SSCP · ● Active · Associate · ISC2
The Systems Security Certified Practitioner (SSCP) is the ideal certification for those with proven technical skills and practical, hands-on security knowledge in operational IT roles. It validates the ability to implement, monitor, and administer IT infrastructure using security best practices.
Exam facts
| Field | Value |
|---|---|
| Cost | USD $249 |
| Duration | 120 minutes (2 hours) |
| Questions | 100–125 multiple choice |
| Passing | 700/1000 (scaled score) |
| Format | Multiple choice (Computer Adaptive Test as of October 2025) |
| Delivery | Pearson VUE (OnVUE or test center) |
| Languages | English (and regional variations) |
| Valid | 3 years |
| Renewal | 60 CPE credits over 3 years + USD $135 annual AMF |
| Prerequisites | 1 year experience in ≥1 SSCP domain (waived with bachelor's degree in CS/IT/related or master's in cybersecurity) |
| Released | Originally 2002; current format effective November 2021 |
| Retiring | N/A — Active |
Vendor source — ISC2 SSCP ↗
Official exam guide — SSCP Exam Outline & Objectives ↗
Self-study resources — SSCP Study Tools ↗
About
The SSCP certification, established by the International Information Systems Security Certification Consortium (ISC)², targets security operations professionals and hands-on IT administrators responsible for implementing and administering security controls in operational environments. It is a vendor-neutral credential that validates mastery of the seven ISC2 Security Certification Body of Knowledge (CBK) domains. As of October 2025, the exam became a Computer Adaptive Test (CAT), adjusting question difficulty in real-time based on candidate responses. The credential is highly valued in SOC (Security Operations Center), system administration, and network security roles.
Domain context — Security
Operational IT security: the practices, technologies, and processes used to implement, monitor, and administer security within IT infrastructure — firewalls, access controls, cryptographic systems, incident response, network security, and systems hardening.
Read full deep dive — Security Domain →
Topics covered
The seven SSCP CBK domains and their exam weights:
- Domain 1: Security Concepts and Practices (16%) — foundational principles, code of ethics, policy frameworks, security culture
- Domain 2: Access Controls (15%) — authentication, authorization, privilege management, identity governance
- Domain 3: Risk Identification, Monitoring, and Analysis (15%) — risk assessment, monitoring tools, security metrics, threat analysis
- Domain 4: Incident Response and Recovery (14%) — incident handling, forensics, business continuity, disaster recovery
- Domain 5: Cryptography (9%) — encryption algorithms, key management, hashing, digital signatures, cryptographic protocols
- Domain 6: Network and Communications Security (16%) — network architectures, protocols, firewalls, intrusion detection, VPN, secure communications
- Domain 7: Systems and Application Security (15%) — OS hardening, application security, secure development, endpoint protection
Source: ISC2 SSCP Exam Outline ↗
Common skills at Security · Associate
Shared content for the Security domain at Associate level — not specific to this cert.
- Access control implementation and troubleshooting
- Network security monitoring and firewall rule management
- Incident response and containment procedures
- Cryptographic system operation and key lifecycle management
- Security policy compliance and audit support
- Log analysis and security event investigation
- Endpoint and server hardening
- Vulnerability assessment and remediation tracking
Recommended courses at Security · Associate
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISC2 Official | SSCP Online Self-Paced Training | $499–$699 | ↗ |
| Cybrary | SSCP Certification Prep Path | Free–$39/mo | ↗ |
| Cybrary | SSCP Practice Assessment | Included | ↗ |
| Coursera | SSCP Training Professional Certificate | $39–$49/mo | ↗ |
| A Cloud Guru / Pluralsight | SSCP (search by cert) | $29–$299/yr | Contact provider |
| Udemy | SSCP prep courses (various instructors) | $10–$15 | Search Udemy for "SSCP" |
Course-selection rule: Prioritize ISC2 official or Cybrary SSCP-specific paths; avoid generic "security fundamentals" courses. The exam emphasizes hands-on operational security, not abstract theory.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISC2 Official | Practice Quiz (10-item) | Free | ↗ |
| Boson | ExSim-Max for SSCP (if available) | Not verified | Check Boson ↗ |
| MeasureUp | SSCP Practice Exams | $79–$129 | Check MeasureUp ↗ |
| Whizlabs | SSCP Practice Tests | $29–$49 | Check Whizlabs ↗ |
| ExamTopics | SSCP Practice Questions (community) | Free | ↗ |
| Practice Test Geeks | SSCP Free Practice Test | Free | ↗ |
Note: ISC2 official practice resources and third-party vendors (Boson, MeasureUp, Whizlabs) all offer SSCP materials. Verify current product availability and CAT format alignment (October 2025 format change).
