- What CECI Actually Is
- The Issuer and the Capstone Structure
- The Four Published Learning Outcomes
- Thirteen Preparation Areas Drawn From the Public Narrative
- Exam Mechanics: Format, Fee, Passing Threshold
- Who Qualifies to Sit the Exam
- The Self-Paced Program Versus the Standalone Exam
- Where the Credential Fits in Casework and Hiring
- Sequencing Your Preparation Around the Domains
- Common Misreadings to Avoid
- Frequently Asked Questions
- CECI means Certified Expert in Cyber Investigations, the capstone credential administered by McAfee Institute.
- The standalone exam costs USD 450, allows one attempt, is online proctored, and has a three-hour limit.
- The published passing threshold is 70%; official topic weights and question counts remain unverified.
- Eligibility requires degree-plus-experience combinations ranging from four to seven years in investigations or intelligence work.
What CECI Actually Is
CECI stands for Certified Expert in Cyber Investigations. It is a professional certification aimed at practitioners who conduct or support investigations where digital evidence, online activity, and traditional investigative tradecraft intersect. The credential is administered by McAfee Institute and is positioned as the capstone of a multi-credential program rather than a stand-alone technical specialty.
That framing matters. CECI is not a narrow tool certification and it is not a pure digital forensics credential. It reflects multidisciplinary casework: you may be asked to think about intelligence analysis, open-source research, fraud schemes, evidence handling, surveillance, informant management, and professional reporting within a single investigative picture. If you want the shorter definitional variants of this topic, see our pages on what CECI stands for and the meaning of CECI.
The Issuer and the Capstone Structure
McAfee Institute administers the CECI capstone certification. The word "capstone" is deliberate: CECI sits at the top of a program that bundles six credentials in total. Alongside CECI, the program includes CFHI, CEFI, SMIA, CCIP, and CCTA. Completing the program is the route most candidates associate with CECI, though the standalone exam is also offered separately.
One point deserves emphasis because it is easy to get wrong. The presence of six bundled credentials does not mean the CECI exam has six domains, and it does not mean the credentials share identical examinations. Each credential in the bundle is its own thing; CECI is the capstone that ties the program together. Treating the bundle as an exam blueprint will misdirect your preparation.
For a broader overview of the credential as a whole, our CECI certification page and the what is CECI certification explainer cover complementary angles.
The Four Published Learning Outcomes
The issuer's current public narrative describes four learning outcomes. These are the clearest official statement of what the program is trying to produce in a candidate, so they are worth internalizing before you study any individual topic.
1. Advanced Investigation Methods
The program emphasizes structured, repeatable investigative thinking rather than ad hoc searching.
- Investigative playbooks
- Attribution
- Threat modeling
- Covert intelligence collection
2. Hands-On, Real-World Labs
Practical work is built around simulated cases and tools, so candidates practice applying concepts rather than only memorizing them.
- Simulated cases
- Investigative tooling in applied scenarios
3. Forensically Sound Evidence
Evidence has to survive scrutiny. This outcome centers on handling that is legally defensible and reporting that supports prosecution.
- Legally defensible handling
- Chain of custody
- Prosecution-ready reporting
4. Building and Leading Cyber Programs
Beyond individual casework, the credential speaks to organizational capability.
- Standard operating procedures (SOPs)
- Team structure
- Metric-driven reporting
Notice the range: from tactical collection and evidence handling to program leadership. A candidate who prepares only on the technical end will be underprepared for the management-oriented outcome, and vice versa.
Thirteen Preparation Areas Drawn From the Public Narrative
The thirteen headings below organize technical areas explicitly named in the current public CECI narrative. They are editorial preparation categories, not the program's complete 43-module list, and they are not official weighted exam domains. The public curriculum data does not expose module or lesson titles, so we do not invent them. For a deeper walk-through of each area, read our complete guide to the 13 CECI content areas.
