CCP-CRE Exam Preparation

YOUR PATH TO
CCP-CRE
CERTIFIED

A structured 8–12 week study path built around the 7 exam domains. Pick your pace, we'll give you everything you need to pass on your first attempt.

Starting with the foundation level? The CRA-RE exam is open to all real estate professionals — no deep technical background required.
Take CRA-RE Exam →
CCP-CRE Exam Overview Enrolling Now
Questions 80 items
Format MCQ + Scenario + Lab
Time limit 120 min written + 30 min lab
Passing score 80% (64 / 80 correct)
Delivery Online proctored, anytime
Exam fee $500 (includes CBK)
Prerequisite 1 yr CRE IT, OT, or building technology
Certification validity Biannual + 20 CPE
Avg. candidate readiness at 8 weeks82%
First-attempt pass rate87%

Study Timeline

CHOOSE YOUR PACE

Whether you have 6 weeks or 12, there's a structured path to exam day. All paths cover all 7 domains, you control the intensity.

W1
Week 1–2
Foundation: CRE Threat Landscape

Domain 1, CRE Cyber Risk Framework. CRE-specific threat actors, building system attack surfaces, the IT/OT convergence problem. Read CBK Chapters 1–3, complete practice scenarios.

~8 hrs / week
W3
Week 3–4
OT / BAS Security (heaviest domain)

Domain 2, Building Automation & OT Security. BACnet/Modbus protocols, Niagara Framework vulnerabilities, network segmentation, OT incident response. Requires most study time: 20% of exam questions.

~10 hrs / week
W5
Week 5–6
Physical Systems + Tenant Risk

Domain 3 (Physical Access & Surveillance) and Domain 4 (Tenant Data & Lease Risk). Physical-cyber convergence, NVR security, tenant data segregation, lease clause obligations.

~8 hrs / week
W7
Week 7–8
Vendor Risk + Governance & Compliance

Domain 5 (Third-Party/Vendor Risk) and Domain 6 (Regulatory/Compliance). OT vendor management, REIT SEC disclosure obligations, cyber insurance for CRE, NIST CSF 2.0 mapping.

~8 hrs / week
W9
Week 9
Incident Response & Recovery

Domain 7, CRE IR/DR. OT-aware incident response, building system recovery, chain of custody, post-incident communication to tenants and investors.

~8 hrs
W10
Week 10
Practice Exam + Lab Prep

Full 80-question practice exam, timed. Review missed items by domain. Run through lab scenario exercise. Schedule your proctored exam for this week or the next.

~6 hrs + exam day
WHAT'S INCLUDED
Everything in your $500 exam registration
Full CCP-CRE Common Body of Knowledge (CBK), 300+ pages
Domain-by-domain study guide with CRE scenarios
30 practice questions with detailed answer explanations
7 CRE incident case studies (real-world scenarios)
Lab exercise workbook (OT/BAS network analysis)
Full 80-question practice exam simulator
NIST CSF 2.0 and MITRE ATT&CK ICS mapping guides
Online proctored exam scheduling, anytime, anywhere
Register, $500 →
FIRST-ATTEMPT TIPS
From candidates who passed on attempt 1
Spend extra time on Domain 2 (BAS/OT), it's 20% of the exam and the most unfamiliar for IT-background candidates
Read every case study in the CBK, exam scenarios are structured similarly
On scenario questions, think like a CRE practitioner, not a general IT auditor, tenant impact and building continuity matter
Schedule your exam for Week 10–11 when your practice scores hit 80%+
Lab section: know the standard OT network segmentation model cold

Exam Blueprint

7 DOMAINS.
CLICK TO EXPLORE.

Each domain's weight is fixed in the exam blueprint. Click any domain to see the topic breakdown, study focus, and expected question types.

