AAQ Cyber Security, often written as AAQ cybersecurity, is the OCR Level 3 Cambridge Advanced National in Cyber Security (H037) and Cyber Security and Networks (H137), first taught from September 2026. It is assessed through two written exams, F193 Fundamentals of cyber security and F194 Fundamentals of networks, plus coursework units set by OCR and marked by your centre, starting with F195 Preventing cyberattacks. This guide covers the whole qualification: what is in each unit, how the exams work, how the coursework is graded, and how to revise for a specification that has no past papers yet.
What is AAQ Cyber Security?
AAQ Cyber Security is a Level 3 Alternative Academic Qualification awarded by OCR, part of Cambridge University Press and Assessment, and it comes in two sizes: the Certificate (H037), which is 150 guided learning hours, and the Extended Certificate (H137), which is 360 guided learning hours and the same size as one full A Level. The full title of the larger qualification is the Cambridge OCR Level 3 Alternative Academic Qualification Cambridge Advanced National in Cyber Security and Networks.
The letters AAQ matter. An Alternative Academic Qualification is designed to be academically rigorous and to sit alongside A Levels in a sixth form or college study programme, not to replace them with a vocational alternative. It appears in the Department for Education's 16 to 19 performance tables in the Alternative Academic Qualifications category, meets funding approval criteria, and is recognised in the UCAS tariff tables.
The subject matter is genuinely applied. You learn why cyber security matters to individuals, organisations and society; who attacks systems and what motivates them; how vulnerabilities arise in people, buildings and technology; and what actually stops attacks, from firewalls and intrusion detection through to written user policies. On the Extended Certificate you also learn how networks are built, addressed and measured, because you cannot secure a network you do not understand. The coursework then puts all of it into practice on a scenario organisation: assessing risk, auditing existing defences, and designing the policies and measures that close the gaps.
There is no programming requirement. This is the main structural difference between AAQ Cyber Security and A Level Computer Science, and it is the reason many students choose it: the emphasis is on threat, risk, network fundamentals and defensive design rather than on writing code.
- Pearson or BTEC AAQ IT. Pearson runs its own Alternative Academic Qualification in IT which contains a cyber security and incident management unit. Different awarding body, different unit codes, different content. Revision material written for it will not match F193 or F194.
- OCR Cambridge Technicals Unit 3 Cyber Security. That is the older OCR suite which the Cambridge Advanced Nationals replace. Its content overlaps in places but its assessment and unit codes are completely different.
- OCR A Level Computer Science (H446). A separate, programming-heavy A Level with its own structure, papers and grade scale.
- T Level Digital Support Services. A much larger Level 3 qualification with a mandatory industry placement, equivalent to three A Levels.
- AAQ Computing. The sister Cambridge Advanced National, in Computing: Application Development (H029 and H129), with units F160 to F166. Same qualification family, entirely different subject content.
Qualification Structure: H037 Certificate vs H137 Extended Certificate
The Certificate (H037) is 150 guided learning hours and needs two units. The Extended Certificate (H137) is 360 guided learning hours and needs five. The smaller qualification is nested inside the larger one, so F193 and F195 are common to both and nothing is wasted if a centre offers only the Certificate.
| Feature | H037 Certificate | H137 Extended Certificate |
|---|---|---|
| Full title | Cambridge Advanced National in Cyber Security | Cambridge Advanced National in Cyber Security and Networks |
| Qualification number | 610/6207/8 | 610/6208/X |
| Guided learning hours | 150 | 360 |
| Total qualification time | 200 | 500 |
| Size comparison | Roughly half an A Level | One full A Level |
| Units required | 2: one exam, one NEA | 5: two exams, three NEA |
| Examined units | F193 | F193 and F194 |
| Mandatory NEA | F195 | F195 |
| Optional NEA | None | Two from F196, F197, F198, F199 |
| Exam weighting | 50 per cent | 40 per cent |
| NEA weighting | 50 per cent | 60 per cent |
| Maximum uniform marks | 120 | 300 |
| Registration code | A024 for both, entered at the start of the course | |
Both qualifications are offered in England only, are approved for ages 16 to 18, 18 plus and 19 plus, and have no formal entry requirements: there is no specific qualification you must already hold before starting. Both are graded Distinction*, Distinction, Merit and Pass.
If you are choosing between them, the practical difference is networks. The Extended Certificate adds F194 Fundamentals of networks and two optional coursework units, which is what turns the qualification from an introduction to cyber security into a full A Level equivalent covering both security and the networks it protects.
