Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Systems Security Certified Practitioner (SSCP)
Certification Explained.

Everything you need to know about ISC2's hands-on practitioner certification as of 2026, covering the seven domains, the adaptive exam format, the one year experience requirement, the Associate of ISC2 path, career fit, and how SSCP compares to CISSP and Security+. Written for people one to two years into a security or systems administration role.

SSCP_FAST_FACTS
Issuer: ISC2
Exam: 100 to 125 questions, 2 hours
Passing Score: 700 / 1000
Experience: 1 year in a domain
DoD 8140 Approved
7 SSCP Domains 1 YR Experience Required 100-125 Exam Questions 2-HOUR Adaptive Exam 700/1000 To Pass
UPDATED 2026
Overview

What Is the Systems Security Certified Practitioner (SSCP)?

SSCP is ISC2's practitioner credential, built for the people who implement, monitor and administer IT infrastructure day to day rather than the people who design the program.

It covers seven domains, from access controls and network security through incident response and cryptography. The framing throughout is operational. ISC2 describes it as the certification for those with proven technical skills and practical, hands-on security knowledge in operational IT roles, and the exam questions read that way: less "define this term", more "you are the admin, what do you do next".

The credential is ANAB-accredited under ISO/IEC 17024, approved under DoD 8140, and gated behind a single year of experience. That one year bar is the point. It sits one tier below CISSP, which asks for five. SSCP is issued and maintained by ISC2, the same body behind CISSP and CCSP.

7 Domains
1 Yr Experience
2 Hr Adaptive Exam
The SSCP Domains

Seven Domains of Practice

01

Security Concepts and Practices

Ethics, security controls, asset and change management, awareness training. Tied heaviest at 16%.

02

Access Controls

Authentication, trust architectures, and the identity management lifecycle. 15% of the exam.

03

Risk Identification, Monitoring and Analysis

Risk management, vulnerability work, and analyzing monitoring output. 15% of the exam.

04

Incident Response and Recovery

The incident lifecycle, forensic support, and continuity planning. 14% of the exam.

05

Cryptography

Requirements, applied concepts, secure protocols, and PKI. The lightest domain at 9%.

06

Network and Communications Security

Network fundamentals and attacks, access control, appliances, wireless, IoT. Tied heaviest at 16%.

07

Systems and Application Security

Malicious code, endpoints, mobile, cloud config, and virtual environments. 15% of the exam.

Why SSCP Matters

Why Is SSCP So Widely Recognized?

Four things that make SSCP the credential employers name when they want proof someone can actually run the controls.

Built for the Hands-On Role

The seven domains follow the shape of an operational job: identity and access, network security, monitoring, incident response, endpoints. Two of the seven, Security Concepts and Practices and Network and Communications Security, carry 16 percent each, which is where most administrators already spend their time. Nothing on the exam assumes you manage a budget or write policy for a board.

One Year, Not Five

SSCP asks for one year of full-time experience in one or more of its domains. CISSP asks for five across two or more. That gap is the reason SSCP exists: it gives early-career practitioners an ISC2 credential they can actually qualify for now, and a degree can cover that year outright.

The Cheapest Way Into ISC2

At $249 the SSCP exam costs a third of CISSP's $749, and holders join the same ISC2 membership with the same $135 annual maintenance fee. Pay moves with the role rather than the certificate, so our Security+ salary guide is a reasonable baseline to compare against.

DoD 8140 Approved

ISC2 lists SSCP as approved by the Department of Defense under DoD Manual 8140.03. Approved qualifications are mapped to individual DoD Cyber Workforce Framework (DCWF) work roles at a stated proficiency level, and those mappings are revised as the matrix is updated.

Because the mapping moves, confirm the work role you are filling against the current matrix rather than an older list. Qualification matrices are published at the DoD Cyber Exchange, and we keep a work role view of the credentials we teach on our DoD 8140 page.

DoDM 8140.03 Approved ISO/IEC 17024 Accredited ANAB Recognized
Fast Facts

What Are the Key Facts About SSCP?

The certification, the exam structure, and what it takes to keep SSCP current as of 2026. Every figure below comes from ISC2.

01

The Certification

Certification Name
Systems Security Certified Practitioner (SSCP)
Issued By
ISC2
Exam Outline
Effective October 1, 2025
Domains
7 (weights unchanged since Sept 15, 2024)
Prerequisites
1 year full-time in one or more domains
Experience Waiver
Bachelor's or master's in CS, IT or related
No-Experience Path
Pass and hold Associate of ISC2 (2 years)
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Approved under DoDM 8140.03
02

Exam & Maintenance

Exam Format
Computerized Adaptive Testing (CAT)
Number of Items
100 to 125 questions
Item Types
Multiple choice plus advanced items
Exam Duration
2 hours
Passing Score
700 out of 1000
Languages
English, Japanese, Spanish (Pearson VUE)
Exam Cost
$249 USD
CPE Requirement
60 CPEs over 3 years (45 Group A)
Maintenance
$135 annual maintenance fee to ISC2
Going Deeper

What Comes After the SSCP?

