Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about ISC2's hands-on practitioner certification as of 2026, covering the seven domains, the adaptive exam format, the one year experience requirement, the Associate of ISC2 path, career fit, and how SSCP compares to CISSP and Security+. Written for people one to two years into a security or systems administration role.
SSCP is ISC2's practitioner credential, built for the people who implement, monitor and administer IT infrastructure day to day rather than the people who design the program.
It covers seven domains, from access controls and network security through incident response and cryptography. The framing throughout is operational. ISC2 describes it as the certification for those with proven technical skills and practical, hands-on security knowledge in operational IT roles, and the exam questions read that way: less "define this term", more "you are the admin, what do you do next".
The credential is ANAB-accredited under ISO/IEC 17024, approved under DoD 8140, and gated behind a single year of experience. That one year bar is the point. It sits one tier below CISSP, which asks for five. SSCP is issued and maintained by ISC2, the same body behind CISSP and CCSP.
Ethics, security controls, asset and change management, awareness training. Tied heaviest at 16%.
Authentication, trust architectures, and the identity management lifecycle. 15% of the exam.
Risk management, vulnerability work, and analyzing monitoring output. 15% of the exam.
The incident lifecycle, forensic support, and continuity planning. 14% of the exam.
Requirements, applied concepts, secure protocols, and PKI. The lightest domain at 9%.
Network fundamentals and attacks, access control, appliances, wireless, IoT. Tied heaviest at 16%.
Malicious code, endpoints, mobile, cloud config, and virtual environments. 15% of the exam.
Four things that make SSCP the credential employers name when they want proof someone can actually run the controls.
The seven domains follow the shape of an operational job: identity and access, network security, monitoring, incident response, endpoints. Two of the seven, Security Concepts and Practices and Network and Communications Security, carry 16 percent each, which is where most administrators already spend their time. Nothing on the exam assumes you manage a budget or write policy for a board.
SSCP asks for one year of full-time experience in one or more of its domains. CISSP asks for five across two or more. That gap is the reason SSCP exists: it gives early-career practitioners an ISC2 credential they can actually qualify for now, and a degree can cover that year outright.
At $249 the SSCP exam costs a third of CISSP's $749, and holders join the same ISC2 membership with the same $135 annual maintenance fee. Pay moves with the role rather than the certificate, so our Security+ salary guide is a reasonable baseline to compare against.
ISC2 lists SSCP as approved by the Department of Defense under DoD Manual 8140.03. Approved qualifications are mapped to individual DoD Cyber Workforce Framework (DCWF) work roles at a stated proficiency level, and those mappings are revised as the matrix is updated.
Because the mapping moves, confirm the work role you are filling against the current matrix rather than an older list. Qualification matrices are published at the DoD Cyber Exchange, and we keep a work role view of the credentials we teach on our DoD 8140 page.
The certification, the exam structure, and what it takes to keep SSCP current as of 2026. Every figure below comes from ISC2.
SSCP proves you can operate the controls. What follows depends on whether you want more seniority, a specialty, or deeper analyst skills. These three come up most often.
The usual destination. ISC2's flagship covers eight domains and asks for five years across two or more of them, so most people reach it three or four years after SSCP. Read what CISSP covers before you plan the jump.
If your infrastructure moved to someone else's data center, CCSP is the ISC2 cloud credential. It needs five years of IT experience, three in security, so it is a later step rather than an immediate one.
If the monitoring and analysis domain is the part you enjoy, CompTIA CySA+ goes further into threat detection, behavioral analytics and incident response than SSCP has room for.
SSCP is the second stop for most people, not the first. It follows a foundational credential and a year on the job, and it leads toward CISSP or a specialty once the years add up.
Build the baseline
One year in
Two questions to answer before you commit: can you certify, and should you pursue SSCP specifically. Here's a straight answer to both.
You can certify in full.
ISC2 asks for one year of cumulative, full-time paid work experience in one or more of the seven SSCP domains. Administering accounts, running patching, watching alerts or configuring firewalls all count. A bachelor's or master's degree in computer science, information technology or a related field may satisfy up to one year, which covers the requirement on its own. Pass the exam, get endorsed, and you hold the full SSCP.
You can still pass now.
Sit the exam without the experience and you become an Associate of ISC2 when you pass. You then have two years to earn the one year of experience and convert. Associates pay a $50 annual maintenance fee and earn 15 CPE credits a year, then pay an $85 upgrade fee at conversion, which starts a fresh three-year certification cycle.
