{"id":542,"date":"2026-09-16T21:44:40","date_gmt":"2026-09-16T21:44:40","guid":{"rendered":"https:\/\/www.directcertify.com\/blog\/?p=542"},"modified":"2026-09-16T21:44:40","modified_gmt":"2026-09-16T21:44:40","slug":"cisco-ccnp-security-scor-v2-2026","status":"publish","type":"post","link":"https:\/\/www.directcertify.com\/blog\/cisco-ccnp-security-scor-v2-2026\/","title":{"rendered":"Cisco Just Overhauled the CCNP Security Core Exam: What SCOR v2.0 Actually Tests in 2026"},"content":{"rendered":"<p>Cisco just pushed through the biggest change to its security certification portfolio in more than six years, and it centers on one exam almost every security-focused Cisco candidate eventually has to sit: SCOR 350-701, the core requirement for CCNP Security and CCIE Security. On August 27, 2026, the exam moved from v1.1 to v2.0, and Cisco&#8217;s own team described it during a live session earlier that month as the biggest update to the security certification lineup since the current framework launched.<\/p>\n<p>If you passed SCOR years ago, are mid-study right now, or are trying to decide whether CCNP Security is even worth pursuing in 2026, the practical questions are the same: what actually changed on the exam, does an old pass still count, and what does this credential pay once you have it. Here&#8217;s what&#8217;s real, sourced directly from Cisco&#8217;s own certification team and the published exam blueprint, not secondhand guesswork.<\/p>\n<h2>The Biggest Cisco Security Certification Update in Six Years<\/h2>\n<p>SCOR v1.0 launched in February 2020 and received exactly one minor update in the six and a half years since. Cisco&#8217;s own certification program manager, Francois Caen, called the new v2.0 blueprint the first major revision in that entire stretch, and said candidates who studied against v1.1 material should treat v2.0 as new content rather than a refresh. That&#8217;s a notably blunt admission from a vendor that usually frames updates as incremental. A similar pattern played out earlier this year when <a href=\"https:\/\/www.directcertify.com\/blog\/ccnp-wireless-2026-wlcor-wlsd-wlsi\/\">Cisco split its wireless track into a standalone CCNP Wireless certification<\/a>, rebuilding a legacy blueprint around how the technology is actually deployed today rather than a decade-old product catalog.<\/p>\n<p>The reason for the overhaul is straightforward. The old blueprint reflected a 2020 security stack built around on-premises appliances and manually configured VPN tunnels. The new one reflects what a security engineer actually touches in 2026: cloud-delivered security, AI-integrated attack surfaces, and identity-first access models that replaced the old perimeter.<\/p>\n<h2>What&#8217;s Actually New in the SCOR 350-701 v2.0 Blueprint<\/h2>\n<p>Cisco&#8217;s published exam topics document breaks the new blueprint into six weighted domains, and three of them contain content that simply did not exist on the old exam.<\/p>\n<h3>AI and LLM Security Gets Its Own Exam Objective<\/h3>\n<p>Domain 1.0 (Security Concepts, 20% of the exam) now includes a dedicated objective on vulnerabilities in AI and large language model systems: prompt injection, system prompt leakage, weaknesses in vector and embedding stores, and AI supply chain risk. It&#8217;s specific enough that a candidate needs to understand how an LLM-integrated application can actually be attacked, not just that AI exists as a buzzword.<\/p>\n<h3>Post-Quantum Cryptography Enters the Core Curriculum<\/h3>\n<p>The same domain now lists post-quantum cryptography as a named cryptography security component alongside PKI, TLS, and IPsec, and references PQC directly as an attack-surface consideration. This tracks with the wider industry timeline: <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2024\/08\/nist-releases-first-3-finalized-post-quantum-encryption-standards\" target=\"_blank\" rel=\"noopener\">NIST finalized its first three post-quantum encryption standards<\/a>, ML-KEM, ML-DSA, and SLH-DSA, back in August 2024, and enterprise security teams have spent the two years since figuring out migration paths. Cisco folding PQC into a foundational security exam in 2026 means the concept has moved from research curiosity to something a working network security engineer is expected to at least explain.