Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about the Cloud Security Alliance's CCSK as of 2026: the twelve v5 domains, the open-book exam, what it costs, who it fits, the jobs it leads to, and how CCSK compares to CCSP and CISSP. A complete reference for anyone deciding whether the CCSK is the right first step into cloud security.
CCSK is the Cloud Security Alliance's vendor-neutral certificate for cloud security knowledge, and often the first credential people earn when they move into cloud security.
It tests your understanding of the twelve domains of CSA Security Guidance v5, from cloud architecture and governance through identity, monitoring, workload and data security, application security, incident response, and the Zero Trust and artificial intelligence material CSA added in v5. Nothing in it belongs to one provider. The same concepts apply to AWS, Azure, Google Cloud, or all three at once.
CSA is deliberate about the word certificate. CCSK proves knowledge, not years on the job: there are no prerequisites, the exam is open book, and the certificate never expires. The current version, v5, has been available since July 16, 2024; the v4 exam retired on January 1, 2026. CCSK is issued and maintained by the Cloud Security Alliance, the nonprofit behind the Security Guidance that much of the industry treats as its cloud security reference.
Service and deployment models, shared responsibility, the logical model of cloud.
Governance hierarchy, cloud policies, contracts and provider relationships.
Cloud risk assessment, compliance obligations, audits and provider attestations.
Account hierarchies, organizational policies, hybrid and multi-cloud structures.
Federation, single sign-on, strong authentication, authorization for people and workloads.
Cloud telemetry, logging, security analytics and detection.
Virtual networks, segmentation, the management plane, infrastructure as code.
Virtual machines, containers, serverless and platform services.
Data lifecycle, classification, encryption, key management, residency.
DevSecOps, secure pipelines, API security, secrets management.
Cloud incident handling, evidence, provider coordination, recovery.
Zero Trust as a strategy, artificial intelligence as workload and tool.
Four things that make CCSK a common first credential in cloud security, and one thing it is not.
CCSK is focused entirely on cloud security and architecture, and it belongs to no provider. You learn the shared responsibility model, the governance structure, and the data and identity controls once, then apply them to whichever platform your employer runs. Teams that span two or three clouds tend to value that more than a console-specific badge.
The Cloud Security Alliance publishes the Security Guidance that security teams, auditors, and providers cite when they talk about cloud controls. CCSK is that body testing you on its own material, which is why the certificate is recognized across providers and frameworks rather than inside one ecosystem.
ISC2 and CSA built the CCSP together in 2015, and CSA calls CCSK the essential first step in preparing for other cloud certifications. ISC2 accepts CCSK in place of one year of the CCSP experience requirement. Our CCSP guide covers where that path leads.
CCSK is a vendor-neutral certificate, and it is not the credential people use to qualify for DoD 8140 work roles. If your position depends on the DoD Cyber Workforce Framework, treat CCSK as background knowledge rather than a qualification.
Check the current DoD 8140 Approved Qualifications Matrix at the DoD Cyber Exchange for what a given role accepts. If you need a cloud credential that appears on that matrix, ISC2's CCSP is the one to look at.
The certificate, the exam, and what happens after you pass, as CSA publishes them in 2026.
CCSK proves you understand cloud security. The credentials that follow prove you can do it at a professional level, or that you know one platform in depth. These three come up most often.
ISC2's Certified Cloud Security Professional is the natural next step. CSA says it builds on many of the areas CCSK covers with deeper knowledge from hands-on experience. It requires five years of experience, and CCSK counts for one of them.
ISC2's flagship CISSP covers security across eight domains, of which cloud is one part. For people who want to lead security programs rather than specialize in cloud, it is the broader target. Five years of experience required.
AWS Certified Security Specialty and Microsoft's Azure Security Engineer (AZ-500) go deep on one provider. CCSK gives you the concepts; these prove you can configure the specific services your organization runs on.
CCSK sits at the entry to cloud security. It assumes basic security literacy, adds the cloud-specific layer on top, and leads into professional cloud certification, broad security leadership, or platform-specific depth.
Security fundamentals
The vendor-neutral certificate
Pick your path
Two things to settle before you buy a token: whether you are ready for the material, and whether CCSK is the credential that moves you toward the work you want. A straight answer to both.
You can start now.
CCSK has no prerequisites, and CSA's recommended background is a basic understanding of security fundamentals: firewalls, secure development, encryption, and identity and access management. If you have that from an IT, development, audit, or security role, the cloud-specific material is the only new layer. Study the CCSK Study Guide, buy a token, and sit the open-book exam when you are ready.
Nothing stops you, but sequence it.
There is no gate, so you can register today. In practice the twelve domains assume you already know what a firewall does and why keys matter. Spend time on the fundamentals first, whether that is Security+, ISC2's CC, or a solid self-study run, and the CCSK material will land as an extension of what you know rather than a wall of new terms.
CCSK is rarely the only credential a job asks for, but it is often the one that gets a resume past the cloud filter. These are the roles where it does the most work.
