Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

SSCP Passing Score and Scaled Scoring

Updated 8 min read
Key takeaway

The published SSCP passing grade is 700 on a 1,000-point scale.

  • This is not a claim that 70% of raw questions must be correct: CAT uses item difficulty and an ability estimate, and 25 pretest items are unscored.
  • ISC2 issues pass/fail results without a numerical scaled score.
On this page12 sections
  1. The SSCP passing standard
  2. What “scaled” means in practice
  3. The three published CAT stop rules
  4. What item count does and does not tell you
  5. Domain performance and an overall result
  6. What the score report shows
  7. A realistic way to interpret practice results
  8. Examples of misleading score calculations
  9. Using domain feedback after a failure
  10. Original worked scoring scenario
  11. How to prepare for the standard
  12. Frequently asked score questions

The SSCP passing standard

ISC2 publishes a passing grade of 700 out of 1,000 points for the SSCP exam. Treat 700 as the threshold on a scaled proficiency measure. It does not mean that you must answer exactly 70% of the displayed questions correctly. ISC2 does not publish a fixed raw-number-of-correct-answers conversion for candidates to use.

The exam is Computerized Adaptive Testing, or CAT. Item selection depends on response history and item difficulty, and the number of items varies from 100 to 125. Of these, 25 are pretest items that are not scored. At least 75 operational items are required for a pass/fail result. A candidate cannot tell which items count, so trying to estimate a raw percentage from memory is not reliable.

What “scaled” means in practice

A scaled score places performance on a defined reporting scale so a passing standard can be stated consistently. It is not a simple percentage displayed on the screen. On an adaptive test, the difficulty of items and the information gathered from responses matter to the ability estimate. Two candidates can receive different item sets and still be evaluated against the same required standard.

ISC2’s CAT overview says that each response contributes to re-estimating the candidate’s ability. The published description is enough to explain why a raw tally is misleading, but it is not a license to invent the hidden scoring formula. ISC2 does not publish item-level weights or a score-conversion table for candidates. Avoid claims such as “you need 70 correct” or “a harder question counts double.”

The three published CAT stop rules

ISC2 describes three rules used to determine when a CAT exam ends. First is the confidence-interval rule: after the minimum length has been met, the exam can stop when the ability estimate is sufficiently separated from the pass standard at 95% statistical confidence. A result can therefore occur at the 100-item minimum. This rule is about the statistical evidence in the adaptive estimate, not a raw answer percentage.

If the confidence interval has not resolved the result before the maximum length, the maximum-length rule applies. At 125 items, the candidate’s final ability estimate is compared with the passing standard. If the estimate meets or exceeds it, the result is a pass; if below, it is a fail.

The run-out-of-time rule applies if the exam reaches the two-hour limit before another stop rule determines the outcome. The final ability estimate is compared with the standard. However, a candidate who has not answered at least 75 operational items plus 25 pretest items within the maximum time automatically fails. This is why pacing matters even when you know the content.

What item count does and does not tell you

An exam ending at 100 items does not by itself mean pass or fail. The confidence rule can stop the exam after the minimum in either direction. An exam that continues past 100 does not mean you are failing; additional items can provide more information about proficiency across domains. The total length is a consequence of the adaptive process, not an unofficial score report.

Candidates often remember the last question as either unusually easy or difficult. That impression cannot reveal the result. ISC2 states candidates should expect each item to be challenging; a question’s perceived difficulty is relative, and items near the candidate’s estimated ability can feel uncertain. Do not use the last item, screen transition, or time remaining to predict pass or fail.

Domain performance and an overall result

ISC2’s CAT FAQ says the pass/fail decision is based on overall performance across operational items. A candidate does not have to reach above-proficiency in every domain. The exam is compensatory: stronger performance in one area can offset weaker performance elsewhere, subject to the overall passing standard. This does not make a domain optional. The outline’s item mix must still cover all seven domains and a weak area can lower the overall estimate.

Domain weights guide the expected content mix. For SSCP, the current outline assigns 16% to Security Concepts and Practices, 15% to Access Controls, 15% to Risk Identification, Monitoring and Analysis, 14% to Incident Response and Recovery, 9% to Cryptography, 16% to Network and Communications Security, and 15% to Systems and Application Security. These percentages are average weights, not guarantees of an exact item count on an individual adaptive exam.

What the score report shows

After the CAT exam, candidates receive an immediate pass/fail result. ISC2 says candidates do not receive a numerical scaled score on the pass/fail report. Domain proficiency feedback is provided only to candidates who fail. That report is designed to help focus a future study attempt; it is not a transcript of missed questions, a raw score, or a guarantee about which topic will be tested next time.

