- Defining CIoTSP: The Credential in Plain Terms
- Who Issues It and What the Exam Code Means
- Exam Format and Question Style
- The Seven Domains at a Glance
- Why Securing IoT Portals Dominates the Blueprint
- Concrete Topics You Must Be Able to Explain
- Registration, Voucher, and Retake Mechanics
- Who Should Pursue It and Who Hires for It
- Validity and Renewal
- Sequencing Your Preparation Around the Blueprint
- Frequently Asked Questions
- CIoTSP stands for Certified Internet of Things Security Practitioner, issued by CertNexus; the exam code is ITS-110.
- The exam has 100 multiple-choice and multiple-response questions in 120 minutes, with a passing score of roughly 60%.
- Securing IoT Portals carries 29% of the blueprint, more than any other domain.
- No formal prerequisites exist, though IoT and security familiarity is recommended before you sit the exam.
Defining CIoTSP: The Credential in Plain Terms
CIoTSP is the acronym for Certified Internet of Things Security Practitioner. It is a vendor-neutral certification aimed at professionals who design, deploy, operate, or assess connected-device ecosystems and need to build security into every layer of them. If you have seen the same four letters attached to other credentials elsewhere, set those aside. Everything on this page refers only to the CertNexus credential examined through exam ITS-110.
The certification's premise is simple: IoT environments fail differently from traditional IT environments. Devices are often constrained in memory and processing power, deployed in physically exposed locations, difficult to patch, and connected through a mix of protocols that were never designed with adversaries in mind. A practitioner-level credential validates that you can reason about those weaknesses across the full stack, from the device and its firmware to the network services, the management portal, the data it generates, and the privacy obligations that data creates.
For a related angle on terminology, see our short explainers on what CIoTSP stands for and the broader CIoTSP certification overview.
Who Issues It and What the Exam Code Means
The credential is issued by CertNexus, an organization that focuses on emerging-technology certifications. The exam you take to earn it is coded ITS-110. When you search for study materials, book a voucher, or confirm the correct blueprint, that code is the identifier that keeps you anchored to the right exam.
The current exam objectives are published as blueprint v1.4, originally issued on 15 January 2019 and modified on 29 June 2022. Because the blueprint is the authoritative statement of what can be tested, it should be the spine of your preparation. Our complete guide to all seven content areas walks through each domain's objectives in more detail.
Exam Format and Question Style
The ITS-110 exam consists of 100 questions delivered as a mix of multiple-choice (one correct answer) and multiple-response (select all that apply) items. You are given 120 minutes in total, and that window includes five minutes for the candidate agreement and five minutes for the tutorial, so your effective working time on questions is somewhat shorter than the headline figure suggests.
| Feature | CIoTSP (ITS-110) |
|---|---|
| Issuing body | CertNexus |
| Number of questions | 100 |
| Question types | Multiple-choice and multiple-response |
| Total time | 120 minutes (includes agreement and tutorial time) |
| Passing score | Approximately 60% (60% or 61% depending on form) |
| Delivery | Pearson VUE test center or OnVUE online proctoring |
| Book policy | Closed book |
| Formal prerequisites | None |
What the question style demands
Multiple-response items are where candidates most often lose points. They test whether you can identify all correct controls for a scenario rather than just recognize one familiar term. Expect scenario framing: a described deployment with a stated weakness, followed by a request to choose the best mitigation or the set of appropriate mitigations. The exam rewards applied judgment about IoT architectures more than rote definition recall.
Because the test is closed book and you are working in a fixed time block, pacing matters. Roughly a minute per question is a workable average, leaving a margin to revisit flagged multiple-response items. For a frank look at how this feels in practice, read our difficulty analysis of the CIoTSP exam. If you want the scoring specifics, our passing score breakdown covers the 60% versus 61% nuance.
The Seven Domains at a Glance
The blueprint divides the exam into seven domains whose weights total 100%. Knowing the weights tells you where the questions will concentrate.
| Domain | Weight |
|---|---|
| 1. Securing IoT Portals | 29% |
| 2. Implementing Authentication, Authorization, and Accounting | 14% |
| 3. Securing Network Services | 14% |
| 4. Securing Data | 14% |
| 5. Addressing Privacy Concerns | 12% |
| 6. Securing Software/Firmware | 10% |
| 7. Enhancing Physical Security | 7% |
Three domains at 14% each, plus privacy at 12%, mean the middle of the blueprint is broad and evenly weighted. Physical security, at 7%, is the smallest slice but should not be ignored, since IoT devices frequently live in unattended locations where tampering is a realistic threat.
