AWS Certified Security Specialty: The 2026 Guide
- #AWS Security
- #AWS Certified Security Specialty
- #Cloud Security
- #Certification
- #SCS-C03
Part of our CCSP Complete Guide series.
If your organization runs primarily on AWS and you work in a technical security role — cloud security engineer, DevSecOps, security-focused solutions architect — the AWS Certified Security Specialty is one of the most direct ways to prove you can actually secure an AWS environment, not just talk about cloud security in the abstract.
This guide covers what the current exam (SCS-C03) tests, what it costs, the (non-mandatory) prerequisites AWS recommends, and how it stacks up against vendor-neutral credentials like CCSP when you’re deciding which one to study for first.
What the AWS Certified Security Specialty Exam Covers
The current version of the exam is SCS-C03, and it is organized into six content domains, each with an official scored weighting from AWS:
| Domain | Weighting |
|---|---|
| Domain 1: Detection | 16% |
| Domain 2: Incident Response | 14% |
| Domain 3: Infrastructure Security | 18% |
| Domain 4: Identity and Access Management | 20% |
| Domain 5: Data Protection | 18% |
| Domain 6: Security Foundations and Governance | 14% |
(Domain names and weightings per the official SCS-C03 exam guide.)
Identity and Access Management carries the single largest weighting, which matches how the exam actually feels in practice — a large share of scenario questions hinge on IAM policy logic, permission boundaries, service control policies (SCPs), and identity federation, rather than any one detection or logging service in isolation.
Expect deep, service-specific coverage across areas like:
- Identity: IAM policies, roles, permission boundaries, SCPs, AWS Organizations, identity federation
- Detection and monitoring: GuardDuty, Security Hub, Inspector, Macie, CloudTrail, CloudWatch, Security Lake
- Infrastructure security: VPC design, security groups, NACLs, AWS WAF, Shield, PrivateLink
- Data protection: KMS key management, encryption at rest and in transit, Secrets Manager, CloudHSM
- Incident response: AWS-native tooling for containment, forensics, and automated response
The exam is scenario-based rather than pure recall — most questions describe a situation (a misconfigured bucket policy, a compromised credential, a compliance requirement) and ask you to choose the AWS-native approach that resolves it correctly.
Prerequisites (AWS Foundational/Associate Recommended)
There is no exam or certification you are formally required to hold before sitting the AWS Certified Security Specialty. AWS does not gate registration behind a prerequisite credential the way some vendor programs do.
Per the official SCS-C03 exam guide, the target candidate should have the equivalent of 3–5 years of experience securing cloud solutions, along with working knowledge of the AWS shared responsibility model, identity management at scale, multi-account governance, incident response strategies, and encryption methodologies for data at rest and in transit.
In practice, most candidates who pass have already earned an AWS Associate-level certification (commonly AWS Certified Solutions Architect – Associate or AWS Certified SysOps Administrator – Associate) first. That’s not a formal requirement — it’s a reflection of the fact that the Security Specialty exam assumes working familiarity with core AWS services (VPC, IAM, EC2, S3) that the Associate-level exams also test. If you can’t comfortably explain how a VPC security group differs from a NACL, or what an SCP does that an IAM policy doesn’t, you’re likely to find the Security Specialty exam disorienting regardless of your general security background.
Cost and Exam Format
| Item | Detail |
|---|---|
| Exam code | SCS-C03 |
| Cost | $300 USD per attempt |
| Format | Multiple choice and multiple response, plus ordering and matching question types |
| Number of questions | 65 total (50 scored, 15 unscored) |
| Time limit | 170 minutes |
| Passing score | 750 out of a 100–1,000 scaled range |
| Validity | 3 years, after which recertification is required |
(Pricing and format per the official AWS Certified Security – Specialty page and SCS-C03 exam guide.)
The 15 unscored questions are mixed in with the 50 scored ones and are not identified during the exam — AWS uses them to evaluate future exam content, so there’s no way to know in the moment which questions count toward your score. Budget your time as if all 65 matter, because functionally, you can’t tell which ones don’t.
