- ISFCE's current training page publishes ten preparation modules, not an officially weighted exam blueprint.
- The online exam component is at least 100 randomly generated multiple-choice questions in 60 minutes, no notes or internet allowed.
- Certification also requires three consecutive forensic practical investigations with written reports.
- Entry paths include issuer training, 18 months of verifiable experience, or a board-accepted digital-forensics credential - confirm specifics with ISFCE.
What CCE Training Actually Covers
"CCE training" for the Certified Computer Examiner credential refers specifically to the preparation path published by the International Society of Forensic Computer Examiners (ISFCE), the body that administers this certification. If you've landed here searching for training around a different "CCE" acronym, this article - and this site - is exclusively about the ISFCE-administered Certified Computer Examiner credential, not any other certification that happens to share the same three letters.
ISFCE's training page currently reproduces ten preparation modules that map to the forensic skill set a working examiner needs: imaging, file systems, operating-system artifacts, mobile and cloud evidence, and reporting/ethics. These modules are issuer-course preparation topics. Their count of ten does not, by itself, establish ten official weighted examination domains - it simply reflects how the current course is organized. For a breakdown of how those topics relate to what's actually tested, see the CCE Exam Domains 2026: Complete Guide to All 10 Content Areas.
The Ten ISFCE Training Modules
Below is the complete module order as currently published by ISFCE. Candidates preparing on their own, without the formal course, still use this list as a syllabus because it reflects the skills a practical investigation will test.
Domain 1: Introduction to Digital Forensics
Foundational vocabulary, chain of custody, evidence handling, and the role of a forensic examiner in legal and investigative contexts.
- Understand how evidentiary integrity is preserved from seizure through reporting
Domain 2: Forensic Imaging
Bit-for-bit acquisition methods, write-blocking, hashing, and verification - the procedural backbone of every subsequent analysis step.
- Be able to explain why imaging methodology is defensible under cross-examination
Domain 3: File Types and Structures
Recognizing file signatures, headers, and container formats independent of file extensions.
- Practice identifying files by hex signature, not just by name
Domain 4: File Systems - FAT, exFAT, Linux, UDF
Non-NTFS file system structures commonly encountered on removable media, legacy drives, and optical/Linux-based evidence.
- Know directory entry structures and allocation table behavior
Domain 5: NTFS File System
The Windows-native file system examiners encounter most - MFT records, timestamps, alternate data streams, and deleted-record recovery.
- Expect this to be heavily represented in any practical involving a Windows image
Domain 6: Windows Forensics
Registry artifacts, user activity reconstruction, prefetch, event logs, and other Windows-specific evidence sources.
- Pair registry knowledge with NTFS timestamp interpretation
Domain 7: macOS Forensics
APFS structures and macOS-specific artifact locations for examiners who may receive Apple hardware as evidence.
- Understand how macOS metadata differs from Windows equivalents
Domain 8: Mobile Forensics
Acquisition and analysis considerations unique to smartphones and tablets.
- Focus on how mobile evidence differs procedurally from disk imaging
Domain 9: Email & Cloud Forensics
Message store formats, header analysis, and the growing challenge of evidence that lives outside a single physical device.
- Know the limits of what can be examined without provider cooperation
Domain 10: Legal, Reporting & Ethics
Report writing, testimony preparation, and the ethical obligations tied directly to the certification's background-check and notarized work-statement requirements.
- This module underlies the written reports required for all three practical investigations
For a module-by-module study strategy rather than just a list of topics, review the CCE Study Guide 2026: How to Pass on Your First Attempt, which sequences these areas against the two-part exam format.
Eligibility Routes Before You Train
Before investing time in training materials, confirm which eligibility route applies to you - ISFCE's public pages describe more than one, and they are not fully consistent with each other. The certification page lists alternative entry routes through issuer or authorized training, 18 months of verifiable experience, or a board-accepted digital-forensics credential. Full Member status requires that 18-month experience window; Associate status is described as available without it. Separately, the linked Exam Process policy describes training or a digital-forensics degree, 18 months of experience, and 40 hours of documented self-study together as a bundled requirement.
Because these two public descriptions diverge, treat any eligibility summary - including this one - as a starting point, and confirm your specific path directly with ISFCE before registering. A full breakdown of the documentation involved (background check, ethics agreement, notarized independent-work statement, and board approval) is covered in CCE Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Key Takeaway
Don't assume a single "18 months or a degree" rule applies uniformly - ISFCE's own pages describe eligibility differently in two places. Email ISFCE directly before you commit to a training track.
How Training Maps to the Exam Structure
Training exists to prepare candidates for two very different kinds of assessment, and understanding the split changes how you should study.
- Online timed component: At least 100 randomly generated multiple-choice questions, completed in 60 minutes, under proctored conditions. The Evaluation Standards policy is explicit that this must be done without books, notes, outside assistance, internet access, or other materials. The policy also permits up to ten experimental questions that are excluded from scoring, so the exact scored-versus-unscored breakdown on any given attempt is not publicly verified.
- Practical investigations: Three consecutive forensic practical exercises, each requiring a written report. These are where the module content on imaging, file systems, and OS artifacts gets applied directly rather than recognized from a question bank.
