C/OSINT logo
Focused certification exam prep
Start practice

C/OSINT Certification

TL;DR
  • C/OSINT here means Certified in Open Source Intelligence, issued and examined by McAfee Institute, which styles it C|OSINT.
  • The exam-only listing is $450 USD: one attempt, a one-year exam license, three hours, online proctored, 70% to pass.
  • Five preparation topics are listed: OSINT, social media intelligence, cyber investigations, intelligence collection and legal fundamentals.
  • Eligibility depends on degree and experience combinations, and criminal-history disclosure and conduct review apply.

What the C/OSINT Credential Actually Is

The Certified in Open Source Intelligence credential is offered by McAfee Institute, which also administers the examination. The issuer styles the name C|OSINT; this site uses the abbreviation C/OSINT for readability. It is a practitioner-oriented certification aimed at people who collect, analyze and report on publicly available information as part of investigative or intelligence work.

If you are still orienting yourself, our explainers on what C/OSINT certification is and what C/OSINT stands for cover the naming and scope. This article goes further into the mechanics: what you pay, how the exam is delivered, which topics to master, and where the published information is ambiguous enough that you should verify it yourself before spending money.

A note on identity: several unrelated credentials in the intelligence and security world share this acronym. Everything below applies only to the McAfee Institute's Certified in Open Source Intelligence. If a salary figure, fee or domain weighting you read elsewhere does not match what follows, it may belong to a different certification entirely.

Exam Format, Fee and Passing Threshold

The exam-only product is the most concrete part of this credential, and the numbers published on the issuer's exam page are clear:

ItemWhat the issuer lists
Exam-only price$450 USD for one attempt
Exam licenseOne year
DurationThree hours
DeliveryOnline, remotely proctored
Passing threshold70%
Institute-wide retake/license price$450 USD

The institute-wide examination page describes closed-book, on-demand AI remote proctoring and a mix of true/false, multiple-choice and scenario-based questions. That page gives only an approximate question count for the institute's exams in general, and it would be a mistake to treat that as the exact number of items on your C/OSINT paper. Plan around the three-hour window and the 70% threshold rather than a specific item count. For a deeper treatment of the cut score, see our guide to the C/OSINT passing score.

A full cost picture also includes optional training, which is priced separately. We break the numbers down in C/OSINT certification cost.

What closed-book, remotely proctored means in practice

  • You will not be able to look up a platform's terms of service, a statute citation or a tool's syntax mid-exam, so recall matters.
  • Scenario-based items reward judgment: choosing the lawful, defensible next step in an investigation, not just naming a tool.
  • Remote proctoring means your testing environment, connection and identification are part of the risk. Check the issuer's technical requirements well ahead of your sitting.

The Five Preparation Areas, Unpacked

The exam product's curriculum overview lists five preparation topics. Important caveat: these are unweighted preparation areas, not a verified official domain blueprint. The issuer's public pages did not expose a detailed blueprint with percentages or sub-objectives, and the paid manual is where the fine detail lives. So treat what follows as a map of the territory, and don't assume equal or unequal weighting. Our C/OSINT exam domains guide gives a companion walkthrough.

Domain 1: Open Source Intelligence

The foundation: what counts as open source information, how the intelligence cycle applies to it, and how analysts move from raw public data to something an investigator can act on.

  • Distinguishing information from intelligence, and sourcing from analysis
  • Planning collection around a question rather than a tool
  • Assessing source reliability and the credibility of what you find
  • Documenting your method so findings can be reproduced and defended

Domain 2: Social Media Intelligence

Social platforms are among the richest and most volatile OSINT sources. Expect questions that probe how you gather and preserve platform content, and how you interpret it responsibly.

  • Profile, connection and content analysis across major platforms
  • Preservation: capturing content before it is edited or deleted
  • Attribution caution: similar usernames and reused photos are leads, not proof
  • Platform rules, privacy settings and the limits of what is genuinely public

Domain 3: Cyber Investigations

The technical layer beneath online activity. Even a non-technical investigator needs to read infrastructure and digital artifacts correctly.

  • Domain, IP and hosting concepts as investigative pivots
  • Email and web-based artifacts and what they can and cannot establish
  • Anonymity tools and how they complicate attribution
  • Operational security for the investigator: protecting your own identity and device

Domain 4: Intelligence Collection

The discipline of gathering systematically: search technique, source diversity, and the tradecraft that separates a structured collection effort from aimless browsing.

  • Advanced search methods and combining sources to corroborate findings
  • Collection planning, tasking and requirements
  • Organizing, validating and reporting collected material
  • Recognizing gaps, bias and deception in what you collect

Domain 5: Legal Fundamentals

Arguably the area where scenario questions are most likely to trip up technically strong candidates. Knowing how to find information is not the same as knowing whether you may use it.

  • Privacy expectations and the boundary between public and protected data
  • Terms of service, authorization and the risks of overstepping access limits
  • Evidence handling, admissibility concerns and chain-of-custody thinking
  • Ethical conduct and professional responsibility in investigative work
Why the legal area deserves extra respect: in scenario-based questions, several answer choices may be technically feasible. The correct one is usually the option that is also lawful, documented and proportionate. Candidates who study only tools tend to underperform on exactly these items.

Eligibility: Read This Before You Buy

The exam page lists three experience pathways:

  • Bachelor's degree or higher, with zero years of required experience
  • Associate degree, with two years of relevant investigative or intelligence experience
  • High school diploma or equivalent, with three years of relevant investigative or intelligence experience

That looks straightforward, but there is a wrinkle. The same page also describes candidates as people currently employed full-time in paid investigative or intelligence work. Taken together, the degree-only pathway should not be assumed to mean unrestricted entry for anyone with a diploma. If you are a student, career-changer or part-time analyst, contact the issuer for an eligibility review before purchasing.

