CyberSAFE logo
Focused certification exam prep
Start practice

CyberSAFE Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • CyberSAFE has no formal registration prerequisites, application fee, supporting documentation, or eligibility verification.
  • The current assessment is CBS-510: 25 multiple-choice/multiple-response questions with an 80% (20/25) passing score and unlimited retakes.
  • Resist Social-Engineering Attacks and Use the Internet Securely are the largest domains, at 28% each.
  • Everyday familiarity with business computing, the web, and email is recommended, not required.

The Short Answer: What You Actually Need to Qualify

If you are searching for a long list of eligibility rules, here is the good news: CyberSAFE: Securing Assets for End Users does not have one. The credential is issued by CertNexus and is built for ordinary computer users rather than security professionals. There is no required work experience, no prior certification to hold, no application to submit, and no documentation to upload. Nobody reviews your background before you are allowed to sit the assessment.

What "qualifying" really means for this credential is simpler and more demanding in a different way: you must earn the passing score on the assessment. That bar is 80%, which works out to 20 correct answers out of 25 questions. So the practical requirement is not paperwork. It is knowledge of how everyday cyber risk works and how to respond to it.

Requirements at a glance: No formal prerequisites, no application fee, no supporting documentation, no eligibility verification. The only gate is the assessment itself, passed at 80% (20 of 25). If you want the full picture of what the credential is, start with our overview of what CyberSAFE certification is.

What "No Formal Prerequisites" Means in Practice

The absence of formal prerequisites is deliberate. CyberSAFE targets the broad population of people who use computers, phones, email, and the internet for work, which means students, office staff, remote workers, frontline employees, and anyone whose organization wants a baseline of safe digital behavior. A requirement like years of IT experience would defeat the entire purpose.

What you do not need

  • A degree, diploma, or particular education level
  • Prior security or IT certifications
  • Documented work history or a sponsor
  • An application, approval step, or eligibility check
  • Technical skills such as scripting, networking configuration, or system administration

What "no prerequisites" does not mean

It does not mean the assessment is a formality. An 80% passing score on 25 questions leaves room for only five incorrect answers, and the questions are scenario-flavored. A candidate who walks in cold, assuming common sense will carry them, can easily miss the threshold. For a realistic read on difficulty, see our guide on how hard the CyberSAFE exam is.

While nothing is mandatory, the issuer recommends everyday familiarity with business computing, the web, and email. That recommendation is more meaningful than it sounds, because the assessment's scenarios are written around ordinary workplace situations. You will reason much faster if you have already lived them.

  • Email habits: You should be comfortable reading sender details, spotting odd links and attachments, and understanding what it means to reply to or forward a message. Phishing questions assume you have seen an inbox.
  • Web browsing: Knowing what a URL is made of, how a browser indicates an encrypted connection, and why a padlock does not prove a site is trustworthy makes the secure-internet domain far easier.
  • Everyday devices: Familiarity with installing updates, using a phone or laptop for work, and connecting to Wi-Fi gives you context for the device-security questions.
  • Accounts and logins: If you already use passwords, a password manager, or multi-factor authentication (MFA) prompts, the credential-related material will feel intuitive.
A quick self-check: Could you explain to a coworker why a legitimate-looking text asking you to confirm a delivery might be smishing, or why an urgent voice message from "your manager" could be voice cloning? If those scenarios sound unfamiliar, that is precisely what the preparation process is for, and nothing about it requires prior expertise.

Check Your Version: CBS-510 vs. the Legacy CBS-410 Notice

One real "requirement" for candidates is making sure you prepare for the correct assessment version. The current CertNexus offering is assessment CBS-510, launched in October 2025 and marketed as CyberSAFE: Cyber Safety in the Age of AI. Its objectives are published in the CBS-510 Exam Blueprint, version 1.0, issued October 10, 2025.

Be aware that the current issuer page also retains a notice about the older CBS-410 assessment, saying it is active and expected to retire in Q1 2026. That notice is stale and does not confirm an actual retirement date, so do not treat it as a firm deadline or rely on it to plan around. The safe approach is to confirm which assessment your course access key unlocks before you start studying.