Why Securing IoT Portals Dominates the Blueprint
At 29%, Securing IoT Portals is by far the heaviest domain, worth nearly as much as the next two domains combined. In IoT terminology, the portal is the management and interaction surface: the web dashboards, mobile apps, cloud consoles, and APIs through which users and administrators configure devices and consume their data. Because the portal is typically internet-facing and aggregates control over many devices, a weakness there can cascade across an entire fleet.
Domain 1: Securing IoT Portals (29%)
Candidates must understand how portal-layer weaknesses expose devices and data, and which controls reduce that exposure.
- Common web and API attack classes as they apply to device-management interfaces
- Secure session handling, credential recovery flows, and account lockout design
- Input validation and output handling for device-originated data displayed in portals
- Secure configuration of cloud-hosted management consoles and mobile companion apps
- Testing and review approaches that surface portal vulnerabilities before attackers do
Because this domain is so large, a candidate who is strong on web application security fundamentals starts with a real advantage on the exam. Conversely, a candidate with embedded-systems experience but little web security background should budget extra time here. Our CIoTSP study guide suggests how to allocate that time against the other domains.
Concrete Topics You Must Be Able to Explain
Beyond the portal, each remaining domain has a recognizable set of subjects. The lists below are the kinds of ideas that appear repeatedly across the blueprint objectives.
Domain 2: Authentication, Authorization, and Accounting (14%)
Controlling who and what can talk to your devices and services, and keeping a record of it.
- Device identity and credential provisioning at scale, including why default credentials are dangerous
- Strong authentication choices for users, devices, and service-to-service communication
- Role-based and least-privilege authorization models for administrators and operators
- Logging and accounting practices that support auditing and incident investigation
Domain 3: Securing Network Services (14%)
Protecting communications and the services devices expose or consume.
- Transport protection for common IoT communication patterns
- Hardening exposed services and closing unnecessary ports and protocols
- Network segmentation to contain compromised devices
- Understanding how wireless and constrained-network protocols change the threat picture
Domain 4: Securing Data (14%)
Protecting information at rest, in transit, and across its lifecycle.
- Encryption choices and key management challenges on resource-limited devices
- Data integrity and authenticity for sensor readings and commands
- Retention, minimization, and secure disposal of collected data
Domain 5: Addressing Privacy Concerns (12%)
Recognizing that connected devices often collect personal or behavioral information.
- Identifying what personal data a device or service collects and why
- Privacy-by-design principles applied during development and deployment
- Consent, transparency, and regulatory awareness at a conceptual level
Domain 6: Securing Software/Firmware (10%)
Keeping the code that runs on devices trustworthy over its lifetime.
- Secure update mechanisms, including signed images and rollback protection
- Secure development practices and handling of third-party components
- Boot integrity concepts and protecting firmware from tampering
Domain 7: Enhancing Physical Security (7%)
Defending devices that attackers can touch.
- Tamper resistance and tamper detection
- Protecting debug interfaces and exposed ports
- Securing storage media and preventing extraction of secrets from hardware
Registration, Voucher, and Retake Mechanics
The exam is delivered through Pearson VUE, either at a physical testing center or remotely through OnVUE online proctoring. The current voucher price is $367.50 USD. If you choose online proctoring, the program's environment and technical requirements apply, so complete any system checks well before exam day rather than minutes before your appointment.
There are no formal education, experience, training-hour, reference, or prior-certification prerequisites to register. CertNexus does recommend familiarity with IoT and security concepts, and that recommendation is worth taking seriously given the applied nature of the questions. Our requirements and eligibility article covers this in greater depth.
Current policy includes one free same-version retake within the voucher's validity period, which is normally 18 months. That safety net lowers the cost of a first attempt that does not go to plan, but it is not a reason to sit unprepared. A same-version retake means you will face the same blueprint, so a failed attempt is best treated as diagnostic information about which domains need work. For a complete financial view, including what falls outside the voucher, see the CIoTSP certification cost breakdown, and for timing logistics see the exam dates and scheduling guide.
