IBACTP® — International Board of AI, Cybersecurity & Technology Professionals
CCDP®

Certified Cyber Defense Professional

Detect Earlier. Respond Effectively. Recover Securely. Build Cyber Resilience.

Modern organizations face ransomware, credential attacks, cloud compromise, malicious insiders, supply-chain attacks, advanced persistent threats, AI-enabled attacks, data breaches, endpoint compromise, application attacks, and rapidly evolving vulnerabilities.

A security analyst monitoring code on dark screens
Cyber Defense
CCDP® Certified Cyber Defense Professional badge

Detect Earlier. Respond Effectively. Recover Stronger.

Professional Level For practitioners, specialists, analysts and engineers
Vendor-Neutral Skills and knowledge that apply across platforms and tools
Global Recognition Recognized internationally across industries and regions
Digital Credential Shareable, verifiable credential and certificate

What You Will Learn

Master the core areas of cyber defense.

  • 8 Comprehensive Cyber Defense Modules

Module 1 — Cyber Defense Foundations and Defensive Architecture

  • Cyber-defense principles and threat landscape
  • Attack surfaces and adversary behavior
  • Defense-in-depth and Zero Trust
  • Defensive architecture and resilience

Module 2 — Security Monitoring, Detection, and SOC Operations

  • SOC operations and security monitoring
  • SIEM, EDR/XDR, IDS/IPS, and telemetry
  • Alert triage and event correlation
  • Detection strategies and escalation

Module 3 — Threat Intelligence, Hunting, and Adversary Analysis

  • Threat-intelligence lifecycle
  • Indicators and adversary behavior
  • Threat-hunting methodologies
  • Attack-pattern and campaign analysis

Module 4 — Vulnerability, Exposure, and Attack-Surface Management

  • Vulnerability identification and assessment
  • Exploitability and threat context
  • Attack-surface and exposure management
  • Risk-based remediation prioritization

Module 5 — Incident Detection, Triage, and Response

  • Incident identification and classification
  • Severity, escalation, and triage
  • Containment and eradication
  • Response coordination and documentation

Module 6 — Digital Forensics and Cyber Investigation

  • Forensic readiness and evidence handling
  • Chain of custody and preservation
  • Endpoint, network, log, and cloud evidence
  • Timeline reconstruction and investigation

Module 7 — Recovery, Continuity, and Cyber Resilience

  • Secure restoration
  • Business continuity and disaster recovery
  • Recovery validation and exercises
  • Lessons learned and resilience improvement

Module 8 — AI-Enabled Defense and Emerging Threats

  • AI-assisted cyberattacks
  • AI-enabled detection and defense
  • Cloud, IoT, OT, APIs, and containers
  • Automation, supply-chain threats, and emerging risks
About the credential

Become a Cyber Defense professional the market trusts.

Modern organizations face ransomware, credential attacks, cloud compromise, malicious insiders, supply-chain attacks, advanced persistent threats, AI-enabled attacks, data breaches, endpoint compromise, application attacks, and rapidly evolving vulnerabilities.

Organizations therefore need cyber-defense professionals who can do more than recognize cybersecurity terminology. They need professionals who can monitor environments, detect threats, analyze security evidence, investigate incidents, contain attacks, support recovery, and strengthen resilience.

The Certified Cyber Defense Professional (CCDP®) is a comprehensive, vendor-neutral professional certification designed to validate practical competency across the modern cyber-defense lifecycle.

Offered by the:

International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)

CCDP® integrates

  • Cyber Defense
  • SOC Operations
  • Security Monitoring
  • Threat Detection
  • Threat Intelligence
  • Threat Hunting
  • Vulnerability Management
  • Exposure Management
  • Incident Response
  • Digital Forensics
  • Recovery
  • Cyber Resilience
  • AI-Enabled Defense

The CCDP® Professional Mission

Detect Threats → Analyze Evidence → Contain Incidents → Investigate Effectively → Recover Securely → Strengthen Cyber Resilience

A security analyst monitoring code on dark screens

Professional level — Three-year certification cycle with continuing professional education

Build the practical cyber-defense competencies organizations need to identify threats earlier, investigate security activity accurately, contain incidents effectively, and strengthen cyber resilience.

The Certified Cyber Defense Professional (CCDP®) is a comprehensive, vendor-neutral professional certification from the International Board of AI, Cybersecurity & Technology Professionals (IBACTP®) designed for professionals responsible for protecting modern digital environments.

CCDP® brings together the critical capabilities required across the cyber-defense lifecycle

  • Security Monitoring
  • Threat Detection
  • SOC Operations
  • Threat Intelligence
  • Threat Hunting
  • Vulnerability & Exposure Management
  • Incident Response
  • Digital Forensics
  • Recovery
  • Cyber Resilience
  • AI-Enabled Defense

CCDP® Professional Objective

Identify Exposure → Detect Threats → Analyze Activity → Contain Incidents → Investigate Compromise → Recover Securely → Strengthen Resilience

[APPLY FOR CCDP®]

  • [REGISTER FOR THE EXAM]
  • [ENROLL IN CCDP® TRAINING]
  • [DOWNLOAD PROGRAM GUIDE]
A security analyst monitoring code on dark screens
Why this credential

Why Earn the CCDP® Certification?

Modern cyber defense is no longer a collection of isolated technical tasks.

A single security alert can involve endpoint activity, identity compromise, cloud services, network traffic, exploitable vulnerabilities, threat intelligence, digital evidence, incident response, business disruption, and recovery—all at the same time.

Organizations therefore need cyber-defense professionals who can understand how these signals connect, determine what matters most, and support effective defensive action across the complete incident lifecycle.

The Certified Cyber Defense Professional (CCDP®) is designed around this integrated operational reality.

  • Detect Earlier. Analyze Accurately. Respond Effectively. Recover Securely. Build Cyber Resilience.

Build End-to-End Cyber Defense Competency

CCDP® develops the ability to move from isolated security events to informed defensive decisions.

Professionals learn to answer practical questions such as:

  • Is this activity normal, suspicious, or malicious?
  • What does this security alert actually indicate?
  • What evidence should be collected and analyzed first?
  • Which vulnerability creates the greatest real-world exposure?
  • Is the vulnerability actively being exploited?
  • What does current threat intelligence reveal about the adversary or attack?
  • Should this event be escalated into an incident?
  • How severe is the incident and what is the potential business impact?
  • Which systems, accounts, or services should be contained first?
  • What digital evidence must be preserved?
  • Has the malicious activity been fully eradicated?
  • Can affected systems and services be restored safely?
  • Which defensive controls failed or proved insufficient?
  • What lessons should be incorporated into future detection and response?
  • How can the organization reduce the likelihood and impact of a similar incident?

From Security Data to Defensive Action

CCDP® helps professionals connect the full cyber-defense chain:

Security Events → Detection → Analysis → Investigation → Containment → Recovery → Resilience

This integrated perspective is critical because effective cyber defense depends on more than recognizing an attack.

Professionals must be able to understand:

What Happened

Identify suspicious behavior, attack indicators, vulnerabilities, and affected assets.

Why It Matters

Determine severity, scope, exploitability, business impact, and organizational exposure.

What Must Happen Next

Prioritize investigation, escalation, containment, eradication, and recovery actions.

What Must Improve Afterwards

Apply lessons learned to strengthen monitoring, controls, response procedures, recovery capability, and resilience.

The CCDP® Professional Advantage

CCDP® brings together competencies that are often treated separately:

SOC Operations + Threat Detection + Threat Intelligence + Threat Hunting + Vulnerability Management + Exposure Management + Incident Response + Digital Forensics + Recovery + Cyber Resilience

This enables professionals to see cyber defense as a continuous operational capability, rather than a collection of disconnected security tools and processes.

CCDP® Value Proposition

The certification prepares professionals to move confidently through the defensive lifecycle:

Recognize the Threat → Interpret the Evidence → Prioritize the Response → Contain the Incident → Support Investigation → Recover Securely → Strengthen Resilience

Cyber Defense

Who Should Earn CCDP®?

CCDP® is designed for professionals working in or preparing for roles involving:

  • Cyber Defense
  • Security Operations Centers
  • Cybersecurity Operations
  • Incident Response
  • Threat Analysis
  • Threat Intelligence
  • Threat Hunting
  • Vulnerability Management
  • Exposure Management
  • Digital Forensics
  • Security Monitoring
  • Network Defense
  • Endpoint Security
  • Cloud Security
  • Cybersecurity Engineering
  • Security Analysis
  • Cyber Resilience

Relevant Career Roles

CCDP® can support career development for:

Cyber Defense Analyst • SOC Analyst • Cybersecurity Analyst • Security Operations Analyst • Incident Response Analyst • Cybersecurity Specialist • Threat Analyst • Threat Hunter • Vulnerability Analyst • Security Engineer • Digital Forensics Analyst • Cyber Incident Analyst • Cloud Security Analyst • Cyber Defense Specialist

Learning outcomes

CCDP® Course Learning Outcomes

The Certified Cyber Defense Professional (CCDP®) curriculum is designed to develop practical, analytical, and professional competency across the complete cyber-defense lifecycle.

Upon successful completion of CCDP® training, participants will be able to:

1. Apply Cyber Defense Principles and Defensive Architecture

Evaluate cyber threats, attack surfaces, adversary behavior, defensive controls, defense-in-depth, Zero Trust principles, and resilient security architectures.

Participants develop the ability to connect threats and vulnerabilities with appropriate defensive safeguards across networks, endpoints, identities, applications, cloud environments, and enterprise infrastructure.

2. Perform Security Monitoring, Detection, and SOC Analysis

Analyze security information from networks, endpoints, identities, cloud services, applications, and security platforms to identify suspicious or malicious activity.

Participants develop competency involving:

Learning Progression:

Monitor → Identify → Validate → Analyze → Escalate

  • Security monitoring
  • Logs and event analysis
  • SIEM concepts
  • EDR/XDR telemetry
  • Network monitoring
  • Alert triage
  • Event correlation
  • Indicators of compromise
  • Detection and escalation

3. Apply Threat Intelligence, Threat Hunting, and Adversary Analysis

Use threat intelligence, indicators of compromise, adversary behaviors, attack techniques, and analytical hypotheses to support proactive cyber defense.

Participants learn to connect:

Threat Intelligence → Adversary Behavior → Security Telemetry → Hunting Hypothesis → Defensive Action

The objective is to move beyond purely reactive monitoring toward intelligence-driven defense.

4. Assess Vulnerabilities, Exposure, and Attack Surfaces

Identify and evaluate vulnerabilities, misconfigurations, exposed assets, attack paths, and security weaknesses.

Participants learn to prioritize defensive action using factors such as:

Technical Severity + Exploitability + Threat Activity + Asset Criticality + Exposure + Business Impact

This risk-based approach helps distinguish vulnerabilities that are merely present from exposures requiring urgent defensive attention.

