AWS SCS-C03 Guide: Exam Changes, SCS-C02 Comparison, and Key Updates

What Is AWS SCS-C03
The AWS Certified Security Specialty (SCS-C03) is the current version of AWS's advanced security certification, designed for professionals responsible for securing AWS workloads, managing identity and access controls, protecting sensitive data, and responding to security incidents in enterprise cloud environments. It targets security engineers, cloud security architects, and DevSecOps practitioners with real, hands on experience securing AWS environments.
There are no formal prerequisites, but AWS recommends three to five years of experience securing cloud solutions, and most successful candidates hold AWS Certified Solutions Architect – Associate first, since it establishes foundational AWS knowledge the Security Specialty exam assumes throughout.
SCS-C03 vs SCS-C02: What Actually Changed
AWS released SCS-C03 on December 2, 2025, and it represents a genuine restructuring rather than a superficial refresh. Here is what changed and why it matters.
Domain Restructuring
SCS-C02's "Threat Detection and Incident Response" domain and its "Security Logging and Monitoring" domain, which had overlapping concerns, were split into two cleaner, more focused domains in SCS-C03: Detection and Incident Response. This mirrors how modern Security Operations Centers actually organize their work, since detection teams and incident response teams represent genuinely distinct roles with distinct skill sets in real world security operations.
Additionally, "Management and Security Governance" was renamed to "Security Foundations and Governance," reflecting a subtle but meaningful shift in emphasis toward foundational, structural governance practices across multi-account environments.
IAM Weight Increased Significantly
Identity and Access Management jumped from 16% in SCS-C02 to 20% in SCS-C03, making it the single heaviest domain on the updated exam. This shift reflects a genuine industry trend: identity has increasingly become the primary attack surface in cloud environments, with misconfigured IAM policies, overly permissive roles, and confused deputy vulnerabilities causing more real world breaches than pure network misconfigurations.
New Generative AI and Machine Learning Security Content
This is the headline addition in SCS-C03. The exam now tests your ability to secure Amazon Bedrock workloads, implement guardrails for generative AI applications, protect model training data, and understand GuardDuty's detection capabilities specific to AI and ML activity. Importantly, this is not organized as a standalone seventh domain, despite what some third party study guides incorrectly suggest. AI and ML security content is woven into the existing six domains, particularly Infrastructure Security and Detection, rather than isolated separately.
Real world exam takers report that AI related questions tend to focus on practical IAM controls around generative AI, such as who can invoke which models and what resource based policies govern access, rather than deep machine learning theory. This means mastering IAM and KMS fundamentals still matters more than panicking over new AI specific study material.
New Question Formats
SCS-C02 used only two question formats: multiple choice, selecting one answer from four options, and multiple response, selecting two or more answers from five or more options. SCS-C03 introduces two additional formats. Ordering questions ask you to arrange three to five responses in the correct sequence, such as placing incident response steps in proper order. Matching questions ask you to pair AWS services or concepts with their correct descriptions, such as matching policy types like SCPs, RCPs, permission boundaries, and session policies to their appropriate use cases. These new formats test procedural knowledge and precise conceptual understanding rather than simple recognition.
New Services and Concepts Added
SCS-C03 introduces coverage of newer AWS security services and concepts that did not exist or were not emphasized in SCS-C02, including Amazon Security Lake for centralized security data management, AWS IAM Identity Center for centralized workforce identity management, AWS Verified Access for secure application access without a VPN, and automated security response workflows. Resource Control Policies, a relatively newer AWS Organizations feature, also appear as new content candidates need to add to their SCS-C02 era knowledge base.
SCS-C03 Exam Domains and Weightings
Here is the complete, official domain breakdown as published in AWS's SCS-C03 exam guide.
Domain | SCS-C03 Weight | SCS-C02 Equivalent Weight |
|---|---|---|
Detection | 16% | 14% (as part of combined domain) |
Incident Response | 14% | 18% (as part of combined domain) |
Infrastructure Security | 18% | 20% |
Identity and Access Management | 20% | 16% |
Data Protection | 18% | 18% |
Security Foundations and Governance | 14% | 14% |
Notice that Identity and Access Management, Infrastructure Security, and Data Protection together account for 56% of the exam, making them the areas deserving the most concentrated study time, alongside genuine, dedicated attention to the newly restructured Detection and Incident Response domains.