All Seven AAQ Cyber Security Units at a Glance
There are seven units in the suite: two examined and five non-examined. F193 and F195 are mandatory for both qualification sizes, F194 is mandatory for the Extended Certificate, and the remaining four are the optional coursework units from which Extended Certificate students choose two.
| Unit | Title | GLH | Assessment | H037 | H137 |
|---|---|---|---|---|---|
| F193 | Fundamentals of cyber security | 75 | Exam, 1h15, 60 marks | Mandatory | Mandatory |
| F194 | Fundamentals of networks | 70 | Exam, 1h15, 60 marks | Not used | Mandatory |
| F195 | Preventing cyberattacks | 75 | NEA, 24 criteria | Mandatory | Mandatory |
| F196 | Digital forensic investigation | 70 | NEA, 24 criteria | Not used | Optional |
| F197 | Penetration testing and incident response | 70 | NEA, 24 criteria | Not used | Optional |
| F198 | Implementing secure local area networks (LANs) | 70 | NEA, 24 criteria | Not used | Optional |
| F199 | Designing and communicating secure global computing systems | 70 | NEA, 24 criteria | Not used | Optional |
Every unit is mapped to four performance objectives, and knowing which is which explains how questions are written. PO1 is showing knowledge and understanding and is assessed in the exams only. PO2 is applying knowledge and understanding. PO3 is analysing and evaluating. PO4 is demonstrating and applying practical skills and processes, and is assessed in the NEA units only. In the exams, PO3 carries 12.5 per cent of the Certificate and 10 per cent of the Extended Certificate, which is why the extended response questions matter so much: they are where the analysis and evaluation marks live.
F193 Fundamentals of Cyber Security: Revision by Topic Area
F193 is a 75 guided learning hour unit examined by a 1 hour 15 minute paper worth 60 marks. It has six topic areas, and the paper samples content from all six, so there is no topic you can afford to skip. The exam is built around a short scenario that develops through the paper, and includes one six mark and one nine mark extended response question with levels of response mark schemes.
Topic Area 1: The cyber security landscape
The foundations, and the topic most heavily reused everywhere else. You need cyber security defined, and its importance to individuals, to organisations and to society. Then three frameworks: the CIA triad (confidentiality, integrity, availability), the IAAA principles (identification, authentication, authorisation, accountability), and risk management, where risk is impact multiplied by probability, and mitigations split into proactive and reactive.
Next, the seven incident types: destruction of data, environmental and physical, inaccessibility of data, information disclosure, modification of data, theft (of finance, identity, industrial secrets or military secrets) and unauthorised access. Incidents can be accidental or deliberate, and you need to be able to say which. Then targets, split into human (individuals, organisations, nation states) and system (data classifications, data at rest and in transit, devices, six server types, wired and wireless networking, and onsite or cloud storage). Finally the twelve actors, from script kiddie to nation state, and their motivations from thrill to political gain.
Topic Area 2: Cyber security vulnerabilities
How attackers actually get in. The vulnerability vectors are cloud, direct network access, email and social media, removable media, third party access through suppliers or workers, and wireless networks, and for each one you need how access is gained plus its advantages and disadvantages for the organisation.
Then physical vulnerabilities, which are mostly human: not following policies, competency levels, poor policies, poor screening, poor data habits, malicious employees, disguised criminals, state sponsored actors, targeted attacks and social engineering, alongside failures of access control such as recycled door codes and unnecessary access rights. Natural disasters sit here too. Finally the digital methods: botnets, malware, DoS and DDoS, hacking, lack of supplier support, malicious spam, man in the middle, and out of date software, hardware and firmware.
Topic Area 3: Impact of cyber security events
The shortest topic area and the one most likely to appear as an extended response question, because it rewards developed answers. Three headings: disruption (financial, information, operational, service), loss (data availability, financial, identity, integrity, reputation and customer confidence) and safety (financial, personal, society, transport systems, utilities and services). The specification asks for effects in the short and long term and across a range of targets, so an answer that only covers immediate financial cost to one organisation is capped.
Topic Area 4: Cyber security mitigations
The largest topic area by content. Endpoint mitigation measures covers around twenty named controls: air gap, anomaly based systems, anti-malware, anti-virus, backup, cryptography, encryption at rest and in transit, hardware and software firewalls, identity and access controls (access rights, levels of privilege, passwords, separation of duties), machine learning and AI systems, network segregation by VLAN, physical separation or offline network, physical controls from alarms to swipe cards, physical location, quantum cryptography, two-factor authentication, VPNs, and whitelisting and blacklisting.
Detection measures covers behavioural analytics, emerging technologies, honeypots, the intrusion detection family (IDS, NIDS, HIDS, DIDS), intrusion prevention systems, network monitoring and vulnerability testing. The examinable distinction is that an IDS detects and alerts while an IPS detects and blocks. Intelligence assessment is the short third section: human intelligence and open-source intelligence, and how each is used in mitigation.
