- What "Requirements" Actually Means for C)IHE
- The Suggested Background: Networking, TCP/IP and Linux
- What Is Not Required (and What We Couldn't Verify)
- Exam Format and Registration Mechanics
- The Twelve-Area Preparation Scope
- Readiness Check Against the Course Modules
- Sequencing Your Preparation by Module
- After You Pass: Validity, CEUs and Renewal
- Where the Credential Fits in Hiring
- Frequently Asked Questions
- Mile2 suggests about 12 months of network-technology experience, plus TCP/IP and essential Linux knowledge, before attempting C)IHE.
- Buying the course is not required to buy the exam; no mandatory degree or reference count was verified.
- The exam is 100 multiple-choice questions in roughly two hours, with a 70% minimum to pass.
- Credentials last three years and need 60 qualifying CEUs, a policy and ethics agreement, and a renewal fee.
What "Requirements" Actually Means for C)IHE
The Certified Incident Handling Engineer credential, abbreviated C)IHE, is issued by Mile2. When candidates search for its requirements, they usually want to know four things: whether they need prior experience, whether training is mandatory, what the exam itself demands, and what it takes to keep the credential afterward.
The honest picture is that C)IHE is built around a suggested background rather than a gatekeeping checklist. Mile2's reviewed public material points to practical familiarity with networks and Linux as the foundation, not a degree, a reference letter, or a documented count of job years. This article separates what the published material states from what we could not confirm, so you can plan without guessing.
The Suggested Background: Networking, TCP/IP and Linux
The reviewed outline recommends three things before you sit the exam:
- Roughly 12 months of network-technology experience. This is a suggestion, not an enforced prerequisite, and no verification mechanism was found in the reviewed material.
- Working knowledge of networking and TCP/IP. Incident handling is largely about reading traffic, logs and host behavior, so protocol fluency is the single most useful foundation.
- Essential Linux knowledge. You should be comfortable at a command line, reading logs, and understanding basic file and process concepts.
Why these three? Because the course content assumes you can follow an investigation. When the material discusses attack vectors, signs of an incident, and sources of precursors and indicators, it expects you to picture what a suspicious connection, an odd process, or an unexpected log entry looks like. Candidates who lack that mental model tend to find the detection and analysis material abstract. If that sounds like you, our C)IHE difficulty guide explains where newcomers usually struggle.
How to self-assess against the suggested background
- Can you explain what happens during a TCP handshake and why unusual connection patterns matter?
- Can you navigate a Linux system, read logs, and recognize which directories hold what?
- Have you worked with or around network devices, even in a help-desk or administration capacity?
If you answer "no" to most of these, treat the suggested background as a real gap to close rather than a formality. The exam tests incident handling concepts, but it is difficult to reason about containment or evidence handling without the underlying technical vocabulary.
What Is Not Required (and What We Couldn't Verify)
Clarity about the negatives saves candidates money and time. Based on the reviewed official material:
- Course purchase is not required to buy the exam. You may purchase the exam on its own terms, though a bundled option exists (see the pricing notes below).
- No mandatory degree was verified. The material does not make a degree a condition of testing.
- No reference count was verified. We found no requirement to submit professional references.
| Question | What the reviewed material supports |
|---|---|
| Minimum experience | About 12 months of network-technology experience is suggested |
| Required prior knowledge | Networking, TCP/IP, essential Linux |
| Mandatory course purchase | No; course is not required to buy the exam |
| Mandatory degree | None verified |
| Reference or endorsement count | None verified |
| Open-book, calculator, adaptive, remote-proctoring rules | Not verified in reviewed material |
Exam Format and Registration Mechanics
The exam is delivered online through the Mile2 Learning Management System. The published format facts are straightforward:
- 100 multiple-choice questions
- Approximately two hours of testing time
- 70% minimum to pass
The split between scored and unscored questions is not stated, and the candidate pass rate is not publicly disclosed in the reviewed official material. For a fuller discussion of what we can and cannot say about performance data, read C)IHE Pass Rate 2026: What the Data Shows and C)IHE Passing Score 2026.
Pricing as it appears in the reviewed material
The official indexed Exam Combo, which includes the exam, a simulator and a guide, was listed at USD $500 on sale against an original $795. Several details could not be verified: the bare-exam fee on its own, any member versus nonmember distinction, checkout taxes, and how long the sale runs. Treat the combo figure as a snapshot, not a guarantee, and see C)IHE Certification Cost 2026 for the full breakdown and caveats.
Scheduling windows and deadlines are covered separately in C)IHE Exam Dates 2026.
The Twelve-Area Preparation Scope
Understanding the "requirements" for passing means understanding what you must know. The reviewed course outline lists twelve substantive modules (the Module 00 introduction is excluded). These are unweighted preparation headings drawn from the course outline, not an official weighted exam blueprint, and no percentage or "largest domain" is published. Plan to cover all twelve.
Domain 1: Incident Handling Explained
The conceptual foundation. You need to distinguish an event from an incident and separate incident handling from incident response.
- What an incident is and what incident handling covers
- The difference between IH and IR
- The incident response process and why a plan matters
- Building an effective incident response team and the considerations behind it
Domain 2: Incident Response Policy, Plan and Procedure Creation
How governance documents relate to one another and to outside parties.
- Policy versus plan versus procedures
- Sharing information with outside parties
Domain 3: Incident Response Team Structure
Team models, how to choose among them, the personnel involved, and organizational dependencies.
Domain 4: Incident Response Team Services
The services a team provides: intrusion detection, advisory distribution, education and awareness, and information sharing.