<\/p>\n<h3>Secure Service Edge Is an Entirely New Domain<\/h3>\n<p>Domain 4.0, Secure Service Edge, is worth 10% of the exam on its own and covers SSE and SASE architecture, configuring Cisco Secure Access for both internet and private access, AI guardrails for data loss prevention, and reading Secure Access Investigate risk scores. None of this existed as a standalone domain on v1.1. It reflects how much of enterprise security has shifted away from site-to-site VPNs and toward cloud-delivered access brokering in just a few years.<\/p>\n<h3>Splunk and Cisco XDR Show Up in Network Visibility<\/h3>\n<p>Two separate objectives now name Splunk directly, once for ingesting cloud logging and monitoring data and once for orchestrating and automating security operations, alongside a broader objective on native AI and machine learning telemetry inside XDR and SIEM\/SOAR platforms. Cisco closed its acquisition of Splunk in March 2024, and this is the clearest sign yet that the integration has reached the certification curriculum, not just the product roadmap.<\/p>\n<p>Here&#8217;s how the full domain breakdown weights out on the new exam:<\/p>\n<table style=\"width:100%;border-collapse:collapse;margin:16px 0\">\n<thead>\n<tr style=\"background:#f5f7fa\">\n<th style=\"border:1px solid #e0e0e0;padding:10px;text-align:left\">Domain<\/th>\n<th style=\"border:1px solid #e0e0e0;padding:10px;text-align:left\">Weight<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #e0e0e0;padding:10px\">1.0 Security Concepts<\/td>\n<td style=\"border:1px solid #e0e0e0;padding:10px\">20%<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #e0e0e0;padding:10px\">2.0 Network Security<\/td>\n<td style=\"border:1px solid #e0e0e0;padding:10px\">25%<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #e0e0e0;padding:10px\">3.0 Cloud Security<\/td>\n<td style=\"border:1px solid #e0e0e0;padding:10px\">15%<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #e0e0e0;padding:10px\">4.0 Secure Service Edge<\/td>\n<td style=\"border:1px solid #e0e0e0;padding:10px\">10%<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #e0e0e0;padding:10px\">5.0 Endpoint Protection and Detection<\/td>\n<td style=\"border:1px solid #e0e0e0;padding:10px\">15%<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #e0e0e0;padding:10px\">6.0 Network Access, Visibility, and Enforcement<\/td>\n<td style=\"border:1px solid #e0e0e0;padding:10px\">15%<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Network Security still carries the largest single weight at 25%, so this remains fundamentally a hands-on firewall and infrastructure exam. The new material is layered on top of that foundation, not a wholesale replacement of it.<\/p>\n<h2>What Got Retired, Renamed, or Left Alone<\/h2>\n<p>The core exam isn&#8217;t the only thing moving. Cisco&#8217;s certification team walked through the full set of changes in <a href=\"https:\/\/blogs.cisco.com\/learning\/cisco-security-certification-updates-your-questions-answered\" target=\"_blank\" rel=\"noopener\">a public Q&amp;A addressing the update<\/a>, and the details matter depending on which concentration exam you&#8217;re planning to pair with SCOR:<\/p>\n<ul>\n<li><strong>SVPN (300-730) is retiring outright.<\/strong> August 26, 2026 was the last day to test, and there&#8217;s no direct replacement concentration exam. VPN content hasn&#8217;t disappeared, though. It&#8217;s been redistributed into SCOR itself (VPN fundamentals) and into SNCF (VPN configuration on Secure Firewall).<\/li>\n<li><strong>SNCF only got a minor exam update<\/strong>, but the training behind it changed more. It used to require two separate five-day courses, Foundations and Advanced. Going forward it&#8217;s a single consolidated course that matches the exam name.<\/li>\n<li><strong>SSCA, formerly branded SCAZT, kept its exam number (300-740) but got renamed and refocused<\/strong> entirely on Secure Service Edge and Cisco Secure Access, splitting off the incident-response content that used to share the same exam.<\/li>\n<li><strong>SISE received only a light refresh<\/strong> to cover current ISE software versions, with training already live.