- What the CIoTSP Credential Actually Is
- Who Issues It and Where It Fits
- Exam ITS-110: Format, Timing, and Question Style
- The Seven Domains and Their Weights
- Concrete Topics You Must Master
- Registration, Voucher, and Retake Mechanics
- Prerequisites and Who Should Sit the Exam
- Validity and Renewal
- Who Hires for IoT Security Skills
- Sequencing Your Preparation by Domain
- Frequently Asked Questions
- CIoTSP stands for Certified Internet of Things Security Practitioner, issued by CertNexus and earned by passing exam ITS-110.
- ITS-110 has 100 multiple-choice and multiple-response questions in a 120-minute session, closed book.
- Securing IoT Portals is the heaviest domain at 29%; the other six range from 7% to 14%.
- The current voucher is $367.50 USD and includes one free same-version retake within its validity window.
What the CIoTSP Credential Actually Is
CIoTSP stands for Certified Internet of Things Security Practitioner. It is a vendor-neutral professional certification that validates your ability to identify, analyze, and mitigate security risks across Internet of Things ecosystems. That means more than the devices themselves. The exam covers the web and mobile portals that manage devices, the network services that connect them, the data they produce, the firmware that runs them, and the physical environments where they live.
Unlike general-purpose security certifications that treat IoT as a footnote, this credential makes the connected-device ecosystem the entire subject. A candidate is expected to reason about an end-to-end deployment: a sensor reports to a gateway, the gateway talks to a cloud platform, an administrator manages everything through a portal, and an attacker looks for the weakest link among them.
If you are weighing whether this credential suits your career, our guide on whether the CIoTSP certification is worth it walks through the return-on-investment question in detail. For alternate phrasings of the same basic question, see What Is CIoTSP? and What Does CIoTSP Stand For?.
Who Issues It and Where It Fits
The credential is issued by CertNexus, a vendor-neutral certification body focused on emerging technology disciplines. The exam code is ITS-110, and every CIoTSP-related fact you need to plan around, such as the blueprint, the voucher, and the retake policy, is tied to that code.
Because the credential is vendor-neutral, you will not be tested on a single manufacturer's product line. Instead, the questions focus on principles and controls that apply whether a deployment runs on one cloud provider or another, one radio protocol or another. That makes the knowledge portable, but it also means you cannot shortcut your preparation by memorizing one platform's console screens.
The current blueprint is version 1.4, issued 15 January 2019 and modified 29 June 2022. Candidates should always confirm they are studying against the blueprint that matches the exam form they will take, since the official objectives are what the questions are written from.
Exam ITS-110: Format, Timing, and Question Style
Understanding the mechanics of the exam removes a surprising amount of test-day stress. Here is the format at a glance:
| Attribute | ITS-110 Detail |
|---|---|
| Questions | 100 multiple-choice and multiple-response |
| Session length | 120 minutes |
| Time included in the session | Five minutes for the candidate agreement and five minutes for the tutorial |
| Passing score | 60% on the older blueprint; the current official page lists 60% or 61% depending on the exam form |
| Open or closed book | Closed book |
| Delivery | Pearson VUE testing centers or OnVUE online proctoring |
Two details deserve attention. First, the 120 minutes include roughly ten minutes of administrative time, so your effective working time on questions is closer to 110 minutes. That works out to a little over a minute per question, which is comfortable for most prepared candidates but punishing if you stall on long scenarios. Second, the passing mark is reported as 60% or 61% depending on the form, so aim comfortably above that range rather than planning to scrape through. For a deeper look at how the cut score is described, read CIoTSP Passing Score 2026.
What the questions feel like
Expect a mix of single-answer items and multiple-response items where you must select every correct option. The multiple-response format is where careless candidates lose points: a statement can be partially right, and you need to distinguish the complete set of correct controls from a plausible-looking subset. Many items are scenario-based, describing a deployment problem and asking which control, configuration, or process best addresses it.
For help calibrating your expectations, see How Hard Is the CIoTSP Exam?, and when you want to rehearse the format itself, the CIoTSP practice tests on this site are built around the same multiple-choice and multiple-response style.
