is worth it.

Validity, Renewal, and the Marketing Conflict

The issuer's current renewal help article specifies two-year validity, two-year extensions, and a 30-day grace period after expiration. However, an issuer blog dated June 15, 2026 promotes non-expiring credentials, which contradicts that help article.

Until the issuer clarifies, the safe approach is:

  1. Treat the help article's two-year terms as the working assumption
  2. Request written, credential-specific confirmation of renewal terms for Certified in Open Source Intelligence
  3. Do not assume the course's 50 CPE award satisfies any renewal requirement; the CPE policy (updated January 1, 2026) should be read for how credits are actually counted
  4. Calendar your own expiration date once you earn the credential

Who Hires and What Employers Expect

The eligibility language itself signals the target audience: people in paid investigative or intelligence roles. Practically, that points toward environments where open source research supports decisions:

  • Law enforcement and public-safety investigative units
  • Corporate security, brand protection, and threat intelligence teams
  • Fraud, loss-prevention, and insurance investigation functions
  • Private investigation and risk-consulting firms
  • Government-adjacent analysis and compliance roles

Employers in these settings tend to value defensible methodology and documented process as much as search skill, which is why the legal and collection areas matter. No reliable public figure ties this credential to a specific salary, so treat any dollar claim with caution; the C/OSINT salary guide discusses what can and cannot be said, and C/OSINT jobs covers the role landscape.

A Domain-Ordered Review Sequence

If you want one structured pass through the five areas, sequence them so that early material supports later material. This is a suggestion, not an official schedule, and the weeks can be compressed or stretched.

Week 1

Open Source Intelligence and Legal Fundamentals

  • Lock in vocabulary and the information-versus-intelligence distinction
  • Start the legal area early so it frames every later topic
Week 2

Social Media Intelligence

  • Practice attribution caution and preservation habits
  • Review operational security and platform-boundary scenarios
Week 3

Cyber Investigations and Intelligence Collection

  • Cover digital footprints and evidence-handling principles
  • Work through requirements, planning, corroboration, and reporting
Week 4

Mixed Scenario Practice

  • Take timed mixed sets under closed-book conditions
  • Revisit missed items and re-read the legal area last

For a fuller plan, the C/OSINT study guide goes deeper, and the practice test site offers timed question sets that mirror the closed-book, mixed-format experience.

Check dates before you commit: Because the exam license runs one year and delivery is on-demand, scheduling flexibility is real, but confirm current windows and policies in the C/OSINT exam dates guide and with the issuer.

Quick-Answer FAQ

What is the passing score for the C/OSINT exam?

The stated passing threshold is 70%. The exam is closed-book, runs three hours, and is delivered online with AI remote proctoring.

How much does the exam cost?

The exam-only listing is $450 USD for one attempt with a one-year exam license. Training is a separate product priced at $2,497 USD standard or $997 USD at the scholarship price at the time of verification.

How many questions are on the exam?

No exact item count for this credential was verified. The issuer describes true/false, multiple-choice, and scenario-based formats, but an approximate figure from the institute-wide page should not be treated as the C/OSINT count.

Does the credential expire?

The renewal help article describes two-year validity with two-year extensions and a 30-day grace period, while a June 2026 issuer blog promotes non-expiring credentials. Get written confirmation specific to this credential before relying on either claim.

Do the 50 CPE credits from the course cover renewal?

Not necessarily. The 50 CPE credits are what the training awards, not a verified renewal requirement. Check the issuer's CPE policy and request written confirmation of what renewal actually requires.

Ready to pass your C/OSINT exam?

Put this into practice with free C/OSINT questions across every exam domain.