Updated September 2026: A revised CCSP exam outline took effect August 1, 2026. The six domains stay, but ISC2 revisited the domain weights and subdomains and added explicit AI and machine learning topics, including two new subdomains on AI/ML (ISC2). The exam uses Computerized Adaptive Testing: 100 to 150 items in three hours. Make sure your study materials cover the August 2026 outline.
The Certified Cloud Security Professional (CCSP) is ISC2’s cloud security certification. It proves you can design, secure and run data, applications and infrastructure in the cloud, and handle the legal, risk and compliance questions that come with putting data in someone else’s data center. It’s vendor-neutral, so it tests principles that apply across AWS, Azure, Google Cloud and SaaS rather than one provider’s console.
This guide covers who CCSP is for, the exam facts, the experience requirement and the Associate path, the six domains and weights, the full cost including annual fees, a study plan, career value, and how CCSP compares with CISSP, CISM and SecurityX.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Who CCSP is for
- Cloud security engineers and architects
- Cloud engineers, administrators and consultants who own security for cloud workloads
- Security analysts and auditors who assess cloud providers and cloud services
- CISSP holders who want to prove cloud depth (CISSP satisfies the whole CCSP experience requirement)
ISC2 lists roles such as cloud architect, cloud engineer, cloud consultant, cloud administrator, cloud security analyst and auditor of cloud computing services as typical CCSP holders (ISC2).
CCSP exam facts (2026)
| Item | Details |
|---|---|
| Current exam outline | Effective August 1, 2026 |
| Format | Computerized Adaptive Testing (CAT) |
| Number of items | 100 to 150 |
| Time limit | 3 hours |
| Item types | Multiple choice and advanced item types |
| Passing score | 700 out of 1,000 |
| Languages | English, Chinese, Japanese and German (Chinese only in set appointment windows) |
| Where you test | Pearson VUE test centers |
| Experience required | Five years in IT, including three in cybersecurity and one in a CCSP domain (waivers and Associate path below) |
| Exam price (Americas) | $599 |
| Annual maintenance fee | $135 a year ($50 as an Associate of ISC2) |
| Renewal | Three-year cycle: 90 CPE credits (at least 60 Group A) plus the annual fee |
Sources: ISC2’s CCSP exam outline, exam pricing, annual maintenance fee FAQ and member policies. Prices vary by region, so confirm at checkout.
CCSP experience requirements and the Associate path
ISC2’s requirement, from the CCSP exam outline:
- Five years of cumulative, full-time experience in information technology, of which three years must be in cybersecurity and one year in one or more of the six CCSP domains.
- Waivers: A bachelor’s or master’s degree in computer science, IT or a related field can satisfy up to one year. Cloud Security Alliance’s CCSK certificate can substitute for one year. Only one year can be waived in total.
- CISSP shortcut: An active CISSP substitutes for the entire CCSP experience requirement.
- Part-time work and internships can count toward the requirement.
- No experience yet? Pass the exam and become an Associate of ISC2. You then have six years to earn the five years of required experience. Associates pay a $50 annual fee and earn 15 CPE credits a year (ISC2).
Before ISC2 awards CCSP, you complete its endorsement application: an active ISC2-certified professional in good standing attests to your experience, or ISC2 can act as your endorser if you provide proof of employment. If you already have the experience, submit it within nine months of passing the exam.
The six CCSP domains and their weights (August 2026 outline)
| Domain | Weight | What it covers |
|---|---|---|
| 1. Cloud Concepts, Architecture and Design | 17% | Cloud roles and characteristics, reference architecture, service and deployment models, cryptography and key management, virtualization and container security, secure design principles, evaluating cloud providers, and a new subdomain on AI/ML (threat detection, data validation, SOAR, ethics and regulation) |
| 2. Cloud Data Security | 20% | The cloud data life cycle, storage types and threats, encryption, hashing, masking, tokenization, DLP, secrets management, data discovery and classification, information rights management, retention and legal hold, logging of data events, and a new subdomain on protecting AI/ML data sets and models |
| 3. Cloud Platform and Infrastructure Security | 17% | Physical, network, compute, virtualization and storage components, the management plane, secure data center design, infrastructure risk analysis, security controls, and business continuity and disaster recovery |
| 4. Cloud Application Security | 16% | Secure SDLC, common cloud vulnerabilities (including the OWASP Top 10 for LLM applications and API Top 10), threat modeling, application security testing, supply chain and third-party software, containers and Kubernetes, and cloud IAM (federation, SSO, MFA, CASB) |
| 5. Cloud Security Operations | 17% | Building and operating physical and logical cloud infrastructure, hardening, patching, availability, ITSM processes, digital forensics, communication with stakeholders, and SOC operations including SIEM, incident response, vulnerability assessment and penetration testing |
| 6. Legal, Risk and Compliance | 13% | Conflicting international laws, eDiscovery and forensics standards, privacy laws (GDPR, HIPAA and others), audit reports (SOC, SSAE, ISAE), enterprise risk management, and cloud contracts, SLAs and vendor management |
Domain names, weights and topics: ISC2 CCSP exam outline, effective August 1, 2026. Cloud Data Security is the heaviest domain at 20%, and the AI/ML material appears across all six domains, not just the two new subdomains.
What CCSP costs in 2026
- Exam: $599 in the Americas and most regions (EUR 575.04 in EMEA and GBP 485.19 in the UK), per ISC2’s pricing page. Rescheduling costs $50 and canceling costs $100. ISC2 also sells a two-attempt Peace of Mind Protection option.