Key Takeaway
Confirm your testing method early. If you plan to use OnVUE, run the system check and review the online-proctoring rules ahead of time, since closed-book conditions and workspace requirements are enforced.
Who Should Pursue It and Who Hires for It
CIoTSP suits professionals whose work touches connected devices and who need a structured credential showing security competence across the IoT stack. Typical profiles include:
- Security analysts and engineers expanding from enterprise IT into device-heavy environments
- Embedded and firmware developers who want to formalize secure-development knowledge
- IoT solution architects and systems integrators responsible for end-to-end deployments
- Network and operations engineers supporting smart-building, industrial, healthcare, or consumer-device platforms
- Consultants and auditors assessing client IoT implementations
Employers most likely to value it are organizations that build or operate connected products and services: device manufacturers, industrial and building-automation firms, healthcare technology providers, utilities and smart-infrastructure operators, managed service providers, and security consultancies that assess IoT deployments. Hiring demand and compensation vary by region, role, and seniority, and we deliberately avoid quoting figures we cannot source. For discussion of how the credential tends to factor into hiring, see our pieces on CIoTSP jobs, the salary analysis, and the broader question of whether the certification is worth it.
Validity and Renewal
The CIoTSP credential is valid for three years. The verified renewal route is to pass the latest-version exam before your credential expires. It is worth stating clearly what is not established: CIoTSP does not appear on the reviewed CertNexus continuing-education-eligible list, so you should not assume that a 90-credit CE pathway or a CE-only renewal fee applies. Plan on the retest route unless CertNexus publishes something different, and confirm current renewal terms directly with the issuer as your expiration date approaches.
That three-year cycle has a practical implication for study: because renewal means taking the latest version of the exam, the knowledge you build now has to stay current. IoT threats, protocols, and regulations evolve, and the blueprint itself may be updated by the time you renew.
Sequencing Your Preparation Around the Blueprint
You do not need an elaborate methodology for this exam, but you do benefit from ordering your study by domain weight and dependency. Start with the heavy, foundational material, then layer in the narrower domains. The outline below is one reasonable arrangement for a candidate with moderate prior exposure.
Securing IoT Portals
- Review web and API threat categories against the 29% domain
- Map portal weaknesses to the controls the blueprint expects
Authentication, Authorization, Accounting and Network Services
- Cover identity, least privilege, and logging together
- Pair them with transport protection and segmentation, since they reinforce each other
Securing Data and Addressing Privacy Concerns
- Study encryption, integrity, and lifecycle handling
- Connect data protection to privacy-by-design reasoning
Software/Firmware, Physical Security, and Full Review
- Finish the two smallest domains
- Run timed practice sets and revisit weak multiple-response areas
Front-loading the portal domain makes sense because of its weight, and grouping authentication with network services and data with privacy reflects how those topics conceptually connect. Stretch or compress the plan to match your background. For a more detailed approach, use our full study guide, keep the one-page cheat sheet handy for final review, and test yourself regularly with the CIoTSP practice tests to see how scenario-based multiple-response questions actually feel under time pressure.
Frequently Asked Questions
CIoTSP stands for Certified Internet of Things Security Practitioner. It is a CertNexus credential earned by passing exam ITS-110, and it validates security knowledge across the IoT stack, from portals and networks to data, firmware, privacy, and physical protection.
The exam contains 100 multiple-choice and multiple-response questions with a 120-minute time limit. That total includes five minutes for the candidate agreement and five minutes for the tutorial, so your net time for answering questions is a bit less than two hours.
No. There are no formal education, experience, training-hour, reference, or prior-certification requirements. CertNexus recommends familiarity with IoT and security concepts, which is practical advice given how applied the questions are.
Securing IoT Portals, which carries 29% of the blueprint. It is the largest domain by a wide margin, so strong command of portal and web-interface security pays off disproportionately. The remaining domains range from 14% down to 7%.
Current policy includes one free same-version retake within the voucher's validity period, normally 18 months. Use the first attempt's experience to identify weak domains, then focus your remaining preparation there before rebooking.