SSCP proves you can operate the controls. What follows depends on whether you want more seniority, a specialty, or deeper analyst skills. These three come up most often.

CISSP (Seniority)

The usual destination. ISC2's flagship covers eight domains and asks for five years across two or more of them, so most people reach it three or four years after SSCP. Read what CISSP covers before you plan the jump.

CCSP (Cloud Specialty)

If your infrastructure moved to someone else's data center, CCSP is the ISC2 cloud credential. It needs five years of IT experience, three in security, so it is a later step rather than an immediate one.

CySA+ (Detection Depth)

If the monitoring and analysis domain is the part you enjoy, CompTIA CySA+ goes further into threat detection, behavioral analytics and incident response than SSCP has room for.

Certification Roadmap

Where Does SSCP Fit in Your Career?

SSCP is the second stop for most people, not the first. It follows a foundational credential and a year on the job, and it leads toward CISSP or a specialty once the years add up.

STAGE 02 You Are Here

Practitioner

One year in

PRIMARY
SSCP
ISC2 ยท Systems Security Certified Practitioner
Associate of ISC2
ISC2 ยท Pass first, earn the year after
STAGE 03

Advance

Pick your path

Broad Security
Specialize
Decision Point

Is SSCP Right For You?

Two questions to answer before you commit: can you certify, and should you pursue SSCP specifically. Here's a straight answer to both.

Q1

Do You Qualify for SSCP?

Path A

One Year in a Domain, or a Degree

You can certify in full.

ISC2 asks for one year of cumulative, full-time paid work experience in one or more of the seven SSCP domains. Administering accounts, running patching, watching alerts or configuring firewalls all count. A bachelor's or master's degree in computer science, information technology or a related field may satisfy up to one year, which covers the requirement on its own. Pass the exam, get endorsed, and you hold the full SSCP.

Path B

Not There Yet

You can still pass now.

Sit the exam without the experience and you become an Associate of ISC2 when you pass. You then have two years to earn the one year of experience and convert. Associates pay a $50 annual maintenance fee and earn 15 CPE credits a year, then pay an $85 upgrade fee at conversion, which starts a fresh three-year certification cycle.

Q2

Is SSCP the Right Certification for Your Goals?

SSCP Is a Strong Fit If...

  • You are one to two years into a security, systems or network administration role and want the next credential up
  • You already hold Security+ and want something that proves operational depth rather than another foundational cert
  • You want an ISC2 credential now and cannot meet the five year CISSP requirement for another few years
  • You need a DoD 8140 approved credential for a federal or contractor position
  • Your day job is access control, patching, monitoring, endpoints or network security, which is most of the exam
  • You want the ISC2 name on your resume without a $749 exam fee

Consider Alternatives If...

  • You have no hands-on IT experience yet, where Security+ or ISC2's CC is the better first credential
  • You already have five years across two or more domains, in which case go straight to CISSP
  • You are heading for management and governance rather than hands-on work, where CISM fits better
  • Your infrastructure is entirely cloud and you meet the experience bar, where CCSP is the closer match
  • You want deep detection and threat hunting skills specifically, where CySA+ goes further
  • A specific job posting names a different certification by name, in which case chase that one
Career Paths

What Jobs Can You Get With SSCP?

ISC2 positions SSCP for operational IT roles. These six are the titles it shows up against most often, in both commercial and federal hiring.

Infrastructure

Systems Administrator

Builds, patches and hardens the servers and services everything else runs on. SSCP is the credential that turns "I keep the systems up" into documented security capability, which is the jump most sysadmins are trying to make.

Network Security

Network Security Engineer

Configures firewalls, segmentation, VPNs and network-based security appliances. Network and Communications Security is tied for the heaviest SSCP domain at 16 percent, so the exam maps closely to the day job.

Security Operations

Security Analyst

Watches the alerts, triages what matters and escalates the rest. SSCP covers monitoring, analysis and the incident response lifecycle, which is most of what a first or second year analyst is measured on.

Access and Identity

Security Administrator

Owns accounts, groups, entitlements and the identity management lifecycle. Access Controls is a full 15 percent domain, and provisioning discipline is the part employers audit first.

Systems Engineering

Systems Engineer

Designs and deploys the platforms other teams consume, then keeps them within policy. SSCP proves the security half of that role without requiring the five years CISSP asks for.

Data Platforms

Database Administrator

Runs and protects the data stores, from access control and encryption to backup and recovery. SSCP covers the surrounding security controls that database work sits inside.

