CECI logo
Focused certification exam prep
Start practice

What Is CECI?

TL;DR
  • CECI means Certified Expert in Cyber Investigations, the capstone credential administered by McAfee Institute.
  • The standalone exam costs USD 450, allows one attempt, is online proctored, and has a three-hour limit.
  • The published passing threshold is 70%; official topic weights and question counts remain unverified.
  • Eligibility requires degree-plus-experience combinations ranging from four to seven years in investigations or intelligence work.

What CECI Actually Is

CECI stands for Certified Expert in Cyber Investigations. It is a professional certification aimed at practitioners who conduct or support investigations where digital evidence, online activity, and traditional investigative tradecraft intersect. The credential is administered by McAfee Institute and is positioned as the capstone of a multi-credential program rather than a stand-alone technical specialty.

That framing matters. CECI is not a narrow tool certification and it is not a pure digital forensics credential. It reflects multidisciplinary casework: you may be asked to think about intelligence analysis, open-source research, fraud schemes, evidence handling, surveillance, informant management, and professional reporting within a single investigative picture. If you want the shorter definitional variants of this topic, see our pages on what CECI stands for and the meaning of CECI.

Identity check: Several unrelated credentials share the acronym "CECI." This site covers only the Certified Expert in Cyber Investigations credential from McAfee Institute. If a source quotes different exam fees, dates, or domain structures, it is probably describing a different certification.

The Issuer and the Capstone Structure

McAfee Institute administers the CECI capstone certification. The word "capstone" is deliberate: CECI sits at the top of a program that bundles six credentials in total. Alongside CECI, the program includes CFHI, CEFI, SMIA, CCIP, and CCTA. Completing the program is the route most candidates associate with CECI, though the standalone exam is also offered separately.

One point deserves emphasis because it is easy to get wrong. The presence of six bundled credentials does not mean the CECI exam has six domains, and it does not mean the credentials share identical examinations. Each credential in the bundle is its own thing; CECI is the capstone that ties the program together. Treating the bundle as an exam blueprint will misdirect your preparation.

For a broader overview of the credential as a whole, our CECI certification page and the what is CECI certification explainer cover complementary angles.

The Four Published Learning Outcomes

The issuer's current public narrative describes four learning outcomes. These are the clearest official statement of what the program is trying to produce in a candidate, so they are worth internalizing before you study any individual topic.

1. Advanced Investigation Methods

The program emphasizes structured, repeatable investigative thinking rather than ad hoc searching.

  • Investigative playbooks
  • Attribution
  • Threat modeling
  • Covert intelligence collection

2. Hands-On, Real-World Labs

Practical work is built around simulated cases and tools, so candidates practice applying concepts rather than only memorizing them.

  • Simulated cases
  • Investigative tooling in applied scenarios

3. Forensically Sound Evidence

Evidence has to survive scrutiny. This outcome centers on handling that is legally defensible and reporting that supports prosecution.

  • Legally defensible handling
  • Chain of custody
  • Prosecution-ready reporting

4. Building and Leading Cyber Programs

Beyond individual casework, the credential speaks to organizational capability.

  • Standard operating procedures (SOPs)
  • Team structure
  • Metric-driven reporting

Notice the range: from tactical collection and evidence handling to program leadership. A candidate who prepares only on the technical end will be underprepared for the management-oriented outcome, and vice versa.

Thirteen Preparation Areas Drawn From the Public Narrative

The thirteen headings below organize technical areas explicitly named in the current public CECI narrative. They are editorial preparation categories, not the program's complete 43-module list, and they are not official weighted exam domains. The public curriculum data does not expose module or lesson titles, so we do not invent them. For a deeper walk-through of each area, read our complete guide to the 13 CECI content areas.