5. Conduct Incident Detection, Triage, and Response

Recognize cybersecurity incidents, determine severity and scope, establish priorities, support containment and eradication, coordinate response activities, and document defensive decisions.

Participants develop competency across:

Detect → Validate → Triage → Investigate → Contain → Eradicate → Recover

Incident response is a defining component of the CCDP® competency model.

6. Support Digital Forensics and Cyber Investigations

Apply forensic-readiness and evidence-handling principles during cybersecurity investigations.

Participants develop competency involving:

The objective is to help professionals determine:

What Happened → How It Happened → What Was Affected → What Evidence Supports the Conclusion

  • Evidence identification
  • Evidence preservation
  • Chain of custody
  • Endpoint artifacts
  • Network evidence
  • Log evidence
  • Cloud evidence
  • Timeline reconstruction
  • Investigation documentation
  • Root-cause analysis

7. Support Secure Recovery, Continuity, and Cyber Resilience

Apply recovery and resilience principles following cybersecurity incidents.

Participants learn to evaluate:

The learning progression is:

Contain → Recover → Validate → Learn → Strengthen

  • Restoration priorities
  • Backup and recovery
  • Business continuity
  • Disaster recovery
  • Critical-service dependencies
  • Recovery validation
  • Post-recovery monitoring
  • Lessons learned
  • Corrective actions
  • Resilience improvements

8. Evaluate AI-Enabled Defense and Emerging Cyber Threats

Assess cybersecurity implications associated with AI, Generative AI, defensive automation, cloud-native technologies, APIs, containers, IoT, Operational Technology, software supply chains, and evolving attack techniques.

Participants examine AI from two complementary perspectives:

AI as a Cyber-Defense Capability + AI as a Cybersecurity Risk

The emphasis is on responsible application, appropriate validation, human oversight, security controls, and emerging-risk awareness.

Learning outcomes

CCDP® Integrated Learning Outcome

Upon completion of the program, participants develop the integrated professional capability to:

  • Recognize Threats
  • Interpret Security Evidence
  • Identify Exposure
  • Investigate Incidents
  • Prioritize Defensive Action
  • Support Response
  • Recover Securely
  • Strengthen Cyber Resilience

The CCDP® learning objective is not simply to understand cyber defense.

It is to develop the competency to apply cyber-defense knowledge when organizations face real threats, incidents, disruptions, and recovery challenges.

CCDP®

CCDP® Certification Testing Outcomes

The CCDP® certification assessment evaluates whether candidates can apply professional cyber-defense knowledge, interpret security information, exercise technical judgment, and make appropriate defensive decisions.

Assessment is organized across eight integrated competency domains.

Domain 1 — Cyber Defense Foundations and Architecture

Candidates demonstrate the ability to evaluate:

Testing Focus: Select and evaluate appropriate defensive approaches for realistic organizational environments.

  • Cyber threats and adversary behavior
  • Attack surfaces
  • Security controls
  • Defense-in-depth
  • Zero Trust
  • Defensive architecture
  • Security dependencies
  • Resilience considerations

Domain 2 — Security Monitoring, Detection, and SOC Operations

Candidates demonstrate the ability to interpret:

Testing Focus: Determine whether observed activity is normal, suspicious, malicious, or requires escalation.

  • Security alerts
  • Logs
  • Network activity
  • Endpoint telemetry
  • Identity events
  • Cloud events
  • Security-platform information
  • Indicators of compromise
  • Detection information

Domain 3 — Threat Intelligence, Hunting, and Adversary Analysis

Candidates demonstrate the ability to evaluate:

Testing Focus: Use threat information and available evidence to support proactive detection and defensive decision-making.

  • Threat intelligence
  • Indicators of compromise
  • Adversary behaviors
  • Attack techniques
  • Intelligence sources
  • Threat-hunting hypotheses
  • Attack patterns
  • Emerging threats

Domain 4 — Vulnerability, Exposure, and Attack-Surface Defense

Candidates demonstrate the ability to evaluate:

Testing Focus: Determine which exposures create the greatest risk and identify appropriate remediation priorities.

  • Vulnerability findings
  • Exploitability
  • Asset exposure
  • Attack surfaces
  • Security misconfigurations
  • Asset criticality
  • Threat activity
  • Business impact
  • Remediation priorities

Domain 5 — Incident Detection, Triage, and Response

Candidates demonstrate the ability to determine:

Testing Focus: Select defensible incident-response actions based on available evidence, risk, and operational context.

  • Whether an incident has occurred
  • Incident severity
  • Incident scope
  • Escalation requirements
  • Investigation priorities
  • Appropriate containment actions
  • Eradication requirements
  • Communication priorities
  • Recovery requirements

Domain 6 — Digital Forensics, Investigation, and Evidence

Candidates demonstrate the ability to evaluate:

Testing Focus: Determine how digital evidence supports incident understanding, investigation, documentation, and corrective action.

  • Evidence-preservation requirements
  • Chain-of-custody considerations
  • Relevant forensic artifacts
  • Investigation timelines
  • Endpoint evidence
  • Network evidence
  • Log evidence
  • Cloud evidence
  • Root-cause information
  • Investigation findings

Domain 7 — Recovery, Continuity, and Cyber Resilience

Candidates demonstrate the ability to evaluate:

Testing Focus: Determine how affected operations can be restored securely while reducing the likelihood or impact of future incidents.

  • Recovery priorities
  • Secure restoration
  • Backup requirements
  • Business continuity
  • Disaster recovery
  • Recovery validation
  • Critical-service dependencies
  • Lessons learned
  • Corrective actions
  • Resilience improvements

Domain 8 — AI-Enabled Defense and Emerging Cyber Threats

Candidates demonstrate the ability to evaluate cyber-defense considerations involving:

Testing Focus: Evaluate how emerging technologies affect threats, detection, response, defensive controls, and organizational resilience.

  • AI-assisted attacks
  • AI-enabled detection
  • Defensive automation
  • Generative AI
  • Cloud-native technologies
  • APIs
  • Containers
  • IoT
  • Operational Technology
  • Software supply chains
  • Emerging attack techniques
CCDP®

The CCDP®–IBACTP® Cyber Defense Competency Model

The CCDP®–IBACTP® Cyber Defense Competency Model defines the integrated knowledge, technical capabilities, analytical skills, and professional judgment required to operate effectively across the modern cyber-defense lifecycle.

Rather than treating monitoring, threat intelligence, vulnerability management, incident response, forensics, and recovery as separate disciplines, the CCDP® model connects them into eight integrated professional competency dimensions.

Together, these dimensions prepare professionals to move from security visibility and threat recognition to investigation, response, secure recovery, and continuous resilience improvement.

1. Cyber Defense Foundations and Defensive Architecture

Build the foundation required to understand how organizations design and maintain resilient defensive environments.

Professionals develop competency in:

Professional Focus: Understand how threats interact with enterprise technologies and how layered defensive architectures reduce exposure and support resilience.

  • Cyber-defense principles
  • Threat actors and adversary objectives
  • Attack vectors and attack surfaces
  • Common attack techniques
  • Security controls
  • Defense-in-depth
  • Zero Trust principles
  • Network and system defense
  • Security architecture
  • Resilience principles

2. Security Monitoring, Detection, and SOC Operations

Develop the ability to maintain security visibility and recognize suspicious or malicious activity across enterprise environments.

Professionals develop competency in:

Professional Focus: Transform security telemetry into meaningful detection and actionable defensive information.

  • Security Operations Center practices
  • Security monitoring
  • Log and event analysis
  • SIEM concepts
  • EDR/XDR telemetry
  • Network-security monitoring
  • Identity-related events
  • Cloud-security telemetry
  • Alert triage
  • Event correlation
  • Indicators of compromise
  • Detection and escalation

3. Threat Intelligence, Hunting, and Adversary Analysis

Develop a proactive understanding of adversaries, attack behaviors, indicators, and emerging threats.

Professionals develop competency in:

Professional Focus: Use threat intelligence and adversary behavior to move cyber defense from purely reactive monitoring toward proactive threat discovery.

  • Threat-intelligence concepts
  • Intelligence sources
  • Indicators of compromise
  • Adversary tactics and techniques
  • Threat behavior
  • Intelligence analysis
  • Threat-hunting hypotheses
  • Proactive investigation
  • Attack-pattern analysis
  • Intelligence-driven defense

4. Vulnerability, Exposure, and Attack-Surface Defense

Develop risk-based competency for identifying and reducing weaknesses that attackers may exploit.

Professionals develop competency in:

CCDP® emphasizes that vulnerability priority is not determined by technical severity alone.

Professionals learn to consider:

  • Vulnerability identification
  • Vulnerability assessment
  • Exploitability
  • Asset criticality
  • Threat context
  • Attack-surface analysis
  • Exposure management
  • Security misconfigurations
  • Remediation prioritization
  • Compensating controls
  • Continuous exposure reduction

Vulnerability + Exploitability + Threat Activity + Exposure + Asset Criticality + Business Impact

Professional Focus: Identify the exposures that matter most and support risk-based remediation.

5. Incident Detection, Triage, and Response

Develop the professional judgment required to recognize, classify, investigate, contain, and respond to cybersecurity incidents.

Professionals develop competency in:

The incident progression is:

  • Incident identification
  • Alert validation
  • Incident classification
  • Severity determination
  • Incident triage
  • Escalation
  • Scope assessment
  • Containment
  • Eradication
  • Response coordination
  • Documentation
  • Recovery initiation
  • Lessons learned

Security Event → Suspicious Activity → Confirmed Incident → Response → Recovery

Professional Focus: Convert detection into coordinated defensive action while limiting organizational impact.

6. Digital Forensics, Investigation, and Evidence

Develop foundational investigative competency required to preserve evidence, understand attack activity, and support defensible incident investigations.

Professionals develop competency in:

Professional Focus: Preserve and interpret digital evidence so organizations can understand what happened, how it happened, what was affected, and what corrective action is required.

  • Forensic readiness
  • Evidence identification
  • Evidence preservation
  • Chain of custody
  • Endpoint artifacts
  • Network evidence
  • Log evidence
  • Cloud evidence
  • Timeline reconstruction
  • Investigation documentation
  • Root-cause analysis
  • Reporting findings

7. Recovery, Continuity, and Cyber Resilience

Extend cyber defense beyond incident containment by ensuring that affected systems and critical services can be restored securely.

Professionals develop competency in:

The CCDP® resilience approach follows:

  • Secure system restoration
  • Recovery planning
  • Backup and restoration concepts
  • Business continuity
  • Disaster recovery
  • Critical-service dependencies
  • Recovery validation
  • Post-recovery monitoring
  • Lessons learned
  • Corrective actions
  • Cyber exercises
  • Resilience improvement

Respond → Recover → Validate → Learn → Strengthen

Professional Focus: Help the organization restore operations securely while using incident experience to reduce future disruption.

