- The Short Answer: Certified in Open Source Intelligence
- Why You See C/OSINT, C|OSINT, and COSINT
- What Each Word in the Name Signals
- The Five Preparation Areas Behind the Name
- What the Name Means for the Exam Itself
- Who the Credential Is Built For
- Four Numbers People Mix Up
- Validity and Renewal: Read the Fine Print
- Sequencing Your Preparation Around the Five Areas
- Frequently Asked Questions
- C/OSINT stands for Certified in Open Source Intelligence, issued and examined by McAfee Institute.
- The issuer writes it C|OSINT; this site uses C/OSINT as its abbreviation for the same credential.
- The exam-only listing is $450 USD: one attempt, a one-year exam license, three hours, online proctored, 70% to pass.
- Five listed preparation areas run from Open Source Intelligence to Legal Fundamentals; they are unweighted topics, not an official blueprint.
The Short Answer: Certified in Open Source Intelligence
C/OSINT stands for Certified in Open Source Intelligence. It is a professional credential offered by McAfee Institute, which also administers the examination. Candidates who pass demonstrate working knowledge of collecting, analyzing, and applying intelligence drawn from publicly available sources, within the legal and ethical limits that govern that work.
That is the whole expansion, and it is worth stating precisely because the acronym is crowded. Other credentials in other fields use similar letters, and search results blend them together. On this site, C/OSINT always means the McAfee Institute credential in open source intelligence. If you want the broader picture of what the credential is and what holding it signals, our overview What Is C/OSINT Certification? goes deeper, and C/OSINT Meaning covers the terminology from another angle.
Why You See C/OSINT, C|OSINT, and COSINT
The issuer styles the credential with a vertical bar: C|OSINT. This site uses C/OSINT with a forward slash as its chosen abbreviation, largely because the slash is easier to type, link, and search. You will also see the unpunctuated form "COSINT" in URLs and casual conversation. All three point at the same credential.
| Form | Where you will see it | Refers to |
|---|---|---|
| C|OSINT | Issuer's own branding and product pages | Certified in Open Source Intelligence |
| C/OSINT | This site and its study materials | Certified in Open Source Intelligence |
| COSINT | URLs, forum posts, informal references | Certified in Open Source Intelligence, when the context is McAfee Institute |
When you search for exam logistics, check that any page you rely on names McAfee Institute and open source intelligence explicitly. If it does not, treat its details as unverified for this credential. For a dedicated treatment of the naming question, see What Does C/OSINT Mean?
What Each Word in the Name Signals
"Certified"
The credential is awarded after passing a proctored examination, not simply after attending a course. The training and the exam are sold as separate products, and the exam is the gate. Completing instruction does not by itself make you certified.
"Open Source"
Open source here means information anyone can lawfully access: public records, websites, social platforms, and other openly available material. It has nothing to do with open source software licensing. The skill being certified is finding, verifying, and using public information well.
"Intelligence"
This is the demanding word. Intelligence is not a pile of search results. It is information that has been collected deliberately, evaluated for reliability, and organized to support a decision or an investigation. A candidate who can run searches but cannot assess source quality or document a chain of work is missing the point of the title.
The Five Preparation Areas Behind the Name
The exam product's curriculum overview lists five preparation areas. Treat them as unweighted topic headings, not a verified count of official examination domains or an exhaustive exam outline. The detailed blueprint was not retrievable from the public pages, so no percentage weighting is attached here. Our companion piece C/OSINT Exam Domains 2026: Complete Guide to All 5 Content Areas expands each one.
Domain 1: Open Source Intelligence
The foundation: what OSINT is, how it fits into the wider intelligence picture, and how practitioners approach public-source research.
- Core concepts and vocabulary of open source intelligence
- How public-source research differs from other collection disciplines
- Evaluating the credibility of what you find
Domain 2: Social Media Intelligence
Social platforms are among the richest public sources, and the exam names them as their own area.
- Gathering and interpreting publicly visible social content
- Attribution caution: public does not mean verified
- Documenting findings so they can be reviewed later
Domain 3: Cyber Investigations
Investigative technique applied to online environments, where digital traces become the evidence trail.
- Online investigative workflows and digital footprints
- Connecting accounts, infrastructure, and activity patterns
- Recording methods so work is reproducible
Domain 4: Intelligence Collection
Collection as a planned activity: deciding what you need, where it lives, and how to gather it systematically.
- Collection planning and requirements thinking
- Source selection and organization of gathered material
- Turning raw collection into usable intelligence
Domain 5: Legal Fundamentals
The boundary-setting area. Knowing what you may collect, and how, protects both the investigation and the investigator.
- Legal limits on collecting and using information
- Privacy and conduct considerations
- Why lawful method affects whether findings are usable
Notice how the five areas map onto the name. "Open Source Intelligence" and "Intelligence Collection" carry the intelligence discipline. "Social Media Intelligence" and "Cyber Investigations" carry the online practice. "Legal Fundamentals" carries the professional guardrails that make the word "certified" meaningful.
What the Name Means for the Exam Itself
Knowing what the letters stand for is the first step; knowing what you will actually sit is the second. For the exam-only listing, the facts are these:
- Fee: $450 USD for one attempt.
