AWS Certified Security – Specialty is AWS’s advanced security certification, and the current exam is SCS-C03: 65 questions in 170 minutes for $300, with a passing score of 750 out of 1,000. It replaced SCS-C02 in December 2025, and AWS says the new version has a dedicated focus on generative AI and machine learning security.
This guide covers the six exam domains and their weights, exactly which AI topics the exam guide names, what changed from SCS-C02, who should take it, how to prepare with AWS’s official resources, and how to keep the certification current. One thing up front: we don’t have practice questions for this exam, so we point you to AWS’s own.
AWS Security Specialty at a glance
| Full name | AWS Certified Security – Specialty |
|---|---|
| Exam code | SCS-C03 (SCS-C02 was last available on December 1, 2025) |
| Level | Specialty |
| Cost | $300 USD. Local prices include €256, A$449 and ¥40,000; taxes may apply |
| Length | 170 minutes |
| Questions | 65: 50 scored and 15 unscored (you can’t tell which) |
| Question types | Multiple choice and multiple response; the exam guide also lists ordering and matching |
| Passing score | 750 on a scale of 100 to 1,000 |
| Delivery | Pearson VUE test center or online proctored |
| Languages | English, Japanese, Korean, Portuguese (Brazil), Simplified Chinese and Spanish (Latin America). The last three retire after December 31, 2026 |
| Prerequisites | None required |
| Recommended experience | 3 to 5 years securing cloud solutions (exam guide) |
| Valid for | 3 years |
| Retakes | Wait 14 calendar days; full fee for each attempt |
| Official practice | Free Official Practice Question Set on AWS Skill Builder |
Checked against the AWS Certified Security – Specialty certification page, the SCS-C03 exam guide, AWS Certification’s recertification page and exam policies on October 8, 2026.
SCS-C03 exam domains and weights
AWS’s exam guide splits the scored content into six domains. Identity and Access Management is the biggest single domain; the published outline is below.
| Domain | Weight | Task statements (published outline) |
|---|---|---|
| 1. Detection | 16% | Design and implement monitoring and alerting for an account or organization; design and implement logging; troubleshoot monitoring, logging and alerting |
| 2. Incident Response | 14% | Design and test an incident response plan; respond to security events, from capturing forensic artifacts to containment, recovery and root cause analysis |
| 3. Infrastructure Security | 18% | Security controls for network edge services; security controls for compute workloads; network security controls |
| 4. Identity and Access Management | 20% | Design, implement and troubleshoot authentication strategies and authorization strategies |
| 5. Data Protection | 18% | Controls for data in transit; controls for data at rest; protecting confidential data, credentials, secrets and cryptographic key material |
| 6. Security Foundations and Governance | 14% | Centrally deploy and manage AWS accounts; secure, consistent deployment of cloud resources; evaluate the compliance of AWS resources |
Scoring is compensatory: you need to pass the exam overall, not each domain. Your score report may show how you did in each section, but AWS warns against reading too much into it.
Services each domain leans on
- Detection: Amazon GuardDuty, AWS Security Hub, Amazon Security Lake, Amazon Macie, AWS Config, AWS CloudTrail (including organization trails), Amazon CloudWatch, Athena and VPC Flow Logs.
- Incident Response: Systems Manager, AWS Step Functions, Lambda, Amazon Detective, AWS Fault Injection Service and AWS Resilience Hub.
- Infrastructure Security: AWS WAF, CloudFront, AWS Shield Advanced, Amazon Inspector, EC2 Image Builder, Systems Manager Patch Manager and Session Manager, security groups, network ACLs, AWS Network Firewall and AWS Verified Access.
- Identity and Access Management: IAM, AWS IAM Identity Center, Amazon Cognito, AWS STS, Amazon Verified Permissions, IAM Roles Anywhere, IAM Access Analyzer and the IAM Policy Simulator.
- Data Protection: AWS KMS, AWS CloudHSM, AWS Secrets Manager, AWS Private Certificate Authority, S3 Object Lock, AWS Backup, AWS PrivateLink and VPC endpoints.
- Security Foundations and Governance: AWS Organizations, AWS Control Tower, SCPs and RCPs, CloudFormation StackSets, AWS Firewall Manager, AWS Audit Manager and AWS Artifact.
Those are the examples AWS gives in its task statements, not a complete list. The exam guide also publishes in-scope and out-of-scope service lists, and notes that security features of an otherwise out-of-scope service can still be tested: you won’t be asked how to set up S3 replication, but you might be asked about an S3 bucket policy.
The AI and generative AI security content
AWS describes SCS-C03 as having a dedicated focus on generative AI and machine learning security. In the exam guide itself, that shows up in a handful of specific places rather than as its own domain:
- Generative AI guardrails (task 3.2): implement protections and guardrails for generative AI applications, for example by applying protections from the OWASP Top 10 for LLM Applications (OWASP’s list of the most common security risks in apps built on large language models).
- AI service opt-out policies (task 6.1): use organization policies, including AI service opt-out policies, to manage permissions across accounts.
