BTL1 certification is the cheapest way to prove you can actually work an incident rather than describe one. The exam hands you a compromised corporate network in a browser, gives you 24 hours, and marks you on what you find. There is no multiple choice to guess your way through.
This guide covers what the Blue Team Level 1 exam tests, what it costs, what changed when the provider rebranded, and a 6-week study plan that fits around a job.
What BTL1 Is, and Who Runs It Now
Blue Team Level 1 is a junior defensive security certification aimed at people going into or already sitting in a tier 1 SOC seat. It is training and exam bundled together, so you buy the course and the exam as one product.
The provider changed name on 1 June 2026. Security Blue Team is now Centri, trading as Security Team Training Ltd. The certification itself did not change: same BTL1 name, same syllabus, same badge. What changed is where you log in and where you look things up.
Watch out: most BTL1 study advice still points at securityblue.team and its old support site. Those URLs redirect, but the current home is centri.org and students now log in at elearning.centri.org. If a guide still tells you to sign in at the old domain, it predates June 2026 and its pricing and exam detail may be stale too.
BTL1 Cost and What You Get for It
The course costs £399. That single price covers everything:
- Roughly 30 hours of course content across 330+ lessons, videos and activities
- 23 browser-based labs
- 4 months of on-demand access to the material
- Two exam attempts, not one. The first resit is free
Two attempts matters more than it sounds. Around 70% of students pass on their first go, which means roughly three in ten need the resit, and Centri builds that into the price rather than charging you again.
| BTL1 | CompTIA CySA+ (CS0-004) | ISACA CCOA | |
|---|---|---|---|
| Price | £399, training included | Exam voucher only, training extra | Exam fee only, training extra |
| Format | 24-hour practical, browser lab | Multiple choice and performance-based | Multiple choice and performance-based |
| Pass mark | 70% | Scaled score | Scaled score |
| Attempts included | 2 | 1 | 1 |
| Renewal | None, certified for life | 3-year CE cycle | Annual CPE |
| Proctored | No, open book, unproctored | Yes | Yes |
BTL1 is certified for life. There is no continuing education cycle and no annual maintenance fee, which is unusual in this market and a real saving over a career. Compare that to the renewal admin covered in our CompTIA continuing education breakdown.
What the 24-Hour Exam Actually Tests
The exam gives you in-browser access to a compromised corporate lab for up to 24 hours. You work 20 task-based questions against that environment, using real tools to investigate what happened. Questions push you towards identifying attack vectors and mapping them to the MITRE ATT&CK framework rather than reciting definitions.
You need 70% to pass. Score 90% or higher on your first attempt and you get the gold challenge coin, which is the flex people post about on LinkedIn.
The format is open book and unproctored. You can sit it at home or at work, and you are allowed to use the course material, your own notes and search engines.
Exam Tip: AI assistants are explicitly banned. Centri's exam rules prohibit ChatGPT, Gemini, Copilot or any similar tool, and treat AI help the same as asking another person. That counts as cheating and can disqualify you. Build your own notes, because they are the thing you are actually allowed to use.
The six domains are:
- Security Fundamentals
- Phishing Analysis
- Threat Intelligence
- Digital Forensics
- SIEM
- Incident Response
Centri does not publish percentage weightings per domain, so treat anyone quoting exact weights with suspicion. What the exam structure tells you is more useful: the tasks sit inside one connected incident, so phishing analysis, forensics and SIEM work all feed the same investigation. Studying the domains as six separate silos is the mistake most people make.
The Real Difficulty: Time and Notes, Not Knowledge
BTL1 is not a hard exam on knowledge. The content is junior level and the labs teach you the tools directly. Candidates who fail generally fail for one of three reasons:
- They burn the clock. Twenty-four hours sounds generous until you spend four of them on one artefact. People who pass typically finish in 8 to 14 hours and sleep in the middle.
- They have no notes. Open book only helps if you built something searchable while working through the labs. Scrolling the course platform mid-exam is slow.
- They studied passively. Watching the videos without doing the 23 labs leaves you knowing the concept and not the tool.