<\/li>\n<li><strong>SDSI is unchanged<\/strong>, so if that&#8217;s your planned concentration, nothing here affects your study plan.<\/li>\n<\/ul>\n<p>According to Cisco&#8217;s own certification team, the rationale for retiring SVPN specifically was that manual VPN configuration, while still a real and used skill, is too narrow a specialty to justify a standalone professional-level concentration on its own in a market that&#8217;s moved toward SASE and orchestrated overlay networks.<\/p>\n<h2>Key Dates for the SCOR v1.1 to v2.0 Cutover<\/h2>\n<p>If you&#8217;re timing an exam registration around this transition, the schedule Cisco published breaks down like this:<\/p>\n<ol>\n<li><strong>August 26, 2026<\/strong>: last day to test on the current v1.1 versions of SCOR and the affected concentration exams.<\/li>\n<li><strong>August 27, 2026<\/strong>: first day the new SCOR v2.0 and SSCA v2.0 exams became available.<\/li>\n<li><strong>September 2026<\/strong>: official SCOR v2.0 training content releases through Cisco U., alongside new Secure Access training material.<\/li>\n<li><strong>Late 2026<\/strong>: the consolidated SNCF training course and a dedicated SCOR v2.0 practice exam both go live through Cisco&#8217;s own store.<\/li>\n<\/ol>\n<h2>If You&#8217;re Mid-Study for CCNP Security Right Now<\/h2>\n<p>The single most important thing Cisco clarified is that nobody who&#8217;s already invested time gets stranded by the version change. If you passed SCOR v1.1 before August 27, that pass still combines with any concentration exam, in either version, to award the full CCNP Security certification. It works the other direction too: if you&#8217;ve already passed a concentration exam, it still counts toward the certification once you pass SCOR, on either version.<\/p>\n<p>The window that actually matters is the three-year clock. Whichever CCNP-level exam you pass first, core or concentration, you have three years from that pass date to complete the other one. A version transition doesn&#8217;t reset or shorten that clock. One detail candidates commonly get wrong: Continuing Education credits recertify a certification you already hold, but they cannot extend the three-year window to earn one you&#8217;re still working toward. Those are two separate systems, and mixing them up is the most frequent point of confusion Cisco reported hearing during its live Q&amp;A session.<\/p>\n<p>For anyone eyeing CCIE Security rather than stopping at CCNP, SCOR remains the qualifying written exam for the practical lab, and v2.0 doesn&#8217;t trigger any direct change to the lab itself. Cisco has separately said an AI-focused module is planned for the CCIE Security lab, on its own review cycle, unconnected to this update. If your longer-term plan looks anything like the broader path laid out in <a href=\"https:\/\/www.directcertify.com\/blog\/cisco-certification-changes-2026-ccna-to-ccie-explained\/\">Cisco&#8217;s 2026 certification changes from CCNA up through CCIE<\/a>, this is one more sign the professional and expert tiers keep getting rebuilt around cloud and AI content instead of staying static.<\/p>\n<h2>SCOR 350-701 Exam Format and What It Costs<\/h2>\n<p>The exam itself is unchanged in basic format: 120 minutes, delivered through Pearson VUE either at a test center or online proctored, available in English and Japanese. <a href=\"https:\/\/www.cisco.com\/site\/us\/en\/learn\/training-certifications\/exams\/scor.html\" target=\"_blank\" rel=\"noopener\">Cisco&#8217;s official exam registration page<\/a> lists the fee at $400, or redeemable through Cisco Learning Credits if your employer provisions those. That&#8217;s a meaningful jump from the entry-level certifications most candidates cut their teeth on, which is part of why going in with a blueprint-accurate practice set matters more on this exam than on an associate-level one.<\/p>\n<p>DirectCertify&#8217;s own <a href=\"https:\/\/www.directcertify.com\/cisco\/350-701\">350-701 practice test set<\/a> was refreshed on September 16, 2026, putting it inside the same window as the live v2.0 rollout, and it&#8217;s worth confirming the practice material you&#8217;re using has actually been updated for the new domains rather than still reflecting the 2020-era v1.1 content.