- What Certified in Open Source Intelligence Actually Is
- C/OSINT vs. C|OSINT: A Note on the Name
- The Five Preparation Areas
- How the Exam Works
- Who Can Sit the Exam
- Fees, Training, and What You Actually Pay For
- Validity, Renewal, and CPE: Three Different Clocks
- Who This Credential Is For
- Sequencing Your Preparation Around the Five Areas
- Frequently Asked Questions
- C/OSINT here means Certified in Open Source Intelligence, issued and examined by McAfee Institute.
- The exam-only listing is $450 USD for one attempt, a one-year exam license, and a three-hour online proctored test.
- The stated passing threshold is 70%; the exam is closed-book with AI remote proctoring.
- Listed preparation areas: Open Source Intelligence, Social Media Intelligence, Cyber Investigations, Intelligence Collection, and Legal Fundamentals.
What Certified in Open Source Intelligence Actually Is
Certified in Open Source Intelligence is a professional credential from McAfee Institute aimed at people who gather, evaluate, and report on information from publicly available sources as part of investigative or intelligence work. It sits in the practitioner tier: it is built around what an investigator does with open sources day to day, not around academic theory or a single software product.
The same organization that designs the training also administers the examination. That matters for candidates, because the exam, the training course, the eligibility rules, and the renewal policy all come from one issuer. When you have a question about any of them, the issuer is the authoritative source, and this site's guidance should always be checked against current issuer pages.
C/OSINT vs. C|OSINT: A Note on the Name
McAfee Institute styles its credential with a vertical bar, C|OSINT, which is how the issuer brands all of its certifications. This site uses C/OSINT as its working abbreviation, largely because a slash is easier to type, link, and search for. They refer to the same credential.
If you are searching for the meaning behind the acronym, our explainers on what C/OSINT stands for and the meaning of C/OSINT cover the terminology in more detail. For the certification as a whole, see What Is C/OSINT Certification?
The Five Preparation Areas
The exam product's curriculum overview lists five preparation areas. These are unweighted topics: the issuer has not published percentage weights for them in the material we could verify, and they should not be read as a complete, official exam blueprint. Treat them as the confirmed spine of your preparation, and expect that questions may touch adjacent material. For a deeper walk-through, see the complete guide to all 5 content areas.
1. Open Source Intelligence
The foundation: what open source intelligence is, how it differs from other intelligence disciplines, and how information from public sources becomes usable intelligence.
- The difference between raw information, processed information, and finished intelligence
- Evaluating source reliability and information credibility before relying on either
- Structuring a collection effort around a defined question rather than open-ended browsing
2. Social Media Intelligence
Social platforms are among the richest and most volatile open sources. This area covers extracting investigative value from them.
- Identifying and corroborating people, accounts, and relationships across platforms
- Understanding how content, timestamps, and metadata can support or undermine a lead
- Preserving evidence from content that can be edited or deleted
3. Cyber Investigations
Investigations increasingly run through digital infrastructure. Expect questions that connect online identifiers and digital artifacts to real-world investigative questions.
- Working with online identifiers such as usernames, email addresses, domains, and IP-related information
- Recognizing what digital trails can and cannot establish
- Protecting your own operational security while investigating
4. Intelligence Collection
The tradecraft of gathering information deliberately and defensibly.
- Planning collection against specific requirements
- Documenting sources, methods, and the chain of how you obtained each item
- Knowing when open sources are sufficient and when a question needs other means
5. Legal Fundamentals
The area candidates most often underestimate. Public availability does not automatically mean lawful collection or admissible use.
- Privacy expectations and the limits on how public information may be gathered and used
- Terms-of-service and access issues when collecting from online platforms
- How lawful, well-documented collection supports later use of the findings
One caution: the specific laws and standards that apply to you depend on your jurisdiction and employer. The exam tests the issuer's curriculum, so base your study on the official training material rather than on assumptions from your own workplace practice.
How the Exam Works
The verified details for the C/OSINT exam listing are straightforward:
| Feature | What the issuer states |
|---|---|
| Administrator | McAfee Institute |
| Delivery | Online, with on-demand AI remote proctoring |
| Time allowed | Three hours |
| Book policy | Closed-book |
| Passing threshold | 70% |
| Attempts in the exam-only listing | One, with a one-year exam license |
| Question styles (institute-wide guidance) | True/false, multiple-choice, and scenario-based |
The institute-wide examination page gives an approximate question count for its exams generally, but we do not convert that into an exact number of C/OSINT items, because the credential-specific count is not stated. Plan around the time limit and the format rather than a fixed item total. Details on scoring are in our C/OSINT passing score guide.
What scenario-based questions reward
Scenario questions typically describe an investigative situation and ask what you should do, collect, or avoid. In a certification built around practice, the strongest answer is usually the one that is lawful, documented, proportionate to the requirement, and protective of the investigation. Memorizing definitions helps with true/false and multiple-choice items; practicing decisions helps with scenarios. Our difficulty guide discusses where candidates tend to find the exam demanding, and the pass rate article explains what is and is not publicly known about outcomes.
