On 2 December 2025, AWS replaced SCS-C02 with SCS-C03 as the live version of the AWS Certified Security – Specialty exam, and more than the code moved. Identity and Access Management rose from 16 to 20 percent of scored content, Infrastructure Security fell from 20 to 18, and the two older domains that mixed threat detection, logging and response were rebuilt as Detection and Incident Response.
AWS also wrote seven new pieces of content into the blueprint, including guardrails for generative AI applications, and took out a long list of fundamentals such as TCP/IP basics and host-based firewalls. If you studied for the old version, or you are reading notes written for it, this SCS-C02 vs SCS-C03 comparison shows what still counts, what is gone and where to spend the hours you have left. Every change listed here comes from the comparison AWS publishes in its own exam guide.
Table of Contents
- What changed between SCS-C02 and SCS-C03?
- What does the SCS-C03 exam look like on the day?
- Which topics are new in SCS-C03?
- What did AWS remove from the exam?
- Where do the six SCS-C03 domains put their weight?
- Who is the SCS-C03 exam written for?
- How should an SCS-C02 candidate adjust a study plan?
- How long does the certification last, and which languages are ending?
- Frequently Asked Questions
- Conclusion
What changed between SCS-C02 and SCS-C03?
SCS-C03 keeps six domains but reshapes them. AWS split the old threat detection, incident response, logging and monitoring material into two cleaner domains called Detection and Incident Response, raised Identity and Access Management from 16 to 20 percent, cut Infrastructure Security from 20 to 18 percent, and renamed the governance domain Security Foundations and Governance.
AWS sets the two blueprints side by side in its SCS-C02 and SCS-C03 comparison, which states that SCS-C02 was in use until 1 December 2025 and SCS-C03 from the following day.
| Position | SCS-C02 domain | SCS-C02 weight | SCS-C03 domain | SCS-C03 weight |
|---|---|---|---|---|
| 1 | Threat Detection and Incident Response | 14% | Detection | 16% |
| 2 | Security Logging and Monitoring | 18% | Incident Response | 14% |
| 3 | Infrastructure Security | 20% | Infrastructure Security | 18% |
| 4 | Identity and Access Management | 16% | Identity and Access Management | 20% |
| 5 | Data Protection | 18% | Data Protection | 18% |
| 6 | Management and Security Governance | 14% | Security Foundations and Governance | 14% |
The first two domains were rebuilt, not renamed
Do not read the first two rows as a simple swap. Under SCS-C02, logging sat in its own domain and detection shared a domain with response. Under SCS-C03, monitoring, alerting and logging all live in Detection, while planning for and responding to an event live in Incident Response. Together the pair still carries 30 percent. The old pair carried 32.
Identity is now the heaviest domain
Infrastructure Security used to lead at 20 percent. Identity and Access Management now holds that position, and it is the only domain that gained four points. Data Protection and governance kept their weights exactly.
“To better serve security professionals, we’ve restructured the exam domains, creating distinct sections for Detection and Incident Response capabilities.”
What does the SCS-C03 exam look like on the day?
The SCS-C03 exam has 65 questions and lasts 170 minutes. It costs 300 USD and the minimum passing score is 750 on a scale of 100 to 1,000. Only 50 of the 65 questions affect your score. The other 15 are unscored items that AWS is trialling, and they are not identified on the exam.
| Field | Value |
|---|---|
| Exam name | AWS Certified Security – Specialty |
| Exam code | SCS-C03 |
| Questions | 65 (50 scored, 15 unscored) |
| Duration | 170 minutes |
| Passing score | 750 on a scale of 100 to 1,000 |
| Price | 300 USD |
| Delivery | Pearson VUE testing center or online proctored exam |
| Category | Specialty |
How the score works
AWS uses a compensatory scoring model. That means you do not need to pass each domain separately, only the exam as a whole, so a strong identity score can cover a weaker incident response score. Unanswered questions count as incorrect and there is no penalty for guessing. Never leave a question blank.