ISC2 positions SSCP for operational IT roles. These six are the titles it shows up against most often, in both commercial and federal hiring.
Builds, patches and hardens the servers and services everything else runs on. SSCP is the credential that turns "I keep the systems up" into documented security capability, which is the jump most sysadmins are trying to make.
Configures firewalls, segmentation, VPNs and network-based security appliances. Network and Communications Security is tied for the heaviest SSCP domain at 16 percent, so the exam maps closely to the day job.
Watches the alerts, triages what matters and escalates the rest. SSCP covers monitoring, analysis and the incident response lifecycle, which is most of what a first or second year analyst is measured on.
Owns accounts, groups, entitlements and the identity management lifecycle. Access Controls is a full 15 percent domain, and provisioning discipline is the part employers audit first.
Designs and deploys the platforms other teams consume, then keeps them within policy. SSCP proves the security half of that role without requiring the five years CISSP asks for.
Runs and protects the data stores, from access control and encryption to backup and recovery. SSCP covers the surrounding security controls that database work sits inside.
These are the two certifications buyers actually weigh SSCP against: the ISC2 credential above it and the CompTIA credential below it. Here's how they line up.
| SSCP | CISSP | Security+ | |
|---|---|---|---|
| Issuer | ISC2 | ISC2 | CompTIA |
| Focus | Hands-on operations, 7 domains | Program design and leadership, 8 domains | Security fundamentals, 5 domains |
| Exam Format | Adaptive, 100 to 125 items, 2 hrs | Adaptive, 100 to 150 items, 3 hrs | Up to 90 items, 90 min |
| Experience | 1 yr in 1+ domain | 5 yrs in 2+ domains | None required |
| Passing Score | 700 / 1000 | 700 / 1000 | 750 (scale 100 to 900) |
| Exam Cost | $249 | $749 | $439 |
| Renewal | 60 CPEs over 3 years | 120 CPEs over 3 years | 50 CEUs over 3 years |
| DoD 8140 Approved | Yes | Yes | Yes |
| Best For | Practitioners 1 to 2 years in | Senior generalists and architects | People entering security |
Prices and renewal details vary by region and membership status. A common sequence is Security+ first, SSCP once you have a year on the job, then CISSP when the five years arrive.
Our official ISC2 SSCP boot camp works through all seven domains over five days, with the $249 exam voucher, official ISC2 courseware, CAT-style practice, and on-site testing included, so practitioners sit the exam while the material is fresh.
The Associate path, what comes next, DoD 8140 work roles, and what these jobs actually look like.
The route for people who can pass the SSCP exam before they have the year of experience. What the Associate designation is, what it costs to hold, and how the conversion to full SSCP works.
The credential most SSCP holders aim at next. A full walkthrough of the eight domains, the five year experience requirement, and how to tell when you are actually ready for it.
Where SSCP sits against the genuinely entry-level options, and why it is usually the second certification you earn rather than the first one.
How the first few years of a security career tend to unfold, and where a practitioner credential like SSCP fits in the sequence between help desk and senior work.
An honest look at the work behind the job title. Useful if you are weighing SSCP because monitoring, analysis and incident response are where you expect to spend your time.
A work role by work role map of which credentials satisfy DoD 8140, and at which proficiency level, for anyone certifying to meet a federal or contractor requirement.
What the foundational security credential pays, with the figures and their sources laid out. A reasonable baseline to compare against before you add a practitioner credential on top.
The SSCP Common Body of Knowledge is organized into seven domains, each carrying its own weight on the exam. Click any domain for what it covers.
Tied for the heaviest domain. The ISC2 code of ethics, core security concepts, selecting and documenting functional security controls, the asset management lifecycle across hardware, software and data, change management, security awareness and training, and working with physical security operations.
Implementing and maintaining authentication methods, internetwork trust architectures, the identity management lifecycle from provisioning to deprovisioning, and administering the access control models an organization actually runs on.
Risk management concepts, legal and regulatory concerns, running security assessments and vulnerability management, operating and monitoring security platforms, and turning monitoring output into something a team can act on.
Supporting the incident response lifecycle from detection through lessons learned, supporting forensic investigations without contaminating evidence, and the business continuity and disaster recovery plans that follow.
The lightest domain by weight. Why cryptography is required and what drives those requirements, applying cryptographic concepts in practice, implementing secure protocols, and working with public key infrastructure.
