- What the Data Actually Shows About the CHS-CY1 Pass Rate
- What CodeHS Publishes (and What It Doesn't)
- Format and Passing Score: The Numbers You Can Rely On
- Why a Single Pass Rate Would Be Misleading
- Where Candidates Tend to Lose Points: Six Domains
- Attempt Mechanics: Vouchers, Retakes, and Expiry
- A Domain-Ordered Readiness Plan
- Who Takes This Exam and Why
- Frequently Asked Questions
- CodeHS does not publish a CHS-CY1 pass rate, so any specific percentage you see online is unverified.
- The exam has 45 multiple-choice questions, a 90-minute limit, and a 60% passing score.
- Sixty percent of 45 questions means you need at least 27 correct answers.
- Six content domains are tested, and CodeHS publishes no percentage weights for them.
What the Data Actually Shows About the CHS-CY1 Pass Rate
If you searched for the CodeHS Cybersecurity Level 1 pass rate hoping for a tidy percentage, here is the honest answer: CodeHS has not published one. The official exam overview and the Certifications FAQ describe the format, the topics, the timing, and the passing score, but neither document reports how many candidates pass on a first or any attempt.
That matters because pass-rate figures circulate widely for certification exams, and many of them are recycled from unrelated credentials. The acronym "CHS-CY1" in particular is easy to confuse with other programs, so numbers you find on forums or aggregator sites may describe a completely different exam. On this site, every fact is tied to CodeHS Cybersecurity Level 1 and its official sources, which means we will not give you a number we cannot support.
What we can do is lay out the verified data points that determine how hard it is to pass: the question count, the time limit, the passing threshold, and the six content domains. Those facts let you build a realistic picture of readiness without relying on a made-up statistic. For a broader take on difficulty, see our guide on how hard the CHS-CY1 exam really is.
What CodeHS Publishes (and What It Doesn't)
It helps to separate what is confirmed from what is not. The table below summarizes the current public picture of the exam.
| Item | Status | Detail |
|---|---|---|
| Number of questions | Published | 45 multiple-choice questions |
| Exam delivery | Published | Online timed exam |
| Time limit | Published | 90 minutes |
| Passing score | Published | 60% (the exception in the FAQ is the Java exam, not this one) |
| Prerequisites | Published | None |
| Credential expiry | Published | 10 years |
| Retake mechanics | Published | New voucher required for each attempt |
| Overall pass rate | Not published | No official figure |
| Domain weights | Not published | Six topic headings, no percentages |
| Exam fee | Not in our supplied sources | Check CodeHS directly for current pricing |
The gaps are as informative as the facts. Because domain weights are not published, you cannot safely skip a domain on the theory that it is lightly tested. Because no pass rate is released, you cannot calibrate your effort against a benchmark. The sensible response is to prepare across all six areas and verify readiness with timed practice. Our complete guide to the six content areas breaks down each one.
Format and Passing Score: The Numbers You Can Rely On
The exam is a single timed sitting of 45 multiple-choice questions in 90 minutes. That works out to an average of two minutes per question, which is generous for recall-style items but tighter for questions that ask you to interpret a snippet, such as a SQL query or a command-line instruction.
The passing score is 60%. Applied to 45 questions, that means you need 27 correct answers to reach the threshold (27 ÷ 45 = 60%). Put differently, you can miss up to 18 questions and still pass. This is a useful reframe: you do not need mastery of every sub-topic, but you do need broad, dependable coverage, because missing entire domains would put the 27-question line out of reach.
Note that because the exam is all multiple choice, there are no coding labs or free-response sections to worry about. Your preparation should therefore emphasize recognition and reasoning: identifying an attack type from a description, choosing the correct cipher method, or deciding which network device performs a given function.
Why a Single Pass Rate Would Be Misleading
Even if CodeHS did publish an aggregate number, it would tell you less than you might expect. Several characteristics of this certification make a single percentage a poor predictor of your own outcome.
