C)SA1 logo
Focused certification exam prep
Start practice

C)SA1 Requirements 2026: Eligibility, Prerequisites & How to Qualify

TL;DR
  • Certified Security Awareness 1 from Mile2 has no suggested prerequisites; it targets end users, employees and managers.
  • Mile2 training is not mandatory, and completing the course is different from earning the certification.
  • The Exam Combo lists the exam, simulator and prep guide, with two attempts per combo.
  • Question count, timer and passing threshold remain unverified; do not assume the 100-item rule applies.

What "Requirements" Really Means for C)SA1

When people search for the requirements of a certification, they usually want three answers: who is allowed to sit the exam, what they must do beforehand, and what they must do to keep the credential afterward. For Certified Security Awareness 1, issued by the Mile2 Cybersecurity Institute, the honest answer to the first two is refreshingly short, while the third has some wrinkles worth understanding before you commit.

This article covers eligibility, prerequisites, registration mechanics, the content you need to be ready for, and renewal. It deliberately separates what is publicly documented from what is not. Where Mile2's own materials disagree with each other, we say so rather than smoothing it over. For the broader picture of what the credential is, see our overview, What Is C)SA1 Certification?

Scope note: This article is about the standalone Certified Security Awareness 1 certification from Mile2. It is not about a combined C)SA1/C)SA2 course, and it is not about any other organization's exam that happens to share a similar abbreviation. Everything below is drawn from Mile2's public course outline, policies, FAQ and product pages.

Prerequisites: What You Need Before You Start

Mile2 lists no suggested prerequisites for Certified Security Awareness 1. There is no required prior certification, no minimum years of IT or security experience, no degree requirement, and no prescribed background in networking or systems administration. That matches the design of the course: it is built for people whose job is not cybersecurity.

Requirement TypeC)SA1 Status
Prior certificationsNone suggested
Work experienceNone suggested
Technical backgroundNot expected; intended for non-specialists
Mile2 training courseNot mandatory
Mile2 account / learning management systemNeeded, since delivery is online through the account

The practical prerequisite is simply access: a Mile2 account and a reliable internet connection, because the exam is delivered online through the Mile2 learning management system. Beyond that, candidates should be comfortable reading scenario-based material about everyday workplace risks. If you are wondering whether a lack of technical background will hurt you, our C)SA1 difficulty guide discusses what actually makes the material easy or hard for newcomers.

Who the Certification Is Built For

The course is intended for end users, employees and managers. That framing tells you a lot about what the exam is likely to reward: practical judgment about everyday security behavior rather than deep engineering knowledge. Typical candidates include:

  • Employees across departments who handle email, shared documents, customer information and collaboration tools daily.
  • Managers who need to model good security habits and respond properly when a team member reports something suspicious.
  • Organizations that want a recognized, third-party-issued credential to document awareness training rather than relying only on an internal slide deck.
  • Career changers who want a low-barrier first entry on their record before pursuing more technical credentials.

It is worth being realistic about the career side. A security awareness credential can demonstrate baseline competence and initiative, but we do not promise a pay increase or a particular job outcome from it. If you are weighing that question, read Is the C)SA1 Certification Worth It? and C)SA1 Jobs for a grounded discussion rather than hype.

Training Is Not the Same as Certification

One of the most common misunderstandings concerns the difference between taking the course and earning the credential. Mile2 publishes a two-hour, English-language live class that carries four CEUs. Those figures describe the training, not the certification exam. The length of the class tells you nothing about the exam timer, and the CEUs earned from the class are a separate matter from passing the exam.

Mile2 training is not mandatory. That means the formal path to certification does not require you to attend the live class first. A candidate who already works with these topics, or who prefers to self-study, can approach the exam directly. Conversely, completing the class does not by itself make you certified; the Mile2 certification is earned through the exam.

Course completion vs. certification: Finishing the two-hour class gives you training and four CEUs. Earning the Mile2 certification is a separate outcome that depends on the exam. Do not list the credential on a resume or profile until you have actually been awarded it.

For more on how the course experience fits into preparation, see C)SA1 Training.

What We Can and Cannot Confirm About the Exam

This is the section where precision matters most. Several exam parameters are not reliably documented for C)SA1 specifically, and importing numbers from other exams would mislead you.

Items we are holding back on

  • Number of questions: not verified.
  • Question format: not verified.
  • Exact exam timer: not verified.
  • Passing threshold: not verified.

