← All Certifications
ISC2

ISC2 SSCP Certification

SSCP · 7 domains

Last updated: March 31, 2026

Exam Syllabus & Domains

The ISC2 SSCP certification exam covers the following domains. Focus your training time proportionally to each domain's weight.

Domain 1 16%

Security Concepts and Practices

  • 1.1 Comply with codes of ethics
  • 1.2 Understand security concepts (CIA, accountability, non-repudiation, least privilege, SoD)
  • 1.3 Identify and implement security controls (technical, physical, administrative)
  • 1.4 Document and maintain functional security controls
  • 1.5 Support and implement asset management lifecycle
  • 1.6 Support and implement change management lifecycle
  • 1.7 Support security awareness and training
  • 1.8 Collaborate with physical security operations
CIA TriadLeast PrivilegeSeparation of DutiesSecurity ControlsAsset ManagementChange ManagementSecurity AwarenessPhysical Security
Domain 2 15%

Access Controls

  • 2.1 Implement and maintain authentication methods (MFA, SSO, device auth, federated access)
  • 2.2 Understand and support internetwork trust architectures
  • 2.3 Support and implement the identity management lifecycle
  • 2.4 Understand and administer access controls (MAC, DAC, RBAC, rule-based, ABAC)
MFASingle Sign-OnFederated AccessIdentity LifecycleRBACMACDACABAC
Domain 3 15%

Risk Identification, Monitoring and Analysis

  • 3.1 Understand risk management (visibility, reporting, frameworks, tolerance, treatment)
  • 3.2 Understand legal and regulatory concerns
  • 3.3 Perform security assessments and vulnerability management activities
  • 3.4 Operate and monitor security platforms (continuous monitoring, SIEM)
  • 3.5 Analyze monitoring results (baselines, anomalies, metrics, trends)
Risk FrameworksRisk TreatmentVulnerability ManagementSIEMContinuous MonitoringComplianceSecurity AssessmentsBaselines & Anomalies
Domain 4 14%

Incident Response and Recovery

  • 4.1 Understand and support the incident response lifecycle
  • 4.2 Understand and support forensic investigations
  • 4.3 Understand and support business continuity and disaster recovery plans
IR LifecyclePreparationDetection & ContainmentEradication & RecoveryPost-Incident ReviewDigital ForensicsBCPDRP
Domain 5 9%

Cryptography

  • 5.1 Understand reasons and requirements for cryptography
  • 5.2 Apply cryptography concepts (hashing, salting, encryption, digital signatures)
  • 5.3 Understand and implement secure protocols
  • 5.4 Understand public key infrastructure (PKI)
Symmetric EncryptionAsymmetric EncryptionHashing & SaltingDigital SignaturesPKICertificate AuthorityTLS/SSLKey Management
Domain 6 16%

Network and Communications Security

  • 6.1 Understand and apply fundamental networking concepts
  • 6.2 Understand network attacks and countermeasures
  • 6.3 Manage network access controls
  • 6.4 Manage network security (segmentation, device placement)
  • 6.5 Operate and configure network-based security appliances
  • 6.6 Secure wireless communications
  • 6.7 Secure and monitor IoT devices
OSI ModelTCP/IPFirewallsIDS/IPSNetwork SegmentationWireless SecurityIoT SecurityVPN
Domain 7 15%

Systems and Application Security

  • 7.1 Identify and analyze malicious code and activity
  • 7.2 Implement and operate endpoint device security
  • 7.3 Administer and manage mobile devices
  • 7.4 Understand and configure cloud security
  • 7.5 Operate and maintain secure virtual environments
Malware AnalysisEndpoint SecurityMDMCloud SecurityVirtualizationApplication WhitelistingPatch ManagementSecure SDLC

Where to Focus Your Study Time

Domains with higher weight have more exam questions — allocate your study hours accordingly.

D1 Security Concepts and Practices
16%
D2 Access Controls
15%
D3 Risk Identification, Monitoring and Analysis
15%
D4 Incident Response and Recovery
14%
D5 Cryptography
9%
D6 Network and Communications Security
16%
D7 Systems and Application Security
15%

Study Tips

Free Study Resources

๐Ÿ“‹

Study Roadmap

Week-by-week study plan with free resources

โœ…

Study Tracker

Track objective completion with progress dashboard

๐Ÿ’ฐ

Cost Calculator

Total cost breakdown and ROI analysis

๐Ÿงช

Practice Quiz

Test your knowledge with free practice questions

Practice Quiz

Test your knowledge before the exam with our free practice quiz.

Take the ISC2 SSCP Practice Quiz

Related Comparisons

Not sure if ISC2 SSCP is the right choice? Compare it with similar certifications:

Security+ vs SSCP SSCP vs CISSP

Get the ISC2 SSCP Study Planner

Fillable PDF with 8-week schedule, domain trackers, flashcard templates, progress tracking, and quick reference sheets. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.

Get the Study Planner — $5.99

Also available as a 4-Format Bundle for $15.99

CyberFolio

Earned your certs? Show employers.

Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.

Build Your Portfolio →

Free Training Resources

Use these free tools to support your ISC2 SSCP certification training:

Frequently Asked Questions

What is the ISC2 SSCP certification?

The ISC2 SSCP (SSCP) is a professional IT certification that validates your knowledge and skills in the exam domains covered. It is recognized globally by employers and is a valuable credential for career advancement in cybersecurity and IT.

What does the ISC2 SSCP certification syllabus cover?

The ISC2 SSCP exam syllabus covers 7 domains. Each domain is weighted differently, so focus your training on higher-weighted domains first. Review the complete domain breakdown above for objectives and key concepts.

How should I study for ISC2 SSCP?

Create a structured study plan covering all exam domains, use practice tests to identify weak areas, and review key concepts regularly. A fillable study planner can help you organize your training with weekly schedules and progress tracking.

How long does it take to prepare for ISC2 SSCP?

Preparation time varies by experience level. Most candidates spend 8-12 weeks of dedicated training. Using a structured study planner with domain-by-domain breakdown helps ensure you cover all certification objectives efficiently.