- Annual maintenance fee: $135 a year once certified. ISC2 charges one AMF no matter how many ISC2 certifications you hold, so a CISSP who adds CCSP still pays $135 in total (ISC2).
- Associate route: $50 a year while you earn the experience, then an $85 upgrade when you become fully certified.
- Training: Optional. ISC2 sells official self-paced and instructor-led courses; many candidates use the official study guide, a practice test bank and hands-on time in a cloud account.
A 10-week CCSP study plan
This assumes about eight hours a week and some hands-on cloud experience. Add time for any domain you’ve never worked in, which for most people is domain 6.
- Weeks 1 to 2: cloud concepts and architecture. NIST and ISO cloud definitions, roles, service and deployment models, the shared responsibility model and secure design principles. Read the August 2026 outline so you know what’s new.
- Weeks 3 to 4: data security. The biggest domain. Data life cycle, encryption and key management, tokenization vs masking, DLP, classification, IRM, retention and legal hold. Add the new AI/ML data protection subdomain.
- Week 5: platform and infrastructure. Virtualization and hypervisor security, the management plane, data center design, and BC/DR in the cloud (RTO, RPO).
- Week 6: application security. Secure SDLC, threat modeling (STRIDE, PASTA), SAST vs DAST vs IAST vs SCA, API security, containers and Kubernetes, and federated identity.
- Week 7: security operations. Hardening, patching, ITSM processes, SIEM and SOC work, forensics in the cloud, and incident response.
- Week 8: legal, risk and compliance. Privacy laws, eDiscovery, audit report types, contracts and SLAs, and vendor risk. This domain trips up engineers, so give it a full week.
- Weeks 9 to 10: practice. Timed practice tests and review by domain. Because CAT adapts to you, aim for consistent performance across all six domains rather than acing a few.
Is CCSP worth it? Jobs and salary
CCSP targets cloud security architect and engineer roles. BLS doesn’t track pay by certification. For the closest occupations, it reports May 2025 median pay of $129,180 for information security analysts, with 21% projected growth from 2025 to 2035 (BLS), and $134,050 for computer network architects (BLS).
In practice, CCSP carries the most weight when you pair it with hands-on experience in at least one major cloud platform. It shows you understand the principles; provider-specific skills show you can apply them.
CCSP vs CISSP, CISM and SecurityX
- CCSP vs CISSP: CISSP is the broad, senior generalist certification; CCSP goes deep on cloud. They share an ISC2 membership and a single AMF, and an active CISSP covers the whole CCSP experience requirement, so CISSP then CCSP is a common sequence.
- CCSP vs CISM: CISM is about running a security program and managing risk. CCSP is technical cloud security. Cloud-heavy security leaders often hold both.
- CCSP vs SecurityX: SecurityX (formerly CASP+) is CompTIA’s hands-on advanced cert for security architects and engineers, and it includes cloud security, but it isn’t cloud-specific. CCSP is the cloud-focused choice.
- CCSP vs vendor cloud security certs: Provider certifications, such as AWS Certified Security – Specialty, prove skill on one platform. CCSP is vendor-neutral and adds legal, risk and compliance. Many cloud security engineers hold one of each.
Planning your next certification? See the full certification roadmap for the order to take them by career goal.
What I would tell a friend starting CCSP
Study the principles, but keep a free-tier cloud account open while you do. Every time the outline mentions key management, logging or IAM federation, go and find it in a real console. And read cloud breach write-ups: most come down to misconfiguration, identity and shared responsibility, which is exactly what CCSP tests.
Cloud misconfigurations make the news every week. Know which ones matter. The CyberExperts Daily Brief covers what changed in security and why it matters, in five minutes, weekday mornings. Get tomorrow’s brief.
Frequently asked questions
How many questions are on the CCSP exam?
The CCSP exam uses Computerized Adaptive Testing with 100 to 150 items and a three-hour time limit.
What is the passing score for CCSP?
700 out of 1,000 points.
How much does the CCSP exam cost?
$599 in the Americas and most regions. Once certified, you pay ISC2’s $135 annual maintenance fee, which covers all of your ISC2 certifications.
What are the CCSP experience requirements?
Five years of cumulative, full-time IT experience, including three years in cybersecurity and one year in one or more of the six CCSP domains. A relevant degree or the CCSK can waive one year (one year maximum), and an active CISSP covers the whole requirement.
Can I take CCSP without experience?
Yes. If you pass without the required experience, you can become an Associate of ISC2 and then have six years to earn the five years of experience.
What changed in the August 2026 CCSP exam outline?
The six domains stay, with weights of 17%, 20%, 17%, 16%, 17% and 13%. ISC2 revised subdomains throughout and added AI and machine learning topics, including new subdomains 1.6 (AI/ML concepts) and 2.9 (protecting AI/ML data).
Should I get CISSP or CCSP first?
If you have the experience, CISSP first is common because an active CISSP satisfies the entire CCSP experience requirement. If your work is almost entirely cloud security, CCSP first is reasonable.
Sources
- ISC2, CCSP certification: isc2.org
- ISC2, CCSP exam outline (effective August 1, 2026): isc2.org
- ISC2 Insights, ISC2’s CCSP exam outline revised (June 2026): isc2.org
- ISC2, Exam pricing: isc2.org
- ISC2, Annual maintenance fees FAQ: isc2.org
- ISC2, Member policies (CPE requirements): isc2.org
- ISC2, Associate of ISC2: isc2.org
- ISC2, Endorsement: isc2.org
- BLS, Information security analysts: bls.gov
- BLS, Computer network architects: bls.gov
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.