← Certifications

CCP · Professional (flagship)

Certified Computing Professional

The flagship credential for autonomous, full-lifecycle software professionals.

Questions

29 multiple choice

Duration

75 minutes

Pass mark

80%

Fee

$35 per attempt

About this certification

The Certified Computing Professional (CCP) is the American Computer Society's flagship credential, designed to confirm that a practitioner can operate with genuine autonomy across the entire software delivery lifecycle. Rather than certifying knowledge of a single tool, language, or framework, the CCP verifies that a candidate can move fluidly between requirements engineering, architectural decision-making, secure coding, verification, deployment, and long-term operational stewardship of a system, exercising judgment comparable to a senior engineer trusted with production systems and client relationships.

Candidates preparing for the CCP are expected to demonstrate not only technical competence but also the professional discipline that separates a credentialed practitioner from a self-taught coder. This includes the ability to elicit and negotiate requirements with non-technical stakeholders, translate ambiguous business needs into testable specifications, and make architectural trade-offs that are defensible under scrutiny — for example weighing consistency against availability, or coupling against duplication, with an understanding of the long-term maintenance cost of each choice.

A significant portion of the CCP's scope addresses secure implementation and quality assurance, reflecting the reality that most computing failures in practice are failures of discipline rather than of algorithmic knowledge. The exam probes familiarity with secure coding practices aligned to OWASP guidance, defensive programming, input validation, and the systematic use of unit, integration, and acceptance testing to build justified confidence in a system before it reaches production.

The credential also treats delivery and operations as first-class professional concerns. A CCP holder is expected to understand continuous integration and continuous delivery pipelines, infrastructure as code, containerized deployment, and the observability practices — logging, metrics, tracing, and alerting — required to operate a system responsibly after release, including incident response and blameless postmortems that feed back into design improvement.

Finally, the CCP distinguishes itself by treating professional ethics and legal/regulatory duty as examinable material rather than an afterthought. Candidates must understand data privacy obligations such as those raised by GDPR and similar regimes, intellectual property considerations, the duty to disclose known defects or risks, and the ethical obligations codified in professional codes of conduct such as the ACM Code of Ethics and Professional Conduct.

Because the CCP certifies autonomous professional practice, it is positioned as a mid-to-senior career credential. It is well suited to practitioners who already have hands-on delivery experience and are seeking formal, third-party validation of their ability to be trusted with end-to-end ownership of software systems, whether as a senior engineer, technical lead, or independent consultant.

Syllabus and exam weighting

Requirements Engineering

15%

Covers the elicitation, analysis, specification, and validation of software requirements. Candidates must be able to translate ambiguous stakeholder input into precise, testable specifications and manage evolving scope.

  • ▪Stakeholder elicitation techniques (interviews, workshops, observation)
  • ▪User stories, use cases, and acceptance criteria
  • ▪Functional vs. non-functional requirements
  • ▪Requirements prioritization (MoSCoW, weighted scoring)
  • ▪Traceability matrices and change management
  • ▪Ambiguity, conflict, and gap detection in requirements
  • ▪Domain modeling and glossary development

Architecture and Design

20%

Assesses the ability to make and justify structural decisions for a system, balancing quality attributes such as scalability, maintainability, and performance. Includes both high-level architectural styles and detailed design patterns.

  • ▪Architectural styles: monolith, microservices, event-driven, layered
  • ▪Design patterns (creational, structural, behavioral)
  • ▪API design and versioning strategies
  • ▪Data modeling and database selection (relational vs. NoSQL)
  • ▪Scalability, caching, and load-balancing strategies
  • ▪CAP theorem and distributed systems trade-offs
  • ▪Architecture decision records (ADRs) and documentation
  • ▪Domain-driven design fundamentals

Secure Implementation

20%

Focuses on writing code that resists common attack vectors and adheres to defensive programming principles. Candidates are expected to recognize vulnerable patterns and apply mitigations grounded in industry-standard guidance.

