C/OSINT logo
Focused certification exam prep
Start practice

What Is C/OSINT Certification?

TL;DR
  • Certified in Open Source Intelligence is issued and examined by McAfee Institute, which styles it C|OSINT.
  • The exam-only listing is $450 USD for one attempt, a one-year exam license, and a three-hour online proctored test.
  • The stated passing threshold is 70%; format is closed-book with AI remote proctoring.
  • Five listed preparation areas run from open source intelligence to legal fundamentals.

What the Credential Is and Who Issues It

Certified in Open Source Intelligence is a professional credential from McAfee Institute, which also administers the examination. It is aimed at people who gather, evaluate, and apply information from publicly available sources in investigative and intelligence settings. That includes analysts, investigators, and security professionals who need to turn open data into defensible, usable findings.

What separates this credential from a general cybersecurity or IT certification is its focus. It is not primarily about defending networks or configuring systems. It is about collection and analysis of public information, how to do that lawfully, and how to document it so the results hold up. If you want a quick orientation on the terminology itself, our explainer on what C/OSINT is covers the basics, and the page on what C/OSINT stands for addresses the acronym directly.

A Note on the Name: C|OSINT vs. C/OSINT

The issuer styles the credential C|OSINT, with a vertical bar. This site uses C/OSINT as its abbreviation for the same credential. Both refer to Certified in Open Source Intelligence from McAfee Institute.

Verify the credential, not just the acronym: Several unrelated credentials in the intelligence and investigations space use similar abbreviations. When you research fees, dates, or requirements, confirm that the page you are reading is about the McAfee Institute product. Facts from a different certification will not apply to your exam.

The Five Preparation Areas

The exam product's curriculum overview lists five preparation areas. It is important to be precise about what these are: they are the topics the issuer explicitly names, presented without weightings. They are not a confirmed, exhaustive exam blueprint, and the detailed outline sits behind the paid training manual. Treat them as the confirmed core of what to study, and expect the exam to probe them in applied, scenario-driven ways. For a deeper walk-through, see our guide to all five C/OSINT content areas.

Domain 1: Open Source Intelligence

The foundation. Candidates need to understand what counts as open source information, how it differs from other intelligence disciplines, and how it fits into an intelligence cycle.

  • Distinguishing public, publicly accessible, and restricted information
  • Source evaluation: reliability, bias, and corroboration
  • Turning raw collection into analysis that supports a decision

Domain 2: Social Media Intelligence

Social platforms are among the richest and messiest sources an investigator touches. Expect questions about how people, networks, and activity appear online and how to interpret them responsibly.

  • Profile and network analysis across platforms
  • Attribution caution: similar names and accounts are not proof of identity
  • Preserving content that may be edited or deleted

Domain 3: Cyber Investigations

This area connects open source work to the digital environment: online infrastructure, digital footprints, and the traces activity leaves behind.

  • Reading digital artifacts and public technical records
  • Understanding how online activity can be traced and where tracing breaks down
  • Operational security for the investigator, so your own collection does not expose you

Domain 4: Intelligence Collection

Collection is where planning meets execution. The emphasis is on being deliberate: defining requirements, choosing sources, and recording what you did.

  • Collection planning tied to a clear question
  • Documentation and chain-of-custody thinking for open source material
  • Knowing when you have enough versus when you are just accumulating data

Domain 5: Legal Fundamentals

Often underestimated, this area governs what you may collect, how, and what you may do with it. Scenario questions frequently turn on a legal or ethical boundary rather than a technical one.

  • Privacy considerations and the limits of "publicly available"
  • Terms-of-service and authorization boundaries
  • Admissibility and defensibility of collected material
Don't over-read the order: The five areas are listed without percentages. Do not assume Domain 1 carries the most weight or that Legal Fundamentals carries the least. Prepare for all five, and use the training manual to see how the issuer treats each topic.

Exam Format and Delivery

The exam-only listing describes a three-hour online proctored examination with a stated 70% passing threshold. The issuer's institute-wide examination page adds delivery detail: the exam is closed-book, taken on demand with AI remote proctoring, and draws on true/false, multiple-choice, and scenario-based formats.

One caution: the institute-wide page gives an approximate question count for its exams generally. Do not treat that as the exact number of items on the C/OSINT exam, because it is a general figure rather than a C/OSINT-specific one. Plan around the three-hour window and the 70% threshold instead. For more on scoring, see what you need to pass, and for realistic expectations on difficulty, read how hard the C/OSINT exam is.

Exam ElementWhat the Issuer Lists
AdministratorMcAfee Institute
DurationThree hours
DeliveryOnline, AI remote proctored, on demand
Reference materialsClosed-book
Question stylesTrue/false, multiple-choice, scenario-based
Passing threshold70%
Exam-only fee$450 USD for one attempt

Eligibility and Conduct Review

The exam page lays out three experience pathways based on education:

  • Bachelor's degree or higher: zero required experience
  • Associate degree: two years of relevant investigative or intelligence experience
  • High school or equivalent: three years of relevant investigative or intelligence experience

Here is the nuance many candidates miss. The same page describes candidates as currently employed full-time in paid investigative or intelligence work. That wording means the zero-experience degree route should not be assumed to give unrestricted entry. If you are a degree holder without a current investigative role, contact the issuer and request an eligibility review before you pay for anything.