Comparison

How Does SSCP Compare to CISSP and Security+?

These are the two certifications buyers actually weigh SSCP against: the ISC2 credential above it and the CompTIA credential below it. Here's how they line up.

  SSCP CISSP Security+
Issuer ISC2 ISC2 CompTIA
Focus Hands-on operations, 7 domains Program design and leadership, 8 domains Security fundamentals, 5 domains
Exam Format Adaptive, 100 to 125 items, 2 hrs Adaptive, 100 to 150 items, 3 hrs Up to 90 items, 90 min
Experience 1 yr in 1+ domain 5 yrs in 2+ domains None required
Passing Score 700 / 1000 700 / 1000 750 (scale 100 to 900)
Exam Cost $249 $749 $439
Renewal 60 CPEs over 3 years 120 CPEs over 3 years 50 CEUs over 3 years
DoD 8140 Approved Yes Yes Yes
Best For Practitioners 1 to 2 years in Senior generalists and architects People entering security

Prices and renewal details vary by region and membership status. A common sequence is Security+ first, SSCP once you have a year on the job, then CISSP when the five years arrive.

Ready to Get Certified?

Train for SSCP with Training Camp.

Our official ISC2 SSCP boot camp works through all seven domains over five days, with the $249 exam voucher, official ISC2 courseware, CAT-style practice, and on-site testing included, so practitioners sit the exam while the material is fresh.

View Boot Camp
Dive Deeper

SSCP Articles and Guides.

The Associate path, what comes next, DoD 8140 work roles, and what these jobs actually look like.

Featured ISC2 Path

A Comprehensive Guide to Becoming an Associate of ISC2

The route for people who can pass the SSCP exam before they have the year of experience. What the Associate designation is, what it costs to hold, and how the conversion to full SSCP works.

Read Article โ†’
What Comes Next

The Complete CISSP Guide

The credential most SSCP holders aim at next. A full walkthrough of the eight domains, the five year experience requirement, and how to tell when you are actually ready for it.

Read Article โ†’
Getting Started

Entry-Level Cybersecurity Certifications for Beginners

Where SSCP sits against the genuinely entry-level options, and why it is usually the second certification you earn rather than the first one.

Read Article โ†’
Career Path

Getting Started in Cybersecurity: Entry-Level Certifications and Career Paths

How the first few years of a security career tend to unfold, and where a practitioner credential like SSCP fits in the sequence between help desk and senior work.

Read Article โ†’
Role Reality

What Does a SOC Analyst Actually Do All Day?

An honest look at the work behind the job title. Useful if you are weighing SSCP because monitoring, analysis and incident response are where you expect to spend your time.

Read Article โ†’
DoD 8140

Which Certifications Qualify for DoD 8140 Work Roles? A DCWF Map

A work role by work role map of which credentials satisfy DoD 8140, and at which proficiency level, for anyone certifying to meet a federal or contractor requirement.

Read Article โ†’
Salary and Demand

CompTIA Security+ Salary Guide

What the foundational security credential pays, with the figures and their sources laid out. A reasonable baseline to compare against before you add a practitioner credential on top.

Read Article โ†’
Curriculum

Inside the Seven SSCP Domains.

The SSCP Common Body of Knowledge is organized into seven domains, each carrying its own weight on the exam. Click any domain for what it covers.

Domains 01-04

Concepts to Incident Response
01 Security Concepts and Practices 16%

Tied for the heaviest domain. The ISC2 code of ethics, core security concepts, selecting and documenting functional security controls, the asset management lifecycle across hardware, software and data, change management, security awareness and training, and working with physical security operations.

02 Access Controls 15%

Implementing and maintaining authentication methods, internetwork trust architectures, the identity management lifecycle from provisioning to deprovisioning, and administering the access control models an organization actually runs on.

03 Risk Identification, Monitoring and Analysis 15%

Risk management concepts, legal and regulatory concerns, running security assessments and vulnerability management, operating and monitoring security platforms, and turning monitoring output into something a team can act on.

04 Incident Response and Recovery 14%

Supporting the incident response lifecycle from detection through lessons learned, supporting forensic investigations without contaminating evidence, and the business continuity and disaster recovery plans that follow.

Domains 05-07

Cryptography to Systems
05 Cryptography 9%

The lightest domain by weight. Why cryptography is required and what drives those requirements, applying cryptographic concepts in practice, implementing secure protocols, and working with public key infrastructure.

06 Network and Communications Security 16%

Tied for the heaviest domain. Networking fundamentals, common network attacks, network access controls, managing network security, operating network-based security appliances and services, securing wireless, and securing and monitoring IoT.

07 Systems and Application Security 15%

Identifying and analyzing malicious code and activity, endpoint device security, mobile device administration, configuring cloud security, and operating and maintaining secure virtual environments.