8. AI-Enabled Defense and Emerging Cyber Threats

Develop awareness and professional judgment for defending rapidly changing technology environments and using emerging defensive capabilities responsibly.

Professionals develop competency in:

CCDP® addresses AI from both perspectives:

  • AI-assisted threat detection
  • AI-enabled security analytics
  • AI-supported threat intelligence
  • Defensive automation
  • AI-assisted incident response
  • Generative AI security risks
  • AI-enabled cyberattacks
  • Adversarial AI
  • Cloud-native security
  • API security
  • Containers
  • IoT security
  • Operational Technology security
  • Software supply-chain threats
  • Emerging attack techniques

AI as a Cyber-Defense Capability + AI as a Cybersecurity Risk

Professional Focus: Evaluate emerging threats and use AI-enabled defensive capabilities with appropriate validation, security controls, and human oversight.

CCDP®

Option 2 — CCDP® Applied Cyber Defense Capstone

Eligible candidates participating in an approved instructor-led pathway may demonstrate competency through the CCDP® Applied Cyber Defense Capstone.

The Capstone provides an applied alternative that integrates multiple CCDP® competency domains into a realistic cyber-defense scenario. Instead of evaluating competencies only through individual examination questions, candidates demonstrate their ability to analyze an evolving cybersecurity situation, investigate evidence, make defensive decisions, recommend response actions, and strengthen organizational resilience.

  • The CCDP® Capstone Progression
  • Threat Assessment → Detection → Analysis → Investigation → Incident Response → Recovery → Resilience Improvement
  • What Happened → How Serious Is It → What Is Affected → What Must Be Contained → What Evidence Must Be Preserved
  • Incident Containment → Secure Recovery → Lessons Learned → Stronger Cyber Resilience

Capstone Part 1 — Threat Detection and Security Analysis

Candidates evaluate a simulated organizational environment containing security events, vulnerabilities, alerts, threat information, and potential indicators of malicious activity.

Activities may include:

  • Reviewing security alerts
  • Interpreting logs and telemetry
  • Identifying indicators of compromise
  • Evaluating threat intelligence
  • Identifying attack patterns
  • Assessing vulnerabilities
  • Evaluating enterprise exposure
  • Determining affected assets
  • Establishing investigation priorities

Candidate Objective

Determine:

What is happening?

What evidence supports the conclusion?

What is potentially at risk?

What requires immediate investigation?

Capstone Part 2 — Incident Investigation and Response

Candidates investigate the developing cyber incident and determine appropriate defensive actions.

Activities may include:

  • Classifying the incident
  • Determining severity
  • Establishing scope
  • Developing an incident timeline
  • Identifying compromised assets
  • Evaluating attacker activity
  • Preserving relevant evidence
  • Recommending containment actions
  • Supporting eradication
  • Establishing escalation requirements
  • Documenting response decisions

Candidate Objective

Determine:

Capstone Part 3 — Recovery and Cyber Resilience

Candidates develop recommendations for secure restoration and post-incident improvement.

Activities may include:

  • Establishing recovery priorities
  • Evaluating restoration requirements
  • Validating system security
  • Identifying failed or insufficient controls
  • Evaluating continuity requirements
  • Recommending corrective actions
  • Improving monitoring and detection
  • Strengthening incident-response procedures
  • Reducing future exposure
  • Developing resilience recommendations
  • Documenting lessons learned

Candidate Objective

Move the organization from:

CCDP®

What the CCDP® Capstone Demonstrates

Successful Capstone candidates demonstrate their ability to integrate multiple cyber-defense competencies rather than treating each security function independently.

The Capstone evaluates the ability to:

  1. Detect the Threat
  2. Interpret the Evidence
  3. Assess the Exposure
  4. Investigate the Incident
  5. Prioritize Defensive Actions
  6. Support Containment and Eradication
  7. Recommend Secure Recovery
  8. Strengthen Future Resilience

This reflects the interconnected nature of real-world cyber-defense operations.

One Certification Standard. Two Assessment Pathways.

Whether competency is demonstrated through the CCDP® Certification Examination or an eligible Applied Cyber Defense Capstone, the professional objective remains consistent:

Can the Candidate Detect, Analyze, Investigate, Respond, Recover, and Improve?

CCDP® assessment focuses on the ability to transform:

Security Information → Professional Judgment → Defensive Action → Secure Recovery → Cyber Resilience

CCDP® Assessment Philosophy

CCDP®

CCDP® Assessment Cognitive Levels

CCDP® evaluates candidates across multiple levels of professional competency.

Knowledge and Understanding

Recognize and explain cyber-defense concepts, technologies, threats, vulnerabilities, controls, procedures, and professional practices.

Application

Apply appropriate cyber-defense principles and controls to realistic technical and organizational situations.

Analysis

Interpret logs, alerts, telemetry, vulnerabilities, threat intelligence, digital evidence, and incident scenarios.

Evaluation and Technical Judgment

Compare defensive options, prioritize actions, evaluate consequences, and select appropriate responses.

Scenario-Based Decision-Making

Integrate multiple cyber-defense competencies when addressing realistic threats, incidents, investigations, and recovery situations.

CCDP®

CCDP® Certification Competency Standard

CCDP® evaluates more than a candidate's ability to recall cybersecurity terminology.

Successful candidates demonstrate the ability to combine:

Technical Knowledge + Security Analysis + Threat Recognition + Investigation + Incident Judgment + Recovery + Professional Responsibility

The CCDP® certification competency progression is:

CCDP®

CCDP® Technology Competency Standard

Candidates develop the ability to:

Understand → Interpret → Correlate → Investigate → Respond → Recover → Improve

A CCDP® professional should understand:

  • What the technology is designed to do
  • What security information it provides
  • How the output supports threat detection
  • How information from multiple tools can be correlated
  • What limitations may exist
  • When human analysis is required
  • How the technology supports incident response
  • How it contributes to recovery and resilience
What it validates

What Is CCDP®?

The Certified Cyber Defense Professional (CCDP®) is a professional-level, vendor-neutral certification designed to validate practical competency in threat detection, security analysis, incident investigation, response, recovery, and cyber resilience.

CCDP® prepares professionals to understand how the major components of modern cyber defense work together across Security Operations Centers, incident-response teams, threat-intelligence functions, vulnerability programs, digital investigations, and recovery environments.

The certification develops competency across:

  • Cyber-defense architecture
  • Security monitoring and SOC operations
  • SIEM and security analytics
  • Endpoint and network detection
  • Threat intelligence and threat hunting
  • Vulnerability and exposure management
  • Attack-surface analysis
  • Incident detection and triage
  • Incident response and containment
  • Digital forensics and evidence handling
  • Business continuity and disaster recovery
  • Cyber resilience
  • Cloud defense
  • AI-enabled cyber defense
  • Emerging cyber threats

More Than Cybersecurity Knowledge

CCDP® is not designed simply to test whether a candidate understands cybersecurity terminology.

It focuses on whether a professional can interpret security information, identify meaningful threats, evaluate evidence, prioritize defensive actions, support incident response, and contribute to secure recovery.

The defining question is not:

“Do you know cybersecurity?”

It is:

“Can you recognize the threat, understand the evidence, make the right defensive decision, respond effectively, and help the organization recover securely?”

The CCDP® Professional Focus

CCDP® connects the core stages of cyber defense into one practical competency framework:

Monitor → Detect → Analyze → Investigate → Respond → Recover → Strengthen

This prepares CCDP® professionals to contribute across the complete defensive lifecycle—from identifying suspicious activity to helping organizations become more resilient after an incident.

Detect Earlier. Analyze Accurately. Respond Effectively. Recover Securely.

Applied practice

Applied Cyber Defense Labs

CCDP® training can incorporate practical management and technical-analysis activities.

Assessment

Option 1 — CCDP® Certification Examination

The CCDP® Certification Examination provides a structured assessment of professional cyber-defense knowledge, application, analysis, and decision-making across the CCDP® Body of Knowledge.

Option 1

Examination Structure

100 Questions

90 Minutes

Multiple-Choice and Scenario-Based Multiple-Choice Questions

Closed Book

Secure Online Proctoring or Approved Testing Center

Recommended Passing Score: 70%

Option 2

What Examination Measures

The examination evaluates competency across the major stages of modern cyber defense:

Knowledge • Application • Detection • Analysis • Threat Recognition • Technical Judgment • Incident Response • Investigation • Recovery • Resilience

Candidates may be required to interpret realistic situations involving:

  • Security alerts and events
  • Logs and security telemetry
  • Indicators of compromise
  • Threat intelligence
  • Adversary behavior
  • Vulnerabilities and enterprise exposures
  • Attack-surface conditions
  • Incident severity and escalation
  • Containment and eradication decisions
  • Digital evidence
  • Investigation findings
  • Recovery priorities
  • Business continuity considerations
  • Cyber-resilience improvements
  • AI-enabled and emerging cyber threats
Option 3

Scenario-Based Assessment

CCDP® examination questions emphasize practical professional judgment.

Rather than asking only:

“What does this cybersecurity term mean?”

Candidates may be asked:

“Given the available evidence, what is the most appropriate defensive action?”

This approach evaluates whether candidates can apply cyber-defense principles when facing realistic technical and organizational situations.

Option 4

Examination Decision Progression

Candidates demonstrate the ability to move through:

Option 5

Recognize → Interpret → Analyze → Prioritize → Respond → Recover → Improve

The objective is to determine whether the candidate can connect cybersecurity knowledge with appropriate professional action.

Cyber Defense

Standards and International Framework Alignment

The CCDP® Body of Knowledge is designed to reflect recognized cybersecurity, risk-management, incident-response, business-continuity, AI-risk, and professional workforce practices relevant to modern cyber defense.

Rather than requiring candidates to memorize individual standards, CCDP® emphasizes the ability to understand, interpret, and apply recognized principles within practical cyber-defense situations.

The certification incorporates relevant concepts and practices associated with:

ISO/IEC 27001

Information security management principles, security governance, risk-based controls, and continual improvement.

ISO/IEC 27002

Information security controls and implementation practices supporting organizational cyber defense.

ISO/IEC 27005

Information security risk-management principles supporting threat, vulnerability, impact, and risk-based decision-making.

ISO/IEC 27701

Privacy information management principles relevant to security operations, incident handling, data protection, and privacy-related risk.

ISO 22301

Business continuity principles supporting incident preparedness, operational continuity, recovery, and organizational resilience.

ISO 31000

Enterprise risk-management principles supporting structured risk identification, analysis, evaluation, treatment, monitoring, and communication.

ISO/IEC 42001

AI management-system principles relevant to the responsible governance and organizational management of artificial intelligence.

ISO/IEC 23894

AI risk-management principles relevant to identifying, evaluating, treating, and monitoring risks associated with artificial intelligence.

