CIoTSP logo
Focused certification exam prep
Start practice

CIoTSP Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • CertNexus sets no formal education, experience, training-hour, reference, or prior-certification prerequisites for the ITS-110 exam.
  • The current voucher is $367.50 USD and includes one free same-version retake within normal 18-month voucher validity.
  • ITS-110 has 100 questions in 120 minutes; five minutes each go to the candidate agreement and tutorial.
  • Securing IoT Portals carries 29% of the blueprint, more than any other domain.

What the CIoTSP Actually Requires

The Certified Internet of Things Security Practitioner (CIoTSP) is issued by CertNexus, and the exam code is ITS-110. If you are searching for a checklist of mandatory degrees, years of experience, or sponsor signatures, the short answer is that there isn't one. CertNexus publishes no formal education, experience, training-hours, reference, or prior-certification prerequisites for this credential. You do not need to hold another certification first, and you do not need to document a work history.

That makes CIoTSP unusually accessible compared with credentials that gate the exam behind verified experience. In practice, "qualifying" means two things: buying an exam voucher and demonstrating, under test conditions, that you can apply IoT security concepts across the seven blueprint domains. There is no application review that can reject you.

Eligibility versus readiness: The absence of prerequisites is a policy statement, not a prediction of how easy the exam is. CertNexus recommends IoT and security familiarity, and the blueprint rewards candidates who can reason about real device ecosystems. For a candid view of difficulty, see How Hard Is the CIoTSP Exam? Complete Difficulty Guide 2026.

If you are new to the topic and want a plain-language orientation before reading further, What Is CIoTSP Certification? explains the credential's purpose and scope.

Because nothing is mandatory, your real "requirements" are the knowledge gaps you need to close. CertNexus recommends familiarity with both IoT and security. Concretely, candidates who feel comfortable on exam day tend to share a working understanding of the following:

  • Core networking: addressing, common protocols, how devices reach gateways and cloud back ends, and where traffic can be intercepted.
  • Basic security principles: confidentiality, integrity, availability, least privilege, and defense in depth.
  • Cryptography fundamentals: the difference between symmetric and asymmetric approaches, hashing, certificates, and why key management is hard on constrained devices.
  • Embedded and constrained-device concepts: limited memory, limited compute, long deployment lifetimes, and the difficulty of patching devices in the field.
  • Web and portal concepts: how management consoles and APIs expose device fleets, and how they are attacked.

You do not need to be a firmware engineer or a penetration tester. The exam is a practitioner-level assessment of security decision-making across the IoT lifecycle, not a hands-on lab. For training options that help fill gaps, see CIoTSP Training.

Exam Format, Delivery, and Candidate Requirements

Meeting the exam-day requirements is as important as meeting any knowledge standard. Here is what is verified about ITS-110 delivery:

ItemDetail
Certifying bodyCertNexus
Exam codeITS-110
Question count100 multiple-choice and multiple-response questions
Time allowed120 minutes, including five minutes for the candidate agreement and five minutes for the tutorial
Passing score60% or 61% depending on form; older blueprint says 60%
DeliveryPearson VUE testing centers or OnVUE online proctoring
Reference materialsClosed book
BlueprintVersion 1.4, issued 15 January 2019, modified 29 June 2022

Closed book, and what that implies

The exam is closed book. No notes, no browser, no outside references. I could not verify any permission for an external calculator, so do not plan on bringing one; if a question involves arithmetic, expect it to be simple enough to reason through by hand. If calculator access matters to you, confirm the current testing rules with the delivery provider when you schedule.

Testing center versus online proctoring

You can test at a Pearson VUE center or remotely through OnVUE. Choosing online proctoring comes with its own requirements: a quiet private space, a working computer and webcam, a stable connection, and compliance with the proctor's room and conduct rules. Treat those as part of your eligibility checklist. A candidate who is knowledge-ready but fails a system check or room inspection loses momentum and possibly scheduling flexibility. For timing details, review CIoTSP Exam Dates 2026: Testing Windows, Deadlines & Scheduling.

