- What the C/OSINT Credential Actually Is
- Exam Format, Fee and Passing Threshold
- The Five Preparation Areas, Unpacked
- Eligibility: Read This Before You Buy
- Training vs. Exam-Only: Where Buyers Get Confused
- Validity, Renewal and the Conflicting Messaging
- Who Benefits From This Credential
- Sequencing Your Preparation Around the Five Areas
- Frequently Asked Questions
- C/OSINT here means Certified in Open Source Intelligence, issued and examined by McAfee Institute, which styles it C|OSINT.
- The exam-only listing is $450 USD: one attempt, a one-year exam license, three hours, online proctored, 70% to pass.
- Five preparation topics are listed: OSINT, social media intelligence, cyber investigations, intelligence collection and legal fundamentals.
- Eligibility depends on degree and experience combinations, and criminal-history disclosure and conduct review apply.
What the C/OSINT Credential Actually Is
The Certified in Open Source Intelligence credential is offered by McAfee Institute, which also administers the examination. The issuer styles the name C|OSINT; this site uses the abbreviation C/OSINT for readability. It is a practitioner-oriented certification aimed at people who collect, analyze and report on publicly available information as part of investigative or intelligence work.
If you are still orienting yourself, our explainers on what C/OSINT certification is and what C/OSINT stands for cover the naming and scope. This article goes further into the mechanics: what you pay, how the exam is delivered, which topics to master, and where the published information is ambiguous enough that you should verify it yourself before spending money.
Exam Format, Fee and Passing Threshold
The exam-only product is the most concrete part of this credential, and the numbers published on the issuer's exam page are clear:
| Item | What the issuer lists |
|---|---|
| Exam-only price | $450 USD for one attempt |
| Exam license | One year |
| Duration | Three hours |
| Delivery | Online, remotely proctored |
| Passing threshold | 70% |
| Institute-wide retake/license price | $450 USD |
The institute-wide examination page describes closed-book, on-demand AI remote proctoring and a mix of true/false, multiple-choice and scenario-based questions. That page gives only an approximate question count for the institute's exams in general, and it would be a mistake to treat that as the exact number of items on your C/OSINT paper. Plan around the three-hour window and the 70% threshold rather than a specific item count. For a deeper treatment of the cut score, see our guide to the C/OSINT passing score.
A full cost picture also includes optional training, which is priced separately. We break the numbers down in C/OSINT certification cost.
What closed-book, remotely proctored means in practice
- You will not be able to look up a platform's terms of service, a statute citation or a tool's syntax mid-exam, so recall matters.
- Scenario-based items reward judgment: choosing the lawful, defensible next step in an investigation, not just naming a tool.
- Remote proctoring means your testing environment, connection and identification are part of the risk. Check the issuer's technical requirements well ahead of your sitting.
The Five Preparation Areas, Unpacked
The exam product's curriculum overview lists five preparation topics. Important caveat: these are unweighted preparation areas, not a verified official domain blueprint. The issuer's public pages did not expose a detailed blueprint with percentages or sub-objectives, and the paid manual is where the fine detail lives. So treat what follows as a map of the territory, and don't assume equal or unequal weighting. Our C/OSINT exam domains guide gives a companion walkthrough.
Domain 1: Open Source Intelligence
The foundation: what counts as open source information, how the intelligence cycle applies to it, and how analysts move from raw public data to something an investigator can act on.
- Distinguishing information from intelligence, and sourcing from analysis
- Planning collection around a question rather than a tool
- Assessing source reliability and the credibility of what you find
- Documenting your method so findings can be reproduced and defended
Domain 2: Social Media Intelligence
Social platforms are among the richest and most volatile OSINT sources. Expect questions that probe how you gather and preserve platform content, and how you interpret it responsibly.
- Profile, connection and content analysis across major platforms
- Preservation: capturing content before it is edited or deleted
- Attribution caution: similar usernames and reused photos are leads, not proof
- Platform rules, privacy settings and the limits of what is genuinely public
Domain 3: Cyber Investigations
The technical layer beneath online activity. Even a non-technical investigator needs to read infrastructure and digital artifacts correctly.
- Domain, IP and hosting concepts as investigative pivots
- Email and web-based artifacts and what they can and cannot establish
- Anonymity tools and how they complicate attribution
- Operational security for the investigator: protecting your own identity and device
Domain 4: Intelligence Collection
The discipline of gathering systematically: search technique, source diversity, and the tradecraft that separates a structured collection effort from aimless browsing.
- Advanced search methods and combining sources to corroborate findings
- Collection planning, tasking and requirements
- Organizing, validating and reporting collected material
- Recognizing gaps, bias and deception in what you collect
Domain 5: Legal Fundamentals
Arguably the area where scenario questions are most likely to trip up technically strong candidates. Knowing how to find information is not the same as knowing whether you may use it.
- Privacy expectations and the boundary between public and protected data
- Terms of service, authorization and the risks of overstepping access limits
- Evidence handling, admissibility concerns and chain-of-custody thinking
- Ethical conduct and professional responsibility in investigative work
Eligibility: Read This Before You Buy
The exam page lists three experience pathways:
- Bachelor's degree or higher, with zero years of required experience
- Associate degree, with two years of relevant investigative or intelligence experience
- High school diploma or equivalent, with three years of relevant investigative or intelligence experience
That looks straightforward, but there is a wrinkle. The same page also describes candidates as people currently employed full-time in paid investigative or intelligence work. Taken together, the degree-only pathway should not be assumed to mean unrestricted entry for anyone with a diploma. If you are a student, career-changer or part-time analyst, contact the issuer for an eligibility review before purchasing.