Scoring is equally weighted across four components with an overall average of at least 80% required. ISFCE's published policy language is internally inconsistent at the 75% boundary - one statement reads "no score 75% or lower" and another reads "none below 75%" - and there is a separate rule removing candidates from the practical track below a 70% score. Candidates should verify exactly how retakes and boundary scores are treated before assuming either interpretation. See CCE Passing Score 2026: Exactly What You Need to Pass for a closer look at that discrepancy.
Also note that the online score carries a maximum 90-day validity window, and candidates who tested after training must register to begin certification within 90 days of that training. This is a registration/validity deadline, not the 60-minute sitting limit, and it's a separate concept from the overall practical-process duration, which is not independently verified. Review CCE Exam Dates 2026: Testing Windows, Deadlines & Scheduling before you schedule training around any particular window.
If you're trying to gauge how demanding this format actually is compared to other digital-forensics credentials, How Hard Is the CCE Exam? Complete Difficulty Guide 2026 walks through the online-plus-practical structure in more depth, and our practice test platform lets you rehearse the multiple-choice format under a comparable time limit before you sit the real thing.
Training Costs vs. Certification Fees
Training materials and the certification fees charged by ISFCE are two separate line items, and it's worth not conflating them when budgeting. The indexed ISFCE store lists the following certification-related fees:
| Item | Fee |
|---|---|
| Initial exam | $495 |
| Retake | $150 |
| Two-year recertification | $250 |
| Reinstatement | $250 |
ISFCE's public pricing does not state a member/non-member split for these amounts, so don't assume a discounted tier without confirming it directly. Training-course pricing itself sits outside these certification fees and varies by format. A fuller line-item breakdown, including how these fees interact with retake and recertification timing, is in CCE Certification Cost 2026: Complete Pricing Breakdown.
A Domain-Aligned Study Timeline
Generic study techniques only help if they're scheduled against the specific modules above. Here is one way to sequence preparation across the ten topics rather than studying them in the order they happen to appear.
Foundations and Imaging
- Domain 1: Introduction to Digital Forensics - terminology, custody, evidentiary handling
- Domain 2: Forensic Imaging - acquisition and hashing procedures
File-Level Structures
- Domain 3: File Types and Structures - signature-based identification
- Domain 4: FAT/exFAT/Linux/UDF - non-NTFS file systems
Windows Depth
- Domain 5: NTFS - because it underlies most Windows practical evidence
- Domain 6: Windows Forensics - registry and activity artifacts
Platform Breadth
- Domain 7: macOS Forensics
- Domain 8: Mobile Forensics
- Domain 9: Email & Cloud Forensics
Reporting and Practice Exams
- Domain 10: Legal, Reporting & Ethics - report structure and testimony readiness
- Full-length timed practice runs on our practice test platform to rehearse the 60-minute, no-notes format
Notice that weeks 3 and 5 carry the heaviest load deliberately - NTFS because it underpins the most commonly encountered Windows evidence, and reporting because the practical investigations are graded partly on written output, not just technical findings. For a deeper version of this sequencing logic, see the CCE Study Guide 2026.
Who Hires CCE-Trained Examiners
Because the credential requires both a knowledge exam and hands-on practical investigations, employers in law enforcement, litigation support, corporate incident response, and private forensic consulting tend to value it as evidence of applied skill, not just memorized theory. The practical-investigation requirement - three consecutive exercises with written reports - is specifically designed to demonstrate courtroom-ready reporting, which is a common requirement in roles that touch litigation or testimony.
If you're evaluating whether the time and fee investment translates into career value, CCE Jobs covers role types that commonly list this credential, and Is the CCE Certification Worth It? Complete ROI Analysis 2026 and CCE Salary Guide 2026: Complete Earnings Analysis address the broader return-on-investment question using only publicly disclosed figures.
Key Takeaway
Training that skips the practical-investigation component - i.e., only drilling multiple-choice questions - leaves a real gap, since certification explicitly requires three consecutive practicals with written reports, not just a passing score on the timed online portion.
Frequently Asked Questions
ISFCE's certification page lists issuer/authorized training as one eligibility route alongside verifiable experience or a board-accepted digital-forensics credential. Whether training is strictly required for your situation depends on which route you qualify under, so confirm directly with ISFCE rather than assuming one universal rule.
The ten published modules are built to support both. They cover imaging, file systems, and OS-specific artifacts that show up directly in the three required forensic practical investigations, not only in the 60-minute online component.
At least 100 randomly generated multiple-choice questions in 60 minutes, and the Evaluation Standards policy requires it be completed without books, notes, outside assistance, or internet access. Up to ten experimental questions may be excluded from scoring, so the precise scored total is not publicly confirmed.
Training-course pricing is separate from certification fees. The certification fees themselves, per the indexed ISFCE store, are $495 for the initial exam, $150 for a retake, $250 for two-year recertification, and $250 for reinstatement.
ISFCE's current training page lists ten preparation modules, covering areas from forensic imaging through legal reporting and ethics. This module count reflects course organization and does not by itself confirm an official weighted exam-domain count.