Why the time breakdown matters

Of the 120 minutes, ten go to the candidate agreement and tutorial, leaving roughly 110 minutes of actual question time for 100 items. That is a little over a minute per question, which is comfortable for single-answer items but tighter for multiple-response questions where you must evaluate every option. Practice pacing before test day.

Voucher, Fee, and Retake Mechanics

The financial requirement is a single exam voucher. The current price is $367.50 USD. There is no separate application fee listed in the verified facts, and no mandatory course purchase. Beyond the voucher, your costs are whatever study resources you choose. For the full picture, see CIoTSP Certification Cost 2026: Complete Pricing Breakdown.

The retake safety net: Current policy includes one free same-version retake within voucher validity, which is normally 18 months. That means a first attempt does not have to be a high-stakes, one-shot event. Use the window deliberately: if you do not pass, study the domains where you were weakest and retake on the same exam version before the voucher expires.

Two cautions. First, "same-version" is a condition worth confirming when you purchase, since a version change could affect eligibility for the free retake. Second, the 18-month figure is described as normal, so check the terms attached to your specific voucher rather than assuming. Understanding how the scoring line works also helps you interpret a failed attempt; see CIoTSP Passing Score 2026: Exactly What You Need to Pass.

Qualifying Yourself Domain by Domain

Since the real gate is competence, the most useful "requirements" list maps to the seven domains. The weights tell you where depth matters most.

Domain 1: Securing IoT Portals (29%)

The largest domain, and the one where weak preparation costs the most. Portals are the management and user-facing surfaces of an IoT deployment.

  • Common web and application weaknesses as they apply to device-management consoles and dashboards
  • Secure session handling, input validation, and protecting administrative interfaces
  • Exposure created by APIs and cloud-connected management layers

Domain 2: Implementing Authentication, Authorization, and Accounting (14%)

How devices, users, and services prove identity and receive appropriate access.

  • Device identity versus user identity, and credentials suited to constrained hardware
  • Role-based access and least-privilege design for fleets
  • Logging and accountability so actions can be traced

Domain 3: Securing Network Services (14%)

Protecting communication paths between devices, gateways, and back-end systems.

  • Segmentation and limiting the services a device exposes
  • Secure protocol choices and transport protection
  • Monitoring for abnormal device behavior

Domain 4: Securing Data (14%)

Protecting information at rest, in transit, and across its lifecycle.

  • Encryption choices and key-handling constraints on devices
  • Data integrity and protection of sensor and telemetry information
  • Secure storage and disposal practices

Domain 5: Addressing Privacy Concerns (12%)

IoT devices often collect personal or behavioral data without obvious user awareness.

  • Data minimization and purpose limitation
  • User consent and transparency considerations
  • Privacy risks specific to always-on, sensor-heavy devices

Domain 6: Securing Software/Firmware (10%)

The integrity and update story for code running on devices.

  • Secure update mechanisms and verifying firmware authenticity
  • Risks from outdated components and unpatched devices
  • Secure development and lifecycle practices

Domain 7: Enhancing Physical Security (7%)

Devices live in the field, where attackers can touch them.

  • Tamper resistance and tamper detection
  • Protecting debug interfaces and physical ports
  • Considerations for devices deployed in uncontrolled locations

For a deeper treatment of each area and how questions are framed, read CIoTSP Exam Domains 2026: Complete Guide to All 7 Content Areas. The weights sum to 100%, and the top three domains alone account for 57% of the blueprint, so a candidate with strong portal and identity knowledge starts well ahead.

Who Benefits Most From This Credential

With no prerequisites, CIoTSP attracts a broad audience. The profiles that tend to get the most from it include:

  • Security analysts and engineers moving into connected-device environments such as industrial, healthcare, building automation, or consumer products.
  • IoT developers and solution architects who build devices or platforms and want a structured security vocabulary.
  • Network and systems administrators who now manage fleets of connected endpoints.
  • Product, compliance, and risk professionals who need to evaluate IoT security claims and privacy exposure.
  • Career changers and students who want a credential that does not require prior certifications or documented experience to attempt.