Question types
The exam guide lists four response types:
- Multiple choice, with one correct response and three distractors.
- Multiple response, with two or more correct responses out of five or more options.
- Ordering, where you pick 3 to 5 responses and place them in the correct order.
- Matching, where you pair responses with a list of 3 to 7 prompts.
Ordering and matching give no partial credit. Every position or pair must be right. On pacing, 170 minutes across 65 questions is a little over two and a half minutes each, which sounds generous until you meet a question built around an IAM policy document. Working a set of SCS-C03 sample questions early shows you how long those scenario items really take to read.
Which topics are new in SCS-C03?
AWS added seven items to SCS-C03. They cover validating findings during an incident, integrating edge services with third-party tools, guardrails for generative AI applications, encryption in transit between resources, imported key material, masking sensitive data, and managing keys and certificates across Regions. Four of the seven sit in the Data Protection domain.
| Task | Domain | What was added |
|---|---|---|
| 2.2.3 | Incident Response | Validate findings from AWS security services to assess the scope and impact of an event |
| 3.1.4 | Infrastructure Security | Configure integrations with AWS edge services and third-party services |
| 3.2.7 | Infrastructure Security | Implement protections and guardrails for generative AI applications |
| 5.1.3 | Data Protection | Design and configure inter-resource encryption in transit |
| 5.3.3 | Data Protection | Describe the differences between imported key material and AWS generated key material |
| 5.3.4 | Data Protection | Mask sensitive data |
| 5.3.5 | Data Protection | Create and manage encryption keys and certificates across a single Region or multiple Regions |
Generative AI guardrails
This is the addition that gets the attention. The blueprint gives one example for it: applying the protections in the OWASP LLM Top 10. The 2025 edition of that list opens with prompt injection and sensitive information disclosure, and also covers supply chain risk and excessive agency. Keep it in proportion, though. It is one task inside an 18 percent domain, and training machine learning models is explicitly out of scope for the target candidate.
OCSF and third-party edge tools
Task 3.1.4 names the Open Cybersecurity Schema Framework as its example, alongside third-party WAF rules. OCSF is an open, vendor-neutral format for security events, and the OCSF schema project publishes it in the open. Amazon Security Lake, which the Detection domain also names, is the service where candidates usually meet it.
Keys, masking and multi-Region
The Data Protection additions are practical. You should be able to explain how imported key material differs from key material that AWS KMS generates, mask sensitive values with CloudWatch Logs data protection policies or Amazon SNS message data protection, and manage customer managed keys and AWS Private Certificate Authority across Regions. Inter-node encryption for Amazon EMR, Amazon EKS and SageMaker AI is named as well.
What did AWS remove from the exam?
AWS removed a set of fundamentals and older references from SCS-C03. The published deletions include TCP/IP networking concepts, host-based security, the components of an IAM policy, TLS concepts, the AWS Security Finding Format, the AWS Security Incident Response Guide, log format and components, and configuring S3 static website hosting.

The full list of published deletions, grouped by the SCS-C02 task each one came from:
- Task 1.1: AWS Security Finding Format (ASFF).
- Task 1.3: the AWS Security Incident Response Guide.
- Task 2.5: log format and components, such as CloudTrail logs.
- Task 3.3: host-based security and activating host-based firewalls.
- Task 3.4: analysing reachability, fundamental TCP/IP networking concepts, and prioritising problems in network connectivity.
- Task 4.2: the components and impact of a policy, such as Principal, Action, Resource and Condition.
- Task 5.1: TLS concepts, and cross-Region networking with private and public VIFs.
- Task 5.2: configuring S3 static website hosting.
- Task 6.4: identifying security gaps through architectural reviews and cost analysis.
Removed from the list is not the same as safe to skip
Read the pattern before you delete your notes. Most of what left is knowledge a working engineer already has. The exam no longer asks you to describe the parts of a policy, yet it still asks you to design, interpret and implement IAM policies and to analyse authorization failures. You cannot do that without knowing what a Condition block does.
