SailPoint Certified Identity Security Engineer banner showing an engineer at a console before a network of glowing identity nodes

SailPoint Certified Identity Security Engineer: Ten Areas, No Weightings

The SailPoint Certified Identity Security Engineer is SailPoint’s professional-level credential for engineers who build and run Identity Security Cloud, the vendor’s SaaS identity governance platform. It is a 73 question paper, you get 120 minutes, and it costs $400. What makes it unusual is what SailPoint does not tell you: the blueprint lists ten objective areas and attaches a weighting to none of them. Every other decision you make about preparing follows from that one fact. You cannot decide that virtual appliances are only worth five percent and skip them, because nobody has said they are. This article covers what those ten areas ask, what the exam costs in money and time, how it differs from the older IdentityIQ Engineer exam, how long the credential lasts, and how to plan study with nothing to triage against.

What Does the SailPoint Certified Identity Security Engineer Prove?

It proves you can implement identity governance in SailPoint Identity Security Cloud rather than merely describe it. The blueprint is written in scenario language: given an HR source, order the steps; given a business case, judge whether a lifecycle design is valid; given an error, find the cause. SailPoint expects roughly a year of hands-on work before you sit it.

That phrasing matters more than it looks. An exam that says “define federation” wants a definition. An exam that says “propose a solution for lifecycle state change requirements” wants judgement, and judgement is much harder to fake from a study guide. Read through the objectives and you find verbs like troubleshoot, deduce, analyze, recommend and propose far more often than list or name.

Who actually sits it

Three groups, in practice. Implementation consultants at SailPoint partners, where the credential is often a delivery requirement. In-house IAM engineers whose organisation has moved from on-premises IdentityIQ to the cloud platform. And IdentityIQ practitioners who want the cloud credential on their profile before their next role hunt. All three arrive with product experience already, which is why the exam can afford to skip the basics.

The credential also sits inside a programme that has grown quickly. SailPoint’s own account of it is direct.

“By renewing and expanding their knowledge, participants can not only uphold the value of their certification but also contribute to a stronger, more knowledgeable ecosystem of identity security professionals. The number of SailPoint Certified professionals has quadrupled over the last year.”

Meredith Blanchar, Chief Customer Officer at SailPoint

A fourfold rise in a year tells you two things. The credential is becoming a normal expectation rather than a differentiator, and the pool of people you are competing against for SailPoint roles is getting larger and better qualified.

What Is on the Exam, and What Does It Cost?

The exam presents 73 questions in 120 minutes for $400 USD, and it is graded pass or fail with no published percentage threshold. It is scheduled directly through SailPoint rather than a third-party test centre. Ten objective areas are listed on the blueprint, and none of them carries a stated weighting.

Exam detailValue
CertificationSailPoint Certified Identity Security Engineer
Questions73
Duration120 minutes
Price$400 USD
ResultPass or fail
SchedulingSailPoint
Objective areas10, unweighted
Recommended experienceAbout one year hands-on

Do the arithmetic and you have 98 seconds per question. That sounds generous until you remember the scenario framing. A question that opens with a paragraph about an HR feed, two identity profiles and a correlation problem eats thirty seconds before you have read the options. The timing is comfortable only if you already know the product well enough to skim.

The full objective list is published on the official credential page, and it is worth reading in the vendor’s own words before you commit the $400.

Why Are There No Domain Weightings, and What Does That Change?

Most certification blueprints tell you a domain is worth 25% so you can budget study time against it. SailPoint publishes ten objective areas for this exam and no percentages at all. The practical consequence is that no area can be safely deprioritised, because a single weak area could plausibly account for enough questions to fail you.

Candidates handle this badly in a predictable way. They study the areas they already work in, which for most engineers means lifecycle management and provisioning, and they skim the ones they have never touched, which is usually virtual appliances and rules. That is exactly the wrong allocation. Familiar material has diminishing returns; unfamiliar material is where the marks are lost.

A better default assumption

Treat the ten areas as roughly equal until evidence says otherwise. Ten areas across 73 questions averages about seven questions each. Seven questions is enough to matter and small enough that a single blind spot is survivable, which is a reassuring way to think about it: you do not need to be excellent everywhere, but you cannot be absent anywhere.

Objective areaWhat it is really testing
Identity and Lifecycle ManagementIdentity profiles, attribute mapping, joiner and leaver states, manager correlation
ProvisioningPredicting provisioning outcomes, attribute sync, multi-account behaviour, error diagnosis
Access ManagementReminders and escalation, segments, testing access changes safely
Virtual AppliancesDeployment topology, cluster keys, logging, networking, high availability
SourcesConnector choice, Active Directory and JDBC configuration, aggregation flow, data residency
General knowledgeGovernance concepts, authentication against authorization, federation, REST APIs
PlatformsAPI gateway, identity search, workflow ordering, email configuration, monitoring
Supporting GovernanceCertification campaigns, approver options, separation of duties
ArchitectureEncryption at rest and in transit, tenant behaviour, component redundancy
Rules and TransformsWhat is achievable with a transform, rule syntax, when to use which

What Do the Identity, Provisioning and Access Areas Ask?