SCS-C03 Exam Format
Here is exactly what to expect on exam day.
Number of questions: 65 total, consisting of 50 scored questions and 15 unscored questions used by AWS for future exam development
Question types: Multiple choice, multiple response, ordering, and matching
Duration: 170 minutes
Passing score: 750 out of a possible 1000, using a scaled, compensatory scoring model, meaning you do not need to pass each domain individually
Cost: 300 USD, with a 50% discount voucher available if you already hold an active AWS certification
Validity: 3 years from the date you pass
Delivery: Pearson VUE testing center or online proctored exam
The unscored questions are not identified during the exam, so treat every question with the same level of care and attention regardless of which ones you suspect might be unscored.
SCS-C01 vs SCS-C02: Brief Historical Context
For candidates researching the exam's evolution more broadly, SCS-C01 was the original version of the Security Specialty certification, eventually replaced by SCS-C02 in 2023 with updated content reflecting AWS service changes at that time. SCS-C02 itself covered largely similar domain territory to SCS-C01, with periodic content refreshes rather than the kind of structural domain restructuring seen in the more recent SCS-C02 to SCS-C03 transition. If you are researching older exam versions purely for historical context, know that both SCS-C01 and SCS-C02 are now retired, and SCS-C03 is the only version currently available to new candidates.
Should You Study SCS-C02 Materials If Preparing for SCS-C03
If you already invested time studying SCS-C02 materials before the transition, the good news is that roughly 85% of the core security knowledge remains directly relevant. Core services like GuardDuty, Security Hub, KMS, IAM, CloudTrail, Config, and WAF are all still heavily tested under the new structure. What you specifically need to add includes Resource Control Policies, Amazon Security Lake, generative AI and machine learning security concepts, and familiarity with the new ordering and matching question formats.
Rather than starting your preparation completely from scratch, treat SCS-C02 materials as a strong foundation, then layer in the specific new content areas and practice the new question formats using resources specifically updated for SCS-C03.
How to Prepare for the SCS-C03 Exam
A structured approach that reflects the exam's updated priorities works best.
Start with Identity and Access Management, since it is now the single heaviest domain at 20%, and nearly every SCS-C03 scenario involves a permission boundary, service control policy, resource policy, session policy, trust policy, or cross-account access decision.
Study Infrastructure Security and Data Protection next, since together with IAM these three domains make up 56% of the exam and deserve the majority of your preparation time.
Dedicate specific attention to the newly separated Detection and Incident Response domains, understanding how they now represent genuinely distinct skill areas rather than a single combined topic.
Add generative AI and machine learning security concepts to your study plan, focusing particularly on practical IAM controls around Amazon Bedrock rather than deep machine learning theory.
Practice with the new ordering and matching question formats specifically, since these test different skills than traditional multiple choice and require genuine procedural understanding rather than simple recognition.
Use AWS's official exam guide as your primary reference for domain weightings and task statements, since it remains the single most authoritative source for exactly what SCS-C03 covers.
Conclusion
The transition from SCS-C02 to SCS-C03 represents a meaningful update rather than a superficial rebrand, restructuring detection and incident response into distinct domains, elevating IAM to the heaviest weighted domain, and introducing genuinely new generative AI and machine learning security content alongside new question formats. If you are starting fresh, focus your preparation according to the updated domain weights, with particular attention to IAM, Infrastructure Security, and Data Protection. If you already studied SCS-C02 material, your foundation remains largely valid, but plan to specifically add coverage of Resource Control Policies, Amazon Security Lake, AI security concepts, and practice with the new ordering and matching question styles before sitting for the current exam.
Frequently Asked Questions

AllExamQuestions Editorial Team
AllExamQuestions Editorial Team creates high-quality exam preparation content, practice resources, and certification guides to help learners achieve their goals.
Our content is carefully researched, regularly updated, and reviewed for accuracy and relevance.
