SCS-C03 AWS Security Specialty banner showing a security engineer in an operations room facing a wall of monitoring screens

SCS-C02 vs SCS-C03: What Changed in AWS Security Specialty

On 2 December 2025, AWS replaced SCS-C02 with SCS-C03 as the live version of the AWS Certified Security – Specialty exam, and more than the code moved. Identity and Access Management rose from 16 to 20 percent of scored content, Infrastructure Security fell from 20 to 18, and the two older domains that mixed threat detection, logging and response were rebuilt as Detection and Incident Response.

AWS also wrote seven new pieces of content into the blueprint, including guardrails for generative AI applications, and took out a long list of fundamentals such as TCP/IP basics and host-based firewalls. If you studied for the old version, or you are reading notes written for it, this SCS-C02 vs SCS-C03 comparison shows what still counts, what is gone and where to spend the hours you have left. Every change listed here comes from the comparison AWS publishes in its own exam guide.

Table of Contents

  1. What changed between SCS-C02 and SCS-C03?
  2. What does the SCS-C03 exam look like on the day?
  3. Which topics are new in SCS-C03?
  4. What did AWS remove from the exam?
  5. Where do the six SCS-C03 domains put their weight?
  6. Who is the SCS-C03 exam written for?
  7. How should an SCS-C02 candidate adjust a study plan?
  8. How long does the certification last, and which languages are ending?
  9. Frequently Asked Questions
  10. Conclusion

What changed between SCS-C02 and SCS-C03?

SCS-C03 keeps six domains but reshapes them. AWS split the old threat detection, incident response, logging and monitoring material into two cleaner domains called Detection and Incident Response, raised Identity and Access Management from 16 to 20 percent, cut Infrastructure Security from 20 to 18 percent, and renamed the governance domain Security Foundations and Governance.

AWS sets the two blueprints side by side in its SCS-C02 and SCS-C03 comparison, which states that SCS-C02 was in use until 1 December 2025 and SCS-C03 from the following day.

PositionSCS-C02 domainSCS-C02 weightSCS-C03 domainSCS-C03 weight
1Threat Detection and Incident Response14%Detection16%
2Security Logging and Monitoring18%Incident Response14%
3Infrastructure Security20%Infrastructure Security18%
4Identity and Access Management16%Identity and Access Management20%
5Data Protection18%Data Protection18%
6Management and Security Governance14%Security Foundations and Governance14%

The first two domains were rebuilt, not renamed

Do not read the first two rows as a simple swap. Under SCS-C02, logging sat in its own domain and detection shared a domain with response. Under SCS-C03, monitoring, alerting and logging all live in Detection, while planning for and responding to an event live in Incident Response. Together the pair still carries 30 percent. The old pair carried 32.

Identity is now the heaviest domain

Infrastructure Security used to lead at 20 percent. Identity and Access Management now holds that position, and it is the only domain that gained four points. Data Protection and governance kept their weights exactly.

“To better serve security professionals, we’ve restructured the exam domains, creating distinct sections for Detection and Incident Response capabilities.”

Tim Trsar, AWS Training and Certification Blog

What does the SCS-C03 exam look like on the day?

The SCS-C03 exam has 65 questions and lasts 170 minutes. It costs 300 USD and the minimum passing score is 750 on a scale of 100 to 1,000. Only 50 of the 65 questions affect your score. The other 15 are unscored items that AWS is trialling, and they are not identified on the exam.

FieldValue
Exam nameAWS Certified Security – Specialty
Exam codeSCS-C03
Questions65 (50 scored, 15 unscored)
Duration170 minutes
Passing score750 on a scale of 100 to 1,000
Price300 USD
DeliveryPearson VUE testing center or online proctored exam
CategorySpecialty

How the score works

AWS uses a compensatory scoring model. That means you do not need to pass each domain separately, only the exam as a whole, so a strong identity score can cover a weaker incident response score. Unanswered questions count as incorrect and there is no penalty for guessing. Never leave a question blank.

