Free study guide — no purchase required

ASIS CPP Pass Rate, Format & Study Guide

A real reference for anyone preparing for the ASIS Certified Protection Professional (CPP) exam — pass rate, retake policy, how it's scored, and a practical study timeline. This is independent reference content, not a sales page: everything below is sourced from ASIS CPP's own certifying body.

What the ASIS CPP exam is

The Certified Protection Professional (CPP) is administered by ASIS International, the security profession's largest membership and standard-setting body — founded in 1955 as the American Society for Industrial Security, holding its first annual meeting outside Washington, D.C. that same October, and renamed ASIS International in 2002 to reflect its growth into a genuinely global organization now representing roughly 34,600 members across 155 countries. CPP itself was established in 1977 and has been widely regarded as the security industry's gold-standard credential ever since — the certification most consistently referenced when a hiring board, insurer, or client wants independent validation that a security professional can operate at a senior management level, not just execute tactical security work.

Why it matters

Security leadership roles increasingly sit at the intersection of physical security, risk management, investigations, and information security, and CPP is built specifically to test that broad, senior-management-level competency across all of it — which is why it's frequently listed as a preferred or required credential for Director of Security, VP of Security, and Chief Security Officer roles, particularly in industries (financial services, critical infrastructure, healthcare, higher education) where a security program failure carries real regulatory or liability consequences. For a security professional already working in management, CPP is often the single most recognized credential to add credibility with a board or executive team that isn't itself made up of security specialists and needs an external signal of competence they can trust.

Who this exam is for

CPP is designed for experienced, senior-level security managers — professionals already responsible for a security function's strategy and operations, not entry- or mid-level security officers or analysts. Typical candidates include Directors and VPs of Security, security consultants advising organizations at a strategic level, and senior security managers preparing for their next step into executive leadership. Given the multi-year experience requirement (detailed below), it is explicitly not an entry point into the security field.

Pass rate

The certifying body does not publicly publish an official pass rate for this exam. Be wary of third-party sites citing a specific number here — treat any pass-rate claim you see elsewhere for this exam as unverified.

If you don't pass — retake policy

Per ASIS International's own certification support content, there must be a 60-day wait between testing dates, and candidates get up to three attempts within their eligibility (candidacy) period; if you fail all three, you have to reapply for a new eligibility period once the current one ends. Retake fee is $480 for members and nonmembers alike ($360/$330 under ASIS's Emerging Market 1/2 discounted pricing).

How it's scored

ASIS does not publicly disclose the exact passing score or cut score for the CPP exam — only that it's pass/fail across the 200 scored multiple-choice questions (plus 25 unscored pretest items, 225 total). Third-party prep sources report conflicting numbers, which is itself a signal the real cut score isn't officially published; treat any specific percentage you see elsewhere as an estimate, not an ASIS-confirmed figure.

Format at a glance

Format: 225 questions (200 scored)
Real exam cost: $580 (members) / $910 (nonmembers)

The CPP exam consists of approximately 225 multiple-choice questions — 200 "live," scoreable questions plus up to 25 unscored pre-test items mixed in indistinguishably — administered over a 4-hour time limit at Prometric testing centers or via ASIS's remote proctoring option (ProProctor). Results are reported using ASIS's scaled-score methodology: a scaled score of at least 650 is required to pass, calculated through item response theory (Rasch analysis) rather than a simple percentage of questions answered correctly, which is why the raw number of correct answers needed to pass isn't publicly disclosed and can vary slightly between exam forms.

Full eligibility requirements and everything the ASIS CPP study portal includes is on the ASIS CPP product page.

