CECI logo
Focused certification exam prep
Start practice

What Is CECI Certification?

TL;DR
  • CECI stands for Certified Expert in Cyber Investigations and is administered by McAfee Institute as a capstone credential.
  • The standalone exam costs USD 450: one attempt, online proctored, three-hour limit, one-year exam license.
  • The published passing threshold is 70%; eligibility requires degree-plus-experience combinations in investigations or intelligence work.
  • The USD 2,497 program has 43 modules and 100 instructional hours, but those modules are not weighted exam domains.

What CECI Actually Is

CECI stands for Certified Expert in Cyber Investigations. It is a professional credential for investigators who work cases where digital evidence, online activity, and traditional investigative tradecraft overlap. If you have searched the acronym and found several unrelated credentials sharing the same letters, note that this article covers only the McAfee Institute credential. For shorter definitions, see our explainers on what CECI stands for and the meaning of CECI.

What distinguishes CECI from a narrowly technical forensic certificate is its breadth. The credential is positioned as a capstone: it assumes you can move across intelligence collection, open-source research, financial and retail crime, electronic discovery, device forensics, surveillance, informant handling, and the discipline of turning all of that into a case a prosecutor or client can actually use. That multidisciplinary framing is the thing to understand first, because it shapes how you should prepare.

Capstone, not entry-level: CECI is built for people who already do or support investigative work. The eligibility rules reflect this, and the content assumes you can reason through a case rather than simply recall definitions. Preparation that treats it like a vocabulary quiz tends to miss the point.

Who Issues It and How the Program Is Packaged

McAfee Institute administers the certification. Candidates encounter it in two ways: as a standalone exam purchase, or as the final credential in a larger self-paced program. The program-versus-exam distinction trips up many candidates, so it is worth laying out plainly.

FeatureStandalone ExamSelf-Paced Program
PriceUSD 450USD 2,497
What you getThe proctored CECI examTraining, study manual, review quizzes, exam license, lifetime course access
InstructionNone included43 modules, 100 instructional hours
Course CPE creditsNot applicable100
Exam licenseOne yearOne year
AttemptsOneOne

The program bundles six credentials with CECI as the capstone. The other five are CFHI, CEFI, SMIA, CCIP, and CCTA. That bundling does not mean CECI has six exam domains or that the exams are identical; it simply describes how the training pathway is organized. For a cost-focused view, our CECI certification cost breakdown compares the paths in more detail.

Do not confuse these numbers: The 100 instructional hours and 100 course CPE credits describe the training program. They are not the exam length, not a question count, and not a renewal requirement. Likewise, the 43 modules are course units, not weighted exam domains.

Eligibility: Experience Comes First

CECI is not open to anyone who can pay the fee. Candidates must document relevant experience, and the required amount depends on education level:

  • Bachelor's degree or higher: four years of relevant experience
  • Associate degree: six years of relevant experience
  • High-school diploma or equivalent: seven years of relevant experience

The experience must involve criminal investigations or intelligence in investigations, and it can come from law enforcement, criminal justice, the military, or a similar field. Eligibility documentation and professional-conduct requirements apply, which means the credential involves a review step beyond simply sitting the exam. Details and edge cases are covered in our guide to CECI requirements and how to qualify.

Practically, this means you should gather your documentation before you commit to a study plan. A candidate who studies for months and then discovers their experience does not fit the stated categories has lost time. Confirm fit against the official issuer pages first.

Exam Mechanics: Fee, Format, and Licensing

Here is what is firmly established about the current standalone examination:

  • Fee: USD 450
  • Delivery: online, proctored
  • Time limit: three hours
  • Attempts: one
  • Exam license: one year
  • Passing threshold: 70%

Just as important is what is not verified. The current question count, the split between scored and unscored items, and the exact live item format have not been confirmed, so you should not assume a particular number of questions or a pure multiple-choice structure. Anyone claiming exact item counts or an observed pass rate is working from information we cannot verify. Our pages on the CECI passing score and pass rate data explain what can and cannot be said.

Key Takeaway

The one-year exam license is an access window for taking the exam, not a statement about how long your credential stays valid. With a single attempt, treat scheduling as a readiness decision rather than a formality. See CECI exam dates and scheduling for practical planning.

The single-attempt rule changes the risk calculation. Many certifications let you absorb a failed first try as a learning experience. Here, you should arrive having already tested your reasoning under timed conditions. You can do that with the CECI practice tests on our main site, which use original questions grounded in the published preparation scope.

The Four Published Learning Outcomes

The current public description of the program names four learning outcomes. They are the closest thing to an official statement of what the credential is meant to prove, so they deserve attention.

1. Advanced investigation methods

Covers investigative playbooks, attribution, threat modeling, and covert intelligence collection.

  • Know how structured playbooks make investigations repeatable
  • Understand the limits and risks of attribution claims
  • Be able to reason about threats before and during a case

2. Hands-on, real-world labs

Simulated cases and tools give learners practice applying techniques rather than only reading about them.

  • Expect scenario reasoning, not just terminology

3. Forensically sound evidence

Legally defensible handling, chain of custody, and prosecution-ready reporting.

  • Documentation discipline is as important as technical skill
  • Evidence that cannot be defended is evidence that may not be usable

4. Building and leading cyber programs

Standard operating procedures, team structure, and metric-driven reporting.