Employers in manufacturing, healthcare technology, smart-infrastructure, telecommunications, and device-maker supply chains are the natural audiences for IoT security skills. To explore how the credential is positioned in the market, see CIoTSP Jobs, and for whether the investment makes sense for you, Is the CIoTSP Certification Worth It? Complete ROI Analysis 2026. Compensation questions are covered in CIoTSP Salary Guide 2026: Complete Earnings Analysis.

Validity and Renewal Rules

Once you pass, the credential is valid for three years. The verified renewal route is to pass the latest-version exam before your credential expires.

Key Takeaway

Do not assume a continuing-education shortcut. CIoTSP was not on the reviewed CertNexus CE-eligible list, so do not count on earning 90 CE credits or paying a CE-only renewal fee. Plan on retaking the current exam version, and calendar that date well before expiration.

This matters for planning. Because renewal means sitting a newer version of the exam, content may shift between your first attempt and your renewal. The blueprint you study today is version 1.4, but you should always check which version is current when you schedule.

A Domain-Weighted Preparation Sequence

Generic study advice is plentiful elsewhere; the only planning logic worth stating here is tied to the blueprint. Sequence your preparation by weight and by dependency: start with the heaviest domain, then build the identity and network foundations that later domains rely on, and leave the lightest domain for last.

Week 1-2

Securing IoT Portals

  • Spend the most time here because it is 29% of the exam
  • Work through portal and API weaknesses and how they apply to device management
Week 3

Authentication, Authorization, Accounting plus Network Services

  • Identity concepts underpin both domains, so study them together
  • Cover segmentation, protocol choices, and logging
Week 4

Securing Data and Privacy

  • Pair encryption and data protection with privacy principles
  • Note where technical controls and privacy obligations overlap
Week 5

Software/Firmware and Physical Security

  • Cover update integrity, then tamper and port protection
  • Finish with timed practice across all seven domains

This is a template, not a mandate; compress or extend it to match your background. For a fuller method, work from CIoTSP Study Guide 2026: How to Pass on Your First Attempt, and use CIoTSP Cheat Sheet 2026: One-Page Review of Must-Know Facts for last-week review. When you are ready to test yourself under realistic conditions, run a set on the CIoTSP practice test site and use the results to decide which domain deserves another pass before you book your voucher.

If you are still deciding whether this is the right credential, What Is CIoTSP? and What Does CIoTSP Stand For? give quick grounding. Data on outcomes is discussed in CIoTSP Pass Rate 2026: What the Data Shows. Our practice questions are built to mirror the multiple-choice and multiple-response style you will see on ITS-110.

Frequently Asked Questions

Do I need work experience or another certification to take the CIoTSP exam?

No. CertNexus lists no formal education, experience, training-hours, reference, or prior-certification prerequisites for ITS-110. IoT and security familiarity is recommended, but it is not enforced.

How do I register, and what does it cost?

You purchase an exam voucher, currently $367.50 USD, and schedule the exam through Pearson VUE, either at a testing center or via OnVUE online proctoring. Confirm current pricing and terms at the time of purchase.

What happens if I fail on the first attempt?

Current policy includes one free same-version retake within voucher validity, which is normally 18 months. Check the specific terms of your voucher, and use your first attempt to identify weak domains before retaking.

Can I use notes or a calculator during the exam?

The exam is closed book, so notes and outside references are not allowed. External-calculator permission could not be verified, so do not plan on having one. Online-proctoring rules also apply if you test remotely.

How long is the certification valid, and how do I renew?

The credential is valid for three years. The verified renewal route is passing the latest-version exam before expiration. CIoTSP was not on the reviewed CertNexus CE-eligible list, so do not assume a CE-credit renewal option.

Ready to pass your CIoTSP exam?

Put this into practice with free CIoTSP questions across every exam domain.