- The Two Routes to Eligibility
- Self-Study Route: What You Must Prove
- Fees: What Is Included and What Is Separate
- What You Qualify For: The 312-39 Exam Format
- Applicants Who Are Minors
- Knowledge Readiness: What the Blueprint Expects
- Sequencing Your Prep by Domain Weight
- After You Pass: Keeping the Credential Active
- Where the Credential Fits in Hiring
- Frequently Asked Questions
- CSA (Certified SOC Analyst, exam 312-39, version 2) is issued by EC-Council and has two eligibility routes: official training or self-study.
- Self-study applicants need one year of verified network-administration or security experience plus a USD 100 nonrefundable application fee.
- The exam voucher costs USD 450, is non-transferable, and stays valid for one year after purchase.
- Approved self-study eligibility gives you a three-month window to buy the voucher.
The Two Routes to Eligibility
The Certified SOC Analyst credential from EC-Council does not let you simply buy a voucher and sit the exam. Eligibility must be established first, and there are two official paths: the official training route (a qualifying purchase of official courseware or training) and the self-study route (a verified-experience application). Both lead to the same exam, 312-39 for CSA v2, and the same credential.
One point trips up many candidates. EC-Council's training-page FAQ suggests that official training is mandatory, while the certification portal's CSA-specific eligibility provisions describe the self-study alternative. The portal's CSA-specific rules take precedence. If you have the required experience, you are not forced into a training purchase. If you lack it, the training route is your straightforward way in.
| Factor | Official Training Route | Self-Study Route |
|---|---|---|
| Basis for eligibility | Qualifying official training or courseware purchase | One year of verified network-administration or security experience |
| Application fee | USD 100 charge is included in official-training fees | USD 100 nonrefundable eligibility-application fee, paid separately |
| Verification needed | Proof of the qualifying purchase | Employer, supervisor or department verifier |
| Voucher | Purchased per portal instructions (USD 450 voucher price) | USD 450 voucher bought within three months of approval |
| Best suited to | Career changers and those without qualifying experience | Working network or security staff with documented experience |
Self-Study Route: What You Must Prove
The self-study route rewards people who already work near the problem space. The core requirement is one year of verified experience in network administration or security. That wording matters. The experience must be verifiable, and the portal requires an employer, supervisor or department verifier to confirm it. A personal statement or home-lab description does not substitute for that verification.
Preparing a clean application
- Identify your verifier early. A direct supervisor or department contact who can confirm your duties is the practical choice. Contact them before you apply so the request does not stall your timeline.
- Describe duties in terms the reviewer recognizes. Firewall and switch administration, log review, endpoint or server administration with security duties, and alert handling are all relevant to the SOC context.
- Keep the USD 100 fee in mind. It is a nonrefundable eligibility-application fee, so submit only when your experience and verifier are genuinely in place.
- Watch the clock after approval. Approved eligibility provides a three-month window to purchase the voucher. Do not apply until you can commit to buying within that period.
Fees: What Is Included and What Is Separate
Candidates routinely confuse three different purchases. Keeping them straight prevents overpaying or buying the wrong product. For a full pricing breakdown, see our CSA certification cost guide.
| Item | Amount | What It Is |
|---|---|---|
| CSAv2 Exam Voucher (remote proctored) | USD 450 | Your exam attempt; non-transferable; valid one year from purchase |
| Self-study eligibility application | USD 100 | Nonrefundable fee to have your experience reviewed |
| Separately listed eCourseware | USD 250 | Study materials only; not an exam voucher |
| Official training bundles | Varies by package | Training that satisfies the training route; the USD 100 application charge is included in official-training fees |
The most important distinction: the USD 250 eCourseware is not an exam voucher. Buying courseware gives you study content, not a seat in the exam. Likewise, if you take the training route, the eligibility page states that the USD 100 application charge is already included in official-training fees, so you should not pay it a second time. Self-study candidates, by contrast, pay the USD 100 application fee and the USD 450 voucher as separate line items.
What You Qualify For: The 312-39 Exam Format
Understanding the exam you are qualifying for helps you decide whether the effort is justified and how to prepare. The CSA v2 exam, 312-39, has these characteristics:
- 100 multiple-choice questions
- Three-hour time limit
- 70% passing score
- Remote proctoring through the EC-Council exam portal and ECC Exam Centre
A clarification worth making: the three-day figure you see in the training description is the course duration, not the exam timer. And although training labs are hands-on, the certification exam itself is a multiple-choice assessment, not a lab-based practical. For more on scoring, read our CSA passing score guide, and for a realistic view of difficulty, see how hard the CSA exam is.
Be careful with older material. Six-domain v1 lists, third-party four-domain breakdowns and claims of a two-hour exam do not describe the verified v2 scope. Rely on the official blueprint titled Certified SOC Analyst (CSA) v2 Exam Blueprint, exam 312-39.
Applicants Who Are Minors
If you are under the age of majority, the portal applies additional rules. Applicants who are minors must follow the portal's parental-consent and educational-institution documentation requirements. Because these requirements are specific and procedural, read that section of the CSA application page directly and gather the documents before you pay any fees. Treat the portal text as the only authority here rather than relying on summaries from training vendors.