These three areas cover the everyday work of the platform: getting identities in, getting entitlements out, and controlling who approves what along the way. The questions are scenario-driven and frequently ask you to predict an outcome, order a set of steps correctly, or diagnose why something failed rather than recite configuration options.

Identity and lifecycle management

Expect to be handed a source containing both employees and contractors and asked how many identity profiles are needed and in what priority order. That single question type covers most of the area. You also need attribute mapping, including which attributes are the irreducible minimum, plus manager correlation and the joiner and leaver states that hang off prehire, hire, termination and post-termination events.

Provisioning

The signature question gives you a current access state and a provisioning transaction and asks what the resulting state will be. Getting those right depends on understanding role assignment types and how de-provisioning behaves differently for each. Troubleshooting appears repeatedly, and so does the distinction between attribute sync and true provisioning, which is a common source of confusion in real deployments as well as in the exam.

Access management and governance

Smaller in scope but easy to lose marks on because it is procedural. Reminder and escalation patterns, when a segment is the right tool, and on the governance side, choosing the right certification campaign type for a stated business requirement. Separation of duties turns up here too, in the form of when to apply it rather than what it means. The underlying concepts of authentication, authorization and federation that the general-knowledge area tests are defined formally in the NIST digital identity guidelines, which is a useful reference if your grounding in them is informal.

Provisioning to and from external systems increasingly runs over a standard rather than a bespoke connector, and the SCIM provisioning standard is the one to know. It will not be named in a question, but understanding how a standards-based provisioning protocol models users and groups makes the connector material considerably easier to reason about.

How Much Infrastructure Does the Virtual Appliance Area Expect?

More than most candidates expect. The virtual appliance is the component that bridges Identity Security Cloud to on-premises systems, and its objective area is one of the longest on the blueprint. You need deployment options, configuration steps, networking, where log files live, common commands, cluster key behaviour, and the trade-offs of running appliances in high availability and disaster recovery patterns.

This is the area that separates engineers who have built a deployment from engineers who have only administered one. If somebody else stood up your virtual appliances, this is where your preparation has to go, and no amount of familiarity with the admin console will substitute for it.

The parts people miss

  • Which keys the appliance holds, how they are generated, and at what point they are set across a cluster
  • Where on the appliance to look when something fails, and which command tells you what
  • Why you would place an appliance in one network segment rather than another
  • What is and is not permitted to be installed on the appliance, and the reasoning behind it

That last point is worth dwelling on. The blueprint asks you to judge whether a described installation on a virtual appliance is valid and to say why. It is a question about the support boundary as much as about technology, and the answer is usually more restrictive than engineers assume.

Platforms and APIs

Adjacent to the appliance material sits the platform area, which covers the API gateway, how to authenticate against it, identity search syntax, workflow step ordering, email configuration and monitoring practice. The general-knowledge area separately asks you to leverage REST APIs, so a working familiarity with the request and response shapes in the SailPoint API documentation pays for itself twice over.

Is This the Same as the IdentityIQ Engineer Exam?

No. They are different exams for different products. The Certified IdentityIQ Engineer covers IdentityIQ, SailPoint’s on-premises identity governance software. The Certified Identity Security Engineer covers Identity Security Cloud, the SaaS platform. Holding one does not grant the other, and the objective areas overlap only at the level of governance concepts.

The confusion is understandable because the underlying discipline is the same. Identity profiles, certification campaigns and separation of duties exist in both worlds. What differs is everything about how you implement them: the cloud exam’s virtual appliance, multi-tenant architecture, API gateway and transform material has no direct IdentityIQ equivalent, and IdentityIQ’s application onboarding and workflow engine specifics are not on the cloud paper.

QuestionIdentity Security EngineerIdentityIQ Engineer
ProductIdentity Security Cloud (SaaS)IdentityIQ (on-premises)
Infrastructure focusVirtual appliances and tenant architectureApplication server deployment
Customisation modelRules and transformsIdentityIQ rules and workflows
Shared groundGovernance concepts and campaignsGovernance concepts and campaigns

If you already hold the IdentityIQ credential, the SailPoint IdentityIQ Engineer route is worth revisiting for how the two credentials sit in a career path. The short version: choose by which product your organisation actually runs, not by which exam looks easier.

How Long Is the Certification Valid, and How Do You Renew It?

SailPoint certifications are valid for two years. Since early 2026 there has been a formal recertification route that extends a credential for a further two years without retaking the exam. It requires 80 recertification credits and carries a $200 USD recertification fee, and the credits are earned through SailPoint learning activities, community contribution and project work.

