CSA logo
Focused certification exam prep
Start practice

CSA Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • CSA (Certified SOC Analyst, exam 312-39, version 2) is issued by EC-Council and has two eligibility routes: official training or self-study.
  • Self-study applicants need one year of verified network-administration or security experience plus a USD 100 nonrefundable application fee.
  • The exam voucher costs USD 450, is non-transferable, and stays valid for one year after purchase.
  • Approved self-study eligibility gives you a three-month window to buy the voucher.

The Two Routes to Eligibility

The Certified SOC Analyst credential from EC-Council does not let you simply buy a voucher and sit the exam. Eligibility must be established first, and there are two official paths: the official training route (a qualifying purchase of official courseware or training) and the self-study route (a verified-experience application). Both lead to the same exam, 312-39 for CSA v2, and the same credential.

One point trips up many candidates. EC-Council's training-page FAQ suggests that official training is mandatory, while the certification portal's CSA-specific eligibility provisions describe the self-study alternative. The portal's CSA-specific rules take precedence. If you have the required experience, you are not forced into a training purchase. If you lack it, the training route is your straightforward way in.

Check the portal before you pay anyone: Eligibility rules are set on the EC-Council certification portal, not by third-party training sellers or exam-dump sites. Before spending money, read the CSA-specific section of the application and eligibility page and confirm which route fits your background.
FactorOfficial Training RouteSelf-Study Route
Basis for eligibilityQualifying official training or courseware purchaseOne year of verified network-administration or security experience
Application feeUSD 100 charge is included in official-training feesUSD 100 nonrefundable eligibility-application fee, paid separately
Verification neededProof of the qualifying purchaseEmployer, supervisor or department verifier
VoucherPurchased per portal instructions (USD 450 voucher price)USD 450 voucher bought within three months of approval
Best suited toCareer changers and those without qualifying experienceWorking network or security staff with documented experience

Self-Study Route: What You Must Prove

The self-study route rewards people who already work near the problem space. The core requirement is one year of verified experience in network administration or security. That wording matters. The experience must be verifiable, and the portal requires an employer, supervisor or department verifier to confirm it. A personal statement or home-lab description does not substitute for that verification.

Preparing a clean application

  • Identify your verifier early. A direct supervisor or department contact who can confirm your duties is the practical choice. Contact them before you apply so the request does not stall your timeline.
  • Describe duties in terms the reviewer recognizes. Firewall and switch administration, log review, endpoint or server administration with security duties, and alert handling are all relevant to the SOC context.
  • Keep the USD 100 fee in mind. It is a nonrefundable eligibility-application fee, so submit only when your experience and verifier are genuinely in place.
  • Watch the clock after approval. Approved eligibility provides a three-month window to purchase the voucher. Do not apply until you can commit to buying within that period.
Timing trap: Two different clocks run in this process. After approval you have three months to purchase the voucher. After you purchase it, the voucher is valid for one year. Plan your study calendar around both, and do not buy the voucher merely to lock in a price if your preparation is months away.

Fees: What Is Included and What Is Separate

Candidates routinely confuse three different purchases. Keeping them straight prevents overpaying or buying the wrong product. For a full pricing breakdown, see our CSA certification cost guide.

ItemAmountWhat It Is
CSAv2 Exam Voucher (remote proctored)USD 450Your exam attempt; non-transferable; valid one year from purchase
Self-study eligibility applicationUSD 100Nonrefundable fee to have your experience reviewed
Separately listed eCoursewareUSD 250Study materials only; not an exam voucher
Official training bundlesVaries by packageTraining that satisfies the training route; the USD 100 application charge is included in official-training fees

The most important distinction: the USD 250 eCourseware is not an exam voucher. Buying courseware gives you study content, not a seat in the exam. Likewise, if you take the training route, the eligibility page states that the USD 100 application charge is already included in official-training fees, so you should not pay it a second time. Self-study candidates, by contrast, pay the USD 100 application fee and the USD 450 voucher as separate line items.

What You Qualify For: The 312-39 Exam Format

Understanding the exam you are qualifying for helps you decide whether the effort is justified and how to prepare. The CSA v2 exam, 312-39, has these characteristics:

  • 100 multiple-choice questions
  • Three-hour time limit
  • 70% passing score
  • Remote proctoring through the EC-Council exam portal and ECC Exam Centre

A clarification worth making: the three-day figure you see in the training description is the course duration, not the exam timer. And although training labs are hands-on, the certification exam itself is a multiple-choice assessment, not a lab-based practical. For more on scoring, read our CSA passing score guide, and for a realistic view of difficulty, see how hard the CSA exam is.

Be careful with older material. Six-domain v1 lists, third-party four-domain breakdowns and claims of a two-hour exam do not describe the verified v2 scope. Rely on the official blueprint titled Certified SOC Analyst (CSA) v2 Exam Blueprint, exam 312-39.

Applicants Who Are Minors

If you are under the age of majority, the portal applies additional rules. Applicants who are minors must follow the portal's parental-consent and educational-institution documentation requirements. Because these requirements are specific and procedural, read that section of the CSA application page directly and gather the documents before you pay any fees. Treat the portal text as the only authority here rather than relying on summaries from training vendors.

Knowledge Readiness: What the Blueprint Expects

Meeting the administrative eligibility rule is not the same as being ready. The blueprint defines eight weighted domains, and candidates should assess themselves against them before buying a voucher. Our complete guide to all 8 CSA content areas goes deeper; the summary below shows where the weight sits.

