SCS-C02 vs SCS-C03: What Changed in the AWS Security Specialty Exam?

2026/07/20

Click to upload or drag and drop

PDF, DOCX, PPTX, TXT, JPG, JPEG, PNG, HEIC, ODP, ODT, BMP, or TIFF

up to 20MB

Please wait, your quiz is being created...

Uploading...

SCS-C02 was in use until December 1, 2025, and SCS-C03 has been the only version of the AWS Certified Security Specialty exam you can sit since December 2, 2025. If you are studying now, study SCS-C03. The update restructured the six domains, raised the weight of identity and access management to 20 percent, split detection and incident response into separate domains, added ordering and matching question types, and brought in new content on generative AI protections, the Open Cybersecurity Schema Framework, and multi-Region key management. The format basics stayed the same: 65 questions, 170 minutes, a passing score of 750, a US$300 fee, and three-year validity.

The tricky part is that most course material, video series, and question banks still describe SCS-C02. If your prep lists security logging and monitoring or threat detection and incident response as domains, it predates the current exam. Here is a clear side-by-side so you know what actually changed and where to point your study time.

The quick version comparison

 SCS-C02 (retired)SCS-C03 (current)
In useUntil December 1, 2025From December 2, 2025
Questions65 (50 scored + 15 unscored)65 (50 scored + 15 unscored)
Time170 minutes170 minutes
Passing score750 / 1000750 / 1000
CostUS$300US$300
Question typesMultiple choice, multiple responseMultiple choice, multiple response, ordering, matching
Domains66 (restructured)

What changed in the domains?

Both versions have six domains, but SCS-C03 renamed and rebalanced them. The clearest change is that identity and access management became the single heaviest domain, and the old combined detection-and-response area was split so detection and incident response now stand on their own.

SCS-C02 domains (retired)SCS-C03 domains (current)
Threat Detection and Incident Response 14%Detection 16%
Security Logging and Monitoring 18%Incident Response 14%
Infrastructure Security 20%Infrastructure Security 18%
Identity and Access Management 16%Identity and Access Management 20%
Data Protection 18%Data Protection 18%
Management and Security Governance 14%Security Foundations and Governance 14%

The practical takeaway: identity and access management is now a fifth of the exam, so policy evaluation logic, permission boundaries, resource policies, and cross-account access deserve the most study time. Infrastructure security dropped slightly, and governance kept its weight but was renamed. If you built a study plan around the C02 weightings, shift reps toward IAM.

What new content did SCS-C03 add?

This is where the update matters most, because these topics simply were not on the retired exam. AWS added several modern security areas to SCS-C03:

  • Generative AI protections. The exam now references the OWASP Top 10 for large language model applications, reflecting how security teams have to defend AI systems. This is a fast-moving area, and defending a deployed model at runtime, for example blocking prompt injection and enforcing tool and data boundaries, is exactly the kind of protection the newer content points at.
  • Open Cybersecurity Schema Framework (OCSF). Schema-based ingestion of security findings, which changes how detection data is normalized and correlated.
  • Data masking. CloudWatch Logs data protection policies and SNS message data protection for sensitive data.
  • Inter-resource in-transit encryption. Encryption between services like EMR, EKS, SageMaker, and Nitro.
  • Key material and multi-Region keys. Imported versus AWS-generated KMS key material, and multi-Region key and certificate management with KMS and AWS Private CA.

SCS-C03 also dropped some content, including the AWS Security Finding Format, host-based hardening specifics, and VPC Reachability Analyzer network-reachability tasks. If your notes lean heavily on those, you can de-prioritize them.

Did the question format change?

Yes. Alongside the familiar multiple choice and multiple response items, SCS-C03 introduced ordering and matching question types. Ordering asks you to put steps in the correct sequence, and matching asks you to pair items, such as a service to its purpose or a control to a requirement. Neither is conceptually harder, but they reward precise knowledge and are worth practicing so the format does not surprise you on exam day. The scoring model is unchanged: 50 of the 65 questions are scored, 15 are unscored pretest items, and you need 750 on a 100 to 1,000 scale using compensatory scoring, so a weak domain can be offset by strong ones.

How should you adjust your study plan?

Start by confirming every resource you use is built for SCS-C03, not SCS-C02. Then weight your time toward the three heaviest domains: identity and access management, infrastructure security, and data protection. Make sure you cover the new topics, because they are easy points if you have studied them and easy misses if you have not. And practice the new ordering and matching formats so they feel routine.

Because the exam is scenario-based, the most efficient preparation is drilling judgment rather than rereading documentation. Upload your notes and the current exam guide and generate scenario questions that mirror the format, weighting the new SCS-C03 content, with the AWS Security Specialty practice exam generator. Retake fresh sets until the best answer for a described situation comes back instantly, and aim to clear practice sets comfortably above the equivalent of the 750 bar before you book.

How long should you study for SCS-C03?

It depends on your starting point. If you already secure AWS workloads day to day and hold an associate-level certification, most people are ready in four to six weeks of focused study, a few hours most days. If AWS security is newer to you, plan for two to three months and budget extra time for the heaviest domains. The single biggest predictor of readiness is hands-on comfort with IAM policy evaluation and KMS, because those show up across multiple domains and are where scenario questions get subtle.

A useful checkpoint is your practice-set accuracy. When you are consistently clearing mixed practice sets well above the equivalent of the 750 bar, across all six domains rather than just your strong ones, you are close. If one domain keeps dragging you down, that is where the remaining study should go. Do not book the exam off a single good practice score; look for stable performance across several sessions and question types, including the newer ordering and matching items.

The bottom line

SCS-C02 is retired, so target SCS-C03. The exam is the same length, price, and passing bar, but the domains were rebalanced toward identity and access management, detection and incident response split apart, two new question types appeared, and the content now covers generative AI security, OCSF, data masking, and multi-Region key management. Update your resources, reweight your study, and practice the current outline. That is the difference between preparing for the exam you will actually sit and preparing for the one that no longer exists.

From the same family of tools