NIST Cybersecurity Framework (CSF)

Risk-based cybersecurity practices supporting the integrated functions of:

Govern • Identify • Protect • Detect • Respond • Recover

NIST NICE Workforce Framework for Cybersecurity

Cybersecurity workforce concepts supporting the relationship between professional roles, tasks, knowledge, and skills.

NIST AI Risk Management Framework (AI RMF)

Risk-management principles supporting trustworthy, responsible, secure, and risk-aware use of artificial intelligence.

Relevant NIST Cybersecurity and Incident-Response Guidance

Recognized practices involving security controls, monitoring, incident handling, digital investigation, vulnerability management, recovery, and cyber resilience.

CISA Cybersecurity Guidance

Relevant defensive practices involving cyber hygiene, vulnerability reduction, threat awareness, incident preparedness, critical infrastructure security, and organizational resilience.

Cyber Defense

Integrated Standards Perspective

The value of framework alignment is found in how recognized practices work together.

Security Management

ISO/IEC 27001 + ISO/IEC 27002

Support structured information-security management and security-control practices.

Risk Management

ISO/IEC 27005 + ISO 31000

Support risk-based analysis, prioritization, treatment, and decision-making.

Privacy

ISO/IEC 27701

Connects information security with privacy-management considerations.

Continuity and Resilience

ISO 22301

Supports organizational preparedness, continuity, recovery, and resilience.

AI Governance and Risk

ISO/IEC 42001 + ISO/IEC 23894 + NIST AI RMF

Provide relevant perspectives for understanding AI governance, AI-related risk, and responsible adoption of AI-enabled capabilities.

Cybersecurity Operations and Workforce

NIST CSF + NIST NICE Workforce Framework + Relevant NIST and CISA Guidance

Connect cyber-risk management with practical cybersecurity activities, workforce competencies, incident response, and defensive operations.

Cyber Defense

Vendor-Neutral Technology Philosophy

CCDP® is not tied to one:

  • Understand the Tool. Interpret Evidence. Apply Technology. Defend the Environment.

SIEM • SOAR • EDR/XDR • IDS/IPS • Firewall Vendor • Cloud Provider • Vulnerability Scanner • Threat-Intelligence Platform • Forensics Product • Incident Platform • AI Security Vendor

The certification focuses on the professional capabilities behind the technology.

Cyber Defense

Accreditation and Recognition Disclosure

References to ISO, ISO/IEC 17024, ANAB, NCCA, I.C.E., NIST, NICE, CISA, or other standards, frameworks, credentialing organizations, or professional bodies describe applicable areas of standards alignment, credentialing-quality consideration, workforce relevance, or professional-practice alignment.

Such references do not, by themselves, constitute or imply formal accreditation, endorsement, recognition, approval, authorization, partnership, or affiliation.

Formal accreditation or external recognition of IBACTP® or the CCDP® certification is represented only when it has been officially granted by the applicable authorized organization.

This distinction is particularly important because accreditation under ISO/IEC 17024 involves an independent accreditation process for personnel-certification bodies and schemes.

CCDP®

Flexible CCDP® Certification Assessment Pathways

The Certified Cyber Defense Professional (CCDP®) assessment is designed to evaluate more than cybersecurity knowledge. It measures a candidate’s ability to interpret security information, recognize threats, analyze incidents, exercise technical judgment, support effective response, and strengthen cyber resilience.

CCDP® provides two assessment pathways to accommodate both independent certification candidates and eligible participants completing approved instructor-led programs.

Both pathways are designed around the same core CCDP® competency expectations.

CCDP®

How the Eight Competencies Work Together

The strength of the CCDP® model is the integration of all eight dimensions.

A professional may begin with:

Security Monitoring

which identifies:

Suspicious Activity

that requires:

Threat and Adversary Analysis

and reveals:

A Vulnerability or Enterprise Exposure

which develops into:

An Incident

requiring:

Investigation and Digital Evidence

followed by:

Secure Recovery

and ultimately:

Improved Cyber Resilience

Throughout this lifecycle, AI and emerging technologies can introduce new risks while also strengthening defensive capabilities.

CCDP® Integrated Competency Progression

The eight dimensions support a unified professional progression:

Prepare → Monitor → Detect → Analyze → Prioritize → Investigate → Respond → Recover → Strengthen

The objective is to develop professionals who can connect technical evidence with effective defensive action.

The CCDP® Professional Standard

A CCDP® professional is prepared to:

Recognize Threats → Interpret Security Evidence → Identify Exposure → Prioritize Action → Investigate Incidents → Support Containment → Recover Securely → Strengthen Cyber Resilience

This integrated competency model represents the central professional promise of CCDP®:

CCDP®

See the Threat. Understand the Evidence. Take Defensive Action. Recover Securely. Become More Resilient.

.

CCDP®

CCDP® Cyber Defense Lifecycle

The CCDP® curriculum develops competency through an integrated defensive lifecycle:

Prepare → Monitor → Detect → Analyze → Contain → Investigate → Recover → Strengthen

Prepare

Understand assets, threats, attack surfaces, vulnerabilities, defensive architectures, and incident-readiness requirements.

Monitor

Maintain visibility across networks, endpoints, identities, cloud services, applications, and security technologies.

Detect

Identify anomalies, suspicious behavior, indicators of compromise, vulnerabilities, and potential attacks.

Analyze

Interpret security evidence and determine severity, scope, potential impact, and appropriate action.

Contain

Limit attacker access, reduce damage, isolate affected resources, and support coordinated response.

Investigate

Preserve evidence, establish timelines, identify attack activity, and support root-cause analysis.

Recover

Restore systems and services securely while validating the integrity of the environment.

Strengthen

Apply lessons learned, threat intelligence, vulnerability findings, and performance information to improve resilience.

CCDP®

Technologies You Will Understand

CCDP® is vendor-neutral while addressing major defensive technology categories, including:

SIEM • SOAR • EDR/XDR • IDS/IPS • Firewalls • Threat Intelligence Platforms • Vulnerability Scanners • Attack-Surface Management • Network Monitoring • Cloud Security • Digital Forensics • Incident Management • Backup & Recovery • AI-Assisted Security

The objective is not certification on a particular product.

The objective is to understand how technologies support detection, investigation, response, recovery, and resilience.

Here is a more comprehensive and professionally positioned version for the CCDP® webpage, with careful language that distinguishes framework alignment from accreditation or endorsement.

CCDP®

From Framework Knowledge to Cyber-Defense Action

CCDP® does not treat standards and frameworks as isolated memorization requirements.

Candidates develop the ability to connect recognized practices with real-world defensive responsibilities.

The CCDP® framework application progression is:

  • Understand → Apply → Detect → Respond → Recover → Improve

Understand

Recognize relevant cybersecurity, risk, continuity, incident-response, workforce, and AI-security principles.

Apply

Use appropriate controls, processes, and defensive practices within organizational environments.

Detect

Apply monitoring, intelligence, vulnerability, and detection principles to recognize threats and security events.

Respond

Use structured incident-response and investigation practices to contain threats and coordinate defensive action.

Recover

Apply continuity, restoration, and recovery principles to support the secure return of systems and critical services.

Improve

Use incidents, assessments, threat intelligence, lessons learned, metrics, and emerging practices to continuously strengthen cyber-defense capabilities.

CCDP®

Globally Relevant. Practically Applied.

By incorporating principles from internationally recognized standards and cybersecurity frameworks, CCDP® provides candidates with a broader professional perspective that can be applied across:

Private Enterprises • Government • Critical Infrastructure • Financial Services • Healthcare • Technology • Manufacturing • Education • Energy • Cloud Environments • Multinational Organizations

The goal is not to train candidates to become specialists in one individual standard.

The goal is to develop cyber-defense professionals who understand how recognized practices can support:

  • Better Detection • Better Decisions • Better Incident Response • Secure Recovery • Stronger Cyber Resilience
CCDP®

CCDP® Framework Application Philosophy

  • Learn the Principles → Understand the Risk → Apply the Practice → Defend the Environment → Recover Securely → Continuously Improve

Global. Vendor-Neutral. Transferable.

CCDP® is not tied to one:

Security Vendor • SIEM • Cloud Provider • EDR Platform • Firewall • Operating System • Vulnerability Scanner • Forensic Product • AI Security Platform

This allows CCDP® competencies to transfer across organizations, technologies, industries, and countries.

CCDP®

Certification Maintenance

The recommended CCDP® certification cycle is:

Three Years

Credential holders maintain professional competency through applicable IBACTP® continuing professional education, ethics, and recertification requirements.

CCDP®

Where Does CCDP® Lead?

CCDP® forms the professional level of the IBACTP® cyber-defense pathway.

CCDP®

Certified Cyber Defense Professional

Monitor • Detect • Analyze • Investigate • Respond • Recover

CCDM®

Certified Cyber Defense Manager

Assess • Strategize • Govern • Prioritize • Lead • Measure • Transform

Move from performing cyber defense to leading enterprise cyber defense.

Below is a more comprehensive, web-ready FAQ section that strengthens candidate information while keeping the answers readable and marketable.

CCDP®

CCDP® Professional Objective

  • APPLY FOR CCDP® → | REGISTER FOR THE EXAM → | ENROLL IN TRAINING → | EXPLORE THE CAPSTONE →
  • Detect Earlier
  • Analyze Accurately
  • Respond Effectively
  • Recover Securely
  • Strengthen Cyber Resilience

Ready to build your cyber-defense capabilities?

CCDP®

Build the Capability to Defend What Matters

Cyber defense requires more than tools.

It requires professionals capable of turning:

  • Security Data → Threat Detection → Analysis → Action → Recovery → Resilience
CCDP®
  • Detect
  • Analyze
  • Prioritize
  • Investigate
  • Contain
  • Recover
  • Improve

The ultimate testing objective is:

  • Recognize the Threat → Interpret the Evidence → Assess the Exposure → Prioritize the Response → Support Investigation → Contain the Incident → Recover Securely → Strengthen Cyber Resilience
CCDP®

Tools, Technology, and Cyber Defense Applications

The CCDP® certification is vendor-neutral, but candidates are expected to understand how major cyber-defense technologies support monitoring, detection, investigation, incident response, recovery, and resilience.

The program focuses on technology purpose, defensive use, interpretation of outputs, integration, limitations, and practical application rather than certification on any single commercial product.

1. Security Information and Event Management (SIEM)

CCDP® addresses SIEM technologies used to collect, normalize, correlate, and analyze security events across enterprise environments.

Key applications include:

Cyber Defense Application:

Use SIEM data to identify suspicious activity, correlate events, investigate incidents, and support escalation decisions.

  • Centralized log collection
  • Event correlation
  • Detection rules
  • Security dashboards
  • Alert generation
  • Investigation support
  • Threat hunting
  • Incident analysis

2. Security Orchestration, Automation, and Response (SOAR)

SOAR technologies help security teams coordinate and automate response activities.