The Seven Domains and Their Weights
The blueprint divides the exam into seven domains that total 100%. The distribution matters because it tells you where a single hour of study returns the most points.
| Domain | Name | Weight |
|---|---|---|
| 1 | Securing IoT Portals | 29% |
| 2 | Implementing Authentication, Authorization, and Accounting | 14% |
| 3 | Securing Network Services | 14% |
| 4 | Securing Data | 14% |
| 5 | Addressing Privacy Concerns | 12% |
| 6 | Securing Software/Firmware | 10% |
| 7 | Enhancing Physical Security | 7% |
Securing IoT Portals alone accounts for nearly three in every ten questions. Domains 2, 3, and 4 are each 14%, so together with the portal domain they make up 71% of the exam. Privacy, firmware, and physical security fill the remaining 29%. A full breakdown of each area is in CIoTSP Exam Domains 2026: Complete Guide to All 7 Content Areas.
Concrete Topics You Must Master
Below is a domain-by-domain view of the kinds of knowledge the exam rewards. Treat these as study prompts rather than an exhaustive syllabus, and always verify against the official blueprint.
Domain 1: Securing IoT Portals (29%)
Portals are the management and user-facing surfaces of an IoT deployment, typically web or mobile interfaces. Because they sit on the internet and control devices, they are a prime attack target.
- Common web-application weaknesses and how they apply to device management interfaces
- Secure session handling, input validation, and protection of administrative functions
- Credential handling, account recovery, and default-password risks
- Securing the APIs that portals use to talk to devices and back-end services
Domain 2: Implementing Authentication, Authorization, and Accounting (14%)
This domain is about proving who or what is connecting, deciding what it may do, and keeping a record of what it did.
- Authenticating both users and devices, including certificate-based and token-based approaches
- Role-based and least-privilege authorization models
- Accounting and logging so that actions are traceable
- Credential lifecycle: provisioning, rotation, and revocation for large device fleets
Domain 3: Securing Network Services (14%)
IoT devices rely on a variety of network protocols and services, and each exposes its own attack surface.
- Hardening exposed services and closing unnecessary ports
- Segmentation of IoT devices from sensitive enterprise networks
- Securing communications with appropriate transport-layer protections
- Monitoring for anomalous traffic and unauthorized devices
Domain 4: Securing Data (14%)
Data is generated, transmitted, stored, and eventually disposed of. Protection must follow it through that whole lifecycle.
- Encryption for data in transit and at rest, and the key-management challenges on constrained devices
- Integrity protection and detecting tampering
- Secure storage, backup, and retention practices
- Secure disposal of data and decommissioned devices
Domain 5: Addressing Privacy Concerns (12%)
Connected devices often collect sensitive personal or behavioral information, making privacy a design requirement rather than an afterthought.
- Data minimization and purpose limitation in device design
- Consent, transparency, and user control over collected data
- Recognizing how regulatory and compliance expectations shape IoT data handling
- Privacy risks created by aggregation and inference from seemingly harmless sensor data
Domain 6: Securing Software/Firmware (10%)
Firmware runs below the layer most administrators monitor, so flaws there can persist for the life of a device.
- Secure update mechanisms, including signed updates and rollback protection
- Secure boot and trusted execution concepts
- Vulnerability management and patching constraints in embedded environments
- Secure development practices and handling third-party components
Domain 7: Enhancing Physical Security (7%)
The smallest domain still matters, because IoT devices are frequently deployed in places an attacker can touch.
- Tamper resistance, tamper evidence, and protection of debug interfaces
- Controlling physical access to devices and gateways
- Protecting stored secrets from extraction through hardware access
- Deployment-environment considerations for unattended devices
Key Takeaway
Think in lifecycle terms. The exam repeatedly rewards candidates who can follow a single device or data stream from provisioning through operation to retirement and name the control that belongs at each stage.
Registration, Voucher, and Retake Mechanics
You register for ITS-110 through the CertNexus ecosystem and take it either at a Pearson VUE testing center or through OnVUE online proctoring from your own location. The current exam voucher price is $367.50 USD. Prices can change, so confirm the figure at checkout, and see CIoTSP Certification Cost 2026 for the broader budgeting picture including optional training.
Current policy includes one free same-version retake within the voucher's validity period, normally 18 months. That is a meaningful safety net, but treat it as insurance rather than strategy. The retake applies to the same exam version, so a failed first attempt is best used as a diagnostic: review which domains felt weakest and rebuild around them before the second try.
