- Identity Check: Which CECI This Sheet Covers
- Exam Mechanics at a Glance
- Eligibility Grid
- Money, Program Size, and What They Are Not
- The Four Published Learning Outcomes
- The Thirteen Preparation Areas
- Evidence and Reporting Rules to Know Cold
- Numbers That Get Confused
- Sequencing the Areas Across Your Prep
- Where the Credential Fits in Casework and Hiring
- Frequently Asked Questions
- CECI is the McAfee Institute capstone: online proctored, three hours, one attempt, USD 450, 70% passing threshold.
- The one-year exam license is an access window for sitting the exam, not the validity period of the credential.
- The USD 2,497 program has 43 modules and 100 hours, but modules are not weighted exam domains.
- Official topic weights, question count and item format are unverified, so never memorize a "blueprint" claiming otherwise.
Identity Check: Which CECI This Sheet Covers
Several credentials in the wider world share the acronym "CECI." This cheat sheet covers exactly one of them: the Certified Expert in Cyber Investigations, administered by McAfee Institute. Nothing below applies to any other credential that happens to abbreviate the same way, so if you have seen fees, dates or pass-rate claims attached to a different "CECI," discard them. If you are still orienting, the explainer pages What Is CECI? and What Does CECI Stand For? cover the naming question in more depth.
This page is built for a final-week skim: hard facts first, then the technical areas named in the issuer's public curriculum narrative, then the traps that cost candidates points through confusion rather than ignorance. For a slower, full-length plan, use the CECI study guide alongside this sheet.
Exam Mechanics at a Glance
| Item | What the issuer publishes |
|---|---|
| Certifying body | McAfee Institute |
| Role of CECI | Capstone certification in a multi-credential program |
| Delivery | Online proctored |
| Time limit | Three hours |
| Attempts | One attempt |
| Standalone exam fee | USD 450 |
| Exam license | One year (an access period) |
| Passing threshold | 70% |
| Question count | Unverified: do not assume a number |
| Item format | Unverified: do not assume multiple choice |
| Official topic weights | Unverified |
The single most important line in that table is "one attempt." A one-attempt, proctored, three-hour exam rewards candidates who have rehearsed pacing and scenario reasoning, not just vocabulary. See CECI Passing Score for how to think about the 70% threshold, and How Hard Is the CECI Exam? for a difficulty assessment grounded in what is actually published.
Eligibility Grid
CECI is experience-gated. Your education level determines how much qualifying experience you need:
| Education | Required relevant experience |
|---|---|
| Bachelor's degree or higher | Four years |
| Associate degree | Six years |
| High-school diploma or equivalent | Seven years |
Qualifying experience must involve criminal investigations or intelligence in investigations, in law enforcement, criminal justice, the military, or a similar field. Eligibility documentation and professional-conduct requirements also apply, which means the credential is not a pure "pay and test" product. Work through the details in CECI Requirements: Eligibility, Prerequisites & How to Qualify before you budget time or money.
Money, Program Size, and What They Are Not
There are two ways to reach the exam, and the numbers attached to each are easy to cross-contaminate.
Standalone exam path
For candidates who prepare independently and qualify on experience.
- USD 450 exam fee
- Online proctored, three hours, one attempt
- One-year exam license
Self-paced program path
A bundled training product with CECI as the capstone.
- USD 2,497
- 43 modules and 100 instructional hours
- 100 course CPE credits
- Training, study manual, review quizzes, a one-year exam license, and lifetime course access
- Bundles six credentials: CFHI, CEFI, SMIA, CCIP and CCTA, with CECI as the capstone
The full economic picture, including how to compare the two paths, lives in CECI Certification Cost. If you are weighing the investment, Is the CECI Certification Worth It? and the CECI salary guide address return on investment.
The Four Published Learning Outcomes
The issuer's current narrative frames the program around four outcomes. Treat these as the spine of your preparation:
- Advanced investigation methods: investigative playbooks, attribution, threat modeling and covert intelligence collection.
