CCSP (Certified Cloud Security Professional)
ISC2
Complete guide to passing the CCSP (Certified Cloud Security Professional) exam on your first attempt.
$599
~60%
3 years (90 CPE)
Global
ISC2
$130k-$175k
Are you ready for CCSP (Certified Cloud Security Professional)?
Loading quiz...
Complete Overview
The Certified Cloud Security Professional (CCSP) is a vendor-neutral cloud security certification from ISC2, written for people who already secure cloud workloads for a living rather than for newcomers. ISC2 lists the exam at USD 599 for the Americas, Asia Pacific, the Middle East and Africa, EUR 575.04 for its EMEA pricing region, and GBP 485.19 in the United Kingdom, with price and tax set by the country where you sit the test.
ISC2 requires five years of cumulative paid full-time IT experience, of which three years must be information security and one year must fall inside the six CCSP domains. A bachelor's or master's degree in a related field waives one year, and so does the Cloud Security Alliance CCSK certificate, but only one year can be waived in total. An active CISSP replaces the entire experience requirement. Candidates who pass without the experience become an Associate of ISC2 and get six years to accumulate the five years required.
Since 1 October 2025 the CCSP has been delivered exclusively in Computerized Adaptive Testing format at Pearson VUE test centres. The exam runs three hours and delivers between 100 and 150 items, of which 25 are unscored pretest items. The engine stops as soon as it can place your ability estimate above or below the pass point with 95 percent statistical confidence, so a candidate who finishes at item 100 may have passed or failed. You cannot skip a question or return to an earlier one. The passing standard is 700 out of 1000 points. ISC2 lists the item formats as multiple choice and advanced item types, and returns a pass or fail result with no numeric score attached. The exam is available in English, Chinese, Japanese and German.
ISC2 published a revised CCSP exam outline that took effect on 1 August 2026, keeping the same six domains and revising the subdomains beneath them. The current blueprint is Cloud Concepts, Architecture and Design at 17 percent, Cloud Data Security at 20 percent, Cloud Platform and Infrastructure Security at 17 percent, Cloud Application Security at 16 percent, Cloud Security Operations at 17 percent, and Legal, Risk and Compliance at 13 percent.
The content sits at a design and governance altitude rather than a console altitude. You are asked which deployment model fits a stated regulatory constraint, when tokenization beats format-preserving encryption, who holds the key in a bring-your-own-key arrangement, and which party in the shared responsibility model owns hypervisor patching under IaaS versus SaaS. The exam names no cloud provider, so AWS, Azure and Google Cloud terminology has to be translated back into the neutral vocabulary ISC2 uses.
Maintaining the credential takes 90 CPE credits across a three-year cycle, 60 of them Group A credits tied to the CCSP domains, plus a USD 135 annual maintenance fee that covers all ISC2 certifications a member holds rather than each one separately.
Why Get CCSP (Certified Cloud Security Professional) Certified?
CCSP is the cloud specialisation most often paired with CISSP, and holding an active CISSP satisfies the entire five-year CCSP experience requirement, so the second credential costs only the USD 599 exam fee and study time.
CCSP is accredited to ANSI/ISO/IEC 17024, the accreditation public sector procurement frameworks check for. ISC2's 2025 Cybersecurity Workforce Study put cloud security second only to AI among the skills the profession most needs, with cloud architecture and secure design named by half of the respondents working on cloud skills.
One CCSP domain, Legal, Risk and Compliance, carries 13 percent of the exam and covers cross-border data transfer, eDiscovery in cloud environments, and audit scope for CSA STAR and SOC 2, which is exactly the language procurement and legal teams use when they block a cloud migration.
The credential is vendor-neutral, so it holds value through a platform migration in a way that an AWS or Azure specialty certification does not.
CCSP is approved under the US Department of Defense 8140 cyberspace workforce framework, which makes it a hiring filter for defence contractor roles.
A single USD 135 annual maintenance fee covers every ISC2 certification you hold, so adding CCSP to a CISSP adds no recurring cost.
Passing the exam without the experience still yields the Associate of ISC2 designation, giving you six years to earn the five years of experience while carrying a credential on your CV.
