Skip to content

Certified Cloud Native Platform Engineer (CNPE)

The first performance-based platform engineering certification — two hours in a live cluster building GitOps pipelines, platform APIs and self-service provisioning, with half the marks on those two domains alone.

The Linux Foundation / CNCF
Exam cost
$445 USD (exam only, includes one retake); $625 USD bundled with a Full Access Subscription
src
Linux Foundation Training & Certification — Certified Cloud Native Platform Engineer (CNPE) certification page (training.linuxfoundation.org)
chk
Duration
120 minutes
Passing score
Not publicly disclosed by the Linux Foundation — performance-based cut scores are set per exam, and unlike the LFCS this one is unpublished
Valid for
2 years

Platform engineering spent five years as a job title with no exam behind it. The CNPE is the first hands-on attempt to fix that, and the blueprint is unusually honest about what it thinks the job is.

Where the marks actually are

Half the exam — 50% — is two domains: GitOps and Continuous Delivery at 25%, and Platform APIs and Self-Service Capabilities at 25%. Everything else splits the remainder: observability and operations at 20%, architecture and infrastructure at 15%, security and policy at 15%.

That weighting is an argument. It says a platform is a set of APIs other engineers consume without asking you, delivered by a pipeline that reconciles itself. The domain that would have dominated a DevOps exam — build the infrastructure — is the smallest one here at 15%, and it is mostly about cost and multi-tenancy rather than provisioning.

The practical consequence: if your platform work has been Terraform modules and Helm charts, you have prepared for the smallest domain. Writing a CustomResourceDefinition that models a service, and putting an operator behind it, is where a quarter of the marks live and where most candidates have the least practice.

The unfamiliar-tool clause

The curriculum lists fifteen tools it may draw on, then adds something no other CNCF exam says so plainly: candidates are expected to complete tasks using unfamiliar tools by relying on the help and documentation available in the exam, and will not be tested on deep tool-specific knowledge unless a competency names it.

Read that as an instruction rather than a reassurance. It means memorising Argo CD's flags is the wrong preparation, and knowing what a GitOps reconciler must do — so you can find it in any tool's docs within a two-hour clock — is the right one. It also means the exam is partly testing whether you read documentation quickly under pressure, which is a fair description of the job.

Against the CNPA

These are not two difficulties of one exam, they are two different claims. The CNPA is multiple-choice, $250, and spends 36% of its marks on core fundamentals — it establishes that you know what an internal developer platform is. The CNPE has no fundamentals domain, costs $445, and puts you in a terminal.

The blueprints barely overlap. Someone who passed the CNPA has not half-prepared for the CNPE; they have learned the vocabulary the CNPE assumes you already had.

Before you book

Build one self-service path end to end. A CRD, an operator or Crossplane composition behind it, a GitOps reconciler deploying it, a policy engine admitting it and a dashboard showing it. That single exercise touches four of the five domains, and it is closer to the exam than any course.

Use both simulator attempts. They are included in the price and are traditionally harder than the exam. Sitting the first one early — before you feel ready — is what turns them into a study plan rather than a verdict.

The cut score is not published. The Linux Foundation discloses 75% for its multiple-choice exams and 67% for the LFCS, and says nothing about this one. Specific numbers in study guides are inferred from score reports, not stated by the vendor.

New to Linux and the command line?

This path assumes fundamentals you may not have yet. Our Foundations Pack is out and free — Linux, the shell and Git, with exercises that mark your work and explain why you got it wrong. We're writing an agents pack next; leave your email if you want to hear when it ships.

One email when the pack launches. No spam, unsubscribe any time.

Your progress0%

Exam domains

GitOps and Continuous Delivery

25%
Implementing GitOps Workflows for Application and Infrastructure DeploymentBuilding and Configuring CI/CD Pipelines Integrated with KubernetesDeploying Applications Using Progressive Delivery Strategies (e.g., Blue/Green or Canary)

Platform APIs and Self-Service Capabilities

25%
Designing and Creating Custom Resource Definitions (CRDs) for Platform ServicesImplementing Workflows for Self-Service Provisioning Using Platform APIsUsing Kubernetes Operators for Platform Automation and IntegrationUsing Automation Frameworks for Self-Service Provisioning

Observability and Operations

20%
Implementing Monitoring, Alerting, Logging, and Tracing SolutionsMeasuring and Improving Platform Efficiency Using Deployment Metrics and Performance IndicatorsDiagnosing and Remediating Platform Issue and Incident Scenarios

Platform Architecture and Infrastructure

15%
Applying Platform Architecture Best Practices for Networking, Storage, and ComputeUsing Cost Management Solutions for Right-Sizing and ScalingOptimizing Multi-Tenancy Resource Usage

Security and Policy Enforcement

15%
Configuring Secure Service-to-Service CommunicationApplying RBAC and Security Controls Across Platform ResourcesGenerating Audit Trails and Enforcing Policy Compliance (SBOM, Compliance Reports, etc.)Using Policy Engines and Admission Controllers for GovernanceIntegrating Security Scanning and Compliance Checks into Deployment Pipelines

Preparation path

  1. 1

    Read the curriculum and the CNCF platforms white paper before touching a tool

    The exam blueprint names eighteen competencies and the white paper explains the product thinking behind them. Half an afternoon here decides what you practise for the next two months, and the blueprint is the only document that tells you the weights.

    ~4 hours
  2. 2

    Build a GitOps pipeline end to end — this is 25% of the exam

    Reconcile an application and its infrastructure from Git with Argo CD or Flux, then put a progressive rollout in front of it. Do the blue/green and the canary yourself rather than reading about them: the exam asks you to configure one, not to define it.

    ~25 hours
  3. 3

    Expose a platform API with a CRD and an operator — the other 25%

    Write a CustomResourceDefinition that models a service your platform offers, then make something reconcile it. Crossplane covers the provisioning half. This domain is where platform engineering stops being DevOps with a new title, and the exam weights it accordingly.

    ~30 hours
  4. 4

    Instrument the platform itself, then break it and fix it under time

    Monitoring, alerting, logging and tracing, plus the deployment metrics that say whether the platform is any good. The third competency here is diagnosing and remediating incidents, which in a performance-based exam means a broken cluster and a clock.

    ~18 hours
  5. 5

    Enforce policy with an admission controller, and sign what you ship

    Kyverno and OPA Gatekeeper both appear on the tool list, so learn the admission-control model rather than one syntax. Add mTLS between services and an audit trail, and you have covered a domain that is only 15% but sits across every task.

    ~15 hours
  6. 6

    Put a number on multi-tenancy and cost before exam day

    The smallest domain, and the one platform engineers most often skip. Right-sizing, scaling and shared-tenant resource usage are examinable, and OpenCost is the tool the blueprint points at. A weekend is enough to stop this being three lost marks.

    ~10 hours
  7. 7

    Sit both Killer.sh simulator attempts, and sit them early

    The simulator is included in the exam price and is harder than the exam. Take the first one before you feel ready — its value is showing you which of the eighteen competencies you cannot do under a clock, while there is still time to fix it.

    ~12 hours

Frequently asked questions

Career Roadmaps