CIoTSP logo
Focused certification exam prep
Start practice

CIoTSP Certification

TL;DR
  • CIoTSP is CertNexus's Certified Internet of Things Security Practitioner credential, earned by passing exam ITS-110.
  • The exam has 100 questions in 120 minutes, including five minutes each for the agreement and tutorial.
  • Securing IoT Portals carries 29% of the blueprint, more than any other domain.
  • The current voucher is $367.50 USD and includes one free same-version retake within its validity window.

What the Credential Actually Is

The Certified Internet of Things Security Practitioner (CIoTSP) is a vendor-neutral credential issued by CertNexus. It validates that you can identify and address security risks across the IoT ecosystem: the web and mobile portals that manage devices, the network services devices rely on, the data they collect, the firmware they run, and the physical hardware itself. The single exam that earns it is ITS-110.

If you are still orienting yourself on terminology, our explainers on what CIoTSP certification is and what CIoTSP stands for cover the basics. This article goes further into how the certification is structured and how to prepare for it.

A note on the acronym: Several unrelated credentials in the technology world abbreviate to similar letters. Everything on this page refers specifically to the CertNexus Certified Internet of Things Security Practitioner and its ITS-110 exam. If you are comparing prices, dates, or domain weights from another source, confirm it describes the same credential before relying on it.

ITS-110 Exam Mechanics at a Glance

Knowing the logistics removes surprises on test day. Here is the format as published for the current exam:

ElementDetail
Exam codeITS-110
Issuing bodyCertNexus
Question count100 multiple-choice and multiple-response items
Time allowed120 minutes, including five minutes for the candidate agreement and five minutes for the tutorial
Passing score60% or 61% depending on the exam form
DeliveryPearson VUE test centers or OnVUE online proctoring
Book policyClosed book
BlueprintVersion 1.4, issued 15 January 2019 and modified 29 June 2022
Voucher price$367.50 USD (current)

Two practical points deserve attention. First, the 120 minutes are not all testing time. Once you subtract the agreement and tutorial segments, you have roughly 110 minutes for 100 questions, which works out to a little over a minute per item. Second, the passing threshold varies slightly by form, so aim comfortably above 61% in practice rather than targeting the minimum. For a deeper treatment of scoring, see our guide to the CIoTSP passing score.

The Seven Domains and Where the Points Live

The blueprint divides the exam into seven domains whose weights total 100%. The distribution is lopsided: one domain carries nearly a third of the exam, three carry 14% each, and the remaining three are comparatively small.

DomainWeight
1. Securing IoT Portals29%
2. Implementing Authentication, Authorization, and Accounting14%
3. Securing Network Services14%
4. Securing Data14%
5. Addressing Privacy Concerns12%
6. Securing Software/Firmware10%
7. Enhancing Physical Security7%

Our companion piece, the complete guide to all 7 CIoTSP content areas, walks through each objective in detail. Here, the focus is on what each domain asks of you in practical terms.

Domain 2: Implementing Authentication, Authorization, and Accounting

This domain tests whether you can control who and what gets access to IoT systems, and how you track that access afterward.

  • Distinguishing authentication, authorization, and accounting as separate functions
  • Choosing credential strategies suited to constrained devices
  • Applying role-based and least-privilege thinking to device and user access
  • Recognizing weaknesses such as default credentials and weak password policies

Domain 3: Securing Network Services

IoT devices live on networks that were rarely designed for them. Expect questions about protecting communication paths and the services devices depend on.

  • Securing the protocols and transport layers IoT devices use
  • Network segmentation and limiting exposure of device-facing services
  • Identifying insecure or unnecessary services running on devices
  • Monitoring traffic for abnormal device behavior

Domain 4: Securing Data

Devices generate and move large volumes of data. This domain covers protecting it at rest, in transit, and throughout its lifecycle.

  • Encryption choices for stored and transmitted data
  • Key management considerations on resource-limited hardware
  • Integrity protection and data handling across the device-to-cloud path
  • Secure retention and disposal practices

Domain 5: Addressing Privacy Concerns

At 12%, privacy is not an afterthought. IoT devices often capture personal information, sometimes quietly.