#Preparation AreaWhat It Covers in Practice
1Intelligence foundationsCore intelligence concepts that frame how investigators think about collection, analysis, and attribution
2Open-source intelligence and online researchStructured discovery and verification of publicly available information
3Social media intelligenceCollecting and interpreting platform-based information relevant to a case
4Cybercrime investigationsInvestigating offenses carried out or enabled through digital systems
5CounterintelligenceRecognizing and countering hostile information-gathering activity
6Fraud investigationsExamining deceptive schemes and the evidence that proves them
7Organized retail crimeInvestigating coordinated theft and resale networks
8Electronic discoveryIdentifying, preserving, and producing electronically stored information
9Computer forensicsExamining computer systems and storage for evidentiary artifacts
10Mobile forensicsExamining mobile devices and their data as evidence sources
11SurveillanceObservation methods and their investigative and legal considerations
12InformantsDeveloping and managing human sources responsibly
13Case development and professional reportingAssembling findings into a defensible, readable case file
Why the caveat matters: Official topic weights and exhaustive exam coverage remain unverified. Do not assume that an area listed here earns an equal share of exam items, and do not assume the list is complete. Use these categories to structure your study, then rely on the official course materials for authoritative scope.

How the areas connect

The most useful way to study these areas is as a connected workflow rather than thirteen silos. A realistic case might begin with intelligence foundations and open-source research, branch into social media intelligence to identify a subject's online footprint, move through computer and mobile forensics to examine seized devices, rely on electronic discovery when data sits in enterprise systems, and finish with case development and professional reporting. Fraud investigations and organized retail crime provide domain-specific context in which those methods get applied. Surveillance and informants represent the human-intelligence side, and counterintelligence supplies the defensive mindset that runs underneath all of it.

Exam Mechanics: Format, Fee, Passing Threshold

Here is what is verified about the current standalone CECI examination, and just as importantly, what is not.

ItemVerified Detail
Standalone exam feeUSD 450
AttemptsOne attempt
DeliveryOnline proctored
Time limitThree hours
Exam licenseOne year (an access period, not credential validity)
Passing threshold70%
Question countNot verified
Scored versus unscored itemsNot verified
Exact live item formatNot verified
Observed pass rateNot verified

Because the question count and item format are unverified, you should not plan around an assumed number of questions or assume the exam is purely multiple choice. What you can plan around is the combination of a single attempt, a three-hour window, and a 70% threshold. The one-attempt rule is the strategic centerpiece: there is no built-in retake cushion, so readiness should be established before you begin the exam clock.

Our related pages go deeper on the numbers: the CECI passing score, what is and is not known about the pass rate, and how difficult the exam is. For full pricing context, see the CECI certification cost breakdown. Scheduling questions are covered in our CECI exam dates guide.

Key Takeaway

Treat the one-year exam license as a deadline for starting and finishing your attempt, not as proof that the credential lasts a year. License duration and certification validity are two different things.

Who Qualifies to Sit the Exam

CECI is not open to anyone with a credit card. Eligibility is experience-based, and the issuer offers three education-and-experience pathways:

  • Bachelor's degree or higher plus four years of relevant experience
  • Associate degree plus six years of relevant experience
  • High-school diploma or equivalent plus seven years of relevant experience

The experience must involve criminal investigations or intelligence in investigations, within law enforcement, criminal justice, the military, or a similar field. Eligibility documentation and professional-conduct requirements also apply, so expect to substantiate your background rather than simply self-attest. If you are unsure where your own history lands, our CECI requirements guide walks through the prerequisites in more detail.

Plan the paperwork early: Because documentation and conduct review are part of the process, gather employment verification, position descriptions, and education records before you pay for anything. Discovering an eligibility gap after purchase is an avoidable frustration.

The Self-Paced Program Versus the Standalone Exam

There are two ways candidates typically approach CECI, and they differ in cost and in what you receive.

FeatureStandalone ExamSelf-Paced Program
PriceUSD 450USD 2,497
Instructional contentNot included43 modules, 100 instructional hours
Study manual and review quizzesNot includedIncluded
Exam licenseOne yearOne year
Course accessNot applicableLifetime
Course CPE creditsNot applicable100
Credentials bundledCECI exam onlySix credentials, CECI as capstone

Two cautions. First, the 100 course CPE credits are course credits; they are not a renewal requirement for the credential. Second, the 43 modules and 100 instructional hours describe the training program, not the exam: they are not an exam question count, an exam duration, or weighted exam domains. Confusing program metrics with exam metrics is one of the most common errors candidates make.

If you are weighing whether the larger investment pays off, our ROI analysis and the broader CECI training overview can help frame the decision.

