CPP, or Certified Protection Professional, is ASIS International’s board certification for experienced security managers. It validates leadership-level knowledge across seven domains: security principles, business practices, investigations, personnel security, physical security, information security, and crisis management. Candidates generally need five to seven years of security experience, including three years in responsible charge. The 2026 exam contains 200 scored and 25 unscored multiple-choice questions, lasts four hours, and may be taken at a Prometric center or remotely through the ProProctor testing platform.
The CPP Certified Protection Professional credential is a board certification in security management issued by ASIS International. It is designed for experienced professionals who make security decisions, manage programs, control budgets, assess organizational risks, lead investigations, oversee personnel protection, and prepare organizations for crises.
People searching what is the CPP certification should understand an important distinction: CPP is not simply a training-completion award. A CPP certificate is earned only after a candidate:
Meets ASIS education and experience requirements.
Documents relevant security employment.
Demonstrates responsible-charge experience.
Agrees to the ASIS professional code and certification policies.
Passes the official examination.
Maintains the credential through continuing professional education.
ASIS certifications are accredited by the ANSI National Accreditation Board against ISO/IEC 17024, an international standard for organizations that certify individuals. This gives the ASIS International CPP certification greater professional weight than a basic course-completion certificate.
The ASIS CPP certification is best suited to mid-career and senior-level security professionals rather than complete beginners.
Relevant candidates may include:
Corporate security managers
Regional or global security directors
Security operations managers
Loss-prevention leaders
Security consultants
Risk and resilience managers
Executive protection managers
Investigations leaders
Security program and compliance managers
Military or law-enforcement professionals moving into corporate security
The strongest candidates already handle decisions involving staffing, risk acceptance, vendor selection, policies, budgets, investigations, emergency response, or protection programs.
This is why CPP security preparation requires more than memorizing definitions. Questions may require candidates to choose the most appropriate management action after considering organizational objectives, legal exposure, financial impact, stakeholder responsibilities, and risk-treatment priorities.
ASIS requires every candidate to have at least three years in responsible charge of a security function. Responsible charge means having authority to make independent decisions and manage the execution of a security-related project or process. Supervising employees is not mandatory, but purely operational positions such as patrol duties generally do not meet this definition.
Education and credentials
Required security experience
Responsible-charge requirement
No higher-education degree
7 years
At least 3 years
No degree but already APP-certified
6 years
At least 3 years
Bachelor’s degree or international equivalent
6 years
At least 3 years
Bachelor’s degree plus APP
5 years
At least 3 years
Master’s degree or international equivalent
5 years
At least 3 years
Master’s degree plus APP
4 years
At least 3 years
Applicants must also be employed full-time in a security-related role, meet ASIS conduct requirements, and disclose any relevant criminal history that could affect professional eligibility.
A candidate does not need the title “Security Director” to qualify. Examples of responsible charge may include:
Designing and implementing an access-control program
Selecting security vendors and approving performance requirements
Managing an investigation process
Conducting enterprise security risk assessments
Developing workplace-violence policies
Controlling a security budget
Leading business continuity or crisis-response planning
The application should describe authority, decisions, outcomes, and scope—not merely list daily duties.
The ASIS CPP exam is a computer-based multiple-choice examination delivered throughout the year. Candidates can test at an authorized Prometric center or use Prometric’s remote-proctored ProProctor platform when technical and room-security requirements are met.
Exam feature
2026 details
Total questions
225 multiple-choice questions
Scored questions
200
Unscored pretest questions
25
Exam duration
4 hours
Answer choices
4 per question
Delivery
Prometric test center or remote proctoring
Languages
English or Spanish
Availability
Year-round
Scoring method
Scaled scoring
The 25 pretest questions are mixed into the examination and are not identified. Candidates should therefore treat every item as scored. ASIS uses scaled scoring because questions may vary in difficulty.
The Certified Protection Professional CPP examination measures management-level knowledge across seven domains.
CPP domain
Exam weight
Main focus
Security Principles and Practices
22%
Security programs, risk assessment, ESRM, awareness and program improvement
Physical Security
16%
Surveys, system selection, implementation, testing and maintenance
Business Principles and Practices
15%
Budgets, policies, staffing, ethics, contracts and performance
Information Security
14%
Information protection, cyber risks, governance and integrated controls
Crisis Management
13%
Threat assessment, emergency response, continuity and recovery
Personnel Security
11%
Screening, workplace threats, travel security and executive protection
Investigations
9%
Evidence, interviews, surveillance, legal support and case management
These percentages show where preparation time should be concentrated. Security Principles and Practices, Physical Security, and Business Principles represent 53% of the scored examination, so weak performance across those three areas can be difficult to offset.