Domains and weights reflect the ISC2 SSCP Exam Outline effective October 1, 2025, the version ISC2 administers today.

Frequently Asked Questions

Common Questions About SSCP.

The questions candidates ask most often when researching the Systems Security Certified Practitioner certification.

What is the SSCP certification?

SSCP is ISC2's hands-on practitioner certification. It validates the ability to implement, monitor and administer IT infrastructure in line with security policies and procedures, across seven domains. It sits one tier below CISSP: same issuer, same body of knowledge family, but aimed at the person doing the work rather than the person designing the program.

Who should get the SSCP?

SSCP fits people one to two years into a security or systems administration role: systems and network administrators, security analysts, security administrators, and systems engineers. You need a year of real operational experience for it to make sense. If you have none yet, Security+ or ISC2's CC is the better first step.

How much does the SSCP exam cost in 2026?

The SSCP exam costs $249 USD as of 2026, set by ISC2 and varying by region. That fee covers the exam only, not training or study materials. Boot camps often include the voucher in the course price, so check what is bundled before you buy one separately.

What is the SSCP exam like?

Since October 1, 2025 the SSCP has been delivered exclusively as a Computerized Adaptive Testing (CAT) exam. You get 100 to 125 items in a maximum of 2 hours, mixing multiple choice with advanced item types, and you need a scaled score of 700 out of 1000 to pass. It is offered in English, Japanese and Spanish at Pearson VUE test centers.

What experience do you need for the SSCP?

ISC2 requires a minimum of one year of cumulative, full-time paid work experience in one or more of the seven SSCP domains. That is the whole requirement, and it is the main thing separating SSCP from CISSP, which asks for five years. A bachelor's or master's degree in computer science, information technology or a related field may satisfy up to one year, which covers the requirement outright.

Can you take the SSCP exam without experience?

Yes. Pass the exam without the year of experience and you become an Associate of ISC2. You then have two years to earn that year of experience and convert to full SSCP. Associates pay a $50 annual maintenance fee, earn 15 CPE credits a year, and pay an $85 upgrade fee when they convert.

What are the seven SSCP domains?

The seven domains are Security Concepts and Practices (16%), Access Controls (15%), Risk Identification, Monitoring and Analysis (15%), Incident Response and Recovery (14%), Cryptography (9%), Network and Communications Security (16%), and Systems and Application Security (15%). Security Concepts and Practices ties with Network and Communications Security for the heaviest weight.

How do I maintain my SSCP certification?

SSCP runs on a three-year certification cycle. You earn 60 Continuing Professional Education (CPE) credits across the cycle and pay ISC2 an annual maintenance fee of $135. At least 45 of those credits must be Group A, meaning directly related to the SSCP domains, and up to 15 can come from Group B professional development. ISC2 suggests 20 credits a year to spread the load but does not require an annual minimum for certified members.

Is SSCP approved for DoD 8140?

Yes. ISC2 lists SSCP as approved by the Department of Defense under DoDM 8140.03, and the credential is ANAB accredited to ISO/IEC 17024. Approved qualifications are mapped to specific DCWF work roles and proficiency levels, and that mapping changes as the matrix is revised, so check the current qualification matrix for the work role you are filling. See the full DoD 8140 work role paths.

What is the difference between SSCP and CISSP?

Both are ISC2 credentials, but they target different seniority. SSCP is the practitioner credential: seven domains, one year of experience, and a focus on implementing and operating controls. CISSP is the management-leaning credential: eight domains, five years of experience, and a focus on designing and governing a security program. Plenty of people earn SSCP first and CISSP three or four years later.

Is SSCP harder than Security+?

Most candidates find it harder, for two reasons. Security+ has no experience requirement and tests recognition of concepts; SSCP assumes you have administered real systems and asks what you would do. The adaptive format also stops feeding easy items once you clear them. If Security+ felt comfortable and you have a year on the job, SSCP is a reasonable next step rather than a leap.

Which SSCP exam outline is current?

The outline in force took effect October 1, 2025, when the exam moved to the adaptive format. It keeps the seven domains and the weights introduced on September 15, 2024, when ISC2 renamed domain 1 from Security Operations and Administration to Security Concepts and Practices. Check that any study material you buy is written against the current outline and the CAT format.

Is SSCP worth it in 2026?

If you are one to two years into operational security or systems work, it is one of the better-value credentials available: a $249 exam, a one year experience bar, ISC2's name behind it, and DoD 8140 approval. It is worth less if you have no hands-on experience yet, or if you already have five years and could sit CISSP instead.

Get In Touch

Have Questions About SSCP?

Whether you're weighing SSCP against CISSP, working out whether your year of experience counts, or planning training for a team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    ISC2 SSCP Boot Camp 5-Day Boot Camp ยท Exam Voucher Included
    View Boot Camp