  • The credential reaches beyond casework into management of investigative capability

Notice the fourth outcome. Many candidates prepare only for the investigator's tasks and neglect the program-leadership angle. Given that the credential is a capstone, expect it to matter.

Thirteen Preparation Areas for CECI Candidates

The thirteen areas below are drawn from technical topics named in the current public CECI narrative. They are editorial preparation categories, not an official weighted blueprint and not the complete 43-module list. Official topic weights and exhaustive exam coverage remain unverified. The full breakdown lives in our guide to all 13 CECI content areas; here is a working orientation.

Intelligence and online research

Intelligence foundations

The conceptual base for everything else: how information becomes intelligence, how collection is planned, and how analysis supports decisions.

Open-source intelligence and online research

Systematic collection from publicly available sources, including how to document what you found and how you found it.

Social media intelligence

Investigating through social platforms, including attribution challenges, preservation of volatile content, and the legal boundaries around collection.

Crime-type investigations

Cybercrime investigations

Working cases where the offense is committed through or against digital systems.

Counterintelligence

Detecting and countering hostile collection efforts against an organization or operation.

Fraud investigations

Tracing deception-based financial loss, building the evidentiary trail, and presenting findings.

Organized retail crime

Coordinated theft and resale schemes, which often blend physical investigation with digital and financial tracing.

Evidence and technical analysis

Electronic discovery

Identifying, preserving, and producing electronically stored information in a defensible manner.

Computer forensics

Acquiring and examining data from computers while protecting integrity and chain of custody.

Mobile forensics

Extracting and interpreting data from mobile devices, with attention to the handling concerns unique to them.

Field methods and case delivery

Surveillance

Observation techniques and the legal and documentation considerations that come with them.

Informants

Developing, managing, and corroborating human sources while protecting the integrity of the case.

Case development and professional reporting

Pulling findings into a coherent, defensible case file and a report suited to prosecutors, clients, or leadership.

Why this spread matters: The areas run from tradecraft that predates computers (surveillance, informants) to purely digital disciplines (computer and mobile forensics, e-discovery). Most working investigators are strong in some and thin in others. Your preparation advantage comes from honestly identifying which half you are weaker in.

Who Benefits From This Credential

Because eligibility is tied to investigative or intelligence experience, the natural audience is people already in or adjacent to those roles. That includes law enforcement and criminal justice professionals, military personnel with investigative or intelligence backgrounds, and corporate or private-sector investigators in fraud, loss prevention, retail crime, and similar functions. The retail-crime and e-discovery areas in particular hint at relevance beyond government work.

Whether the credential improves your job prospects or pay depends heavily on your sector and existing experience, and we avoid quoting unverified figures. For a qualitative treatment, read CECI jobs, the CECI salary guide, and the worth-it analysis. A reasonable framing is that the credential signals breadth and a documented investigative foundation, which employers can weigh alongside your actual casework history.

Sequencing Your Preparation

Generic study habits matter less here than ordering the material sensibly. Because the exam appears to test reasoning across a wide span, a sequence that builds from foundations to case delivery works well. This is one illustrative arrangement, not an official plan; adjust it to your background.

Weeks 1-2

Foundations and collection

  • Intelligence foundations, so later topics have a framework to attach to
  • Open-source intelligence and social media intelligence, which share methods and legal concerns
Weeks 3-4

Offense types

  • Cybercrime, fraud, and organized retail crime, comparing how evidence differs across them
  • Counterintelligence as a contrasting, defensive mindset
Weeks 5-6

Digital evidence

  • Electronic discovery, computer forensics, and mobile forensics
  • Drill chain of custody and defensible handling until it is second nature
Week 7

Field methods

  • Surveillance and informants, focusing on corroboration and documentation
Week 8

Integration

  • Case development and professional reporting, then timed full-length practice under three-hour conditions

Place the digital evidence block after your offense-type review so the forensic handling rules have concrete cases to anchor to. Finish with case development because it integrates everything else; it is where weak spots in earlier areas show up. The full method is laid out in our CECI study guide, and if you want a compact refresher near exam day, use the CECI cheat sheet. To gauge difficulty honestly, see how hard the CECI exam is.

Key Takeaway

Preparation supplements, but does not replace, the official course, the experience eligibility review, the conduct requirements, and the proctored assessment itself. Use practice questions on the main site to rehearse case reasoning, and treat the issuer's own materials as the authority.

Frequently Asked Questions

What does CECI stand for?

CECI stands for Certified Expert in Cyber Investigations. It is the capstone credential administered by McAfee Institute and should not be confused with other credentials that happen to share the same acronym.

How much does the CECI exam cost?

The standalone exam is USD 450 and includes one attempt and a one-year exam license. The separate self-paced program is USD 2,497 and adds training, a study manual, review quizzes, and lifetime course access.

What score do I need to pass?

The current published passing threshold is 70%. An observed pass rate has not been verified, so any specific pass-rate figure you encounter should be treated with caution.

Who is eligible to sit the exam?

Candidates need a bachelor's degree plus four years of relevant experience, an associate degree plus six years, or a high-school diploma or equivalent plus seven years. The experience must involve criminal investigations or intelligence in investigations, and documentation and conduct requirements apply.

Does the one-year exam license mean the certification expires after a year?

No. The one-year license is the period during which you can access and use your exam attempt. It is separate from credential validity, and the 100 course CPE credits in the program are likewise not a renewal requirement.

Ready to pass your CECI exam?

Put this into practice with free CECI questions across every exam domain.