- The Short Answer: What the Letters Stand For
- Why You See C/OSINT and C|OSINT
- What the Credential Is Meant to Show
- The Five Preparation Areas Behind the Name
- Exam Mechanics in Plain Terms
- Training Hours, CPE, and Validity Are Not the Same Thing
- Who Can Sit for It
- Where the Credential Gets Used
- Sequencing the Five Areas in Your Prep
- Frequently Asked Questions
- C/OSINT means Certified in Open Source Intelligence, issued and examined by McAfee Institute, which styles it C|OSINT.
- The exam-only listing is $450 USD for one attempt, with a one-year exam license and a three-hour online proctored test.
- The stated passing threshold is 70%, and the exam is closed-book with AI remote proctoring.
- Five listed preparation areas: open source, social media, cyber investigations, intelligence collection, and legal fundamentals.
The Short Answer: What the Letters Stand For
C/OSINT stands for Certified in Open Source Intelligence. It is a professional credential administered by McAfee Institute, and it signals that the holder has been tested on the practice of gathering and analyzing intelligence from publicly available sources. "Open source" in this context does not mean open-source software. It means information anyone can lawfully access: public records, social media posts, websites, published reports, and other material that does not require breaking into anything or deceiving anyone to obtain.
If you are searching for a broader explainer, our companion pages cover the same ground from different angles, including what C/OSINT stands for, the C/OSINT meaning, and what C/OSINT certification is. This article focuses on the name itself, what each word commits the credential to, and what that means for someone deciding whether to pursue it.
Why You See C/OSINT and C|OSINT
The issuer writes its credential as C|OSINT, with a vertical bar. This site uses C/OSINT with a forward slash as its standard abbreviation, largely because the slash is easier to type, search, and link. They refer to the same thing. When you register through the issuer's catalog, expect to see the pipe style; when you read prep material on this site, expect the slash.
Each word in the full name does real work:
- Certified means the issuer verifies you through an eligibility review, an exam, and conduct requirements, not just course attendance.
- Open Source sets the legal and ethical boundary: public, lawfully accessible information.
- Intelligence signals that collection is only the start. The work is turning raw material into something decision-makers can act on.
What the Credential Is Meant to Show
A C/OSINT credential is best understood as evidence of structured investigative competence rather than tool proficiency. Anyone can run a search engine or scroll a profile. The credential is aimed at demonstrating that you can plan a collection effort, work across platforms and data types, understand the technical context of online activity, and stay inside legal and ethical lines while doing it.
That last element matters more than newcomers expect. A large share of the risk in OSINT work comes from mishandling evidence, over-collecting personal data, or crossing into unauthorized access. The credential's inclusion of legal fundamentals as a named preparation area reflects that reality.
Key Takeaway
Think of the name as a promise about method, not software. Employers reading "Certified in Open Source Intelligence" are looking for disciplined, lawful, repeatable collection and analysis, not familiarity with a particular tool.
The Five Preparation Areas Behind the Name
The exam product's curriculum overview lists five preparation areas. These are unweighted topics. They are not a verified official domain blueprint with percentages, and the detailed outline sits behind the paid materials. Treat them as the confirmed scope headings and expect depth beyond the one-line titles. For a deeper walk-through, see our complete guide to the five C/OSINT content areas.
Domain 1: Open Source Intelligence
The foundation: what counts as open source information, how it differs from other intelligence disciplines, and how to approach collection as a process.
- Defining sources and distinguishing public from restricted information
- Planning a collection effort around a question rather than a tool
- Evaluating reliability and relevance of what you find
Domain 2: Social Media Intelligence
Platform-based collection and analysis, where much modern OSINT work happens.
- Understanding how platforms expose profiles, connections, and content
- Attribution and verification challenges, including fake and impersonated accounts
- Preserving what you find in a way that holds up later
Domain 3: Cyber Investigations
The technical context around online activity and digital footprints.
- How online identities, infrastructure, and artifacts relate to one another
- Using publicly available technical information responsibly
- Recognizing where open source work ends and unauthorized access begins
Domain 4: Intelligence Collection
The tradecraft of gathering, organizing, and documenting information.
- Collection planning and source management
- Documentation, note-taking, and evidence handling
- Moving from raw data to usable findings
Domain 5: Legal Fundamentals
The boundaries that keep an investigator and their employer out of trouble.
- Privacy considerations and lawful collection limits
- Evidence admissibility and chain-of-custody thinking
- Ethical conduct expectations that tie into the issuer's conduct review
Because the blueprint is not published in detail, avoid any study resource that claims exact percentage weights per area. Build breadth across all five, with extra attention to scenario reasoning where legal and technical judgment intersect.