Exam Format & Structure
Duration
3 hours
Questions
100 to 150 items, adaptive. The exam ends once the algorithm places your ability estimate above or below the pass point with 95 percent confidence.
Passing Score
700 out of 1000 points. ISC2 reports the exam as pass or fail and releases no numeric score to candidates; failing candidates receive domain proficiency levels instead.
Question Types
- Multiple choice, four options, one best answer
- Advanced item types, which ISC2 does not itemise publicly
- Scenario-framed items that give a deployment model and a compliance constraint and ask for the correct control
Delivery Method
Computerized Adaptive Testing at Pearson VUE test centres. Linear fixed-form delivery was retired for CCSP on 1 October 2025. Questions cannot be skipped, flagged or revisited.
Exam Domains & Topics
Covers the shared vocabulary the rest of the exam depends on: the five essential characteristics of cloud computing, the service and deployment models, the roles of cloud service provider, customer, broker and partner, and the design principles that make an architecture secure. Expect questions that hinge on which party owns a control under a stated service model.
Key Topics to Master:
- NIST SP 800-145 definition and the five essential characteristics
- IaaS, PaaS and SaaS responsibility boundaries
- Public, private, community, hybrid and multi-cloud deployment models
- Shared responsibility model applied to patching, identity and physical security
- Cloud reference architecture and the roles of provider, customer, broker, partner and auditor
- Cost-benefit analysis, functional security requirements and vendor lock-in
- Trusted Platform Module, hardware security modules and confidential computing
- Certification frameworks including ISO/IEC 27017, ISO/IEC 27018 and FIPS 140-3
The heaviest domain. It follows the cloud data lifecycle from create through destroy and asks which protection applies at each stage. Encryption, key management, tokenization, masking, data loss prevention, classification and retention all appear here, along with the audit and logging controls that prove data handling met policy.
Key Topics to Master:
- Cloud data lifecycle: create, store, use, share, archive, destroy
- Storage types by service model: volume, object, ephemeral, long-term, raw
- Encryption at rest and in transit, key management, BYOK and HYOK
- Tokenization, data masking, obfuscation and anonymization
- Data classification, labelling and discovery in object storage
- Information rights management and its cloud limitations
- Data retention, deletion, archiving policies and crypto-shredding
- Chain of custody and non-repudiation for cloud-held evidence
Deals with the physical and virtual layers underneath the workload: data centre design, network segmentation, hypervisor and container isolation, storage clusters, and the management plane. It also covers business continuity and disaster recovery planning where the recovery target is a cloud region rather than a second data centre.
Key Topics to Master:
- Physical, network, compute, virtualization, storage and management plane components
- Type 1 and Type 2 hypervisors, VM escape and hyperjacking risk
- Container and serverless isolation models
- Network security groups, micro-segmentation and zero trust network access
- Data centre design: logical, physical, environmental, tiering and redundancy
- Risk assessment of the shared infrastructure and tenant isolation failures
- Identity and access management including federation, SSO, MFA and secrets management
- Business continuity and disaster recovery strategy, RTO, RPO and RSL
Covers secure software development in cloud environments: awareness training, the secure SDLC, threat modelling, testing, supply chain risk in third-party libraries, and the identity and API controls that sit in front of an application. Application-layer defences such as web application firewalls and API gateways are examined here rather than in the infrastructure domain.
Key Topics to Master:
- Cloud application architecture, APIs and API gateway controls
- Secure SDLC phases and cloud-specific threat modelling with STRIDE and DREAD
- OWASP Top 10 and OWASP API Security Top 10 in cloud deployments
- SAST, DAST, IAST, software composition analysis and penetration testing
- Supply chain security, verified secure software and open-source dependency risk
- Identity as a service, federated identity, single sign-on and secrets management
- Web application firewall, database activity monitoring and XML gateways
- Cryptography selection and sandboxing for application isolation
Runs the operational lifecycle: building and configuring the physical and logical infrastructure, hardening baselines, running the environment against ITIL-style processes, monitoring, and handling incidents and forensics when the evidence sits on hardware you do not own. Change, configuration and problem management appear as named processes with expected inputs and outputs.