- Exam license: one year.
- Length: three hours, delivered online with proctoring.
- Passing threshold: 70%.
The issuer's institute-wide examination page describes closed-book, on-demand delivery with AI remote proctoring, and formats that include true/false, multiple-choice, and scenario-based questions. That page also gives an approximate question count for the institute's exams generally; do not treat it as the exact item count for C/OSINT, because the credential-specific number was not published. Our pieces on the C/OSINT passing score and how hard the exam is unpack what the 70% threshold and the scenario format mean for preparation.
Who the Credential Is Built For
The exam page lists three eligibility routes based on education and experience:
| Education | Relevant investigative or intelligence experience listed |
|---|---|
| Bachelor's degree or higher | None required |
| Associate degree | Two years |
| High school or equivalent | Three years |
Read this carefully. The same page describes candidates as currently employed full-time in paid investigative or intelligence work. That means the zero-experience degree route should not be read as unrestricted entry; the issuer reviews eligibility, and criminal-history disclosure and a conduct review apply. If you are unsure whether you qualify, ask the issuer before you pay. The full breakdown lives in C/OSINT Requirements 2026: Eligibility, Prerequisites & How to Qualify.
In practice, the target audience is people who investigate or gather intelligence for a living: law enforcement and corporate security investigators, fraud and threat analysts, and others whose work involves public-source research. For a look at the roles that value the credential, see C/OSINT Jobs, and for the earnings side, the C/OSINT salary guide.
Four Numbers People Mix Up
The single most common source of confusion around this credential is that several different numbers sound interchangeable. They are not.
| Quantity | What it actually measures | Value from the issuer's listings |
|---|---|---|
| Course duration | Instructional time in the training product | 55 hours |
| CPE credits earned | Continuing professional education awarded by the course | 50 CPE |
| Exam-license validity | How long your right to sit the exam lasts | One year |
| Certification validity | How long the credential stays current | See renewal section below |
The training product also lists a standard tuition of $2,497 USD and a $997 USD scholarship price at the time of verification. These are the training prices, not the exam fee. If you want the full cost picture across both products, read C/OSINT Certification Cost 2026: Complete Pricing Breakdown, and if you are weighing the spend, Is the C/OSINT Certification Worth It? frames the decision.
Validity and Renewal: Read the Fine Print
The training product advertises lifetime course access. That is access to the learning material, not lifetime validity of the credential. Do not conflate them.
For renewal, the issuer's current help article specifies two-year validity with two-year extensions, plus a 30-day grace period after expiration. However, an issuer blog post dated June 15, 2026 promotes non-expiring credentials, which contradicts the help article. Marketing copy is not a policy document. Obtain written, credential-specific confirmation of the renewal terms that apply to Certified in Open Source Intelligence before you plan around either claim.
Key Takeaway
The 50 CPE credits awarded by the course are not a verified renewal requirement. Ask the issuer how many CPE credits your renewal actually needs, and get the answer in writing. The institute's CPE policy was updated January 1, 2026, so rely on the current version, not older forum advice.
Sequencing Your Preparation Around the Five Areas
You do not need a generic study system here; you need an order that respects how the five areas depend on each other. One sensible way to stage a roughly four-week plan:
Open Source Intelligence and Legal Fundamentals
- Learn the core vocabulary first, since every later area assumes it
- Study legal limits early so they shape how you read every scenario question afterward
Intelligence Collection
- Focus on collection planning and source evaluation
- Practice turning a vague requirement into a collection approach
Social Media Intelligence and Cyber Investigations
- Pair these because both apply collection logic to online environments
- Work scenario-style problems that combine platform content with investigative workflow
Mixed review under exam conditions
- Take timed, closed-book practice across all five areas
- Revisit weak areas; re-check legal reasoning in scenario answers
Putting Legal Fundamentals in week one is deliberate: scenario questions often hinge on what is permissible, so absorbing that lens early improves your answers across the other four areas. For a fuller plan, see C/OSINT Study Guide 2026: How to Pass on Your First Attempt, and keep the C/OSINT cheat sheet handy for last-day review. When you are ready to test yourself, our C/OSINT practice tests follow the five-area structure above.
Frequently Asked Questions
C/OSINT stands for Certified in Open Source Intelligence. The credential is issued and examined by McAfee Institute, which styles it C|OSINT; this site uses C/OSINT as its abbreviation.
Yes, in this context. All three spellings refer to the McAfee Institute credential. The vertical bar is the issuer's styling, the slash is this site's choice, and COSINT is the unpunctuated shorthand seen in URLs.
The exam-only listing is $450 USD for one attempt with a one-year exam license. The separate training product is priced differently, so confirm exactly which items your purchase includes. See our pricing breakdown for detail.
The stated passing threshold is 70%. The exam is three hours, closed-book, and delivered online with remote proctoring. No official pass rate is published here, so we do not quote one.
The current renewal help article describes two-year validity with two-year extensions and a 30-day post-expiration grace period, but an issuer blog conflicts by promoting non-expiring credentials. Get written, credential-specific confirmation from the issuer before relying on either claim.