- The Plain Definition
- Who Issues the Credential
- What the CECI Covers
- The Four Published Learning Outcomes
- Why CECI Is Called a Capstone
- Exam Mechanics: Fee, Format and Passing Threshold
- Eligibility and Experience Rules
- Who Uses This Credential
- Sequencing Your Preparation
- What a CECI Is Not
- Frequently Asked Questions
- CECI stands for Certified Expert in Cyber Investigations, a capstone credential administered by McAfee Institute.
- The standalone exam costs USD 450, allows one attempt, runs online proctored with a three-hour limit, and requires 70% to pass.
- Eligibility is experience-based: four, six, or seven years depending on education, all in investigations or intelligence-related work.
- The USD 2,497 program bundles six credentials, 43 modules, and 100 instructional hours, but those are not exam domains.
The Plain Definition
A CECI is a Certified Expert in Cyber Investigations: a professional who has completed the McAfee Institute's capstone certification pathway in cyber investigations and passed its proctored exam. The term refers to both the credential and the person who holds it. If you see "CECI" on a resume, an email signature, or a job posting for an investigator or intelligence analyst, this is the credential in question.
The acronym is shared by other, unrelated credentials in other fields, so it pays to be precise. Everything on this page concerns the cyber investigations certification only. If you are comparing definitions, our companion pages on what CECI stands for and the meaning of CECI cover the naming question from other angles, and the broader overview lives at What Is CECI Certification?
Who Issues the Credential
The CECI is administered by McAfee Institute, a training and certification organization that serves investigators, intelligence professionals, and others working in law enforcement, corporate security, and related fields. The institute publishes the course, the exam, and the eligibility rules. This site, CECI Exam Prep, is an independent preparation resource and does not replace the official course, the experience requirements, the conduct review, or the proctored assessment.
The official product pages are the authority for anything that can change, such as pricing and exam logistics. The facts in this article were checked against the issuer's public pages on September 30, 2026, and you should confirm current details there before you register.
What the CECI Covers
The CECI is deliberately multidisciplinary. Rather than testing one narrow technical specialty, the issuer's public curriculum narrative spans intelligence tradecraft, online research, digital forensics, financial and retail crime, legal process, and case reporting. We organize those areas into thirteen editorial preparation categories. They are our groupings of the technical areas the public narrative names, not an official weighted blueprint and not the full list of 43 course modules.
The thirteen preparation categories
Domains 1 to 3: Intelligence Foundations, Open-Source Intelligence, and Social Media Intelligence
These categories cover how an investigator frames a question, collects information, and evaluates what comes back.
- Intelligence foundations: the logic of collection, analysis, and attribution, plus threat modeling.
- Open-source intelligence and online research: structured searching, source evaluation, and documenting what you found and how.
- Social media intelligence: working with platform-based information while keeping collection defensible.
Domains 4 to 7: Cybercrime, Counterintelligence, Fraud, and Organized Retail Crime
These categories are about the offenses and adversary behaviors an investigator is expected to recognize and work.
- Cybercrime investigations: how online offenses are structured and traced.
- Counterintelligence: recognizing and countering hostile collection against an organization.
- Fraud investigations: following money, records, and representations.
- Organized retail crime: coordinated theft and resale operations as a case type.
Domains 8 to 10: Electronic Discovery, Computer Forensics, and Mobile Forensics
These categories center on digital evidence and the rules that make it usable.
- Electronic discovery: identifying, preserving, and producing electronically stored information.
- Computer forensics: acquiring and examining evidence from computer systems in a forensically sound way.
- Mobile forensics: the same discipline applied to phones and similar devices.
Domains 11 to 13: Surveillance, Informants, and Case Development and Professional Reporting
These categories cover field methods and the work product that results from them.
- Surveillance: planning and documenting observation lawfully and usefully.
- Informants: sourcing, handling, and corroboration concerns.
- Case development and professional reporting: assembling findings into prosecution-ready, defensible reports.
The Four Published Learning Outcomes
The issuer's public narrative states four learning outcomes. They are the clearest signal of what the credential is meant to certify, so it is worth knowing them closely.
- Advanced investigation methods. This includes investigative playbooks, attribution, threat modeling, and covert intelligence collection.
- Hands-on, real-world labs. Learners work simulated cases and tools rather than only reading about them.
- Forensically sound evidence. This means legally defensible handling, chain of custody, and prosecution-ready reporting.
- Building and leading cyber programs. This covers standard operating procedures, team structure, and metric-driven reporting.
Notice the range. Two of the four outcomes are about doing investigations (methods and evidence), one is about practice through labs, and one is about management of an investigative function. A candidate who has only ever worked as a hands-on analyst may find the program-building outcome the least familiar, while a supervisor may need to refresh the evidence-handling details.
Why CECI Is Called a Capstone
The CECI is the capstone credential in a McAfee Institute program that bundles six credentials: CFHI, CEFI, SMIA, CCIP, CCTA, and CECI itself. Completing the lower-level credentials and the program content builds toward the capstone. The program is self-paced, with 43 modules and 100 instructional hours, and it awards 100 course CPE credits.
There is an easy mistake to make here, and the table below separates the numbers that people tend to conflate.
| Figure | What it describes | What it is NOT |
|---|---|---|
| 6 credentials | The bundle in the full program, with CECI as capstone | Six exam domains or six identical exams |
| 43 modules | Course content in the self-paced program | A count of exam questions or weighted domains |
| 100 instructional hours | Length of the training program | The exam duration (the exam has a three-hour limit) |
| 100 course CPE credits | Credits awarded for completing the course | A renewal requirement for the credential |
| One-year exam license | The window in which you may sit the exam | The validity period of the certification itself |
Our thirteen categories above are an editorial map of the technical subject matter, and they do not correspond to the 43 modules. The public module and lesson listings were not available to us, so we do not list module titles.
