Here's a roadmap based on the current exam (SCS-C03), which replaced SCS-C02 in December 2025.

Exam at a Glance

The 6 Domains (in priority order)

#DomainWeightYour Likely Gap
4Identity & Access Management20%Medium — SAA covered IAM basics; here you need deep policy evaluation logic, permission boundaries, ABAC/RBAC design, IAM Identity Center, cross-account patterns
3Infrastructure Security18%Medium-Low — VPC, security groups, NACLs from SAA; now add WAF, Shield, Network Firewall, edge security, container/host hardening
5Data Protection18%High — KMS key policies, CloudHSM, envelope encryption, Secrets Manager, S3 Object Lock, cross-region key management, data masking
1Detection16%High — GuardDuty, Security Hub, Security Lake, Config conformance packs, CloudWatch Logs Insights, log correlation with Athena/OpenSearch
2Incident Response14%High — Forensics (Automated Forensics Orchestrator for EC2), runbooks, containment strategies, root cause analysis with Detective
6Security Foundations & Governance14%Medium — AWS Organizations SCPs/RCPs, Control Tower, CloudFormation Guard, AWS Config rules, Audit Manager, Artifact

Three-Phase Plan

Phase 1: Foundation Refresh (2–3 weeks)

Goal: Rebuild core AWS fluency and fill security-specific fundamentals.

Phase 2: Domain-by-Domain Deep Dive (6–8 weeks)

Goal: Master each domain, roughly in weight order (IAM first, then Infrastructure, Data Protection, Detection, IR, Governance). Spend more time where your background is weakest.

For every service that appears in the in-scope list [1], you should know:

Phase 3: Practice & Assess (3–4 weeks)

Key New Topics in SCS-C03 (not in the old SCS-C02)

These are likely to be emphasized, so pay extra attention:

Recommended Core Resources

ResourcePurpose
AWS Skill Builder — Security Specialty learning pathOfficial digital courses + labs
Exam Guide (SCS-C03)Your permanent reference — map every task statement to a hands-on exercise
Tutorials Dojo practice examsWidely praised for realistic questions and excellent explanations
AWS re:Inforce talks (YouTube)Deep dives on security services from AWS experts
AWS Security BlogReal-world patterns and new feature announcements
Hands-on labs (AWS Builder Labs / personal sandbox)Nothing replaces building: set up an Organization, deploy SCPs, configure GuardDuty, encrypt an RDS with KMS, write a WAF rule, etc.

Suggested Timeline