ASIS CPP Certification, officially the Certified Protection Professional (CPP®), is ASIS International’s board certification for experienced security managers. It validates leadership-level knowledge across seven domains, including security principles, business practices, investigations, personnel security, physical security, information security, and crisis management. Candidates generally need five to seven years of security experience, including three years in responsible charge. The current exam contains 200 scored plus 25 unscored questions, allows four hours, and is designed around applied security-management judgment rather than simple memorization.
The ASIS Certified Protection Professional (CPP®) is a board certification in security management offered by ASIS International. ASIS describes the CPP as its benchmark credential for professionals who manage broad security responsibilities and lead security functions.
If you are searching what is CPP certification, what is a Certified Protection Professional, or what does CPP stand for in security, the answer is simple: CPP stands for Certified Protection Professional.
The credential is designed for experienced professionals who manage security programs rather than specialists working only in one technical area.
Typical responsibilities may include:
Enterprise security risk management
Physical security
Security operations
Information protection
Investigations
Personnel security
Crisis and business continuity planning
Budgeting and vendor management
Policy development
Security leadership and governance
A CPP certificate should not be confused with a professional license. ASIS awards a professional certification and the CPP designation to candidates who meet its requirements and pass the examination.
The CPP certification requirements depend partly on your education.
Education / Credential
Required Security Experience
Responsible Charge Requirement
No higher education degree
7 years
At least 3 years
Bachelor's degree or equivalent
6 years
At least 3 years
Master's degree or equivalent
5 years
At least 3 years
Existing APP + no degree
6 years
At least 3 years
Existing APP + bachelor's degree
5 years
At least 3 years
Existing APP + master's degree
4 years
At least 3 years
ASIS defines responsible charge as having authority to make independent decisions and take independent action concerning the operational methodology and execution of a security-related project or process. It does not necessarily require directly supervising employees.
Candidates must also meet ASIS program requirements, including working full-time in a security-related role and agreeing to its certification policies and Code of Conduct.
The CPP qualification is most appropriate for experienced professionals such as:
Security Managers
Corporate Security Leaders
Security Directors
Regional Security Managers
Security Consultants
Loss Prevention Leaders
Security Operations Managers
Risk and Security Professionals
Critical Infrastructure Security Leaders
The important point is that CPP is a management-level security certification. Years of service alone are not enough if the applicant cannot demonstrate the required level of responsibility.
The current ASIS CPP exam includes approximately 225 multiple-choice questions:
200 scored questions
25 unscored pretest questions
4 answer options per question
4-hour exam duration
The unscored questions are mixed throughout the examination, so candidates do not know which questions are pretest items.
That works out to roughly 64 seconds per question across the full 225-question examination.
This makes time management an important part of CPP training and exam preparation.
The current Certified Protection Professional examination covers seven security-management domains.
CPP Exam Domain
Weight
Security Principles and Practices
22%
Business Principles and Practices
15%
Investigations
9%
Personnel Security
11%
Physical Security
16%
Information Security
14%
Crisis Management
13%
These percentages come from the current ASIS Board Certification Handbook.
This is the largest exam domain.
Candidates need to understand areas such as security-program management, risk assessment, security theory, industry standards, continuous improvement, security awareness, and Enterprise Security Risk Management (ESRM).
Do not treat this domain as basic security terminology. Questions may require you to evaluate risks and select appropriate management actions.
A strong security leader must understand the business behind the security function.
Expect topics involving:
Budgeting
Financial controls
ROI
Policies and procedures
Performance measures
Staffing
Vendor management
Contracts
Relevant laws and regulations
This domain often exposes a weakness in candidates who have extensive operational security experience but limited business-management exposure.
The investigations section includes investigation programs, evidence, chain of custody, surveillance, interviewing, reporting, and relevant legal considerations.
Personnel security covers areas such as background investigations, screening, workplace threats, travel security, executive protection, and policies designed to protect employees and organizations.
The CPP security certification does not focus only on guards and access control.
Physical security includes:
Facility surveys
Risk assessment
Security system fundamentals
Countermeasures
Security technology
Vendor selection
Testing and commissioning
Maintenance
Cost-benefit analysis
ASIS currently assigns 16% of the CPP examination to this domain.
Senior physical-security professionals cannot ignore cyber and information risk.