Domain 5: Incident Response Recommendations
Establishing a formal incident response capability, information sharing capabilities, and building the team.
Domain 6: Preparation
One of the most hands-on areas. Note that the issuer prints this as "Chapter 06" in the same sequential list.
- Threat hunting and threat analysis frameworks
- Tools and toolkits
- Policy and procedures
- Preventing incidents
Domain 7: Detection and Analysis
Where Linux and TCP/IP fluency pay off most.
- Attack vectors and signs of an incident
- Sources of precursors and indicators
- Incident analysis, documentation, prioritization and notification
Domain 8: Containment, Eradication and Recovery
- Selecting the right containment strategy
- Gathering and handling evidence
- Identifying the attacking hosts
- Eradication and recovery
Domain 9: Post Incident Activity
Lessons learned, using collected incident data, and evidence retention.
Domain 10: Incident Handling Checklist
Why checklists matter and how to build them.
Domain 11: Incident Handling Recommendations
Recommendations, including implementing threat intelligence.
Domain 12: Coordination and Information Sharing
- Coordination and purple teaming
- Information sharing techniques, including granular information sharing
- Sharing recommendations
For a deeper treatment of each area, see C)IHE Exam Domains 2026: Complete Guide to All 12 Content Areas.
A note on the NIST model and version string
The currently linked outline carries the version string "vs.922021" and describes the older four-phase NIST 800-61 incident response model. NIST published Revision 3 on April 3, 2025, but we could not verify that Mile2 has adopted it. Keep these separate in your mind: the four-phase model is historical course content, not proof that the exam follows Revision 3. If you want to read Revision 3 for professional context, do so, but anchor your exam preparation to the Mile2 course scope.
Readiness Check Against the Course Modules
Because there is no formal eligibility gate, the practical "requirement" is honest readiness. A useful self-test is whether you can speak to a concrete scenario in each cluster below.
- Framing: Explain to a non-technical manager why an incident response plan is justified, and distinguish handling from response.
- Governance: Describe how policy, plan and procedures differ, and what you would and wouldn't share with outside parties.
- Team design: Compare team models and name the dependencies an incident team has within an organization.
- Detection: List attack vectors, signs of an incident, and where precursors and indicators come from.
- Response actions: Choose a containment strategy and justify it, then describe evidence handling and eradication.
- Closure: Explain lessons learned, how collected data is reused, and why evidence is retained.
- Collaboration: Describe coordination, purple teaming, and granular information sharing.
Key Takeaway
Treat the twelve modules as equally in scope. Because no official weights are published, any claim that one area dominates the exam is editorial speculation. Your safest strategy is balanced coverage with extra time on the areas where your networking and Linux background is thinnest, typically Detection and Analysis and Containment, Eradication and Recovery.
Sequencing Your Preparation by Module
This is the one place we'll talk methodology, and it's tied directly to the module order. The course is sequential, and later modules build on earlier vocabulary, so schedule accordingly. The weeks below are editorial pacing suggestions, not an official plan.
Foundations and Governance (Domains 1-3)
- Lock in definitions: incident, incident handling, IH versus IR
- Memorize the distinctions among policy, plan and procedures
- Compare team models
Services, Recommendations and Preparation (Domains 4-6)
- Learn the team services and the formal-capability recommendations
- Study threat hunting, analysis frameworks and toolkits
The Technical Core (Domains 7-8)
- Spend the most time here if your networking or Linux is rusty
- Practice sorting precursors from indicators and choosing containment strategies
Closure and Collaboration (Domains 9-12) plus review
- Cover lessons learned, checklists, recommendations and information sharing
- Run full-length timed practice against the 100-question, roughly two-hour format
For a complete preparation approach, see the C)IHE Study Guide 2026, and use the C)IHE cheat sheet for last-day review. You can also test yourself on the C)IHE practice test site.
After You Pass: Validity, CEUs and Renewal
Meeting the requirement to earn the credential is only half of the lifecycle. Under the current dedicated renewal policy, the key points are:
- Three-year validity for the credential
- 60 qualifying CEUs to renew
- Agreement to Mile2's policies and ethics
- Payment of the applicable renewal fee (the amount was not verified)
Where the Credential Fits in Hiring
C)IHE targets people who detect, analyze, contain and report on security incidents. Typical landing roles include security analyst, SOC analyst, incident responder, and IT or network staff moving toward security duties. The twelve-module scope maps to those daily tasks: triage, documentation, prioritization, notification, evidence handling and information sharing.
We don't cite salary figures here because none were verified for this credential. For a qualitative look at earnings and career fit, see C)IHE Salary Guide 2026, C)IHE jobs, and Is the C)IHE Certification Worth It?
One more training note: the course includes Cyber Range exercises. These support learning but do not establish a practical, hands-on component of the certification exam. The exam is the 100-question multiple-choice format described above. For training options, see C)IHE training.
Frequently Asked Questions
No mandatory degree was verified in the reviewed Mile2 material. The published guidance focuses on suggested experience and knowledge instead of formal education.
Mile2 suggests about 12 months of network-technology experience, plus knowledge of networking, TCP/IP and essential Linux. This is a recommendation, and no verification process was found.
No. The course is not required to buy the exam. A bundled Exam Combo that includes the exam, simulator and guide has been listed, but confirm current pricing before purchase.
You need a minimum of 70% on 100 multiple-choice questions, with approximately two hours allotted. The scored and unscored split is not stated in the reviewed material.
It is valid for three years. Renewal under the current policy involves 60 qualifying CEUs, agreeing to Mile2's policies and ethics, and paying the applicable renewal fee, whose amount was not verified.