Monitors cloud accounts, reviews configurations, and works alerts from cloud telemetry. CCSK gives an analyst the shared responsibility model and the monitoring domain in a form that applies to any provider.
Builds and maintains the controls that protect cloud workloads: identity policies, encryption, network segmentation, and logging. CCSK is often the first credential asked for before a platform-specific one.
Designs cloud environments and has to make security decisions early, when they are cheap to get right. CCSK covers governance, architecture, and data security at the level an architect needs to reason about them.
Assesses cloud providers, maps controls to frameworks, and answers auditors. The Cloud Governance and Risk, Audit, and Compliance domains are written for exactly this work.
Secures the pipelines and platforms developers ship through: infrastructure as code, container and serverless workloads, and secrets. CCSK v5 expanded its application security, CI/CD, and DevSecOps material, which is where this role lives.
Advises clients on cloud adoption, migration risk, and provider selection. A vendor-neutral certificate is useful when the next client runs a different cloud from the last one.
All three touch cloud security, at different depths: a knowledge certificate, a professional cloud certification, and a broad security certification. Side by side.
| CCSK | CCSP | CISSP | |
|---|---|---|---|
| Issuer | Cloud Security Alliance | ISC2 | ISC2 |
| Type | Knowledge certificate | Professional certification | Professional certification |
| Focus | Cloud security, 12 domains | Cloud security, 6 domains | Broad security across 8 domains |
| Exam Format | Open book, 60 items, 120 min | Adaptive, 100 to 150 items, 3 hrs | Adaptive, 100 to 150 items, 3 hrs |
| Experience | None required | 5 yrs IT (3 security, 1 in domain) | 5 yrs in 2+ domains |
| Passing Score | 80% | 700 / 1000 | 700 / 1000 |
| Exam Cost | $445 token, 2 attempts | ~$599 USD | ~$749 USD (Americas) |
| Renewal | None (no expiration) | 90 CPEs over 3 years | 120 CPEs over 3 years |
| DoD 8140 Matrix | Not the credential used for 8140 roles | Yes (Int. to Advanced) | Yes (Advanced) |
| Best For | Entering cloud security | Cloud security professionals | Architects and senior generalists |
ISC2 pricing varies by region. A common sequence is CCSK first, CCSP once the experience is there, and CISSP for those who move toward broader security leadership.
Our CSA CCSK v5 Plus Training runs three days: all twelve v5 domains, plus a full day of instructor-guided AWS labs, with the $445 exam voucher (two attempts) and a free retake included. If you want the lectures without the labs, the two-day CSA CCSK v5 Foundation Training covers the same twelve domains. Both are listed on our CSA training page.
How CCSK relates to CCSP and CISSP, the domains in practice, and what maintaining a stack of credentials actually involves.
People compare these two because both show up in cloud job postings, but they measure different things. A plain read on what CCSK proves, what CISSP proves, and who needs which.
The two ISC2 credentials most CCSK holders consider next. How they differ in scope, experience requirements, and exam format, and which one follows CCSK more naturally.
If CCSK is your stepping stone to CCSP, the CCSP outline you will sit changed in August 2026. What moved, what stayed, and how to time the second exam.
Incident response is one of the twelve CCSK domains for a reason. Why investigating an incident in someone else's data center is different, and what teams get wrong.
Zero Trust entered the CCSK with v5. A look at the credentials that cover it, how CCSK treats it as a strategy rather than a product, and where to go for more depth.
The provider handles security, the cloud is less safe than on premises, encryption solves everything. Five assumptions the CCSK material takes apart, and what is actually true.
CCSK has no continuing education requirement and does not expire, which is unusual. How that compares with ISC2, ISACA, and CompTIA renewal rules if you plan to hold several credentials.
The CCSK v5 exam covers all twelve domains of CSA Security Guidance v5. CSA does not publish per-domain weights, so expect questions from across the set. Click any domain for what it covers.
What cloud computing is and how CSA defines it: service and deployment models, the shared responsibility model, and the logical model of cloud infrastructure. It sets the vocabulary every other domain builds on.
How an organization steers its use of cloud rather than just consuming it. It covers the governance hierarchy, cloud policies, and how contracts and provider assessments fit into that structure.
Assessing and managing cloud risk, from provider due diligence to the responsibilities that shift as you move up the service stack. It also covers compliance obligations, audit approaches, and how provider attestations are used.
How to structure and secure the organizational layer of a cloud deployment: account hierarchies, organizational units, and the policies applied across them. It also covers the hybrid and multi-cloud arrangements most enterprises actually run.
Identity in the cloud, where the identity layer replaces the network perimeter as the primary control. Federation, single sign-on, strong authentication, and authorization models for both people and workloads.
Collecting and using cloud telemetry: logs, events, and metrics from the provider and from your own workloads. It covers security analytics, detection approaches, and the practical differences between monitoring on premises and monitoring a cloud account.
Securing the infrastructure layer: virtual networks, software-defined networking, segmentation, and the provider management plane. It also covers infrastructure as code and how to protect the pipelines that build cloud environments.