Question types

The exam guide lists four response types:

  • Multiple choice, with one correct response and three distractors.
  • Multiple response, with two or more correct responses out of five or more options.
  • Ordering, where you pick 3 to 5 responses and place them in the correct order.
  • Matching, where you pair responses with a list of 3 to 7 prompts.

Ordering and matching give no partial credit. Every position or pair must be right. On pacing, 170 minutes across 65 questions is a little over two and a half minutes each, which sounds generous until you meet a question built around an IAM policy document. Working a set of SCS-C03 sample questions early shows you how long those scenario items really take to read.

Which topics are new in SCS-C03?

AWS added seven items to SCS-C03. They cover validating findings during an incident, integrating edge services with third-party tools, guardrails for generative AI applications, encryption in transit between resources, imported key material, masking sensitive data, and managing keys and certificates across Regions. Four of the seven sit in the Data Protection domain.

TaskDomainWhat was added
2.2.3Incident ResponseValidate findings from AWS security services to assess the scope and impact of an event
3.1.4Infrastructure SecurityConfigure integrations with AWS edge services and third-party services
3.2.7Infrastructure SecurityImplement protections and guardrails for generative AI applications
5.1.3Data ProtectionDesign and configure inter-resource encryption in transit
5.3.3Data ProtectionDescribe the differences between imported key material and AWS generated key material
5.3.4Data ProtectionMask sensitive data
5.3.5Data ProtectionCreate and manage encryption keys and certificates across a single Region or multiple Regions

Generative AI guardrails

This is the addition that gets the attention. The blueprint gives one example for it: applying the protections in the OWASP LLM Top 10. The 2025 edition of that list opens with prompt injection and sensitive information disclosure, and also covers supply chain risk and excessive agency. Keep it in proportion, though. It is one task inside an 18 percent domain, and training machine learning models is explicitly out of scope for the target candidate.

OCSF and third-party edge tools

Task 3.1.4 names the Open Cybersecurity Schema Framework as its example, alongside third-party WAF rules. OCSF is an open, vendor-neutral format for security events, and the OCSF schema project publishes it in the open. Amazon Security Lake, which the Detection domain also names, is the service where candidates usually meet it.

Keys, masking and multi-Region

The Data Protection additions are practical. You should be able to explain how imported key material differs from key material that AWS KMS generates, mask sensitive values with CloudWatch Logs data protection policies or Amazon SNS message data protection, and manage customer managed keys and AWS Private Certificate Authority across Regions. Inter-node encryption for Amazon EMR, Amazon EKS and SageMaker AI is named as well.

What did AWS remove from the exam?

AWS removed a set of fundamentals and older references from SCS-C03. The published deletions include TCP/IP networking concepts, host-based security, the components of an IAM policy, TLS concepts, the AWS Security Finding Format, the AWS Security Incident Response Guide, log format and components, and configuring S3 static website hosting.

SCS-C03 study triage showing what to keep, what to drop and what to add after SCS-C02

The full list of published deletions, grouped by the SCS-C02 task each one came from:

  • Task 1.1: AWS Security Finding Format (ASFF).
  • Task 1.3: the AWS Security Incident Response Guide.
  • Task 2.5: log format and components, such as CloudTrail logs.
  • Task 3.3: host-based security and activating host-based firewalls.
  • Task 3.4: analysing reachability, fundamental TCP/IP networking concepts, and prioritising problems in network connectivity.
  • Task 4.2: the components and impact of a policy, such as Principal, Action, Resource and Condition.
  • Task 5.1: TLS concepts, and cross-Region networking with private and public VIFs.
  • Task 5.2: configuring S3 static website hosting.
  • Task 6.4: identifying security gaps through architectural reviews and cost analysis.

Removed from the list is not the same as safe to skip

Read the pattern before you delete your notes. Most of what left is knowledge a working engineer already has. The exam no longer asks you to describe the parts of a policy, yet it still asks you to design, interpret and implement IAM policies and to analyse authorization failures. You cannot do that without knowing what a Condition block does.

