- What the CIoTSP Actually Requires
- Recommended Background Before You Sit ITS-110
- Exam Format, Delivery, and Candidate Requirements
- Voucher, Fee, and Retake Mechanics
- Qualifying Yourself Domain by Domain
- Who Benefits Most From This Credential
- Validity and Renewal Rules
- A Domain-Weighted Preparation Sequence
- Frequently Asked Questions
- CertNexus sets no formal education, experience, training-hour, reference, or prior-certification prerequisites for the ITS-110 exam.
- The current voucher is $367.50 USD and includes one free same-version retake within normal 18-month voucher validity.
- ITS-110 has 100 questions in 120 minutes; five minutes each go to the candidate agreement and tutorial.
- Securing IoT Portals carries 29% of the blueprint, more than any other domain.
What the CIoTSP Actually Requires
The Certified Internet of Things Security Practitioner (CIoTSP) is issued by CertNexus, and the exam code is ITS-110. If you are searching for a checklist of mandatory degrees, years of experience, or sponsor signatures, the short answer is that there isn't one. CertNexus publishes no formal education, experience, training-hours, reference, or prior-certification prerequisites for this credential. You do not need to hold another certification first, and you do not need to document a work history.
That makes CIoTSP unusually accessible compared with credentials that gate the exam behind verified experience. In practice, "qualifying" means two things: buying an exam voucher and demonstrating, under test conditions, that you can apply IoT security concepts across the seven blueprint domains. There is no application review that can reject you.
If you are new to the topic and want a plain-language orientation before reading further, What Is CIoTSP Certification? explains the credential's purpose and scope.
Recommended Background Before You Sit ITS-110
Because nothing is mandatory, your real "requirements" are the knowledge gaps you need to close. CertNexus recommends familiarity with both IoT and security. Concretely, candidates who feel comfortable on exam day tend to share a working understanding of the following:
- Core networking: addressing, common protocols, how devices reach gateways and cloud back ends, and where traffic can be intercepted.
- Basic security principles: confidentiality, integrity, availability, least privilege, and defense in depth.
- Cryptography fundamentals: the difference between symmetric and asymmetric approaches, hashing, certificates, and why key management is hard on constrained devices.
- Embedded and constrained-device concepts: limited memory, limited compute, long deployment lifetimes, and the difficulty of patching devices in the field.
- Web and portal concepts: how management consoles and APIs expose device fleets, and how they are attacked.
You do not need to be a firmware engineer or a penetration tester. The exam is a practitioner-level assessment of security decision-making across the IoT lifecycle, not a hands-on lab. For training options that help fill gaps, see CIoTSP Training.
Exam Format, Delivery, and Candidate Requirements
Meeting the exam-day requirements is as important as meeting any knowledge standard. Here is what is verified about ITS-110 delivery:
| Item | Detail |
|---|---|
| Certifying body | CertNexus |
| Exam code | ITS-110 |
| Question count | 100 multiple-choice and multiple-response questions |
| Time allowed | 120 minutes, including five minutes for the candidate agreement and five minutes for the tutorial |
| Passing score | 60% or 61% depending on form; older blueprint says 60% |
| Delivery | Pearson VUE testing centers or OnVUE online proctoring |
| Reference materials | Closed book |
| Blueprint | Version 1.4, issued 15 January 2019, modified 29 June 2022 |
Closed book, and what that implies
The exam is closed book. No notes, no browser, no outside references. I could not verify any permission for an external calculator, so do not plan on bringing one; if a question involves arithmetic, expect it to be simple enough to reason through by hand. If calculator access matters to you, confirm the current testing rules with the delivery provider when you schedule.
Testing center versus online proctoring
You can test at a Pearson VUE center or remotely through OnVUE. Choosing online proctoring comes with its own requirements: a quiet private space, a working computer and webcam, a stable connection, and compliance with the proctor's room and conduct rules. Treat those as part of your eligibility checklist. A candidate who is knowledge-ready but fails a system check or room inspection loses momentum and possibly scheduling flexibility. For timing details, review CIoTSP Exam Dates 2026: Testing Windows, Deadlines & Scheduling.
Why the time breakdown matters
Of the 120 minutes, ten go to the candidate agreement and tutorial, leaving roughly 110 minutes of actual question time for 100 items. That is a little over a minute per question, which is comfortable for single-answer items but tighter for multiple-response questions where you must evaluate every option. Practice pacing before test day.
Voucher, Fee, and Retake Mechanics
The financial requirement is a single exam voucher. The current price is $367.50 USD. There is no separate application fee listed in the verified facts, and no mandatory course purchase. Beyond the voucher, your costs are whatever study resources you choose. For the full picture, see CIoTSP Certification Cost 2026: Complete Pricing Breakdown.
Two cautions. First, "same-version" is a condition worth confirming when you purchase, since a version change could affect eligibility for the free retake. Second, the 18-month figure is described as normal, so check the terms attached to your specific voucher rather than assuming. Understanding how the scoring line works also helps you interpret a failed attempt; see CIoTSP Passing Score 2026: Exactly What You Need to Pass.
Qualifying Yourself Domain by Domain
Since the real gate is competence, the most useful "requirements" list maps to the seven domains. The weights tell you where depth matters most.
Domain 1: Securing IoT Portals (29%)
The largest domain, and the one where weak preparation costs the most. Portals are the management and user-facing surfaces of an IoT deployment.
- Common web and application weaknesses as they apply to device-management consoles and dashboards
- Secure session handling, input validation, and protecting administrative interfaces
- Exposure created by APIs and cloud-connected management layers
Domain 2: Implementing Authentication, Authorization, and Accounting (14%)
How devices, users, and services prove identity and receive appropriate access.