Key Topics to Master:
- Hardware-specific security configuration and baseline hardening
- Guest OS baselines, patch management and image management
- Availability of clustered hosts, distributed resource scheduling and high availability
- Operational controls and standards: change, continuity, incident, problem, release, deployment, configuration, service level and availability management
- Log capture, SIEM correlation and continuous monitoring in the cloud
- Digital forensics, evidence collection and forensic limitations in multi-tenant environments
- Communication with vendors, customers, partners, regulators and other stakeholders
- Security operations centre design and threat intelligence feeds
Covers the legal and regulatory environment around cloud services: conflicting international laws, privacy regimes, eDiscovery and forensic requirements, the audit process and its cloud-specific limits, and how to run a risk management programme against a supplier you cannot inspect. Contract terms, SLAs and outsourcing risk fall in this domain.
Key Topics to Master:
- Conflicting international legislation and cross-border data transfer
- GDPR, HIPAA, PCI DSS, GLBA, SOX and sector-specific privacy law
- eDiscovery, ISO/IEC 27050 and CSA guidance on cloud evidence
- Internal and external audit controls, audit scope statements and gap analysis
- SOC 1, SOC 2 and SOC 3 report types and what each proves
- CSA STAR programme levels and the Cloud Controls Matrix
- Risk frameworks, risk appetite, risk treatment and residual risk
- Cloud contract design, SLAs, vendor management and supply chain risk
Recommended Study Plan
- 1Download the current CCSP Exam Outline from isc2.org and confirm you are studying the version effective 1 August 2026
- 2Read NIST SP 800-145 in full, it is six pages and defines terms the exam reuses constantly
- 3Read chapter 1 of the ISC2 CCSP Official Study Guide (Sybex, Chapple and Seidl)
- 4Write out the shared responsibility split for IaaS, PaaS and SaaS across eight control areas from memory
- 5Confirm your five years of experience map to the ISC2 categories before you pay for the exam
- 1Work through the domain 1 chapters of the Sybex Official Study Guide
- 2Read CSA Security Guidance v5 domains 1 and 2
- 3Build a comparison table of ISO/IEC 27017, ISO/IEC 27018 and FIPS 140-3 and what each certifies
- 4Take the domain 1 questions from the ISC2 CCSP Official Practice Tests and log every miss with the reason
- 5Translate ten AWS or Azure services you use into vendor-neutral CCSP terminology
- 1Map the six phases of the cloud data lifecycle to the controls available at each phase
- 2Learn the storage types tied to each service model, volume and object for IaaS, structured and unstructured for PaaS
- 3Read the CSA Cloud Controls Matrix data security and privacy control family
- 4Drill the difference between tokenization, masking, anonymization and obfuscation until you can state which preserves referential integrity
- 5Write a one-page summary of crypto-shredding and when it is the only viable deletion method
- 1Study BYOK, HYOK and provider-managed keys and who holds the key material in each
- 2Learn where a hardware security module sits in each key management architecture
- 3Review information rights management and the reasons it fails across cloud tenants
- 4Complete a 50-question domain 2 practice set and target 80 percent before moving on
- 5Diagram key rotation and escrow for a multi-region SaaS deployment
- 1Study hypervisor types, VM escape, hyperjacking and the isolation guarantees each layer provides
- 2Compare container isolation with virtual machine isolation and note where the exam treats them differently
- 3Learn RTO, RPO and RSL and be able to compute a recovery strategy from a stated business impact
- 4Read CSA Security Guidance v5 on infrastructure and virtualization
- 5Build a data centre tiering cheat sheet covering redundancy and environmental controls
- 1Review the OWASP Top 10 and OWASP API Security Top 10 from owasp.org
- 2Practise threat modelling one application with STRIDE and record the mitigations
- 3Learn the differences between SAST, DAST, IAST and software composition analysis and what each cannot find
- 4Study federated identity, SAML, OAuth 2.0 and OpenID Connect at a conceptual level, the exam does not ask for protocol syntax
- 5Complete a domain 4 practice set and review every missed item against the study guide
- 1Learn the ITIL-derived process names ISC2 uses: change, configuration, release, deployment, problem, incident, availability, continuity and service level management