Topic Area 5: Policies, procedures and event handling
Six policies (acceptable use, BYOD, credential management, information security, remote working and staff training), and for each you need its purpose, the procedures it covers and how it improves security. The specification is explicit that you do not need the detailed contents of each policy.
Event handling covers roles, responsibilities and procedures, plus the components of a cyber security incident report: title and date, target, category (critical, significant, minor, negligible), description, attacker type, vector, method, impact, the responses required including internal and external notifications, and recommendations for future management. You will not be asked to write a report from scratch, but you will be asked to identify components and explain how it is used. Legislation covers the Computer Misuse Act, the Data Protection Act and UK GDPR, plus the ISO 27001 standard: latest version, main purpose, impact on cyber security, compliance steps and consequences of non-compliance. Two numbers are worth memorising: 72 hours to report a personal data breach to the ICO, and fines of up to £17.5 million or 4 per cent of global annual turnover.
Topic Area 6: Job roles and responsibilities
Six roles: computer forensic engineer, cyber security analyst, cyber security officer, IT security compliance analyst, network security engineer and penetration tester. You need main responsibilities only, not full job descriptions or the qualifications required. Then communication skills, verbal, written and non-verbal, plus using appropriate language for the audience and questioning techniques. The specification asks something slightly unusual here: how communication skills increase cyber security risk, as well as how they contribute to mitigation and incident response. Social engineering is the answer to the first part.
F194 Fundamentals of Networks: Revision by Topic Area
F194 is a 70 guided learning hour unit, examined by a 1 hour 15 minute paper worth 60 marks, and taken only on the Extended Certificate. It has the same exam structure as F193 with one addition: short answer questions with calculations and working. It is the more technical of the two papers and the one where precise recall of terminology pays off.
Topic Area 1: Network types, models, topologies and services
The network types are PAN, LAN (with intranet and extranet), WLAN, MAN, WAN, SAN and VPN, each needing purpose, features and advantages and disadvantages. The models are client-server, peer-to-peer and thin client. The topologies are hybrid, partial mesh, point-to-point, star including distributed star, tree and wireless, plus the difference between a logical and a physical topology. The specification explicitly excludes bus and ring topologies, so do not revise them and do not offer them as an answer. Network services covers domain controller, DNS, email, firewall, internet access, IDS, IPS, proxy, routing, voice and VPN termination.
Topic Area 2: Network layers, protocols and addressing
The TCP/IP four layer model only: application, transport, internet and network access. The specification states that it does not include the OSI model, so an answer with seven layers is wrong here. You need the function of each layer, how data moves between them, and encapsulation and decapsulation.
Fourteen protocols are named: DHCP, FTP, HTTP, HTTPS, IMAP, IP, NTP, POP, SSL, SMTP, VOIP, TCP, UDP and Ethernet, each with features, use and associated terminology. Addressing covers MAC, IPv4 and IPv6, network classes A to E with their default subnet masks, APIPA, classless addressing, dynamic and static allocation, loopback, NAT, private and public ranges, reservations, subnets and subnet masks, and the default gateway. You also need how devices obtain an IP address, and how to complete subnet calculations, which is the part that needs practice rather than reading.
Topic Area 3: Wired network components
Transmission media splits into copper (coaxial, and twisted pair as STP and UTP) and optical (fibre). Connection devices are bridge (transparent and source routing), brouter, gateway, NIC, repeater, router, and switch at layer 2 and layer 3. Host devices are laptops, mobile handheld devices, PCs, printers, servers (application, database, email, file, hypervisor, print, web) and VOIP phones. The examinable comparison that comes up most often is switch against router: a switch connects devices within one network using MAC addresses, a router connects separate networks using IP addresses.
Topic Area 4: Mobile and wireless networks
The biggest topic area in F194. Transmission media covers microwave, Bluetooth, infra-red, laser and radio. Cellular technologies are AMPS, CDMA, GSM, LTE and TDMA, and the hardware is the wireless access point and the wireless network interface controller. The concepts section covers access points, bands and channels, frequencies, SSIDs and wireless security, including the difference between WPA2 Personal with a pre-shared key and WPA2 Enterprise authenticating against a RADIUS server, plus WPA3. Radio frequency concepts are amplitude, attenuation, bandwidth, modulation, phase and wavelength. Antennas are bi-directional, omni-directional and semi-directional. Standards covers the cellular generations and wideband systems (CDMA and OFDM), then Bluetooth and IEEE 802.11. GPS closes the topic area.
