SSCP 2026 in One Minute
The Systems Security Certified Practitioner is ISC2's hands-on credential for people who implement, monitor, and administer security infrastructure. It is not simply a shorter CISSP. The questions are written for operational decisions involving access, monitoring, incident handling, cryptography, networks, systems, and applications.
The current official SSCP exam outline took effect October 1, 2025. It defines a two-hour Computerized Adaptive Testing exam with 100-125 multiple-choice and advanced items. The passing standard is 700 out of 1000 scaled points. The exam is offered in English, Japanese, and Spanish at Pearson VUE test centers.
Those details replace older descriptions of a fixed 125-question, three-hour linear exam. They also change how you should practice: SSCP CAT does not let you return to a submitted answer.
Current SSCP Exam Facts
| Item | Current official detail |
|---|---|
| Credential | Systems Security Certified Practitioner |
| Exam outline | Effective October 1, 2025 |
| Delivery | Computerized Adaptive Testing at authorized Pearson VUE test centers |
| Time limit | 2 hours |
| Exam length | 100-125 items |
| Item formats | Multiple choice and advanced item types |
| Passing standard | 700 out of 1000 scaled points |
| Languages | English, Japanese, and Spanish |
| U.S. price | $249 on ISC2's current pricing page; currency, taxes, and location-based pricing can differ |
| Experience for certification | One year in one or more SSCP domains, subject to the experience pathways below |
Check the ISC2 SSCP page, exam pricing page, and your Pearson VUE checkout before paying. A dollar amount shown for the Americas should not be treated as a universal worldwide price.
The 700 passing standard is scaled. It does not mean that 70 percent correct is guaranteed to pass, and ISC2 does not publish a universal raw-score cutoff or candidate pass rate.
What 100-125 CAT Items Actually Means
CAT is more than a timed computer exam. After each response, the system updates its estimate of your ability and selects the next item using all previous responses. The exam is not divided into seven visible domain sections, and its order is not predetermined, although each delivered exam must conform to the content outline.
The ISC2 CAT policy creates several practical rules:
- You must finalize each answer before advancing. There is no review screen and no backtracking.
- The exam ends between 100 and 125 items under ISC2's stopping rules. Ending at 100 does not disclose whether you passed.
- At the 100-item minimum, the exam contains 75 scored operational items and 25 unscored pretest items. You cannot identify the pretest items, so answer every item seriously.
- If you do not complete at least 100 items before the two-hour limit, ISC2 reports an automatic failure.
- Breaks are allowed, but the exam clock continues to run.
- You receive a pass or fail result after testing, not a useful raw percentage. A failed result includes domain proficiency feedback.
Do not spend the first half trying to judge whether a question is easy, unscored, or evidence that the algorithm likes your performance. None of those guesses helps. Read for role, scope, and the requested action; eliminate choices that violate policy or authority; select the best supported answer; then move on.
A practical pacing checkpoint is 50 items near the one-hour mark. It is only an editorial practice target, not an ISC2 rule, because the exam may continue beyond 100. Practice making decisions without a review queue, but do not mistake any practice platform for a reproduction of ISC2's adaptive algorithm or scoring.
The Seven Domains and Exact Weights
| Domain | Weight | Operational focus |
|---|---|---|
| 1. Security Concepts and Practices | 16% | Security principles, controls, asset management, change, ethics, awareness, and physical security |
| 2. Access Controls | 15% | Identity lifecycle, authentication, authorization, access models, privileged access, and federation |
| 3. Risk Identification, Monitoring and Analysis | 15% | Risk, assessment, vulnerability management, logging, monitoring, and security analytics |
| 4. Incident Response and Recovery | 14% | Preparation, detection, analysis, containment, evidence, recovery, continuity, and lessons learned |
| 5. Cryptography | 9% | Symmetric and asymmetric uses, hashing, signatures, PKI, key management, and cryptographic attacks |
| 6. Network and Communications Security | 16% | Architecture, segmentation, protocols, wireless, firewalls, detection, remote access, and attacks |
| 7. Systems and Application Security | 15% | Hardening, lifecycle security, virtualization, cloud, application controls, patching, and endpoint protection |
Use those percentages as allocation guidance, not a prediction of question order. Domains 1 and 6 are largest at 16 percent each, yet the other four non-cryptography domains sit only one or two points lower. Ignoring a 14-15 percent domain to chase the largest pair is poor risk management. Cryptography is the smallest domain, but its tools also appear in network, access, and application scenarios.
