1.1 About the ASIS APP Exam
Key Takeaways
- The ASIS Associate Protection Professional (APP) exam consists of 125 multiple-choice questions (100 scored, 25 unscored pretest) with a 2-hour (120-minute) time limit.
- Content is divided across four domains: Security Fundamentals (35%), Risk Management (25%), Business Operations (22%), and Response Management (18%).
- Eligibility requires one or more years of compensated security experience (or six months with an ASIS-approved related certification); active CPP holders are ineligible.
- The exam costs $300 for ASIS members and $620 for non-members, delivered globally via Pearson VUE test centers or OnVUE online proctoring.
- Maintaining the APP designation requires completing 60 Continuing Professional Education (CPE) credits every 3 years.
1.1 About the ASIS APP Exam
Exam Snapshot: The ASIS Associate Protection Professional (APP®) is a board-certified credential demonstrating foundational knowledge in security management. The exam features 125 multiple-choice questions administered over 120 minutes via Pearson VUE.
What is the ASIS APP Certification?
The Associate Protection Professional (APP®) designation was created by ASIS International—the leading global association for security management professionals—to validate board-level competence for practitioners with one or more years of compensated security experience. Positioned as the foundational stepping stone in the ASIS board certification portfolio, the APP serves as a precursor to advanced designations such as the Certified Protection Professional (CPP®) and Physical Security Professional (PSP®). Earning the APP demonstrates mastery across core security disciplines, including physical asset protection, risk assessment, business continuity, emergency response, and operational leadership.
Unlike entry-level certificate programs that require completing specific coursework, the APP is an independent board certification. Candidates must demonstrate verified professional experience, adhere to the ASIS Code of Professional Responsibility, and pass a rigorous, proctored examination based on the ASIS Security Body of Knowledge.
Exam Format and Administration
The APP examination is administered electronically by Pearson VUE, offering candidates the flexibility to test at physical Pearson VUE Professional Centers worldwide or via the OnVUE online proctoring platform from a secure home or office environment.
| Exam Parameter | Details & Specifications |
|---|---|
| Total Question Count | 125 multiple-choice questions |
| Scored Questions | 100 live questions |
| Unscored Pretest Questions | 25 pretest questions (randomly distributed) |
| Time Allowed | 2 hours (120 minutes) |
| Pace Requirement | ~57.6 seconds per question |
| Delivery Method | Pearson VUE Test Centers or OnVUE Remote Proctoring |
| Question Structure | 4 option choices per item; 1 single correct answer |
| Passing Standard | Scaled score of at least 650 (ASIS does not publish the raw percentage equivalent) |
| Exam Retests | Up to 3 attempts during the candidacy period, with at least 90 days between attempts |
Scored vs. Unscored Pretest Questions
Of the 125 total items on the examination, exactly 100 questions are scored toward your final result. The remaining 25 items are unscored pretest questions used by ASIS International to evaluate potential future exam items for psychometric validity, difficulty, and fairness.
- Pretest items are randomly intermixed throughout the exam.
- Candidates cannot distinguish between scored items and pretest items.
- Therefore, every question must be treated with equal diligence and focus.
The Four Domain Weightings
The APP examination content outline is divided into four distinct domains. The weightings reflect the percentage of scored questions drawn from each area on any given exam form.
| Domain Number | Domain Title | Percentage Weight | Approx. Scored Questions |
|---|---|---|---|
| Domain 1 | Security Fundamentals | 35% | 35 questions |
| Domain 2 | Business Operations | 22% | 22 questions |
| Domain 3 | Risk Management | 25% | 25 questions |
| Domain 4 | Response Management | 18% | 18 questions |
| Total | All Four Domains | 100% | 100 questions |
Domain Breakdown Overview
- Security Fundamentals (35%): Covers physical security measures, access controls, information asset protection, personnel security, executive protection, security standards, and professional ethics.
- Business Operations (22%): Focuses on business alignment, project management, budgeting (CapEx vs. OpEx), financial metrics, legal compliance, training development, vendor management, and contract oversight.
- Risk Management (25%): Focuses on Enterprise Security Risk Management (ESRM), threat/vulnerability/consequence analysis, quantitative/qualitative risk assessment methodologies, risk treatment strategies, and business impact analysis.
- Response Management (18%): Addresses incident response frameworks (Incident Command System/NIMS), crisis management, emergency operations centers (EOCs), business continuity, crisis communications, workplace violence prevention, insider threat mitigation, and investigations.
Eligibility Requirements and Restrictions
Under the current ASIS Board Certification Handbook, the APP is intended for entry-level security professionals with one or more years of related, compensated security experience. There is no education tiering — a candidate must demonstrate at least one year of full-time, compensated security work, verified by references and a supervisor.
| Eligibility Path | Required Compensated Security Experience |
|---|---|
| Standard path (no approved related certification) | 1 year of compensated security experience |
| Approved certification path | 6 months of compensated security experience, if the candidate already holds an ASIS-approved related certification |
Experience Reductions and Ineligibility Rules
- Approved Credential Reduction: Candidates who already hold an ASIS-approved related certification may qualify with as little as six months of compensated security experience instead of one year.
- CPP Ineligibility Rule: Active CPP holders are explicitly ineligible to sit for the APP exam. ASIS policy states that the APP designation expires if a candidate later obtains the CPP, because the two designations cannot be held concurrently.
Fees and Registration
Exam registration fees vary based on ASIS International membership status at the time of application submission:
- ASIS Members: $300 application and examination fee.
- Non-Members: $620 application and examination fee.
- Retest Fee: Candidates who do not pass may retake the exam for $250 (the same fee applies to ASIS members and nonmembers) after a mandatory 90-day waiting period between attempts.
Tip: Joining ASIS International as a member before registering often offsets the cost difference while providing access to member-discounted study materials.
Recertification Requirements
To maintain the integrity of the credential, APP certificants must renew their certification every 3 years.
- 60 CPE Credits: Certificants must accumulate 60 Continuing Professional Education (CPE) credits during each 3-year cycle.
- CPE Categories: Credits can be earned through continuing education, attending security conferences (e.g., GSX), authoring security publications, serving in professional security leadership roles, or completing relevant academic coursework.
- Recertification Fee: A recertification fee of $180 (members) or $220 (non-members) is due at the end of the 3-year cycle.
Official Resources and Links
Candidates should refer to official ASIS International resources throughout their exam preparation:
- ASIS International APP Overview Page — Official eligibility details and application portal.
- ASIS Certification Handbook (PDF) — Policies, rules, scoring details, and exam candidate regulations.
- ASIS Protection of Assets (POA) & Standards — The primary reference materials utilized for exam item writing.
- Pearson VUE ASIS Exam Portal — Exam scheduling, testing center locator, and OnVUE system compatibility checks.
Under current ASIS APP eligibility, what is the minimum compensated security experience a candidate must demonstrate if they do NOT hold an ASIS-approved related certification?
Which of the following statements correctly describes the composition of items on the 125-question ASIS APP examination?
An active Certified Protection Professional (CPP) credential holder wishes to take the APP exam to add the designation to their resume. What is the official ASIS policy regarding this application?