ProfessionalVendor-neutralEC-Council· issued from US

CSA

EC Council Certified SOC Analyst

EC Council Certified SOC Analyst

Exam fee
$450
Ongoing
$80/yr AMF · 40 CPE/yr
Study time
60–120 hrs
Delivery
Hybrid
Validity
3 yrs (renewal cycle)

› Quality score

24.5 / 40

Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.

Blueprint rigor
How well-defined and rigorous the exam blueprint is.
Certified SOC Analyst — entry SOC credential with broad blueprint.
6.5/10
Practical evidence
Hands-on labs / written reports vs pure MCQ.
Lab-style scenarios but largely MCQ.
5.5/10
Currency & upkeep
How aggressively content is kept current with the field.
Updated alongside the EC-Council SOC track.
6.5/10
Market recognition
How often this signal actually moves a hiring decision.
Recognised in EC-Council-trained SOCs; CySA+ is the more common HR-screen signal.
6.0/10

› Exam format

100 multiple-choice questions, 3 hours, proctored. Passing score: 70%.

Retake policy
Fee: $499 per attempt
Wait: 0d between attempts

First retake immediate; 14 days between attempts 2-3, 1 month between 3-4, 3 months between 4-5. Max 5 attempts/year.

› Recertification

Valid for 3 years. 120 ECE credits over 3 years + annual AMF (80 USD).

› 3-year cost of ownership

Exam (1×)
$450
AMF (3×)
$240@$80/yr
Total
$690

Excludes study materials, training, retake risk, and lost-wage opportunity. Use as a floor estimate.

› NICE Framework work roles

The NIST NICE work-role IDs this cert maps to. NICCS lookup.

PD-WRL-001PD-WRL-003
Recognition
Global
Exam languages
en

› Core domains covered

The 2 domains this cert is centrally about. Passing the exam demonstrates working knowledge of each.

› Prerequisites

Experience

No formal prerequisites. Recommended: CEH or CND.

› Careers that commonly pursue this cert

Cloud Security Engineer

Secure cloud infrastructure across AWS, Azure, and GCP. Specialize in the shared responsibility model and cloud-native controls.

AppSec / DevSecOps Engineer

Embed security into the software development lifecycle. Shift left to catch vulnerabilities before they reach production.

Cloud Detection / SecOps Engineer

A hybrid role growing out of the realisation that SOCs need engineers who understand cloud-native telemetry, IAM-first threat models, and how to instrument AWS/Azure/GCP for detection.

ML Platform Security Engineer

Secures the platform that trains, stores, and serves ML models — multi-tenant GPU isolation, pipeline integrity, feature-store hygiene, secrets management in ML workflows.

See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.