For scheduling windows and booking considerations, consult CIoTSP Exam Dates 2026.
Prerequisites and Who Should Sit the Exam
There are no formal education, experience, training-hours, reference, or prior-certification prerequisites for the exam. Anyone can register. That said, IoT and general security familiarity is recommended, and the exam assumes you can already speak the language of authentication, encryption, network segmentation, and vulnerability management. Our page on CIoTSP requirements and eligibility covers this in more detail.
The credential suits several kinds of professionals:
- Security analysts and engineers who are being asked to extend their coverage to connected devices
- IoT developers and embedded engineers who want to build security in from the start
- Network and systems administrators responsible for environments where device counts are growing
- Product and architecture staff who need to make sound design decisions about connected products
- Career changers with a technical background seeking a focused entry into IoT security
Validity and Renewal
The credential is valid for three years. The verified renewal route is to pass the latest version of the exam before your credential expires. Note that CIoTSP does not appear on the reviewed CertNexus continuing-education-eligible list, so do not assume that a block of continuing-education credits or a CE-only renewal fee applies to it. Plan on re-examination, and confirm the current renewal terms with CertNexus as your expiration date approaches.
Because the renewal path points to the latest exam version, your three-year clock is also a prompt to refresh your knowledge against whatever the current blueprint emphasizes.
Who Hires for IoT Security Skills
IoT security work shows up wherever connected devices are deployed at scale or built into products. Typical employer categories include:
- Device and hardware manufacturers shipping connected consumer or industrial products
- Industrial and operational-technology organizations such as manufacturers, utilities, and logistics operators
- Healthcare organizations managing connected medical and facility equipment
- Smart building and smart city operators running large sensor networks
- Managed security and consulting firms advising clients on connected-device risk
- Technology and cloud platform companies operating IoT back-end services
Job titles vary widely and often fold IoT responsibilities into broader security or engineering roles, so read postings for the skills requested rather than searching only for the credential name. For a closer look at roles and employers, see CIoTSP Jobs, and for the compensation side, CIoTSP Salary Guide 2026. Earnings depend heavily on role, region, and experience, so treat any single number with caution.
Sequencing Your Preparation by Domain
One short note on method: the most useful scheduling principle for this exam is to let the domain weights set your order and your time. Here is a sample sequence for a candidate with a few weeks to prepare, built around where the points are rather than generic habits.
Securing IoT Portals (29%)
- Start with the biggest domain so it gets the most repetition
- Work through web and API weaknesses as they apply to device-management portals
Authentication/Authorization/Accounting and Securing Network Services (14% each)
- Pair these because device identity and network segmentation reinforce each other
- Practice distinguishing user authentication from device authentication
Securing Data and Addressing Privacy Concerns (14% and 12%)
- Cover the data lifecycle, then layer privacy principles on top
- Focus on where encryption and minimization apply on constrained devices
Software/Firmware, Physical Security, and full review (10% and 7%)
- Learn the smaller domains quickly, then take full-length practice sets
- Revisit the portal domain last, since it carries the most weight
Adjust the pacing to your own background. A developer may move quickly through firmware but need more time on privacy; a network administrator may be the reverse. For a fuller plan, see the CIoTSP Study Guide 2026, keep the CIoTSP cheat sheet handy for last-minute review, and use the practice exams to confirm your weak domains before booking your slot.
Frequently Asked Questions
CIoTSP stands for Certified Internet of Things Security Practitioner. It is a CertNexus credential earned by passing exam ITS-110, and it focuses specifically on securing IoT ecosystems end to end.
ITS-110 contains 100 multiple-choice and multiple-response questions. You have 120 minutes in total, which includes five minutes for the candidate agreement and five minutes for the tutorial.
No. There are no formal education, experience, training-hours, reference, or prior-certification prerequisites. IoT and security familiarity is recommended, but not required to book the exam.
Securing IoT Portals is the largest domain at 29% of the exam. Because it carries so much weight, it deserves the most study time and the most practice questions.
The credential is valid for three years. The verified renewal route is to pass the latest version of the exam before expiration. It is not on the reviewed CE-eligible list, so do not assume continuing-education credits apply.