- 2Study forensic collection limits in multi-tenant environments and the role of the provider in evidence handover
- 3Review baseline hardening for guest operating systems and image lifecycle management
- 4Set up log aggregation from a free-tier cloud account and inspect what the provider does and does not expose
- 5Complete a domain 5 practice set
- 1Compare SOC 1, SOC 2 Type I, SOC 2 Type II and SOC 3 and what each report can be shown to whom
- 2Study the CSA STAR registry levels and pull one real STAR entry to see what a provider actually attests
- 3Learn GDPR roles: controller, processor, joint controller, and the lawful bases for transfer
- 4Read ISO/IEC 27050 coverage of eDiscovery in the study guide
- 5Build a risk treatment table covering accept, avoid, transfer and mitigate with a cloud example for each
- 1Sit a full-length timed practice exam of at least 125 questions in one sitting
- 2Score by domain and rank the six domains by accuracy
- 3Spend two sessions on your two weakest domains using the study guide chapters only
- 4Re-drill every question you missed twice across all practice sets
- 5Practise answering without flagging or revisiting, since the CAT format forbids both
- 1Sit a second full-length timed practice exam and confirm a stable score above your target
- 2Review the ISC2 exam outline one final time and check every subdomain bullet against your notes
- 3Schedule the exam at a Pearson VUE test centre and confirm your two forms of ID match your ISC2 profile name exactly
- 4Read the ISC2 exam day policies and the Pearson VUE candidate rules the day before
- 5Identify your endorser in advance, since you have nine months from the exam date to complete endorsement
Ready to pass CCSP (Certified Cloud Security Professional)?
Get 500+ practice questions, video walkthroughs, and a pass guarantee.
Best Study Resources
ISC2 CCSP Certification Exam Outline
Official blueprintThe authoritative domain and subdomain list with weights. Check the effective date at the top, the current version took effect 1 August 2026.
Free
ISC2 CCSP Official Study Guide (Sybex)
BookWritten by Mike Chapple and David Seidl and organised by domain. The most widely used single text for the exam, with chapter review questions and online flashcards.
Paid, sold in print and ebook
ISC2 CCSP Official Practice Tests (Sybex)
Practice questionsDomain-by-domain question sets plus full-length practice exams. Use the domain sets while learning and save the full-length exams for weeks 9 and 10.
Paid, sold in print and ebook
ISC2 CCSP Official Online Self-Paced Training
Video courseThe vendor's own course, aligned to the current exam outline and including knowledge checks. It is republished against each outline revision, so it tracks the 1 August 2026 blueprint.
Paid, ISC2 members receive a discount
CSA Security Guidance for Critical Areas of Focus in Cloud Computing v5
Reference documentThe Cloud Security Alliance guidance document that CCSP content draws on heavily. Free download after registration on cloudsecurityalliance.org.
Free
CSA Cloud Controls Matrix
Control frameworkThe CSA control framework mapped to major standards, used directly in the compliance and audit content. Download the spreadsheet and read the control families rather than memorising individual control IDs.
Free
NIST SP 800-145, The NIST Definition of Cloud Computing
StandardSix pages that define the five essential characteristics, three service models and four deployment models. The exam uses this vocabulary verbatim.
Free
OWASP Top 10 and OWASP API Security Top 10
ReferenceSource material for the application security domain. Read both lists and the mitigation notes rather than memorising rank order.
Free
ISC2 CCSP All-in-One Exam Guide (McGraw Hill)
BookDaniel Carter's alternative text. Useful as a second explanation when the Sybex treatment of a topic does not land, particularly for the operations domain.
Paid, sold in print and ebook
ISC2 Community CCSP Study Group
ForumThe vendor-hosted forum where ISC2 staff post format and outline changes, including the CAT transition announcement.
Free
Common Mistakes to Avoid
Studying a specific cloud provider's implementation instead of the neutral model. Candidates who live in AWS answer with AWS defaults and miss items where the correct answer depends on the abstract service model.
For every provider service you know well, write down the CCSP-neutral term and the responsibility boundary. The exam never names a provider, so your mental index has to be keyed on IaaS, PaaS and SaaS rather than on EC2 or Azure Functions.
