C/OSINT logo
Focused certification exam prep
Start practice

What Is A C/OSINT?

TL;DR
  • C/OSINT here means Certified in Open Source Intelligence, issued and examined by McAfee Institute, which styles it C|OSINT.
  • The exam costs $450 USD for one attempt, with a one-year exam license and a three-hour online proctored sitting.
  • The stated passing threshold is 70%, and the curriculum lists five preparation areas, from OSINT to Legal Fundamentals.
  • Eligibility pairs education with experience, and full-time investigative employment is described, so confirm your route with the issuer first.

What a C/OSINT Actually Is

A C/OSINT is a professional certification in open source intelligence: the discipline of collecting, evaluating and applying information from publicly available sources to support investigations and intelligence work. The credential is Certified in Open Source Intelligence, and it is issued and examined by McAfee Institute. If you are asking what a C/OSINT is, the short answer is a credential that signals you can run structured, lawful, source-based research across social platforms, websites, records and digital traces, and that you understand the legal boundaries around doing so.

The word "certified" matters. This is not a degree and it is not a vendor tool badge. It is a credential awarded after passing an examination, backed by an issuer with a defined eligibility and conduct policy. For a deeper walkthrough of the term itself, see our explainer on what C/OSINT certification is, and for the plain-language definition see what C/OSINT stands for.

Identity check: Several credentials in the security and intelligence world abbreviate to something similar. Everything on this page refers only to Certified in Open Source Intelligence from McAfee Institute. Fees, formats and policies from other programs do not apply here, so always verify details against the issuer's own product pages.

The C|OSINT Styling and Why This Site Uses C/OSINT

McAfee Institute writes the credential as C|OSINT, with a vertical bar, which is a house style it applies across its certification family. This site uses C/OSINT with a slash as its chosen abbreviation, largely because a slash is easier to handle in URLs and plain text. They refer to the same credential. When you register, read official materials or list the certification on a résumé, follow the issuer's styling.

If you are comparing the many ways people search for this credential, our pages on C/OSINT meaning and what C/OSINT means cover the naming variations in more detail.

The Five Preparation Areas

The exam product's curriculum overview lists five preparation areas. Treat these as unweighted topic headings, not a verified count of official examination domains and not an exhaustive blueprint. The detailed outline sits behind the paid course materials, so no public source gives percentage weights per area. Anyone quoting precise domain percentages for this exam is guessing.

Domain 1: Open Source Intelligence

The foundation: what OSINT is, how the intelligence cycle applies to public-source work, and how to plan collection around a question instead of wandering through search results.

  • Defining requirements before collecting anything
  • Distinguishing information from assessed intelligence
  • Evaluating source reliability and information credibility
  • Documenting methods so findings can be reproduced and defended

Domain 2: Social Media Intelligence

Platforms are where much modern open-source investigation happens. Expect to understand how profiles, connections, posts and metadata can inform an inquiry, and how to preserve what you find.

  • Profile and network analysis across major platforms
  • Attribution caution: similar usernames are not proof of identity
  • Capturing and preserving content before it disappears
  • Awareness of platform terms and privacy settings

Domain 3: Cyber Investigations

The technical layer: domains, infrastructure, digital artifacts and the traces people leave online. This area connects open-source research to the wider world of digital investigation.

  • Reading digital footprints and public technical records
  • Understanding how online activity can be traced and corroborated
  • Operational security for the investigator, so your own research does not expose you

Domain 4: Intelligence Collection

Collection is about method and discipline: choosing sources, structuring searches, managing what you gather and avoiding bias in what you keep.

  • Building repeatable collection plans
  • Search strategy and source diversification
  • Organizing, tagging and validating collected material
  • Knowing when you have enough to answer the question

Domain 5: Legal Fundamentals

Legal knowledge separates a professional from a hobbyist. Candidates should expect scenario-style thinking about what is permissible, what crosses a line and how handling affects the usefulness of evidence.

  • Lawful access versus unauthorized access
  • Privacy considerations and acceptable-use limits
  • Evidence handling and documentation expectations
  • Recognizing when to stop and escalate to counsel or a supervisor

For a section-by-section breakdown of how these areas fit together, read our complete guide to the five C/OSINT content areas.

How the Exam Is Delivered

The exam-only listing describes a three-hour online proctored examination with a stated passing threshold of 70%. The institute-wide examination page adds that delivery is closed-book, on demand and monitored by AI remote proctoring, and that formats include true/false, multiple-choice and scenario-based questions. That page gives only an approximate question count for the institute's exams generally, so do not treat any number you see quoted as the exact item count for this particular exam.

What scenario-based means for you: Scenario items reward judgment, not recall. You may be handed a short investigative situation and asked what the most appropriate, lawful or defensible next step is. Candidates who only memorized definitions tend to struggle here; candidates who practiced applying concepts to situations do better.

Because the format is closed-book and remotely proctored, set up your testing environment in advance: a quiet room, a stable connection and a device that meets the proctoring requirements. Our guides on the C/OSINT passing score and exam dates and scheduling go further into logistics, and how hard the exam is covers what makes it demanding.