A common mistake is studying only physical protection topics. The CPP is broader. It assesses whether a security leader can connect protection measures to business objectives, governance, financial controls, legal duties, personnel risk, information security, and organizational resilience.
The official ASIS CPP exam fee 2026 varies according to ASIS membership and the applicant’s emerging-market category.
Candidate category
ASIS CPP certification cost
ASIS member—standard rate
$580
ASIS member—Emerging Market 1
$480
ASIS member—Emerging Market 2
$460
Nonmember—standard rate
$910
Nonmember—Emerging Market 1
$720
Nonmember—Emerging Market 2
$680
Retake—standard rate
$480
Retake—Emerging Market 1
$360
Retake—Emerging Market 2
$330
The published CPP certification cost includes application and examination processing. If an application is denied, ASIS refunds the payment after deducting a $160 nonrefundable processing fee. Approved candidates who fail to test within their one-year eligibility period forfeit their application and testing payment. Fees can change, so candidates should confirm the amount displayed in the ASIS application portal before paying.
Membership should not be purchased solely because of the exam discount without calculating the full cost. Compare membership fees, study-material discounts, webinars, networking access, and potential recertification benefits before deciding.
The phrase CPP certification online can refer to two separate things:
Completing CPP training through virtual, instructor-led or self-paced study
Taking the official examination through remote proctoring
ASIS allows approved candidates to take the same examination remotely through Prometric ProProctor. However, the CPP certification course itself does not award the credential. Training providers can help candidates prepare, but only ASIS can approve applications and issue the certification.
Remote candidates need a stable internet connection, a working webcam and microphone, an appropriate private room, valid identification, and a computer that meets Prometric requirements. ASIS strongly discourages using a company-owned computer because corporate firewall controls can disrupt the exam. Technical failure can lead to forfeiture of the examination payment when the session cannot be completed.
A reliable CPP training plan should be organized around the official body of knowledge rather than random practice questions.
Confirm that your education, security experience, and responsible-charge history satisfy ASIS requirements. Training cannot compensate for an ineligible application.
Allocate study time according to examination weight:
22%: Security Principles and Practices
16%: Physical Security
15%: Business Principles and Practices
14%: Information Security
13%: Crisis Management
11%: Personnel Security
9%: Investigations
ASIS offers a CPP Study Manual, reference materials, standards, guidelines, flash cards, review courses, a practice exam, and an online practice test. ASIS warns that its study manual is a supplement and should not be treated as the sole preparation source.
For each scenario, ask:
What is the organization trying to protect?
Which stakeholder owns the risk?
Is there an immediate life-safety concern?
What legal, ethical, or regulatory obligations apply?
Which response is proportionate and financially justified?
What should a security manager do first?
Four hours for 225 questions provides an average of roughly 64 seconds per question. Candidates should learn to mark difficult questions, continue through the exam, and return to them later rather than spending several minutes on one scenario.
The search phrase CPP PSP certification often appears when professionals are deciding which ASIS credential matches their role.
Area
CPP
PSP
Full name
Certified Protection Professional
Physical Security Professional
Main focus
Broad security management
Physical security assessment, design and implementation
Career level
Experienced managers and leaders
Physical-security specialists
Domains
Seven
Three
Exam length
225 questions, 4 hours
140 questions, 2.5 hours
Best fit
Enterprise or multi-function security leadership
Technical and operational physical-security work
A physical-security specialist who designs barriers, access control, surveillance, and protection systems may prefer PSP. A professional responsible for enterprise risk, business alignment, budgets, investigations, information protection, personnel security, and crisis leadership is generally better aligned with CPP.
Becoming CPP certified is not a permanent one-time achievement. Credential holders must recertify every three years by completing 60 continuing professional education credits connected to security or business management.
Credits can come from qualifying education, teaching, authorship, professional memberships, volunteer service, other relevant certifications, standards work, or public service. The activities must be completed within the three-year certification cycle.
Candidates comparing different CPP certifications should also avoid confusing the ASIS credential with Certified Payroll Professional, Canada Pension Plan, or other programs that use the same abbreviation. For security careers, phrases such as security CPP, CPP certification security, CPP certification ASIS, or CPP ASIS refer specifically to ASIS International’s Certified Protection Professional designation.
Choose the CPP certification when your responsibilities extend across the complete security-management function and you can document the required leadership authority. Before enrolling in a CPP certification course, download the latest ASIS handbook, map your experience against the eligibility rules, calculate the complete CPP certification cost, and assess your knowledge against all seven domains.