1
15%
CRE Cyber Risk Framework
2
20%
Building Automation & OT Security
3
14%
Physical Access & Surveillance
4
14%
Tenant Data & Lease Risk
5
14%
Third-Party Vendor Risk
6
12%
Regulatory & Compliance
7
11%
Incident Response & Recovery
Key Topics
CRE asset classification and risk tiers
Threat actor taxonomy, nation-state, ransomware groups, opportunistic
IT/OT convergence in commercial buildings
NIST CSF 2.0 applied to CRE organizations
Risk quantification for building system compromises
CRE cyber maturity model and gap analysis
Exam Focus
Scenario: classifying risk tier for mixed-use high-rise
Application of NIST CSF tiers to CRE program maturity
Understanding attacker motivation in CRE context
Prioritizing remediation under budget constraints
Communicating risk to non-technical CRE executives
15%
of exam weight
≈ 12 questions
Key Topics
BAS/BMS architecture and attack surfaces
BACnet/IP, Modbus, LonWorks, Niagara Framework
OT network segmentation and DMZ design
Vulnerability management for legacy OT systems
OT-aware endpoint detection and response
Remote access security for OT vendors (jump servers, MFA)
Exam Focus
Identifying attack vectors through internet-exposed BAS gateways
Segmentation architecture for multi-tenant buildings
Vendor remote access controls, best practices
Incident detection in OT environments with limited visibility
Risk-based patch prioritization for Windows XP OT endpoints
20%
of exam weight
≈ 16 questions
Key Topics
IP-connected access control system security
CCTV / NVR hardening and credential management
Physical-cyber convergence incident response
Vendor account lifecycle for physical security systems
Elevator, parking, and utility system risk
Exam Focus
Attacker pivot from cyber to physical systems
Chain of custody for digital evidence from CCTV systems
Access controller privilege model and least privilege
Balancing physical safety and cyber containment during incidents
14%
of exam weight
≈ 11 questions
Key Topics
Tenant data segregation on shared building networks
Lease clause cybersecurity obligations
Tenant incident notification requirements
Major tenant cyber due diligence
Legal exposure when building systems are compromised
Exam Focus
Shared infrastructure scenarios: who owns the risk?
Contractual obligations triggered by building system incidents
Communicating cyber incidents to tenants
Evaluating tenant RFP cybersecurity requirements
14%
of exam weight
≈ 11 questions
Key Topics
OT vendor risk lifecycle management
Remote access provisioning and de-provisioning
Vendor security assessment for CRE environments
Contractual cybersecurity requirements for vendors
Managing generic/shared vendor credentials
Exam Focus
Identifying vendor account persistence after termination
Remote access architecture decisions for OT vendors
Vendor incident notification and response obligations
Due diligence for new BAS/OT vendors
14%
of exam weight
≈ 11 questions
Key Topics
SEC cybersecurity disclosure rules for REITs
NAREIT cybersecurity guidance
NIST CSF 2.0 implementation for CRE organizations
Cyber insurance for commercial real estate
Board and audit committee reporting frameworks
Exam Focus
Determining "material" cyber incident thresholds for REIT disclosure
Mapping existing controls to NIST CSF tiers
Cyber insurance coverage gaps for OT incidents
Structuring board presentations for non-technical audiences
12%
of exam weight
≈ 10 questions
Key Topics
OT-aware incident response playbooks
Building system recovery and physical safety coordination
Chain of custody for digital evidence
Post-incident tenant and investor communication
Business continuity for multi-tenant CRE properties
Exam Focus
Containment decisions when OT systems are compromised
Coordinating with law enforcement and cyber insurers
Forensic preservation in building system environments
Recovery sequencing: safety systems first
11%
of exam weight
≈ 9 questions

Study Resources

EVERYTHING YOU NEED
TO PASS

Core resources are included with your exam registration. Supplemental materials help you go deeper on specific domains.

✓ Included with Exam
CCP-CRE Common Body of Knowledge

The authoritative reference for all 7 exam domains. 300+ pages covering every topic in the exam blueprint, with CRE-specific case studies, diagrams, and real-world scenarios from commercial real estate environments.

300+ pages · PDF + Web Get with exam →
✓ Included with Exam
Domain Study Guide

Condensed, exam-focused companion to the CBK. Each domain summarized with key concepts, exam tips, and 30 practice questions with full explanations tied to the CBK. Built for active recall, not passive reading.

7 domains · Practice Q&A Get with exam →
✓ Included with Exam
Practice Exam Simulator

Full 80-question practice exam with the same domain weighting and question format as the real exam. Timed mode with a 120-minute limit, domain filter, and instant feedback with CBK references for every question.

80 questions · Timed + Untimed Get with exam →
Free Resource
NIST CSF 2.0 (Official)

The Cybersecurity Framework v2.0 from NIST. Domain 1 and Domain 6 of the CCP-CRE map directly to CSF. Understand the Govern, Identify, Protect, Detect, Respond, and Recover functions in a CRE context.

NIST · Free PDF Access at NIST →
Free Resource
MITRE ATT&CK for ICS

The ICS-specific ATT&CK matrix covers 15 techniques relevant to building automation system attacks. Domain 2 exam questions frequently reference ATT&CK ICS tactics. Essential supplemental reading for OT-domain readiness.

MITRE · Free Web/PDF Access at MITRE →
Supplemental, $35
CCP-CRE Flashcard Set

350 flashcards covering key terms, framework mappings, and protocol definitions across all 7 domains. Especially useful for memorizing BAS protocol characteristics and NIST CSF function definitions before exam day.

350 cards · Digital Add on registration →

What to Expect

EXAM DAY,
EXPLAINED

No surprises. Here's exactly how the CCP-CRE exam is structured and what you'll experience on test day.

01
Identity Verification

Online proctored exam via secure browser. Government-issued photo ID required. Workspace check by proctor. 5-minute setup process.

Online · Anytime
02
Written Exam (120 min)

80 multiple-choice and scenario-based questions. Timer displayed. Flag for review. No reference materials permitted. Average candidate uses 90–100 minutes.

80 questions · 120 min
03
Lab Exercise (30 min)

One practical scenario requiring analysis of an OT network diagram or building system configuration. Demonstrates applied competency beyond theoretical knowledge.

Scenario-based · 30 min
04
Results & Credential

Preliminary pass/fail at exam completion. Official scored results within 3 business days. Digital badge and certificate issued within 5 business days of passing.

Pass/fail same day

READY TO START
YOUR STUDY PATH?

Register for the CCP-CRE exam and get immediate access to the CBK, study guide, and practice exam simulator. Start studying today.

CBK + study guide + practice exam included · Online proctored · Schedule anytime