Topic Area 5: Network performance
The four indicators are bandwidth, data transfer rate, latency and throughput, and the distinction between them is examinable: bandwidth is theoretical maximum capacity, throughput is what is actually delivered, and latency is delay, which is independent of both. Units covers bit, nibble and byte, and the difference between binary units (kibibyte through exbibyte, powers of 1024) and metric units (kilobyte through exabyte, powers of 1000).
Three formulae are named in the specification and must be learned: bandwidth requirement is each application's requirement multiplied by its simultaneous users, then summed across applications; data transfer speed is size divided by time; and duration is size divided by speed. You also need the difference between best case and typical calculations. Finally, twelve factors affecting performance, from jitter and interference to intervening objects and signal strength, with how each is resolved.
Topic Area 6: Cloud networks
Cloud types are community, hybrid, private and public. Service models are XaaS, CaaS, IaaS, PaaS and SaaS, and the examinable thread is how much the provider manages versus the customer. Cloud computing techniques covers automation, bursting, elasticity, orchestration, clustering, multi-tenancy, resource pooling across compute, networks and storage, and ubiquitous network access. Virtualisation closes the unit: application, data, desktop, network (internal and external), server and storage virtualisation.
F195 Preventing Cyberattacks: The NEA Explained
F195 is the coursework unit every AAQ Cyber Security student takes, on both H037 and H137. It is 75 guided learning hours, assessed against 24 criteria, and worth 60 uniform marks, the same as a whole exam paper. OCR sets the assignment, your centre marks it, and OCR moderates the marking through a visit in one of two windows each year.
The assignment gives you a scenario organisation and asks you to work through four connected tasks:
- Task 1: create a risk assessment covering every risk in the scenario, use a risk matrix to define each severity level, and identify three assumptions you made.
- Task 2: audit all the existing cyberattack prevention measures, and identify the gaps that leave the Task 1 risks uncovered.
- Task 3: design access control policies for external access, internal access and user group rights, design written user policies, and design prevention measures using an IDS and an IPS.
- Task 4: describe the purpose of each design, explain how each prevents exposure and how each reduces likelihood and severity, explain implementation, analyse advantages and disadvantages, and evaluate effectiveness.
The six topic areas exist to supply the tools for those tasks: concepts and threats, identifying risks, auditing and network access control, access control models and policies, written user policies, and reviewing what you designed. The content that most often catches students out is the terminology the criteria are written in: audit findings recorded as points of strength, observations, gaps, minor or major non-conformity, and opportunities for improvement; and access control models named as MAC, DAC, RBAC, ABAC and PBAC.
The Optional NEA Units: F196 to F199, and How to Choose
Extended Certificate students take two optional coursework units alongside F195. Each is 70 guided learning hours, each carries 24 assessment criteria and 60 uniform marks, and each is set by OCR and moderated in the same way. Your centre normally decides which two it offers, based on the equipment and expertise it has, so you may not get a free choice, but it is worth knowing what each involves.
F196 Digital forensic investigation
Planning investigations, collecting and preserving evidence, analysis, reporting and review
F197 Penetration testing and incident response
Introduction to penetration testing, planning and conducting tests, reporting findings, and responding to incidents
F198 Implementing secure local area networks
Designing, building, configuring and securing a LAN
F199 Designing and communicating secure global computing systems
Designing secure systems that span sites and borders, and communicating those designs to stakeholders
All five NEA units are synoptically linked to both examined units, which is the specification's way of saying the coursework is where you apply what F193 and F194 taught you. Revising the exam content properly makes the coursework easier, and doing the coursework properly makes the exam content stick. They are not separate workloads.
Exam Technique for F193 and F194
Both papers are 1 hour 15 minutes for 60 marks, which is 75 minutes for 60 marks, so roughly a mark a minute with time to spare for the long questions. Every question is compulsory. Both papers are structured the same way, and knowing that structure in advance is worth marks on its own.
The scenario develops through the paper
Each paper opens with a short scenario, and it develops as the paper goes on. That means later questions add detail to the same organisation rather than introducing a new one. Read the scenario properly before you start, and re-read the new information in each question, because the marks for application depend on using it. An answer that would score full marks in a generic context can score nothing if it ignores the scenario, since PO2 credit is specifically for applying knowledge to that organisation.
The question types you will meet
- Forced choice and controlled response, such as multiple choice or matching. Fast marks, do not overthink them.
- Short answer, closed response. Usually one or two marks: state, identify, name. One point per mark, no elaboration needed.
- Short answer with calculation and working, in F194 only. Show every step, because method marks are available even when the final figure is wrong.
- Extended response with points-based mark schemes. Each creditworthy point earns a mark, so more distinct valid points is better.
- Extended response with levels of response mark schemes, including one six mark and one nine mark question in every paper. These are marked holistically on the quality of the whole answer, not by counting points.
