GFACT logo
Focused certification exam prep
Start practice

GFACT Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • GFACT has zero formal prerequisites - no degree, certification, or job title required to register.
  • A single attempt costs $399; retakes and extensions each run $199 if you need them.
  • You get 120 days from activation to sit the exam, proctored via ProctorU or Pearson VUE.
  • Passing requires 71% on 75 questions across nine domains within a 2-hour window.

Does GFACT Have Prerequisites?

No. GIAC lists no formal prerequisites for GFACT - no required degree, no prior certification, no minimum job title, and no mandated training course. This is unusual in a certification catalog where many credentials expect you to already hold a lower-tier badge or a certain number of years in the field. GFACT was designed by GIAC and SANS specifically to remove that barrier, positioning it as the entry point into the broader GIAC ecosystem rather than a gate that keeps people out.

That "no prerequisites" language is easy to misread as "no preparation needed." It doesn't mean the exam is trivial - it means eligibility is open, not that mastery is optional. If you want a full breakdown of exactly how demanding the material is once you sit down at the keyboard, our complete difficulty guide walks through what candidates actually encounter.

The Real Requirement Is Knowledge, Not Paperwork: GIAC doesn't check your resume before letting you register. Instead, the exam itself acts as the filter - 75 questions across nine technical domains, with a 71% passing score, decide whether you qualify.

Who Actually Qualifies for GFACT

Because there are no gatekeeping requirements, GIAC frames GFACT around who it's built for rather than who's allowed to take it. The certification is explicitly aimed at:

  • Career changers moving into cybersecurity from unrelated fields
  • Students building a technical foundation before graduation
  • New IT and cybersecurity hires who need baseline literacy fast
  • Business professionals who interact with security teams but aren't technical specialists
  • Self-driven learners studying independently, without an employer sponsoring training
  • Participants in re-skilling or workforce-transition programs

Employers use GFACT the same way GIAC markets it: as proof that someone understands the technical scaffolding of cybersecurity - hardware, operating systems, networking, basic scripting - before they're trusted with more specialized work. If you're wondering what kinds of roles actually list GFACT as a plus or requirement, see our dedicated rundown of GFACT jobs. GFACT also maps to DoD 8140 directives and NIST NICE work roles, which matters if you're targeting government, contractor, or military-adjacent IT positions where credential mapping affects hiring and job classification.

Key Takeaway

If you're unsure whether you're "qualified enough" to attempt GFACT, the honest answer is that GIAC doesn't require you to be anything in particular - it requires you to know the nine domains well enough to clear 71%.

Registration and Eligibility Mechanics

Eligibility for GFACT isn't about credentials - it's about understanding the logistics and fee structure so you don't get caught off guard. Here's what actually governs whether you can register, sit, and pass:

  • Attempt cost: A certification attempt is $399. Retakes are $199, attempt extensions are $199, and renewals are $199 - making GFACT one of the two cheapest certifications in the entire GIAC catalog alongside GISF.
  • Time window: Once your attempt is activated, you have 120 days to complete the exam.
  • Format: All GIAC exams, including GFACT, are web-based and must be proctored. You choose between remote proctoring through ProctorU or onsite proctoring through Pearson VUE.
  • Missed appointments: If you no-show or miss a proctored session, expect a $175 reseating fee plus a 7-day extension tacked onto your window.
  • Practice exams: GIAC sells an official practice exam for $189, though like all practice tools it draws from a limited question bank and never reuses actual exam questions.

For a line-by-line breakdown of every fee scenario - including what happens if you need multiple retakes or let your attempt lapse - read our complete pricing breakdown.