This domain addresses information-security programs, confidentiality, integrity and availability, authentication, encryption, social engineering, ransomware, penetration testing concepts, security awareness, systems integration, and related controls.
Crisis management covers threat assessment, business impact considerations, emergency planning, response, communications, exercises, resource management, recovery, and continuity-related concepts.
The current standard ASIS CPP certification cost is:
Candidate Type
CPP Exam Fee
ASIS Member
$580
Nonmember
$910
Retake – Member or Nonmember
$480
ASIS also publishes reduced pricing for qualifying emerging-market countries. Fees can change, so applicants should confirm current pricing when they apply.
The complete cost of CPP certification may be higher once you include training, books, practice resources, membership, and future recertification.
For candidates asking how to get CPP, how to obtain CPP certification, or how to become a Certified Protection Professional, use this sequence:
Check your eligibility against ASIS education and experience requirements.
Document your security experience, particularly your years in responsible charge.
Submit the ASIS certification application.
Pay the applicable certification fee.
Build a study plan around all seven domains.
Use official references and realistic practice questions.
Complete timed practice sessions.
Schedule and pass the CPP examination.
Maintain the credential through continuing professional education.
ASIS emphasizes that its exams are experience-based and advises candidates to apply their professional experience rather than trying to memorize reference material alone.
Good Certified Protection Professional training should mirror how security managers actually make decisions.
A strong CPP security course should cover:
All seven official CPP domains
Risk assessment scenarios
Security management concepts
Business and financial principles
Physical and information security
Investigation scenarios
Crisis-management decisions
Timed Certified Protection Professional practice tests
Exam-style question review
Weak-area analysis
ASIS itself provides a study manual, reference materials, review courses, flash cards, and a practice test. Its official study manual also notes that it should supplement the recommended references rather than serve as the candidate's only preparation source.
Candidates who prefer instructor-led preparation can also explore ASIS CPP Certification training from NYTCC alongside the official ASIS exam blueprint and reference material.
Do not measure preparation only by the number of questions completed.
After every Certified Protection Professional test or mock exam, categorize errors into:
Knowledge gap
Misread scenario
Wrong risk priority
Business-versus-security judgment error
Time-management problem
That approach turns CPP practice questions into a diagnostic tool rather than a memorization exercise.
There is no single official Certified Protection Professional salary or ASIS CPP certification salary that applies to every credential holder.
Compensation depends heavily on:
Country and city
Industry
Management level
Scope of responsibility
Years of experience
Team and budget size
Regional or global responsibilities
Employer
ASIS states that earning the credential may enhance career and earnings potential, but its current certification page does not promise a fixed salary after becoming CPP certified.
Be cautious with pages that present one salary figure as the guaranteed CPP certification salary.
The CPP PSP certification comparison is often misunderstood.
CPP
PSP
Broad security management
Specialized physical security
Designed for senior security managers
Focuses on physical security assessment and systems
Seven knowledge domains
Three physical-security domains
Strong business and leadership component
Strong technical physical-security component
CPP is better described as broad security-management certification, while ASIS PSP® specializes in physical security assessment, design, integration, and implementation.
Some experienced professionals eventually earn both because the credentials validate different areas of expertise.
Search results for what does CPP mean can be confusing.
In this article, CPP means Certified Protection Professional, the security-management credential issued by ASIS International.
It is not the same as:
Certified Payroll Professional
Certified Purchasing Professional
CPPB procurement certification
Canada Pension Plan
A government security license
Terms such as Certified Protection Specialist or “security asset protection professional certification” should also not be treated as the official ASIS credential name. The recognized title is Certified Protection Professional (CPP®).
The strongest case for pursuing the ASIS CPP Certification is role alignment.
It is particularly relevant when you already manage security at an organizational level and need to demonstrate knowledge beyond one narrow specialty. The exam combines operational security with business, people, technology, investigations, risk, and crisis-management responsibilities.
CPP holders must also complete 60 Continuing Professional Education hours every three years to maintain an active ASIS certification.
Before choosing a Certified Protection Professional course, first confirm that you satisfy the experience requirement. Then map your study plan directly to the seven weighted domains, put extra attention on Security Principles and Practices, and use scenario-based questions to test how you apply security-management judgment. That gives you a far stronger preparation strategy than simply memorizing a CPP study guide.