- Encryption between AI resources (task 5.1): inter-node encryption in transit, with SageMaker AI named alongside Amazon EMR and Amazon EKS.
- AI tools in security work: SageMaker AI notebooks for incident response runbooks (task 2.1), and Amazon Q Developer and Amazon CodeGuru Security for finding vulnerabilities in a pipeline (task 3.2).
- In-scope machine learning services: Amazon Bedrock, Amazon CodeGuru Security, Amazon Q Business, Amazon Q Developer and Amazon SageMaker AI.
Just as useful is what’s out of scope: the guide says the target candidate is not expected to train machine learning models. SCS-C03 tests whether you can secure AI workloads on AWS, not whether you can build them. If AI security is your main goal, compare it with vendor-neutral options in our AI security certifications guide, which sets SCS-C03 against CompTIA SecAI+ and ISACA AAISM. If you build generative AI apps on AWS, the AWS Certified Generative AI Developer – Professional gives 20% of its exam to AI safety, security and governance.
What changed from SCS-C02
SCS-C03 replaced SCS-C02, which was available until December 1, 2025; SCS-C03 has been in use since December 2, 2025. Identity and Access Management gained weight, and AWS restructured the first two domains: SCS-C02’s detection, logging and incident response content is now split between Detection and Incident Response, so domains 1 and 2 don’t map one-to-one.
| Domain | SCS-C02 (until Dec 1, 2025) | SCS-C03 (since Dec 2, 2025) |
|---|---|---|
| 1 | Threat Detection and Incident Response (14%) | Detection (16%) |
| 2 | Security Logging and Monitoring (18%) | Incident Response (14%) |
| 3 | Infrastructure Security (20%) | Infrastructure Security (18%) |
| 4 | Identity and Access Management (16%) | Identity and Access Management (20%) |
| 5 | Data Protection (18%) | Data Protection (18%) |
| 6 | Management and Security Governance (14%) | Security Foundations and Governance (14%) |
Content AWS added for SCS-C03:
- Validating findings from AWS security services to judge the scope and impact of an event
- Ingesting data in Open Cybersecurity Schema Framework (OCSF) format and using third-party WAF rules
- Guardrails for generative AI applications (OWASP Top 10 for LLM Applications)
- Inter-resource encryption in transit for Amazon EMR, Amazon EKS, SageMaker AI and Nitro
- The difference between imported key material and AWS-generated key material
- Masking sensitive data with CloudWatch Logs data protection policies and Amazon SNS message data protection
- Managing keys and certificates across one or multiple Regions with KMS and AWS Private Certificate Authority
Content AWS removed includes the AWS Security Finding Format (ASFF), fundamental TCP/IP networking concepts, host-based firewalls and hardening as named topics, the components of a policy statement, TLS concepts, and S3 static website hosting. If your course or book still uses the domain names “Threat Detection and Incident Response” and “Security Logging and Monitoring”, it was written for SCS-C02.
Exam languages: three retire after December 31, 2026
AWS is retiring the Simplified Chinese, Spanish (Latin America) and Portuguese (Brazil) versions of the exam after December 31, 2026, leaving English, Japanese and Korean. If you planned to test in one of those languages, our news post AWS Security Specialty retires 3 exam languages covers what to do, including the extra 30 minutes AWS offers non-native speakers who switch to English.
Who should take it
AWS aims this exam at experienced security people. The exam guide recommends the equivalent of 3 to 5 years of experience securing cloud solutions; the certification page describes the candidate as having five years of IT security experience plus two or more years of hands-on experience securing AWS workloads. Neither is a formal requirement, and no other certification is required first, though AWS says candidates commonly earn the AWS Certified Solutions Architect – Associate or Professional before this one.
The recommended knowledge in the guide includes the shared responsibility model, managing identity at scale, multi-account governance, software supply chain risk, firewall rules for layers 3 to 7, incident root cause analysis, responding to an audit, logging and monitoring strategy, encryption at rest and in transit, and disaster recovery. Out of scope: designing cryptographic algorithms, packet-level traffic analysis, architecting whole cloud deployments, managing end-user compute, and training machine learning models.
Newer to AWS? Start with a foundational or associate exam. Our AWS AI certifications guide lays out the full AWS path.
How to prepare for SCS-C03
Start with AWS’s own material. Much of it is free.
- Read the SCS-C03 exam guide, including the task statements, the in-scope and out-of-scope service lists and the SCS-C02 comparison appendix. It is the only official outline of the exam.
- Follow the Exam Prep Plan on AWS Skill Builder. The certification page lays out four steps: get to know the exam with exam-style questions, refresh your knowledge with digital courses and hands-on labs, review and practice by domain, then assess your readiness. AWS also points SCS-C03 candidates to its Security Engineer Advanced Learning Plan.
- Take the free Official Practice Question Set on AWS Skill Builder to see the question style. AWS’s full-length Official Practice Exam and extra practice material need a Skill Builder subscription, which AWS says starts at $29 a month for individuals.