Knowledge Readiness: What the Blueprint Expects
Meeting the administrative eligibility rule is not the same as being ready. The blueprint defines eight weighted domains, and candidates should assess themselves against them before buying a voucher. Our complete guide to all 8 CSA content areas goes deeper; the summary below shows where the weight sits.
| Domain | Weight |
|---|---|
| Security Operations and Management | 5% |
| Understanding Cyber Threats, IoCs, and Attack Methodology | 8% |
| Log Management | 15% |
| Incident Detection and Triage | 25% |
| Proactive Threat Detection | 12% |
| Incident Response | 25% |
| Forensics Investigation and Malware Analysis | 5% |
| SOC for Cloud Environments | 5% |
The weights total 100%, and these are official weighted exam objectives, not allocations derived from a curriculum. Notice that Incident Detection and Triage and Incident Response are jointly the largest domains at 25% each, which together represent 50% of the blueprint.
Incident Detection and Triage (25%)
This is where a SOC analyst's day-to-day judgment is tested. Expect to reason about which alerts deserve escalation and why.
- SIEM use cases and how detection logic maps to attacker behavior
- Alert triage: severity, context, false-positive reasoning
- AI-generated detection rules, a v2-era topic worth understanding critically
- Correlating events across Windows, Linux, Mac, network and application sources
Incident Response (25%)
Beyond knowing the phases, candidates should be comfortable applying them to a scenario.
- Incident response processes and playbooks
- Containment, eradication and recovery decisions
- Coordination between SOC tiers and other teams
- Documenting actions so findings are defensible
Log Management (15%)
The third-largest domain underpins the two above it. Triage is only as good as your ability to read and correlate logs.
- Windows, Linux and Mac system logs
- Network and application logs
- Collection, normalization and retention concerns
The smaller domains are not throwaway. Proactive Threat Detection (12%) covers threat intelligence and hunting, Understanding Cyber Threats, IoCs, and Attack Methodology (8%) builds your adversary vocabulary, and the three 5% domains, Security Operations and Management (SOC operations and maturity), Forensics Investigation and Malware Analysis, and SOC for Cloud Environments (Azure, AWS and GCP), can each swing a close result.
Sequencing Your Prep by Domain Weight
Because the weights are so uneven, the order in which you study matters. Here is one way to align a timeline to the blueprint. For a fuller plan, see our CSA study guide.
Foundations: Logs and Threat Vocabulary
- Work through Log Management (15%) first, since every later domain depends on reading logs.
- Cover attack methodology and IoCs (8%) alongside it so alerts have meaning.
The 25% Core: Triage
- Spend the most time on Incident Detection and Triage.
- Build your own scenarios: take a handful of raw log lines and decide escalate, monitor or close, then justify it.
The 25% Core: Response
- Study Incident Response, then practice walking a scenario through each playbook step.
- Add Proactive Threat Detection (12%) to connect hunting back to response.
Smaller Domains and Practice
- Review SOC operations, forensics and malware analysis, and Azure/AWS/GCP SOC topics.
- Take timed practice sets on the CSA practice test site to rehearse three-hour pacing across 100 questions.
Practice with original explanations rather than leaked or memorized questions. Memorized dumps do not transfer to scenario-based items, and they conflict with the credential's integrity rules. The main practice test platform is built around explained, original-style questions mapped to these eight domains.
After You Pass: Keeping the Credential Active
Requirements do not end at the exam. CSA is maintained on a three-year cycle, requiring 120 CPE/ECE credits in that period. EC-Council also publishes a USD 80 annual continuing-education fee, which is USD 240 across three years. Paying the fee alone does not satisfy the continuing-education requirement; you must earn and report the credits as well.
Scheduling details, including how remote proctoring is booked, are covered in our CSA exam dates guide.
Where the Credential Fits in Hiring
CSA targets people working in or moving into security operations: SOC analysts at the tier 1 and tier 2 level, security monitoring staff, and network or systems administrators shifting toward security. Its blueprint centers on the work those roles perform, which is triage, log analysis and incident response, rather than offensive testing or governance.
On compensation, be cautious. SOC analyst pay is an occupational figure that varies by region, employer and experience. There is no verified evidence here of a CSA-specific salary premium, so treat any claim of a guaranteed bump skeptically. Our CSA salary guide separates general SOC analyst earnings from what can honestly be attributed to the certification, and the CSA pass rate article explains why no certification-wide pass rate is claimed.
If you are still orienting yourself to the credential, our overview of what CSA certification is is a good starting point.
Key Takeaway
Decide your route first. If you have a year of verifiable network or security experience and a willing verifier, self-study costs a USD 100 application plus the USD 450 voucher. If not, the official training route is your way in, with the application charge already included in training fees.
Frequently Asked Questions
No. The certification portal's CSA-specific eligibility provisions allow a self-study route for applicants with one year of verified network-administration or security experience, and those provisions take precedence over the training page's blanket suggestion that training is mandatory.
One year of verified network-administration or security experience. An employer, supervisor or department verifier must confirm it, and you pay a USD 100 nonrefundable eligibility-application fee.
Approved eligibility provides a three-month window to purchase the voucher. Once purchased, the USD 450 voucher is valid for one year and cannot be transferred to another person.
No. The separately listed USD 250 eCourseware is study material only. You still need the USD 450 CSAv2 Exam Voucher to sit the exam, plus established eligibility.
Exam 312-39 has 100 multiple-choice questions, a three-hour limit and a 70% passing score, delivered with remote proctoring. The three-day figure in training descriptions refers to course length, not the exam timer.