AWS Security Specialty vs CCSP: Vendor-Specific vs Vendor-Neutral
The AWS Security Specialty is frequently compared against CCSP, the vendor-neutral cloud security governance certification from ISC2. They are not competing for the same role, and understanding the difference matters more than picking a “better” one.
| Factor | AWS Security Specialty | CCSP |
|---|---|---|
| Issuing body | AWS (vendor) | ISC2 (non-profit) |
| Vendor neutrality | No — AWS only | Yes — multi-cloud |
| Exam focus | Technical implementation | Governance, policy, architecture |
| Cost | $300 | $599 |
| Recognition scope | Cloud/tech sector, AWS-heavy shops | Global, multi-industry |
| Best suited for | Engineers implementing AWS security controls | Architects and leaders setting cloud security policy |
If your day-to-day work is configuring GuardDuty findings, writing IAM policies, or responding to AWS-native security alerts, the Security Specialty tests exactly that. If your work is closer to deciding what a cloud security program should look like — across providers, for an entire organization — CCSP is testing a different, broader skill set. For a deeper breakdown of how these two compare directly, see our CCSP vs AWS Security Specialty comparison.
Some professionals in AWS-heavy governance roles pursue both: AWS Security Specialty to demonstrate platform-specific technical credibility, CCSP to demonstrate that the governance judgment generalizes beyond a single cloud provider. If you’re still deciding where to start within the vendor-neutral track specifically, our CCSK vs CCSP guide covers the entry-level vendor-neutral option as well.
Career Value for AWS-Heavy Environments
The AWS Security Specialty’s value is concentrated, not universal. It carries real weight in specific situations:
- You work at a company that runs primarily or exclusively on AWS. In that context, the certification demonstrates operational credibility that a vendor-neutral credential can’t — you’re proving you know this specific platform, not cloud security in the abstract.
- You’re in a technical implementation role. Cloud security engineer, DevSecOps, security-focused AWS architect — roles where you’re actually configuring the controls, not just approving the policy that governs them.
- You need a credential that maps directly to a job requisition. Many AWS-shop job postings list this certification by name, which isn’t true of every vendor-neutral credential.
It carries less weight in a few common situations worth being honest about:
- Multi-cloud or cloud-agnostic organizations, where AWS-specific depth doesn’t transfer to the Azure or GCP workloads you’re also responsible for.
- Governance, GRC, or CISO-track roles, where the hiring signal you need is closer to what CCSP or CISSP demonstrates — organization-wide judgment, not platform-specific configuration knowledge.
- Early-career candidates without hands-on AWS time. Because the exam is scenario-based and assumes real operational familiarity, studying for it without practical AWS experience tends to produce shallow, exam-only knowledge that doesn’t hold up on the job.
Neither AWS nor ISC2 publishes official salary-premium data tied to a specific certification, so treat any specific salary figure you see elsewhere with skepticism — what’s verifiable is which job postings request the credential by name, and in AWS-centric organizations, that’s the AWS Certified Security Specialty far more often than any vendor-neutral alternative.
Summary
The AWS Certified Security Specialty (SCS-C03) is a $300, 170-minute, 65-question exam that tests deep, hands-on AWS security implementation knowledge across identity, detection, infrastructure, and data protection. There’s no mandatory prerequisite, but AWS recommends five years of security experience and two years of hands-on AWS work before attempting it.
It is the right choice if you work in a technical AWS security role and need a credential that maps directly to the platform you operate. If your role is broader — governance, multi-cloud, or organization-wide policy — a vendor-neutral certification like CCSP tests a more directly relevant skill set. For many professionals in AWS-heavy governance roles, the two are complementary rather than competing.
FAQ
How much does the AWS Certified Security Specialty exam cost?
The exam costs $300 USD per attempt, per AWS's official pricing. This does not include the cost of retakes if you don't pass, or any paid training materials you choose to use.
What are the prerequisites for AWS Certified Security Specialty?
There is no mandatory prerequisite exam or certification. AWS recommends at least five years of IT security experience and a minimum of two years of hands-on experience securing AWS workloads before attempting the exam.
Is AWS Certified Security Specialty worth it in 2026?
It depends on your environment. For engineers and architects working in AWS-heavy organizations, it demonstrates implementation-level AWS security knowledge that vendor-neutral certifications like CCSP do not test. It carries less weight if your organization is multi-cloud or if you're targeting governance-level roles rather than technical implementation roles.
About the authors
Sekiko Jo
"Sekiko Jo" is the pen name used by Team Creative Lab’s security editorial desk. Articles are written and reviewed by an editor-in-chief who holds CISSP, CCSP and the Registered Information Security Specialist (情報処理安全確保支援士) credential, with a focus on cloud threat modeling and security governance.
Registered Information Security Specialist (情報処理安全確保支援士), Japan