- How the ITS-110 Blueprint Is Built
- Domain Weights at a Glance
- Domain 1: Securing IoT Portals (29%)
- Domain 2: Authentication, Authorization, and Accounting (14%)
- Domain 3: Securing Network Services (14%)
- Domain 4: Securing Data (14%)
- Domain 5: Addressing Privacy Concerns (12%)
- Domain 6: Securing Software/Firmware (10%)
- Domain 7: Enhancing Physical Security (7%)
- Sequencing the Domains in Your Study Plan
- Exam Format and Registration Mechanics
- Who Uses This Credential
- Frequently Asked Questions
- The CIoTSP exam (ITS-110) from CertNexus covers seven domains, and Securing IoT Portals alone carries 29% of the blueprint.
- Domains 2, 3, and 4 each carry 14%, so together they match roughly the weight of Domain 1 plus a bit more.
- The exam has 100 multiple-choice and multiple-response questions in 120 minutes, including five-minute agreement and tutorial segments.
- The voucher is $367.50 USD and includes one free same-version retake within its validity period, normally 18 months.
How the ITS-110 Blueprint Is Built
The Certified Internet of Things Security Practitioner credential is issued by CertNexus, and the exam code is ITS-110. The blueprint (version 1.4, issued 15 January 2019 and modified 29 June 2022) divides the content into seven domains that together account for 100% of scored content. If you are new to the credential itself, start with What Is CIoTSP Certification? and then return here to dig into the weighting.
The blueprint is organized around the IoT stack rather than around generic information security categories. You move from the user-facing portals and management interfaces, through identity controls, the network layer, stored and transmitted data, privacy obligations, the code running on devices, and finally the physical hardware itself. That progression is useful when you study: each domain builds on assumptions from the previous one.
The question style matters as much as the topic list. Items are multiple-choice and multiple-response, so some questions ask you to select more than one correct answer. Scenario-style wording is common: you are given an IoT deployment problem and asked which control, configuration, or design decision best addresses it. Rote memorization of definitions rarely carries you through those items on its own.
Domain Weights at a Glance
| Domain | Name | Weight |
|---|---|---|
| 1 | Securing IoT Portals | 29% |
| 2 | Implementing Authentication, Authorization, and Accounting | 14% |
| 3 | Securing Network Services | 14% |
| 4 | Securing Data | 14% |
| 5 | Addressing Privacy Concerns | 12% |
| 6 | Securing Software/Firmware | 10% |
| 7 | Enhancing Physical Security | 7% |
On a 100-question exam, these weights translate into a rough expectation of how many items you will see per domain, though the exact count can vary by form. Do not treat the weights as a license to skip the small domains. A candidate who ignores the 7% physical security domain and the 10% firmware domain is surrendering a meaningful slice of available points, and the passing score sits around 60% or 61% depending on the form. For more on that threshold, see CIoTSP Passing Score 2026: Exactly What You Need to Pass.
Domain 1: Securing IoT Portals (29%)
This is the heaviest domain by a wide margin, and it should anchor your preparation. An IoT portal is any interface through which people or systems interact with devices: web dashboards, mobile apps, administrative consoles, and APIs that sit between the user and the device fleet. Because portals are exposed and often internet-facing, they are the most attractive entry point for attackers, which explains the weighting.
Domain 1: Securing IoT Portals
Expect questions on how portals are attacked and how they are hardened, including both the application layer and the surrounding management functions.
- Common web and application vulnerabilities as they apply to device management dashboards
- Secure session handling, input validation, and protection against injection and cross-site attacks
- API security for device registration, command, and telemetry endpoints
- Secure default configurations and the risk of leaving factory credentials unchanged
- Account lockout, password policy, and secure recovery workflows for portal users
- Cloud-hosted versus locally hosted portal considerations
The trap in this domain is thinking only in terms of "the website." Portal questions frequently involve the connection between the portal and the devices it manages, so a weak management channel can compromise an otherwise well-protected device. When you review a scenario, ask who can reach the portal, what they can do once they are in, and what happens to the fleet if that one interface is compromised.
Domain 2: Implementing Authentication, Authorization, and Accounting (14%)
Authentication, authorization, and accounting (AAA) govern who or what is allowed onto the system, what they may do, and how their activity is recorded. In an IoT context, "who" includes not just human users but also devices, gateways, and services talking to each other.
Domain 2: AAA in IoT Environments
Know the distinctions between the three functions cold, because questions often hinge on which function a given control actually provides.
