AWS Security — SpecialtyAmazon Web Services certification
AWS Certified Security — Specialty (SCS-C02). Specialty AWS certification covering threat detection and incident response, security logging and monitoring, infrastructure security, identity and access management, data protection, and management/governance. Recertify within 3 years by retaking the exam.
Renewal cycle
3 years
Between full re-certifications.
Recertification
Retake exam
Every 3 yrs — no continuing-credit requirement.
Indexed here
22
Opportunities mapped to this cert.
AWS Certified Security – Specialty (SCS-C02) is valid for 3 years and maintained by exam, not by continuing education — there are no CPEs or CEUs to track. The credential is either active (within 3 years of your last pass) or expired; there is no soft middle ground and no grace period.
How AWS Security – Specialty recertification works
Unlike the Associate certs, Security – Specialty sits at AWS's top tier alongside the Professional certifications. There is no higher AWS exam that renews it, so the standard recertification path is to retake the current Specialty exam (SCS-C02), which resets the 3-year clock from the new pass date. AWS opens the recertification window 6 months before expiry; you can sit the exam any time before expiry.
There is no free renewal assessment — that model is unique to Microsoft. The exam is $300 USD, roughly 170 minutes, 65 questions.
The renewal that goes the other way
The high-leverage move with Security – Specialty isn't renewing it cheaply — it's what earning it does for the rest of your AWS stack. AWS's recertification rule extends your Associate-level and Foundational certs for a fresh 3-year cycle when you pass a higher exam, and the Specialty qualifies. If you hold Solutions Architect, SysOps, or Developer Associate, passing Security – Specialty renews them as a side effect.
That turns the timing into a stack decision: practitioners carrying several AWS certs often schedule the Specialty (or a Professional) into year 2–3 of their Associate cycles so a single exam renews the lot. Confirm the current renewal pairings on the AWS Recertification page — AWS occasionally adjusts which exams extend which certs.
For the Specialty itself, though, plan on the retake. Budget the $300 and a focused refresh rather than expecting a cheaper path to materialise.
What's on SCS-C02 (and what changed)
SCS-C02 (current as of 2026) is organised around six domains: threat detection and incident response, security logging and monitoring, infrastructure security, identity and access management, data protection, and management and security governance. The C01 → C02 refresh (2023) added explicit incident-response and governance weight and broadened the service set.
Service focus that rewards study: GuardDuty, Security Hub, Detective, and Inspector for detection; CloudTrail, Config, and CloudWatch for logging; KMS, ACM, Macie, and Secrets Manager for data protection; IAM Identity Center, SCPs, and permission boundaries for access control; and Network Firewall, WAF, and Shield at the perimeter.
If you've been doing AWS security day-to-day, much of this is familiar — the refresh delta is mostly the detection and governance services AWS has shipped since your version. AWS Skill Builder's official Security – Specialty learning plan plus the Official Practice Question Set are the AWS-authored study materials.
Common pitfalls (and how to avoid them)
Pitfall 1: Waiting for a "level-up" path that doesn't exist. Because Security – Specialty is top-tier, there's no higher AWS exam to renew it — candidates who assume they'll "just take the Pro later" can find the Specialty expires first. Plan the retake.
Pitfall 2: Letting Associates lapse before earning the Specialty. The stack-renew benefit only fires for certs that are still active when you pass. If your Solutions Architect has already expired, passing Security – Specialty won't revive it. Earn the higher exam before the lower ones lapse.
Pitfall 3: Missing the date. Your 3-year window runs from the exam-completion date in your AWS Certification account, not badge issuance. Schedule the retake with at least 90 days of buffer; there is no grace period.
Frequently asked
Does passing a higher AWS cert renew Security – Specialty?+
Not under the standard rule — it's already at AWS's top tier, so there's no higher exam that renews it. You recertify Security – Specialty by retaking the current SCS-C02. The reverse is the useful part: earning the Specialty renews your active Associate-level AWS certs.
What does recertifying cost?+
$300 USD for the SCS-C02 retake. AWS periodically issues discount vouchers (for example, 50% off after passing certain exams) — check the benefits page in your AWS Certification account before paying full price.
Is there a free renewal assessment like Azure's AZ-500?+
No. AWS has no free renewal assessment for any certification as of 2026. The only path for Security – Specialty is retaking SCS-C02. Azure's renewal-assessment model is specific to Microsoft.
How is this different from renewing an Associate cert?+
Associates can be renewed either by retaking the Associate exam or by passing a higher-level exam (Professional or Specialty). The Specialty has no higher tier, so retake is the only standard path — but it's also the cert that does the renewing for your Associates.