Exam Mechanics: Fee, Format and Passing Threshold
Here is what is published about the standalone CECI exam.
- Fee: USD 450 for the standalone exam.
- Attempts: one attempt.
- Delivery: online proctored.
- Time limit: three hours.
- Access period: a one-year exam license.
- Passing threshold: 70%.
Equally important is what is not published. We could not verify the current question count, how many items are scored versus unscored, or the exact live item format, so we do not state them. We also have no verified pass rate, and you should be skeptical of any site that quotes one. For a fuller treatment of the numbers that are known, see CECI Passing Score and CECI Pass Rate: What the Data Shows.
Key Takeaway
With a single attempt and a one-year exam license, you should schedule deliberately and not treat the first sitting as a practice run. Complete your preparation across all thirteen areas, and use realistic scenario questions, before you begin your attempt. You can practice case reasoning on our CECI practice test.
Standalone exam versus full program
You can pursue the credential in two ways. The standalone exam costs USD 450. The self-paced program costs USD 2,497 and includes the training, a study manual, review quizzes, a one-year exam license, and lifetime course access. Which route suits you depends on whether you already have the underlying knowledge. A candidate with years of casework behind them may be comfortable with the exam alone, while someone crossing from a neighboring specialty may value the structured course. Our CECI certification cost breakdown compares the two paths in detail, and CECI exam dates and scheduling explains how the access window works in practice.
Eligibility and Experience Rules
The CECI is not open to everyone who can pay the fee. Eligibility combines education with years of relevant experience:
| Education | Required experience |
|---|---|
| Bachelor's degree or higher | Four years |
| Associate degree | Six years |
| High-school diploma or equivalent | Seven years |
The experience must involve criminal investigations or intelligence in investigations, in law enforcement, criminal justice, the military, or a similar field. Candidates must also supply eligibility documentation and meet professional-conduct requirements. In other words, the credential signals both knowledge and a track record. Read the full breakdown in CECI Requirements: Eligibility, Prerequisites and How to Qualify before you spend money on preparation.
Who Uses This Credential
Because the experience prerequisite is rooted in investigations and intelligence, the typical CECI holder comes from or works alongside:
- Law enforcement and criminal justice, including investigators who handle digital evidence and online-enabled crime.
- Military and government intelligence functions where investigative and analytic tradecraft matter.
- Corporate security and investigations teams handling fraud, organized retail crime, insider issues, and counterintelligence concerns.
- Legal and compliance support roles that touch electronic discovery and defensible evidence handling.
The breadth of the thirteen categories explains why. A fraud investigator, a retail loss-prevention investigator, and a digital forensics practitioner can all find their work reflected in the material. For a view of the roles that reference it, see CECI jobs. We avoid quoting salary figures here because we have no verified numbers to offer; the qualitative picture is in our CECI salary guide, and the return-on-investment question is addressed in Is the CECI Certification Worth It?
Sequencing Your Preparation
Generic study advice matters less here than the order in which you tackle the subject matter. Because the thirteen areas are interconnected, a sensible sequence builds foundations first, then the offense-specific and digital-evidence material, then the reporting skills that tie everything together.
Foundations and Collection
- Intelligence foundations, open-source intelligence, and social media intelligence.
- Practice documenting how you collected each finding, since reporting rewards it later.
Offense Types
- Cybercrime, counterintelligence, fraud, and organized retail crime.
- Compare how each case type differs in evidence sources and investigative priorities.
Digital Evidence
- Electronic discovery, computer forensics, and mobile forensics.
- Rehearse chain of custody and preservation reasoning until it is automatic.
Field Methods and Reporting
- Surveillance, informants, and case development with professional reporting.
- Finish with full-length scenario review under a three-hour time budget.
That eight-week outline is only a template; compress or stretch it to fit your existing strengths. A forensics examiner can shorten weeks 5 and 6 and spend longer on informants and surveillance, while a field investigator may do the reverse. For a complete plan, see the CECI study guide, the one-page CECI cheat sheet, and our overview of CECI training options. If you are wondering about difficulty, How Hard Is the CECI Exam? discusses what makes it demanding.
What a CECI Is Not
- Not a single-subject certification. It spans intelligence, forensics, fraud, retail crime, discovery, and reporting.
- Not a replacement for experience. The eligibility rules require years of investigative or intelligence work.
- Not defined by the course hours. The 100 instructional hours and 100 CPE credits describe training, not exam length or renewal duties.
- Not a guarantee of a particular exam format. Current item count and format are unverified, so prepare for scenario-based reasoning and not memorized lists.
- Not the same as the other certifications that share the acronym. Always confirm you are reading about Certified Expert in Cyber Investigations.
Our broader pages, CECI Certification, What Is CECI?, What Does CECI Mean?, and What Is A CECI?, approach the same core definition with slightly different emphasis, so use whichever matches the question you are trying to answer.
Frequently Asked Questions
It stands for Certified Expert in Cyber Investigations. The credential is administered by McAfee Institute and serves as the capstone of a program that bundles six credentials.
The standalone exam costs USD 450 and allows one attempt. The separate self-paced program costs USD 2,497 and includes training, a study manual, review quizzes, a one-year exam license, and lifetime course access.
The current published passing threshold is 70%. The question count and exact item format are not verified, and we have no verified pass rate to share.
Yes. You need a bachelor's degree plus four years, an associate degree plus six years, or a high-school diploma plus seven years of relevant investigative or intelligence experience, along with documentation and conduct requirements.
No. The 43 modules describe the self-paced course. Official exam topic weights are unverified, and the thirteen headings used here are editorial preparation categories, not a published blueprint.