How to approach the six and nine mark questions
These two questions are worth 15 of the 60 marks between them, a quarter of the paper, and they are where PO3 analysis and evaluation marks sit. A levels of response mark scheme rewards a developed, balanced answer that reaches a judgement, not a list.
A reliable structure: make a point, explain the mechanism behind it, apply it explicitly to the organisation in the scenario, then weigh it against an alternative or a limitation. For a nine mark question, do that three times and finish with a conclusion that actually decides something. If the command word is evaluate or discuss, an answer with no judgement at the end cannot reach the top level however accurate the content is.
Plan them briefly. Two minutes spent listing three points and a conclusion will beat ten minutes of writing whatever comes to mind first.
Command words
Appendix A of the specification defines every command word used in the exams and in the NEA criteria, and they are not interchangeable. The ones that matter most:
| Command word | What the answer must do |
|---|---|
| State, identify, name | Give the answer with no explanation. Do not waste time elaborating. |
| Describe | Set out characteristics or features. What it is. |
| Explain | Give reasons or mechanisms. How and why, usually needing a because. |
| Analyse | Break it into parts and show how they relate to each other. |
| Discuss | Present more than one side, with support for each. |
| Evaluate | Weigh evidence and reach a supported judgement. |
| Justify | Give reasons why your choice is the right one, not just what it is. |
The single most common way to lose marks in these papers is answering a level below the command word: describing when asked to explain, or explaining when asked to evaluate. Underline the command word before you start writing.
Sample Assessment Materials and Practising Without Past Papers
There are no past papers for AAQ Cyber Security, because the first teaching is September 2026. What OCR does provide, free, is a full sample assessment paper for both F193 and F194, plus an annotated version of each that explains the features of the paper question by question. Those annotated guides are the single most useful free resource available for this specification, and most students never open them.
Use them in this order:
- Sit the sample paper properly, timed, closed book, in one 75 minute sitting. Do it before you feel ready, because the point is to find the gaps.
- Mark it against the mark scheme without being generous to yourself.
- Then read the annotated version. It shows why questions are worded the way they are, what the examiner is looking for in the extended responses, and where marks are typically dropped.
- Rewrite your two long answers using what the annotated guide told you. Rewriting one nine mark answer well is worth more than attempting five new questions badly.
Beyond the samples, the specification itself is a practice tool. The breadth and depth column next to each piece of teaching content tells you exactly what can be asked. A line that says "the advantages and disadvantages of each" is telling you that a question can ask for advantages and disadvantages of any item in that list. Turning each breadth and depth line into a question of your own is the closest thing to writing your own past paper, and it is free.
The other trick that works on a new specification: use the sister qualification. AAQ Computing (F160 and F161) shares its exam design, question types and mark scheme structure with these papers, so its sample materials are useful practice for the format even though the content is different.
Grading: Distinction*, UMS and What Compensatory Marking Means
The overall qualification grades are Distinction* (D*), Distinction (D), Merit (M) and Pass (P). Individual units are graded pass, merit or distinction, and a unit where you do not reach a pass is reported as unclassified. Crucially, the marks from an unclassified unit still count towards your final grade.
Compensatory grading, and why it changes how you work
Cambridge Advanced Nationals use a compensatory model rather than a hurdles model. For an NEA unit, your grade comes from the total number of assessment criteria achieved, and those criteria can come from any combination of pass, merit and distinction criteria. You do not have to achieve every pass criterion before a distinction criterion counts.
NEA design thresholds, the same for every NEA unit
Read those numbers carefully, because they change your strategy. A distinction in F195 needs 20 of the 24 criteria, which means you cannot get there on pass criteria alone: there are only 12. You have to attempt merit and distinction criteria to reach a unit distinction, and there is no penalty for attempting one and missing it. The single worst approach to an NEA unit is to polish the pass criteria and run out of time before the distinctions.
How the qualification grade is calculated
Each unit's raw mark, the exam mark out of 60 or the number of criteria out of 24, is converted onto the Uniform Mark Scale. Every unit is worth a maximum of 60 uniform marks regardless of how it was assessed, so an NEA unit counts exactly as much as an exam paper. Unit uniform marks are then added together and the total determines your overall grade.
| Qualification | Units | Max UMS | Pass | Merit | Distinction | Distinction* |
|---|---|---|---|---|---|---|
| H037 Certificate | F193 + F195 | 120 | 48 | 72 | 96 | 108 |
| H137 Extended Certificate | F193 + F194 + F195 + two optional | 300 | 120 | 180 | 240 | 270 |
At unit level, the uniform mark boundaries are 24 for a pass, 36 for a merit and 48 for a distinction, out of 60. There is no Distinction* at unit level; it exists only as an overall qualification grade, which is why consistency across every unit matters more than one standout performance.
