C/OSINT logo
Focused certification exam prep
Start practice

C/OSINT Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • McAfee Institute lists three routes: bachelor's degree or higher with no experience, associate degree with two years, or high school with three years.
  • The exam page also describes candidates as employed full-time in paid investigative or intelligence work, so confirm degree-route eligibility with the issuer...
  • Criminal-history disclosure and a conduct review apply to every applicant, regardless of education or experience.
  • The exam-only listing is $450 USD for one attempt, a one-year exam license, and a three-hour online proctored test with a 70% passing threshold.

What You Are Actually Qualifying For

The Certified in Open Source Intelligence credential is issued and examined by McAfee Institute. The issuer styles it C|OSINT, while this site uses C/OSINT as its abbreviation. Before you read a single requirement, it helps to separate three things that candidates routinely blur together: eligibility to sit the exam, the exam license that lets you attempt it, and the certification you hold afterward.

Eligibility is about who you are: your education, your investigative or intelligence background, and your conduct record. The exam license is a purchased, time-limited right to attempt the test. The certification is what you hold if you pass, and it carries its own validity and renewal rules. Each has different dates, different costs, and different failure modes. This guide walks through all three so you know exactly what to prepare before you pay anything. If you are still orienting yourself on the credential itself, our primer on what C/OSINT certification is covers the basics.

The Three Eligibility Routes

The exam page lays out a tiered model that trades formal education against hands-on experience. The more education you have, the less experience is demanded.

Education LevelRelevant Experience Listed
Bachelor's degree or higherZero years required
Associate degreeTwo years of investigative or intelligence experience
High school diploma or equivalentThree years of investigative or intelligence experience

Notice the phrase "relevant investigative or intelligence experience." The issuer does not publish an exhaustive list of qualifying job titles in the material reviewed for this article, so do not assume that a loosely related role counts. Experience that clearly qualifies tends to look like casework: building a subject profile from public sources, documenting a digital trail, supporting a fraud, threat, or due-diligence inquiry, or producing intelligence reporting for a decision-maker. If your history sits at the edges, document the actual tasks you performed rather than relying on a job title.

Keep your evidence organized: Whichever route you fall into, assemble a short record before applying. For degree holders, that means a transcript or diploma copy. For experience routes, it means dates of employment, a supervisor or HR contact, and a plain-language description of investigative duties. Having this ready turns a potential back-and-forth with the issuer into a single clean submission.

The Full-Time Employment Wrinkle

Here is the nuance that most summaries of the requirements skip. The same exam page that offers a zero-experience route for bachelor's degree holders also describes candidates as currently employed full-time in paid investigative or intelligence work. Those two statements sit in tension. Read literally, a degree holder with no experience qualifies on education, yet the candidate description implies a working investigator or analyst.

We cannot resolve that tension for you, and neither should you resolve it by assumption. The zero-experience degree route should be treated as subject to issuer eligibility review rather than unrestricted entry. In practical terms:

  • If you are a full-time paid investigator, analyst, or intelligence professional, you match the candidate description directly, and your education tier determines the experience you must document.
  • If you are a student, career changer, or part-time practitioner holding a bachelor's degree, contact McAfee Institute and ask in writing whether your situation is eligible before purchasing an exam license.
  • If you freelance or run an investigative practice, ask whether self-employment satisfies the "paid" and "full-time" language.

Key Takeaway

Do not pay $450 on the assumption that a bachelor's degree alone clears you. Get a written eligibility answer from the issuer first, especially if you are not yet working full-time in an investigative or intelligence role.

Conduct Review and Criminal-History Disclosure

Eligibility under McAfee Institute's policy is not purely educational. Criminal-history disclosure and conduct review apply to applicants. That matters in a field built on handling sensitive information, supporting legal processes, and being trusted with other people's data.

Treat this part of the process with the same seriousness as a background questionnaire for a clearance or professional license:

  • Read the issuer's Eligibility and Conduct Policy in full before applying; do not rely on a summary.
  • Disclose accurately and completely. Omissions discovered later are typically worse than the underlying issue.
  • If you have a record you are unsure how to characterize, ask the issuer how disclosure is evaluated rather than guessing.

Because the policy governs conduct as well as eligibility, it is also relevant after you certify. Credentials of this type generally expect holders to maintain professional standards, so read the policy as an ongoing commitment, not a one-time gate.

Training Product vs. Exam-Only Purchase

There is no listed requirement that you complete the official training before testing, but the issuer sells two distinct products, and understanding the difference prevents expensive confusion.

FeatureExam-Only ListingTraining Product
Price at verification$450 USD$2,497 USD standard tuition; $997 USD scholarship price
Instructional hoursNot applicable55 hours
CPE credits awardedNone50 CPE
Exam attemptOne attempt, one-year exam licenseConfirm what the purchased SKU includes
Course accessNot applicableLifetime course access advertised
Read the SKU carefully: The exam-only page excludes training, the manual, and review quizzes in its package description, yet a later generic benefits section on the same page appears to include them. Those statements conflict. Before checkout, confirm in writing exactly what your specific purchase contains, so you do not pay $450 expecting study materials that are not included.

Also keep three quantities distinct: course duration (55 hours), CPE earned (50), and validity periods. They measure different things and are not interchangeable. For a full pricing picture, see our C/OSINT certification cost breakdown, and for the trade-offs between self-study and the paid course, our overview of C/OSINT training.

Exam Mechanics You Must Meet on Test Day

Qualifying also means meeting the technical and procedural conditions of the exam itself. Based on the issuer's published material:

  • Delivery: online, with on-demand AI remote proctoring and a closed-book format.
  • Duration: three hours for the exam-only listing.
  • Passing threshold: 70%.
  • Question formats: true/false, multiple-choice, and scenario-based items, per the institute-wide examination page.
  • Exam license: one-year validity on the exam-only listing, covering a single attempt.