Candidates develop an understanding of:

Cyber Defense Application:

Improve response speed and consistency while maintaining appropriate professional oversight and validation.

  • Automated workflows
  • Security playbooks
  • Alert enrichment
  • Incident case management
  • Automated containment
  • Escalation workflows
  • Tool integration
  • Response orchestration
  • Human approval requirements

3. Endpoint Detection and Response / Extended Detection and Response (EDR/XDR)

EDR and XDR technologies provide visibility into suspicious activity across endpoints and connected security environments.

Relevant capabilities include:

Cyber Defense Application:

Detect malicious endpoint behavior, investigate attacker activity, isolate compromised devices, and support incident response.

  • Endpoint telemetry
  • Process monitoring
  • File activity
  • Behavioral detection
  • Malware detection
  • Endpoint isolation
  • Threat containment
  • Investigation timelines
  • Cross-platform event correlation

4. Network Monitoring, IDS/IPS, and Traffic Analysis

Network-defense technologies provide visibility into communications between systems, users, applications, and external networks.

CCDP® addresses concepts involving:

Cyber Defense Application:

Use network activity to identify suspicious communications, attack patterns, compromised hosts, and unauthorized access.

  • Intrusion Detection Systems
  • Intrusion Prevention Systems
  • Packet and traffic analysis
  • Network flows
  • Protocol activity
  • DNS activity
  • Suspicious connections
  • Command-and-control traffic
  • Lateral movement
  • Data-exfiltration indicators

5. Firewalls, Segmentation, and Network Defense

Candidates examine the role of firewalls and related network controls in reducing attack surfaces and restricting unauthorized activity.

Relevant areas include:

Cyber Defense Application:

Use network controls to restrict attacker movement, reduce exposure, and support containment during incidents.

  • Traffic filtering
  • Security zones
  • Network segmentation
  • Ingress and egress controls
  • Access-control rules
  • Secure remote access
  • Network isolation
  • Firewall logging
  • Configuration risks
  • Zero Trust network concepts

6. Threat Intelligence Technologies

Threat-intelligence platforms and services help organizations collect, enrich, analyze, and operationalize threat information.

Candidates examine:

Cyber Defense Application:

Apply threat intelligence to monitoring, detection, vulnerability prioritization, threat hunting, and incident investigation.

  • Indicators of compromise
  • Threat actors
  • Tactics, techniques, and procedures
  • Threat feeds
  • Intelligence enrichment
  • Threat campaigns
  • Attack patterns
  • Intelligence correlation
  • Threat prioritization

7. Vulnerability Assessment and Exposure-Management Technologies

CCDP® addresses technologies used to identify and prioritize weaknesses across enterprise environments.

Relevant technology categories include:

Candidates learn to evaluate vulnerability findings using:

  • Vulnerability scanners
  • Asset discovery platforms
  • Configuration-assessment tools
  • Attack-surface management
  • Exposure-management platforms
  • Remediation tracking
  • Patch-management technologies

Severity + Exploitability + Threat Activity + Asset Criticality + Business Impact

Cyber Defense Application:

Prioritize the vulnerabilities and exposures that create the greatest practical risk.

8. Cloud Security and Cloud-Native Defense

Modern cyber-defense operations increasingly span hybrid and cloud-native environments.

CCDP® addresses:

Cyber Defense Application:

Monitor, detect, investigate, and respond to threats across cloud and hybrid environments.

  • Cloud logging
  • Cloud identity events
  • Cloud workload security
  • Cloud configuration monitoring
  • Storage security
  • API security
  • Container security
  • Cloud-native applications
  • Cloud incident investigation
  • Shared-responsibility considerations

9. Identity and Access Security Technologies

Identity is a major attack surface in modern environments.

CCDP® addresses technologies and practices involving:

Cyber Defense Application:

Identify suspicious identity activity, credential misuse, privilege abuse, and account compromise.

  • IAM
  • MFA
  • SSO
  • PAM
  • Identity governance
  • Federation
  • Authentication monitoring
  • Privileged activity
  • Access anomalies
  • Identity-based attack detection

10. Digital Forensics and Investigation Technologies

Digital-forensics technologies support evidence acquisition, analysis, preservation, and investigation.

Relevant applications include:

Cyber Defense Application:

Preserve and analyze evidence to understand attack activity, determine scope, support root-cause analysis, and document findings.

  • Endpoint evidence
  • Disk and file-system evidence
  • Memory evidence
  • Network evidence
  • Log evidence
  • Cloud evidence
  • Timeline reconstruction
  • Metadata analysis
  • Evidence integrity
  • Chain of custody

11. Incident and Case Management Platforms

Incident-management technologies support structured coordination of cyber incidents.

Capabilities may include:

Cyber Defense Application:

Coordinate incident-response activities in a consistent, documented, and accountable manner.

  • Case tracking
  • Incident classification
  • Task assignment
  • Evidence documentation
  • Escalation
  • Timeline management
  • Communication tracking
  • Workflow management
  • Lessons learned

12. Backup, Recovery, and Resilience Technologies

Because CCDP® places strong emphasis on recovery and resilience, candidates also examine technologies supporting:

Cyber Defense Application:

Restore systems and services securely after an incident while reducing the risk of reinfection or recurrence.

  • Backup
  • Restoration
  • Immutable backup concepts
  • Disaster recovery
  • Recovery validation
  • Business continuity
  • Resilience testing
  • Post-recovery monitoring
  • Critical-service restoration

13. AI-Assisted Cyber Defense

Artificial Intelligence is becoming increasingly integrated into modern security operations.

CCDP® addresses applications such as:

Candidates also evaluate limitations involving:

  • AI-assisted alert triage
  • Behavioral analytics
  • Threat detection
  • Threat-intelligence analysis
  • Threat hunting
  • Vulnerability prioritization
  • Malware-analysis support
  • Incident investigation
  • Security automation
  • Generative AI assistance
  • False positives
  • False negatives
  • Hallucinated analysis
  • Sensitive-data exposure
  • Adversarial manipulation
  • Explainability
  • Overreliance on automation
  • Human validation

CCDP® AI Defense Principle

Automate Where Appropriate → Validate the Output → Maintain Human Oversight → Document Critical Decisions

CCDP®

Representative Tools and Platforms

Approved training programs may use representative commercial or open-source tools for demonstrations and laboratories.

Examples may include technologies in categories such as:

Specific products may vary by training provider, lab environment, availability, and technology evolution.

CCDP® certification competency does not depend on mastery of a particular vendor product.

  • SIEM platforms
  • SOAR platforms
  • EDR/XDR solutions
  • IDS/IPS technologies
  • Network-analysis tools
  • Vulnerability scanners
  • Threat-intelligence platforms
  • Digital-forensics tools
  • Cloud-security platforms
  • Incident-management systems
  • Backup and recovery technologies
  • AI-assisted security tools
CCDP®

Cyber Defense Applications

The technologies covered within CCDP® support practical applications across the full defensive lifecycle.

Monitor enterprise environments, analyze alerts, investigate suspicious activity, and coordinate defensive actions.

Identify indicators, anomalies, behaviors, and attack patterns that may indicate compromise.

Proactively search for attacker activity that may not have generated conventional alerts.

Identify exploitable weaknesses and prioritize remediation according to organizational risk.

Support identification, triage, escalation, containment, eradication, investigation, and recovery.

Preserve and interpret evidence to determine attack scope, timeline, cause, and impact.

Monitor and investigate threats across cloud services, workloads, identities, APIs, and cloud-native technologies.

Detect suspicious authentication, privilege escalation, account misuse, and credential compromise.

Restore critical services securely and use incident experience to strengthen future defensive capability.

Use AI and automation to improve detection, analysis, prioritization, and response while maintaining responsible human oversight.

  • Security Operations Centers
  • Threat Detection
  • Threat Hunting
  • Vulnerability and Exposure Reduction
  • Incident Response
  • Digital Investigation
  • Cloud Defense
  • Identity Defense
  • Recovery and Resilience
  • AI-Enabled Security Operations
CCDP®

CCDP® Integrated Technology Model

CCDP® prepares professionals to understand how multiple technologies work together during a real cyber incident.

A typical defensive workflow may involve:

  • Threat Intelligence
  • SIEM Alert
  • EDR Telemetry
  • Network Evidence
  • Vulnerability Context
  • Incident Investigation
  • Containment
  • Forensics
  • Recovery
  • Resilience Improvement

The objective is to move beyond isolated tool usage and understand how defensive technologies combine to produce better visibility, stronger analysis, faster response, and more secure recovery.

CCDP®

Professional Credentialing Quality Alignment

The CCDP® credentialing framework is structured with consideration of recognized professional certification and personnel-credentialing practices associated with:

ISO/IEC 17024

International requirements for bodies operating certification of persons.

ANSI National Accreditation Board (ANAB)

Relevant personnel-certification accreditation principles and practices associated with competence-based certification.

National Commission for Certifying Agencies (NCCA)

Relevant certification-program quality principles involving governance, assessment, certification policies, examination practices, and continuing competence.

Institute for Credentialing Excellence (I.C.E.)

Professional credentialing practices supporting certification quality, governance, assessment, ethics, and continuous improvement.

International Personnel-Certification and Conformity-Assessment Practices

Broader internationally recognized principles supporting impartiality, consistency, competence assessment, transparency, security, and public confidence in professional credentials.

CCDP®

Cybersecurity Workforce Recognition and Relevance

CCDP® competencies are also structured with consideration of recognized cybersecurity workforce practices.

The NIST NICE Workforce Framework for Cybersecurity describes cybersecurity work through Tasks, Knowledge, and Skills and provides a common framework that can be used by learners, employers, educators, and certification providers.

CCDP® reflects this competency-oriented philosophy by connecting:

  • Professional Tasks
  • Required Knowledge
  • Applied Skills
  • Assessment
  • Demonstrated Competency

This approach supports the professional relevance of the CCDP® Body of Knowledge to cyber-defense, security operations, incident response, investigation, vulnerability management, and resilience responsibilities.

CCDP®

CCDP® Credentialing Quality Framework

The CCDP® certification framework encompasses:

  1. Job Task Analysis
  2. Defined Professional Competencies
  3. Validated Body of Knowledge
  4. Certification Examination Blueprint
  5. Subject Matter Expert Review
  6. Competency-Based Assessment
  7. Impartial Certification Decision
  8. Credential Award
  9. Continuing Professional Education
  10. Recertification
  11. Periodic Review and Continuous Improvement
CCDP®

CCDP® Credentialing Quality Lifecycle

The certification-quality lifecycle follows:

CCDP®
  • Define
  • Validate
  • Assess
  • Certify
  • Maintain
  • Verify
  • Review
  • Improve

Define

Establish the professional role, certification scope, eligibility requirements, and competencies.

Validate

Use professional and Subject Matter Expert input to validate job tasks, competencies, Body of Knowledge, and assessment requirements.

Assess

Evaluate candidates through structured, secure, competency-based certification assessment.