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| ISC2 SSCP Systems Security Certified Practitioner Official Study Guide (Sybex) | Michael S. Wills, Wesley Phillips | Wiley Sybex | 2023 | 978-1-119-85498-2 | ↗ |
| SSCP Systems Security Certified Practitioner All-in-One Exam Guide | Darril Gibson | McGraw-Hill | 2018 | 978-1-260-12870-3 | ↗ |
| The Official (ISC)² Guide to the SSCP CBK | Steven Hernandez, Adam Gordon | Wiley | 2022 | 978-1-119-27863-4 | ↗ |
Book rule: The Wills/Phillips Sybex guide (2023) is the official ISC2-approved study guide covering the November 2021 exam outline. Gibson's all-in-one guide is comprehensive but based on the 2018 version; verify alignment with current domains before use.
Typical job titles at Security · Associate
Security Analyst · Junior Security Engineer · IT Security Specialist · SOC Analyst · Security Operations Analyst · Security Administrator · Network Security Administrator · Systems Security Engineer (entry-level)
(Job titles drawn from current job-board postings that list SSCP as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $80,000–$108,000 | PayScale ↗ · ZipRecruiter ↗ · ISC2 Cybersecurity Workforce Study |
| ZAR | R242,000–R275,000 (annual) | PayScale ZA ↗ |
| GBP | £55,000–£75,000 | IT Jobs Watch (regional UK data) |
| EUR | €65,000–€85,000 (DE/FR) | Regional salary surveys |
Salary context: SSCP salary ranges reflect junior-to-mid-level security operations roles (SOC Analyst, Security Analyst, junior engineer). Experience level, industry, and company size drive significant variation; financial services, healthcare, and tech companies typically offer 15–25% premiums over general market rates. ZAR figures reflect mid-market ZA security analyst postings (2026).
Skills validated
Cert-specific — what this exam actually tests, distinct from the shared "Common skills" above.
- Security policy design and enforcement
- Access control implementation (DAC, MAC, RBAC, ABAC)
- Risk assessment and mitigation strategies
- Incident containment and evidence preservation
- Encryption and key management practices
- Firewall configuration and network segmentation
- Security operations center (SOC) procedures
- Business continuity and disaster recovery planning
- Vulnerability scanning and remediation workflows
- Secure coding principles and application security testing
- Operating system hardening (Windows, Linux)
- Intrusion detection/prevention system (IDS/IPS) operation
- Log aggregation and security event analysis
- Security monitoring tools (SIEM, EDR, vulnerability scanners)
- Threat modeling and risk-based prioritization
- AI and machine learning in security operations
Related certifications
- Stacks with: [CompTIA Security+ (SY0-701) ↗]({file not yet created}) · [Cisco CCNA Security ↗]({file not yet created})
- Prerequisite for: [ISC2 CISSP ↗]({file not yet created}) — CISSP requires 5 years SSCP-equivalent experience or 5 years + SSCP (reduces to 4)
- Equivalent at this level: [CompTIA Security+ ↗]({file not yet created}) · [Cisco CCNA Security ↗]({file not yet created})
- Vendor overview: ISC2 Overview ↗
Experience pathway
Prerequisite: 1 year full-time experience in ≥1 of the 7 SSCP domains, OR a bachelor's/master's degree in computer science, IT, or cybersecurity (degree waives the 1-year requirement).
Post-certification: Candidates who pass the exam but lack the 1-year experience become Associate of ISC2 and have 2 years to earn the required experience before full certification lapsing.
Endorsement: After passing the exam, apply for endorsement (online application signed by another ISC2-certified professional). ISC2 will endorse if no sponsor is available.
Source: SSCP Experience Requirements ↗
Renewal
Cycle: 3 years
CPE requirement: 60 CPE credits over 3 years (20 per year average)
AMF (Annual Maintenance Fee): USD $135/year (single fee covers all ISC2 certifications held)
Grace period: 90 days after expiration to pay AMF; lapse results in suspension
CPE sources: Training courses, vendor certifications, conference attendance, published security articles, military cybersecurity training (COOL credits), and university coursework. CPE submissions must occur within 90 days of expiration.
Source: ISC2 AMF Overview ↗
Sources
- ISC2 SSCP Certification ↗
- SSCP Exam Outline ↗
- SSCP Experience Requirements ↗
- ISC2 AMF & Member Policies ↗
- SSCP Study Tools & Resources ↗
- ISC2 Training Options ↗
- Cybrary SSCP Prep Path ↗
- PayScale SSCP Salary (US) ↗
- PayScale SSCP Salary (ZA) ↗
- ZipRecruiter SSCP Salary ↗
- Amazon – Wills, Phillips SSCP Study Guide ↗
- Amazon – Gibson SSCP All-in-One Exam Guide ↗
Last verified: 2026-05-01
Ecosystem: ISC2 Ecosystem
Domain: Security Domain