Skip to content

Certified Cloud Security Professional (CCSP)

The senior cloud security certification — architecture, data protection, infrastructure, application security, operations, and the legal and risk side that most technical certifications leave out entirely.

ISC2
Exam cost
$599 USD
src
ISC2 exam pricing page, Americas region (isc2.org/register-for-exam/isc2-exam-pricing)
chk
Duration
3 hours
Passing score
700 out of 1000 points
Valid for
3 years (three-year certification cycle, 90 CPE credits)

The CCSP is the cloud security certification that hiring managers recognise without explanation, and the one technical candidates most often underestimate — because a third of it is not technical at all.

What the weights tell you to study

Cloud Data Security is the largest domain at 20%, and it is the most misread. Engineers arrive fluent in one provider's encryption options and find questions about the data lifecycle, tokenisation, information rights management and retention policy — vendor-neutral vocabulary that has to be learned deliberately.

The rest sits close together: Architecture, Platform and Infrastructure and Operations at 17% each, Application Security at 16%. There is no domain you can afford to skip, and no domain that dominates. Even coverage is the correct strategy.

Legal, Risk and Compliance is the smallest at 13% and the one that decides passes. Jurisdiction, e-discovery, contract design and privacy regimes cannot be reasoned out from engineering knowledge. They have to be memorised, and technical candidates reliably run out of patience before they are.

Note the outline date. These weights come from the exam outline that took effect on 1 August 2026. Study material written against the previous outline is now describing a slightly different exam, and the AI/ML sub-domains in Domains 1 and 2 are new — check the publication date of anything you buy.

What the exam is actually like

Three hours, 100 to 150 items, scored 700 out of 1000. The scoring is scaled and compensatory, so a strong domain can offset a weak one — but only if you answered. There is no penalty for guessing and no way to recover an unanswered item.

The questions want the best answer, not the correct one. Two options will usually both work. The one that scores is the one a risk manager would sign off: policy before tooling, contract before configuration, the control that is auditable over the control that is clever. Candidates who argue with this pattern rather than learning it are the ones who resit.

Where the marks are lost

Answering as an engineer. The exam consistently rewards governance thinking, and the most common failure is a strong practitioner picking the technically superior answer over the one the framework prescribes.

Before you book

The exam costs $599 in the Americas, and the certification runs on a three-year cycle with 90 CPE credits and an annual maintenance fee — a recurring commitment, not a one-off purchase. Confirm the experience requirement before you pay: without it you can still pass and hold Associate of ISC2 status while you accrue it, but that is a decision worth making on purpose.

Your progress0%

Exam domains

Cloud Concepts, Architecture and Design

17%
Understand cloud computing conceptsDescribe cloud reference architectureUnderstand security concepts relevant to cloud computingUnderstand design principles of secure cloud computingEvaluate cloud service providers (CSP)Comprehend artificial intelligence (AI) and machine learning (ML)

Cloud Data Security

20%
Describe cloud data conceptsDesign and implement cloud data storage architecturesDesign and apply data security technologies and strategiesImplement data discoveryPlan and implement data classificationDesign and implement information rights management (IRM)Plan and implement data retention, deletion and archiving policiesDesign and implement auditability, traceability and accountability of data eventsComprehend data protection of AI and ML data

Cloud Platform and Infrastructure Security

17%
Comprehend cloud infrastructure and platform componentsDesign a secure data centreAnalyze risks associated with cloud infrastructure and platformsPlan and implementation of security controlsPlan business continuity (BC) and disaster recovery (DR)

Cloud Application Security

16%
Advocate training and awareness for application securityDescribe the secure software development life cycle (SDLC) processApply the secure software development life cycle (SDLC)Apply cloud software assurance and validationUse verified secure softwareComprehend and apply the specifics of cloud application architectureDesign appropriate identity and access management (IAM) solutions

Cloud Security Operations

17%
Build and implement physical and logical infrastructure for cloud environmentOperate and maintain physical and logical infrastructure for cloud environmentImplement operational controls and standardsSupport digital forensicsManage communication with relevant partiesManage security operations

Legal, Risk and Compliance

13%
Articulate legal requirements and unique risks within the cloud environmentUnderstand privacy issuesUnderstand audit process, methodologies and required adaptations for a cloud environmentUnderstand implications of cloud to enterprise risk managementUnderstand outsourcing and cloud contract design

Preparation path

  1. 1

    Check the experience requirement before you spend anything

    CCSP needs five years of paid IT experience, three of them in information security and one in a CCSP domain. Without it you can still sit the exam and become an Associate of ISC2 while you accrue the rest — but decide that deliberately rather than discovering it at endorsement.

    ~2 hours
  2. 2

    Read the outline as a checklist, not as background

    Every sub-domain begins with a verb — understand, design, evaluate, implement — and that verb is the depth you are expected to reach. 'Comprehend cloud infrastructure components' and 'design a secure data centre' are not the same amount of study, and the outline is telling you so.

    ~4 hours
  3. 3

    Work Cloud Data Security first — it is the largest domain

    At 20% it outweighs every other domain, and it is the one where vendor experience misleads: the exam asks about the data lifecycle, tokenisation, IRM and retention policy rather than about a particular provider's encryption menu. Learn the vocabulary the outline uses.

    ~35 hours
  4. 4

    Do not skip Legal, Risk and Compliance

    It is the smallest domain at 13% and the one technical candidates fail on. Jurisdiction, e-discovery, cloud contract design and privacy regimes are unfamiliar and cannot be reasoned out from engineering knowledge — this is memorisation, and it is where an otherwise strong candidate loses a pass.

    ~20 hours
  5. 5

    Cover the four remaining domains in weight order

    Architecture, Platform and Infrastructure, Operations and Application Security together carry 67%. None is dominant, which makes even coverage the right strategy — the compensatory scoring means a strong domain can rescue a weak one, but only if nothing has been left blank.

    ~45 hours
  6. 6

    Practise the question style, not just the material

    ISC2 items are scenario-based and often have two defensible answers, one of which is better. Train the habit of asking what a risk manager would choose rather than what an engineer would build — that single reframing moves more marks than another pass through the material.

    ~20 hours

Frequently asked questions

Career Roadmaps