AWS Retired the Security Specialty SCS-C02 Exam for SCS-C03: What Changed
AWS retired the Security Specialty exam (SCS-C02) on December 1, 2025, and replaced it with SCS-C03 the next day. Here is what changed in domains, weights, question format, and the new generative AI security content.
If you have been planning to sit the AWS Certified Security - Specialty exam, the version you may have been studying for no longer exists. AWS retired SCS-C02 on December 1, 2025, and the replacement, SCS-C03, has been the only version available since December 2, 2025 — with registration for it opening as early as November 18, 2025. If you already hold the SCS-C02 credential, nothing changes for you: your certification stays valid under its original code until it expires. This post is for anyone who has not sat the exam yet and needs to know what is actually being tested now.
What Stayed the Same
The exam’s core mechanics did not change. SCS-C03 is still 65 questions total (50 scored, 15 unscored — unscored questions are not identified during the exam), still runs 170 minutes, still costs $300 USD, and still requires a scaled score of 750 out of 1000 to pass. AWS’s recommended background is also roughly unchanged: three to five years of general experience securing cloud workloads, plus at least two years of hands-on experience securing AWS environments specifically.
What Changed: Question Format
SCS-C02 was pure multiple choice and multiple response. SCS-C03 adds two new question types AWS has been rolling out across its exams: ordering and matching questions, alongside the existing multiple choice and multiple response formats. If your practice material is built entirely around single-answer multiple choice, it is no longer representative of the full exam experience.
What Changed: Domain Structure
Both versions score across six domains that sum to 100%, but AWS restructured and reweighted them for SCS-C03:
| SCS-C02 (retired Dec 1, 2025) | Weight | SCS-C03 (current) | Weight |
|---|---|---|---|
| Threat Detection and Incident Response | 14% | Detection | 16% |
| Security Logging and Monitoring | 18% | Incident Response | 14% |
| Infrastructure Security | 20% | Infrastructure Security | 18% |
| Identity and Access Management | 16% | Identity and Access Management | 20% |
| Data Protection | 18% | Data Protection | 18% |
| Management and Security Governance | 14% | Security Foundations and Governance | 14% |
The biggest shifts: AWS split the old “Threat Detection and Incident Response” domain into two separate domains (Detection and Incident Response), which is more of a relabeling than a content change. More substantively, Infrastructure Security dropped 2 points while Identity and Access Management — already the single largest domain on SCS-C02 alongside Infrastructure Security — picked those points up and is now the heaviest domain on the exam at 20%. If your study plan was built around the old weights, shift more study time toward IAM and slightly less toward network-layer infrastructure controls.
What’s New: Generative AI Security Content
This is the headline addition, and it is the first time generative AI security has entered an AWS specialty-level exam blueprint. SCS-C03 does not add a separate AI domain — instead, generative AI security content is folded into the existing Infrastructure Security domain. Candidates are now expected to know how to implement protections and guardrails for generative AI applications, including applying concepts from the OWASP Top 10 for LLM Applications, configuring Amazon Bedrock guardrails against prompt injection and sensitive-data leakage, scoping IAM permissions for actions like bedrock:InvokeModel, and using Bedrock model invocation logging and CloudTrail for auditability of AI workloads.
What’s New: Governance Content
The domain formerly called “Management and Security Governance” is now “Security Foundations and Governance,” and its scope grew. New task content includes Resource Control Policies (RCPs), AI service opt-out policies, and declarative policies — organizational-level controls that did not exist as testable content on SCS-C02. The Data Protection domain also picked up new content on inter-resource encryption in transit and data masking techniques.
What Was Removed
Configuring S3 static website hosting was dropped from the Data Protection domain’s content outline, consistent with AWS trimming legacy, lower-relevance content from its exam guides as it makes room for newer service coverage.
What This Means for Your Study Plan
If you have been using SCS-C02 study material — courses, question banks, or guides published before December 2025 — treat it as a starting point, not a complete plan. It will be missing the generative AI and Bedrock guardrail content entirely, it will under-cover IAM relative to the new weighting, and it will not prepare you for ordering or matching question formats. Our existing Security Specialty study guide covers the retired SCS-C02 domain structure; treat it as background on the fundamentals rather than a current blueprint while we work on a refreshed SCS-C03 version. In the meantime, the official AWS Certified Security - Specialty (SCS-C03) exam guide is the authoritative source for the current task statements and in-scope services.
For hands-on practice, StudyKits’ AWS Security Specialty prep app covers core exam domains like IAM, infrastructure security, and data protection — useful for reinforcing the fundamentals that carried over from SCS-C02, though you should pair it with the official exam guide for the newer generative AI and governance content until your materials fully catch up to the SCS-C03 blueprint.
The Bigger Pattern
This is the second AWS specialty or associate-level exam to be substantially restructured in the past year — the SysOps Administrator exam went through the same process when it became the CloudOps Engineer Associate (SOA-C03) in September 2025. If you are deep into preparation for any AWS exam, check the official AWS Certification documentation for the current exam guide before you lock in a study plan. Exam codes, domain weights, and even entire domains can shift with only a few weeks’ notice, and generative AI content is clearly becoming a permanent fixture across AWS’s certification portfolio rather than a one-off addition.
Start Studying Free on iOS
Practice cloud certification questions anytime, anywhere. Track your progress and ace your exam.
Download FreeRelated Articles
AWS MLA-C01 vs GCP Professional Machine Learning Engineer: Which ML Certification Should You Get?
Compare the AWS Certified Machine Learning Engineer -- Associate (MLA-C01) and the Google Cloud Professional Machine Learning Engineer -- exam format, domains, cost, and which one fits your role -- verified against the current official AWS and Google Cloud exam guides.
AWS SOA-C03 vs GCP Associate Cloud Engineer: Which Cloud Operations Certification Should You Get First?
Compare the AWS Certified CloudOps Engineer - Associate (SOA-C03) and Google Cloud Associate Cloud Engineer (ACE) certifications -- exam format, cost, domains, and which one fits the cloud you actually operate.
AWS DVA-C02 vs GCP Professional Cloud Developer: Which Certification Should You Get First?
Compare the AWS Certified Developer Associate (DVA-C02) and Google Cloud Professional Cloud Developer certifications -- exam format, cost, domains, prerequisites, and which one fits the stack you actually build on.