What is the CrowdStrike certification path?
The CrowdStrike certification path is the Falcon Certification Program (CFCP): eight job-role credentials, each earned by passing a single timed exam. There are no prerequisite chains between them - you pick the credential that matches your role and sit that exam. CrowdStrike recommends hands-on Falcon experience for every one of them: three to six months for the entry-level CCFP, and at least six months in a production environment for the rest.
The shared rules are simple. Every exam is 60 questions in 90 minutes and costs $250 USD. Every certification lasts three years, and recertification means passing the most current version of the exam. CrowdStrike publishes no numeric passing score for any exam - the guides say only that you must 'achieve a passing score.'
This page maps all eight credentials by role so you can pick the right one first, instead of paying $250 to learn the difference the hard way.
Where do you start? The CCFP entry point
The CrowdStrike Certified Falcon Practitioner (CCFP) is the program's entry credential, directed at entry-level SOC analysts and cybersecurity professionals who are new to the Falcon platform. Its exam guide validates foundational knowledge across four domains: cybersecurity fundamentals, Falcon platform overview, core operational workflows, and AI and automation in Falcon - including Charlotte AI.
CCFP asks for the least experience of the eight: CrowdStrike suggests three to six months working in the Falcon platform. If your organization just deployed Falcon and you need a first credential to prove baseline fluency, CCFP is the front door.
If you already run the platform daily, skip ahead. The practitioner exam spends questions on foundations that working administrators, responders, and hunters already have - the role-based credentials below are where the path gets specific.
The core Falcon trio: CCFA, CCFR, and CCFH
Three credentials cover the classic Falcon console roles, and picking the wrong one is the most common path mistake. CCFA is for the person who runs the platform. CCFR is for the person who works what the platform fires. CCFH is for the person who goes hunting past what it fires.
The CrowdStrike Certified Falcon Administrator (CCFA) exam covers eight administrative scope areas: user management, sensor deployment, host management and setup, group creation, policy application, rule configuration, dashboards and reports, and workflows. It is directed at the administrator or any analyst with access to the administrative side of the platform.
The CrowdStrike Certified Falcon Responder (CCFR) exam covers six responder scope areas: MITRE ATT&CK Framework Application, Detection Analysis, Event Search, Event Investigation, Search Tools, and Falcon Real Time Response (RTR). It is directed at the front-line analyst responding to detections.
The CrowdStrike Certified Falcon Hunter (CCFH) exam covers seven hunting scope areas, including CrowdStrike Query Language (CQL) work, and is directed at the investigative analyst who performs deeper detection analysis and response. All three recommend at least six months of hands-on Falcon experience.
| Credential | Built for | Scope shape |
|---|---|---|
| CCFA - Falcon Administrator | The admin who runs the platform | 8 administrative scope areas: users, sensors, hosts, groups, policies, rules, reports, workflows |
| CCFR - Falcon Responder | The front-line analyst in the queue | 6 responder scope areas: MITRE ATT&CK, detection analysis, event search, investigation, search tools, RTR |
| CCFH - Falcon Hunter | The investigative analyst and forensic hunter | 7 hunting scope areas including CQL, hunting analytics, and hunting methodology |
Scroll horizontally to view all columns.
The four specializations: SIEM, identity, and cloud
Past the core trio, the program branches into platform specializations. Two cover Falcon Next-Gen SIEM, one covers identity, and one covers cloud security.
The CrowdStrike Certified SIEM Analyst (CCSA) evaluates analytical reasoning and investigation skills inside Falcon Next-Gen SIEM - CQL querying, correlating events across first-party and third-party data, and contributing to incident investigations. Its scope is Querying and Analytics, Detection Logic and Alert Analytics, Incident Investigation, and Reporting and Communication, and its guide notes all 60 questions are multiple-choice.
The CrowdStrike Certified SIEM Engineer (CCSE) is the build-and-run side of the same platform: onboarding third-party data sources through data connectors and the Falcon Log Collector, parsing and log management across collection, normalization, retention, and disposal, and writing basic CQL. Its scope is User Management, Data Ingestion, Parsing, Content Creation, and Automation and Integration.