Protecting the things that run in the cloud: virtual machines, containers, serverless functions, and the platform services beneath them. It covers hardening, vulnerability management, and the shared responsibility split for each workload type.
The cloud data lifecycle and the controls at each stage: classification, storage, encryption, key management, and access. It also covers data residency and the protections that follow data as it moves between services and regions.
Secure development and deployment in cloud environments, including DevSecOps, secure pipelines, and testing. It covers API security, secrets management, and the application-layer risks introduced by cloud-native architectures.
How incident response changes when the infrastructure belongs to someone else: detection, investigation, evidence collection, and coordination with the provider. It also covers resilience, continuity, and recovery planning across cloud services.
The adjacent topics CSA groups at the end of the guidance: Zero Trust as a strategy, and artificial intelligence both as a workload to secure and as a tool used by attackers and defenders. It closes with how these strategies tie back to the other eleven domains.
Domains reflect CSA Security Guidance v5 and the CCSK v5 exam available since July 16, 2024. The primary study source is the CCSK Study Guide; CSA says the Security Guidance itself is no longer the primary study material and is not required to pass.
The questions people ask most often when researching the Certificate of Cloud Security Knowledge.
CCSK, the Certificate of Cloud Security Knowledge, is the Cloud Security Alliance's vendor-neutral cloud security certificate. It tests your understanding of the twelve domains of CSA Security Guidance v5, from cloud architecture and governance through identity, data security, incident response, Zero Trust, and AI. CSA calls it a certificate rather than a certification: it proves knowledge, and it has no experience requirement.
Anyone who works in or alongside cloud environments and needs a shared, provider-neutral understanding of cloud security: analysts, engineers, architects, developers, auditors, and GRC staff. It's also a sensible first cloud credential for people coming from on-premises security. If you already have years of hands-on cloud security work, CCSP may be the better target.
CSA sells the CCSK exam as a $445 token. Each token includes two attempts and is valid for two years from purchase. Training isn't required, so self-study is a legitimate route, and training providers commonly bundle the token into a course.
The CCSK v5 exam is 60 multiple-choice questions drawn randomly from a question pool, with 120 minutes to complete them and a minimum passing score of 80 percent. It's open book and delivered online, available on demand at any time, so there's no scheduling step. Two attempts come with each token.
No. CCSK has no prerequisites and no work experience requirement. CSA does recommend a basic understanding of security fundamentals before you start: firewalls, secure development, encryption, and identity and access management. If those are new to you, plan to cover them before the cloud material.
The CCSK v5 exam covers all twelve domains of CSA Security Guidance v5: Cloud Computing Concepts and Architectures; Cloud Governance; Risk, Audit, and Compliance; Organization Management; Identity and Access Management; Security Monitoring; Infrastructure and Networking; Cloud Workload Security; Data Security; Application Security; Incident Response and Resilience; and Related Technologies and Strategies. CSA does not publish per-domain weights for v5.
No. The CCSK certificate does not expire, and there are no continuing professional education credits or maintenance fees. CSA does release new versions of the exam, so holders of an older version can choose to sit the current one, but nothing lapses if they don't.
CCSK is a vendor-neutral certificate and is not the credential people use to qualify for DoD 8140 work roles. Check the current DoD 8140 Approved Qualifications Matrix at public.cyber.mil for what a given role accepts. If you need a cloud credential that appears on that matrix, ISC2's CCSP is the one to look at.
CCSK is a knowledge certificate from CSA with no experience requirement and an open-book exam. CCSP is a professional certification from ISC2 that requires five years of experience and an adaptive exam. ISC2 and CSA developed CCSP together in 2015, and CSA describes CCSP as building on many of the areas CCSK covers, with deeper knowledge from hands-on experience. CSA calls CCSK the essential first step toward other cloud certifications, and ISC2 accepts it in place of one year of the CCSP experience requirement.
CCSK v5, available since July 16, 2024. The v4 exam was available until January 1, 2026 and is now retired. The primary study source for v5 is the CCSK Study Guide; CSA says Security Guidance v5 is no longer the primary study material and isn't required to pass. Make sure any course or book you buy is written for v5.
CSA describes Foundation as a lecture course covering the Security Guidance v5 concepts, designed to prepare you for the exam, and Plus as covering all of that material and adding hands-on labs in a cloud environment. Training Camp runs both: the two-day CSA CCSK v5 Foundation Training, and the three-day CSA CCSK v5 Plus Training with a full day of instructor-guided AWS labs. Pick Plus if you want to practice the controls, Foundation if you want the concepts and the certificate.
For anyone new to cloud security, or moving between providers, yes. It's inexpensive next to professional certifications, it never needs renewing, and the v5 update brought Zero Trust, DevSecOps, and AI into scope. It's less useful if you already hold CCSP or work only in one provider's stack and need platform-specific depth.
Tell us where you are, from weighing the certificate against CCSP to planning cloud training for a whole team, and we'll help you map out the right path.