- What CWSP Means and Who Issues It
- Where CWSP Sits in the CWNP Program
- The CWSP-208 Exam at a Glance
- The Four Exam Domains
- Technical Topics You Must Be Able to Reason About
- Taking the Exam Through Remote Proctoring
- Voucher, Validity, and Renewal
- Who Benefits From the Credential
- Sequencing Your Preparation Around the Weighting
- Frequently Asked Questions
- CWSP means Certified Wireless Security Professional, a vendor-neutral wireless security credential issued by CWNP.
- The current exam is CWSP-208: 60 multiple-choice questions, 90 minutes, 70% to pass, remote-proctored only.
- WLAN Security Design and Architecture is 50% of the exam; Vulnerabilities, Threats, and Attacks adds another 30%.
- A current, valid CWNA is required to earn CWSP, and CWSP-207 ended December 31, 2025.
What CWSP Means and Who Issues It
CWSP stands for Certified Wireless Security Professional. It is a professional-level credential issued by CWNP (Certified Wireless Network Professional), a vendor-neutral program focused on enterprise Wi-Fi. The certification validates that you can assess wireless risk, design secure WLAN architectures, and operate those designs over time, rather than configure one manufacturer's controller.
That vendor-neutral stance shapes the exam. You are not asked which menu in a particular product enables a feature. You are asked which design, protocol, or policy decision best fits a described environment, and why the alternatives fail. If you have seen the acronym used for other credentials elsewhere, set those aside: this article, and this site, cover only the CWNP wireless-security certification. For related phrasing, see our explainers on what CWSP stands for and CWSP meaning.
Where CWSP Sits in the CWNP Program
CWSP is not an entry point. A current, valid CWNA (Certified Wireless Network Administrator) is required to earn it, which tells you what the exam assumes: you already understand RF fundamentals, 802.11 frame behavior, and basic WLAN operation. The security exam builds on that foundation rather than reteaching it. Instructor-led training is optional, so self-study is a legitimate route. Our CWSP requirements guide walks through eligibility in more detail.
Because CWSP is professional level, it is one of the credentials that sits above the administrator tier alongside the design and analysis certifications. Candidates who already hold a current CWNA can move directly to the security exam without a separate prerequisite beyond that.
The CWSP-208 Exam at a Glance
The selected current version is CWSP-208, built on the 2025 objectives. CWSP-207 ended December 31, 2025. CWNP's own pages differ slightly on the release month (December 2025 on the credential page, November 2025 in the exam-update table), but both identify CWSP-208 as current and schedule the next version for 2028. Practically, that means any study material written for CWSP-207 or CWSP-205 should be treated with suspicion until you have checked it against the 2025 objectives.
| Item | CWSP-208 Detail |
|---|---|
| Issuer | CWNP |
| Format | 60 multiple-choice, single-correct-answer questions |
| Time | 90 minutes |
| Passing score | 70% (80% for instructors) |
| Language | English |
| Delivery | CWNP remote proctoring only (not Prometric or Pearson VUE) |
| Voucher | USD $349.99, one attempt |
| Retake wait | 10 days, including weekends |
Every question has exactly one correct answer, which sounds forgiving until you meet the style: several options are often technically plausible, and only one is best for the scenario given. For a deeper look at the cut score, read our CWSP passing score breakdown, and note that a passing score is a different thing from a pass rate; we cover that distinction in what the data shows on CWSP pass rates.
The Four Exam Domains
The objectives divide the exam into four weighted domains. The weighting is lopsided, and that should drive how you allocate study hours.
Domain 3: WLAN Security Design and Architecture (50%)
Half the exam. Expect scenario questions where you choose or critique a design.
- Authentication and key-management architecture for enterprise and guest networks
- 802.1X and RADIUS deployment, including EAP method selection
- PKI considerations for certificate-based methods
- Fast roaming and its security implications
- Secure guest access and segmentation
Domain 2: Vulnerabilities, Threats, and Attacks (30%)
Recognizing how wireless networks are attacked and which control actually mitigates each attack.
- Attacks against authentication, handshakes, and management frames
- Rogue and unauthorized devices, and detection approaches
- Matching a threat to the correct countermeasure rather than a generic one
Domain 1: Security Policy (10%)
The governance layer: what a wireless security policy should require and how it connects to technical controls.
Domain 4: Security Lifecycle Management (10%)
Keeping a secure WLAN secure: assessment, monitoring, and maintaining controls as the environment changes.
Our complete guide to the four CWSP content areas expands each domain with study priorities.
Technical Topics You Must Be Able to Reason About
CWSP rewards candidates who can reason about why a design works, not just recite acronyms. These are the clusters that recur across the architecture and threat domains.
802.1X, RADIUS, and the EAP Family
You should be comfortable with the roles of supplicant, authenticator, and authentication server, and with how a RADIUS exchange carries EAP traffic. The exam then asks you to compare methods: EAP-TLS (mutual certificate authentication), EAP-TTLS, and PEAP (tunneled methods that protect an inner credential exchange). Know what each requires on the client and server side, what it protects against, and what operational burden it adds. EAP-TLS offers strong mutual authentication but demands a working PKI and certificate lifecycle; tunneled methods lower client-side certificate burden but introduce their own validation pitfalls, such as clients that do not verify the server certificate.
WPA3 and Its Modes
Know what WPA3 changes relative to WPA2 and how its personal and enterprise modes differ. Keep OWE (Opportunistic Wireless Encryption) clearly separate from the WPA3 authentication modes: OWE provides encryption for open networks without authenticating users, so it solves a different problem than SAE-based personal or 802.1X-based enterprise operation. Mixing these up is a classic way to lose points on a guest-network question. Also be ready for RSN Override, a topic in the current objectives, and for transition-mode reasoning where WPA2 and WPA3 clients coexist.