The same holds for networking. OSI layers are gone as a topic, while security groups, network ACLs, AWS Network Firewall and segmentation remain. Treat the deletions as AWS raising the floor, not shrinking the syllabus.
Where do the six SCS-C03 domains put their weight?
The six SCS-C03 domains are Detection at 16 percent, Incident Response at 14, Infrastructure Security at 18, Identity and Access Management at 20, Data Protection at 18, and Security Foundations and Governance at 14. The weights apply to scored content, so they describe the 50 scored questions and not all 65.
| Domain | Weight | Task statements |
|---|---|---|
| Detection | 16% | Monitoring and alerting solutions; logging solutions; troubleshooting monitoring, logging and alerting |
| Incident Response | 14% | Design and test an incident response plan; respond to security events |
| Infrastructure Security | 18% | Network edge services; compute workloads; network security controls |
| Identity and Access Management | 20% | Authentication strategies; authorization strategies |
| Data Protection | 18% | Data in transit; data at rest; confidential data, credentials, secrets and cryptographic key materials |
| Security Foundations and Governance | 14% | Centrally deploy and manage AWS accounts; consistent deployment strategy; evaluate compliance |
Two task statements carry a fifth of the exam
Identity and Access Management has only two task statements, authentication and authorization, yet it holds the largest share. That makes it the densest domain on the blueprint. Expect IAM Identity Center, Amazon Cognito, AWS STS, permission boundaries, session policies, IAM Roles Anywhere and IAM Access Analyzer to appear in scenario form.
Governance is about many accounts, not one
Security Foundations and Governance assumes an organization, not a single account. Its examples include AWS Organizations, AWS Control Tower, service control policies, resource control policies, AI service opt-out policies and centralised root access for member accounts. If your experience is limited to one account, this is the domain to practise in a sandbox organization.
Who is the SCS-C03 exam written for?
The SCS-C03 exam guide describes a target candidate with the equivalent of 3 to 5 years of experience securing cloud solutions. AWS requires no earlier certification before you sit the exam. Its certification page adds that candidates commonly hold AWS Certified Solutions Architect – Associate or Professional first.
AWS words the experience in a second way on the certification page: five years of IT security experience designing and implementing security solutions, plus two or more years of hands-on work securing AWS workloads. Both descriptions point at the same person, someone who has already run security in production.
What AWS expects you to know already
- The shared responsibility model and how it applies.
- Managing identity at scale and multi-account governance.
- Software supply chain risk and vulnerability management in the cloud.
- Firewall rules at scale for layers 3 to 7.
- Incident root cause analysis and responding to an audit.
- Encryption at rest and in transit, plus backup and disaster recovery controls.
What is out of scope
The guide also lists job tasks the candidate is not expected to perform: designing cryptographic algorithms, analysing traffic at packet level, architecting overall cloud deployments, managing end-user compute resources and training machine learning models. That list is useful when a study resource drifts into packet captures or model training. You can stop reading.
If you want the older blueprint for reference, this site’s earlier SCS-C02 exam walkthrough shows how the previous version was organised, which makes the changes above easier to see.
How should an SCS-C02 candidate adjust a study plan?
An SCS-C02 candidate moving to SCS-C03 should keep most existing notes and re-sort them. Start by mapping old material to the six new domains, then add the seven new tasks, give Identity and Access Management the most time, and practise ordering and matching questions, since both need every part correct to score.

- Re-file your notes under the six SCS-C03 domain names, moving all logging and monitoring material into Detection and all response material into Incident Response.
- Write one page for each of the seven added tasks, using the example services AWS names for each.
- Give Identity and Access Management the largest block of study time, because it now holds 20 percent of scored content.
- Build a multi-account sandbox with AWS Organizations and practise service control policies, delegated administrators and centralised root access.
- Practise ordering and matching questions until you can sequence an incident response without hesitating.
- Sit a full timed set of 65 questions in 170 minutes and review every miss by domain.