What if I let Security – Specialty expire?+
AWS marks it expired in your Credly badge wallet; there's no grace period. To restore, sit the current SCS-C02 at full price. AWS doesn't penalise re-takers — the exam is the same — but you lose Certified status during the gap.
Opportunities that count
22 results mapped to AWS Security — Specialty, ranked by what’s coming up next.
The cloud has become the primary location for businesses to store data. As usage of the cloud has grown, many organizations simply try to lift and shift their tools to the cloud, unaware that better, more tailored and cost-effective cloud-native solutions exist. On April 5, 2022 at 1:00 p.m. Eastern/10:00a.m. Pacific, join IANS and (ISC)² to hear: • Which AWS/Azure/GCP cloud-native tools to consider • Which cloud-native tools aren’t quite ready • When and how to use cloud-native firewalls, vulnerability scanners, DLP and incident response tools for a more scalable, cost-effective and secure environment.
As multi-cloud adoption accelerates, security teams are navigating the delta between each cloud provider’s native capabilities and comprehensive protection from bad actors. Understanding cloud terminology, principles, and security issues is critical. Join (ISC)² and Sysdig March, 29, 1:00 p.m., Eastern/10:00 a.m. Pacific to understand the fundamentals on cloud categories and terms like CSPM (Cloud Security Posture Management), CWPP (Cloud Workload Protection Platform), CNAPP (Cloud-Native Application Protection Platform), etc. so you can move past the acronyms and onto implementing them as best practices. In this session we will: • Debunk new industry acronyms and explain how they fit into your overall cloud security strategy • Explain why native cloud provider tools aren’t always sufficient • Provide CSPM best practices: Detecting misconfigurations, excessive permissions and suspicious activity • Showcase how open-source Falco can be used to detect cloud threats in real-time
The ongoing transition to cloud platforms has meant that more sensitive data is stored in the cloud, making it more tempting for adversaries to exploit. When it comes to securing the cloud, identity is the first line of defense. Proper identity and access management (IAM) policies are the foundation of comprehensive cloud security principles. To understand how IAM policies affect organizations' cloud security posture, Unit 42 researchers analyzed 680,000+ identities across 18,000 cloud accounts from 200 different organizations. The results of our research were shocking - nearly all organizations we analyzed lack the proper IAM management policy controls to remain secure. Misconfigured IAM policies open the door for cloud threat actors. We define a cloud threat actor as "an individual or group posing a threat to organizations through directed and sustained access to cloud platform resources, services or embedded metadata." Cloud threat actors merit a separate definition as they employ a fundamentally different set of tactics, techniques and procedures (TTPs) that are unique to the cloud – such as taking advantage of the ability to perform both lateral movement and privilege escalation operations simultaneously. Join Palo Alto and (ISC)² June 2, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific for this webinar where the audience will be guided through the latest research in overprivileged IAM identities in real-world cloud environments and how cloud threat actors are zeroing in on these excessive permissions to expand their control of cloud environments. Detection and mitigation of these risks are possible, join us to find out how!
Skillful threat detection and investigation starts with a diverse hub of security telemetry to draw from. The Chronicle platform allows security teams to cost effectively store and analyze petabytes of security data in one place and perform investigations in seconds. Now, Chronicle brings Google-scale threat analysis to your SOC with the debut of its detection engine, Chronicle Detect, fully equipped with ATT&CK reference rules, an integrated detection-based rules language, and intelligence from Chronicle’s elite threat research team. In this webcast, we’ll examine what’s new in Chronicle and see the detection engine in action with a live demo.
Cloud adoption is accelerating at an exponential rate. Whether it’s for business collaboration or to store critical data assets, organizations are increasingly relying on the cloud. In the next 3 years, it is anticipated that 70% of workloads will be hosted in a cloud environment. The ease of deploying these workloads within cloud-based infrastructure enables rapid adoption of cloud services and greater business agility, but what about the risks? We have seen a sharp rise in the number of data breaches stemming from misconfigurations in the cloud. These misconfigurations occur as a result of improper settings being used when architecting and deploying services within the cloud platform. Ultimately, this means that cybercriminals have an expanded attack surface to access any data stored within the cloud environment, increasing the risk of a cyber attack. Join eSentire and (ISC)2 on January 18, 2022 at 1:00 p.m. Eastern for a discussion on the top threats associated with utilizing cloud-based infrastructure and explore how they are different from threats to your on-premises infrastructure. Key takeaways will include: • Cloud migration strategy: should you go all in? • Shared responsibility model: what are you on the hook to secure? • Top threat trends: how is cloud different? • Monitoring and response: what solutions should you consider?
