ProfessionalVendor-specificAmazon Web Services· issued from US

AWS Security Specialty

AWS Certified Security — Specialty (SCS-C02)

Deep AWS security: IAM, data protection, detection, incident response within AWS primitives.

Exam fee
$300
Ongoing
$0/yr AMF
Study time
80–150 hrs
Delivery
Online proctored
Validity
3 yrs (renewal cycle)

› Quality score

33.5 / 40

Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.

Blueprint rigor
How well-defined and rigorous the exam blueprint is.
AWS publishes detailed exam guide with task statements per service area.
9.0/10
Practical evidence
Hands-on labs / written reports vs pure MCQ.
Question style includes scenario architectures with multi-service composition; closer to design exercise than MCQ.
6.0/10
Currency & upkeep
How aggressively content is kept current with the field.
Refreshed continuously with new AWS services; SCS-C02 (2023) added AI/ML and post-quantum.
9.5/10
Market recognition
How often this signal actually moves a hiring decision.
Universally cited on AWS-heavy job postings; the default AWS cloud-security signal.
9.0/10

› Market signals

public, citable inputs to the recognition score

AWS doesn't publish per-cert counts; widely cited on AWS-heavy security listings.

› Built for these roles

Cloud Security Engineer (AWS)DevSecOps Engineer (AWS)Security Architect (cloud-track)AWS Solutions Architect (security-leaning)

› Exam format

65 questions (multiple-choice + multiple-response) over 170 minutes, English plus several other languages. Pearson VUE in person or online proctored.

› Recertification

Recertify by passing the current version of the exam (or any higher-tier AWS cert) within three years. No CPE program, no maintenance fee.

› NICE Framework work roles

The NIST NICE work-role IDs this cert maps to. NICCS lookup.

DD-WRL-004PD-WRL-002OG-WRL-014
Recognition
GlobalUSEUUK
Exam languages
enjakozhesptfrde

› Core domains covered

The 5 domains this cert is centrally about. Passing the exam demonstrates working knowledge of each.

› Also touched

Present in the blueprint but not the primary focus — you’ll be introduced but shouldn’t expect depth.

› Known coverage gaps

Domains this cert does not meaningfully address. Plan follow-up learning here if your role touches any of them.

› Prerequisites

Experience

Five years of IT security experience with two years in AWS security. AWS Solutions Architect Associate / SysOps experience strongly recommended.

Knowledge assumed
  • AWS core services (IAM, VPC, KMS, CloudTrail, GuardDuty)
  • Cloud security primitives
  • Network and data encryption patterns

› Progression

requiredrecommended

Where this cert fits in the typical learning path. Required edges are vendor-gated; recommended edges reflect de facto industry progression.

Required prereqs (0)

No vendor-gated prereqs.

Recommended priors (1)
AWS Security Specialty
Amazon Web Services
Required by (0)

No certs require this one.

Recommended next (0)

No follow-on certs reference this one yet.

› Careers that commonly pursue this cert

Cloud Security Engineer

Secure cloud infrastructure across AWS, Azure, and GCP. Specialize in the shared responsibility model and cloud-native controls.

Cloud Detection / SecOps Engineer

A hybrid role growing out of the realisation that SOCs need engineers who understand cloud-native telemetry, IAM-first threat models, and how to instrument AWS/Azure/GCP for detection.

See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.