The institute-wide page mentions an approximate question count, but that figure describes the issuer's exams generally. Do not treat it as the exact number of items on the C/OSINT paper. What you can plan around is the time allowance and the format mix.

Closed-book, remotely proctored testing has practical entry requirements of its own. Prepare a quiet, private space, a reliable connection, and a computer that meets the proctoring software's needs, and expect identity verification before you begin. Run any system check the issuer offers well ahead of exam day. For details on what a 70% threshold means in practice, read our guide to the C/OSINT passing score.

Knowledge Requirements: The Five Preparation Areas

No formal prerequisite course is listed, so the real gate is knowledge. The exam product's curriculum overview names five preparation areas. These are unweighted preparation topics, not a verified count of official examination domains and not an exhaustive blueprint, so treat them as the confirmed starting map rather than a complete outline. For a deeper walk-through, see our complete guide to the C/OSINT exam domains.

Open Source Intelligence

The foundation: what open source intelligence is, how it differs from other collection disciplines, and how analysts turn public information into usable findings.

  • Distinguishing information from validated intelligence
  • Sourcing, attribution, and reliability of public data
  • Documenting methods so findings can be reproduced

Social Media Intelligence

Working with platform content, profiles, and connections as investigative sources.

  • Profile and account analysis across platforms
  • Relationship and network mapping from public activity
  • Preservation of volatile content before it disappears

Cyber Investigations

The technical layer of tracing activity and artifacts online.

  • Digital footprints and infrastructure indicators
  • Investigative handling of online identities and communications
  • Operational security for the investigator

Intelligence Collection

Planning and executing collection in a disciplined, repeatable way.

  • Defining requirements before searching
  • Selecting appropriate collection methods and tools
  • Organizing and recording collected material

Legal Fundamentals

The boundaries that keep an investigation defensible.

  • Lawful collection and privacy considerations
  • Evidentiary handling and documentation
  • Knowing when a task requires legal guidance

Because the exam includes scenario-based questions, expect to apply these areas to situations rather than recite definitions. A scenario might combine several areas at once, for example a social media lead that raises both a collection-planning question and a legal one. To gauge how demanding that application can feel, see how hard the C/OSINT exam is.

Keeping the Credential Current

Qualifying does not end at passing. Renewal rules are one of the few areas where issuer sources actively contradict each other, so handle this carefully.

  • The current renewal help article specifies two-year validity, two-year extensions, and a 30-day grace period after expiration.
  • A McAfee Institute blog post dated June 15, 2026 promotes non-expiring credentials, which conflicts with the help article.
  • The training course awards 50 CPE credits, but that figure is not a verified renewal quota. Do not assume 50 CPE satisfies a renewal requirement.
  • Lifetime access to the training course does not mean lifetime credential validity.
Get renewal terms in writing: Marketing copy and help documentation disagree, so request written, credential-specific renewal confirmation from McAfee Institute for C/OSINT before you rely on either version. Record the date you certify, calendar the two-year mark, and note the 30-day grace window as a safety net, not a plan.

If you are weighing whether the ongoing commitment is worthwhile, our C/OSINT ROI analysis and the overview of C/OSINT jobs can help you judge the career side of the decision.

A Domain-Sequenced Qualification Plan

Rather than a generic schedule, sequence your preparation so the areas that constrain everything else come first. Legal Fundamentals and Open Source Intelligence frame how you should think about the other three, so they anchor the plan.

Week 1

Eligibility and Foundations

  • Obtain written eligibility confirmation and confirm the SKU contents
  • Study Open Source Intelligence fundamentals
Week 2

Legal Fundamentals

  • Learn the lawful-collection boundaries early, so later topics are framed correctly
Week 3

Social Media Intelligence and Intelligence Collection

  • Pair platform analysis with collection planning
Week 4

Cyber Investigations and Scenario Practice

  • Work mixed scenarios that blend all five areas under three-hour timing

Adjust the pacing to your experience. Working investigators may compress the early weeks, while career changers may need longer on Cyber Investigations. For a fuller preparation approach, see our C/OSINT study guide, and when you are ready to test your recall under realistic conditions, try the C/OSINT practice tests. Our exam dates and scheduling guide covers timing, and what the data shows about pass rates sets honest expectations.

Frequently Asked Questions

Do I need a degree to qualify for the C/OSINT exam?

Not necessarily. McAfee Institute lists three routes: a bachelor's degree or higher with no required experience, an associate degree with two years of relevant experience, or a high school diploma or equivalent with three years of relevant investigative or intelligence experience.

Can I qualify with a bachelor's degree and no investigative experience?

The exam page lists a zero-experience route for degree holders, but it also describes candidates as employed full-time in paid investigative or intelligence work. Treat the degree route as subject to issuer eligibility review and get written confirmation before purchasing an exam license.

Is the official training course required before I can sit the exam?

The materials reviewed do not list the training as a prerequisite. The exam-only listing is $450 USD for one attempt, while the separate training product lists 55 instructional hours and 50 CPE credits. Confirm what your specific purchase includes.

Does a criminal record disqualify me?

Criminal-history disclosure and conduct review apply to applicants, but this article cannot state how any particular record is evaluated. Read the issuer's Eligibility and Conduct Policy and ask McAfee Institute directly about your circumstances.

How long does the credential stay valid once I pass?

Sources conflict. The renewal help article specifies two-year validity, two-year extensions, and a 30-day grace period, while a June 2026 issuer blog promotes non-expiring credentials. Request written, credential-specific confirmation of the renewal terms that apply to you.

Ready to pass your C/OSINT exam?

Put this into practice with free C/OSINT questions across every exam domain.