Tied for the heaviest domain. Networking fundamentals, common network attacks, network access controls, managing network security, operating network-based security appliances and services, securing wireless, and securing and monitoring IoT.
Identifying and analyzing malicious code and activity, endpoint device security, mobile device administration, configuring cloud security, and operating and maintaining secure virtual environments.
Domains and weights reflect the ISC2 SSCP Exam Outline effective October 1, 2025, the version ISC2 administers today.
The questions candidates ask most often when researching the Systems Security Certified Practitioner certification.
SSCP is ISC2's hands-on practitioner certification. It validates the ability to implement, monitor and administer IT infrastructure in line with security policies and procedures, across seven domains. It sits one tier below CISSP: same issuer, same body of knowledge family, but aimed at the person doing the work rather than the person designing the program.
SSCP fits people one to two years into a security or systems administration role: systems and network administrators, security analysts, security administrators, and systems engineers. You need a year of real operational experience for it to make sense. If you have none yet, Security+ or ISC2's CC is the better first step.
The SSCP exam costs $249 USD as of 2026, set by ISC2 and varying by region. That fee covers the exam only, not training or study materials. Boot camps often include the voucher in the course price, so check what is bundled before you buy one separately.
Since October 1, 2025 the SSCP has been delivered exclusively as a Computerized Adaptive Testing (CAT) exam. You get 100 to 125 items in a maximum of 2 hours, mixing multiple choice with advanced item types, and you need a scaled score of 700 out of 1000 to pass. It is offered in English, Japanese and Spanish at Pearson VUE test centers.
ISC2 requires a minimum of one year of cumulative, full-time paid work experience in one or more of the seven SSCP domains. That is the whole requirement, and it is the main thing separating SSCP from CISSP, which asks for five years. A bachelor's or master's degree in computer science, information technology or a related field may satisfy up to one year, which covers the requirement outright.
Yes. Pass the exam without the year of experience and you become an Associate of ISC2. You then have two years to earn that year of experience and convert to full SSCP. Associates pay a $50 annual maintenance fee, earn 15 CPE credits a year, and pay an $85 upgrade fee when they convert.
The seven domains are Security Concepts and Practices (16%), Access Controls (15%), Risk Identification, Monitoring and Analysis (15%), Incident Response and Recovery (14%), Cryptography (9%), Network and Communications Security (16%), and Systems and Application Security (15%). Security Concepts and Practices ties with Network and Communications Security for the heaviest weight.
SSCP runs on a three-year certification cycle. You earn 60 Continuing Professional Education (CPE) credits across the cycle and pay ISC2 an annual maintenance fee of $135. At least 45 of those credits must be Group A, meaning directly related to the SSCP domains, and up to 15 can come from Group B professional development. ISC2 suggests 20 credits a year to spread the load but does not require an annual minimum for certified members.
Yes. ISC2 lists SSCP as approved by the Department of Defense under DoDM 8140.03, and the credential is ANAB accredited to ISO/IEC 17024. Approved qualifications are mapped to specific DCWF work roles and proficiency levels, and that mapping changes as the matrix is revised, so check the current qualification matrix for the work role you are filling. See the full DoD 8140 work role paths.
Both are ISC2 credentials, but they target different seniority. SSCP is the practitioner credential: seven domains, one year of experience, and a focus on implementing and operating controls. CISSP is the management-leaning credential: eight domains, five years of experience, and a focus on designing and governing a security program. Plenty of people earn SSCP first and CISSP three or four years later.
Most candidates find it harder, for two reasons. Security+ has no experience requirement and tests recognition of concepts; SSCP assumes you have administered real systems and asks what you would do. The adaptive format also stops feeding easy items once you clear them. If Security+ felt comfortable and you have a year on the job, SSCP is a reasonable next step rather than a leap.
The outline in force took effect October 1, 2025, when the exam moved to the adaptive format. It keeps the seven domains and the weights introduced on September 15, 2024, when ISC2 renamed domain 1 from Security Operations and Administration to Security Concepts and Practices. Check that any study material you buy is written against the current outline and the CAT format.
If you are one to two years into operational security or systems work, it is one of the better-value credentials available: a $249 exam, a one year experience bar, ISC2's name behind it, and DoD 8140 approval. It is worth less if you have no hands-on experience yet, or if you already have five years and could sit CISSP instead.
Whether you're weighing SSCP against CISSP, working out whether your year of experience counts, or planning training for a team, tell us where you are and we'll help you map out the right path.