Who Can Sit the Exam
The exam page describes three eligibility paths based on education and relevant investigative or intelligence experience:
- A bachelor's degree or higher, with zero required experience
- An associate degree with two years of relevant experience
- A high-school diploma or equivalent with three years of relevant experience
Criminal-history disclosure and a conduct review also apply under the issuer's eligibility and conduct policy. This is typical of credentials that certify people who may handle sensitive investigative information. Our C/OSINT requirements guide goes through qualification step by step.
Fees, Training, and What You Actually Pay For
There are two separate products, and confusing them is the most common budgeting mistake:
| Product | Price shown at verification | Key details |
|---|---|---|
| Exam only | $450 USD | One attempt, one-year exam license, three-hour online proctored exam |
| Training course | $2,497 USD standard; $997 USD scholarship price | 55 instructional hours, 50 CPE credits, lifetime course access |
Prices and scholarship availability can change, so confirm them on the issuer's pages at purchase time. The institute-wide page also lists an examination and retake license at $450 USD.
Check what your exam purchase includes
The exam-only page is internally inconsistent. Its package description says training, manual, and review quizzes are excluded, yet a later generic benefits section appears to include them. Do not assume either reading. Before you pay, confirm in writing which materials come with the specific SKU you are buying, and budget for the training separately if it is not included. Our full pricing breakdown lays out the cost scenarios, and the C/OSINT training overview describes the course itself.
Validity, Renewal, and CPE: Three Different Clocks
Several different durations get blurred together in discussions of this credential. Keep them apart:
- Exam license validity: The exam-only listing carries a one-year license for your attempt.
- Course access: The training product advertises lifetime course access. That is access to the course, not a promise that your credential never expires.
- Credential validity: The issuer's current renewal help article describes two-year validity, two-year extensions, and a 30-day post-expiration grace period.
The course's 50 CPE credits are an award for completing the training. They are not a verified renewal requirement, so do not assume 50 credits equals a renewal. Meanwhile, an issuer blog post dated June 15, 2026 promotes non-expiring credentials, which contradicts the help article. Until you have written confirmation specific to this credential, plan around the two-year renewal cycle rather than the marketing claim. The institute also maintains a CPE policy, updated January 1, 2026, which is the right place to check how credits are counted.
Key Takeaway
Get renewal terms for Certified in Open Source Intelligence in writing from McAfee Institute before you budget for the long term. Treat the two-year cycle in the help article as the working assumption.
Who This Credential Is For
Because eligibility is tied to investigative or intelligence work, the natural audience is people already in or moving within that field. Typical settings include law enforcement and public-safety agencies, corporate security and investigations teams, fraud and risk units, threat intelligence functions, and private investigators. The credential signals structured training in lawful online collection, which is useful anywhere the output of an investigation may be scrutinized.
We do not publish invented salary or hiring numbers for it. Compensation depends far more on your role, employer, and clearance or licensing environment than on any single certification, and published data specific to this credential is thin. If you want to weigh the investment, see our discussions of whether the certification is worth it, the salary analysis, and the C/OSINT jobs overview.
Sequencing Your Preparation Around the Five Areas
Generic study advice is less useful here than a sensible order for the five areas. One reasonable sequence follows how the topics build on one another:
Open Source Intelligence + Legal Fundamentals
- Learn the vocabulary and the intelligence cycle first, since every other area assumes it
- Pair it with legal basics early so lawful collection becomes a habit, not an afterthought
Intelligence Collection
- Practice turning a vague question into a collection plan and documenting each step
Social Media Intelligence + Cyber Investigations
- These two overlap heavily on identifiers and attribution, so study them together
- Rehearse scenario reasoning: what a lead proves, what it does not
Integration and timed practice
- Work mixed scenarios under a three-hour time frame, then revisit Legal Fundamentals, the area most likely to be underprepared
For a fuller plan, read the C/OSINT study guide, and keep the one-page cheat sheet nearby for final review. When you are ready to test yourself, the C/OSINT practice tests let you rehearse scenario-style questions, and you can track your readiness across all five areas on our main practice site. If you are still deciding on timing, see the notes on exam dates and scheduling.
Frequently Asked Questions
On this site it means Certified in Open Source Intelligence, a credential from McAfee Institute. The issuer writes it as C|OSINT; C/OSINT is the abbreviation used here.
The exam-only listing is $450 USD for one attempt with a one-year exam license. The separate training product lists $2,497 USD standard tuition and a $997 USD scholarship price at the time we verified it. Confirm current pricing with the issuer.
The stated passing threshold is 70%. The exam is three hours, closed-book, and delivered online with AI remote proctoring.
It depends on your education. The listed routes are a bachelor's degree or higher with no required experience, an associate degree with two years, or a high-school diploma or equivalent with three years of relevant experience. Because the issuer also describes candidates as employed in investigative or intelligence work, verify your route with them first.
The issuer's current renewal help article describes two-year validity with two-year extensions and a 30-day grace period after expiration. A marketing blog suggests otherwise, so get written confirmation for this specific credential before relying on either.