- Authentication methods for users and for constrained devices, including credentials, certificates, and multi-factor approaches
- Device identity and how unique credentials per device limit blast radius
- Authorization models such as role-based and least-privilege access
- Accounting and audit logging, including what to log and how to protect logs from tampering
- Federated identity and token-based approaches for connecting portals to device services
- Credential lifecycle: provisioning, rotation, revocation, and decommissioning
A frequent exam pattern presents a symptom, such as a device impersonating another or a user exceeding their permissions, and asks which AAA component failed. Train yourself to map each symptom to authentication, authorization, or accounting before you evaluate the answer choices.
Domain 3: Securing Network Services (14%)
This domain covers the communication paths that connect devices, gateways, and back-end systems. IoT networks are heterogeneous: a single deployment may mix short-range wireless protocols, cellular links, and conventional IP networking.
Domain 3: Network Services
Focus on how traffic is protected in transit and how network exposure is minimized.
- Transport-layer protections and secure protocol selection for device communications
- Network segmentation to isolate IoT devices from critical enterprise systems
- Firewalls, access control lists, and limiting open ports and services on devices
- Wireless security considerations and weaknesses in common IoT connectivity options
- Common network attacks such as eavesdropping, man-in-the-middle, and denial of service
- Monitoring and anomaly detection for unusual device traffic
Segmentation is a recurring theme worth internalizing. Many scenario questions reward the answer that contains a compromised device rather than the one that merely detects it, so favor containment-oriented thinking when two options both sound reasonable.
Domain 4: Securing Data (14%)
Data protection spans three states: data at rest on devices and servers, data in transit across networks, and data in use during processing. IoT adds the wrinkle that devices are often resource-constrained, which limits the cryptographic options available on the endpoint.
Domain 4: Securing Data
Be ready to choose appropriate protections for a given data state and device capability.
- Encryption of data at rest and in transit, and the role of key management
- Symmetric versus asymmetric cryptography and where each is typically applied
- Hashing and integrity verification to detect tampering
- Digital signatures and certificates, including trust and certificate lifecycle concerns
- Secure storage of keys and secrets on constrained hardware
- Data retention, secure deletion, and handling of sensitive telemetry
Key management is where many candidates lose points. Encryption is only as strong as the handling of its keys, and exam writers know it. If an answer choice improves algorithm strength but ignores a badly exposed key, be skeptical.
Key Takeaway
Domains 2, 3, and 4 are weighted equally at 14% each and share a common thread: trust. Identity establishes who is trusted, the network carries that trust, and cryptography protects it. Studying them as a connected unit makes each one easier to recall.
Domain 5: Addressing Privacy Concerns (12%)
Privacy is distinct from security, and the exam tests whether you can tell them apart. Security protects data from unauthorized access; privacy concerns how personal data is collected, used, shared, and retained, even by authorized parties. IoT devices are especially sensitive here because they can collect continuous streams of behavioral, location, and environmental data.
Domain 5: Privacy
Expect questions that ask you to identify privacy risks in a device design and select appropriate mitigations.
- Types of personal and sensitive data that IoT devices commonly collect
- Privacy-by-design principles, including data minimization and purpose limitation
- User consent, notice, and transparency expectations
- Regulatory and compliance considerations that affect IoT data handling
- Anonymization and pseudonymization techniques and their limitations
- Third-party data sharing and the privacy implications of cloud back ends
Read privacy questions carefully for who is accessing the data and why. A control that is perfect from a security standpoint, such as strong encryption, may not address a privacy concern if the organization is collecting more data than it needs in the first place.
Domain 6: Securing Software/Firmware (10%)
The code running on a device is both its brain and its biggest long-term liability, since fielded devices can stay in service for years. This domain tests secure development and update practices.
Domain 6: Software and Firmware
Think about the entire lifecycle of device code, from development through patching and retirement.
- Secure coding practices and common coding flaws in embedded software
- Code signing and verification to ensure only trusted firmware runs
- Secure boot and the concept of a hardware-anchored chain of trust
- Over-the-air update mechanisms and their security requirements
- Vulnerability management, patching cadence, and end-of-life considerations
- Third-party and open-source component risk in device software
Update mechanisms are a favorite exam subject because they are a double-edged sword: a patch channel that is not authenticated and integrity-checked becomes an attack vector itself. When a question describes an update process, check for signing and verification before anything else.
Domain 7: Enhancing Physical Security (7%)
The smallest domain still deserves attention, because IoT devices are often deployed in unattended or publicly accessible locations where an attacker can touch the hardware. Physical access can undermine software controls entirely.
Domain 7: Physical Security
Focus on how physical exposure changes the threat model for deployed devices.