The practical consequence of all this is the specification's own phrase: every mark counts. A unit you did not pass still contributes uniform marks, so a weak F194 does not write off the qualification, and criteria scraped in an NEA unit still add up. It is a system that rewards attempting everything.
Resits and resubmission
You can resit each examined unit twice, giving three attempts in total at each of F193 and F194. For F193 that total carries across both qualification sizes. For NEA units, there is one resubmission opportunity per assignment: if you have not performed at your best, you can improve the work and hand it back for assessment, with your teacher's agreement. Your teacher can tell you a criterion has not been met, but is not allowed to tell you specifically what to change.
AAQ Cyber Security vs BTEC, Cambridge Technicals, A Level and T Level
This is the most confused area of the whole subject, partly because several qualifications share the words "cyber security" and "Level 3", and partly because search results mix them together. Here is what is actually different.
| Qualification | Board | Size | Programming? | Assessment |
|---|---|---|---|---|
| AAQ Cyber Security (H037 / H137) | OCR | 150 or 360 GLH | No | 40 per cent exam, 60 per cent NEA on the Extended Certificate |
| Pearson AAQ IT (cyber security unit) | Pearson | Varies | No | Different unit codes and assessment model |
| OCR Cambridge Technicals IT Unit 3 | OCR | Legacy suite | No | The predecessor suite that Cambridge Advanced Nationals replace |
| A Level Computer Science (H446) | OCR | 360 GLH | Yes | Two 2h30 exams plus a programming project |
| T Level Digital Support Services | Various | Around 1080 GLH | Partial | Exams, employer-set project and a 45 day industry placement |
Should you take AAQ cybersecurity or A Level Computer Science?
They are the same size and the same level, so the honest answer depends on what you are good at rather than which is "better". A Level Computer Science is heavily programming-based, mathematical and abstract: algorithms, data structures, Boolean logic, computer architecture, and a substantial coded project. AAQ Cyber Security has no programming at all and is applied: threat, risk, network fundamentals, defensive design and written policy work, assessed partly through coursework you complete over time rather than entirely in a single exam season.
If you want to write software, take Computer Science. If you want to work in security operations, networks, forensics or governance, or if you perform better across sustained coursework than in three-hour exams, the AAQ is a genuinely academic route to the same destination. Many students take both, and the two complement each other well.
Should you take AAQ Cyber Security or a T Level?
Size is the deciding factor. A T Level is roughly three A Levels in one qualification and includes a 45 day industry placement, so it is a full-time programme in itself. The AAQ is one A Level in size and is designed to be taken alongside two other subjects. If you want to keep studying other A Levels, the AAQ fits into a normal study programme and the T Level does not.
Entry Requirements, University and Careers
Entry requirements
There is no formal entry requirement. The specification states plainly that students do not need to have achieved any specific qualification before starting. In practice, centres usually ask for the same GCSE profile they ask for across their Level 3 offer, commonly five GCSEs at grade 4 or above including English and often Maths, but that is a centre decision rather than an OCR one. Ask your school or college what they require.
Progression to university
The qualification is recognised in the UCAS tariff tables, and the Extended Certificate is the same size as one A Level. OCR designed it for progression to higher education in computer networks, computer networks and cyber security, computer science with cyber security, cyber security, cyber security and digital forensics, cyber security management, and ethical hacking and cyber security. Those are the exact destinations named in the specification.
Be realistic about competitive courses. Some computer science degrees still specify A Level Computer Science or Mathematics, and an AAQ will not substitute for a named subject requirement. Acceptance is much broader across cyber security, networking, digital forensics and IT degrees. Because the qualification is new, some universities have not yet updated their published requirements, so contact admissions directly rather than assuming a course that does not list it will reject it.
Careers this leads to
The content maps onto real entry-level roles, and F193 Topic Area 6 names six of them explicitly: computer forensic engineer, cyber security analyst, cyber security officer, IT security compliance analyst, network security engineer and penetration tester. The coursework units map just as directly: F196 to digital forensics, F197 to penetration testing and incident response, F198 to network engineering, and F199 to systems design.
Cyber security is one of the strongest growth areas in the IT sector, and the skills the qualification builds, risk assessment, access control design, user awareness, forensic procedure and incident response planning, are the ones employers screen for at entry level. The apprenticeship route is also well established, and a Level 3 qualification in the subject is strong evidence for a cyber security apprenticeship application.
How to Revise AAQ Cyber Security When There Are No Past Papers
Revising a brand new specification is a different problem from revising an established one. There is no bank of past questions, no examiner reports, and very little third party material. Here is what actually works.