Where the Credential Fits in Casework and Hiring

The eligibility rules tell you who the credential is designed for: people already working in or adjacent to investigations and intelligence. That includes professionals in law enforcement, criminal justice, and the military, as well as practitioners in "similar" fields, such as corporate investigations, fraud and loss-prevention units, and intelligence-support roles. The thirteen preparation areas hint at the same audience: organized retail crime and fraud investigations are staples of corporate and retail investigative teams, while counterintelligence, surveillance, and informants point toward public-sector and security-oriented work.

We do not publish salary figures here because verified earnings data specific to CECI is not available, and invented numbers would mislead you. For a qualitative discussion of how the credential relates to compensation and roles, see the CECI salary guide and the CECI jobs page. The credential's fourth learning outcome, building and leading cyber programs through SOPs, team structure, and metric-driven reporting, also suggests relevance to people moving from hands-on casework into supervisory or program-management responsibilities.

Sequencing Your Preparation Around the Domains

Study methodology is secondary to knowing the material, but sequence does matter. Because the thirteen areas build on one another, a logical order reduces rework. The timeline below is an editorial suggestion, not an official schedule; adapt the pacing to your experience and available time.

Phase 1

Lay the intelligence groundwork

  • Intelligence foundations: the vocabulary and logic everything else relies on
  • Open-source intelligence and online research, then social media intelligence
Phase 2

Study the offense categories

  • Cybercrime investigations, fraud investigations, and organized retail crime
  • Counterintelligence as a defensive lens across all three
Phase 3

Master evidence-centric technical areas

  • Electronic discovery, computer forensics, and mobile forensics
  • Revisit chain of custody and defensible handling after each
Phase 4

Human collection and case assembly

  • Surveillance and informants, with attention to legal and procedural limits
  • Case development and professional reporting, tying every earlier area into one narrative

Placing case development and reporting last is intentional: it is where earlier material converges, so it works best as a synthesis exercise. For a full week-by-week approach and resource suggestions, see our CECI study guide, and for last-minute review, the CECI cheat sheet. When you want to test yourself with original scenario-style questions, our practice test platform is built around this published preparation scope.

Key Takeaway

Reason in cases, not flashcards. Every preparation area ultimately feeds a defensible case file, so practice asking: what was collected, how was it preserved, what does it prove, and how would I report it?

Common Misreadings to Avoid

  • "The 43 modules are the exam domains." They are the structure of the training program, not a weighted exam blueprint.
  • "Six bundled credentials means six exam sections." The bundle does not establish six CECI domains or identical examinations.
  • "100 CPE credits means I must renew with 100 credits." Course CPE credits are not a renewal requirement.
  • "The exam license is how long my credential lasts." It is a one-year access period for taking the exam.
  • "I can assume a multiple-choice, fixed-length test." Question count, scoring allocation, and live item format are unverified.
  • "Practice material replaces the official course." It does not. Preparation supplements the official course, experience eligibility, conduct review, and the proctored assessment.

For the official source of truth, consult McAfee Institute's pages directly: the CECI exam page and the CECI program page. Details such as fees and policies can change, so verify them before committing. If you arrived here searching for a short definition, our pages on what a CECI is and what CECI means offer quick answers, and our main practice test site is the place to turn preparation into measured readiness.

Frequently Asked Questions

What does CECI stand for?

CECI stands for Certified Expert in Cyber Investigations. It is a capstone certification administered by McAfee Institute, and it is distinct from other credentials that happen to share the same acronym.

How much does the CECI exam cost and how many attempts do I get?

The standalone exam costs USD 450 and allows one attempt. It is delivered online with proctoring, has a three-hour limit, and comes with a one-year exam license. The self-paced program, which includes training and the exam license, is priced separately at USD 2,497.

What score do I need to pass?

The current published passing threshold is 70%. The total number of questions, the split between scored and unscored items, and the exact item format are not verified, so avoid planning around an assumed count.

Who is eligible to take the CECI exam?

Candidates need a bachelor's degree or higher with four years of relevant experience, an associate degree with six years, or a high-school diploma or equivalent with seven years. The experience must involve criminal investigations or intelligence in investigations, such as in law enforcement, criminal justice, or the military. Documentation and professional-conduct requirements apply.

Does the one-year exam license mean the certification expires after a year?

No. The one-year exam license is the window during which you have access to take the exam. It is not the validity period of the credential, and the 100 course CPE credits from the program are not a renewal requirement.

Ready to pass your CECI exam?

Put this into practice with free CECI questions across every exam domain.