Treating the CCSP as a technical exam and skipping domain 6. Legal, risk and compliance is 13 percent and is the domain that technical candidates score worst on.
Give domain 6 a full week. Learn the SOC report types, the CSA STAR levels, GDPR controller and processor roles, and what a scope statement covers. These are memorisation items that convert directly into marks.
Preparing as though the exam is still linear and fixed-form. Some study plans still tell candidates to skip hard questions and come back to them, which the CAT format does not allow.
Practise answering every question in sequence with no flagging and no review. CCSP has been CAT-only since 1 October 2025 and the engine will not let you return to a prior item.
Confusing tokenization with encryption in data security questions. Both protect the field, but only one keeps the original value recoverable through a key.
Learn the exact mechanism: tokenization substitutes a value and stores the mapping in a token vault, encryption transforms it with a key, masking hides characters at display time, anonymization is intended to be irreversible. Exam items turn on which property the scenario requires.
Assuming the shared responsibility model is the same for every control across every service model. It changes control by control, not just model by model.
Build a matrix with the control areas down the side (physical, network, hypervisor, OS, application, data, identity) and IaaS, PaaS, SaaS across the top, then fill it in from memory until you can reproduce it in five minutes.
Paying for the exam before checking the experience requirement, then discovering you qualify only for Associate status.
Map your work history to the ISC2 categories before you register. Five years cumulative IT, three of them security, one inside a CCSP domain. Note that an active CISSP waives all of it, and that a degree or the CSA CCSK waives one year but the two waivers do not stack.
Memorising practice question answers instead of the reasoning. Adaptive delivery draws from a large item pool and rephrases the same concept in different scenarios.
For every practice item you get wrong, write one sentence naming why the correct answer wins and one sentence naming why your choice loses. Review that log rather than re-taking the same test.
Answering forensics questions as if you had full access to the hardware. Cloud forensics is constrained by multi-tenancy and provider control of the underlying media.
Study what the customer can collect directly, what requires a provider request, and how chain of custody works when a third party performs the collection. Contract and SLA terms determine the answer more often than technique does.
Leaving the endorsement step until later and then losing the pass. ISC2 gives nine months from the exam date to complete the application.
Line up an ISC2-certified endorser before you sit the exam. If you do not know one, plan for ISC2 to endorse you directly, which requires employment documentation and takes longer.
Exam Day Tips
- 1
Bring two valid forms of unexpired ID, one photo-bearing, with names that match your ISC2 profile exactly. A mismatch between a middle initial on your ID and your registration is a common cause of turned-away candidates at Pearson VUE.
- 2
Arrive at least 30 minutes early. Pearson VUE runs check-in, palm vein scan and locker storage before the clock starts, and late arrivals forfeit the appointment fee.
- 3
Plan for three hours of continuous work. Any break you take runs against your exam time, so decide in advance whether you will break at all.
- 4
Answer every item as it appears. The adaptive engine will not let you skip, flag or revisit, so a question you are unsure about has to be resolved and left behind.
- 5
Do not read early difficulty as a signal. In CAT delivery a run of hard items usually means you are answering well, and the engine is narrowing your ability estimate rather than punishing you.
- 6
Watch for the item count rather than the timer. Most candidates finish inside the three hours because the exam ends when the algorithm reaches 95 percent confidence, which can happen at item 100.
- 7
No reference material, scratch paper of your own, or calculator is permitted. The test centre supplies an erasable noteboard and marker if you need to draw a responsibility matrix.
- 8
Expect an unofficial pass or fail printout from the proctor at check-out, with official confirmation arriving by email. ISC2 warns that during high-volume periods results can be delayed by six to eight weeks.
- 9
If you fail, take the domain proficiency breakdown you receive at the test centre with you. It ranks your performance by domain and is the only diagnostic ISC2 provides.
Career Paths & Salary Ranges
Cloud security architect
Designs the security model for cloud platforms: identity federation, network segmentation, key management and the control mapping that satisfies auditors. The CCSP blueprint matches this role more closely than any other, particularly domains 1 and 3.