Beyond education and experience, the issuer's eligibility and conduct policy applies: criminal-history disclosure and a conduct review are part of the process. Our C/OSINT requirements guide goes deeper on qualifying and how to prepare your documentation.
Key Takeaway
Do not treat "zero experience required" as a guarantee. Email the issuer, describe your employment situation, and get eligibility confirmed in writing before you pay for an exam license that runs on a one-year clock.
Training vs. Exam-Only: Where Buyers Get Confused
McAfee Institute sells the credential through two distinct products, and the difference matters to your budget and your preparation.
| Feature | Exam-only product | Training product |
|---|---|---|
| Price at verification | $450 USD | $2,497 USD standard tuition; $997 USD scholarship price |
| Instruction | Not the focus; see inclusions note below | 55 instructional hours |
| CPE credits | None listed | 50 CPE credits awarded |
| Access | One-year exam license | Lifetime course access advertised |
| Exam attempt | One attempt | Confirm what is bundled before purchase |
The inclusions conflict
The exam-only page's package description excludes the training, manual and review quizzes. A later generic benefits section on the same page appears to include them. These two statements cannot both describe your cart. Before checkout, confirm in writing exactly what your specific SKU includes: whether you receive the manual, review quizzes and any retake, or only the exam license itself. Because the detailed blueprint reportedly lives in the paid manual, whether you get it can materially affect how you prepare.
If you are weighing the larger course, our overview of C/OSINT training and the pricing breakdown will help you decide whether the tuition fits your situation.
Validity, Renewal and the Conflicting Messaging
Four quantities get conflated constantly, and each runs on its own clock:
- Course duration: 55 instructional hours in the training product.
- CPE earned: 50 CPE credits awarded by the course.
- Exam-license validity: one year to sit the exam.
- Credential validity: governed by the renewal policy, not by any of the above.
The issuer's current renewal help article specifies two-year validity with two-year extensions and a 30-day grace period after expiration. However, an issuer blog post dated June 15, 2026 promotes non-expiring credentials, which contradicts that help article. Marketing copy and policy documentation disagree.
Who Benefits From This Credential
Open source intelligence skills are used wherever someone has to establish facts about people, organizations or events from public information. Typical settings include law enforcement and investigative units, corporate security and fraud teams, insurance and claims investigation, threat intelligence, due diligence and compliance functions, and private investigation. The eligibility language itself points to working investigators and intelligence personnel as the core audience.
We deliberately do not quote salary figures here, because no verified, credential-specific compensation data supports them. For a discussion of how the credential may translate into career outcomes, see C/OSINT jobs, the salary guide and the ROI analysis. Think of the certification as a way to document and standardize skills you apply on the job, with the value depending heavily on your employer and field.
Sequencing Your Preparation Around the Five Areas
Because the areas are unweighted publicly, a balanced approach is safest, with extra attention on whichever area is furthest from your daily work. Here is one way to order a roughly five-week plan, tied to how the topics build on each other:
Open Source Intelligence
- Lock down core terminology and the collection-to-reporting workflow
- Practice documenting sources and assessing reliability
Intelligence Collection
- Drill search technique and corroboration across sources
- Build a simple collection plan for a practice scenario
Social Media Intelligence
- Work through profile analysis, preservation and attribution pitfalls
Cyber Investigations
- Review infrastructure concepts and investigator operational security
- Allow extra time if you come from a non-technical background
Legal Fundamentals and full review
- Revisit legal and ethical scenarios, then take timed practice sets
- Simulate the three-hour closed-book condition
Placing legal fundamentals last is deliberate: it lets you apply legal reasoning to the techniques you have just learned. But revisit it throughout, since scenario questions blend areas. Our C/OSINT study guide offers a fuller plan, the cheat sheet helps with last-minute review, and our difficulty guide can help you calibrate how much time you need. When you are ready to test yourself under realistic conditions, use the C/OSINT practice tests to find weak areas before exam day.
Frequently Asked Questions
The exam-only listing is $450 USD for one attempt with a one-year exam license. The separate training product displayed $2,497 USD standard tuition and a $997 USD scholarship price at verification. Confirm what your specific purchase includes before checkout.
The stated passing threshold is 70%. The exam is three hours, closed-book and remotely proctored online. Do not assume an exact question count, as the issuer publishes only an approximate figure for its exams generally.
The issuer lists three pathways: a bachelor's degree or higher with no required experience, an associate degree with two years, or a high-school diploma or equivalent with three years of relevant investigative or intelligence experience. Because the page also describes candidates as employed full-time in such work, seek an eligibility review first. See the requirements guide.
The issuer's renewal help article specifies two-year validity, two-year extensions and a 30-day post-expiration grace period, but a June 2026 issuer blog promotes non-expiring credentials. Get written, credential-specific confirmation rather than relying on either statement.
Not necessarily. The training awards 50 CPE credits, but that is not a verified renewal quota. Course hours, CPE earned, exam-license validity and credential validity are separate quantities, so confirm requirements with the issuer.