- What the Credential Is and Who Issues It
- A Note on the Name: C|OSINT vs. C/OSINT
- The Five Preparation Areas
- Exam Format and Delivery
- Eligibility and Conduct Review
- Fees, Training Product, and Package Details
- Validity and Renewal: Read the Fine Print
- Who Benefits From This Credential
- Sequencing Your Preparation
- Frequently Asked Questions
- Certified in Open Source Intelligence is issued and examined by McAfee Institute, which styles it C|OSINT.
- The exam-only listing is $450 USD for one attempt, a one-year exam license, and a three-hour online proctored test.
- The stated passing threshold is 70%; format is closed-book with AI remote proctoring.
- Five listed preparation areas run from open source intelligence to legal fundamentals.
What the Credential Is and Who Issues It
Certified in Open Source Intelligence is a professional credential from McAfee Institute, which also administers the examination. It is aimed at people who gather, evaluate, and apply information from publicly available sources in investigative and intelligence settings. That includes analysts, investigators, and security professionals who need to turn open data into defensible, usable findings.
What separates this credential from a general cybersecurity or IT certification is its focus. It is not primarily about defending networks or configuring systems. It is about collection and analysis of public information, how to do that lawfully, and how to document it so the results hold up. If you want a quick orientation on the terminology itself, our explainer on what C/OSINT is covers the basics, and the page on what C/OSINT stands for addresses the acronym directly.
A Note on the Name: C|OSINT vs. C/OSINT
The issuer styles the credential C|OSINT, with a vertical bar. This site uses C/OSINT as its abbreviation for the same credential. Both refer to Certified in Open Source Intelligence from McAfee Institute.
The Five Preparation Areas
The exam product's curriculum overview lists five preparation areas. It is important to be precise about what these are: they are the topics the issuer explicitly names, presented without weightings. They are not a confirmed, exhaustive exam blueprint, and the detailed outline sits behind the paid training manual. Treat them as the confirmed core of what to study, and expect the exam to probe them in applied, scenario-driven ways. For a deeper walk-through, see our guide to all five C/OSINT content areas.
Domain 1: Open Source Intelligence
The foundation. Candidates need to understand what counts as open source information, how it differs from other intelligence disciplines, and how it fits into an intelligence cycle.
- Distinguishing public, publicly accessible, and restricted information
- Source evaluation: reliability, bias, and corroboration
- Turning raw collection into analysis that supports a decision
Domain 2: Social Media Intelligence
Social platforms are among the richest and messiest sources an investigator touches. Expect questions about how people, networks, and activity appear online and how to interpret them responsibly.
- Profile and network analysis across platforms
- Attribution caution: similar names and accounts are not proof of identity
- Preserving content that may be edited or deleted
Domain 3: Cyber Investigations
This area connects open source work to the digital environment: online infrastructure, digital footprints, and the traces activity leaves behind.
- Reading digital artifacts and public technical records
- Understanding how online activity can be traced and where tracing breaks down
- Operational security for the investigator, so your own collection does not expose you
Domain 4: Intelligence Collection
Collection is where planning meets execution. The emphasis is on being deliberate: defining requirements, choosing sources, and recording what you did.
- Collection planning tied to a clear question
- Documentation and chain-of-custody thinking for open source material
- Knowing when you have enough versus when you are just accumulating data
Domain 5: Legal Fundamentals
Often underestimated, this area governs what you may collect, how, and what you may do with it. Scenario questions frequently turn on a legal or ethical boundary rather than a technical one.
- Privacy considerations and the limits of "publicly available"
- Terms-of-service and authorization boundaries
- Admissibility and defensibility of collected material
Exam Format and Delivery
The exam-only listing describes a three-hour online proctored examination with a stated 70% passing threshold. The issuer's institute-wide examination page adds delivery detail: the exam is closed-book, taken on demand with AI remote proctoring, and draws on true/false, multiple-choice, and scenario-based formats.
One caution: the institute-wide page gives an approximate question count for its exams generally. Do not treat that as the exact number of items on the C/OSINT exam, because it is a general figure rather than a C/OSINT-specific one. Plan around the three-hour window and the 70% threshold instead. For more on scoring, see what you need to pass, and for realistic expectations on difficulty, read how hard the C/OSINT exam is.
| Exam Element | What the Issuer Lists |
|---|---|
| Administrator | McAfee Institute |
| Duration | Three hours |
| Delivery | Online, AI remote proctored, on demand |
| Reference materials | Closed-book |
| Question styles | True/false, multiple-choice, scenario-based |
| Passing threshold | 70% |
| Exam-only fee | $450 USD for one attempt |
Eligibility and Conduct Review
The exam page lays out three experience pathways based on education:
- Bachelor's degree or higher: zero required experience
- Associate degree: two years of relevant investigative or intelligence experience
- High school or equivalent: three years of relevant investigative or intelligence experience
Here is the nuance many candidates miss. The same page describes candidates as currently employed full-time in paid investigative or intelligence work. That wording means the zero-experience degree route should not be assumed to give unrestricted entry. If you are a degree holder without a current investigative role, contact the issuer and request an eligibility review before you pay for anything.
