Skip to main content
← Back to certifications
ISC2CybersecurityIntermediateVendor-neutralActive

ISC2 SSCP

A practitioner-oriented cybersecurity credential covering day-to-day security administration, access controls, monitoring, incident response, cryptography, and systems security.

Last verified: 2026-09-01

Overview

ISC2 SSCP is a practitioner-focused cybersecurity certification for professionals who implement, monitor, and administer security controls and IT infrastructure. It emphasizes operational security work across security concepts, access controls, risk monitoring, incident response, cryptography, network security, and systems and application security.\n\nSSCP is well suited to security administrators, systems administrators, network security professionals, and analysts whose responsibilities involve hands-on protection of organizational systems. Candidates may pass the exam before meeting the experience requirement and use the Associate of ISC2 pathway while gaining the required experience.

Recommended experience
ISC2 requires one year of cumulative paid work experience in one or more SSCP domains for full certification. A qualifying bachelor's or master's degree in cybersecurity or a related field may satisfy up to one year. Candidates without the experience may pass the exam first and become an Associate of ISC2, then earn the required experience within two years.
Estimated study time
80–140 hours
Target job roles
Security AdministratorSystems AdministratorNetwork Security EngineerSOC AnalystSecurity AnalystSystems Engineer

Exam Details

ISC2 SSCP Exam

Exam code
SSCP
Number of exams
1
Duration
120 minutes
Question count
100–125 items (computerized adaptive testing)
Delivery method
Pearson VUE testing center (in person)
Price
$249 USD in the Americas and many regions; regional pricing varies

Skills and Domains

Security Concepts and Practices

16%

Core security principles, ethics, governance, risk, policies, and foundational security practices.

Access Controls

15%

Identity, authentication, authorization, access models, and administrative or technical access controls.

Risk Identification, Monitoring and Analysis

15%

Risk identification, assessment, vulnerability management, monitoring, and analysis activities.

Incident Response and Recovery

14%

Incident handling, response procedures, recovery, continuity, and operational readiness.

Cryptography

9%

Cryptographic concepts, key management, encryption, hashing, certificates, and related protection mechanisms.

Network and Communications Security

16%

Network architecture, communications security, protocols, wireless security, and network defenses.

Systems and Application Security

15%

Secure systems, applications, virtualization, cloud environments, endpoint protection, and application-security concepts.

Study Resources

ISC2 SSCP Certification

Official resource

Documentation · Free

Official ISC2 SSCP certification overview and candidate information.

View resource

ISC2 SSCP Exam Outline

Official resource

Official Guide · Free

Official current SSCP exam outline, exam format, and seven domain weights.

View resource

ISC2 SSCP Experience Requirements

Official resource

Documentation · Free

Official ISC2 explanation of the work-experience and Associate pathway requirements.

View resource

Renewal

Validity period
3 years
Renewal method
Earn 60 CPE credits during the three-year cycle and remain current on ISC2 annual maintenance requirements.
Notes
SSCP holders currently pay the ISC2 member Annual Maintenance Fee of U.S. $135; only one member AMF is charged even when multiple qualifying ISC2 certifications are held.

Recommended Before

Verify with official provider.

Recommended After

Verify with official provider.

Alternatives

Verify with official provider.

Specializations

Verify with official provider.

Explore certification categories

Browse focused certification guides by technology and career domain.