ItemCBS-510 (current)CBS-410 (legacy)
Marketing titleCyberSAFE: Cyber Safety in the Age of AIEarlier CyberSAFE assessment
LaunchOctober 2025Earlier release; blueprint dated February 8, 2022
BlueprintVersion 1.0, issued October 10, 2025Separate legacy blueprint
Study guidanceUse the CBS-510 blueprint and course outlineUse only for legacy comparison; do not mix objectives

The key point: do not blend the two. The CBS-510 content explicitly includes AI-era topics such as deepfakes, voice cloning, and generative-AI privacy, and mixing in legacy objectives can send you studying the wrong material. For a structured walkthrough of the current objectives, use our CyberSAFE study guide.

Assessment Format and the 80% Bar

Since the assessment is the only real gate, it pays to understand exactly what it asks of you.

  • Question count: 25 questions
  • Question style: Multiple-choice and multiple-response (some questions require selecting more than one correct answer)
  • Passing score: 80%, equal to 20 of 25 correct
  • Retakes: Unlimited
  • Delivery: Online, through CHOICE or the issuer's e-learning offering

On timing, the sources give slightly different completion estimates. The blueprint and the current-page FAQ suggest roughly 20 to 45 minutes, while the page's assessment table gives a 20 to 40 minute average. Treat these as typical completion times, not a verified fixed exam timer. Separately, the half-day training is its own thing and should not be confused with how long the assessment takes to complete.

Key Takeaway

Multiple-response questions are where candidates lose points. Because you can only miss five questions, practice reading every option and deciding on each one independently rather than stopping at the first plausible answer. Our breakdown of the CyberSAFE passing score explains how that 20-of-25 threshold plays out.

Readiness by Domain: What You Must Be Able to Do

Because there are no entry requirements, your real qualification is demonstrated competence across four weighted domains from the official CBS-510 blueprint. Here is what readiness looks like in each, and you can go deeper in our complete guide to all four CyberSAFE domains.

Domain 1: Use Technology Responsibly (20%)

Responsible use covers how you treat information and tools, with a strong modern emphasis on generative AI.

  • Recognize privacy risks of putting sensitive information into AI prompts
  • Understand that generative AI can produce hallucinations, meaning confident but wrong output
  • Respect intellectual property when using or sharing AI-generated and third-party content
  • Follow organizational expectations for acceptable technology use

Domain 2: Resist Social-Engineering Attacks (28%)

Tied for the heaviest weighting, this domain tests whether you can spot manipulation across channels.

  • Distinguish phishing (email), smishing (text), and vishing (voice) attempts
  • Recognize deepfakes and voice cloning as tools used to impersonate trusted people
  • Identify pressure tactics such as urgency, authority, and fear
  • Know when and how to report suspicious contact

Domain 3: Secure Devices (24%)

This domain focuses on protecting the endpoints and accounts you use every day.

  • Use MFA and password managers appropriately
  • Keep systems patched through updates
  • Maintain backups and understand why they matter
  • Recognize malware risks and safe handling of BYOD (bring your own device) scenarios

Domain 4: Use the Internet Securely (28%)

The second 28% domain covers safe behavior online and on networks.

  • Evaluate suspicious URLs and understand the limits of HTTPS (a secure connection does not guarantee a trustworthy site)
  • Use cloud services safely
  • Handle public Wi-Fi, home networks, and remote work setups with appropriate caution
  • Report incidents promptly and correctly

Notice that Domains 2 and 4 together account for 56% of the assessment. If you only have limited time, that is where a disciplined candidate concentrates effort without neglecting the other two.

Access Mechanics: Key, Delivery, and Cost

Qualifying is mostly about access rather than eligibility. The course access key includes the CHOICE credential process, which means the key you purchase is what gets you into the learning and assessment environment. Delivery is online through CHOICE or the issuer's e-learning offering, so you need a computer with an internet connection, not a testing center appointment.

On cost, the published price is USD 15.17 for the CBS-510 Student Digital Course Bundle (SKU CNX0024SEBU2) in the CertNexus store. It is important to read that correctly: this is a courseware-bundle price, not a standalone exam-only fee. There is no separate application fee on top of the access mechanics described above, but you should confirm current pricing and what each purchase option includes before buying. We cover the full picture in our CyberSAFE certification cost breakdown, and scheduling considerations in our exam dates guide.

