- The CertNexus ITS-110 passing score is listed as 60% or 61% depending on exam form; the older blueprint says 60%.
- The exam has 100 multiple-choice and multiple-response questions in a 120-minute session that includes agreement and tutorial time.
- Securing IoT Portals carries 29% of the blueprint, more than any other domain.
- The current voucher is $367.50 USD and includes one free same-version retake within its validity window.
What the Passing Score Actually Is
The Certified Internet of Things Security Practitioner (CIoTSP) is issued by CertNexus, and the exam code is ITS-110. Unlike some vendor exams that report a scaled score on a 100-to-1000 range, the CertNexus materials describe the requirement as a percentage. The current official exam page lists a passing score of 60% or 61% depending on the form you receive, while the older blueprint document states 60%.
That small discrepancy is the most common point of confusion for candidates researching this exam. If you want the broader picture of how the credential is structured, the overview at What Is CIoTSP Certification? covers the basics, and this article stays focused on the score itself and how to plan around it.
Why You See 60% and 61%
Certification bodies commonly maintain more than one exam form, and the cut score can shift slightly between forms so that the effective difficulty stays equivalent. When one form contains marginally harder items, the required percentage may be set a little lower; when another is slightly easier, it may be set a little higher. That is the reasonable explanation for a "60% or 61%" range on the official page.
The blueprint behind the exam is version 1.4, issued 15 January 2019 and modified 29 June 2022. The older blueprint's 60% reflects the document's own wording, while the live exam page reflects current form-level practice. Rather than trying to reconcile the two, build your preparation around the higher figure.
| Source | Stated Passing Score | How to Use It |
|---|---|---|
| Current official exam page | 60% or 61%, depending on form | Target 61% or higher on practice |
| Older blueprint document | 60% | Treat as a floor, not a goal |
The Math of 100 Questions
With 100 questions on the exam, a percentage cut score maps neatly to a question count: roughly 60 to 61 correct answers. That framing is helpful, but two cautions apply.
- Not every item may be scored identically. Certification exams sometimes include unscored items used for future test development. Candidates are not told which questions those are, so treat every question as if it counts.
- Multiple-response items are all-or-nothing in spirit. The exam mixes multiple-choice and multiple-response formats. On multiple-response items you must identify every correct option, so partial understanding is punished more harshly than on single-answer items.
The practical consequence: do not budget on "I can miss 39 questions." Budget on getting the high-weight domains right and keeping your multiple-response accuracy strong. For a realistic read on difficulty, see How Hard Is the CIoTSP Exam?, and for what the broader data suggests about outcomes, read CIoTSP Pass Rate 2026: What the Data Shows.
Where the Points Live: Domain Weights
The seven domains total 100% of the blueprint. Because the passing score is a flat percentage across the whole exam, you do not need to pass each domain individually in the way the blueprint is described, but weak performance in a large domain is very hard to offset elsewhere.
| Domain | Weight | Approx. Questions on a 100-Item Exam |
|---|---|---|
| 1. Securing IoT Portals | 29% | About 29 |
| 2. Implementing Authentication, Authorization, and Accounting | 14% | About 14 |
| 3. Securing Network Services | 14% | About 14 |
| 4. Securing Data | 14% | About 14 |
| 5. Addressing Privacy Concerns | 12% | About 12 |
| 6. Securing Software/Firmware | 10% | About 10 |
| 7. Enhancing Physical Security | 7% | About 7 |
The question counts above are simple proportional estimates from the blueprint weights; actual forms can vary slightly. For a deeper walk through each area, the CIoTSP Exam Domains guide breaks down all seven content areas.
Domain 1: Securing IoT Portals (29%)
This is the heaviest domain by a wide margin, and it is where the passing score is most often won or lost. Expect scenario questions about the web and mobile interfaces that users and administrators use to manage IoT devices and services.
- Common portal weaknesses and how to mitigate them
- Secure session handling and credential protection at the portal layer
- Hardening administrative interfaces and limiting exposed functionality
Domains 2, 3, and 4 (14% each)
Together these three account for 42% of the exam, so they function almost like a second "super-domain."
- Authentication, Authorization, and Accounting: identity for devices and users, access control models, and audit trails
- Securing Network Services: protecting the communications and protocols IoT deployments depend on
- Securing Data: protecting data in transit and at rest across devices, gateways, and back-end services
Domains 5, 6, and 7 (12%, 10%, 7%)
These three total 29%, matching Domain 1 in aggregate. Candidates who neglect them because each seems small often lose the cushion they needed.