Who Can Sit the Exam

The exam page describes three entry routes based on education and experience:

Education LevelRelevant Experience Described
Bachelor's degree or higherZero required experience
Associate degreeTwo years of relevant investigative or intelligence experience
High school or equivalentThree years of relevant investigative or intelligence experience

There is an important wrinkle. The same page also describes candidates as currently employed full-time in paid investigative or intelligence work. That means the zero-experience route for degree holders should not be read as unrestricted entry. If you are a student, career changer or hobbyist, contact the issuer and request an eligibility review before you buy anything. Criminal-history disclosure and a conduct review also apply under the issuer's eligibility and conduct policy.

Key Takeaway

Do not pay for the exam until the issuer has confirmed in writing that your background qualifies. Eligibility wording on the product page is broader than the employment language elsewhere, and an email confirmation removes the ambiguity. Our C/OSINT requirements guide lays out the qualification process step by step.

Fees, Training and What You Pay For

Costs split into two separate products, and mixing them up is the most common budgeting mistake.

ItemWhat the Listing States
Exam only$450 USD for one attempt, one-year exam license, three-hour online proctored exam
Retake / exam license (institute-wide page)$450 USD
Training course55 instructional hours, 50 CPE credits awarded
Training tuition$2,497 USD standard; $997 USD scholarship price at the time of verification

Note that course length, CPE earned, exam-license validity and certification validity are four different quantities. A 55-hour course does not mean a 55-day anything, and a one-year exam license is not a one-year credential.

Check what your SKU includes

The exam-only page excludes training, the manual and review quizzes in its package description, yet a later generic benefits section on the same page appears to include them. Before checking out, confirm exactly which materials come with the exact product you are buying. If the manual and quizzes are not included, factor in that cost or the training purchase. For the full financial picture, see our C/OSINT certification cost breakdown and the companion article on C/OSINT training.

Validity, Renewal and CPE

This is where the issuer's own materials disagree, so read carefully. The current renewal help article specifies two-year validity and two-year extensions, with a 30-day post-expiration grace period. However, an issuer blog dated June 15, 2026 promotes non-expiring credentials, which contradicts that help article. Marketing copy is not a policy document. Obtain written, credential-specific renewal confirmation before you plan your career around either claim.

Likewise, the training course advertises lifetime course access, which is about content access and says nothing on its own about how long the credential stays valid. And the 50 CPE credits the course awards are not a verified renewal quota; the CPE policy should be consulted for what actually counts toward renewal.

Three claims to keep apart: Lifetime course access, a one-year exam license and the validity period of the credential itself are different things. Ask the issuer which one governs your renewal date, and keep the reply on file.

Who Benefits From This Credential

Open source intelligence skills are used wherever someone must find, verify and document public information in support of a decision. Typical settings include law enforcement and investigative units, corporate security and risk teams, fraud and compliance functions, threat intelligence groups, and private investigation or consulting practices. Because the exam page describes candidates in paid investigative or intelligence roles, the credential is best understood as professional validation for people already working in or adjacent to those fields.

Whether it moves your pay or promotion prospects depends on your employer and role, and no reliable public salary figure is tied specifically to this credential. For a realistic discussion, see our salary analysis, the worth-it ROI guide and our overview of C/OSINT jobs.

Sequencing Your Preparation

Because the five areas build on each other, the order you study them in matters more than a generic schedule. Start with the foundations, add technique, and finish with legal judgment so it frames everything else.

Week 1

Open Source Intelligence

  • Learn the intelligence cycle vocabulary the rest of the exam assumes
  • Practice rating source reliability on real examples
Week 2

Social Media Intelligence and Intelligence Collection

  • Pair platform analysis with collection planning, since they are used together
  • Practice documenting how you found something, not just what you found
Week 3

Cyber Investigations

  • Work through digital footprint and attribution scenarios
  • Review operational security habits for investigators
Week 4

Legal Fundamentals, then full review

  • Revisit every earlier area through a legal lens
  • Finish with timed mixed practice to simulate the three-hour sitting

Legal Fundamentals goes last on purpose: once you know the techniques, you can judge which ones are permissible and defensible. For a fuller plan, use our C/OSINT study guide, keep the one-page cheat sheet nearby for final review, and test yourself with the questions on the main practice test site. Candidates who want to measure readiness before committing can try a few scenario questions from the practice question bank to see whether they are reasoning from judgment or memory.

Frequently Asked Questions

What does C/OSINT stand for?

On this site it stands for Certified in Open Source Intelligence, a credential issued and examined by McAfee Institute. The issuer styles it C|OSINT with a vertical bar; the slash is simply this site's chosen abbreviation.

How long is the C/OSINT exam and what score passes?

The exam listing describes a three-hour online proctored examination with a stated passing threshold of 70%. The exact number of questions is not published in the sources reviewed, so be wary of anyone quoting one.

How much does the C/OSINT exam cost?

The exam-only listing is $450 USD for one attempt with a one-year exam license. The separate 55-hour training course lists $2,497 USD standard tuition and a $997 USD scholarship price at verification. Confirm which materials your exact purchase includes.

Do I need work experience to take it?

It depends on your education: the exam page describes zero required experience with a bachelor's degree or higher, two years with an associate degree, and three years with a high-school equivalent. The page also describes full-time paid investigative or intelligence employment, so request issuer confirmation of your eligibility before purchasing.

Does the certification expire?

The current renewal help article specifies two-year validity with two-year extensions and a 30-day post-expiration grace period, but an issuer blog promotes non-expiring credentials. Treat the help article as the policy source and get written, credential-specific confirmation from McAfee Institute.

Ready to pass your C/OSINT exam?

Put this into practice with free C/OSINT questions across every exam domain.