  • Identifying what personal data devices collect and why it matters
  • Privacy-by-design principles applied to IoT products and deployments
  • Consent, transparency, and data minimization concepts
  • How regulatory expectations shape device and service design

Domain 6: Securing Software/Firmware

Firmware is where many IoT compromises begin. This domain covers keeping device code trustworthy over its life.

  • Secure update mechanisms and verifying update authenticity
  • Code signing and secure boot concepts
  • Vulnerability management for deployed devices
  • Risks from outdated components and unpatched firmware

Domain 7: Enhancing Physical Security

The smallest domain at 7%, but IoT is unusual because attackers can often touch the device.

  • Tamper resistance and tamper detection
  • Protecting debug ports and exposed interfaces
  • Risks of devices deployed in unattended or public locations
  • Secure decommissioning of hardware

Why Securing IoT Portals Deserves Your First Month

At 29%, Securing IoT Portals alone is worth roughly as much as Domains 6 and 7 plus a good part of Domain 5 combined. A candidate who is shaky here will struggle to recover points elsewhere, so it earns the largest share of your study hours.

The portal domain concerns the interfaces through which people and systems manage IoT deployments: web dashboards, mobile applications, and the management consoles that sit in front of fleets of devices. A portal compromise can expose every device behind it, which is why the blueprint weights it so heavily.

Topics to Master Within the Portal Domain

  • Common web application weaknesses as they apply to device-management interfaces, including injection flaws, broken session handling, and cross-site attacks
  • Mobile companion app risks, such as insecure local storage, weak transport protection, and hardcoded secrets
  • Account recovery and registration flows, which are frequent weak points for consumer IoT products
  • API security for the back-end services that portals and devices call
  • Secure configuration and hardening of the portal infrastructure itself
  • Testing approaches that reveal portal vulnerabilities before attackers do

Key Takeaway

Treat the portal domain as the foundation. Many scenario questions in other domains, such as access control or data protection, are easier when you already think in terms of how a management portal is attacked and defended.

What the Questions Feel Like

ITS-110 uses multiple-choice and multiple-response items. The multiple-response format catches candidates who recognize one correct idea but miss a second. When a question asks you to select more than one answer, treat each option as its own true-or-false judgment rather than hunting for the single best choice.

Expect scenario framing. A typical item describes a deployment, such as a smart building, a connected medical device, or an industrial sensor network, and asks which control best addresses a described weakness. The exam rewards matching the right control to the right layer of the IoT stack. Memorizing definitions alone will not carry you; you need to recognize which problem a given control actually solves.

Because the exam is closed book and external calculator permission has not been verified, plan on reasoning through everything unaided. Anything involving numbers should be conceptual rather than computational. For a realistic read on difficulty, see our analysis of how hard the CIoTSP exam is, and for statistics-related questions, our page on the CIoTSP pass rate explains what is and is not publicly known.

Registration, Voucher, and Retake Mechanics

CertNexus sells exam vouchers, and candidates then schedule through Pearson VUE. You can test at a physical Pearson VUE center or take the exam remotely through OnVUE online proctoring. The current voucher price is $367.50 USD, though you should confirm the figure at purchase since pricing can change. Our full CIoTSP cost breakdown covers what to budget beyond the voucher itself.

Choosing Between a Test Center and Online Proctoring

  • Test center: A controlled environment with no concerns about your home internet, webcam, or interruptions
  • OnVUE online: Convenient, but online-proctoring requirements apply, including workspace checks and system compatibility tests you should complete in advance

Current policy includes one free same-version retake within the voucher's validity period, normally 18 months. That safety net is worth knowing about, but do not treat it as a plan. A retake on the same version means you should use the first attempt's experience to target gaps rather than simply rereading everything.

There are no formal prerequisites: no required education, experience, training hours, references, or prior certifications. IoT and security familiarity is recommended, but nothing is enforced. Our CIoTSP requirements guide details what that means in practice, and our page on exam dates and scheduling helps you plan your booking window.