- Hands-on, real-world labs: simulated cases and tools, which is why practical fluency matters more than definitions alone.
- Forensically sound evidence: legally defensible handling, chain of custody and prosecution-ready reporting.
- Building and leading cyber programs: SOPs, team structure and metric-driven reporting.
Notice that two of the four are about process and defensibility (evidence handling, program leadership) rather than raw technical skill. Candidates from purely technical backgrounds often under-prepare those two.
The Thirteen Preparation Areas
The thirteen headings below organize technical areas explicitly named in the current public CECI narrative. They are editorial preparation categories, not an official blueprint and not the program's 43-module list; the public curriculum data does not expose module titles, and official weights are unverified. For the long-form treatment, see CECI Exam Domains: Complete Guide to All 13 Content Areas.
1. Intelligence foundations
The conceptual base for everything else: how intelligence differs from raw information and how it supports investigative decisions.
- Know how playbooks, attribution and threat modeling structure an investigation
- Be able to explain why a collection plan precedes collection
2. Open-source intelligence and online research
Methodical, documented research using publicly available sources.
- Source evaluation and corroboration before reliance
- Capturing and preserving what you find so it can be defended later
3. Social media intelligence
Extracting investigative value from social platforms without compromising the case.
- Account and relationship analysis
- Preservation of volatile, easily deleted content
4. Cybercrime investigations
Working technology-enabled offenses from complaint through attribution.
- Linking digital artifacts to actors
- Coordinating with other disciplines on multi-part cases
5. Counterintelligence
Protecting investigative operations and information from hostile collection and compromise.
- Recognizing exposure risks to sources, methods and teams
6. Fraud investigations
Reconstructing deceptive schemes and the financial or digital trail they leave.
- Pattern recognition and evidence linkage across records
7. Organized retail crime
Investigating coordinated theft and resale operations as networks rather than isolated incidents.
- Connecting individual events into a group-level case
8. Electronic discovery
Identifying, preserving and producing electronically stored information in a defensible way.
- Scope, preservation and handling of ESI
9. Computer forensics
Acquiring and analyzing data from computing systems while keeping evidence admissible.
- Forensically sound acquisition and documentation
- Chain of custody from seizure to reporting
10. Mobile forensics
Extracting and interpreting data from mobile devices.
- Handling devices to preserve volatile data
- Tying device artifacts to timeline and attribution
11. Surveillance
Observation techniques and their legal and operational constraints.
- Documentation discipline and lawful conduct
12. Informants
Developing, managing and corroborating human sources.
- Reliability assessment and corroboration
- Protecting the source and the case
13. Case development and professional reporting
Turning findings into a coherent, prosecution-ready product.
- Clear, defensible reports that stand up to scrutiny
- SOPs and metric-driven reporting at the program level
Evidence and Reporting Rules to Know Cold
Because "forensically sound evidence" and "prosecution-ready reporting" are named learning outcomes, expect scenario reasoning to reward defensible process. A few principles to internalize, framed as reasoning habits rather than memorized trivia:
- Document before you act. If a step changes the evidence or its context, the record of why and how should exist first.
- Preserve volatile material early. Social media content, device state and online records can disappear; the earlier the capture, the stronger the case.
- Maintain an unbroken custody trail. Every transfer, access and storage point should be accounted for.
- Corroborate before you rely. Whether the input is an informant, an open-source post or a device artifact, independent confirmation strengthens the finding.
- Write for the reader who was not there. A prosecutor, supervisor or reviewing party should be able to follow your reasoning from the report alone.
- Stay inside lawful authority. Surveillance, collection and handling questions often hinge on whether the method is legally defensible, not merely effective.
Key Takeaway
When a scenario offers a fast technical shortcut and a slower defensible process, the defensible process is almost always the intended direction. Practice explaining why a step protects admissibility, not just that it does. You can drill this reasoning style on the CECI practice tests.
