Certified Cloud Security Professional (CCSP)
The senior cloud security certification — architecture, data protection, infrastructure, application security, operations, and the legal and risk side that most technical certifications leave out entirely.
- src
- ISC2 exam pricing page, Americas region (isc2.org/register-for-exam/isc2-exam-pricing)
- chk
The CCSP is the cloud security certification that hiring managers recognise without explanation, and the one technical candidates most often underestimate — because a third of it is not technical at all.
What the weights tell you to study
Cloud Data Security is the largest domain at 20%, and it is the most misread. Engineers arrive fluent in one provider's encryption options and find questions about the data lifecycle, tokenisation, information rights management and retention policy — vendor-neutral vocabulary that has to be learned deliberately.
The rest sits close together: Architecture, Platform and Infrastructure and Operations at 17% each, Application Security at 16%. There is no domain you can afford to skip, and no domain that dominates. Even coverage is the correct strategy.
Legal, Risk and Compliance is the smallest at 13% and the one that decides passes. Jurisdiction, e-discovery, contract design and privacy regimes cannot be reasoned out from engineering knowledge. They have to be memorised, and technical candidates reliably run out of patience before they are.
Note the outline date. These weights come from the exam outline that took effect on 1 August 2026. Study material written against the previous outline is now describing a slightly different exam, and the AI/ML sub-domains in Domains 1 and 2 are new — check the publication date of anything you buy.
What the exam is actually like
Three hours, 100 to 150 items, scored 700 out of 1000. The scoring is scaled and compensatory, so a strong domain can offset a weak one — but only if you answered. There is no penalty for guessing and no way to recover an unanswered item.
The questions want the best answer, not the correct one. Two options will usually both work. The one that scores is the one a risk manager would sign off: policy before tooling, contract before configuration, the control that is auditable over the control that is clever. Candidates who argue with this pattern rather than learning it are the ones who resit.
Where the marks are lost
Answering as an engineer. The exam consistently rewards governance thinking, and the most common failure is a strong practitioner picking the technically superior answer over the one the framework prescribes.
Before you book
The exam costs $599 in the Americas, and the certification runs on a three-year cycle with 90 CPE credits and an annual maintenance fee — a recurring commitment, not a one-off purchase. Confirm the experience requirement before you pay: without it you can still pass and hold Associate of ISC2 status while you accrue it, but that is a decision worth making on purpose.
Exam domains
Cloud Concepts, Architecture and Design
17%Cloud Data Security
20%Cloud Platform and Infrastructure Security
17%Cloud Application Security
16%Cloud Security Operations
17%Legal, Risk and Compliance
13%Preparation path
- 1
Check the experience requirement before you spend anything
CCSP needs five years of paid IT experience, three of them in information security and one in a CCSP domain. Without it you can still sit the exam and become an Associate of ISC2 while you accrue the rest — but decide that deliberately rather than discovering it at endorsement.
~2 hours - 2
Read the outline as a checklist, not as background
Every sub-domain begins with a verb — understand, design, evaluate, implement — and that verb is the depth you are expected to reach. 'Comprehend cloud infrastructure components' and 'design a secure data centre' are not the same amount of study, and the outline is telling you so.
~4 hours - 3
Work Cloud Data Security first — it is the largest domain
At 20% it outweighs every other domain, and it is the one where vendor experience misleads: the exam asks about the data lifecycle, tokenisation, IRM and retention policy rather than about a particular provider's encryption menu. Learn the vocabulary the outline uses.
~35 hours - 4
Do not skip Legal, Risk and Compliance
It is the smallest domain at 13% and the one technical candidates fail on. Jurisdiction, e-discovery, cloud contract design and privacy regimes are unfamiliar and cannot be reasoned out from engineering knowledge — this is memorisation, and it is where an otherwise strong candidate loses a pass.
~20 hours - 5
Cover the four remaining domains in weight order
Architecture, Platform and Infrastructure, Operations and Application Security together carry 67%. None is dominant, which makes even coverage the right strategy — the compensatory scoring means a strong domain can rescue a weak one, but only if nothing has been left blank.
~45 hours - 6
Practise the question style, not just the material
ISC2 items are scenario-based and often have two defensible answers, one of which is better. Train the habit of asking what a risk manager would choose rather than what an engineer would build — that single reframing moves more marks than another pass through the material.
~20 hours
Frequently asked questions
Career Roadmaps
- Cloud Security Engineer RoadmapA path into cloud security as an engineering discipline, covering the shared responsibility model, identity, network segmentation, encryption, workload hardening, detection, governance as code, threat modelling and incident response.
- Cloud Architect RoadmapA path into cloud architecture as the job it actually is — trade-off analysis, migration of systems you did not write, disaster recovery you have rehearsed, decision records, and influence without formal authority.
- AI Security Engineer RoadmapA defensive security path for engineers who secure LLM and agent systems, covering AI threat modelling, prompt injection defence, supply chain integrity, agent permissions, guardrails, governance and incident response.