Key Hierarchies and Handshakes
Understand how keys are derived and distributed after authentication: the master key material, the pairwise and group key hierarchies, and the four-way handshake that installs them. Scenario questions may describe a symptom, such as a failed handshake or an exposed key, and ask you to identify what stage broke or what an attacker could capture.
Fast Roaming and Secure Guest Access
Fast roaming mechanisms trade authentication overhead against security assumptions, and the exam expects you to know what key material is cached or pre-distributed and where that creates exposure. Guest access questions typically hinge on isolation, captive-portal limitations, and choosing an encryption approach that fits an open or lightly authenticated environment.
Key Takeaway
Build a comparison habit: for every protocol or method, be able to state what it authenticates, what it encrypts, what infrastructure it needs, and how it fails. That four-part frame answers most CWSP-208 scenario questions faster than memorizing definitions. Our CWSP cheat sheet is built around exactly these comparisons.
Taking the Exam Through Remote Proctoring
CWSP-208 is delivered exclusively through CWNP remote proctoring, not through Prometric or Pearson VUE test centers. The session runs on Google Meet alongside the CWNP Learning Center. Plan the logistics as carefully as the content:
- Bring matching, unexpired government-issued photo identification.
- Use a working camera and microphone, and a single monitor.
- Expect notes, outside assistance, external devices, and unrelated applications to be prohibited.
- Remember that the timer continues during approved breaks, so a break does not buy you extra time.
With 60 questions in 90 minutes, you have roughly a minute and a half per question, which is comfortable for recall items and tight for long scenarios. Practice reading a scenario, identifying the one constraint that decides the answer, and moving on. For scheduling specifics, see our CWSP exam dates and scheduling guide.
Voucher, Validity, and Renewal
What the Voucher Covers
The exam voucher costs USD $349.99 for a single attempt. It is valid for two years from purchase or until the exam version ends, whichever comes first. A second attempt requires a second voucher, and CWNP's FAQ specifies a 10-day waiting period between attempts, counting weekends. Because a voucher can expire when the version retires, do not buy one for a version near its end of life. Our CWSP certification cost breakdown covers the full spend picture, including training you may or may not need.
Keeping the Credential Current
Standard validity is three years. Renewal under the standard route requires a current CWNA and passing the current CWSP exam; doing so also renews CWNA for three years. There is an alternative professional continuing-education route, which must be elected within one year of certification. It requires eight approved, documented CE hours annually plus annual renewal, and the linked guidelines specify that two of those hours include passing the annual certification CE eLearning. Two cautions: electing CE cannot be reversed back to the three-year testing cycle, and CE renewal does not by itself renew CWNA.
Who Benefits From the Credential
CWSP is aimed at people who own the security of wireless infrastructure: wireless and network engineers, network security engineers, and consultants who assess or design enterprise WLANs. It suits environments where Wi-Fi is a primary access layer, such as campuses, healthcare, large offices, and venues with significant guest traffic, and it is relevant for integrators and managed-service providers who design networks across multiple vendors.
Because the credential is vendor-neutral, it complements product certifications rather than replacing them: the product certificate shows you can operate a platform, while CWSP shows you can judge whether the design is sound. If you are weighing the investment, our analyses of whether the certification is worth it, the CWSP salary landscape, and CWSP jobs take a measured view; we deliberately avoid quoting earnings or pass-rate numbers that cannot be verified for this exact credential.
Sequencing Your Preparation Around the Weighting
Rather than a generic schedule, tie your calendar to the domain weights. A sensible order front-loads the heaviest domain and uses the lighter ones as consolidation.
Authentication Foundations (Domain 3)
- 802.1X roles, RADIUS flow, and the EAP method comparison
- PKI basics needed for EAP-TLS and server certificate validation
Encryption, Keys, and Roaming (Domain 3)
- WPA3 modes, OWE versus SAE versus enterprise, and RSN Override
- Key hierarchies, handshakes, and fast-roaming trade-offs
- Secure guest access designs
Threats and Countermeasures (Domain 2)
- Map each attack class to the control that actually stops it
Policy, Lifecycle, and Practice (Domains 1 and 4)
- Policy and lifecycle review, then timed mixed-domain practice
Use practice questions written against the 2025 objectives, and prefer original scenario-style items over recycled question banks, which tend to teach memorization rather than the reasoning the exam tests. For a fuller plan, see our CWSP study guide, our assessment of how hard the exam is, and the broader CWSP certification overview. When you are ready to test yourself, try the CWSP-208 practice tests and review explanations for every miss.
Frequently Asked Questions
CWSP stands for Certified Wireless Security Professional, a vendor-neutral wireless security certification issued by CWNP. It validates the ability to assess wireless risk and design and manage secure enterprise WLANs.
Yes. A current, valid CWNA is required to earn the CWSP credential. Instructor-led training is optional, so you can prepare through self-study if you already hold an active CWNA.
CWSP-208 has 60 multiple-choice, single-correct-answer questions in 90 minutes, delivered in English through CWNP remote proctoring. The passing score is 70%, or 80% for instructors.
WLAN Security Design and Architecture, which accounts for 50% of the exam. Vulnerabilities, Threats, and Attacks follows at 30%, while Security Policy and Security Lifecycle Management are 10% each.
CWSP-207 ended December 31, 2025, and CWSP-208 uses the 2025 objectives. Older CWSP-207 or CWSP-205 materials may still help with core concepts, but verify every topic against the current objectives before relying on it.
Understanding what CWSP is, an architecture-heavy, vendor-neutral test of wireless security judgment, is the first step toward preparing for it efficiently. Weight your effort toward design and threat reasoning, confirm the renewal terms with CWNP, and practice with material aligned to CWSP-208.