
The CCEP credential verifies that a candidate can engineer cryptographic services across the system lifecycle, with PQC as a major design requirement rather than an isolated algorithm upgrade.
| Credential Element | Specification |
| Recommended preparation | Three years of security, software, hardware, systems, PKI, or network engineering experience. Working knowledge of symmetric and public-key cryptography is expected. |
| Training pathway | Five days of technical instruction, design laboratories, and an engineering capstone. |
| Assessment | 150-minute, 100-question examination plus a design review and oral defense. |
| Passing standard | 75 percent on the examination and satisfactory ratings on every critical capstone criterion. |
| Credential validity | Three years |
| Renewal | 50 continuing professional education hours, including at least 20 hours in cryptographic engineering or PQC, plus one documented engineering activity. |
Intended Audience
- Cryptographic and cybersecurity engineers
- Systems, software, hardware, embedded, and network architects
- PKI and key-management engineers
- Product security and secure-development personnel
- Technical reviewers responsible for cryptographic design assurance
Certification Outcomes
- Translate mission and security requirements into cryptographic services and measurable assurance requirements.
- Select primitives, parameter sets, protocols, libraries, modules, and key-management patterns without inventing custom cryptography.
- Design crypto-agile interfaces, formats, policy controls, lifecycle states, and transition mechanisms.
- Analyze randomness, key generation, storage, distribution, rotation, revocation, recovery, destruction, and audit.
- Evaluate performance, memory, bandwidth, hardware, timing, reliability, availability, and interoperability tradeoffs.
- Conduct threat modeling and design review for side channels, misuse, downgrade, parsing, fault, supply-chain, and operational risks.
Exam Domain Blueprint
| Domain | Weight | Coverage |
| Requirements and architecture | 20% | Services; trust boundaries; misuse cases; assurance; crypto agility |
| Algorithms and protocols | 20% | Symmetric; classical public key; KEMs; signatures; composition; negotiation |
| Key and certificate engineering | 20% | Entropy; generation; storage; KMS and HSM; PKI; lifecycle |
| Implementation security | 25% | APIs; constant time; side channels; validation; errors; memory; supply chain |
| Verification and operations | 15% | Test vectors; interoperability; performance; monitoring; incident response |
Training Modules
Module 1 Cryptographic Systems Engineering
- Security services, assets, trust boundaries, and misuse cases
- Requirements traceability and assurance levels
- Build-versus-buy decisions and approved cryptographic modules
Module 2 Primitive and Protocol Selection
- Symmetric cryptography, hashes, MACs, KDFs, KEMs, and signatures
- PQC parameter sets and performance characteristics
- Protocol composition, domain separation, binding, and negotiation
Module 3 Key Management and PKI
- Entropy sources and deterministic random bit generators
- Key generation, storage, backup, rotation, revocation, recovery, and destruction
- Certificate profiles, enrollment, status, trust stores, and algorithm transitions
Module 4 Secure Implementation Architecture
- Safe APIs, algorithm identifiers, serialization, parsing, and input validation
- Constant-time design, side channels, fault attacks, zeroization, and secret handling
- Hardware acceleration, HSM integration, constrained devices, and secure boot
Module 5 Crypto Agility and PQC Integration
- Algorithm abstraction, policy-driven selection, versioning, and observability
- Hybrid KEM and signature patterns, compatibility, and downgrade resistance
- Migration coexistence and decommissioning
Module 6 Verification and Operational Assurance
- Known-answer, negative, differential, fuzz, interoperability, and regression testing
- Performance and resource benchmarking
- Telemetry, audit, incident response, vulnerability handling, and supplier evidence
Practical Exercises
| Exercise | Candidate Task | Evidence Produced |
| Requirements review | Translate a mission scenario into cryptographic and assurance requirements | Requirements traceability matrix |
| Architecture trade study | Compare design alternatives using security, performance, and lifecycle criteria | Trade study and decision record |
| Threat model | Analyze attack paths across APIs, keys, protocols, modules, and operations | Threat model with mitigations |
| Design review | Inspect a proposed PQC-enabled architecture for composition and lifecycle flaws | Engineering review report |
Capstone Assessment
Candidates engineer a crypto-agile secure communications service that must support classical and PQC deployments, enterprise PKI, HSM-backed keys, constrained clients, signed updates, and phased migration. The design package includes requirements, architecture, algorithm and protocol decisions, key lifecycle, threat model, test strategy, operational controls, and residual risks.
Capstone Scoring
| Criterion | Weight | Performance Evidence |
| Requirements traceability | 15% | Security and mission needs map to design and verification evidence |
| Cryptographic design | 25% | Sound primitive use, composition, parameters, and protocol behavior |
| Lifecycle engineering | 20% | Complete key, certificate, algorithm, and product lifecycle controls |
| Implementation assurance | 20% | Credible protection against misuse, side channels, faults, parsing, and dependency risks |
| Verification and operations | 20% | Testable acceptance criteria, monitoring, response, and maintainability |
Knowledge and Skill Boundaries
Included Engineering established cryptographic primitives into systems, including architecture, implementation requirements, verification, and operations.
Excluded Designing a new cryptographic primitive for real-world deployment or certifying a module, algorithm, or implementation on behalf of NIST or another authority.