  • ▪OWASP Top 10 vulnerability classes
  • ▪Input validation and output encoding
  • ▪Authentication and authorization mechanisms (OAuth2, session management)
  • ▪Secure use of cryptography (hashing, encryption at rest/in transit)
  • ▪Dependency and supply-chain security
  • ▪Secrets management
  • ▪Secure error handling and logging
  • ▪Defensive programming and fail-safe defaults

Testing and Quality Assurance

15%

Covers the strategies and techniques used to build justified confidence in software correctness prior to and after release. Includes both manual and automated approaches across the test pyramid.

  • ▪Unit, integration, system, and acceptance testing
  • ▪Test-driven development and behavior-driven development
  • ▪Code coverage metrics and their limitations
  • ▪Static analysis and linting
  • ▪Performance and load testing
  • ▪Regression testing and test automation frameworks
  • ▪Defect triage and root-cause analysis

Delivery, DevOps, and Observability

15%

Evaluates competence in shipping and operating software reliably, including continuous integration/delivery, infrastructure automation, and the telemetry needed to detect and diagnose production issues.

  • ▪CI/CD pipeline design and branching strategies
  • ▪Infrastructure as code (Terraform, CloudFormation)
  • ▪Containerization and orchestration (Docker, Kubernetes)
  • ▪Blue-green and canary deployment strategies
  • ▪Logging, metrics, and distributed tracing
  • ▪Alerting and on-call incident response
  • ▪Blameless postmortems and continuous improvement

Professional Ethics and Legal/Regulatory Duty

15%

Examines the practitioner's obligations to clients, users, and society, including data protection law, intellectual property, and codes of professional conduct. Candidates must apply these principles to realistic scenarios.

  • ▪ACM/IEEE-CS Software Engineering Code of Ethics and Professional Practice
  • ▪Data privacy regulations (GDPR, CCPA) and their engineering implications
  • ▪Intellectual property: licensing, open-source obligations, patents
  • ▪Duty to disclose defects, risks, and conflicts of interest
  • ▪Accessibility and inclusive design obligations
  • ▪Liability and professional negligence concepts
  • ▪Whistleblowing and escalation of ethical concerns

Learning outcomes

  • ✓Elicit, document, and prioritize software requirements using structured techniques such as user stories, use cases, and acceptance criteria
  • ✓Evaluate and justify architectural trade-offs, including monolith vs. microservices, synchronous vs. asynchronous communication, and consistency vs. availability
  • ✓Apply secure coding practices to prevent common vulnerability classes, including injection, broken authentication, and insecure deserialization
  • ✓Design and execute a layered test strategy encompassing unit, integration, system, and acceptance testing with measurable coverage goals
  • ✓Build and reason about CI/CD pipelines, infrastructure as code, and observability instrumentation to support reliable, monitorable releases
  • ✓Identify and act on legal, regulatory, and ethical obligations, including data privacy, intellectual property, and professional codes of conduct

Exam format

Delivery
Online proctored exam via live remote proctor or AI-monitored proctoring software; also available at authorized testing centers.
Retakes
A $35 USD fee applies per attempt. Candidates must wait a minimum of 14 days before retaking the exam, and are limited to a maximum of 3 attempts within any rolling 12-month period.
Pass mark
80% of 29 scored questions. Results are graded instantly in MyACS with a domain-by-domain breakdown.

Maintaining the credential

  • ▪CCP certification is valid for 3 years from the date of issuance
  • ▪Holders must accumulate a minimum of 60 Continuing Professional Development (CPD) hours over the 3-year cycle through approved training, conference attendance, publishing, or teaching
  • ▪A signed ethics attestation reaffirming adherence to the ACS Code of Professional Conduct is required at each recertification cycle
  • ▪Candidates who do not meet CPD requirements may retake the current version of the CCP exam to renew certification
  • ▪Lapsed certifications beyond 6 months require full re-examination under the then-current exam blueprint

Recommended reading

Software Engineering: A Practitioner's Approach

McGraw-Hill Education

Comprehensive coverage of the software development lifecycle, requirements, and design fundamentals.

Designing Data-Intensive Applications

O'Reilly Media

Deep treatment of distributed systems trade-offs, consistency models, and data architecture.

The OWASP Testing Guide

OWASP Foundation

Authoritative reference for secure coding and web application security testing practices.

Site Reliability Engineering: How Google Runs Production Systems

O'Reilly Media

Foundational text on observability, incident response, and operational excellence.