Two source quirks explain why. First, the course outline PDF contains an exam-information paragraph that names a different Mile2 exam, Certified Network Principles, so its passing-score statement cannot be treated as C)SA1 policy. Second, Mile2's Policies and Procedures document (dated 5-26-2026) states a general rule of 100 multiple-choice items for exams but expressly excludes C)SA1 and C)SA2 from that rule. In short, do not assume a 100-question multiple-choice test. For what is and is not known about scoring, see C)SA1 Passing Score, and note that we also do not publish a candidate pass rate because none has been verified; our pass rate article explains the data limits.

Supervision: a documented conflict

Mile2's materials disagree on how exams are administered. The FAQ describes most standard exams as on-demand, without a live-proctor appointment. The policies document, however, describes proctored, open-book assessment that requires advance scheduling. Because these two statements pull in different directions, treat your own C)SA1 assignment as the source of truth: confirm what supervision applies and which resources you are permitted to use before exam day.

Key Takeaway

Before you start the exam, check inside your Mile2 account for the supervision type, whether scheduling is required, and what reference materials are allowed. Do not rely on a forum post or on rules from a different Mile2 exam.

Timing questions are covered further in C)SA1 Exam Dates.

Registration Mechanics and the Exam Combo

Delivery is online through your Mile2 account and learning management system. The product Mile2 lists for this credential is the C)SA1 Exam Combo, and its public inclusion list names three components:

  • The exam itself
  • An exam simulator
  • A prep guide

The Mile2 FAQ and its exam-combos page indicate two attempts per Exam Combo. That is a meaningful detail: a failed first attempt does not automatically force a second purchase, though you should confirm any waiting period or retake conditions in your account.

A word on price

We are not going to quote a confident current fee. Prior reviews of the product recorded an advertised bundle price of USD 150, with one review also noting a USD 495 original price. However, no price appeared in the product text retrieved for this article, so those figures are historical records, not verified checkout prices, and they do not tell you the cost of a standalone voucher. Check the live product page at checkout. Our C)SA1 certification cost breakdown lays out how to think about the total cost without presenting unverified numbers as fact.

ItemWhat Is Documented
ProductC)SA1 Exam Combo
Public inclusionsExam, simulator, prep guide
AttemptsTwo per Exam Combo (FAQ and exam-combos page)
Current priceNot verified; confirm at checkout
DeliveryOnline via Mile2 account and LMS

Content You Should Be Ready to Handle

Meeting the requirements to sit the exam is easy; meeting the requirements to pass it means knowing the material. Mile2's public outline organizes preparation topics into an introduction plus seven numbered modules (00 through 06). These are unweighted preparation topics, not official exam domains, and no percentage-weighted blueprint has been publicly verified. That means you cannot safely assume one topic dominates the exam, so prepare evenly. The full breakdown lives in C)SA1 Exam Domains: Complete Guide to All 8 Content Areas; here is the requirement-focused summary.

Introduction: Who is Mile2?

Context on the issuing organization and what the credential represents.

  • Know the issuer and the purpose of the certification
  • Understand how awareness training fits an organization's security posture

2025 Cyberthreat Trends

The current threat landscape as the course frames it. The heading references 2025, but that does not mean the exam version is tied to a particular year.

  • Recognize the categories of threats employees are most likely to face
  • Connect each trend to a behavior that reduces risk

The Human Factor

Why people are central to both attacks and defenses.

  • Understand how habits, pressure and trust get exploited
  • Distinguish carelessness from manipulation

Phishing & Social Engineering

The most scenario-friendly topic for a workplace audience.

  • Spot warning signs in messages, calls and in-person pretexts
  • Know the correct reporting step rather than only the detection step

Credentials, Passwords, and Access Security

Protecting the keys to accounts and systems.

  • Understand strong, unique credentials and safe handling
  • Know why access should be limited and how it is misused

Data Protection & Handling Sensitive Information

Everyday decisions about what data goes where.

  • Recognize sensitive information and how to handle, share and dispose of it
  • Apply the idea of using data only as needed for the task

Communication Security & Collaboration Tools

Risks inside email, chat, meetings and shared workspaces.

  • Judge when a channel is appropriate for the information involved
  • Understand sharing permissions and accidental exposure

Incident Response, Security Culture, and Wrap-Up

What to do when something goes wrong and how organizations build lasting habits.