Beyond education and experience, the issuer's eligibility and conduct policy applies: criminal-history disclosure and a conduct review are part of the process. Our C/OSINT requirements guide goes deeper on qualifying and how to prepare your documentation.

Key Takeaway

Do not treat "zero experience required" as a guarantee. Email the issuer, describe your employment situation, and get eligibility confirmed in writing before you pay for an exam license that runs on a one-year clock.

Training vs. Exam-Only: Where Buyers Get Confused

McAfee Institute sells the credential through two distinct products, and the difference matters to your budget and your preparation.

FeatureExam-only productTraining product
Price at verification$450 USD$2,497 USD standard tuition; $997 USD scholarship price
InstructionNot the focus; see inclusions note below55 instructional hours
CPE creditsNone listed50 CPE credits awarded
AccessOne-year exam licenseLifetime course access advertised
Exam attemptOne attemptConfirm what is bundled before purchase

The inclusions conflict

The exam-only page's package description excludes the training, manual and review quizzes. A later generic benefits section on the same page appears to include them. These two statements cannot both describe your cart. Before checkout, confirm in writing exactly what your specific SKU includes: whether you receive the manual, review quizzes and any retake, or only the exam license itself. Because the detailed blueprint reportedly lives in the paid manual, whether you get it can materially affect how you prepare.

If you are weighing the larger course, our overview of C/OSINT training and the pricing breakdown will help you decide whether the tuition fits your situation.

Validity, Renewal and the Conflicting Messaging

Four quantities get conflated constantly, and each runs on its own clock:

  1. Course duration: 55 instructional hours in the training product.
  2. CPE earned: 50 CPE credits awarded by the course.
  3. Exam-license validity: one year to sit the exam.
  4. Credential validity: governed by the renewal policy, not by any of the above.

The issuer's current renewal help article specifies two-year validity with two-year extensions and a 30-day grace period after expiration. However, an issuer blog post dated June 15, 2026 promotes non-expiring credentials, which contradicts that help article. Marketing copy and policy documentation disagree.

How to resolve it: do not rely on either source alone. Ask the issuer for written, credential-specific confirmation of your renewal terms. Also note that the 50 CPE credits awarded by the training are not a verified renewal quota. Do not assume that taking the course automatically satisfies any renewal requirement, and do not assume "lifetime course access" means lifetime credential validity.

Who Benefits From This Credential

Open source intelligence skills are used wherever someone has to establish facts about people, organizations or events from public information. Typical settings include law enforcement and investigative units, corporate security and fraud teams, insurance and claims investigation, threat intelligence, due diligence and compliance functions, and private investigation. The eligibility language itself points to working investigators and intelligence personnel as the core audience.

We deliberately do not quote salary figures here, because no verified, credential-specific compensation data supports them. For a discussion of how the credential may translate into career outcomes, see C/OSINT jobs, the salary guide and the ROI analysis. Think of the certification as a way to document and standardize skills you apply on the job, with the value depending heavily on your employer and field.

Sequencing Your Preparation Around the Five Areas

Because the areas are unweighted publicly, a balanced approach is safest, with extra attention on whichever area is furthest from your daily work. Here is one way to order a roughly five-week plan, tied to how the topics build on each other:

Week 1

Open Source Intelligence

  • Lock down core terminology and the collection-to-reporting workflow
  • Practice documenting sources and assessing reliability
Week 2

Intelligence Collection

  • Drill search technique and corroboration across sources
  • Build a simple collection plan for a practice scenario
Week 3

Social Media Intelligence

  • Work through profile analysis, preservation and attribution pitfalls
Week 4

Cyber Investigations

  • Review infrastructure concepts and investigator operational security
  • Allow extra time if you come from a non-technical background
Week 5

Legal Fundamentals and full review

  • Revisit legal and ethical scenarios, then take timed practice sets
  • Simulate the three-hour closed-book condition

Placing legal fundamentals last is deliberate: it lets you apply legal reasoning to the techniques you have just learned. But revisit it throughout, since scenario questions blend areas. Our C/OSINT study guide offers a fuller plan, the cheat sheet helps with last-minute review, and our difficulty guide can help you calibrate how much time you need. When you are ready to test yourself under realistic conditions, use the C/OSINT practice tests to find weak areas before exam day.

Frequently Asked Questions

How much does the C/OSINT exam cost?

The exam-only listing is $450 USD for one attempt with a one-year exam license. The separate training product displayed $2,497 USD standard tuition and a $997 USD scholarship price at verification. Confirm what your specific purchase includes before checkout.

What score do I need to pass?

The stated passing threshold is 70%. The exam is three hours, closed-book and remotely proctored online. Do not assume an exact question count, as the issuer publishes only an approximate figure for its exams generally.

Do I need prior experience to sit the exam?

The issuer lists three pathways: a bachelor's degree or higher with no required experience, an associate degree with two years, or a high-school diploma or equivalent with three years of relevant investigative or intelligence experience. Because the page also describes candidates as employed full-time in such work, seek an eligibility review first. See the requirements guide.

Does the credential expire?

The issuer's renewal help article specifies two-year validity, two-year extensions and a 30-day post-expiration grace period, but a June 2026 issuer blog promotes non-expiring credentials. Get written, credential-specific confirmation rather than relying on either statement.

Does the 50 CPE from the course cover renewal?

Not necessarily. The training awards 50 CPE credits, but that is not a verified renewal quota. Course hours, CPE earned, exam-license validity and credential validity are separate quantities, so confirm requirements with the issuer.

Ready to pass your C/OSINT exam?

Put this into practice with free C/OSINT questions across every exam domain.