ASIS CPP Certification 2026: Requirements, Exam Cost, Domains & Training Guide
ASIS CPP Certification, officially the Certified Protection Professional (CPP®), is ASIS International’s board certification for experienced security managers. It validates leadership-level knowledge across seven domains, including security principles, business practices, investigations, personnel security, physical security, information security, and crisis management. Candidates generally need five to seven years of security experience, including three years in responsible charge. The current exam contains 200 scored plus 25 unscored questions, allows four hours, and is designed around applied security-management judgment rather than simple memorization.
What Is ASIS CPP Certification?
The ASIS Certified Protection Professional (CPP®) is a board certification in security management offered by ASIS International. ASIS describes the CPP as its benchmark credential for professionals who manage broad security responsibilities and lead security functions.
If you are searching what is CPP certification, what is a Certified Protection Professional, or what does CPP stand for in security, the answer is simple: CPP stands for Certified Protection Professional.
The credential is designed for experienced professionals who manage security programs rather than specialists working only in one technical area.
Typical responsibilities may include:
Enterprise security risk management
Physical security
Security operations
Information protection
Investigations
Personnel security
Crisis and business continuity planning
Budgeting and vendor management
Policy development
Security leadership and governance
A CPP certificate should not be confused with a professional license. ASIS awards a professional certification and the CPP designation to candidates who meet its requirements and pass the examination.
ASIS CPP Certification Requirements
The CPP certification requirements depend partly on your education.
Education / Credential | Required Security Experience | Responsible Charge Requirement |
No higher education degree | 7 years | At least 3 years |
Bachelor's degree or equivalent | 6 years | At least 3 years |
Master's degree or equivalent | 5 years | At least 3 years |
Existing APP + no degree | 6 years | At least 3 years |
Existing APP + bachelor's degree | 5 years | At least 3 years |
Existing APP + master's degree | 4 years | At least 3 years |
ASIS defines responsible charge as having authority to make independent decisions and take independent action concerning the operational methodology and execution of a security-related project or process. It does not necessarily require directly supervising employees.
Candidates must also meet ASIS program requirements, including working full-time in a security-related role and agreeing to its certification policies and Code of Conduct.
Who Is Eligible for CPP?
The CPP qualification is most appropriate for experienced professionals such as:
Security Managers
Corporate Security Leaders
Security Directors
Regional Security Managers
Security Consultants
Loss Prevention Leaders
Security Operations Managers
Risk and Security Professionals
Critical Infrastructure Security Leaders
The important point is that CPP is a management-level security certification. Years of service alone are not enough if the applicant cannot demonstrate the required level of responsibility.
ASIS CPP Exam Format
The current ASIS CPP exam includes approximately 225 multiple-choice questions:
200 scored questions
25 unscored pretest questions
4 answer options per question
4-hour exam duration
The unscored questions are mixed throughout the examination, so candidates do not know which questions are pretest items.
That works out to roughly 64 seconds per question across the full 225-question examination.
This makes time management an important part of CPP training and exam preparation.
ASIS CPP Exam Domains and Weighting
The current Certified Protection Professional examination covers seven security-management domains.
CPP Exam Domain | Weight |
Security Principles and Practices | 22% |
Business Principles and Practices | 15% |
Investigations | 9% |
Personnel Security | 11% |
Physical Security | 16% |
Information Security | 14% |
Crisis Management | 13% |
These percentages come from the current ASIS Board Certification Handbook.
Security Principles and Practices – 22%
This is the largest exam domain.
Candidates need to understand areas such as security-program management, risk assessment, security theory, industry standards, continuous improvement, security awareness, and Enterprise Security Risk Management (ESRM).
Do not treat this domain as basic security terminology. Questions may require you to evaluate risks and select appropriate management actions.
Business Principles and Practices – 15%
A strong security leader must understand the business behind the security function.
Expect topics involving:
Budgeting
Financial controls
ROI
Policies and procedures
Performance measures
Staffing
Vendor management
Contracts
Relevant laws and regulations
This domain often exposes a weakness in candidates who have extensive operational security experience but limited business-management exposure.
Investigations – 9%
The investigations section includes investigation programs, evidence, chain of custody, surveillance, interviewing, reporting, and relevant legal considerations.
Personnel Security – 11%
Personnel security covers areas such as background investigations, screening, workplace threats, travel security, executive protection, and policies designed to protect employees and organizations.
Physical Security – 16%
The CPP security certification does not focus only on guards and access control.
Physical security includes:
Facility surveys
Risk assessment
Security system fundamentals
Countermeasures
Security technology
Vendor selection
Testing and commissioning
Maintenance
Cost-benefit analysis
ASIS currently assigns 16% of the CPP examination to this domain.