The same holds for networking. OSI layers are gone as a topic, while security groups, network ACLs, AWS Network Firewall and segmentation remain. Treat the deletions as AWS raising the floor, not shrinking the syllabus.

Where do the six SCS-C03 domains put their weight?

The six SCS-C03 domains are Detection at 16 percent, Incident Response at 14, Infrastructure Security at 18, Identity and Access Management at 20, Data Protection at 18, and Security Foundations and Governance at 14. The weights apply to scored content, so they describe the 50 scored questions and not all 65.

DomainWeightTask statements
Detection16%Monitoring and alerting solutions; logging solutions; troubleshooting monitoring, logging and alerting
Incident Response14%Design and test an incident response plan; respond to security events
Infrastructure Security18%Network edge services; compute workloads; network security controls
Identity and Access Management20%Authentication strategies; authorization strategies
Data Protection18%Data in transit; data at rest; confidential data, credentials, secrets and cryptographic key materials
Security Foundations and Governance14%Centrally deploy and manage AWS accounts; consistent deployment strategy; evaluate compliance

Two task statements carry a fifth of the exam

Identity and Access Management has only two task statements, authentication and authorization, yet it holds the largest share. That makes it the densest domain on the blueprint. Expect IAM Identity Center, Amazon Cognito, AWS STS, permission boundaries, session policies, IAM Roles Anywhere and IAM Access Analyzer to appear in scenario form.

Governance is about many accounts, not one

Security Foundations and Governance assumes an organization, not a single account. Its examples include AWS Organizations, AWS Control Tower, service control policies, resource control policies, AI service opt-out policies and centralised root access for member accounts. If your experience is limited to one account, this is the domain to practise in a sandbox organization.

Who is the SCS-C03 exam written for?

The SCS-C03 exam guide describes a target candidate with the equivalent of 3 to 5 years of experience securing cloud solutions. AWS requires no earlier certification before you sit the exam. Its certification page adds that candidates commonly hold AWS Certified Solutions Architect – Associate or Professional first.

AWS words the experience in a second way on the certification page: five years of IT security experience designing and implementing security solutions, plus two or more years of hands-on work securing AWS workloads. Both descriptions point at the same person, someone who has already run security in production.

What AWS expects you to know already

  • The shared responsibility model and how it applies.
  • Managing identity at scale and multi-account governance.
  • Software supply chain risk and vulnerability management in the cloud.
  • Firewall rules at scale for layers 3 to 7.
  • Incident root cause analysis and responding to an audit.
  • Encryption at rest and in transit, plus backup and disaster recovery controls.

What is out of scope

The guide also lists job tasks the candidate is not expected to perform: designing cryptographic algorithms, analysing traffic at packet level, architecting overall cloud deployments, managing end-user compute resources and training machine learning models. That list is useful when a study resource drifts into packet captures or model training. You can stop reading.

If you want the older blueprint for reference, this site’s earlier SCS-C02 exam walkthrough shows how the previous version was organised, which makes the changes above easier to see.

How should an SCS-C02 candidate adjust a study plan?

An SCS-C02 candidate moving to SCS-C03 should keep most existing notes and re-sort them. Start by mapping old material to the six new domains, then add the seven new tasks, give Identity and Access Management the most time, and practise ordering and matching questions, since both need every part correct to score.

A four phase move from SCS-C02 to SCS-C03: sort notes into six domains, add seven new tasks, focus on IAM at 20 percent, then test 65 questions in 170 minutes
  1. Re-file your notes under the six SCS-C03 domain names, moving all logging and monitoring material into Detection and all response material into Incident Response.
  2. Write one page for each of the seven added tasks, using the example services AWS names for each.
  3. Give Identity and Access Management the largest block of study time, because it now holds 20 percent of scored content.
  4. Build a multi-account sandbox with AWS Organizations and practise service control policies, delegated administrators and centralised root access.
  5. Practise ordering and matching questions until you can sequence an incident response without hesitating.
  6. Sit a full timed set of 65 questions in 170 minutes and review every miss by domain.