RequirementDetail
PrerequisitesNone - open enrollment for all candidates
Attempt fee$399 (first attempt)
Retake fee$199
Extension fee$199
Time to complete120 days from activation
Exam length75 questions, 2-hour limit
Passing score71%
Proctoring optionsProctorU (remote) or Pearson VUE (onsite)
Validity period4 years

Domain Readiness: What "Qualified" Really Means

Since GIAC won't stop you at registration, the real qualifying bar is domain competence. GFACT tests nine areas, and treating any one of them as optional is the most common reason candidates underperform. For the full scope of each domain, our complete guide to all 9 content areas goes deeper than the summary below, but here's what "ready" looks like domain by domain.

Domain 1: Computer Hardware & Virtualization

Candidates need working knowledge of core hardware components, how virtualization abstracts physical resources, and why that abstraction matters for security architecture.

  • CPU, memory, and storage fundamentals
  • Hypervisors and virtual machine isolation concepts

Domain 2: Exploitation & Mitigation

This domain expects familiarity with how common attacks work and the corresponding defensive controls - not deep offensive-security tradecraft, but enough to recognize attack patterns and mitigation logic.

  • Common vulnerability classes and attack vectors
  • Standard mitigation techniques and defense-in-depth reasoning

Domain 3: Forensics & Post-Exploitation

Expect questions on what happens after compromise - evidence handling, artifact awareness, and the basic logic of incident response.

  • Chain-of-custody and evidence integrity concepts
  • Recognizing indicators of compromise in logs and file activity

Domain 4: Linux Foundations

SEC275's hands-on labs lean heavily on Linux, and the exam reflects that. You need real command-line comfort, not just terminology recognition.

  • File permissions, navigation, and process management
  • Common command-line utilities and shell basics

Domain 5: Logic & Programming

You don't need to be a developer, but you must read and reason through basic code logic - loops, conditionals, variables - across common scripting concepts.

  • Control structures and basic algorithmic thinking
  • Interpreting short code snippets for expected output

Domain 6: Networking & Servers

A dense, high-value domain covering the OSI model, protocols, and how servers communicate - foundational to nearly every other security discipline.

  • TCP/IP fundamentals and common protocols
  • Server roles and client-server communication patterns

Domain 7: Operating Systems, The Web, & Data Storage

Broad coverage spanning OS fundamentals, how the web actually functions under the hood, and how data is stored and structured.

  • OS architecture and process/memory management basics
  • HTTP fundamentals and database/storage concepts

Domain 8: Security Concepts

The connective tissue domain - CIA triad, risk fundamentals, authentication and authorization principles that show up embedded in questions across every other domain too.

  • Core security principles and terminology
  • Risk, threat, and control vocabulary

Domain 9: Windows Foundations

The Windows counterpart to Domain 4 - registry basics, user account structures, and administrative fundamentals specific to the Windows environment.

  • Windows file system and permission models
  • Basic administrative tools and configuration concepts

Every one of the nine areas is drawn from GIAC's published Certification Objectives and Outcome Statements - nine official documents that define exactly what's testable. If you haven't reviewed them yet, they're the single most authoritative source of "what qualifies" beyond anything a study guide can tell you.

Exam Day Requirements and Proctoring Rules

Meeting the eligibility bar on paper is only half the requirement - you also need to satisfy GIAC's exam-day logistics. The exam is a single proctored session: 75 questions, a 2-hour time limit, and a minimum passing score of 71%, a threshold set through a psychometric standard-setting study applied to all versions released on or after July 24, 2021. That means the passing bar isn't an arbitrary round number - it reflects a deliberate difficulty calibration. Our exact breakdown of what you need to pass unpacks how that score translates into practical question-count math.

On proctoring specifics: you'll choose ProctorU for a remote session from your own space, or Pearson VUE for an onsite testing center. Both require ID verification and a controlled environment. Missing your scheduled appointment isn't a soft penalty - it costs a $175 reseating fee and only buys you a 7-day extension, so treat your scheduled time slot as fixed once it's booked. For a full look at how testing windows and scheduling deadlines work in practice, check our testing windows and scheduling guide.