What each domain actually tests

Following ASIS's 2019/2020 job-analysis-driven update to the CPP Body of Knowledge, the exam covers seven domains. Security Principles and Practices (22%) covers the foundational planning, risk-assessment, and program-management skills underlying any security function. Business Principles and Practices (15%) tests budgeting, staffing, vendor management, and the broader business-operations skills a senior security manager needs beyond pure security expertise. Investigations (9%) covers managing investigative operations and evidence handling. Personnel Security (11%) tests background-investigation processes and protecting the workforce against human threats. Physical Security (16%) covers facility surveys, security-system design, and physical countermeasure implementation. Information Security (14%) tests the security-program principles that intersect with protecting organizational data and systems, reflecting how thoroughly physical and information security have converged in modern security-management roles. Crisis Management (13%), the final domain, covers incident response, business continuity, and emergency planning. No single domain dominates the way some other credentials' blueprints do — the weighting is deliberately spread to reflect the genuinely broad scope of a senior security-management role.

Eligibility requirements, in full

ASIS uses a sliding experience scale based on education level, all of which also requires at least 3 years specifically in responsible charge of a security function (meaning independent decision-making authority over a security program or process, not just years worked in any security-adjacent role). Candidates without a higher-education degree need 7 years of security experience (reduced to 6 if they already hold ASIS's Associate Protection Professional, APP, credential). With a bachelor's degree, the requirement drops to 6 years (5 with APP); with a master's degree or higher, it drops further to 5 years (4 with APP). All applicants must also have been employed full-time in a security-related role, have no disqualifying criminal history that would reflect negatively on the security profession or ASIS, and agree to abide by the ASIS Certification Code of Professional Responsibility. Qualifying experience is interpreted fairly broadly by ASIS — it can include protection-of-assets work across public or private sectors, criminal justice, government intelligence, or investigative agencies, and even qualifying full-time educator experience teaching security-management coursework.

What it actually costs

The application/exam fee is $580 for ASIS members and $910 for non-members, which includes a non-refundable $160 processing portion regardless of outcome — meaning even a cancelled or denied application forfeits that $160. If your application is approved but you don't schedule and take the exam within your two-year eligibility (candidacy) window, you don't receive a refund at all. Retesting (if a first attempt doesn't pass) costs $225 flat, the same fee for both members and non-members, and candidates are limited to three attempts within their two-year eligibility period, with a mandatory 90 days between each testing date. Reduced rates are available for candidates in World Bank-designated Emerging Market countries. ASIS membership itself carries its own separate annual dues on top of the certification fees, but member pricing on the CPP application alone ($580 vs. $910) often more than offsets the membership cost for candidates paying non-member rates.

Keeping the credential — maintenance & recertification

CPP requires ongoing recertification every three years, and maintaining it requires completing 60 Continuing Professional Education (CPE) hours across that three-year cycle. Recertification applications can be submitted any time during the third year of the cycle, and ASIS grants a three-month grace period after the official certification end date to submit a recertification application — but critically, that grace period cannot be used to accumulate additional CPE hours; all 60 hours must genuinely be completed within the original three-year cycle itself, not stretched into the grace window. CPE can be earned through a range of ASIS-recognized activities (conferences, coursework, publications, and similar professional-development work), and ASIS publishes specific guidance on which sources and activity types qualify.

How to actually prepare

225 questions with no published time-per-question breakdown beyond the overall appointment window means pacing discipline matters as much as knowledge — treat it like the 200 scored questions are all that count, since the 25 pretest items are unidentifiable. Across the seven domains, Security Principles and Practices is consistently reported as the single largest content block, so anchor your review there first, then layer in Physical Security and Business Principles and Practices, which are the next-largest domains in most breakdowns of ASIS's own Body of Knowledge document.

What's changing (2026)

The CPP eligibility matrix in current use (the 2021-updated version reflected in this guide, with education-tiered experience requirements ranging from 5 to 7 years) remains the active standard as of August 2026 — no newer eligibility change has been publicly announced since that 2021 update, which itself modestly reduced the prior, stricter experience requirements after ASIS's Professional Certification Board reviewed how the security-management profession had matured since CPP launched more than 40 years earlier. No structural changes to the 225-question/4-hour exam format or the three-year/60-CPE recertification cycle have been announced as of August 2026.

Want a full practice question bank built around this exact format?

See the ASIS CPP study portal