| # | Preparation Area | What It Covers in Practice |
|---|---|---|
| 1 | Intelligence foundations | Core intelligence concepts that frame how investigators think about collection, analysis, and attribution |
| 2 | Open-source intelligence and online research | Structured discovery and verification of publicly available information |
| 3 | Social media intelligence | Collecting and interpreting platform-based information relevant to a case |
| 4 | Cybercrime investigations | Investigating offenses carried out or enabled through digital systems |
| 5 | Counterintelligence | Recognizing and countering hostile information-gathering activity |
| 6 | Fraud investigations | Examining deceptive schemes and the evidence that proves them |
| 7 | Organized retail crime | Investigating coordinated theft and resale networks |
| 8 | Electronic discovery | Identifying, preserving, and producing electronically stored information |
| 9 | Computer forensics | Examining computer systems and storage for evidentiary artifacts |
| 10 | Mobile forensics | Examining mobile devices and their data as evidence sources |
| 11 | Surveillance | Observation methods and their investigative and legal considerations |
| 12 | Informants | Developing and managing human sources responsibly |
| 13 | Case development and professional reporting | Assembling findings into a defensible, readable case file |
How the areas connect
The most useful way to study these areas is as a connected workflow rather than thirteen silos. A realistic case might begin with intelligence foundations and open-source research, branch into social media intelligence to identify a subject's online footprint, move through computer and mobile forensics to examine seized devices, rely on electronic discovery when data sits in enterprise systems, and finish with case development and professional reporting. Fraud investigations and organized retail crime provide domain-specific context in which those methods get applied. Surveillance and informants represent the human-intelligence side, and counterintelligence supplies the defensive mindset that runs underneath all of it.
Exam Mechanics: Format, Fee, Passing Threshold
Here is what is verified about the current standalone CECI examination, and just as importantly, what is not.
| Item | Verified Detail |
|---|---|
| Standalone exam fee | USD 450 |
| Attempts | One attempt |
| Delivery | Online proctored |
| Time limit | Three hours |
| Exam license | One year (an access period, not credential validity) |
| Passing threshold | 70% |
| Question count | Not verified |
| Scored versus unscored items | Not verified |
| Exact live item format | Not verified |
| Observed pass rate | Not verified |
Because the question count and item format are unverified, you should not plan around an assumed number of questions or assume the exam is purely multiple choice. What you can plan around is the combination of a single attempt, a three-hour window, and a 70% threshold. The one-attempt rule is the strategic centerpiece: there is no built-in retake cushion, so readiness should be established before you begin the exam clock.
Our related pages go deeper on the numbers: the CECI passing score, what is and is not known about the pass rate, and how difficult the exam is. For full pricing context, see the CECI certification cost breakdown. Scheduling questions are covered in our CECI exam dates guide.
Key Takeaway
Treat the one-year exam license as a deadline for starting and finishing your attempt, not as proof that the credential lasts a year. License duration and certification validity are two different things.
Who Qualifies to Sit the Exam
CECI is not open to anyone with a credit card. Eligibility is experience-based, and the issuer offers three education-and-experience pathways:
- Bachelor's degree or higher plus four years of relevant experience
- Associate degree plus six years of relevant experience
- High-school diploma or equivalent plus seven years of relevant experience
The experience must involve criminal investigations or intelligence in investigations, within law enforcement, criminal justice, the military, or a similar field. Eligibility documentation and professional-conduct requirements also apply, so expect to substantiate your background rather than simply self-attest. If you are unsure where your own history lands, our CECI requirements guide walks through the prerequisites in more detail.
The Self-Paced Program Versus the Standalone Exam
There are two ways candidates typically approach CECI, and they differ in cost and in what you receive.
| Feature | Standalone Exam | Self-Paced Program |
|---|---|---|
| Price | USD 450 | USD 2,497 |
| Instructional content | Not included | 43 modules, 100 instructional hours |
| Study manual and review quizzes | Not included | Included |
| Exam license | One year | One year |
| Course access | Not applicable | Lifetime |
| Course CPE credits | Not applicable | 100 |
| Credentials bundled | CECI exam only | Six credentials, CECI as capstone |
Two cautions. First, the 100 course CPE credits are course credits; they are not a renewal requirement for the credential. Second, the 43 modules and 100 instructional hours describe the training program, not the exam: they are not an exam question count, an exam duration, or weighted exam domains. Confusing program metrics with exam metrics is one of the most common errors candidates make.
If you are weighing whether the larger investment pays off, our ROI analysis and the broader CECI training overview can help frame the decision.