Format Note: The GFACT exam itself is not CyberLive, meaning you won't be working in a live virtual lab environment during the test - even though SEC275's training curriculum is built around hands-on labs in Linux, encryption, and programming. Don't confuse the training format with the exam format.

Renewal Requirements After You Pass

Qualifying isn't a one-time event - GFACT certification is valid for four years, after which you must requalify. GIAC gives you two paths:

  • Accumulate 36 CPE credits within your active four-year window, then pay the $199 renewal fee.
  • Retake the current version of the exam if you'd rather requalify through testing than continuing education.

Work experience counts toward CPEs at a rate of 1 credit per month, capped at 12 CPEs per year - meaning experience alone can't fully cover the 36-credit requirement without stacking additional training or activities across the four years. One quirk worth planning around: renewed certifications extend four years from your current expiration date, not from the date you actually renew. GIAC also lists no grace period after expiration, so letting the clock run out without action means your credential simply lapses - there's no buffer window to scramble in.

Key Takeaway

Start logging CPE-eligible activity early in your four-year window rather than waiting until year three - work-experience credits are capped annually, so last-minute cramming for renewal credits doesn't work the way exam cramming might.

Scheduling Your Preparation Around the Requirements

Since there's no prerequisite course or gatekeeping step, your prep timeline is entirely self-directed - which means the requirements themselves (120-day window, 75 questions, nine domains) should shape your study calendar, not generic productivity advice. A practical way to sequence it:

Week 1-2

Foundational Domains

  • Computer Hardware & Virtualization and Security Concepts - these underpin terminology used everywhere else
  • Begin light Linux command-line practice for Domain 4
Week 3-4

Systems and Networking

  • Networking & Servers, Operating Systems/Web/Data Storage, and Windows Foundations
  • Pair reading with hands-on lab time, mirroring SEC275's lab-centric approach
Week 5-6

Applied and Adversarial Domains

  • Exploitation & Mitigation and Forensics & Post-Exploitation
  • Logic & Programming - practice reading short scripts, not just memorizing syntax
Week 7

Integration and Timed Practice

  • Full-length timed practice runs under the 2-hour, 75-question format
  • Revisit weak domains identified during practice

For a more detailed, domain-weighted study plan and first-attempt strategy, our complete study guide expands on this structure considerably. And if you want a quick reference to sanity-check terminology while you study, the one-page review of must-know facts is built for exactly that.

Still deciding if the investment makes sense for your career stage? Our ROI analysis and earnings analysis both dig into that question using only documented outcomes rather than speculation. And if you'd like a broader look at how other candidates have actually performed on exam day, what the pass-rate data shows is a useful companion read before you lock in a testing date.

Once you're ready to test your readiness under realistic conditions, head back to our GFACT practice test platform and run a timed set that mirrors the real 75-question, 2-hour structure. Practicing under the actual constraints - not just reading domain summaries - is the closest you can get to exam day without spending the $399 attempt fee. You can return to the homepage anytime to track your progress across all nine domains.

Frequently Asked Questions

Do I need any certification before attempting GFACT?

No. GFACT has no prerequisites of any kind - no prior certification, degree, or job experience is required to register or sit the exam.

Is SANS SEC275 training required to take the GFACT exam?

No. SEC275, authored by SANS CTO James Lyne, is the associated training course, but it's optional. You can self-study and still meet every eligibility requirement.

What happens if I don't pass within my 120-day window?

Your attempt expires. To try again, you'd need to pay for a retake at $199, which issues a new attempt subject to its own timing rules.

Can I qualify for GFACT with no IT background at all?

Yes - GIAC explicitly designed GFACT for career changers and re-skilling participants with no prior technical background, though you'll need to study all nine domains thoroughly to pass.

Does GFACT expire, and what's required to keep it active?

Yes, it's valid for four years. Renewal requires either 36 CPE credits plus a $199 fee, or retaking the current version of the exam, with no grace period after expiration.

Ready to pass your GFACT exam?

Put this into practice with free GFACT questions across every exam domain.