DomainWeight
Security Operations and Management5%
Understanding Cyber Threats, IoCs, and Attack Methodology8%
Log Management15%
Incident Detection and Triage25%
Proactive Threat Detection12%
Incident Response25%
Forensics Investigation and Malware Analysis5%
SOC for Cloud Environments5%

The weights total 100%, and these are official weighted exam objectives, not allocations derived from a curriculum. Notice that Incident Detection and Triage and Incident Response are jointly the largest domains at 25% each, which together represent 50% of the blueprint.

Incident Detection and Triage (25%)

This is where a SOC analyst's day-to-day judgment is tested. Expect to reason about which alerts deserve escalation and why.

  • SIEM use cases and how detection logic maps to attacker behavior
  • Alert triage: severity, context, false-positive reasoning
  • AI-generated detection rules, a v2-era topic worth understanding critically
  • Correlating events across Windows, Linux, Mac, network and application sources

Incident Response (25%)

Beyond knowing the phases, candidates should be comfortable applying them to a scenario.

  • Incident response processes and playbooks
  • Containment, eradication and recovery decisions
  • Coordination between SOC tiers and other teams
  • Documenting actions so findings are defensible

Log Management (15%)

The third-largest domain underpins the two above it. Triage is only as good as your ability to read and correlate logs.

  • Windows, Linux and Mac system logs
  • Network and application logs
  • Collection, normalization and retention concerns

The smaller domains are not throwaway. Proactive Threat Detection (12%) covers threat intelligence and hunting, Understanding Cyber Threats, IoCs, and Attack Methodology (8%) builds your adversary vocabulary, and the three 5% domains, Security Operations and Management (SOC operations and maturity), Forensics Investigation and Malware Analysis, and SOC for Cloud Environments (Azure, AWS and GCP), can each swing a close result.

Sequencing Your Prep by Domain Weight

Because the weights are so uneven, the order in which you study matters. Here is one way to align a timeline to the blueprint. For a fuller plan, see our CSA study guide.

Weeks 1-2

Foundations: Logs and Threat Vocabulary

  • Work through Log Management (15%) first, since every later domain depends on reading logs.
  • Cover attack methodology and IoCs (8%) alongside it so alerts have meaning.
Weeks 3-4

The 25% Core: Triage

  • Spend the most time on Incident Detection and Triage.
  • Build your own scenarios: take a handful of raw log lines and decide escalate, monitor or close, then justify it.
Weeks 5-6

The 25% Core: Response

  • Study Incident Response, then practice walking a scenario through each playbook step.
  • Add Proactive Threat Detection (12%) to connect hunting back to response.
Week 7

Smaller Domains and Practice

  • Review SOC operations, forensics and malware analysis, and Azure/AWS/GCP SOC topics.
  • Take timed practice sets on the CSA practice test site to rehearse three-hour pacing across 100 questions.

Practice with original explanations rather than leaked or memorized questions. Memorized dumps do not transfer to scenario-based items, and they conflict with the credential's integrity rules. The main practice test platform is built around explained, original-style questions mapped to these eight domains.

After You Pass: Keeping the Credential Active

Requirements do not end at the exam. CSA is maintained on a three-year cycle, requiring 120 CPE/ECE credits in that period. EC-Council also publishes a USD 80 annual continuing-education fee, which is USD 240 across three years. Paying the fee alone does not satisfy the continuing-education requirement; you must earn and report the credits as well.

Budget for the full lifecycle: When comparing routes, include renewal. Voucher, any application fee, optional courseware, and three years of continuing-education fees all belong in the real cost of holding the credential. Our ROI analysis of the CSA certification weighs these costs against career value.

Scheduling details, including how remote proctoring is booked, are covered in our CSA exam dates guide.

Where the Credential Fits in Hiring

CSA targets people working in or moving into security operations: SOC analysts at the tier 1 and tier 2 level, security monitoring staff, and network or systems administrators shifting toward security. Its blueprint centers on the work those roles perform, which is triage, log analysis and incident response, rather than offensive testing or governance.

On compensation, be cautious. SOC analyst pay is an occupational figure that varies by region, employer and experience. There is no verified evidence here of a CSA-specific salary premium, so treat any claim of a guaranteed bump skeptically. Our CSA salary guide separates general SOC analyst earnings from what can honestly be attributed to the certification, and the CSA pass rate article explains why no certification-wide pass rate is claimed.

If you are still orienting yourself to the credential, our overview of what CSA certification is is a good starting point.

Key Takeaway

Decide your route first. If you have a year of verifiable network or security experience and a willing verifier, self-study costs a USD 100 application plus the USD 450 voucher. If not, the official training route is your way in, with the application charge already included in training fees.

Frequently Asked Questions

Is official training required to take the CSA exam?

No. The certification portal's CSA-specific eligibility provisions allow a self-study route for applicants with one year of verified network-administration or security experience, and those provisions take precedence over the training page's blanket suggestion that training is mandatory.

How much experience do I need for the self-study route?

One year of verified network-administration or security experience. An employer, supervisor or department verifier must confirm it, and you pay a USD 100 nonrefundable eligibility-application fee.

How long do I have to buy the voucher after approval?

Approved eligibility provides a three-month window to purchase the voucher. Once purchased, the USD 450 voucher is valid for one year and cannot be transferred to another person.

Is the USD 250 eCourseware the same as an exam voucher?

No. The separately listed USD 250 eCourseware is study material only. You still need the USD 450 CSAv2 Exam Voucher to sit the exam, plus established eligibility.

What does the exam look like once I qualify?

Exam 312-39 has 100 multiple-choice questions, a three-hour limit and a 70% passing score, delivered with remote proctoring. The three-day figure in training descriptions refers to course length, not the exam timer.

Ready to pass your CSA exam?

Put this into practice with free CSA questions across every exam domain.