$130k-$175k
Cloud security engineer
Implements and operates the controls an architect specifies, including baseline hardening, guardrails, log pipelines and incident response for cloud workloads. Domain 5 covers the operational processes this role owns.
$130k-$175k
Cloud governance, risk and compliance lead
Runs third-party risk assessment of cloud providers, manages SOC 2 and ISO evidence collection, and negotiates security terms in cloud contracts. Domain 6 is the direct preparation for this work.
$130k-$175k
DevSecOps engineer
Embeds security testing into cloud delivery pipelines, covering SAST, DAST, software composition analysis and secrets management. Domain 4 material maps to the tooling and threat modelling side of this role.
$130k-$175k
Cloud security consultant
Advises multiple clients on migration security, regulatory constraint and provider selection. Vendor neutrality is the reason consultancies value CCSP over a single-provider specialty certification.
$130k-$175k
Prerequisites & Requirements
- Five years of cumulative paid full-time work experience in information technology.
- Three of those five years must be in information security.
- One of those five years must be in one or more of the six CCSP domains.
- A bachelor's or master's degree in computer science, information technology or a related field substitutes for one year of experience.
- The Cloud Security Alliance CCSK certificate substitutes for one year of experience. Only one year total can be waived, so the degree and the CCSK do not stack.
- An active ISC2 CISSP satisfies the entire CCSP experience requirement.
- Candidates without the experience may still sit the exam and become an Associate of ISC2, with six years to earn the required five years.
Frequently Asked Questions
How much does the CCSP exam cost?
ISC2 lists USD 599 for the Americas, Asia Pacific, the Middle East and Africa, EUR 575.04 for its EMEA pricing region, and GBP 485.19 in the United Kingdom. ISC2 applies tax based on the location where the exam is administered. Rescheduling costs USD 50, GBP 35 or EUR 40, and cancelling costs USD 100, GBP 70 or EUR 80. ISC2 also sells a Peace of Mind Protection bundle that includes two attempts at less than the price of two separate exams, with both attempts to be used within 180 days of purchase.
What is the CCSP passing score?
The passing standard published in the exam outline is 700 out of 1000 points. Candidates never see that number: ISC2 releases pass or fail only, with no scaled score on the report. Failing candidates receive a proficiency level for each domain instead, marked below, near or above the passing standard.
How many questions are on the CCSP exam?
Between 100 and 150 items in three hours, 25 of them unscored pretest items. The CCSP moved to Computerized Adaptive Testing on 1 October 2025, and the engine stops as soon as it can place your ability estimate above or below the pass point with 95 percent statistical confidence. Finishing at 100 items tells you nothing about whether you passed, because the algorithm reaches confidence in both directions.
What happens if I fail the CCSP?
You receive a domain-by-domain proficiency breakdown at the test centre, which is the only diagnostic ISC2 provides. Under the ISC2 retake policy you may retest after 30 test-free days following a first failure, after 60 test-free days following a second, and after 90 test-free days following a third and any subsequent failure. You may attempt any single ISC2 exam a maximum of four times in a rolling 12-month period, and each attempt requires a new exam fee.
How long do CCSP results take?
The proctor hands you an unofficial pass or fail result when you check out of the Pearson VUE test centre, and ISC2 emails the official result afterwards. ISC2 states that during periods of high exam volume real-time results may not be available and official results can be delayed by roughly six to eight weeks while psychometric analysis is completed. Results are never given over the phone.
Can I take the CCSP online from home?
No. ISC2 delivers the CCSP through Pearson VUE test centres only. There is no remote proctored option, so you need to book a physical seat. This differs from GIAC certifications, which offer ProctorU remote delivery as an alternative to a test centre.
What ID do I need for the CCSP exam?
Two valid, unexpired forms of identification, at least one bearing your photograph and both bearing your signature. The name on your ID must match the name on your ISC2 registration exactly, including middle names or initials. Pearson VUE also captures a digital photograph and a palm vein scan at check-in and stores personal items in a locker before you enter the test room.
Are reference materials or a calculator allowed?