  • Know that fast, honest reporting beats trying to quietly fix a mistake
  • Understand how culture reinforces individual behavior

Because the paid prep guide and the live exam were not reviewed for this article, treat this list as a map of public headings rather than a guarantee of exhaustive exam coverage. Our C)SA1 cheat sheet condenses the core ideas for quick review.

Sequencing Your Preparation Around the Topics

Since there is no verified weighting, a balanced sequence beats guessing which topic to favor. One sensible order puts foundational concepts first, behavior-heavy topics in the middle, and response last. The following is a suggested pattern, not an official plan.

Week 1

Foundations

  • Cover the introduction, 2025 Cyberthreat Trends and The Human Factor
  • Build vocabulary so later scenarios make sense
Week 2

Attack and Defense Behaviors

  • Work through Phishing & Social Engineering and Credentials, Passwords, and Access Security
  • Practice identifying the best action in short workplace scenarios
Week 3

Data, Communication, and Response

  • Review Data Protection, Communication Security & Collaboration Tools, and Incident Response
  • Use the included simulator for original-style practice and revisit weak topics

Why this order? The early topics supply the language the later ones assume, and incident response makes the most sense once you understand what can go wrong. For a fuller approach, see our C)SA1 study guide, and when you want additional practice beyond the bundled simulator, try the C)SA1 practice tests.

Validity and Renewal Requirements

The certification is valid for three years. After that, you need to renew to keep it active. This is where Mile2's public documentation is least consistent, so read carefully.

The standard CEU route

According to Mile2's Certification Renewal Program, the standard route requires 60 documented CEUs over the three-year period, a renewal purchase, and an ethics and policy acknowledgment. The FAQ gives a USD 200 U.S. regional price for CEU-based renewal and states no annual membership requirement.

The alternative path

The dedicated Paths to Renewal page also offers an alternative: passing the latest existing-credential exam.

The conflict you should know about

Other Mile2 documents frame it differently. The course PDF presents a current exam and 20 annual CEUs as joint requirements, and policy page 22 couples annual CEUs with an exam-or-renewal-purchase requirement, which differs from the standalone alternative-path page. These statements should not all be treated as simultaneously satisfied policy.

SourceWhat It Describes
Certification Renewal Program60 documented CEUs over three years, renewal purchase, ethics/policy acknowledgment
Paths to RenewalCEU route, or passing the latest existing-credential exam as an alternative
Course PDFCurrent exam and 20 annual CEUs presented as joint requirements
Policies (page 22)Annual CEUs coupled with exam-or-renewal-purchase requirement
Practical advice: Mark your three-year expiration date when you pass. Well before it arrives, contact Mile2 or check your account to confirm which renewal route applies to you and what the deadline is. Keep records of any CEU activity, including the four CEUs associated with the live class, in case they are relevant to your route.

Frequently Asked Questions

Do I need any prerequisites to take the C)SA1 exam?

No. Mile2 lists no suggested prerequisites for Certified Security Awareness 1. The course is intended for end users, employees and managers, so no prior certification or technical experience is expected.

Is Mile2 training mandatory before the exam?

No. Mile2 training is not mandatory. The two-hour live class and its four CEUs describe training, not the certification exam, and completing the class is not the same as earning the certification.

How many questions are on the C)SA1 exam and what is the passing score?

These details are not verified for C)SA1. Mile2's policies expressly exclude C)SA1 from the general 100-multiple-choice-item rule, and the course PDF's exam paragraph names a different exam. Confirm the format, timer and passing threshold in your Mile2 account.

How many attempts do I get?

The Mile2 FAQ and exam-combos page indicate two attempts per Exam Combo. Check your account for any retake conditions before you begin.

How long is the certification valid and how do I renew?

It is valid for three years. The standard route is 60 documented CEUs over three years plus a renewal purchase and ethics acknowledgment, with passing the latest exam offered as an alternative. Because Mile2's sources conflict on details, confirm your applicable route and deadline directly.

In short, the barrier to entry for Certified Security Awareness 1 is low, but the details around exam administration and renewal reward careful verification. Confirm the live conditions in your Mile2 account, prepare evenly across the eight topic areas, and keep the three-year renewal clock in mind from day one.

Ready to pass your C)SA1 exam?

Put this into practice with free C)SA1 questions across every exam domain.