ISC2 SSCP
A practitioner-oriented cybersecurity credential covering day-to-day security administration, access controls, monitoring, incident response, cryptography, and systems security.
Last verified: 2026-09-01
Overview
ISC2 SSCP is a practitioner-focused cybersecurity certification for professionals who implement, monitor, and administer security controls and IT infrastructure. It emphasizes operational security work across security concepts, access controls, risk monitoring, incident response, cryptography, network security, and systems and application security.\n\nSSCP is well suited to security administrators, systems administrators, network security professionals, and analysts whose responsibilities involve hands-on protection of organizational systems. Candidates may pass the exam before meeting the experience requirement and use the Associate of ISC2 pathway while gaining the required experience.
- Recommended experience
- ISC2 requires one year of cumulative paid work experience in one or more SSCP domains for full certification. A qualifying bachelor's or master's degree in cybersecurity or a related field may satisfy up to one year. Candidates without the experience may pass the exam first and become an Associate of ISC2, then earn the required experience within two years.
- Estimated study time
- 80–140 hours
- Target job roles
- Security AdministratorSystems AdministratorNetwork Security EngineerSOC AnalystSecurity AnalystSystems Engineer
Exam Details
ISC2 SSCP Exam
- Exam code
- SSCP
- Number of exams
- 1
- Duration
- 120 minutes
- Question count
- 100–125 items (computerized adaptive testing)
- Delivery method
- Pearson VUE testing center (in person)
- Price
- $249 USD in the Americas and many regions; regional pricing varies
Skills and Domains
Security Concepts and Practices
16%Core security principles, ethics, governance, risk, policies, and foundational security practices.
Access Controls
15%Identity, authentication, authorization, access models, and administrative or technical access controls.
Risk Identification, Monitoring and Analysis
15%Risk identification, assessment, vulnerability management, monitoring, and analysis activities.
Incident Response and Recovery
14%Incident handling, response procedures, recovery, continuity, and operational readiness.
Cryptography
9%Cryptographic concepts, key management, encryption, hashing, certificates, and related protection mechanisms.
Network and Communications Security
16%Network architecture, communications security, protocols, wireless security, and network defenses.
Systems and Application Security
15%Secure systems, applications, virtualization, cloud environments, endpoint protection, and application-security concepts.
Study Resources
ISC2 SSCP Certification
Official resourceDocumentation · Free
Official ISC2 SSCP certification overview and candidate information.
View resourceISC2 SSCP Exam Outline
Official resourceOfficial Guide · Free
Official current SSCP exam outline, exam format, and seven domain weights.
View resourceISC2 SSCP Experience Requirements
Official resourceDocumentation · Free
Official ISC2 explanation of the work-experience and Associate pathway requirements.
View resourceRenewal
- Validity period
- 3 years
- Renewal method
- Earn 60 CPE credits during the three-year cycle and remain current on ISC2 annual maintenance requirements.
- Notes
- SSCP holders currently pay the ISC2 member Annual Maintenance Fee of U.S. $135; only one member AMF is charged even when multiple qualifying ISC2 certifications are held.
Related Certifications
Recommended Before
Verify with official provider.
Recommended After
Verify with official provider.
Alternatives
Verify with official provider.
Specializations
Verify with official provider.
Keep exploring on ThirdBadge
Connect this certification to its broader technology area, career roadmaps, training, and study resources.
Explore certification categories
Browse focused certification guides by technology and career domain.