<\/p>\n<h2>What CCNP Security Actually Pays in 2026<\/h2>\n<p>Compensation data backs up why candidates keep pursuing this certification despite the cost and the study lift. According to <a href=\"https:\/\/www.payscale.com\/research\/US\/Certification=Cisco_Certified_Network_Professional_(CCNP)_Security\/Salary\" target=\"_blank\" rel=\"noopener\">PayScale&#8217;s own certification-specific salary research<\/a>, CCNP Security holders in the US average roughly $152,000 annually, with most reported salaries falling between $143,000 and $158,500, and top earners in cloud security or enterprise architecture roles clearing $205,000 or more.<\/p>\n<p>That figure comes with a real caveat: it applies most cleanly in Cisco-heavy environments. Security professionals in shops running predominantly non-Cisco tooling won&#8217;t see the same lift, since the value is tied to demonstrated depth on Cisco&#8217;s own stack, not security knowledge in the abstract. The broader security job market has also been shifting toward vendor-neutral, cloud-native skill sets, arguably part of why Cisco rebuilt this exam around SSE and AI content instead of appliance-era networking. Other vendors are moving the same direction: <a href=\"https:\/\/www.directcertify.com\/blog\/isc2-certification-changes-2026-ccsp-cc-cissp\/\">ISC2&#8217;s own 2026 exam refresh across CC, CCSP, and CISSP<\/a> leaned on similar AI-security integration for largely the same reason.<\/p>\n<h2>Is CCNP Security Still Worth Pursuing After a Six-Year-Overdue Rewrite<\/h2>\n<p>The honest answer depends on where you sit today. If you work in an environment running Cisco Secure Firewall, Cisco Secure Access, or Cisco XDR, this certification just got measurably more relevant to your actual job, not less, because the exam finally tests skills you&#8217;re likely using day to day instead of appliance configuration patterns from 2020. If you&#8217;re choosing a first security certification and your organization runs a mixed or non-Cisco stack, a vendor-neutral credential may still serve you better as a starting point, with CCNP Security layered on once you&#8217;re in a Cisco-specific role.<\/p>\n<p>For candidates already partway through the old blueprint, the backward-compatibility guarantees mean there&#8217;s no reason to restart. For candidates just starting out, there&#8217;s genuinely no better time to begin than right after a blueprint rewrite, since you&#8217;ll be studying current material instead of content that was already six years stale.<\/p>\n<p>DirectCertify is an independent certification preparation provider and is not affiliated with, endorsed by, or sponsored by Cisco Systems, Inc. Exam codes, pricing, blueprint domains, and policy details change on Cisco&#8217;s own timeline, so confirm anything time-sensitive directly on Cisco&#8217;s certification pages before registering.<\/p>\n<h2>Frequently Asked Questions About the SCOR v2.0 Exam<\/h2>\n<details style=\"border:1px solid #e0e0e0;border-radius:8px;margin-bottom:10px;padding:0;overflow:hidden\">\n<summary style=\"cursor:pointer;padding:14px 18px;background:#f5f7fa;font-weight:600\">Do I have to retake SCOR if I already passed the v1.1 version?<\/summary>\n<div style=\"padding:14px 18px;border-top:1px solid #e0e0e0\">No. A SCOR v1.1 pass earned before August 27, 2026 still combines with any CCNP Security concentration exam, on either version, to award the full certification. You have three years from your pass date to complete the other required exam.<\/div>\n<\/details>\n<details style=\"border:1px solid #e0e0e0;border-radius:8px;margin-bottom:10px;padding:0;overflow:hidden\">\n<summary style=\"cursor:pointer;padding:14px 18px;background:#f5f7fa;font-weight:600\">What happens to VPN content now that SVPN is retired?<\/summary>\n<div style=\"padding:14px 18px;border-top:1px solid #e0e0e0\">SVPN (300-730) stopped accepting new test-takers after August 26, 2026, with no direct replacement concentration exam. The VPN material didn&#8217;t disappear. It&#8217;s now split between the SCOR core exam, which covers VPN fundamentals, and the SNCF concentration, which covers VPN configuration specifically on Cisco Secure Firewall.