Certify

Award the credential based on documented certification requirements and assessment results.

Maintain

Require applicable continuing professional education, ethics, and recertification activities.

Verify

Provide mechanisms for authorized verification of credential status.

Review

Periodically evaluate professional practice, technologies, threats, workforce requirements, and assessment performance.

Improve

Update competencies, examinations, policies, security controls, and certification processes as professional requirements evolve.

CCDP®

Recognition Through Professional Relevance

CCDP® is designed to provide a credential that communicates competency across the complete cyber-defense lifecycle:

Monitoring + Detection + Threat Intelligence + Exposure Management + Incident Response + Digital Forensics + Recovery + Cyber Resilience + AI-Enabled Defense

Its professional relevance is strengthened through:

  • Vendor-neutral competency
  • Practical cyber-defense application
  • Scenario-based assessment
  • Defined professional outcomes
  • Structured Body of Knowledge
  • Continuing professional development
  • Emerging-technology coverage
  • International framework awareness
  • Cybersecurity workforce alignment
  • Transferable professional competency
CCDP®

The CCDP® Professional Promise

CCDP® brings learning, assessment, workforce competency, and credentialing quality together around one central objective:

Develop and Validate Professionals Who Can Defend Modern Organizations When Cyber Threats Become Real.

The complete CCDP® professional progression is:

CCDP®
  • Learn
  • Apply
  • Detect
  • Analyze
  • Investigate
  • Respond
  • Recover
  • Improve

And the professional outcome is:

CCDP®

Start Your CCDP® Certification Journey

APPLY FOR CERTIFICATION

Take the next step toward becoming a Certified Cyber Defense Professional.

APPLY NOW →

REGISTER FOR THE CCDP® EXAM

Already prepared to demonstrate your competency?

REGISTER FOR THE EXAM →

ENROLL IN CCDP® TRAINING

Develop practical competency across the complete cyber-defense lifecycle.

ENROLL NOW →

CHOOSE THE APPLIED CAPSTONE PATHWAY

Eligible instructor-led candidates can demonstrate competency through a structured applied cyber-defense project.

EXPLORE THE CAPSTONE →

DOWNLOAD THE CCDP® CERTIFICATION GUIDE

Review the Body of Knowledge, eligibility, examination structure, competencies, assessment pathways, and certification requirements.

DOWNLOAD PROGRAM GUIDE →

CCDP®

Who Should Earn CCDP®?

CCDP® is designed for professionals working in or moving toward roles such as:

It is also suitable for IT professionals seeking to transition into cyber defense and security operations.

  • Cyber Defense Analyst
  • SOC Analyst
  • Security Operations Analyst
  • Cybersecurity Analyst
  • Incident Response Analyst
  • Cyber Incident Responder
  • Threat Intelligence Analyst
  • Threat Hunter
  • Vulnerability Analyst
  • Exposure Management Analyst
  • Security Engineer
  • Network Security Analyst
  • Cloud Security Analyst
  • Digital Forensics Analyst
  • Cyber Resilience Analyst
  • Security Operations Specialist
  • Cybersecurity Consultant
Curriculum

CCDP® Body of Knowledge

The certification curriculum is organized into eight major modules:

Module 1 — Cyber Defense Foundations & Defensive Architecture

Module 2 — Security Monitoring, Detection & SOC Operations

Module 3 — Threat Intelligence, Hunting & Adversary Analysis

Module 4 — Vulnerability, Exposure & Attack-Surface Defense

Module 5 — Incident Detection, Triage & Response

Module 6 — Digital Forensics, Investigation & Evidence

Module 7 — Recovery, Continuity & Cyber Resilience

Module 8 — AI-Enabled Defense & Emerging Cyber Threats

Learning outcomes

CCDP® Course Learning Outcomes

Upon successful completion, participants will be able to:

1. Apply Cyber Defense Principles and Architectures

Evaluate attack surfaces, defensive controls, Zero Trust concepts, adversary behavior, defense-in-depth, and resilient architectures.

2. Perform Security Monitoring and Threat Detection

Interpret network, endpoint, identity, cloud, application, and security-platform telemetry.

3. Apply Threat Intelligence and Threat Hunting

Use threat intelligence, indicators, adversary behaviors, attack techniques, and analytical hypotheses to support proactive defense.

4. Assess Vulnerabilities and Enterprise Exposure

Interpret vulnerability findings, assess exploitability and impact, prioritize remediation, and support exposure reduction.

5. Conduct Incident Triage and Response

Classify incidents, determine severity, investigate activity, recommend containment and eradication actions, and coordinate recovery.

6. Support Digital Forensics and Cyber Investigations

Preserve evidence, maintain chain of custody, analyze relevant artifacts, reconstruct timelines, and document findings.

7. Support Secure Recovery and Cyber Resilience

Apply recovery, continuity, restoration, lessons-learned, and resilience-improvement practices.

8. Evaluate AI-Enabled and Emerging Cyber Defense

Assess AI-assisted attacks, defensive automation, cloud-native environments, IoT, OT, and emerging threats.

What is assessed

Skills & Competencies Tested

The CCDP® certification assessment evaluates whether candidates can apply cyber-defense knowledge to realistic situations.

Candidates are tested on their ability to:

CCDP®

The CCDP®–IBACTP® Cyber Defense Competency Model

CCDP® is organized around eight integrated competency dimensions.

  • CCDP® Defense Progression

01 — Cyber Defense Foundations & Defensive Architecture

Understand threats, attack surfaces, adversary behavior, Zero Trust, defense-in-depth, defensive controls, and resilient security architecture.

02 — Security Monitoring, Detection & SOC Operations

Interpret security telemetry, logs, alerts, events, anomalies, and indicators across enterprise environments.

03 — Threat Intelligence, Hunting & Adversary Analysis

Apply threat intelligence, indicators, adversary techniques, behavioral analysis, and hunting hypotheses.

04 — Vulnerability, Exposure & Attack-Surface Defense

Identify vulnerabilities, evaluate exploitability, prioritize remediation, and reduce enterprise exposure.

05 — Incident Detection, Triage & Response

Recognize incidents, establish severity, investigate activity, contain threats, support eradication, and coordinate response.

06 — Digital Forensics, Investigation & Evidence

Preserve evidence, maintain integrity, correlate artifacts, reconstruct timelines, and support cyber investigations.

07 — Recovery, Continuity & Cyber Resilience

Restore affected environments, validate recovery, support continuity, capture lessons learned, and strengthen resilience.

08 — AI-Enabled Defense & Emerging Cyber Threats

Evaluate AI-assisted attacks and defense, automation, cloud-native threats, IoT, OT, APIs, containers, software supply chains, and emerging attack techniques.

What it validates

What Is CCDP®?

The Certified Cyber Defense Professional (CCDP®) is a comprehensive, vendor-neutral professional certification designed to validate practical competency in protecting organizations through effective security monitoring, threat detection, analysis, investigation, incident response, recovery, and cyber resilience.

CCDP® prepares professionals to understand how multiple defensive capabilities work together across modern enterprise technology environments.

The certification bridges the gap between knowing cybersecurity concepts and applying cyber-defense judgment in realistic operational situations.

Its central professional progression is:

What it validates

What Does CCDP® Cover?

CCDP® provides an integrated Body of Knowledge spanning the principal capabilities required for modern cyber defense.

  • Security Data → Alert → Analysis → Determination → Action
  • Who or What Is the Threat? → What Are They Doing? → Are We Exposed? → What Should We Investigate?
  • Vulnerability + Exploitability + Threat Activity + Asset Criticality + Business Impact = Remediation Priority
  • Detect → Validate → Classify → Escalate → Contain → Eradicate → Recover

1. Cyber Defense Architecture & Security Foundations

Develop an understanding of how enterprise security controls work together to reduce exposure and improve defensive capability.

Coverage includes:

Cyber-Defense Architecture • Attack Surfaces • Threat Actors • Attack Techniques • Defense-in-Depth • Zero Trust • Network Security • Endpoint Security • Identity Security • Cloud Security • Resilient Architecture

The emphasis is on understanding how architecture affects an organization’s ability to prevent, detect, contain, and recover from cyber threats.

2. Security Monitoring & SOC Operations

Understand how Security Operations Centers and cyber-defense teams maintain visibility across enterprise environments.

Coverage includes:

SOC Operations • SIEM • Security Analytics • EDR/XDR • Network Monitoring • Log Analysis • Security Telemetry • Alert Triage • Event Correlation • Escalation

Candidates develop the ability to move from:

3. Threat Detection & Analysis

Develop competency in identifying suspicious and malicious activity across multiple security environments.

Coverage includes:

Detection Concepts • Indicators of Compromise • Behavioral Indicators • Anomaly Analysis • Detection Logic • Endpoint Activity • Network Activity • Identity Activity • Cloud Events • Attack Patterns

CCDP® emphasizes the professional judgment required to distinguish normal activity, suspicious activity, and probable malicious behavior.

4. Threat Intelligence & Threat Hunting

Understand how threat information can strengthen both reactive and proactive defense.

Coverage includes:

Threat Intelligence • Adversary Behavior • Indicators • Tactics and Techniques • Threat Profiling • Intelligence Sources • Threat Hunting • Hunting Hypotheses • Evidence Correlation • Intelligence-Driven Defense

Candidates learn to connect intelligence with operational security evidence to determine:

5. Vulnerability, Exposure & Attack-Surface Management

Move beyond simply identifying vulnerabilities to understanding which exposures require priority action.

Coverage includes:

Vulnerability Assessment • Asset Discovery • Exploitability • Asset Criticality • Attack Surfaces • Exposure Management • Configuration Weaknesses • Remediation Prioritization • Threat-Informed Vulnerability Management

CCDP® develops the ability to evaluate:

6. Incident Detection, Triage & Response

Incident response is a defining competency within CCDP®.

Coverage includes:

Incident Identification • Alert Triage • Severity Classification • Escalation • Investigation • Containment • Eradication • Communication • Documentation • Recovery Coordination

Candidates learn to evaluate realistic incidents and determine the appropriate response based on available evidence, severity, operational impact, and risk.

The progression is:

7. Digital Forensics & Evidence Handling

Cyber-defense professionals must understand how digital evidence supports incident investigation and defensible conclusions.

Coverage includes:

Evidence Identification • Evidence Preservation • Chain of Custody • Endpoint Evidence • Logs • Network Evidence • Cloud Evidence • Timeline Reconstruction • Artifact Correlation • Root-Cause Analysis

CCDP® is not intended to replace a specialized digital-forensics certification. Instead, it ensures that cyber-defense professionals understand how forensic evidence supports effective incident response.

8. Recovery, Continuity & Cyber Resilience

Cyber defense does not end when an attacker is contained.

Organizations must restore operations securely and determine whether the environment is safe to return to normal operation.