Separately, the issuer's eligibility and conduct policy includes criminal-history disclosure and conduct review. If anything in your background might be relevant, address it up front rather than discovering a problem after purchase. Our C/OSINT requirements guide goes deeper on qualifying.

Key Takeaway

Before purchasing, email the issuer with your education level and current role and ask for written confirmation that you are eligible. A degree alone may not settle the question if you are not in a paid investigative or intelligence position.

Fees, Training Product, and Package Details

There are two distinct products, and mixing them up is the most common budgeting mistake.

ProductWhat It Lists
Exam only$450 USD; one attempt; one-year exam license; three-hour online proctored exam
Training course55 instructional hours; 50 CPE credits; $2,497 USD standard tuition; $997 USD scholarship price at verification

Keep four quantities separate in your mind: course duration (55 hours), CPE earned (50 credits), exam-license validity (one year), and certification validity. They measure different things and do not substitute for one another. The training product advertises lifetime course access, which is not the same as a lifetime credential.

Confirm what your SKU includes: The exam-only page excludes training, the manual, and review quizzes in its package description, yet a later generic benefits section on the same page appears to include them. Before checkout, confirm in writing exactly what the specific item you are buying contains. The institute-wide exam and retake license is also listed at $450 USD, which matters if you need a second attempt.

For the full financial picture, including how the pieces add up, see the C/OSINT certification cost breakdown.

Validity and Renewal: Read the Fine Print

Issuer materials contradict each other here, and you should know about it. The current renewal help article specifies two-year validity, two-year extensions, and a 30-day post-expiration grace period. However, an issuer blog post dated June 15, 2026 promotes non-expiring credentials.

These cannot both be right for the same credential. The help article reads as an operational policy; the blog reads as marketing. The safest approach is to obtain written, credential-specific renewal confirmation from the issuer before relying on either claim. Also note that the course's 50 CPE award is not a verified renewal quota, so do not assume completing the training automatically satisfies renewal requirements. Our ROI analysis factors in why ongoing maintenance costs matter.

Who Benefits From This Credential

The skills tested map to roles where public information drives decisions. Typical fits include:

  • Investigators in corporate, financial, insurance, and fraud settings who build subject and entity profiles from public records and online activity
  • Intelligence and threat analysts who monitor open sources for risk indicators
  • Security and trust-and-safety teams assessing online threats, impersonation, and exposure
  • Public-sector and law-enforcement-adjacent personnel who need documented, lawful collection practices

Because the eligibility framing emphasizes paid investigative or intelligence work, the credential is positioned as a professional validation for practitioners, not an entry-level on-ramp for those entirely new to the field. For what employers look for, see our overview of C/OSINT jobs, and for compensation context, the salary guide.

Sequencing Your Preparation

Because the exam is closed-book and scenario-heavy, order matters more than volume. A sensible approach is to start with the conceptual foundation, build the technical layers, and leave legal reasoning running throughout instead of saving it for last, since scenario questions often hinge on it.

Weeks 1-2

Foundations and Legal Framing

  • Open Source Intelligence: definitions, source evaluation, the intelligence cycle
  • Start Legal Fundamentals early so privacy and authorization reasoning shapes everything else
Weeks 3-4

Platform and Technical Layers

  • Social Media Intelligence: attribution caution, preservation
  • Cyber Investigations: digital artifacts, investigator opsec
Weeks 5-6

Collection Discipline and Integration

  • Intelligence Collection: planning, documentation, requirements
  • Timed scenario practice that blends all five areas under the three-hour limit

For a complete plan, use our C/OSINT study guide, and keep the one-page cheat sheet handy for last-mile review. When you are ready to test yourself under realistic conditions, take a timed run on the C/OSINT practice test site to find which of the five areas needs more work.

Frequently Asked Questions

Who issues the Certified in Open Source Intelligence credential?

McAfee Institute issues the credential and administers the examination. The issuer styles it C|OSINT, while this site uses C/OSINT as the abbreviation for the same certification.

How much does the exam cost and what does it include?

The exam-only listing is $450 USD for one attempt, a one-year exam license, and a three-hour online proctored exam. Confirm whether your specific purchase includes training, the manual, and review quizzes, because the issuer's page is inconsistent on this point.

What score do I need to pass?

The stated passing threshold is 70%. The exam is closed-book and AI remote proctored, with true/false, multiple-choice, and scenario-based formats.

Can I sit the exam with a degree and no experience?

The exam page lists zero required experience for bachelor's degree holders, but it also describes candidates as employed full-time in paid investigative or intelligence work. Request an eligibility review from the issuer before purchasing, and note that criminal-history disclosure and conduct review apply.

Does the credential expire?

The current renewal help article specifies two-year validity with two-year extensions and a 30-day post-expiration grace period, but an issuer blog promotes non-expiring credentials. Get written, credential-specific confirmation of renewal terms rather than relying on either source alone.

Ready to pass your C/OSINT exam?

Put this into practice with free C/OSINT questions across every exam domain.