Revise from the breadth and depth column
The specification has two columns for every unit: teaching content, and breadth and depth. Most students read the first and ignore the second. The second is the one that tells you what will be asked. If it says "know" at the start of a line, that item is recall only. Everything else must be understood, which the specification defines as being able to handle how, why, when, reasons for, advantages and disadvantages, benefits and limitations, purpose, suitability and appropriateness in different contexts.
So a line reading "the advantages and disadvantages of each mitigation method" is a question waiting to happen. Turn every breadth and depth line into a question and you have built your own question bank.
Learn the lists, because the lists are the spec
These units are unusually list-heavy: twelve actor types, seven incident types, twenty-odd mitigations, fourteen protocols, five cellular technologies, six virtualisation types. Questions frequently ask you to name several or to pick the right one for a scenario, so knowing the complete list beats knowing three items in depth. Active recall works far better than re-reading here, which is exactly what flashcards are for.
Practise applying, not just recalling
Because both papers hang on a developing scenario, pure recall caps your mark. Take any organisation you know, your school, a local shop, a hospital, and run the specification against it: what are its vulnerability vectors, which actors would target it and why, which mitigations would you recommend and what are their limitations. That exercise is the exam, and it is also a rehearsal for the F195 coursework.
Learn the exclusions
The specification tells you what will not be assessed, and every one of those lines saves you revision time. It excludes the OSI model, bus and ring topologies, the detailed contents of each policy, detailed job descriptions and their required qualifications, the detailed content of each Act or standard, methods of attack in the targets section, and creating incident reports from scratch. Knowing these stops you revising material that cannot be examined, and stops you offering an excluded answer in the exam.
A workable timeline
- Through the course: keep a running glossary. Both papers reward precise terminology, and it is far easier to build a glossary weekly than to reconstruct one in April.
- Eight weeks out: first pass through the notes, topic area by topic area, then flashcards daily on the topics you scored worst.
- Six weeks out: sit the sample assessment material properly, timed, then work through the annotated version.
- Four weeks out: write extended answers only. Six and nine mark questions are 25 per cent of each paper and the hardest to improve at the last minute.
- Final fortnight: lists, exclusions, formulae, and the two legislation numbers. Short recall sessions, several times a day.
AAQ Cyber Security: Frequently Asked Questions
These are the questions students and parents actually search for about this qualification. Every answer below is taken from the OCR specification rather than from guesswork, and each one is repeated in the structured data on this page so search engines read the same answer you do.
AAQ Cyber Security is the OCR Level 3 Cambridge Advanced National in Cyber Security (H037) and Cyber Security and Networks (H137). AAQ stands for Alternative Academic Qualification, which is a Level 3 academic qualification designed to sit alongside A Levels in a sixth form or college study programme rather than replace them. It is first taught from September 2026 and is assessed by a mix of written exams (units F193 and F194) and non-examined assessment coursework set by OCR (units F195 to F199).
It depends which size you take. The Extended Certificate (H137, Cyber Security and Networks) is 360 guided learning hours, which is the same size as one full A Level. The Certificate (H037, Cyber Security) is 150 guided learning hours, which is roughly half an A Level. Both are Level 3 and both appear in the UCAS tariff tables, and the 150 hour qualification is made up of units nested inside the 360 hour one.
H037 is the Certificate in Cyber Security. It is 150 guided learning hours and requires two units: F193 Fundamentals of cyber security, taken as an exam, and F195 Preventing cyberattacks, taken as coursework. H137 is the Extended Certificate in Cyber Security and Networks. It is 360 guided learning hours and requires five units: F193 and F194 Fundamentals of networks as exams, F195 as mandatory coursework, and two optional coursework units chosen from F196, F197, F198 and F199.
Only F193 and F194 are examined, and OCR sets and marks those papers. Every other unit (F195 to F199) is non-examined assessment: OCR sets the assignment, your centre marks it, and OCR moderates the marking. On the Extended Certificate the exams are worth 40 per cent of the qualification and the coursework 60 per cent. On the Certificate it is an even 50 per cent split.
Both papers are 1 hour 15 minutes and both are out of 60 marks, with every question compulsory. Each paper is built around a short scenario that develops as you work through it, and each contains one six mark and one nine mark extended response question marked with levels of response. Content is sampled from every topic area, so at least one question or part question relates to each of the six topic areas in the unit.
First teaching is from September 2026 and the first entry date for the qualification is 1 September 2026. Exams then run in two series each year, January and June, so a cohort starting in September 2026 sits its first available series in the 2026 to 2027 academic year. Check with your centre which series you have been entered for, because centres choose whether to enter students in January or June.