- Tamper resistance, tamper evidence, and tamper response mechanisms
- Disabling or protecting debug ports and hardware interfaces
- Risks from device theft, cloning, and hardware modification
- Secure placement, enclosures, and environmental protections
- Protecting stored secrets against physical extraction attempts
- Supply chain concerns for hardware components
Do not study this domain in isolation. An exposed debug port is a physical security problem that becomes a firmware and data problem the moment someone extracts a key. Questions here often reward you for recognizing that cross-domain connection.
Sequencing the Domains in Your Study Plan
The blueprint order is a sensible default, but the weights suggest a refinement. Spend your first and longest block on Domain 1, since it carries 29%, then work through the three 14% domains as a trust-focused cluster. Fold the 12% privacy domain in next, and finish with firmware and physical security, which pair naturally because both concern the device itself. The full methodology is laid out in the CIoTSP Study Guide 2026: How to Pass on Your First Attempt, and you can print the essentials from the CIoTSP Cheat Sheet 2026: One-Page Review of Must-Know Facts for a final pass.
Portals and Interfaces
- Work through Domain 1 end to end, including API and management-channel security
- Take a short diagnostic to see whether portals are a true weak spot
The Trust Cluster
- Cover AAA, network services, and data protection together
- Practice mapping scenarios to the correct control category
Privacy, Firmware, and Physical
- Distinguish privacy from security in scenario questions
- Review secure boot, signing, update channels, and tamper resistance
Full-Length Practice
- Sit timed 100-question sets and review every missed item by domain
- Re-drill any domain where scores trail the others
If you are unsure how much preparation you personally need, How Hard Is the CIoTSP Exam? Complete Difficulty Guide 2026 helps you calibrate based on your background in networking and security.
Exam Format and Registration Mechanics
The ITS-110 exam is delivered through Pearson VUE, either at a testing center or via OnVUE online proctoring. It consists of 100 multiple-choice and multiple-response questions with a 120-minute window. That window includes five minutes for the candidate agreement and five minutes for the tutorial, so your effective time for answering questions is somewhat shorter than the headline figure.
- Voucher cost: $367.50 USD at the time of writing, with a breakdown of related costs in CIoTSP Certification Cost 2026: Complete Pricing Breakdown.
- Passing score: The current official page lists 60% or 61% depending on the form, while the older blueprint states 60%.
- Prerequisites: There are no formal education, experience, training-hours, reference, or prior-certification requirements, although familiarity with IoT and security concepts is recommended. See CIoTSP Requirements 2026: Eligibility, Prerequisites & How to Qualify.
- Retake policy: Current policy includes one free same-version retake within the voucher validity period, normally 18 months.
- Open or closed book: The exam is closed book, and online proctoring requirements apply if you test from home.
- Validity: The credential is valid for three years, and the verified renewal route is taking the latest-version exam before expiration.
Scheduling windows and availability are covered in CIoTSP Exam Dates 2026: Testing Windows, Deadlines & Scheduling. Whichever delivery option you choose, run through the technical and environment checks for online proctoring well ahead of exam day, and use full-length simulations on the CIoTSP practice exam site to rehearse the pacing of a 100-question sitting.
Who Uses This Credential
The seven domains make the credential a fit for people who touch IoT systems from different angles: security analysts expanding into connected devices, embedded and firmware engineers who want formal security grounding, network administrators responsible for segmenting device traffic, and product or compliance staff who need to understand privacy and data handling in connected products. Because there are no formal prerequisites, it also serves as an entry point for professionals pivoting from general IT security into the IoT space.
Employers in manufacturing, smart building and facilities, healthcare technology, utilities, and consumer electronics are the typical environments where IoT security knowledge is applied. For a realistic look at roles and compensation context, see CIoTSP Jobs and Is the CIoTSP Certification Worth It? Complete ROI Analysis 2026 before deciding how the credential fits your career plan.
Frequently Asked Questions
Securing IoT Portals is the largest domain at 29% of the blueprint. It covers the web, mobile, API, and management interfaces through which users and systems interact with IoT devices, so it deserves the largest share of your study time.
There are seven domains, and their weights total 100%: 29%, 14%, 14%, 14%, 12%, 10%, and 7%. The exam code is ITS-110, and the blueprint is version 1.4.
Skipping is risky. Enhancing Physical Security is only 7% and Securing Software/Firmware is 10%, but with a passing score around 60% or 61%, giving away those points leaves little margin. These topics also overlap with data and firmware questions elsewhere on the exam.
The exam uses multiple-choice and multiple-response questions, 100 in total, delivered within a 120-minute session that includes five minutes for the agreement and five for the tutorial. The exam is closed book.
CertNexus does not publish a detailed pass rate breakdown we can cite here, so see CIoTSP Pass Rate 2026: What the Data Shows for what is and is not known, and use the domain weights in this guide to prioritize preparation instead.