- No prerequisites. Anyone can attempt the exam, from a motivated student who completed the recommended course to someone who walks in cold. A pooled rate blends these very different groups.
- Course-linked preparation. CodeHS recommends its Fundamentals of Cybersecurity course. Candidates who completed it are studying the same material the exam draws on, while others are not, which splits outcomes sharply.
- Classroom context. CodeHS credentials are commonly attempted through school and instructor settings, where preparation level, class time, and teacher guidance vary enormously from one program to the next.
- Voucher-per-attempt structure. Because each attempt needs a new voucher, candidates who feel unready may defer rather than fail, which shapes any statistic that counts only completed attempts.
The takeaway is that your personal readiness is a far better indicator than any published average. Rather than asking "what percent pass," ask "can I reliably score above 27 on a fresh set of 45 timed questions across all six domains?" That is a question you can answer yourself using the CHS-CY1 practice tests.
Where Candidates Tend to Lose Points: Six Domains
The official exam lists six topic headings. We do not have official weights, so the guidance below is qualitative: it describes the kind of thinking each domain demands and the traps that commonly cost points on multiple-choice items.
Domain 1: Cybersecurity Essentials
This is the conceptual entry point, covering threats and ethics. Questions often present a short scenario and ask you to name the threat or principle involved.
- Distinguish ransomware from phishing by how each reaches and affects a victim.
- Know the three parts of the CIA Triad and be able to map a scenario to confidentiality, integrity, or availability.
- Understand Internet of Things security concerns.
- Separate legal from illegal hacking, and know the basics of cyber ethics, credit, and copyright.
Domain 2: Cryptography
This domain rewards procedural understanding. Expect questions where you must apply or recognize a method, not just define it.
- Caesar cipher: a fixed shift, and why it is easy to break.
- Vigenere cipher: a keyword-driven shift that resists simple frequency analysis better than Caesar.
- Brute force versus frequency analysis as code-breaking approaches.
- Basic cryptography vocabulary and the goal of encryption.
Domain 3: System Administration
Practical, hands-on knowledge shows up here. Candidates who have never used a terminal often find the command-line items the least intuitive.
- Operating systems and what they manage.
- Software licenses and their implications.
- Application security and browser behavior.
- Basic command line system tasks and administrator responsibilities.
Domain 4: IT Concepts
This is the networking-fundamentals domain, and it is detail-heavy. Precise distinctions matter.
- IPv4 versus IPv6 and the structure of internet addresses.
- The DNS hierarchy and how names resolve to addresses.
- Routing and how packets find a path.
- Packets and protocols, including what each layer of communication does.
Domain 5: IT Infrastructure
Hardware and network components dominate. Many questions are matching-style: given a function, pick the device or option.
- Internal components and peripheral devices.
- Network devices and what each one does.
- Storage options and network options, with their trade-offs.
- Network communication and network management.
Domain 6: Digital Safety and Data Security
This domain blends personal safety topics with introductory technical security. The SQL items trip up candidates who skipped database basics.
- Digital footprint, cyberbullying, and internet safety.
- Clients and servers and how they interact.
- Reading basic SQL queries.
- Recognizing SQL injection and understanding why it works.
- Developer tools and what they reveal.
Because the domains differ so much in style, from conceptual (Domain 1) to procedural (Domain 2) to terminology-dense (Domains 4 and 5), a candidate strong in one can still be weak in another. That is exactly why aggregate pass-rate statistics are less useful than a per-domain self-check. Our one-page cheat sheet is a handy way to review the must-know facts from each area.
Attempt Mechanics: Vouchers, Retakes, and Expiry
A few administrative facts shape how you should think about risk. CodeHS states that a new voucher is required for each exam attempt. In practical terms, a failed or abandoned attempt does not automatically grant another try; you need a fresh voucher to sit the exam again. This is the strongest argument for preparing thoroughly before your first attempt rather than treating it as a trial run.