Unlimited retakes change the risk math. With no cap on attempts, a first try that falls short is a learning event rather than a dead end. That said, do not treat it as a license to skip preparation. Understanding why you missed a question is far more valuable than simply re-attempting.

Who Benefits From Qualifying (and Who Hires for It)

Because CyberSAFE is an end-user credential, its value shows up differently from a technical certification. It rarely functions as a stand-alone job qualifier. Instead, it signals baseline security awareness, which many organizations want across their entire workforce.

  • Employers building security-aware teams: Organizations that train all staff on phishing, safe browsing, and incident reporting use awareness credentials as part of a broader program.
  • Remote and hybrid workers: People handling company data from home networks and personal devices have the most direct use for the content.
  • Students and career starters: Because there are no prerequisites and the cost is low, it is an accessible way to show digital-safety literacy on a resume.
  • Career changers: It can serve as a gentle first step before pursuing deeper security credentials.

Be realistic about career impact. CyberSAFE supports roles by demonstrating awareness; it is not a security-engineering credential. For an honest look at where it helps, read our ROI analysis, and if you are curious about role types, our pages on CyberSAFE jobs and the salary guide discuss the picture without overstating it.

A Domain-Ordered Preparation Sequence

Since you have no entry requirements to satisfy, your preparation time is best spent on the weighted domains. One sensible, CyberSAFE-specific ordering follows. The supplementary course outline, course CNX0024, is helpful here, but remember that its lesson headings are unweighted preparation curriculum, not an exhaustive statement of what the exam covers.

Week 1

Resist Social-Engineering Attacks (28%)

  • Learn the differences among phishing, smishing, and vishing
  • Study deepfakes and voice cloning as impersonation tools
  • Practice spotting manipulation cues and reporting steps
Week 2

Use the Internet Securely (28%)

  • Review suspicious URLs and the limits of HTTPS
  • Cover public Wi-Fi, home networks, cloud use, and remote work
  • Rehearse incident reporting
Week 3

Secure Devices (24%) and Use Technology Responsibly (20%)

  • Cover MFA, password managers, updates, backups, malware, and BYOD
  • Work through generative-AI privacy, hallucinations, intellectual property, and sensitive information in prompts
  • Finish with a full mixed review and practice questions

Starting with the two 28% domains front-loads the material most likely to move your score. When you are ready to test yourself, try the questions on our CyberSAFE practice test site, and keep our one-page cheat sheet handy for last-minute review. You can also see how candidates fare in what the data shows on pass rates, though we avoid quoting numbers the issuer has not published.

Frequently Asked Questions

Do I need any prior experience or certification to take CyberSAFE?

No. There are no formal registration prerequisites, no application fee, no supporting documentation, and no eligibility verification. The issuer recommends everyday familiarity with business computing, the web, and email, but this is a suggestion rather than a requirement.

What score do I need to pass the current CyberSAFE assessment?

The passing score is 80%, which means 20 correct answers out of 25 questions on the CBS-510 assessment. The questions are multiple-choice and multiple-response, and retakes are unlimited if you do not pass on the first attempt.

Is there an official time limit for the assessment?

The sources give completion estimates of about 20 to 45 minutes, with the assessment table citing a 20 to 40 minute average. These are typical completion times, not a verified fixed exam timer. The half-day training is separate from the time it takes to complete the assessment.

Should I study for CBS-410 or CBS-510?

The current assessment is CBS-510, based on the blueprint issued October 10, 2025. The issuer page still carries a stale notice about CBS-410 expected to retire in Q1 2026, but it does not confirm an actual retirement date. Confirm what your access key unlocks, and do not mix objectives from the two versions.

How much does it cost to qualify?

The published price is USD 15.17 for the CBS-510 Student Digital Course Bundle. That figure is a courseware-bundle price, not a standalone exam-only fee, and the course access key includes the CHOICE credential process. Always verify current pricing with the issuer before purchasing.

Ready to pass your CyberSAFE exam?

Put this into practice with free CyberSAFE questions across every exam domain.