- Device identity versus user identity, and credentials suited to constrained hardware
- Role-based access and least-privilege design for fleets
- Logging and accountability so actions can be traced
Domain 3: Securing Network Services (14%)
Protecting communication paths between devices, gateways, and back-end systems.
- Segmentation and limiting the services a device exposes
- Secure protocol choices and transport protection
- Monitoring for abnormal device behavior
Domain 4: Securing Data (14%)
Protecting information at rest, in transit, and across its lifecycle.
- Encryption choices and key-handling constraints on devices
- Data integrity and protection of sensor and telemetry information
- Secure storage and disposal practices
Domain 5: Addressing Privacy Concerns (12%)
IoT devices often collect personal or behavioral data without obvious user awareness.
- Data minimization and purpose limitation
- User consent and transparency considerations
- Privacy risks specific to always-on, sensor-heavy devices
Domain 6: Securing Software/Firmware (10%)
The integrity and update story for code running on devices.
- Secure update mechanisms and verifying firmware authenticity
- Risks from outdated components and unpatched devices
- Secure development and lifecycle practices
Domain 7: Enhancing Physical Security (7%)
Devices live in the field, where attackers can touch them.
- Tamper resistance and tamper detection
- Protecting debug interfaces and physical ports
- Considerations for devices deployed in uncontrolled locations
For a deeper treatment of each area and how questions are framed, read CIoTSP Exam Domains 2026: Complete Guide to All 7 Content Areas. The weights sum to 100%, and the top three domains alone account for 57% of the blueprint, so a candidate with strong portal and identity knowledge starts well ahead.
Who Benefits Most From This Credential
With no prerequisites, CIoTSP attracts a broad audience. The profiles that tend to get the most from it include:
- Security analysts and engineers moving into connected-device environments such as industrial, healthcare, building automation, or consumer products.
- IoT developers and solution architects who build devices or platforms and want a structured security vocabulary.
- Network and systems administrators who now manage fleets of connected endpoints.
- Product, compliance, and risk professionals who need to evaluate IoT security claims and privacy exposure.
- Career changers and students who want a credential that does not require prior certifications or documented experience to attempt.
Employers in manufacturing, healthcare technology, smart-infrastructure, telecommunications, and device-maker supply chains are the natural audiences for IoT security skills. To explore how the credential is positioned in the market, see CIoTSP Jobs, and for whether the investment makes sense for you, Is the CIoTSP Certification Worth It? Complete ROI Analysis 2026. Compensation questions are covered in CIoTSP Salary Guide 2026: Complete Earnings Analysis.
Validity and Renewal Rules
Once you pass, the credential is valid for three years. The verified renewal route is to pass the latest-version exam before your credential expires.
Key Takeaway
Do not assume a continuing-education shortcut. CIoTSP was not on the reviewed CertNexus CE-eligible list, so do not count on earning 90 CE credits or paying a CE-only renewal fee. Plan on retaking the current exam version, and calendar that date well before expiration.
This matters for planning. Because renewal means sitting a newer version of the exam, content may shift between your first attempt and your renewal. The blueprint you study today is version 1.4, but you should always check which version is current when you schedule.
A Domain-Weighted Preparation Sequence
Generic study advice is plentiful elsewhere; the only planning logic worth stating here is tied to the blueprint. Sequence your preparation by weight and by dependency: start with the heaviest domain, then build the identity and network foundations that later domains rely on, and leave the lightest domain for last.
Securing IoT Portals
- Spend the most time here because it is 29% of the exam
- Work through portal and API weaknesses and how they apply to device management
Authentication, Authorization, Accounting plus Network Services
- Identity concepts underpin both domains, so study them together
- Cover segmentation, protocol choices, and logging
Securing Data and Privacy
- Pair encryption and data protection with privacy principles
- Note where technical controls and privacy obligations overlap
Software/Firmware and Physical Security
- Cover update integrity, then tamper and port protection
- Finish with timed practice across all seven domains
This is a template, not a mandate; compress or extend it to match your background. For a fuller method, work from CIoTSP Study Guide 2026: How to Pass on Your First Attempt, and use CIoTSP Cheat Sheet 2026: One-Page Review of Must-Know Facts for last-week review. When you are ready to test yourself under realistic conditions, run a set on the CIoTSP practice test site and use the results to decide which domain deserves another pass before you book your voucher.
If you are still deciding whether this is the right credential, What Is CIoTSP? and What Does CIoTSP Stand For? give quick grounding. Data on outcomes is discussed in CIoTSP Pass Rate 2026: What the Data Shows. Our practice questions are built to mirror the multiple-choice and multiple-response style you will see on ITS-110.
Frequently Asked Questions
No. CertNexus lists no formal education, experience, training-hours, reference, or prior-certification prerequisites for ITS-110. IoT and security familiarity is recommended, but it is not enforced.
You purchase an exam voucher, currently $367.50 USD, and schedule the exam through Pearson VUE, either at a testing center or via OnVUE online proctoring. Confirm current pricing and terms at the time of purchase.
Current policy includes one free same-version retake within voucher validity, which is normally 18 months. Check the specific terms of your voucher, and use your first attempt to identify weak domains before retaking.
The exam is closed book, so notes and outside references are not allowed. External-calculator permission could not be verified, so do not plan on having one. Online-proctoring rules also apply if you test remotely.
The credential is valid for three years. The verified renewal route is passing the latest-version exam before expiration. CIoTSP was not on the reviewed CertNexus CE-eligible list, so do not assume a CE-credit renewal option.