The 6-Week BTL1 Study Plan
This assumes 8 to 10 hours a week. The course itself is about 30 hours of content, so the extra time goes into labs, notes and repetition. Your 4-month access window gives you plenty of slack if life interferes.
Week 1: Security Fundamentals and your note system
Work through Security Fundamentals in full. More importantly, set up how you will take notes before you learn anything worth writing down. One searchable document or a simple Obsidian vault, organised by task type rather than by course module. Headings like "extract headers from a suspicious email" beat headings like "Phishing Analysis Lesson 4".
Week 2: Phishing Analysis
Complete the phishing labs twice. The second run, do it without looking at the walkthrough and write your own procedure as you go. Header analysis, attachment triage and URL defanging are all exam-day tasks, and all three are faster from your own notes than from the platform.
Week 3: Threat Intelligence and OSINT
This domain is the lightest on tooling and the easiest to underestimate. Focus on mapping observed behaviour to ATT&CK techniques, because that framing shows up in exam tasks. Practise going from an indicator to a named technique to what you would check next.
Week 4: Digital Forensics
The heaviest week. Work every forensics lab, then repeat the ones involving memory and disk artefacts. Write down the exact commands and the exact menu paths for each tool. Exam scoring rewards finding the artefact, and a command you have to reconstruct from memory costs you 15 minutes each time.
Week 5: SIEM and Incident Response
Spend the first half on SIEM queries and the second half on the incident response process. These two tie the other domains together, which is how the exam presents them. Practise moving from a SIEM alert to the forensic artefact that explains it.
Week 6: Full dry run and notes cleanup
Re-run three or four labs end to end under a self-imposed time limit. Then spend a full session doing nothing but reorganising your notes so anything you need is two searches away. Book the exam for the start of a weekend so you have the full 24 hours without work in the middle.
Take a rest day before you sit it. A 24-hour exam is an endurance event and starting tired is the most avoidable mistake on this list.
Is BTL1 Worth It Before or Instead of CySA+?
BTL1 and CySA+ do different jobs. BTL1 proves you can perform an investigation. CySA+ is the one that clears HR filters, appears in job adverts by name and satisfies DoD 8140 requirements in US government roles.
The practical answer for most people: BTL1 first if you are trying to get into a SOC and have nothing hands-on to show, CySA+ alongside or after if you need a name recruiters already screen for. Our SOC analyst certification path guide covers how these stack against each other now that AI handles a lot of tier 1 triage.
If you are going the CompTIA route as well, our 8-week CySA+ CS0-004 study plan runs on the same schedule shape as the plan above.
Frequently Asked Questions
Is the BTL1 certification worth it?
For a junior defensive role, yes. At £399 with training, two exam attempts and no renewal fee, it is one of the cheapest practical certifications available, and the 24-hour hands-on exam gives you something specific to talk about in an interview. It carries less recruiter name recognition than CySA+, so it works best as a demonstration of skill rather than as the only certification on your CV.
How much does BTL1 cost?
£399, which includes the course, 23 browser labs, 4 months of access and two exam attempts. There are no renewal fees because the certification does not expire.
Is the BTL1 exam hard?
The knowledge level is junior and the exam is open book, so it is not difficult in the way a closed-book exam is. The difficulty is time management across 20 tasks in 24 hours and having usable notes. About 70% of students pass first time.
What is BTL1 certification?
Blue Team Level 1 is a junior defensive cybersecurity certification from Centri, formerly Security Blue Team. It bundles around 30 hours of training with a 24-hour practical incident response exam covering security fundamentals, phishing analysis, threat intelligence, digital forensics, SIEM and incident response.
How long does it take to prepare for BTL1?
Six weeks at 8 to 10 hours a week is realistic for someone with basic IT knowledge. People already working in a SOC often do it in three or four. Your course access runs for 4 months, so there is room to go slower.
Ready to Start Practising?
BTL1 rewards repetition on the tools, and the same is true of every exam that sits next to it on a SOC job advert. If CySA+ or CCOA is the next step after your challenge coin, CertCrush has practice questions and full exam simulations for both.
Create your free CertCrush account and start with the CySA+ CS0-004 practice exams or the ISACA CCOA course.