Watch for stale materials that call Domain 1 Security Operations and Administration. ISC2 renamed it Security Concepts and Practices in September 2024, and the dated October 2025 outline remains the controlling scope for this guide.
Experience: Exam Eligibility Is Not Certification Eligibility
You do not need the work experience before sitting the exam. You do need it before receiving the full SSCP certification. The current SSCP experience requirements call for one year of work experience in one or more SSCP domains.
ISC2 recognizes more than one way to document that year:
- Full-time experience is credited under ISC2's published weekly and monthly rules.
- Part-time work can count when it meets the stated 20-34 hours per week thresholds and accumulated-hour rules.
- Paid or unpaid internships may count when documented on the employer's or school's official letterhead.
- A qualifying cybersecurity degree or a degree in a preapproved computing field may satisfy up to the full one-year requirement. Verify your program against ISC2's current pathway rather than assuming any technology degree qualifies.
This is broader and more precise than saying the experience must be paid full-time. Before applying, map each role to actual SSCP domain work and collect dates, hours, supervisor contacts, and internship or degree records. Job title alone is weak evidence; duties are what connect the role to the outline.
The Associate of ISC2 Route
If you pass without enough experience, you may become an Associate of ISC2. For SSCP, the Associate route gives you two years to earn the required one year of experience. Passing the exam does not itself let you use the SSCP certification title before the requirements and application are complete.
Treat the two-year experience window and the post-exam application process as separate clocks. Candidates who already qualify must complete the ISC2 certification application and endorsement process within nine months of the exam. An ISC2-certified member in good standing normally endorses the application and attests to the professional experience; ISC2 can assist candidates who do not know an endorser. Candidates using the Associate route should follow the steps and deadlines displayed in their ISC2 account rather than waiting until the end of the two years to investigate them.
A simple post-pass checklist is:
- Save the result and sign in to the same ISC2 account used for registration.
- Choose the full certification application if your experience is complete, or follow the Associate process if it is not.
- Gather accurate role dates, duties, supervisor information, and degree or internship documentation.
- Arrange an eligible endorser or request ISC2 assistance.
- Monitor your account and email until ISC2 confirms the status; do not represent yourself as SSCP-certified early.
After certification, maintain SSCP with 60 continuing professional education credits during each three-year cycle and the current $135 annual maintenance fee. Associate and candidate fees are different, so check the policy for the status you actually hold.
Retakes: Know the Clock Before a Failed Attempt
ISC2's after-your-exam policy currently permits no more than four attempts at an ISC2 exam within a rolling 12-month period. After a first failure, the wait is 30 days; after a second, 60 days; after a third or later failure, 90 days. A retake is a new exam registration, not a free continuation of the first attempt.
Use the domain feedback from a failed CAT result as a triage signal, not a score report. Rebuild the lowest-proficiency domains, but also review timing and first-pass decision quality. Repeating the same mixed-question volume without diagnosing why options looked attractive is unlikely to repair the problem.
A Credential-Specific CAT Practice Plan
1. Domain coverage
Track answered questions against all seven current domain names. Allocate roughly by official weights, then deliberately add work where your accuracy or confidence is weak. Label each miss by its real cause: missing concept, role confusion, sequencing error, overlooked qualifier, or unfamiliar technology.
2. Operational decisions
For scenario misses, write two short lines: why the keyed action is appropriate now, and what makes the strongest distractor premature, outside the administrator's authority, or inconsistent with policy. SSCP often tests the best operational step rather than the most dramatic technical response.
3. CAT execution
Run mixed timed blocks with no answer changes. Practice committing after a disciplined first read. At least once before exam day, complete a 100-item, two-hour block without pausing the clock; this rehearses the minimum item count and exposes fatigue. It does not simulate adaptive selection, and its percentage is not an official pass prediction.
In the last week, confirm the Pearson VUE location, identification requirements, appointment time, travel, and the fact that breaks consume exam time. Keep reviewing recurring misses, but avoid replacing your current October 2025 outline with an undated cram sheet.
Official SSCP Sources to Bookmark
- SSCP certification page for the credential's current purpose and links
- SSCP exam outline for the effective date, format, domains, and weights
- ISC2 CAT policy for item counts, stopping rules, breaks, and answer finality
- SSCP experience requirements for work, internship, degree, and Associate pathways
- ISC2 exam pricing for the amount shown in your testing region
- ISC2 endorsement and after-your-exam policy for application and retake rules
The best readiness signal is not memorizing the table above. It is being able to choose and justify a secure operational action across every domain, within two hours, without relying on a later review screen.