The CrowdStrike Certified Identity Specialist (CCIS) covers Falcon Identity Protection: Zero Trust tenets, policy rules against identity-based risks, identity-based detections and incidents, connectors to MFA/IDaaS providers, and user risk management. The CrowdStrike Certified Cloud Specialist (CCCS) covers Falcon Cloud Security: cloud account registration, cloud security policies and rules, pre-runtime and runtime protection, findings and detection analysis, and remediating and reporting issues.
| Credential | Built for | Scope areas |
|---|---|---|
| CCSA - SIEM Analyst | Analysts investigating detections in Next-Gen SIEM | 4: Querying and Analytics, Detection Logic and Alert Analytics, Incident Investigation, Reporting and Communication |
| CCSE - SIEM Engineer | Engineers implementing and managing Next-Gen SIEM | 5: User Management, Data Ingestion, Parsing, Content Creation, Automation and Integration |
| CCIS - Identity Specialist | IAM staff and identity-focused analysts | Falcon Identity Protection: Zero Trust, policy rules, identity detections, MFA/IDaaS connectors, user risk |
| CCCS - Cloud Specialist | Cloud security engineers | 7: Falcon Cloud Security features, account registration, policies and rules, pre-runtime and runtime protection, findings, remediation |
Scroll horizontally to view all columns.
What the path costs
Every credential on the path costs the same: $250 USD per exam, with the voucher purchased through your CrowdStrike sales representative or online at Pearson. Every registrant must accept the CrowdStrike Certification Exam Agreement and be at least 18 years old.
The retake policy is identical across all eight exams, and it is where the real cost hides. A failed attempt is another full $250 plus a mandatory 48-hour wait before attempt two and a seven-day wait before attempt three and beyond. A fourth performance failure means a 30-day wait, retaken recommended training, and a review with the CrowdStrike Certification Manager before a fifth attempt is approved.
A two-credential path done right costs $500 in exam fees. The same path with one failure along the way costs $750 plus at least 48 lost hours - which is why the order you take them in, and the sitting itself, deserves real planning.
At home via OnVUE or at a Pearson Testing Center
Every exam on the path shares the same two delivery routes. Pearson VUE's CrowdStrike program page states the certification programs are 'delivered by Pearson either online (OnVUE) or at a Pearson Testing Center (PVTC)', and scheduling happens through your Pearson account with a credit card or an exam voucher.
The at-home route carries Pearson's published OnVUE requirements: Windows 10 or macOS 14 or higher, a working webcam, microphone, and speaker with no headphones, one display only, at least 6 Mbps down and 2 Mbps up, and the ability to close every application except OnVUE. Virtual machines, phones, tablets, secondary displays, VPNs, and corporate or public networks are prohibited, and failing the requirements on exam day can mean immediate cancellation and forfeiture of the exam fee.
How should you sequence the path?
Sequence by the job you actually do, not by the alphabet. A SOC analyst's natural ladder is CCFP first if they are new to Falcon, then CCFR for the queue work they already do, then CCFH when they move into proactive hunting. A platform administrator goes straight to CCFA. An IAM specialist goes straight to CCIS, a SIEM engineer to CCSE with CCSA as the analyst-side complement, and a cloud security engineer to CCCS.
Because there are no prerequisite chains, the only wrong sequences are the wasteful ones: paying for CCFP when you already administer the platform daily, or sitting CCFH before you have the CQL and investigation reps the hunting scope assumes.
Whatever order you choose, the three-year validity clock starts at the pass date, and recertification always means the current version of the exam - CrowdStrike's scope-change clause is explicit that exam content can change at any time without notice.
If the Sitting Itself Is the Problem
Path research solves the choosing. It does not solve the doing when your shift pattern, your calendar, or a failed attempt already on the books is the real blocker.
That is the gap Exam Assist fills on this cluster: your CrowdStrike sitting is handled end to end against the current 60-question, 90-minute format, and the service fee is due only after the agreed pass posts. The CCFP, CCFA, CCFR, CCFH, and CCIS service pages have the per-exam details.
Either way, you now know the real shape of the path: eight role-based credentials, one 60-question, 90-minute, $250 exam each, at home or at a center, three years per credential. Pick the role that is yours - then book the sitting yourself, or hand it to a team whose fee only exists if the pass posts.