Separately, the issuer's eligibility and conduct policy includes criminal-history disclosure and conduct review. If anything in your background might be relevant, address it up front rather than discovering a problem after purchase. Our C/OSINT requirements guide goes deeper on qualifying.
Key Takeaway
Before purchasing, email the issuer with your education level and current role and ask for written confirmation that you are eligible. A degree alone may not settle the question if you are not in a paid investigative or intelligence position.
Fees, Training Product, and Package Details
There are two distinct products, and mixing them up is the most common budgeting mistake.
| Product | What It Lists |
|---|---|
| Exam only | $450 USD; one attempt; one-year exam license; three-hour online proctored exam |
| Training course | 55 instructional hours; 50 CPE credits; $2,497 USD standard tuition; $997 USD scholarship price at verification |
Keep four quantities separate in your mind: course duration (55 hours), CPE earned (50 credits), exam-license validity (one year), and certification validity. They measure different things and do not substitute for one another. The training product advertises lifetime course access, which is not the same as a lifetime credential.
For the full financial picture, including how the pieces add up, see the C/OSINT certification cost breakdown.
Validity and Renewal: Read the Fine Print
Issuer materials contradict each other here, and you should know about it. The current renewal help article specifies two-year validity, two-year extensions, and a 30-day post-expiration grace period. However, an issuer blog post dated June 15, 2026 promotes non-expiring credentials.
These cannot both be right for the same credential. The help article reads as an operational policy; the blog reads as marketing. The safest approach is to obtain written, credential-specific renewal confirmation from the issuer before relying on either claim. Also note that the course's 50 CPE award is not a verified renewal quota, so do not assume completing the training automatically satisfies renewal requirements. Our ROI analysis factors in why ongoing maintenance costs matter.
Who Benefits From This Credential
The skills tested map to roles where public information drives decisions. Typical fits include:
- Investigators in corporate, financial, insurance, and fraud settings who build subject and entity profiles from public records and online activity
- Intelligence and threat analysts who monitor open sources for risk indicators
- Security and trust-and-safety teams assessing online threats, impersonation, and exposure
- Public-sector and law-enforcement-adjacent personnel who need documented, lawful collection practices
Because the eligibility framing emphasizes paid investigative or intelligence work, the credential is positioned as a professional validation for practitioners, not an entry-level on-ramp for those entirely new to the field. For what employers look for, see our overview of C/OSINT jobs, and for compensation context, the salary guide.
Sequencing Your Preparation
Because the exam is closed-book and scenario-heavy, order matters more than volume. A sensible approach is to start with the conceptual foundation, build the technical layers, and leave legal reasoning running throughout instead of saving it for last, since scenario questions often hinge on it.
Foundations and Legal Framing
- Open Source Intelligence: definitions, source evaluation, the intelligence cycle
- Start Legal Fundamentals early so privacy and authorization reasoning shapes everything else
Platform and Technical Layers
- Social Media Intelligence: attribution caution, preservation
- Cyber Investigations: digital artifacts, investigator opsec
Collection Discipline and Integration
- Intelligence Collection: planning, documentation, requirements
- Timed scenario practice that blends all five areas under the three-hour limit
For a complete plan, use our C/OSINT study guide, and keep the one-page cheat sheet handy for last-mile review. When you are ready to test yourself under realistic conditions, take a timed run on the C/OSINT practice test site to find which of the five areas needs more work.
Frequently Asked Questions
McAfee Institute issues the credential and administers the examination. The issuer styles it C|OSINT, while this site uses C/OSINT as the abbreviation for the same certification.
The exam-only listing is $450 USD for one attempt, a one-year exam license, and a three-hour online proctored exam. Confirm whether your specific purchase includes training, the manual, and review quizzes, because the issuer's page is inconsistent on this point.
The stated passing threshold is 70%. The exam is closed-book and AI remote proctored, with true/false, multiple-choice, and scenario-based formats.
The exam page lists zero required experience for bachelor's degree holders, but it also describes candidates as employed full-time in paid investigative or intelligence work. Request an eligibility review from the issuer before purchasing, and note that criminal-history disclosure and conduct review apply.
The current renewal help article specifies two-year validity with two-year extensions and a 30-day post-expiration grace period, but an issuer blog promotes non-expiring credentials. Get written, credential-specific confirmation of renewal terms rather than relying on either source alone.