Coverage includes:

Recovery Planning • Restoration Priorities • Backup & Recovery • Recovery Validation • Business Continuity • Disaster Recovery • Critical Services • Lessons Learned • Control Improvement • Cyber Resilience

Candidates learn to consider questions such as:

The objective is not simply:

“Restore the system.”

It is:

  • Has the threat actually been removed?
  • Are credentials secure?
  • Have persistence mechanisms been eliminated?
  • Are restored systems trustworthy?
  • Which services should be restored first?
  • What monitoring should continue after recovery?
  • What controls should be improved?
  • What lessons should influence future readiness?
Cyber Defense

Standards & Framework Alignment

The CCDP® Body of Knowledge incorporates relevant principles from recognized frameworks including NIST CSF, the NICE Framework, ISO information-security and risk-management standards, AI risk-management concepts, incident-response practices, and CISA cybersecurity guidance.

NIST’s current CSF 2.0 explicitly organizes cybersecurity outcomes around Govern, Identify, Protect, Detect, Respond, and Recover, while NICE provides a common language for cybersecurity work and competency development. (NIST)

Framework Application Progression

CCDP®

Why CCDP®?

Cyber Defense Is No Longer a Single-Tool Responsibility

Modern cyber defense is no longer about monitoring one dashboard, managing one security platform, or responding to isolated technical events. Today’s attacks move rapidly across endpoints, identities, networks, cloud platforms, applications, data, and third-party environments, requiring cyber-defense professionals to understand how these components interact throughout an incident.

A security alert may begin as unusual endpoint activity. Further analysis may reveal compromised credentials, unauthorized identity activity, lateral movement, cloud-resource access, exploitation of a known vulnerability, or attempted data exfiltration.

What initially appears to be a single alert can quickly become an enterprise-wide incident requiring coordinated detection, investigation, containment, eradication, recovery, and resilience activities.

For example:

Endpoint Alert → Compromised Identity → Lateral Movement → Cloud Access → Sensitive Data Exposure → Incident Response → Recovery

Investigating such an event may require professionals to correlate information from:

The challenge is therefore no longer simply knowing how to use a cybersecurity tool.

The challenge is knowing what the information means, how different evidence relates, which threats matter most, what action should occur next, and how the organization can recover securely.

  • SIEM platforms and security analytics
  • EDR/XDR technologies
  • Network monitoring and IDS/IPS
  • Identity and authentication systems
  • Threat-intelligence sources
  • Vulnerability and exposure-management platforms
  • Cloud logs and cloud-security technologies
  • Application and API telemetry
  • Digital-forensics evidence
  • Incident-management platforms

From Security Alerts to Defensive Decisions

Cyber-defense professionals must be capable of moving beyond alert recognition to informed defensive action.

They must be prepared to answer questions such as:

These are the practical questions at the center of CCDP®.

  • Is this activity actually malicious?
  • What does the available security evidence indicate?
  • Which systems, accounts, applications, or data may be affected?
  • Is the threat still active?
  • Which vulnerability or exposure enabled the activity?
  • Is there evidence of lateral movement?
  • What does threat intelligence reveal about the adversary?
  • Should the event be escalated?
  • How severe is the incident?
  • What should be contained first?
  • What evidence must be preserved?
  • Has malicious activity been fully eradicated?
  • Can affected systems be restored safely?
  • What controls failed?
  • What should be changed to prevent recurrence?
  • How can the organization become more resilient?

The Complete Cyber-Defense Lifecycle

CCDP® develops integrated competency across the defensive lifecycle:

Prepare → Monitor → Detect → Analyze → Prioritize → Contain → Investigate → Recover → Improve

Rather than treating security monitoring, vulnerability management, threat intelligence, incident response, digital forensics, and recovery as separate disciplines, CCDP® connects them into a unified professional framework.

The result is a cyber-defense professional who understands not only how threats are detected, but also how they are investigated, contained, eradicated, recovered from, and converted into opportunities to strengthen organizational resilience.

CCDP®

CCDP® Is Designed for the Reality of Modern Cyber Defense

Multiple Threats. Multiple Technologies. Multiple Evidence Sources. One Integrated Defensive Lifecycle.

CCDP®
  • Monitor
  • Detect
  • Analyze
  • Investigate
  • Respond
  • Recover
  • Strengthen

CCDP® professionals learn to interpret security information, connect evidence across technologies, assess vulnerabilities and exposures, investigate suspicious activity, support incident containment and eradication, preserve relevant evidence, contribute to secure recovery, and apply lessons learned to strengthen future defensive capability.

CCDP®

“Restore Securely—and Return Stronger.”

9. Cloud & Modern Enterprise Defense

Modern cyber-defense professionals must operate in environments where evidence and security controls extend beyond traditional networks.

Coverage includes:

Cloud Security • Cloud Logging • Identity-Centric Security • SaaS Environments • APIs • Containers • Cloud Workloads • Hybrid Environments • Remote Access • Modern Attack Surfaces

The emphasis is on applying transferable cyber-defense principles across changing technology environments.

10. AI-Enabled Cyber Defense & Emerging Threats

Artificial intelligence is changing both offensive and defensive cybersecurity.

CCDP® introduces professionals to:

AI-Assisted Detection • Automated Triage • Threat Analysis • Security Automation • AI-Assisted Investigation • AI-Enabled Attacks • Adversarial AI Risks • Cloud-Native Threats • IoT • OT • Software Supply Chains

Candidates are expected to understand both the opportunities and limitations of AI-assisted defense, including the need for validation, human judgment, security, and responsible use.

CCDP®

One Integrated Cyber-Defense Framework

CCDP® connects these capabilities rather than teaching them as isolated subjects.

Architecture

Build and understand defensive foundations.

Visibility

Monitor endpoints, networks, identities, applications, and cloud environments.

Detection

Recognize suspicious and malicious activity.

Intelligence

Understand adversaries, indicators, behaviors, and emerging threats.

Exposure

Determine where the organization is vulnerable.

Response

Prioritize, contain, eradicate, and coordinate.

Investigation

Preserve evidence, correlate activity, and reconstruct events.

Recovery

Restore systems and operations securely.

Resilience

Apply lessons learned and strengthen future readiness.

CCDP®

The CCDP® Cyber Defense Lifecycle

  • Prepare → Monitor → Detect → Analyze → Prioritize → Contain → Investigate → Recover → Learn → Strengthen
CCDP®

CCDP® Is About Competency, Not Memorization

The certification does not simply ask:

“Do you understand cybersecurity?”

CCDP® asks whether you can apply that understanding when it matters:

Can you recognize a threat, interpret the evidence, determine its significance, prioritize the response, contain the incident, support the investigation, recover securely, and help prevent recurrence?

That distinction defines the CCDP® professional.

CCDP®

What Makes CCDP® Different?

One Certification. The Complete Defensive Lifecycle.

Many cybersecurity programs focus heavily on individual technologies or narrow technical disciplines.

CCDP® integrates the capabilities required to understand how an organization moves from exposure to detection, from detection to response, and from response to recovery.

EXPOSURE

Understand vulnerabilities, assets, attack surfaces, exploitability, and organizational risk.

DETECTION

Interpret telemetry, logs, alerts, anomalies, identities, endpoints, networks, applications, and cloud activity.

ANALYSIS

Determine what happened, how it happened, what is affected, and what evidence supports the conclusion.

RESPONSE

Triage incidents, determine severity, escalate appropriately, contain threats, and support eradication.

INVESTIGATION

Preserve evidence, reconstruct events, correlate artifacts, and support root-cause analysis.

RECOVERY

Restore affected systems securely and validate that threats have been removed.

RESILIENCE

Apply lessons learned to strengthen future defensive capability.

CCDP®

Tools, Technologies & Applications

CCDP® remains vendor-neutral while introducing candidates to the categories of technologies commonly used in cyber defense.

Security Operations

SIEM • SOAR • EDR/XDR • Security Analytics • Threat Intelligence • Monitoring Platforms

Network & Infrastructure

Firewalls • IDS/IPS • Network Detection • Packet Analysis • Segmentation • Zero Trust Technologies

Vulnerability & Exposure

Vulnerability Scanners • Asset Discovery • Attack-Surface Management • Exposure Platforms • Configuration Assessment

Investigation

Digital Forensics • Log Analysis • Network Analysis • Endpoint Evidence • Timeline Analysis

Cloud & Application Defense

Cloud Security • CSPM Concepts • API Security • Container Security • DevSecOps • Application Security

Incident & Resilience

Incident Management • Backup & Recovery • Continuity Technologies • Crisis Coordination

AI-Assisted Security

Automated Triage • Detection Analytics • Threat Enrichment • Security Automation • AI-Assisted Investigation

The objective is:

CCDP®

Flexible CCDP® Certification Assessment

Option 1 — CCDP® Certification Examination

100 Questions

90 Minutes

Multiple-Choice + Scenario-Based Questions

Closed Book

Secure Online Proctoring or Approved Testing Center

Recommended Passing Score: 70%

Assessment emphasis:

Knowledge • Detection • Analysis • Threat Recognition • Incident Judgment • Investigation • Recovery • Resilience

Option 2 — Applied Cyber Defense Capstone

Eligible candidates participating in an approved instructor-led pathway may demonstrate professional competency through the CCDP® Applied Cyber Defense Capstone.

The Capstone integrates:

CCDP®
  • Understand
  • Apply
  • Detect
  • Respond
  • Recover
  • Improve

Framework alignment does not constitute accreditation, recognition, endorsement, or approval by referenced organizations.

CCDP®

Why Employers Need CCDP® Professionals

Organizations need professionals capable of connecting:

Threat Intelligence + Security Telemetry + Vulnerabilities + Incidents + Evidence + Recovery

The NICE ecosystem explicitly identifies defensive cybersecurity, digital forensics, and incident response as Protection and Defense work roles, reinforcing the importance of integrated defensive competencies.

CCDP® develops professionals who can contribute across that integrated environment.

CCDP®

Your Cyber Defense Career Progression

CCDP®

CCDP®

Certified Cyber Defense Professional

Monitor • Detect • Analyze • Investigate • Respond • Recover

The examination

Exam & Certification Details

Everything you need to plan your sitting.

CCDP-100

Exam code for the Professional-level Cyber Defense credential.

100 questions (maximum)

Multiple choice, completed in 120 minutes.

700 out of 1000

Passing score. Delivered in English.

Recommended experience

A minimum of two years of experience in cyber defense or a closely related technology discipline.

Where you sit it

IBACTP® approved testing centers and online proctored delivery

Staying certified

Three-year certification cycle with continuing professional education

Choose your route

Four ways to enroll. One credential.

Every route leads to the same CCDP® examination and the same designation.