SailPoint Certified Identity Security Engineer recertification path: pass for two years, earn 80 credits, then renew for two more years

Two years is short by industry standards, and that is deliberate for a SaaS product that ships continuously. The recertification path is the more interesting change, because before it existed the only way to stay current was to sit the exam again. Earning credits through work you would arguably do anyway is a considerably lower barrier than a second $400 attempt.

Where the credential sits now

SailPoint added a Certified Identity Security Administrator exam in February 2026, the seventh in its certification programme. That matters for planning: the administrator credential is the lighter entry point for people who operate the platform rather than build on it, and it is a more sensible first step if a year of engineering experience is not something you can honestly claim yet. Full detail on both changes is in the SailPoint recertification announcement.

How Should You Prepare With No Weightings to Guide You?

Build the plan around coverage rather than priority. With ten unweighted areas and roughly seven questions each, the goal is to eliminate blind spots rather than to master favourites. The sequence below works because it front-loads the areas most candidates have never touched, while the areas you use daily need review rather than learning.

Four step study order for the SailPoint Certified Identity Security Engineer exam: audit all ten areas, learn virtual appliances, write a transform, then timed practice
  1. Audit yourself against the ten objective areas first, scoring each one honestly as daily work, occasional work, or never touched, because the never-touched list is your actual syllabus.
  2. Start with virtual appliances, since it is the longest objective area and the one most often owned by somebody else on the team.
  3. Work through rules and transforms next, writing a transform and a rule by hand rather than reading about them, because the blueprint asks what is achievable with each and that judgement only comes from trying.
  4. Rebuild a lifecycle end to end in a sandbox, taking one identity from prehire through hire to termination and watching what provisions and de-provisions at each state change.
  5. Deliberately break something and diagnose it, since troubleshooting verbs appear in five of the ten areas and cannot be revised passively.
  6. Read the architecture and governance material last, because it is conceptual, it revises quickly, and it will still be fresh on exam day.
  7. Finish with timed practice at roughly 98 seconds a question, reviewing every wrong answer against the objective area it came from so gaps surface as areas rather than as isolated mistakes.

For the last step, working SailPoint sample questions in the exam’s own scenario style is more useful than re-reading objectives, because the difficulty of this paper lives in parsing the scenario rather than in recalling the fact.

Frequently Asked Questions

How many questions are on the SailPoint Identity Security Engineer exam?

There are 73 questions and you have 120 minutes, which works out at about 98 seconds each. The questions are scenario-based, so a meaningful share of that time goes on reading rather than answering.

How much does the SailPoint certification cost?

The exam is $400 USD. Recertification later costs a further $200 USD alongside 80 recertification credits, so budget for the renewal as well as the first attempt if you plan to keep the credential current.

What is the passing score?

SailPoint reports the result as pass or fail and does not publish a percentage threshold. Because no objective area carries a weighting either, there is no way to work backwards to a safe minimum in any single area.

How long is the SailPoint Certified Identity Security Engineer valid?

Two years. Since 2026 you can extend it for another two years through the recertification programme by earning 80 credits and paying the recertification fee, instead of sitting the full exam again.

Do you need experience before taking this exam?

SailPoint recommends about a year of hands-on work with Identity Security Cloud. There is no enforced prerequisite, but the blueprint is written in scenario language that assumes you have configured the platform rather than only read about it.

Is this exam the same as the IdentityIQ Engineer certification?

No. This one covers Identity Security Cloud, the SaaS platform, while the IdentityIQ Engineer exam covers the on-premises product. Neither credential grants the other, and the infrastructure and customisation material differs substantially.

Which objective area is hardest?

Most candidates find virtual appliances hardest, because deployment work is often done once by one person and never revisited. It is also one of the longest areas on the blueprint, covering topology, cluster keys, logging and networking.

Where do you book the exam?

Through SailPoint directly rather than a third-party test centre network. That also means exam logistics, rescheduling and results all run through SailPoint’s own certification programme.

Should you take the Identity Security Administrator exam first?

It is a sensible first step if you operate the platform rather than build on it, or if you cannot yet claim a year of engineering experience. It was added in February 2026 as the seventh exam in the programme.

Does the exam test REST API knowledge?

Yes, in two places. The general-knowledge area asks you to leverage REST APIs, and the platforms area covers the API gateway and how to authenticate against it. Practical familiarity with the API is worth building.

Conclusion

The missing weightings are the defining feature of this exam, and they change how you prepare rather than how hard it is. Ten objective areas, roughly seven questions apiece, and no way to know which ones you can afford to be weak in: the only sane response is even coverage, with extra time spent on the areas your day job never sends you near. For most engineers that means virtual appliances and transforms, not lifecycle management. Add the two-year validity and the recertification credits to your planning from the start, because the credential is a commitment rather than a one-off. When your coverage feels even, move to timed scenario practice and let the wrong answers tell you which of the ten areas still needs work.

Rating: 0 / 5 (0 votes)