A candidate who passes should move to the separate certification process if eligible: experience verification, endorsement, Code of Ethics and required maintenance steps. The result does not mean the professional experience requirement has been waived. A candidate who fails should use domain-level diagnostics alongside a personal miss log and not assume that every question in a weak domain was answered incorrectly.

A realistic way to interpret practice results

A static practice test may report 78% or 85%, but that number is not directly comparable to the SSCP CAT scale. Practice items may have different difficulty, content weighting, and distractor quality; they do not include the adaptive algorithm or its pretest items. Use results to locate concepts you do not understand, not to calculate an exact probability of passing.

Look for performance stability across several fresh, mixed-domain sets. Review why an answer is correct and why close distractors are wrong. If you score well on familiar questions but cannot explain the control or the decision order, the readiness signal is weak. If you miss a question because you misread “first” or overlook a stated constraint, practice careful reading as well as content review.

Examples of misleading score calculations

Suppose a candidate sees 110 items and recalls answering 77 correctly. That number does not prove a pass. The candidate cannot distinguish the 25 unscored pretest items, does not know the difficulty profile or item-selection history, and may misremember uncertain responses. A fixed 70% calculation would be an invented threshold.

Suppose a practice bank contains 100 items and the candidate gets 70 right. That is 70% on that bank, not a prediction that the candidate has reached SSCP’s 700 scaled standard. The useful next question is which objectives the 30 misses represent and whether the candidate can now explain the reasoning.

Suppose an exam stops at 100 and the candidate feels that the last item was hard. Neither fact is a result. Wait for the official report. Stress-driven interpretation adds no useful evidence and can cause a candidate to make poor retake or celebration decisions.

Using domain feedback after a failure

If your result is a fail, start with the provided domain proficiency levels. Prioritize below-proficiency areas, but do not abandon near-proficiency topics. A diagnostic identifies where to focus; it does not necessarily identify the exact underlying misconception. Revisit the relevant outline tasks, then use new scenarios to test transfer.

Build a short remediation table: domain, outline task, mistaken assumption, corrected principle, and a practice scenario. If the feedback shows a weak area in Cryptography, for example, check whether the issue is selecting a hash versus encryption, handling key compromise, understanding digital signatures, or matching a secure protocol to the risk. The domain label is a starting point, not a complete explanation.

Before paying for another attempt, check the current retake wait and attempt limit and allow time to repair the gaps. A retake taken immediately after repeating the same question bank may measure memorization rather than improved competence.

Original worked scoring scenario

A learner says, “The SSCP passing score is 700, so I need 70 out of 100 correct.” The correct response is that 700 is a published scaled standard, not a raw percentage. The CAT exam has 100 to 125 items, including 25 unscored pretest items. At least 75 scored items are required for a result; the system uses an adaptive estimate and the official stop rules.

The learner’s practical action should be to study the outline and use practice to diagnose knowledge and reasoning gaps. They should not count correct answers during the exam, guess whether the last item was experimental, or infer performance from how many questions appeared.

How to prepare for the standard

Prepare to meet the whole outline, not a guessed raw score. The largest weights are Security Concepts and Practices, Network and Communications Security, and Systems and Application Security at 16% each. Give substantial review time to them, while reserving coverage for every other domain. Practice selecting an authorized, proportionate action from the facts in a scenario.

Learn the CAT-specific administrative rules: two-hour maximum, variable item count, no answer review, pretest items, and an automatic failure if you do not complete the minimum required operational items before time expires. These facts inform pacing and behavior; they are not a scoring hack.

Frequently asked score questions

Is 700/1,000 the same as 70%? No. It is the scaled passing standard; no fixed raw percentage conversion is published.

Does every domain require a passing score? ISC2 says the exam uses an overall compensatory pass/fail decision, so above-proficiency in each domain is not required.

Do passers get a numerical score? No. ISC2 reports pass/fail without a numerical scaled score; failing candidates receive domain proficiency feedback.

Does an exam ending at 100 items mean I passed? No. The stop count alone does not reveal the outcome.

Common questions

What score do you need to pass SSCP?

The published passing grade is 700 out of 1,000 on the scaled score.

Is 700 the same as 70 percent correct?

No. It is not a raw percentage conversion; CAT uses adaptive item selection and an ability estimate.

Do SSCP candidates get a numerical score?

No. ISC2 reports pass or fail. Failing candidates receive domain proficiency feedback.

Do I need above proficiency in every SSCP domain?

No. ISC2 says the exam is compensatory and uses an overall result, although every domain remains in the outline.