<\/div>\n<\/details>\n<details style=\"border:1px solid #e0e0e0;border-radius:8px;margin-bottom:10px;padding:0;overflow:hidden\">\n<summary style=\"cursor:pointer;padding:14px 18px;background:#f5f7fa;font-weight:600\">Does the SCOR v2.0 update change the CCIE Security lab exam?<\/summary>\n<div style=\"padding:14px 18px;border-top:1px solid #e0e0e0\">No direct impact. SCOR remains the qualifying written exam for the CCIE Security practical, and the two exams sit on separate review cycles. Cisco has mentioned a planned AI-focused module for the CCIE Security lab, but that work is unrelated to this SCOR blueprint change.<\/div>\n<\/details>\n<details style=\"border:1px solid #e0e0e0;border-radius:8px;margin-bottom:10px;padding:0;overflow:hidden\">\n<summary style=\"cursor:pointer;padding:14px 18px;background:#f5f7fa;font-weight:600\">How much does the Cisco 350-701 SCOR exam cost?<\/summary>\n<div style=\"padding:14px 18px;border-top:1px solid #e0e0e0\">Cisco&#8217;s official pricing lists the exam at $400 USD, payable directly or through Cisco Learning Credits. It&#8217;s a 120-minute exam delivered via Pearson VUE, available in English and Japanese.<\/div>\n<\/details>\n<details style=\"border:1px solid #e0e0e0;border-radius:8px;margin-bottom:10px;padding:0;overflow:hidden\">\n<summary style=\"cursor:pointer;padding:14px 18px;background:#f5f7fa;font-weight:600\">Will Continuing Education credits let me skip taking the new exam version?<\/summary>\n<div style=\"padding:14px 18px;border-top:1px solid #e0e0e0\">No. Continuing Education credits recertify a certification you already hold, but they cannot extend the three-year window you have to earn a certification you&#8217;re still working toward. Those are two separate clocks, and Cisco specifically flagged this as the most commonly misunderstood rule in its own program.<\/div>\n<\/details>\n<details style=\"border:1px solid #e0e0e0;border-radius:8px;margin-bottom:10px;padding:0;overflow:hidden\">\n<summary style=\"cursor:pointer;padding:14px 18px;background:#f5f7fa;font-weight:600\">What&#8217;s genuinely new on the SCOR v2.0 blueprint?<\/summary>\n<div style=\"padding:14px 18px;border-top:1px solid #e0e0e0\">Three areas didn&#8217;t exist on the old exam at all: a dedicated AI and LLM vulnerability objective covering prompt injection and model supply chain risk, post-quantum cryptography as a named cryptography component, and an entirely new Secure Service Edge domain covering SASE, SSE, and Cisco Secure Access.<\/div>\n<\/details>\n","protected":false},"excerpt":{"rendered":"<p>CCNP Security&#8217;s core exam got its first major rewrite since 2020. See what SCOR v2.0 tests, what&#8217;s retired, and what it costs in 2026.<\/p>\n","protected":false},"author":3,"featured_media":543,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rank_math_title":"CCNP Security 2026: What Changed in SCOR v2.0","rank_math_description":"CCNP Security's core exam got its first major rewrite since 2020. See what SCOR v2.0 tests, what's retired, and what it costs in 2026.","rank_math_focus_keyword":"CCNP Security","footnotes":""},"categories":[64],"tags":[],"class_list":["post-542","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cisco"],"_links":{"self":[{"href":"https:\/\/www.directcertify.com\/blog\/wp-json\/wp\/v2\/posts\/542","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.directcertify.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.directcertify.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.directcertify.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.directcertify.com\/blog\/wp-json\/wp\/v2\/comments?post=542"}],"version-history":[{"count":1,"href":"https:\/\/www.directcertify.com\/blog\/wp-json\/wp\/v2\/posts\/542\/revisions"}],"predecessor-version":[{"id":544,"href":"https:\/\/www.directcertify.com\/blog\/wp-json\/wp\/v2\/posts\/542\/revisions\/544"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.directcertify.com\/blog\/wp-json\/wp\/v2\/media\/543"}],"wp:attachment":[{"href":"https:\/\/www.directcertify.com\/blog\/wp-json\/wp\/v2\/media?parent=542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.directcertify.com\/blog\/wp-json\/wp\/v2\/categories?post=542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.directcertify.com\/blog\/wp-json\/wp\/v2\/tags?post=542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}