Who Benefits From This Credential

The CIoTSP suits professionals whose work touches connected devices and the systems around them. Typical backgrounds include:

  • Security analysts and engineers expanding from traditional IT security into connected-device environments
  • IoT developers and architects who want a security-focused credential to complement build skills
  • Network and systems administrators responsible for environments where sensors, cameras, and controllers appear on the network
  • Product and compliance staff in device manufacturing who must reason about privacy and secure-update obligations
  • Consultants and integrators who deploy connected solutions for clients in sectors such as building automation, healthcare, and industrial operations

Employers in device manufacturing, managed security services, smart infrastructure, and industrial technology are the natural audience, though hiring demand varies by region and sector. We do not cite earnings figures here because reliable data is limited; our CIoTSP jobs overview, salary guide, and ROI analysis discuss how to weigh the credential against your own career goals.

Sequencing Your Preparation Around the Blueprint

Because the weights are so uneven, your calendar should be uneven too. The sample plan below allocates time roughly in proportion to blueprint weight while placing foundational material first. Adjust the pace to your background; a seasoned web security professional may compress the early weeks.

Weeks 1-2

Securing IoT Portals

  • Work through web, mobile, and API weaknesses in management interfaces
  • Learn hardening and testing approaches for portals
  • Take a short quiz on this domain only to expose gaps early
Week 3

Authentication, Authorization, and Accounting

  • Separate the three functions clearly in your notes
  • Practice matching access control models to scenarios
Week 4

Network Services and Data Security

  • Cover protocol protection, segmentation, and encryption choices
  • Review key management constraints on small devices
Week 5

Privacy, Firmware, and Physical Security

  • Cover privacy-by-design and data minimization
  • Study secure updates, code signing, and tamper protection
Week 6

Full-Length Practice and Review

  • Take timed 100-question practice sets using the CIoTSP practice tests
  • Revisit every domain where you scored lowest

The logic is simple: the largest domain comes first so it gets the most repetition, and the small domains come last, where a focused review is enough. For a more detailed approach, see our CIoTSP study guide, and keep our one-page cheat sheet handy for final-week review. If you prefer structured instruction over self-study, our overview of CIoTSP training options outlines the alternatives.

Practice under real conditions: Run at least two full timed sessions of 100 questions in about 110 minutes. Pacing at a little over a minute per question feels different from untimed drilling, and multiple-response items are the ones that tend to eat the clock. You can start with the free CIoTSP practice test to calibrate.

Validity and Renewal

The CIoTSP is valid for three years. The verified renewal route is to pass the latest version of the exam before your credential expires. This matters for planning: the blueprint may have changed by then, so expect to study updated content rather than simply repeating what you learned the first time.

One point of caution: CIoTSP does not appear on the reviewed CertNexus list of continuing-education-eligible credentials. Do not assume that a block of CE credits or a CE-only renewal fee applies to it. Confirm the current renewal policy directly with CertNexus well before your expiration date.

Frequently Asked Questions

What exam do I take to earn the CIoTSP?

You take ITS-110, administered by CertNexus through Pearson VUE. It consists of 100 multiple-choice and multiple-response questions with a 120-minute time allowance that includes five minutes for the candidate agreement and five minutes for the tutorial.

Which domain is weighted most heavily?

Securing IoT Portals, at 29% of the blueprint. The other six domains range from 14% down to 7%, so allocating your largest block of study time to portals is the most efficient use of effort.

Are there prerequisites to sit for the exam?

No. There are no formal education, experience, training-hour, reference, or prior-certification requirements. CertNexus recommends familiarity with IoT and security concepts, but it is not enforced at registration.

What happens if I fail on my first attempt?

Current policy includes one free same-version retake within the voucher's validity period, normally 18 months. Use your score report to identify weak domains and focus your remaining preparation there rather than restarting from scratch.

How long does the certification last, and how do I renew?

It remains valid for three years. The verified renewal path is passing the latest-version exam before expiration. It is not on the reviewed CE-eligible list, so do not count on continuing-education credits to extend it.

Ready to pass your CIoTSP exam?

Put this into practice with free CIoTSP questions across every exam domain.