Exam Mechanics in Plain Terms
Here is what the issuer's listings confirm, and where they stop being specific:
| Item | What the issuer states |
|---|---|
| Exam-only price | $450 USD for one attempt |
| Exam license | One year |
| Duration | Three hours, online proctored |
| Passing threshold | 70% |
| Delivery | Closed-book, on-demand, AI remote proctoring |
| Question styles (institute-wide) | True/false, multiple-choice, scenario-based |
| Exact item count | Not confirmed for this exam |
The institute-wide examination page gives an approximate question count for its exams generally, but that figure should not be treated as the C/OSINT item count. Plan around the three-hour window and the three question styles rather than a number you cannot verify.
Scenario-based questions are where this credential's name earns its keep. Expect situations that ask what a competent open source investigator would do next, what is lawful, or which source is most reliable, rather than pure definition recall. Our difficulty breakdown and passing score explainer go deeper on both. We have also written up what the available data shows about pass rates, and the short version is that the issuer's own sources do not publish a verified figure, so be skeptical of anyone quoting one.
Training Hours, CPE, and Validity Are Not the Same Thing
People searching for the meaning of C/OSINT often end up confused by four different numbers that all sound like "how long." They measure different things:
- 55 instructional hours: the length of the separate training product.
- 50 CPE credits: what the training awards on completion.
- One-year exam license: how long your purchased exam access remains usable.
- Certification validity: how long the credential itself lasts once earned, which is a different question entirely.
The training product lists standard tuition of $2,497 USD and a $997 USD scholarship price as displayed at the time of verification. It advertises lifetime course access, but lifetime access to coursework is not the same as lifetime credential validity.
The renewal contradiction
The issuer's current renewal help article describes two-year validity with two-year extensions and a 30-day grace period after expiration. A separate issuer blog post dated June 15, 2026 promotes non-expiring credentials. These two statements cannot both be the operative rule for your credential. Do not rely on the marketing claim, and do not assume the 50 CPE credits from training equal a renewal requirement, because that quota has not been verified. Ask the issuer for written, credential-specific renewal terms before you budget for long-term maintenance.
Key Takeaway
When an issuer's own documents disagree, the written confirmation you get for your specific credential is the only source worth trusting. Save that email.
Who Can Sit for It
The exam page describes three eligibility routes: a bachelor's degree or higher with no required experience, an associate degree with two years, or a high-school diploma or equivalent with three years of relevant investigative or intelligence experience. Criminal-history disclosure and a conduct review apply.
There is a wrinkle worth flagging. The same page describes candidates as currently employed full-time in paid investigative or intelligence work. That language sits in tension with the zero-experience degree route, so a recent graduate should not assume unrestricted entry. Contact the issuer for an eligibility review before purchasing. The details are covered in our C/OSINT requirements guide, and scheduling specifics live in our exam dates article.
Where the Credential Gets Used
The eligibility language itself points to the intended audience: people working in investigative or intelligence roles. In practice that includes corporate security and threat intelligence teams, fraud and investigations units, risk and due diligence functions, journalists and researchers who verify online material, and public-sector investigators. The common thread is a need to produce defensible findings from public information.
We will not put a salary figure on the credential here, because no verified one exists in the issuer's materials, and you should distrust any number presented without a source. For discussion of how the credential fits into career planning, see our salary analysis, the worth-it ROI discussion, and our overview of C/OSINT jobs.
Sequencing the Five Areas in Your Prep
You do not need a generic study system here, just a sensible order that follows how the five areas depend on each other. Legal fundamentals should not be saved for last, because it shapes the right answer in scenarios across every other area. A workable four-week order:
Open Source Intelligence + Legal Fundamentals
- Lock down vocabulary and what counts as open source
- Learn the lawful-collection boundaries early so they color everything after
Social Media Intelligence
- Practice attribution, verification, and preservation reasoning
- Work scenario questions about fake or impersonated accounts
Cyber Investigations + Intelligence Collection
- Connect technical artifacts to investigative questions
- Practice collection planning and documentation habits
Mixed scenario review
- Take timed practice across all five areas on the main practice test site
- Revisit weak areas and re-read legal fundamentals one more time
For a fuller plan, use our C/OSINT study guide and the one-page cheat sheet for last-minute review. Because the exam is closed-book and timed at three hours, practice answering scenario questions under time pressure, not just reading. You can also work through realistic questions in the C/OSINT practice tests.
Frequently Asked Questions
It stands for Certified in Open Source Intelligence, a credential issued and examined by McAfee Institute. The issuer styles it C|OSINT with a vertical bar; this site uses a slash for convenience.
No. It refers to intelligence drawn from publicly and lawfully accessible information, such as public records, websites, and social media, not to software with publicly available source code.
The stated passing threshold is 70%, and the exam is a three-hour, closed-book, online proctored test. The exact number of questions has not been confirmed, so avoid sources that claim one.
The issuer's current renewal help article describes two-year validity with two-year extensions and a 30-day grace period, but an issuer blog promotes non-expiring credentials. Get written, credential-specific confirmation rather than relying on either alone.
The eligibility page lists a bachelor's-degree route with zero required experience, but it also describes candidates as employed full-time in investigative or intelligence work. Request an eligibility review from the issuer before you purchase.