- Get hands-on in a sandbox account. Turn on GuardDuty and Security Hub, create an organization CloudTrail trail, write least-privilege IAM policies and test them with IAM Access Analyzer, encrypt data with KMS customer managed keys, build AWS WAF rules, and add guardrails to a small Amazon Bedrock app. Watch your bill: several of these services charge.
- Weight your time like the exam. Identity and Access Management (20%), Infrastructure Security (18%) and Data Protection (18%) add up to more than half of the scored content.
- Learn the short service names. The exam uses short names for some AWS services; AWS says the list is available through the Help button during the exam, and you can review it beforehand.
About practice questions: we don’t have SCS-C03 practice questions, and our exam simulator doesn’t cover this exam. AWS’s free Official Practice Question Set is the place to start. Skip anything sold as real exam questions. For the AI exams we do cover, start at free AI exam prep, and the AI certification index lists every exam’s price, length and status.
Cost, discounts and retakes
- Price: $300 USD for the Specialty tier, the same as AWS Professional exams. AWS updates local currency prices at least once a year, in May.
- 50% off your next exam: once you earn any AWS Certification, AWS gives you a 50% discount on your next exam, available in your AWS Certification Account.
- Retakes: if you fail, wait 14 calendar days. There is no limit on attempts, but each one costs the full fee. After you pass, you can’t retake the same exam for two years unless a new version comes out.
- Rescheduling: you can reschedule an appointment twice, and cancelling more than 24 hours ahead gets you a refund of the fee you paid.
Validity and recertification
The certification is valid for 3 years. AWS lists two ways to keep it active, and your certification must still be active to use either:
| Option | Cost | Adds |
|---|---|---|
| Pass the latest version of the exam | Use the 50% discount voucher in your AWS Certification Account | 3 years from the date you pass |
| Maintain the certification on AWS Skill Builder | Requires a paid Skill Builder subscription | 1 year from the date you finish |
For how other AI and cloud certifications handle renewal, see do AI certifications expire?
Sources
- AWS Certified Security – Specialty certification page
- AWS Certified Security – Specialty (SCS-C03) exam guide
- AWS Training and Certification blog on SCS-C03
- AWS recertification options
- AWS Certification Before Testing policies (pricing, rescheduling)
- AWS Certification After Testing policies (retakes)
HOW TO // AI is not affiliated with or endorsed by Amazon Web Services. AWS Certified Security – Specialty is a certification and trademark of Amazon.com, Inc. or its affiliates; we reference it descriptively.
Get AI Cert Watch: an email when AI certification exams change
We check the official pages of 80+ AI exams every day. When a price, version, format or retirement date changes, you’ll get a short email. At most one a week, plus the HOW TO // AI newsletter on Thursdays.
Unsubscribe anytime. Privacy policy.
Related guides
- AI Security Certifications in 2026: SecAI+, AAISM, GIAC and More
- CompTIA SecAI+ Study Guide (CY0-001): All 4 Domains, Weights and a 4-Week Plan
- AAISM Study Guide: ISACA’s AI Security Management Exam, Domain by Domain
- AWS Generative AI Developer Professional (AIP-C01) Study Guide
- AWS Security Specialty Retires 3 Exam Languages Dec 31
Frequently asked questions
How much does the AWS Security Specialty exam cost?
$300 USD, the standard price for AWS Specialty exams. Local prices include €256, A$449 and ¥40,000, and taxes may apply. If you already hold an AWS Certification, you get 50% off your next exam.
How long is the SCS-C03 exam and how many questions does it have?
170 minutes and 65 questions. 50 questions count toward your score and 15 are unscored questions AWS is testing for future use; they aren't marked.
What is the passing score for AWS Certified Security - Specialty?
750 on a scale of 100 to 1,000. Scoring is compensatory, so you need to pass the exam overall, not every domain.
Is SCS-C02 still available?
No. SCS-C02 was available until December 1, 2025, and SCS-C03 has been the exam since December 2, 2025. Study material that uses the old domain names was written for SCS-C02.
Does SCS-C03 cover AI security?
Yes, in specific places. The exam guide includes guardrails for generative AI applications based on the OWASP Top 10 for LLM Applications, AI service opt-out policies and encryption for SageMaker AI, and lists Amazon Bedrock, Amazon Q and SageMaker AI as in-scope services.
How much experience do I need for AWS Security Specialty?
AWS's exam guide recommends the equivalent of 3 to 5 years of experience securing cloud solutions. There are no formal prerequisites, though AWS says candidates commonly earn an AWS Solutions Architect certification first.
How long is the AWS Security Specialty certification valid?
3 years. You can renew for another 3 years by passing the latest version of the exam with your 50% discount voucher, or extend it by 1 year through maintenance on a paid AWS Skill Builder subscription.
Which languages is the AWS Security Specialty exam offered in?
English, Japanese, Korean, Portuguese (Brazil), Simplified Chinese and Spanish (Latin America). AWS retires the Simplified Chinese, Spanish and Portuguese versions after December 31, 2026.
Does HOW TO // AI have SCS-C03 practice questions?
Not yet. Start with AWS's free Official Practice Question Set on AWS Skill Builder, which shows the real question style, and avoid anything sold as real exam questions.




