Red Hat Certified System Administrator Guide
·11 min read
What the RHCSA is, how the hands-on EX200 exam works, what it costs, how scoring and renewal work, and where it fits in Red Hat's 2026 certification tracks.
Continue readingCKS requires a current CKA, so the real question is whether the security specialisation pays off. Compare difficulty, cost, and career fit before deciding.

"CKA vs CKS" is, strictly speaking, a trick question. You cannot choose the Certified Kubernetes Security Specialist (CKS) instead of the Certified Kubernetes Administrator (CKA), because the Cloud Native Computing Foundation (CNCF) and the Linux Foundation require a current, non-expired CKA before you may even attempt the CKS. The two credentials are rungs on the same ladder, not forks in the road.
Short answer: everyone on this path takes the CKA first — that part is settled by the prerequisite rule. The real decision is whether to add the CKS afterwards, and when. Add it if your work (or target role) involves securing clusters, platform engineering with compliance obligations, or DevSecOps; skip or defer it if you administer clusters generally and security is someone else's remit. If you do want it, schedule it within a few months of passing the CKA, while your hands-on cluster fluency is still sharp and your CKA is far from expiry.
This article deals with that sequencing decision — whether and when the security add-on pays off. For a full walkthrough of either exam on its own, see the Certified Kubernetes Administrator guide and the Certified Kubernetes Security Specialist guide.
The CKA is the CNCF's core administration credential: a performance-based, online proctored exam in which you solve hands-on tasks in live Kubernetes clusters over two hours. Its domains cover troubleshooting (30%), cluster architecture, installation and configuration (25%), services and networking (20%), workloads and scheduling (15%), and storage (10%).
The CKS is a specialisation layered on top. It uses the same performance-based, two-hour format, but its six domains are entirely security-focused: minimising microservice vulnerabilities (20%), supply chain security (20%), monitoring, logging and runtime security (20%), cluster setup (15%), cluster hardening (15%), and system hardening (10%). It assumes you already know everything the CKA tests — that is precisely why the prerequisite exists.
A common confusion is worth clearing up: the Kubernetes and Cloud Native Security Associate (KCSA) is not a CKS prerequisite. The KCSA is an entry-level multiple-choice exam that can help you learn the security landscape, but the only gate in front of the CKS is a valid CKA.
| Factor | CKA | CKS |
|---|---|---|
| Role focus | Cluster administration and operations | Securing Kubernetes clusters and workloads |
| Prerequisites | None | Current, non-expired CKA |
| Format | Performance-based, live clusters, 2 hours | Performance-based, live clusters, 2 hours |
| Passing score | 66% | 67% |
| Cost (2026, exam only) | $445 USD | $445 USD |
| Difficulty | Intermediate; broad admin scope | Advanced; assumes CKA-level fluency plus security tooling |
| Best for | Platform, DevOps and ops engineers running clusters | DevSecOps, platform security, compliance-heavy environments |
| Validity | 2 years (certs earned since 1 April 2024) | 2 years |
| Renewal | Retake the current exam | Retake the current exam |
Both exams are based on Kubernetes v1.35 as of August 2026, are delivered remotely through the PSI Bridge secure browser, and include a 12-month eligibility window, one free retake and two sessions of the killer.sh exam simulator. Prices vary with taxes and region — confirm current figures on the Linux Foundation's certification pages.
Most candidates find the CKS the harder of the two, for a structural reason rather than a statistical one: it is cumulative. Nothing you learned for the CKA becomes irrelevant — the CKS assumes fast, confident cluster administration and then adds a layer of security-specific tooling and reasoning on top, with a marginally higher pass mark (67% versus 66%).
Concretely, the extra difficulty comes from three places:
None of this makes the CKS unreasonable. It makes it a specialist exam that rewards recent, hands-on CKA-level fluency — which feeds directly into the timing advice below. If you want a candid read on the base exam's difficulty first, see how hard the CKA exam really is.
Work through these in order; your first "yes" tells you most of what you need.
Since 1 April 2024, CNCF certifications are valid for two years, and renewal means retaking the current exam — there is no continuing-education route. This has a practical consequence for sequencing: the prerequisite is a current CKA, so the later you leave the CKS, the closer you sit to a deadline where an expired CKA would force a full CKA retake before you could even book the security exam.
The efficient pattern is therefore compact: pass the CKA, keep the momentum, and sit the CKS within roughly three to six months. Your cluster speed is at its peak, the exam environment and PSI Bridge proctoring are familiar, and both certifications' renewal dates land close enough together to plan around. Buying the exams as the Linux Foundation's CKA + CKAD + CKS bundle ($1,245 as of 2026, versus $1,335 separately) can also make sense if you intend to complete the ladder — though only commit to the bundle once you are sure the CKS fits your direction.
One caveat: do not book the CKS as a reflex. A rushed attempt on unfamiliar security material wastes the advantage of fresh CKA skills. Use the included killer.sh simulator sessions — and timed practice runs against the CKS domains — to check readiness honestly before scheduling. ExamPractice's CKS practice questions are a useful benchmark here: score yourself by domain, and treat a weak showing in cluster hardening or supply chain security as a signal to study further, not to memorise answers.
Can I sit the CKS without the CKA?
No. The Linux Foundation requires a current, non-expired CKA before you can attempt the CKS. There is no waiver and no alternative prerequisite.
Does the KCSA count towards the CKS?
No. The Kubernetes and Cloud Native Security Associate is a standalone entry-level exam. It can be useful preparation for the security concepts, but only the CKA unlocks CKS eligibility.
If my CKA expires, does my CKS expire too?
Each certification carries its own two-year validity from its own exam date. But note that renewing the CKS by retake again requires holding a current CKA, which is another argument for keeping the two close together on the calendar.
Is the CKS worth it if I only use managed Kubernetes (EKS, GKE, AKS)?
Managed services take over control-plane operations, but workload hardening, supply chain security, policies and runtime monitoring remain your responsibility — which is most of the CKS syllabus. The credential loses little relevance in managed environments.
There is no "better" between the CKA and CKS, because they answer different questions: the CKA establishes that you can run Kubernetes; the CKS establishes that you can secure it. The CKA is mandatory groundwork for everyone on this path. The CKS is a targeted investment that pays off clearly for security-adjacent roles and regulated environments, pays off modestly as general differentiation, and can be safely deferred by administrators with no security remit — provided they accept that deferring past their CKA's expiry raises the price of changing their mind. If you are mapping where both certs sit in a longer trajectory, the Kubernetes certification career path puts the whole ladder in role-by-role order.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
What the RHCSA is, how the hands-on EX200 exam works, what it costs, how scoring and renewal work, and where it fits in Red Hat's 2026 certification tracks.
Continue reading·11 min read
What the RHCE credential is in 2026: the Ansible-based EX294 exam, prerequisites, cost, renewal rules and the retitling under Red Hat's new track system.
Continue reading·7 min read
An honest look at RHCSA difficulty: why the hands-on EX200 format fails people who could pass on paper, who struggles most, and how failure actually works.
Continue reading