Information Security – 14%
Senior physical-security professionals cannot ignore cyber and information risk.
This domain addresses information-security programs, confidentiality, integrity and availability, authentication, encryption, social engineering, ransomware, penetration testing concepts, security awareness, systems integration, and related controls.
Crisis Management – 13%
Crisis management covers threat assessment, business impact considerations, emergency planning, response, communications, exercises, resource management, recovery, and continuity-related concepts.
ASIS CPP Certification Cost
The current standard ASIS CPP certification cost is:
Candidate Type | CPP Exam Fee |
ASIS Member | $580 |
Nonmember | $910 |
Retake – Member or Nonmember | $480 |
ASIS also publishes reduced pricing for qualifying emerging-market countries. Fees can change, so applicants should confirm current pricing when they apply.
The complete cost of CPP certification may be higher once you include training, books, practice resources, membership, and future recertification.
How to Get CPP Certification
For candidates asking how to get CPP, how to obtain CPP certification, or how to become a Certified Protection Professional, use this sequence:
Check your eligibility against ASIS education and experience requirements.
Document your security experience, particularly your years in responsible charge.
Submit the ASIS certification application.
Pay the applicable certification fee.
Build a study plan around all seven domains.
Use official references and realistic practice questions.
Complete timed practice sessions.
Schedule and pass the CPP examination.
Maintain the credential through continuing professional education.
ASIS emphasizes that its exams are experience-based and advises candidates to apply their professional experience rather than trying to memorize reference material alone.
CPP Training and Exam Preparation
Good Certified Protection Professional training should mirror how security managers actually make decisions.
A strong CPP security course should cover:
All seven official CPP domains
Risk assessment scenarios
Security management concepts
Business and financial principles
Physical and information security
Investigation scenarios
Crisis-management decisions
Timed Certified Protection Professional practice tests
Exam-style question review
Weak-area analysis
ASIS itself provides a study manual, reference materials, review courses, flash cards, and a practice test. Its official study manual also notes that it should supplement the recommended references rather than serve as the candidate's only preparation source.
Candidates who prefer instructor-led preparation can also explore ASIS CPP Certification training from NYTCC alongside the official ASIS exam blueprint and reference material.
A Better Way to Use CPP Practice Questions
Do not measure preparation only by the number of questions completed.
After every Certified Protection Professional test or mock exam, categorize errors into:
Knowledge gap
Misread scenario
Wrong risk priority
Business-versus-security judgment error
Time-management problem
That approach turns CPP practice questions into a diagnostic tool rather than a memorization exercise.
Certified Protection Professional Salary
There is no single official Certified Protection Professional salary or ASIS CPP certification salary that applies to every credential holder.
Compensation depends heavily on:
Country and city
Industry
Management level
Scope of responsibility
Years of experience
Team and budget size
Regional or global responsibilities
Employer
ASIS states that earning the credential may enhance career and earnings potential, but its current certification page does not promise a fixed salary after becoming CPP certified.
Be cautious with pages that present one salary figure as the guaranteed CPP certification salary.
CPP vs PSP: Which Security Certification Is Different?
The CPP PSP certification comparison is often misunderstood.
CPP | PSP |
Broad security management | Specialized physical security |
Designed for senior security managers | Focuses on physical security assessment and systems |
Seven knowledge domains | Three physical-security domains |
Strong business and leadership component | Strong technical physical-security component |
CPP is better described as broad security-management certification, while ASIS PSP® specializes in physical security assessment, design, integration, and implementation.
Some experienced professionals eventually earn both because the credentials validate different areas of expertise.
Important: CPP Has Several Meanings
Search results for what does CPP mean can be confusing.
In this article, CPP means Certified Protection Professional, the security-management credential issued by ASIS International.
It is not the same as:
Certified Payroll Professional
Certified Purchasing Professional
CPPB procurement certification
Canada Pension Plan
A government security license
Terms such as Certified Protection Specialist or “security asset protection professional certification” should also not be treated as the official ASIS credential name. The recognized title is Certified Protection Professional (CPP®).
Is CPP Certification Worth It?
The strongest case for pursuing the ASIS CPP Certification is role alignment.
It is particularly relevant when you already manage security at an organizational level and need to demonstrate knowledge beyond one narrow specialty. The exam combines operational security with business, people, technology, investigations, risk, and crisis-management responsibilities.
CPP holders must also complete 60 Continuing Professional Education hours every three years to maintain an active ASIS certification.
Before choosing a Certified Protection Professional course, first confirm that you satisfy the experience requirement. Then map your study plan directly to the seven weighted domains, put extra attention on Security Principles and Practices, and use scenario-based questions to test how you apply security-management judgment. That gives you a far stronger preparation strategy than simply memorizing a CPP study guide.




Comments