CCSP in 2026: Exam Guide, Cost and Requirements

By Donald Korinchak, MBA, PMP, CISSP, SecurityX, ITILv3   Published: 09/26/26   Updated: 09/26/26   9 min read

Updated September 2026: A revised CCSP exam outline took effect August 1, 2026. The six domains stay, but ISC2 revisited the domain weights and subdomains and added explicit AI and machine learning topics, including two new subdomains on AI/ML (ISC2). The exam uses Computerized Adaptive Testing: 100 to 150 items in three hours. Make sure your study materials cover the August 2026 outline.

The Certified Cloud Security Professional (CCSP) is ISC2’s cloud security certification. It proves you can design, secure and run data, applications and infrastructure in the cloud, and handle the legal, risk and compliance questions that come with putting data in someone else’s data center. It’s vendor-neutral, so it tests principles that apply across AWS, Azure, Google Cloud and SaaS rather than one provider’s console.

This guide covers who CCSP is for, the exam facts, the experience requirement and the Associate path, the six domains and weights, the full cost including annual fees, a study plan, career value, and how CCSP compares with CISSP, CISM and SecurityX.

Who CCSP is for

ISC2 lists roles such as cloud architect, cloud engineer, cloud consultant, cloud administrator, cloud security analyst and auditor of cloud computing services as typical CCSP holders (ISC2).

CCSP exam facts (2026)

ItemDetails
Current exam outlineEffective August 1, 2026
FormatComputerized Adaptive Testing (CAT)
Number of items100 to 150
Time limit3 hours
Item typesMultiple choice and advanced item types
Passing score700 out of 1,000
LanguagesEnglish, Chinese, Japanese and German (Chinese only in set appointment windows)
Where you testPearson VUE test centers
Experience requiredFive years in IT, including three in cybersecurity and one in a CCSP domain (waivers and Associate path below)
Exam price (Americas)$599
Annual maintenance fee$135 a year ($50 as an Associate of ISC2)
RenewalThree-year cycle: 90 CPE credits (at least 60 Group A) plus the annual fee

Sources: ISC2’s CCSP exam outline, exam pricing, annual maintenance fee FAQ and member policies. Prices vary by region, so confirm at checkout.

CCSP experience requirements and the Associate path

ISC2’s requirement, from the CCSP exam outline:

Before ISC2 awards CCSP, you complete its endorsement application: an active ISC2-certified professional in good standing attests to your experience, or ISC2 can act as your endorser if you provide proof of employment. If you already have the experience, submit it within nine months of passing the exam.

The six CCSP domains and their weights (August 2026 outline)

DomainWeightWhat it covers
1. Cloud Concepts, Architecture and Design17%Cloud roles and characteristics, reference architecture, service and deployment models, cryptography and key management, virtualization and container security, secure design principles, evaluating cloud providers, and a new subdomain on AI/ML (threat detection, data validation, SOAR, ethics and regulation)
2. Cloud Data Security20%The cloud data life cycle, storage types and threats, encryption, hashing, masking, tokenization, DLP, secrets management, data discovery and classification, information rights management, retention and legal hold, logging of data events, and a new subdomain on protecting AI/ML data sets and models
3. Cloud Platform and Infrastructure Security17%Physical, network, compute, virtualization and storage components, the management plane, secure data center design, infrastructure risk analysis, security controls, and business continuity and disaster recovery
4. Cloud Application Security16%Secure SDLC, common cloud vulnerabilities (including the OWASP Top 10 for LLM applications and API Top 10), threat modeling, application security testing, supply chain and third-party software, containers and Kubernetes, and cloud IAM (federation, SSO, MFA, CASB)
5. Cloud Security Operations17%Building and operating physical and logical cloud infrastructure, hardening, patching, availability, ITSM processes, digital forensics, communication with stakeholders, and SOC operations including SIEM, incident response, vulnerability assessment and penetration testing
6. Legal, Risk and Compliance13%Conflicting international laws, eDiscovery and forensics standards, privacy laws (GDPR, HIPAA and others), audit reports (SOC, SSAE, ISAE), enterprise risk management, and cloud contracts, SLAs and vendor management

Domain names, weights and topics: ISC2 CCSP exam outline, effective August 1, 2026. Cloud Data Security is the heaviest domain at 20%, and the AI/ML material appears across all six domains, not just the two new subdomains.

What CCSP costs in 2026

A 10-week CCSP study plan

This assumes about eight hours a week and some hands-on cloud experience. Add time for any domain you’ve never worked in, which for most people is domain 6.

Is CCSP worth it? Jobs and salary

CCSP targets cloud security architect and engineer roles. BLS doesn’t track pay by certification. For the closest occupations, it reports May 2025 median pay of $129,180 for information security analysts, with 21% projected growth from 2025 to 2035 (BLS), and $134,050 for computer network architects (BLS).

In practice, CCSP carries the most weight when you pair it with hands-on experience in at least one major cloud platform. It shows you understand the principles; provider-specific skills show you can apply them.

CCSP vs CISSP, CISM and SecurityX

Planning your next certification? See the full certification roadmap for the order to take them by career goal.

What I would tell a friend starting CCSP

Study the principles, but keep a free-tier cloud account open while you do. Every time the outline mentions key management, logging or IAM federation, go and find it in a real console. And read cloud breach write-ups: most come down to misconfiguration, identity and shared responsibility, which is exactly what CCSP tests.

Cloud misconfigurations make the news every week. Know which ones matter. The CyberExperts Daily Brief covers what changed in security and why it matters, in five minutes, weekday mornings. Get tomorrow’s brief.

Frequently asked questions

How many questions are on the CCSP exam?

The CCSP exam uses Computerized Adaptive Testing with 100 to 150 items and a three-hour time limit.

What is the passing score for CCSP?

700 out of 1,000 points.

How much does the CCSP exam cost?

$599 in the Americas and most regions. Once certified, you pay ISC2’s $135 annual maintenance fee, which covers all of your ISC2 certifications.

What are the CCSP experience requirements?

Five years of cumulative, full-time IT experience, including three years in cybersecurity and one year in one or more of the six CCSP domains. A relevant degree or the CCSK can waive one year (one year maximum), and an active CISSP covers the whole requirement.

Can I take CCSP without experience?

Yes. If you pass without the required experience, you can become an Associate of ISC2 and then have six years to earn the five years of experience.

What changed in the August 2026 CCSP exam outline?

The six domains stay, with weights of 17%, 20%, 17%, 16%, 17% and 13%. ISC2 revised subdomains throughout and added AI and machine learning topics, including new subdomains 1.6 (AI/ML concepts) and 2.9 (protecting AI/ML data).

Should I get CISSP or CCSP first?

If you have the experience, CISSP first is common because an active CISSP satisfies the entire CCSP experience requirement. If your work is almost entirely cloud security, CCSP first is reasonable.

Sources

Donald Korinchak, MBA, PMP, CISSP, SecurityX, ITILv3

Donald Korinchak is a Cybersecurity Professional in the Washington DC area. Donald holds an MBA from the University of Pittsburgh Katz School of Business. Donald is considered a thought leader in business, leadership, and cybersecurity issues.