Where the Credential Fits in Casework and Hiring
The eligibility rules tell you who the credential is designed for: people already working in or adjacent to investigations and intelligence. That includes professionals in law enforcement, criminal justice, and the military, as well as practitioners in "similar" fields, such as corporate investigations, fraud and loss-prevention units, and intelligence-support roles. The thirteen preparation areas hint at the same audience: organized retail crime and fraud investigations are staples of corporate and retail investigative teams, while counterintelligence, surveillance, and informants point toward public-sector and security-oriented work.
We do not publish salary figures here because verified earnings data specific to CECI is not available, and invented numbers would mislead you. For a qualitative discussion of how the credential relates to compensation and roles, see the CECI salary guide and the CECI jobs page. The credential's fourth learning outcome, building and leading cyber programs through SOPs, team structure, and metric-driven reporting, also suggests relevance to people moving from hands-on casework into supervisory or program-management responsibilities.
Sequencing Your Preparation Around the Domains
Study methodology is secondary to knowing the material, but sequence does matter. Because the thirteen areas build on one another, a logical order reduces rework. The timeline below is an editorial suggestion, not an official schedule; adapt the pacing to your experience and available time.
Lay the intelligence groundwork
- Intelligence foundations: the vocabulary and logic everything else relies on
- Open-source intelligence and online research, then social media intelligence
Study the offense categories
- Cybercrime investigations, fraud investigations, and organized retail crime
- Counterintelligence as a defensive lens across all three
Master evidence-centric technical areas
- Electronic discovery, computer forensics, and mobile forensics
- Revisit chain of custody and defensible handling after each
Human collection and case assembly
- Surveillance and informants, with attention to legal and procedural limits
- Case development and professional reporting, tying every earlier area into one narrative
Placing case development and reporting last is intentional: it is where earlier material converges, so it works best as a synthesis exercise. For a full week-by-week approach and resource suggestions, see our CECI study guide, and for last-minute review, the CECI cheat sheet. When you want to test yourself with original scenario-style questions, our practice test platform is built around this published preparation scope.
Key Takeaway
Reason in cases, not flashcards. Every preparation area ultimately feeds a defensible case file, so practice asking: what was collected, how was it preserved, what does it prove, and how would I report it?
Common Misreadings to Avoid
- "The 43 modules are the exam domains." They are the structure of the training program, not a weighted exam blueprint.
- "Six bundled credentials means six exam sections." The bundle does not establish six CECI domains or identical examinations.
- "100 CPE credits means I must renew with 100 credits." Course CPE credits are not a renewal requirement.
- "The exam license is how long my credential lasts." It is a one-year access period for taking the exam.
- "I can assume a multiple-choice, fixed-length test." Question count, scoring allocation, and live item format are unverified.
- "Practice material replaces the official course." It does not. Preparation supplements the official course, experience eligibility, conduct review, and the proctored assessment.
For the official source of truth, consult McAfee Institute's pages directly: the CECI exam page and the CECI program page. Details such as fees and policies can change, so verify them before committing. If you arrived here searching for a short definition, our pages on what a CECI is and what CECI means offer quick answers, and our main practice test site is the place to turn preparation into measured readiness.
Frequently Asked Questions
CECI stands for Certified Expert in Cyber Investigations. It is a capstone certification administered by McAfee Institute, and it is distinct from other credentials that happen to share the same acronym.
The standalone exam costs USD 450 and allows one attempt. It is delivered online with proctoring, has a three-hour limit, and comes with a one-year exam license. The self-paced program, which includes training and the exam license, is priced separately at USD 2,497.
The current published passing threshold is 70%. The total number of questions, the split between scored and unscored items, and the exact item format are not verified, so avoid planning around an assumed count.
Candidates need a bachelor's degree or higher with four years of relevant experience, an associate degree with six years, or a high-school diploma or equivalent with seven years. The experience must involve criminal investigations or intelligence in investigations, such as in law enforcement, criminal justice, or the military. Documentation and professional-conduct requirements apply.
No. The one-year exam license is the window during which you have access to take the exam. It is not the validity period of the credential, and the 100 course CPE credits from the program are not a renewal requirement.