TCL Portal

AWS Certified Security Specialty: The 2026 Guide

By: Sekiko Jo (pen name, TCL Security Editorial Desk) Published:
  • #AWS Security
  • #AWS Certified Security Specialty
  • #Cloud Security
  • #Certification
  • #SCS-C03

Part of our CCSP Complete Guide series.

If your organization runs primarily on AWS and you work in a technical security role — cloud security engineer, DevSecOps, security-focused solutions architect — the AWS Certified Security Specialty is one of the most direct ways to prove you can actually secure an AWS environment, not just talk about cloud security in the abstract.

This guide covers what the current exam (SCS-C03) tests, what it costs, the (non-mandatory) prerequisites AWS recommends, and how it stacks up against vendor-neutral credentials like CCSP when you’re deciding which one to study for first.

What the AWS Certified Security Specialty Exam Covers

The current version of the exam is SCS-C03, and it is organized into six content domains, each with an official scored weighting from AWS:

DomainWeighting
Domain 1: Detection16%
Domain 2: Incident Response14%
Domain 3: Infrastructure Security18%
Domain 4: Identity and Access Management20%
Domain 5: Data Protection18%
Domain 6: Security Foundations and Governance14%

(Domain names and weightings per the official SCS-C03 exam guide.)

Identity and Access Management carries the single largest weighting, which matches how the exam actually feels in practice — a large share of scenario questions hinge on IAM policy logic, permission boundaries, service control policies (SCPs), and identity federation, rather than any one detection or logging service in isolation.

Expect deep, service-specific coverage across areas like:

The exam is scenario-based rather than pure recall — most questions describe a situation (a misconfigured bucket policy, a compromised credential, a compliance requirement) and ask you to choose the AWS-native approach that resolves it correctly.

There is no exam or certification you are formally required to hold before sitting the AWS Certified Security Specialty. AWS does not gate registration behind a prerequisite credential the way some vendor programs do.

Per the official SCS-C03 exam guide, the target candidate should have the equivalent of 3–5 years of experience securing cloud solutions, along with working knowledge of the AWS shared responsibility model, identity management at scale, multi-account governance, incident response strategies, and encryption methodologies for data at rest and in transit.

In practice, most candidates who pass have already earned an AWS Associate-level certification (commonly AWS Certified Solutions Architect – Associate or AWS Certified SysOps Administrator – Associate) first. That’s not a formal requirement — it’s a reflection of the fact that the Security Specialty exam assumes working familiarity with core AWS services (VPC, IAM, EC2, S3) that the Associate-level exams also test. If you can’t comfortably explain how a VPC security group differs from a NACL, or what an SCP does that an IAM policy doesn’t, you’re likely to find the Security Specialty exam disorienting regardless of your general security background.

Cost and Exam Format

ItemDetail
Exam codeSCS-C03
Cost$300 USD per attempt
FormatMultiple choice and multiple response, plus ordering and matching question types
Number of questions65 total (50 scored, 15 unscored)
Time limit170 minutes
Passing score750 out of a 100–1,000 scaled range
Validity3 years, after which recertification is required

(Pricing and format per the official AWS Certified Security – Specialty page and SCS-C03 exam guide.)

The 15 unscored questions are mixed in with the 50 scored ones and are not identified during the exam — AWS uses them to evaluate future exam content, so there’s no way to know in the moment which questions count toward your score. Budget your time as if all 65 matter, because functionally, you can’t tell which ones don’t.

AWS Security Specialty vs CCSP: Vendor-Specific vs Vendor-Neutral

The AWS Security Specialty is frequently compared against CCSP, the vendor-neutral cloud security governance certification from ISC2. They are not competing for the same role, and understanding the difference matters more than picking a “better” one.

FactorAWS Security SpecialtyCCSP
Issuing bodyAWS (vendor)ISC2 (non-profit)
Vendor neutralityNo — AWS onlyYes — multi-cloud
Exam focusTechnical implementationGovernance, policy, architecture
Cost$300$599
Recognition scopeCloud/tech sector, AWS-heavy shopsGlobal, multi-industry
Best suited forEngineers implementing AWS security controlsArchitects and leaders setting cloud security policy

If your day-to-day work is configuring GuardDuty findings, writing IAM policies, or responding to AWS-native security alerts, the Security Specialty tests exactly that. If your work is closer to deciding what a cloud security program should look like — across providers, for an entire organization — CCSP is testing a different, broader skill set. For a deeper breakdown of how these two compare directly, see our CCSP vs AWS Security Specialty comparison.

Some professionals in AWS-heavy governance roles pursue both: AWS Security Specialty to demonstrate platform-specific technical credibility, CCSP to demonstrate that the governance judgment generalizes beyond a single cloud provider. If you’re still deciding where to start within the vendor-neutral track specifically, our CCSK vs CCSP guide covers the entry-level vendor-neutral option as well.

Career Value for AWS-Heavy Environments

The AWS Security Specialty’s value is concentrated, not universal. It carries real weight in specific situations:

It carries less weight in a few common situations worth being honest about:

Neither AWS nor ISC2 publishes official salary-premium data tied to a specific certification, so treat any specific salary figure you see elsewhere with skepticism — what’s verifiable is which job postings request the credential by name, and in AWS-centric organizations, that’s the AWS Certified Security Specialty far more often than any vendor-neutral alternative.

Summary

The AWS Certified Security Specialty (SCS-C03) is a $300, 170-minute, 65-question exam that tests deep, hands-on AWS security implementation knowledge across identity, detection, infrastructure, and data protection. There’s no mandatory prerequisite, but AWS recommends five years of security experience and two years of hands-on AWS work before attempting it.

It is the right choice if you work in a technical AWS security role and need a credential that maps directly to the platform you operate. If your role is broader — governance, multi-cloud, or organization-wide policy — a vendor-neutral certification like CCSP tests a more directly relevant skill set. For many professionals in AWS-heavy governance roles, the two are complementary rather than competing.

FAQ

How much does the AWS Certified Security Specialty exam cost?

The exam costs $300 USD per attempt, per AWS's official pricing. This does not include the cost of retakes if you don't pass, or any paid training materials you choose to use.

What are the prerequisites for AWS Certified Security Specialty?

There is no mandatory prerequisite exam or certification. AWS recommends at least five years of IT security experience and a minimum of two years of hands-on experience securing AWS workloads before attempting the exam.

Is AWS Certified Security Specialty worth it in 2026?

It depends on your environment. For engineers and architects working in AWS-heavy organizations, it demonstrates implementation-level AWS security knowledge that vendor-neutral certifications like CCSP do not test. It carries less weight if your organization is multi-cloud or if you're targeting governance-level roles rather than technical implementation roles.

About the authors