Yes. You can resit each examined unit twice, which means a maximum of three attempts in total at each of F193 and F194. For F193 that total includes any attempts made towards the Certificate as well as the Extended Certificate, so the attempts do not reset if you move between the two qualification sizes.
Not yet. The qualification is first taught from September 2026, so no past papers exist. What does exist is a full set of sample assessment materials from OCR for F193 and F194, and an annotated version of each one that walks through the features of the sample paper. Those annotated guides are the closest thing to an examiner report available right now, and they are free on the OCR website.
The qualification is recognised in the UCAS tariff tables. The Extended Certificate is the same size as one A Level, so its tariff points scale in the same way, with the highest grade attracting the same points as a top A Level grade and the Certificate attracting roughly half. UCAS publishes the exact figures per grade in its tariff calculator, and that is the source to use, because tariff values are set by UCAS rather than by OCR.
Alternative Academic Qualifications are designed for progression to higher education and are recognised in the UCAS tariff, but acceptance varies by university and by course. Competitive computer science degrees may still specify A Level Computer Science or Mathematics. Acceptance is generally broader for cyber security, computer networks, digital forensics and IT degrees, which is exactly what this qualification prepares you for. The qualification is new, so some universities have not yet updated their published entry requirements. Always check the specific course page and contact admissions directly if it is not listed.
OCR writes it as two words, Cyber Security, in the qualification titles Cambridge Advanced National in Cyber Security and Cyber Security and Networks. The one word spelling, cybersecurity, is the more common form in industry and in American English, and plenty of students search for it that way. Both refer to the same qualification, so use the two word form in anything you submit to OCR.
It is a Level 3 qualification, so it is pitched at the same level of demand as an A Level, but the demand is different in kind. There is a large amount of terminology to learn precisely, particularly in F194 where protocols, addressing and standards all have to be recalled accurately. The exams reward applying knowledge to a scenario rather than reciting it, and the coursework rewards organised, traceable evidence more than technical brilliance. Students who are systematic tend to do well.
You do not need to program at all. There is no coding requirement in F193 or F194. F194 does contain maths, but it is arithmetic rather than algebra: converting between bits and bytes and between binary and metric units, working out bandwidth requirements and transfer times, and completing subnet calculations. If you can multiply, divide and work with powers of two, that is the level required.
They are different qualifications from different awarding bodies. OCR AAQ Cyber Security is a Cambridge Advanced National with units coded F193 to F199. Pearson offers its own Alternative Academic Qualification in IT, which contains a cyber security and incident management unit, and BTEC Nationals are a separate vocational suite. OCR Cambridge Technicals Unit 3 Cyber Security is a different OCR qualification again, from the suite that Cambridge Advanced Nationals replace. Revision material written for any of those will not match the F193 or F194 specification.
The overall qualification grades are Distinction*, Distinction, Merit and Pass. Compensatory grading means your NEA unit grade comes from the total number of assessment criteria you achieve, in any combination of pass, merit and distinction criteria. Each NEA unit has 24 criteria: 10 gets you a unit pass, 15 a merit and 20 a distinction. You do not have to achieve every pass criterion before merit or distinction criteria count, and even if you fall short of a unit pass, the criteria you did achieve still convert into uniform marks that count towards your final qualification grade.
The Best Free AAQ Cyber Security Revision Resources (2026)
When these notes were written, there was no free site with written revision material covering F193 and F194. Searching for AAQ cyber security revision returned college course pages, a paid publisher, and revision material for entirely different qualifications. That gap is the reason this exists. Everything below is free, and the official OCR material is listed alongside, because you should be revising from the specification as well.
Notes
F193 and F194 Full Revision Notes
All twelve topic areasDefinitions in mark scheme wordingWorked subnet and data transfer calculations
Active recall
Cyber Security Flashcard App
239 cardsDrill by topic, by unit, or shuffle everythingSave to your phone home screen and use it offline
Coursework
F195 Step-by-Step NEA Guide
All 24 assessment criteriaThe official assessment guidance for each oneWhat separates pass, merit and distinction
Official
OCR sample assessment materials
Sample papers for F193 and F194Annotated versions explaining each questionFree on ocr.org.uk
Official
The specification itself
The only authoritative sourceRead the breadth and depth columnCheck you have the current version
This site
Jack's Revision Hub
Free notes and flashcard appsAAQ Cyber Security, AAQ Computing and six A Level subjectsNo login, no paywall
Good luck to the first cohort. Being in the first year of a specification is genuinely harder: no past papers, no seniors to borrow notes from, and no established resources. It also means nobody, including the examiners, has a bank of predictable questions to fall back on, so a student who has actually read the breadth and depth column is at less of a disadvantage than they feel. Everything on this site is free, and it always will be.