KCSA vs CKS: Security Fundamentals or the Hands-On Specialist Exam?

KCSA vs CKS compared: format, prerequisites, difficulty and career value of the two CNCF Kubernetes security certifications — and the recommended path between them.

4 min de lecture

Short answer: these two certs are not competitors — they sit at opposite ends of the same security track. KCSA (Kubernetes and Cloud Security Associate) is a multiple-choice fundamentals exam with no prerequisites. CKS (Certified Kubernetes Security Specialist) is a hands-on lab exam that you cannot register for without having passed CKA first. If you're early in the security journey, take KCSA now and plan CKS after CKA. Both are available through Linux Foundation Training & Certification.

KCSA vs CKS at a glance#

KCSACKS
Full nameKubernetes and Cloud Security AssociateCertified Kubernetes Security Specialist
LevelAssociate (entry)Specialist (advanced)
Exam typeMultiple-choice, 90 minutesPerformance-based lab, 2 hours
PrerequisitesNoneMust have passed CKA (it does not need to be current)
FocusSecurity concepts: threat model, the 4Cs, compliance frameworks, platform security overviewApplied hardening: cluster setup, minimizing microservice vulnerabilities, supply chain security, runtime monitoring
AudienceSecurity-curious engineers, analysts, juniors, managers who need the landscapePlatform engineers and DevSecOps practitioners who harden production clusters

What each exam actually tests#

KCSA verifies that you can reason about Kubernetes security: where the attack surface is, what the cloud native security model (code, container, cluster, cloud) means, how Pod Security Standards and admission control fit together, and which compliance frameworks apply. Nothing in the exam requires touching a terminal.

CKS assumes all of that and then hands you a live cluster: write NetworkPolicies, configure AppArmor and seccomp profiles, scan images for CVEs, lock down the kubelet and API server, detect suspicious runtime behaviour with Falco. It is widely considered the hardest of the five CNCF Kubernetes exams because it layers security tooling on top of CKA-level operational speed.

Decision rules#

  • Take KCSA now if you want a recognized security credential without the CKA gate, you're in a governance/analyst role, or you're validating whether cloud native security is your direction before committing months of prep.
  • Target CKS if you already hold CKA (or will soon) and your work involves securing real clusters — CKS is the credential that moves the needle for DevSecOps and platform security roles.
  • Do both if you're building a deliberate security ladder: KCSA teaches the vocabulary and threat model that CKS assumes you already know.

For someone starting from limited Kubernetes experience and aiming at security specialization, the sequence that avoids wasted effort is: KCNA → KCSA → CKA → CKS. The two associate exams are cheap, fast wins that build the conceptual base; CKA establishes the operational fluency CKS demands; CKS caps the track. If you already administer clusters, compress it to CKA → CKS and read the KCSA curriculum as free study material. Our KCSA guide and CKS guide break down each exam's domains.

Cost and bundles#

KCSA is priced as an associate exam (roughly half of CKS). Both include a free retake and a year of eligibility. If you plan to complete the whole track, the Kubestronaut bundle covers all five CNCF exams at a significant discount over buying them individually.

FAQ#

Is KCSA a prerequisite for CKS?#

No. The only prerequisite for CKS is having passed the CKA exam — and per the Linux Foundation, that CKA does not need to be current or active. KCSA is optional but useful preparation.

Is KCSA worth it if I plan to take CKS anyway?#

If budget allows, yes — it forces you through the threat-modeling and compliance material that CKS touches but doesn't teach. If budget is tight, study the KCSA curriculum without sitting the exam and put the money toward CKS prep.

Which certification do security job postings ask for?#

CKS appears in platform security and DevSecOps postings; KCSA is too new and too introductory to be a hiring filter. Treat KCSA as a learning milestone and CKS as the market credential.

How hard is CKS compared to CKA?#

Harder for most people. You need CKA-level speed plus working knowledge of security tooling (Falco, Trivy, AppArmor, OPA/Gatekeeper) under the same time pressure.

Sources#

Questions fréquentes

Is KCSA a prerequisite for CKS?
No. The only prerequisite for CKS is having passed the CKA exam. Per the Linux Foundation, the CKA does not need to be current or active. KCSA is an optional fundamentals exam with no prerequisites of its own.
Should I take KCSA or CKS first?
KCSA first if you're building foundations — it has no prerequisites. CKS requires having passed CKA, so the full security path is KCNA → KCSA → CKA → CKS.
Is CKS harder than KCSA?
Significantly. KCSA is a 90-minute multiple-choice exam on security concepts; CKS is a 2-hour hands-on lab where you harden live clusters with tools like Falco, Trivy and NetworkPolicies.
Where do I register for KCSA or CKS?
Both exams are administered through the Linux Foundation Training & Certification portal, with bundle and retake options included.

Besoin d’aide sur un projet IA ou plateforme ?

Je suis Gatien, consultant en automatisation IA et infrastructure. Réservez un appel intro gratuit de 15 minutes — sans engagement.