Option 1

Self-Paced Learning

Self-study
$400 USD
  • Exam fee only
  • Complimentary course materials provided
Option 2

Virtual Instructor-Led Training

4 days
$1,200 USD
  • 4 days, 2 hours daily online
  • Includes all course materials + Exam
Select a Date and Purchase
Option 3

Bootcamps & Intensives

10 days
$1,800 USD
  • 10 days, 2 hours daily
  • Includes all course materials + Exam
Select a Date and Purchase
Option 4

Corporate Training

Your schedule
Fees negotiable
  • Certify a whole team on a schedule that suits your organization
  • Fees depend on the team's size / number
Request a Team Quote
Questions

Frequently Asked Questions — CCDP®

Find answers to common questions about the Certified Cyber Defense Professional (CCDP®) certification, training, assessment, competency areas, and professional pathway.

What is the CCDP® certification?

The Certified Cyber Defense Professional (CCDP®) is a professional-level, vendor-neutral certification designed to validate practical competency across the modern cyber-defense lifecycle.

CCDP® covers security monitoring, threat detection, SOC operations, threat intelligence, threat hunting, vulnerability and exposure management, incident response, digital forensics, secure recovery, cyber resilience, and AI-enabled defense.

The certification emphasizes practical application and professional judgment—not simply memorization of cybersecurity terminology.

Who is CCDP® designed for?

CCDP® is designed for professionals working in, entering, or advancing within cyber-defense and security-operations roles.

Relevant professionals may include:

It can also benefit IT professionals seeking to transition into operational cybersecurity and cyber-defense responsibilities.

  • Cyber Defense Analysts
  • SOC Analysts
  • Cybersecurity Analysts
  • Security Operations Analysts
  • Incident Response Analysts
  • Threat Analysts
  • Threat Hunters
  • Vulnerability Analysts
  • Digital Forensics Analysts
  • Security Engineers
  • Network Defense Professionals
  • Cloud Security Professionals
  • Cybersecurity Specialists
Is CCDP® vendor-neutral?

CCDP® focuses on transferable cyber-defense competencies rather than expertise with one particular product, platform, cloud provider, or security vendor.

Candidates develop an understanding of technology categories such as SIEM, SOAR, EDR/XDR, IDS/IPS, threat-intelligence platforms, vulnerability scanners, cloud-security technologies, forensic tools, and incident-management platforms without making certification dependent on a particular commercial product.

Yes.

Do I need advanced cybersecurity experience before beginning CCDP® training?

No. Advanced cybersecurity experience is not required to begin CCDP® training.

Candidates benefit from foundational familiarity with:

Previous technical-support, networking, systems-administration, cybersecurity, or IT experience can be beneficial.

  • Computer systems
  • Windows or Linux
  • Networking and TCP/IP
  • IP addresses, ports, and protocols
  • User accounts and permissions
  • Basic cybersecurity concepts
  • Cloud-computing concepts
What makes CCDP® different from a general cybersecurity certification?

CCDP® concentrates specifically on the defensive side of cybersecurity and places significant emphasis on incident response, recovery, and resilience.

Its competency progression connects:

Monitor → Detect → Analyze → Investigate → Respond → Recover → Strengthen

Rather than covering cybersecurity only as a broad collection of topics, CCDP® focuses on how professionals use security information and defensive capabilities to recognize attacks, investigate incidents, support response, restore operations, and improve future resilience.

Does CCDP® cover Security Operations Center (SOC) activities?

Candidates develop competency involving:

The emphasis is on understanding how SOC information is transformed into detection, analysis, investigation, and defensive action.

  • Yes.
  • Security operations are a core component of CCDP®.
  • Security monitoring
  • SIEM concepts
  • Logs and event analysis
  • Endpoint telemetry
  • Network-security monitoring
  • Alert triage
  • Event correlation
  • Detection
  • Escalation
  • Threat intelligence
  • Indicators of compromise
  • Security analytics
Does CCDP® cover threat intelligence?

Candidates learn how threat intelligence supports defensive decision-making, including understanding threat actors, indicators of compromise, adversary behaviors, attack techniques, intelligence sources, and emerging threats.

The objective is to use intelligence to help answer:

Yes.

Does CCDP® cover threat hunting?

CCDP® introduces threat-hunting concepts that help professionals proactively search for malicious activity that may not have triggered traditional security alerts.

Candidates examine:

Threat hunting reinforces the transition from purely reactive security monitoring to proactive cyber defense.

Yes.

  • Hunting hypotheses
  • Threat indicators
  • Adversary behaviors
  • Attack techniques
  • Security telemetry
  • Intelligence-driven investigation
  • Anomaly analysis
Does CCDP® cover vulnerability and exposure management?

CCDP® addresses vulnerability identification, exploitability, attack surfaces, asset criticality, threat context, exposure management, and remediation prioritization.

Candidates learn that technical severity alone does not always determine remediation priority.

CCDP® encourages a broader perspective:

Yes.

Vulnerability + Exploitability + Threat Activity + Exposure + Asset Criticality + Business Impact

This helps professionals identify which weaknesses require the greatest defensive attention.

Does CCDP® cover incident response?

Yes. Incident response is one of the defining competency areas of CCDP®.

Candidates examine the complete incident lifecycle, including:

Candidates develop the professional judgment required to move from:

  • Detection
  • Validation
  • Triage
  • Classification
  • Severity assessment
  • Escalation
  • Investigation
  • Containment
  • Eradication
  • Documentation
  • Recovery
  • Lessons learned
Does CCDP® include digital forensics?

CCDP® introduces digital-forensics and investigation principles relevant to cyber-defense professionals.

Topics include:

The goal is to prepare professionals to preserve and interpret evidence while supporting defensible cyber investigations.

Yes.

  • Forensic readiness
  • Evidence identification
  • Evidence preservation
  • Chain of custody
  • Endpoint artifacts
  • Network evidence
  • Log evidence
  • Cloud evidence
  • Timeline reconstruction
  • Investigation documentation
  • Root-cause analysis
Does CCDP® cover business continuity and disaster recovery?

CCDP® recognizes that cyber defense does not end when an attacker is contained.

Candidates examine how cybersecurity incidents interact with business continuity, disaster recovery, restoration priorities, critical services, backup strategies, and recovery validation.

The objective is to help ensure that affected systems and services are not only restored quickly, but restored securely and reliably.

Yes.

Why does CCDP® emphasize cyber resilience?

Because preventing every cybersecurity incident is not realistic.

Organizations must also develop the capability to withstand attacks, limit disruption, respond effectively, recover critical operations, learn from incidents, and adapt their defenses.

CCDP® therefore connects incident response with:

Recovery → Validation → Lessons Learned → Corrective Action → Stronger Resilience

Cyber resilience is a defining element of the CCDP® professional competency model.

Does CCDP® cover cloud cyber defense?

CCDP® addresses security monitoring, detection, exposure, incident response, evidence, and defensive considerations relevant to modern cloud and cloud-native environments.

The certification remains vendor-neutral and does not require candidates to specialize in one particular cloud provider.

Yes.

Does CCDP® cover artificial intelligence?

Candidates explore areas including:

The central perspective is:

  • Yes.
  • CCDP® examines AI from both defensive and risk perspectives.
  • AI-assisted security monitoring
  • AI-enabled threat detection
  • AI-supported threat intelligence
  • Security automation
  • AI-assisted incident response
  • Generative AI risks
  • AI-enabled cyberattacks
  • Adversarial AI considerations
  • Human oversight
  • Emerging AI security risks
What emerging technologies are addressed?

CCDP® considers evolving defensive challenges involving areas such as:

Artificial Intelligence • Generative AI • Cloud-Native Systems • APIs • Containers • IoT • Operational Technology • Automation • Software Supply Chains • Emerging Attack Techniques

The goal is to prepare professionals for cyber-defense environments that continue to change as technology evolves.

What standards and frameworks are incorporated into CCDP®?

The CCDP® Body of Knowledge incorporates relevant principles and practices associated with recognized cybersecurity, risk, continuity, workforce, and AI frameworks, including areas represented by:

CCDP® emphasizes practical professional application rather than memorization of standards.

  • ISO/IEC 27001
  • ISO/IEC 27002
  • ISO/IEC 27005
  • ISO/IEC 27701
  • ISO 22301
  • ISO 31000
  • ISO/IEC 42001
  • ISO/IEC 23894
  • NIST Cybersecurity Framework
  • NIST NICE Workforce Framework
  • NIST AI Risk Management Framework
  • Relevant NIST cybersecurity and incident-response guidance
  • Relevant CISA cybersecurity guidance
How is the CCDP® certification assessed?

CCDP® provides two certification assessment pathways.

Option 1 — CCDP® Certification Examination

The recommended examination structure includes:

100 Questions • 90 Minutes • Multiple-Choice and Scenario-Based Questions • Closed Book • Secure Proctoring • Recommended Passing Score: 70%

The assessment evaluates knowledge, application, detection, analysis, threat recognition, investigation, incident judgment, recovery, and resilience.

Option 2 — CCDP® Applied Cyber Defense Capstone

Eligible candidates participating in an approved instructor-led pathway may demonstrate competency through the Applied Cyber Defense Capstone.

The Capstone integrates:

Are CCDP® examination questions scenario-based?

The assessment includes scenario-based questions designed to evaluate whether candidates can apply cyber-defense knowledge to realistic situations.

Candidates may be asked to interpret alerts, analyze security information, prioritize vulnerabilities, evaluate evidence, determine incident severity, select containment actions, or recommend recovery measures.

The emphasis moves beyond:

toward:

  • Yes.
  • “What do you know?”
What competencies does a successful CCDP® candidate demonstrate?

Successful candidates demonstrate the ability to integrate technical knowledge, analytical reasoning, incident judgment, and resilience principles.

The CCDP® competency standard can be summarized as:

How long is the CCDP® certification valid?

Credential holders maintain continuing professional competency through applicable IBACTP® continuing professional education, professional ethics, and recertification requirements.

Candidates and credential holders should consult current IBACTP® certification policies for applicable maintenance requirements.

The recommended CCDP® certification cycle is three years.

What comes after CCDP®?

CCDP® forms the professional level of the IBACTP® cyber-defense certification pathway.

The advanced progression is:

CCDP® — Certified Cyber Defense Professional
  • Monitor • Detect • Analyze • Investigate • Respond • Recover
CCDM® — Certified Cyber Defense Manager

Assess • Strategize • Govern • Prioritize • Lead • Measure • Transform

CCDP® focuses primarily on performing and supporting cyber defense.

CCDM® advances the professional into governing enterprise cyber-defense capabilities, leading major incidents and cyber crises, directing recovery, measuring resilience, prioritizing investments, and communicating with executives and boards.

CCDP®

Become a Certified Cyber Defense Professional

Ready to Defend What Matters?

Build the skills to detect earlier, respond faster, investigate accurately, and recover securely.

[BECOME CCDP® CERTIFIED]

Certified Cyber Defense Professional (CCDP®) · International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)

28+ Certifications
14 Technology Disciplines
Global Recognition
Industry Validated
Your Career Our Mission