Full cloud native security requires more than application security testing and network monitoring. It requires a concerted approach to vulnerability management within CI/CD pipelines, in pre-production testing, and at runtime. Join Aqua Security and (ISC)2 on April 22, 2021 at 1:00PM Eastern for an examination on how to secure applications in complex cloud native ecosystems, including: · Detecting vulnerabilities and exploits in container images, VMs, and serverless functions · Prioritizing and triaging security risks to accelerate remediation · Uncovering hidden malware and attack kill chains before they’re executed in production
CCSP1.5CySA+~1.5AWS Security — Specialty~1.5+1 more
Ransomware is on the rise, with almost 69% of organizations falling victim to a successful attack according to the 2021 Cyberthreat Defense Report. Those attacks are increasingly shifting to the cloud, either through starting in those environments or moving there from infected on-premises assets. It’s time to take a cloud-based approach to defending against ransomware. In this webinar, the ExtraHop team will show you how analysts and incident responders can use cloud-native network detection and response (NDR) to: o Detect early indicators of compromise, data staging, and exfiltration o Speed investigation to get to ground truth faster o Respond quickly to stop the attack before it gets out of control
Having access to new technology and intelligence to allow proactive response to the threats will change the way teams protect their environments. Harness the massive computing power of Backstory integrated with the powerful insights from VirusTotal to process petabytes worth of data in almost real-time. Watch a step-by-step demo of how Chronicle's security solutions, working with partners like Tenable, can help your organization be better prepared and connected for what comes onto your network.
Modernizing Security Operations involves a combination of people, process, technology, and services to manage risk, monitor, detect, and respond to cybersecurity threats and incidents. Security leaders seeking to modernize security operations face serious challenges in identifying the resources, expertise and tools to meet their goals. Over the past few years, MITRE ATT&CK® a globally-accessible knowledge base of adversary tactics and techniques has gained prominence as a way to determine the effectiveness of Security Operations to detect, analyze, and respond to attacks. Join Sumo Logic and (ISC)2 on April 20, 2021 at 1:00PM Eastern for an exploration on how security practitioners can leverage the MITRE ATT&CK framework and integrate using the Sumo Cloud SIEM.
The XDR technology ecosystem promises a new level of cyber security visibility, improved detection and active protection against modern threats. The full telemetric value of XDR platforms, however, may not be realized without rethinking security analytics. Join the Google Cloud Security team for this webcast to learn more about the dimensions of modern security analytics that will enable you to fully unleash your XDR investment.
GCP Professional Cloud Security Engineer1CySA+1CISSP~1+1 more
While cloud technology is not new, and many organizations have been on their cloud journey for years, cloud service providers continue evolving with new features and services. This fast change and growth make it difficult for organizations to keep up and inadvertently introduce security weaknesses. Join Palo Alto and (ISC)2 April 20, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific as we talk through this year’s results of the Unit 42™ Cloud Threat Report. Our experts offer insights into the most common drivers of cloud incidents and breaches today, giving security leaders and practitioners a comprehensive view of cloud security threats. These findings should enable leaders to understand the greatest risks to their cloud environment and how to manage them most effectively. Webinar attendees will also: - Get lessons from real cloud breach incidents. - Learn tips to stay ahead of cloud threat actors. - Address the most common cloud security issues. - Understand the impacts and risks of open-source software in the cloud.
Want to know more about safeguarding your organization against an increasingly sophisticated array of threats? In this session, Lacework will dissect the most pertinent cloud security attack trends and techniques of 2023. Delve into actionable insights, real-world metrics, and the current threat landscape as we equip your team with the latest knowledge and strategies. This discussion will cover the following topics and more: - Kubernetes attacks and abuses: The rise in complexity and vulnerabilities in deployment, and the resulting increased attacks and administrative plane abuses. - Zenbleed impact: How Zenbleed affected cloud providers and how Lacework approaches this security concern. - Cloud supply chain attacks: An examination of the JumpCloud APT case and its broader implications. - CloudWizard APT: The use of OneDrive, Dropbox, and Google Drive as a C2 in the ongoing CloudWizard threat, including an analysis of its evolution.
CCSP1.5AWS Security — Specialty~1.5CySA+~1.5
Related certifications
Maintaining more than one credential? A single activity often counts toward several — here’s what pairs with AWS Security — Specialty.