Coming soon

ISC2 SSCP — Exam Guide & Domains

The Systems Security Certified Practitioner (SSCP) recently moved to ISC2's new adaptive (CAT) exam format. CertStudio's SSCP practice is in active development — below is a complete, up-to-date exam guide, and you can get notified the moment prep launches.

What is the ISC2 SSCP certification?

ISC2 Systems Security Certified Practitioner (SSCP) is a hands-on, operational security certification for practitioners who implement, monitor, and administer IT infrastructure using security best practices. It's a natural step up from ISC2's entry-level Certified in Cybersecurity (CC).

SSCP is more technical and hands-on than CISSP, which targets senior, managerial security roles with a broader governance focus and a five-year experience requirement. SSCP is aimed at the people doing day-to-day security operations, not just designing policy for them.

SSCP exam overview

Format change: effective October 1, 2025, ISC2 moved the SSCP to Computerized Adaptive Testing (CAT), replacing the older 150-question, 3-hour linear exam. The figures below reflect the current CAT format.
FormatComputerized Adaptive Testing (CAT) — effective Oct 1, 2025
Questions100–125 items (multiple choice + advanced item types)
Time2 hours
Passing score700 out of 1000
Experience requirement1 year cumulative in one or more domains (or the Associate of ISC2 route)
CostPaid to ISC2 — see official pricing

Exam facts last verified: Aug 2026

The 7 SSCP domains

16%

Security Concepts and Practices

Codes of ethics, core security concepts, and the practices that underpin the rest of the exam.

15%

Access Controls

Authentication, authorization models, and implementing access control across systems and data.

15%

Risk Identification, Monitoring and Analysis

Risk management processes plus the monitoring and analysis techniques used to identify security events.

14%

Incident Response and Recovery

Responding to incidents, business continuity, and disaster recovery planning.

9%

Cryptography

Cryptographic concepts, algorithms, and public key infrastructure. The lightest domain.

16%

Network and Communications Security

Securing network infrastructure, wireless technologies, and communications.

15%

Systems and Application Security

Identifying and mitigating threats to endpoints, systems, and applications, including malicious code.

SSCP vs CC vs CISSP

CC

Entry-level, foundational. No experience required — the accessible starting point.

SSCP

Hands-on practitioner cert. About 1 year of experience (or the Associate of ISC2 route).

CISSP

Senior, managerial cert with broader governance focus. 5 years of experience required.

Coming soon

CertStudio SSCP prep is coming — get notified

We're building SSCP practice content now. Join the waitlist and we'll email you at launch — no spam, just the one announcement.

SSCP FAQ

How many questions are on the SSCP exam?

As of ISC2's October 2025 update, the SSCP uses Computerized Adaptive Testing (CAT) with 100–125 items, and you have 2 hours to complete it. This replaced the older 150-question, 3-hour linear format.

What's the passing score for the SSCP?

700 out of 1000. It's a scaled score, so it isn't a simple percentage of questions answered correctly.

What are the seven SSCP domains?

Security Concepts and Practices, Access Controls, Risk Identification/Monitoring & Analysis, Incident Response and Recovery, Cryptography, Network and Communications Security, and Systems and Application Security — with Cryptography the lightest (9%) and the rest each in the 14–16% range.

SSCP vs CISSP — what's the difference?

The SSCP is a hands-on, technical practitioner cert requiring about one year of relevant experience, aimed at people running day-to-day security operations. CISSP is a senior, more managerial cert with a five-year experience requirement and broader governance focus. Many people earn SSCP first and target CISSP later.

Is SSCP a step up from ISC2's CC (Certified in Cybersecurity)?

Yes. CC is ISC2's entry-level, no-experience-required foundation. SSCP goes deeper into operational, hands-on security and expects about a year of relevant work experience (or you can register as an Associate of ISC2 and earn the experience afterward).

Don't wait to start studying

Join the SSCP waitlist and we'll let you know the moment CertStudio prep is live.

New to ISC2 or cybersecurity? Start with our live ISC2 Certified in Cybersecurity (CC) guide.