What carries over unchanged

Data Protection kept its 18 percent and governance kept its 14. Encryption at rest, S3 Object Lock, AWS Secrets Manager, AWS Config, AWS Audit Manager and AWS Firewall Manager all remain. Work you did on those topics for SCS-C02 still pays.

A caution on old material

Search results still surface plenty of SCS-C02 and even SCS-C01 content. Before trusting a resource, check that it names Detection and Incident Response as separate domains. If it lists Security Logging and Monitoring as a domain, it was written for the retired blueprint.

How long does the certification last, and which languages are ending?

AWS Certified Security – Specialty is valid for 3 years, and you recertify by passing the latest version of the exam. AWS offers SCS-C03 in six languages today, but the Simplified Chinese, Spanish (Latin America) and Portuguese (Brazil) versions will be retired after 31 December 2026. English, Japanese and Korean are not part of that notice.

Both facts come from the AWS certification page. If you planned to sit the exam in one of the three retiring languages, the practical deadline is the end of December 2026. After that date you would need to take it in one of the remaining languages.

Cost of the next exam

AWS states that once you hold one AWS Certification, you receive a 50 percent discount on your next AWS Certification exam, claimed through your AWS Certification Account. For a holder of an Associate credential, that halves the 300 USD fee.

Where the credential leads

AWS names AWS Certified DevOps Engineer – Professional and AWS Certified Advanced Networking – Specialty as certifications that professionals earn afterwards, on the way to roles such as DevSecOps Engineer or Networking Engineer. For a wider view of how AWS credentials fit a career, see this site’s piece on AWS certification career value.

Frequently Asked Questions

Is SCS-C02 still available?

No. AWS states that SCS-C02 was in use until 1 December 2025 and that SCS-C03 has been in use since 2 December 2025. Anyone booking the exam now sits SCS-C03.

How many questions are on the SCS-C03 exam?

There are 65 questions. Fifty affect your score and 15 are unscored questions that AWS is evaluating for future use. The unscored questions are not identified, so answer all 65 with equal care.

What is the passing score for SCS-C03?

The minimum passing score is 750 on a scaled range of 100 to 1,000. Scoring is compensatory, so you need to pass the exam overall and not each domain separately.

How much does the AWS Security Specialty exam cost?

The exam costs 300 USD. AWS gives holders of an active AWS Certification a 50 percent discount on their next exam, claimed through the AWS Certification Account.

Which domain has the highest weight in SCS-C03?

Identity and Access Management, at 20 percent of scored content. It was 16 percent under SCS-C02. Infrastructure Security and Data Protection follow at 18 percent each.

Does SCS-C03 test generative AI?

Yes, in one task. Task 3.2.7 asks you to implement protections and guardrails for generative AI applications, with the OWASP Top 10 for LLM Applications as the example. Training machine learning models is out of scope.

Do I need another AWS certification before SCS-C03?

No. AWS requires no specific certification first. It notes that candidates commonly earn AWS Certified Solutions Architect – Associate or Professional before attempting the Security Specialty exam.

How long is AWS Certified Security – Specialty valid?

The certification is valid for 3 years. Before it expires, you can recertify by passing the latest version of the exam.

Which SCS-C03 exam languages are being retired?

AWS will retire the Simplified Chinese, Spanish (Latin America) and Portuguese (Brazil) versions after 31 December 2026. The exam is also offered in English, Japanese and Korean.

Conclusion

SCS-C03 is the same size as the exam it replaced: 65 questions, 170 minutes, 750 to pass. What changed is where the marks sit. Identity and Access Management is now the largest domain at 20 percent, detection and response each have a domain of their own, and seven new tasks bring in generative AI guardrails, OCSF, imported key material and data masking.

For anyone holding SCS-C02 notes, that is good news. Most of the material survives, and the published deletions are fundamentals you still use every day. Re-sort what you have, add the seven new tasks, and put your extra hours into identity and multi-account governance. Then test the plan against timed scenario questions before you book.

Rating: 0 / 5 (0 votes)