No. The CCSP is a closed-book exam and you cannot bring notes, books or a personal calculator. The test centre provides an erasable noteboard and marker, which is enough to sketch a shared responsibility matrix or a data lifecycle before you start working through items. This is the opposite of GIAC exams such as GSEC and GPEN, which are open book.
What is the CCSP break policy?
Any break you take counts against your three hours of exam time. The clock does not stop when you leave the room, and you have to check out and back in with the proctor, including a repeat palm vein scan. Most candidates finish without a break, since adaptive delivery frequently ends before the full three hours elapse.
How do I keep the CCSP current?
The certification runs on a three-year cycle requiring 90 CPE credits plus the ISC2 annual maintenance fee of USD 135. ISC2's CPE Handbook splits the 90 into 60 Group A credits, which must relate to the domains of your certification, and up to 30 that may be Group B, covering broader professional skills such as management or communication training. The single USD 135 fee covers a member regardless of how many ISC2 certifications they hold, and credits submitted apply to every certification in an active cycle.
Do I need the CISSP before the CCSP?
No, but holding an active CISSP satisfies the entire five-year CCSP experience requirement, which removes the endorsement friction entirely. Without a CISSP you need five years cumulative IT experience, three in information security and one in a CCSP domain. Many candidates take CCSP first when their work is cloud-focused, then add CISSP later for the broader management scope.
How does the CCSP compare to the CCSK?
The Cloud Security Alliance CCSK is a shorter open-book online exam with no experience requirement, and it substitutes for one year of CCSP experience. CCSP requires five years of verified experience, an endorsement by an ISC2-certified professional, and ongoing CPE and maintenance fees. CCSK tests knowledge of the CSA Security Guidance and Cloud Controls Matrix; CCSP tests a broader blueprint that includes legal, risk, operations and application security.
How does the CCSP compare to AWS Certified Security Specialty?
The AWS certification tests one provider's services, console behaviour and service limits. CCSP tests vendor-neutral cloud security design and never names a provider. Employers running a single-cloud estate often want the provider certification for engineers; architecture, audit and consulting roles across mixed estates tend to ask for CCSP. Holding both is common, and neither substitutes for the other.
Are accommodations available for the CCSP exam?
Yes. ISC2 provides testing accommodations for candidates with documented disabilities or medical needs, requested through ISC2 before you schedule with Pearson VUE rather than at the test centre. Accommodations can include extra time, a separate testing room, or permission to bring specified medical items. Approval has to be in place before booking, so start the request several weeks ahead.
What is the CCSP pass rate?
ISC2 does not publish official pass rates for the CCSP. Figures circulating in study communities put it somewhere in the region of 60 percent for first attempts, but these are self-reported estimates rather than vendor statistics. The more useful planning figure is the experience requirement: candidates with real cloud architecture or audit experience report far shorter preparation than those studying it as theory.
What changed in the August 2026 CCSP exam outline?
ISC2 published a revised CCSP exam outline effective 1 August 2026. The six domains kept their names, and the weights are Cloud Concepts, Architecture and Design 17 percent, Cloud Data Security 20 percent, Cloud Platform and Infrastructure Security 17 percent, Cloud Application Security 16 percent, Cloud Security Operations 17 percent, and Legal, Risk and Compliance 13 percent. The subdomains were revised, so check any study material published before mid-2026 against the current outline PDF.
How long should I study for the CCSP?
Candidates who already work in cloud security typically report 8 to 12 weeks at 10 hours a week. The plan on this page runs 10 weeks and roughly 100 to 120 hours. If your experience is on-premises security rather than cloud, add time to domains 1 and 3, since the platform and architecture vocabulary is where traditional security professionals lose the most marks.
What is an Associate of ISC2 and how does it work for CCSP?
If you pass the CCSP exam without the five years of required experience, you become an Associate of ISC2 and have six years from that point to earn the experience and convert to full CCSP status. Associates pay a USD 50 annual maintenance fee instead of USD 135 and carry a lower annual CPE obligation of 15 credits per year. Once you submit qualifying experience and are endorsed, the credential converts to CCSP.
Pass CCSP (Certified Cloud Security Professional), Guaranteed
94% pass rate on first attempt
One-time • Lifetime access