Exampractice
Cybersecurity

SSCP Certification Guide

Everything the ISC2 SSCP involves — its seven domains, the one-year experience requirement, the $249 exam, endorsement and renewal — in one guide.

Alexander Novak · 9 min read
Seven-part shield graphic representing the seven domains of the ISC2 SSCP certification being assembled at a security operations desk

The Systems Security Certified Practitioner (SSCP) is ISC2's hands-on, operational security certification. It validates that you can implement, monitor and administer IT infrastructure securely — the day-to-day work of security administrators, systems administrators with security duties, and junior security analysts. It requires just one year of cumulative paid work experience in its domains, costs $249 USD to sit (Americas pricing, as listed in 2026), and is examined through a computerised adaptive test of 100–125 questions in a maximum of two hours.

That combination — a respected certification body, a modest experience bar and a genuinely technical syllabus — makes the SSCP one of the more interesting early-career credentials in security. This guide covers what the certification is, who it suits, the seven domains, the exam itself, eligibility, costs, the full certification process and what it takes to keep the credential active. It deliberately stays out of three lanes covered elsewhere: how difficult the exam feels, how to structure your study, and how SSCP stacks up against other certifications.

What is the SSCP?

The SSCP is a vendor-neutral certification from ISC2, the membership body best known for the Certified Information Systems Security Professional (CISSP). Where CISSP certifies the ability to design and govern security programmes, the SSCP certifies the ability to operate them: configuring access controls, responding to incidents, monitoring for risk, applying cryptography correctly and keeping networks, systems and applications secure in practice.

The relationship between the two matters for understanding what SSCP is. ISC2 pitches CISSP at professionals with five years of experience and managerial breadth; SSCP asks for one year and stays operational and technical. It is a practitioner's credential in the literal sense — the "P" stands for Practitioner, and the exam outline reads like the job description of someone who touches production systems.

Passing the exam alone does not make you certified. Like all ISC2 credentials, SSCP is a membership-backed certification: after passing, you complete an endorsement process, agree to the ISC2 Code of Ethics, and maintain the credential through continuing education and an annual fee. That full lifecycle is covered step by step later in this guide.

Who is the SSCP designed for?

The SSCP fits people whose work is (or will shortly be) hands-on security operations. Typical profiles:

  • Systems and network administrators who have absorbed security responsibilities — hardening servers, managing accounts and permissions, reviewing logs — and want a credential that recognises that work.
  • Early-career security analysts in SOC or operations roles, monitoring, triaging and escalating incidents.
  • IT support professionals moving towards security, using the SSCP's one-year requirement as a realistic near-term target rather than a five-year aspiration.
  • Career changers with some IT exposure who can reach one year of qualifying experience — or who use the Associate of ISC2 route described below to sit the exam first.

A realistic picture: a systems administrator two years into their career spends mornings patching, reviewing access requests and checking backup jobs, and afternoons chasing alerts from the endpoint protection console. Almost everything in that day maps to an SSCP domain. That person doesn't need to learn a new job to pass the SSCP — they need to formalise, deepen and correctly name what they already do.

If your question is less "what is this certification?" and more "which security role does it lead to?", the SSCP career path article traces the roles it feeds and how it connects onwards to CISSP.

The seven SSCP domains

The current exam outline, effective 1 October 2025, organises the SSCP into seven domains. The weightings tell you where the exam concentrates:

#DomainWeight
1Security Concepts and Practices16%
2Access Controls15%
3Risk Identification, Monitoring and Analysis15%
4Incident Response and Recovery14%
5Cryptography9%
6Network and Communications Security16%
7Systems and Application Security15%

Read as a whole, the outline is strikingly balanced: six of the seven domains sit within two percentage points of each other, with only Cryptography noticeably lighter at 9%. There is no single make-or-break domain — you cannot afford a blind spot.

A brief interpretation of what each domain actually asks of you:

  • Security Concepts and Practices grounds everything else: core principles, ethics, security controls and the administrative practices that keep an operation defensible.
  • Access Controls covers how identities are established, authenticated and authorised — the mechanics of who gets to touch what, from provisioning to trust architectures.
  • Risk Identification, Monitoring and Analysis is the watching domain: assessing risk, running monitoring, and making sense of logs and alerts rather than drowning in them.
  • Incident Response and Recovery tests whether you can act when monitoring finds something — containment, escalation, forensic awareness, and recovery alongside business continuity support.
  • Cryptography is the smallest domain but a conceptual hurdle for many: applying encryption, hashing, PKI and secure protocols appropriately, not designing algorithms.
  • Network and Communications Security spans network attacks and countermeasures, secure network design and the protection of data in transit.
  • Systems and Application Security rounds out the practitioner picture: endpoint security, malware countermeasures, virtualisation and securing the systems users actually work on.

SSCP exam format: what you'll face at the test centre

Since 1 October 2025, the SSCP uses Computerised Adaptive Testing (CAT), replacing the older linear format of 125 fixed questions over three hours. The current exam:

  • 100–125 questions, adaptively selected as you answer
  • Maximum 2 hours
  • Passing standard of 700/1000, though CAT results are reported simply as pass/fail
  • Delivered at Pearson VUE test centres
  • Available in English, Japanese and Spanish

The adaptive format has one behavioural consequence worth knowing before exam day: you answer each question in sequence and cannot skip it or return to it later. The engine adjusts to your performance as you go. Two hours across up to 125 questions is a brisk pace, which is why timed practice features so heavily in most candidates' preparation.