- Addressing Privacy Concerns: handling personal data collected by connected devices
- Securing Software/Firmware: update integrity, secure development concerns, and device software lifecycle
- Enhancing Physical Security: tamper resistance and physical access threats to deployed devices
Format, Timing, and Delivery
The scoring threshold only matters if you can actually finish the exam, so pacing deserves attention.
- Questions: 100, a mix of multiple-choice and multiple-response.
- Time: 120 minutes total, which includes five minutes for the candidate agreement and five minutes for the tutorial. That leaves roughly 110 minutes of actual answering time, or a little over a minute per question.
- Delivery: Pearson VUE testing centers or OnVUE online proctoring.
- Open or closed book: closed book. No permission for an external calculator has been verified, so do not plan on bringing one.
- Online proctoring: if you test from home, OnVUE environment and identity requirements apply, so check them before exam day.
A Score-Driven Study Sequence
Because the passing score is a single percentage over a weighted blueprint, the most efficient plan front-loads the heavy domains and reserves the final stretch for mixed practice at or above 61%. This is one way to sequence the material; adjust the pace to your experience. Our CIoTSP Study Guide covers resources in more depth.
Securing IoT Portals
- Work through Domain 1 first because it is 29% of the exam
- Take a short domain quiz to find weak sub-topics
AAA and Network Services
- Cover Domains 2 and 3 together, since access control and network protection overlap heavily
- Practice multiple-response items specifically
Data, Privacy, Firmware, Physical
- Cover Domains 4 through 7, spending the most time on Securing Data
- Do not skip Physical Security; 7% is still around seven questions
Full-Length Timed Practice
- Take 100-question timed sets and score them against 61%
- Review every miss by domain and revisit the weakest one
Eligibility is simple: there are no formal education, experience, training-hours, reference, or prior-certification prerequisites, though IoT and security familiarity is recommended. See CIoTSP Requirements for the full picture. If you want to test yourself against realistic questions, start with the CIoTSP practice tests.
Voucher, Retake, and Renewal Rules
Knowing the policy around the passing score reduces anxiety, because a first attempt below the line is not the end of the road.
| Item | What the Current Policy Says |
|---|---|
| Voucher price | $367.50 USD (current) |
| Retake | One free same-version retake within the voucher validity period, normally 18 months |
| Certification validity | Three years |
| Renewal route | Take the latest-version exam before expiration |
| Continuing education | CIoTSP was not on the reviewed CertNexus CE-eligible list; do not assume 90 CE credits or a CE-only renewal fee applies |
The free same-version retake is valuable, but it is not an excuse to treat the first attempt as a trial run. Review your result by domain after any attempt and let that guide your next round of study. For a full cost picture beyond the voucher, see CIoTSP Certification Cost 2026.
Key Takeaway
Renewal is by retaking the latest-version exam, not by collecting CE credits. Put a reminder on your calendar well before the three-year mark so a lapse does not force you to start over.
What a Pass Gets You
Clearing the cut score earns a vendor-neutral credential aimed at professionals who secure connected devices and the services around them. Typical interest comes from IoT and embedded security roles, network and systems engineers extending their scope to connected devices, and teams responsible for securing smart-device deployments. Roles vary widely by employer, so it helps to read CIoTSP Jobs alongside Is the CIoTSP Certification Worth It? to decide how it fits your career path. For compensation context, see the CIoTSP Salary Guide.
When you are ready to measure yourself against the 61% benchmark, the practice question bank is the quickest way to find out where you stand.
Frequently Asked Questions
The current official page lists 60% or 61% depending on the exam form, while the older blueprint says 60%. Because you cannot know which form you will receive, aim for at least 61% on practice exams.
The exam has 100 questions, so the percentage translates to roughly 60 or 61 correct answers. Treat every question as scored, since unscored items are not identified to candidates.
Securing IoT Portals at 29% is the largest domain by far. Authentication, Authorization, and Accounting, Securing Network Services, and Securing Data each add 14%, so those four domains together make up most of the exam.
Current policy includes one free same-version retake within the voucher validity period, normally 18 months. Use your result feedback to target the domains where you lost the most points before retesting.
It is valid for three years. The verified renewal route is taking the latest-version exam before expiration. CIoTSP was not on the reviewed CE-eligible list, so do not assume continuing education credits will renew it.