What carries over unchanged
Data Protection kept its 18 percent and governance kept its 14. Encryption at rest, S3 Object Lock, AWS Secrets Manager, AWS Config, AWS Audit Manager and AWS Firewall Manager all remain. Work you did on those topics for SCS-C02 still pays.
A caution on old material
Search results still surface plenty of SCS-C02 and even SCS-C01 content. Before trusting a resource, check that it names Detection and Incident Response as separate domains. If it lists Security Logging and Monitoring as a domain, it was written for the retired blueprint.
How long does the certification last, and which languages are ending?
AWS Certified Security – Specialty is valid for 3 years, and you recertify by passing the latest version of the exam. AWS offers SCS-C03 in six languages today, but the Simplified Chinese, Spanish (Latin America) and Portuguese (Brazil) versions will be retired after 31 December 2026. English, Japanese and Korean are not part of that notice.
Both facts come from the AWS certification page. If you planned to sit the exam in one of the three retiring languages, the practical deadline is the end of December 2026. After that date you would need to take it in one of the remaining languages.
Cost of the next exam
AWS states that once you hold one AWS Certification, you receive a 50 percent discount on your next AWS Certification exam, claimed through your AWS Certification Account. For a holder of an Associate credential, that halves the 300 USD fee.
Where the credential leads
AWS names AWS Certified DevOps Engineer – Professional and AWS Certified Advanced Networking – Specialty as certifications that professionals earn afterwards, on the way to roles such as DevSecOps Engineer or Networking Engineer. For a wider view of how AWS credentials fit a career, see this site’s piece on AWS certification career value.
Frequently Asked Questions
Is SCS-C02 still available?
No. AWS states that SCS-C02 was in use until 1 December 2025 and that SCS-C03 has been in use since 2 December 2025. Anyone booking the exam now sits SCS-C03.
How many questions are on the SCS-C03 exam?
There are 65 questions. Fifty affect your score and 15 are unscored questions that AWS is evaluating for future use. The unscored questions are not identified, so answer all 65 with equal care.
What is the passing score for SCS-C03?
The minimum passing score is 750 on a scaled range of 100 to 1,000. Scoring is compensatory, so you need to pass the exam overall and not each domain separately.
How much does the AWS Security Specialty exam cost?
The exam costs 300 USD. AWS gives holders of an active AWS Certification a 50 percent discount on their next exam, claimed through the AWS Certification Account.
Which domain has the highest weight in SCS-C03?
Identity and Access Management, at 20 percent of scored content. It was 16 percent under SCS-C02. Infrastructure Security and Data Protection follow at 18 percent each.
Does SCS-C03 test generative AI?
Yes, in one task. Task 3.2.7 asks you to implement protections and guardrails for generative AI applications, with the OWASP Top 10 for LLM Applications as the example. Training machine learning models is out of scope.
Do I need another AWS certification before SCS-C03?
No. AWS requires no specific certification first. It notes that candidates commonly earn AWS Certified Solutions Architect – Associate or Professional before attempting the Security Specialty exam.
How long is AWS Certified Security – Specialty valid?
The certification is valid for 3 years. Before it expires, you can recertify by passing the latest version of the exam.
Which SCS-C03 exam languages are being retired?
AWS will retire the Simplified Chinese, Spanish (Latin America) and Portuguese (Brazil) versions after 31 December 2026. The exam is also offered in English, Japanese and Korean.
Conclusion
SCS-C03 is the same size as the exam it replaced: 65 questions, 170 minutes, 750 to pass. What changed is where the marks sit. Identity and Access Management is now the largest domain at 20 percent, detection and response each have a domain of their own, and seven new tasks bring in generative AI guardrails, OCSF, imported key material and data masking.
For anyone holding SCS-C02 notes, that is good news. Most of the material survives, and the published deletions are fundamentals you still use every day. Re-sort what you have, add the seven new tasks, and put your extra hours into identity and multi-account governance. Then test the plan against timed scenario questions before you book.