How demanding the exam actually feels — and why candidates fail it — is its own topic, covered in how hard the SSCP exam is.

SSCP requirements: the one-year experience rule

Eligibility for the SSCP is refreshingly simple compared with ISC2's senior credentials:

  • One year of cumulative, paid work experience in one or more of the seven domains.

Note the word cumulative — the year doesn't have to be continuous or with one employer, and it doesn't require a "security" job title. Work in any of the seven domains counts, which is why administrators and support engineers with security duties often qualify without realising it.

No experience yet? The Associate of ISC2 route. You can sit and pass the SSCP exam before meeting the experience requirement. You then become an Associate of ISC2 and have time to earn the required experience while holding that status. This makes the SSCP genuinely accessible to students and career changers — you prove the knowledge now and complete the experience as your career starts.

Endorsement. Once you've passed and met the experience requirement, you must have your application endorsed within nine months of the exam. An endorser is an ISC2-certified professional in good standing who attests to your experience; if you don't know one, ISC2 itself can act as endorser with employment verification. ISC2 also audits a random selection of applications, so claimed experience needs to be real and documentable.

What does the SSCP cost?

The headline figure is modest by certification standards, but budget for the whole lifecycle:

ItemCost (USD, Americas, as listed 2026)
Exam fee$249
Rescheduling$50
Cancellation$100
RetakeFull exam price again
Annual maintenance fee (once certified)$135

Pricing and taxes vary by exam-administration location — EMEA is priced in euros and the UK in pounds — so confirm your region's fee on ISC2's exam pricing page before registering. There is no discounted retake: failing costs you another $249, which is a concrete argument for benchmarking your readiness honestly before booking. Study materials are the other budget line; costs there vary widely depending on whether you self-study or take formal training.

The certification process, step by step

  1. Confirm your eligibility. Map your work history against the seven domains. One cumulative year in any of them qualifies you; if you fall short, plan for the Associate of ISC2 route instead.
  2. Study the current exam outline. Make sure everything you use is aligned to the outline effective 1 October 2025 — older materials built for the 125-question linear exam may organise content differently.
  3. Register and book at Pearson VUE. Create your ISC2 account, agree to the examination terms, and schedule at a Pearson VUE test centre. Pay the $249 fee (or your regional equivalent).
  4. Prepare and benchmark. Work through the domains, then test yourself under realistic conditions. ExamPractice's ISC2 exam hub offers free sample questions, with fuller question sets and a timed practice-test simulation available to subscribers — use a full-length timed run to check you're ready before the booking, not after.
  5. Sit the exam. 100–125 adaptive questions, two-hour limit, no returning to previous questions. You'll receive a pass/fail result rather than a numeric score.
  6. Complete endorsement within nine months. Submit your endorsement application with an ISC2-certified endorser (or ISC2 acting as one), attesting your experience and agreeing to the Code of Ethics.
  7. Activate and maintain your membership. Once endorsed, pay the annual maintenance fee and you are a certified SSCP and ISC2 member.

For a structured study approach to step 4 — resources, sequencing and practice strategy — see how to prepare for the SSCP exam.

Keeping the SSCP: renewal and CPE requirements

The SSCP runs on a three-year certification cycle. To keep it active you need:

  • 60 Continuing Professional Education (CPE) credits per three-year cycle, of which at least 45 must be Group A (activities directly related to the domains).
  • The $135 USD annual maintenance fee, standard across ISC2's professional certifications.

CPEs come from the normal life of a working practitioner — training, conferences, webinars, professional contribution — so most active professionals accumulate them without heroics. A 90-day grace period follows the end of a cycle for submitting CPEs and paying the fee, but treating the deadline as real is the safer habit.

Where the SSCP sits in ISC2's ladder

ISC2's portfolio runs from the entry-level Certified in Cybersecurity (CC), through the SSCP, up to the five-years-experience CISSP and specialised credentials such as the Certified Cloud Security Professional (CCSP). The SSCP occupies the practitioner rung: more technical depth than CC, far less experience demanded than CISSP. How it compares with CISSP on level, requirements and role fit is settled in SSCP vs CISSP, and whether the credential justifies its cost for your situation is the subject of is SSCP worth it? — this guide stays descriptive. For the map of every ISC2 credential, see ISC2 certifications explained.

Frequently asked questions

Can I take the SSCP with no work experience at all?

Yes — you can sit the exam and, on passing, become an Associate of ISC2 while you earn the one year of qualifying experience. You aren't a certified SSCP until the experience and endorsement are complete.

Does the SSCP expire?

The credential runs in three-year cycles. It remains active as long as you earn 60 CPEs per cycle (at least 45 Group A) and pay the $135 annual maintenance fee.

Can I skip a question and come back to it during the exam?

No. The CAT format used since October 2025 presents questions one at a time; once you answer and move on, that question is closed.

What happens if I fail?

You can rebook and retake the exam at the full $249 fee. ISC2 sets waiting-period rules between attempts — check the current retake policy on isc2.org before rebooking, as the details are theirs to define.

Is the SSCP your next step?

If your work already lives in these seven domains — access controls, monitoring, incident handling, network and system security — the SSCP formalises it under one of the most recognised names in the industry, for a $249 exam and a one-year experience bar. Read the official outline, gauge yourself honestly against each domain, and let a timed practice run tell you how close you already are. If the outline reads like your job description, you may be nearer to certified than you think.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like