Numbers That Get Confused
This is the section to reread the night before. Each pair below mixes two figures that candidates routinely blur together.
| Figure | What it actually is | What it is not |
|---|---|---|
| USD 450 | Standalone exam fee | The cost of the full program |
| USD 2,497 | Self-paced program price | The exam fee |
| 100 hours | Instructional hours in the program | Exam length (that is three hours) |
| 100 CPE credits | Course credits awarded by the program | A renewal requirement |
| 43 modules | Program structure | Weighted exam domains or a question count |
| One-year license | Exam access window | Credential validity period |
| Six credentials | Bundle with CECI as capstone | Six CECI exam domains or identical exams |
| 70% | Published passing threshold | An observed pass rate |
That last row matters: a passing threshold is a rule, while a pass rate is an outcome statistic, and no verified pass rate is published. The CECI pass rate page explains how to treat pass-rate claims you encounter elsewhere, and CECI Exam Dates covers scheduling within your license window.
Sequencing the Areas Across Your Prep
You do not need a generic study philosophy here, just a sensible order that follows how the thirteen areas depend on each other. One workable arrangement over four weeks:
Foundations and collection
- Intelligence foundations first, because every later area assumes its vocabulary
- Open-source intelligence and social media intelligence, since both are collection methods built on the same sourcing discipline
Offense-specific investigations
- Cybercrime, fraud and organized retail crime, studied together to practice linking separate incidents into one case
- Counterintelligence alongside, to keep exposure risk in view
Technical evidence
- Electronic discovery, computer forensics and mobile forensics in sequence, centered on chain of custody and defensible handling
Human sources, surveillance, reporting
- Surveillance and informants, then case development and professional reporting last, because reporting synthesizes everything before it
- Finish with full timed scenario practice to rehearse the three-hour limit
The logic: reporting goes last because it consumes the outputs of every other area, and foundations go first because everything else leans on them. Adjust the weeks to your own background; a seasoned digital forensics examiner might compress Week 3 and spend longer on informants and surveillance, which are often the thinner areas for technical candidates.
Where the Credential Fits in Casework and Hiring
CECI targets multidisciplinary investigative casework, meaning the kind of work where a single case touches open-source research, digital evidence, human sources and formal reporting. The eligibility rules signal the intended audience: people with real experience in criminal investigations or intelligence, in law enforcement, criminal justice, the military or similar settings. That makes it relevant to investigators, analysts and program leads who need to show breadth across the investigative lifecycle, not just depth in one tool.
Because the fourth learning outcome covers building and leading cyber programs (SOPs, team structure, metric-driven reporting), the credential also speaks to supervisory and program-management roles. For a view of the job landscape, see CECI Jobs, and for the training pathway options, CECI Training. When you are ready to test yourself against realistic scenarios, start a session on the main practice site.
Frequently Asked Questions
The current public sources do not state a question count, a scored versus unscored split, or a confirmed item format. What is published is the delivery model: online proctored, three-hour limit, one attempt, and a 70% passing threshold. Treat any specific question count you see elsewhere as unverified.
No. The one-year exam license is an access period during which you can sit the exam. It is separate from certification validity, so do not read it as a renewal clock. Check the issuer's official pages for current credential terms.
No. The 43 modules describe the structure of the USD 2,497 self-paced program, which bundles six credentials with CECI as the capstone. They are not weighted exam domains, and the thirteen areas on this page are editorial preparation categories rather than an official blueprint.
The 100 CPE credits are course credits awarded by completing the program. They are not a renewal requirement, and they are not an exam question count or duration. Verify any current maintenance expectations directly with McAfee Institute.
Eligibility is experience-based: four years with a bachelor's degree or higher, six with an associate degree, or seven with a high-school diploma or equivalent, in criminal investigations or intelligence in investigations, law enforcement, criminal justice, the military or a similar field. Documentation and professional-conduct requirements also apply, so review the full requirements first.