Also worth noting:
- No prerequisites: You do not need prior certifications or coursework to register, though the CodeHS Fundamentals of Cybersecurity course is the recommended preparation. See our requirements and eligibility guide for details.
- 10-year expiry: CodeHS states certification credentials expire after 10 years, which is a long validity window compared with many industry credentials.
- Fee details: We have not confirmed current pricing from the supplied official sources, so check CodeHS directly. Our cost breakdown explains how to think about the expense.
- Scheduling: Availability and timing details are covered in our exam dates guide.
Key Takeaway
Since every attempt needs its own voucher, treat your first sitting as the real thing. Hit at least 33 of 45 on timed practice sets across all six domains before you redeem a voucher, giving yourself a buffer above the 27-question passing line.
A Domain-Ordered Readiness Plan
You do not need a complicated system, but the order in which you tackle the domains does matter. The plan below sequences them so that foundational vocabulary comes first and the detail-heavy networking material gets repeated exposure. Adjust the pace to your calendar.
Cybersecurity Essentials and Digital Safety
- Learn the CIA Triad, ransomware, phishing, and IoT concepts.
- Cover digital footprint, cyberbullying, and internet safety.
- Take a short diagnostic quiz to see your starting level.
Cryptography and System Administration
- Work through Caesar and Vigenere examples by hand.
- Compare brute force against frequency analysis.
- Practice basic command line tasks in a real terminal.
IT Concepts and IT Infrastructure
- Memorize IPv4 versus IPv6 differences and the DNS hierarchy.
- Build a device-to-function chart for network devices and storage options.
- Revisit packets, protocols, and routing.
SQL, Injection, and Full Timed Practice
- Read simple SQL queries and spot injection patterns.
- Take full 45-question sets in 90 minutes.
- Review every miss and map it back to its domain.
This sequencing puts the two most detail-dense domains, IT Concepts and IT Infrastructure, in the middle of your schedule so you can revisit them during Week 4 practice. For a complete, step-by-step plan, see the CHS-CY1 study guide, and for course-aligned preparation, our overview of CHS-CY1 training options may help.
Who Takes This Exam and Why
Understanding the candidate pool helps interpret any talk of "pass rates." CodeHS Cybersecurity Level 1 is an introductory credential with no prerequisites, aimed at learners beginning to build cybersecurity literacy, often alongside the CodeHS Fundamentals of Cybersecurity course. It is best understood as an early signal of foundational knowledge rather than a senior-level professional certification.
That context affects how you weigh its value. It can support a student's portfolio, demonstrate initiative on a college or internship application, and provide a structured checkpoint before moving on to more advanced material such as Cybersecurity Level 2, which is a separate certification with its own topics. If you are weighing the investment, our ROI analysis and overview of related roles discuss what the credential can and cannot do for you. For earnings context, see the salary guide, which stays qualitative where official figures do not exist.
Frequently Asked Questions
CodeHS has not published an official pass rate for Cybersecurity Level 1. Any specific percentage you encounter online is unverified and may belong to a different credential that shares the acronym. Rely on the published facts instead: 45 questions, 90 minutes, and a 60% passing score.
With a 60% passing score on a 45-question exam, you need at least 27 correct answers. That allows up to 18 incorrect answers, but because domain weights are not published, you should prepare across all six content areas rather than counting on skipping any.
CodeHS states that a new voucher is required for each exam attempt. A retake is therefore possible but requires obtaining another voucher, which is why thorough preparation before your first attempt is worthwhile.
No. CodeHS lists no prerequisites. It does recommend the CodeHS Fundamentals of Cybersecurity course as preparation, since it aligns with the six topic areas the exam covers.
CodeHS states that certification credentials expire after 10 years. For definitions and background on the credential itself, see what CHS-CY1 is, then use the practice test site to measure your readiness against all six domains.