Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Certification Guide

The Certified Cloud Security Professional
Certification Explained.

Everything you need to know about ISC2's cloud security certification as of 2026, covering the six domains, exam format, experience requirements, career paths, DoD 8140 status, and how CCSP compares to CISSP and CCSK. A complete reference guide for anyone weighing the CCSP or trying to understand what it covers.

CCSP_FAST_FACTS
Issuer: ISC2
Exam: 100 to 150 questions, 3 hours
Passing Score: 700 / 1000
Experience: 5 years (3 in security)
DoD 8140 Approved
6 CCSP Domains 5 YRS Experience Required 100-150 Exam Questions 3-HOUR Adaptive Exam SINCE 2015 ISC2 Issued
UPDATED 2026
The CCSP Domains

Six Domains of Cloud Security

01

Concepts, Architecture and Design

Cloud models, reference architecture, and the shared responsibility model. 17% of the exam.

02

Cloud Data Security

Data lifecycle, encryption, key management, and classification. The heaviest domain at 20%.

03

Platform and Infrastructure Security

Securing compute, storage, networking, and virtualization. 17% of the exam.

04

Cloud Application Security

Secure development, testing, API security, and DevSecOps. 17% of the exam.

05

Cloud Security Operations

Running cloud infrastructure: monitoring, logging, and incident handling. 16% of the exam.

06

Legal, Risk and Compliance

Privacy, jurisdiction, audit, and cloud risk management. 13% of the exam.

Overview

What Is the Certified Cloud Security Professional?

CCSP is ISC2's cloud security certification, launched in 2015 with the Cloud Security Alliance and held by cloud security professionals worldwide.

It validates the ability to design, operate, and secure data, applications, and infrastructure in the cloud across six domains. The credential is deliberately vendor-neutral. Rather than testing one provider's console, it tests the principles that hold across AWS, Azure, Google Cloud, and anywhere else an organization runs workloads, built around the shared responsibility model.

The credential is ANAB-accredited under ISO/IEC 17024, approved under DoD 8140, and gated behind a five-year experience requirement. It sits a tier above foundational cloud credentials. CCSP is issued and maintained by ISC2, which developed the program with the Cloud Security Alliance in 2015.

2015 First Administered
6 Domains
5 Yr Experience
Why CCSP Matters

Why Is CCSP So Widely Recognized?

Four things that have made CCSP the credential most often named when employers describe a cloud security hire.

Vendor-Neutral, Cloud-Wide

CCSP isn't tied to AWS, Azure, or Google Cloud. It validates the principles that hold across all of them, built around the shared responsibility model. That breadth is exactly what multi-cloud and hybrid environments need, and it sits a tier above foundational cloud credentials.

Backed by ISC2 and the CSA

CCSP was developed jointly by ISC2, the body behind CISSP, and the Cloud Security Alliance, the group that defines much of the cloud security guidance the industry follows. That pedigree is why it carries weight the moment it lands on a resume.

Tied to Senior Cloud Pay

As of 2026, CCSP holders in the US commonly land around $170,000, with cloud security architects going higher. Our look at the highest-paid cybersecurity jobs puts it in context.

DoD 8140 Approved

CCSP is an approved qualification under DoD Manual 8140.03, mapped to fifteen work roles in the DoD Cyber Workforce Framework (DCWF). It qualifies at the Intermediate or Advanced proficiency level depending on the role, across the IT, Software Engineering, Cybersecurity, and Cyberspace Enabler elements.

With element-level qualification now mandatory across the department, an approved credential like CCSP is what lets people fill those cloud and security roles. Current qualification matrices are published at the DoD Cyber Exchange.

Int. & Advanced Proficiency 15 DCWF Roles 4 Workforce Elements
Fast Facts

What Are the Key Facts About CCSP?

Everything you need to know about the certification, the exam structure, and how to maintain CCSP as of 2026.

01

The Certification

Certification Name
Certified Cloud Security Professional (CCSP)
Issued By
ISC2 (with the Cloud Security Alliance)
Exam Outline
Effective October 1, 2025
First Administered
2015
Prerequisites
5 yrs IT, 3 in security, 1 in a domain
Experience Waiver
1 year (degree or CCSK); CISSP waives all
No-Experience Path
Pass and hold Associate of ISC2
Accreditation
ANAB-accredited (ISO/IEC 17024)
DoD 8140 Status
Approved (15 DCWF roles, Int. to Advanced)
02

Exam & Maintenance

Exam Format
Computerized Adaptive Testing (CAT)
Number of Items
100 to 150 questions
Item Types
Multiple choice plus advanced items
Exam Duration
3 hours
Passing Score
700 out of 1000
Exam Cost
~$599 USD
Validity
3 years
CPE Requirement
90 CPEs over 3 years
Maintenance
Annual maintenance fee to ISC2
Going Deeper

What Comes After the CCSP?

CCSP proves vendor-neutral cloud security expertise. From there, professionals tend to broaden into general security leadership or go deep on a specific cloud platform. These credentials most often come next.

CISSP (Breadth)

ISC2's flagship CISSP adds broad security depth across eight domains. Many professionals pair the two: CISSP for the wide enterprise view, CCSP for the cloud specialty. It requires five years of experience.

AWS Security Specialty

Where CCSP is vendor-neutral, the AWS Certified Security Specialty goes deep on one platform. It is a strong add for teams running critical workloads in AWS who need provider-specific depth.

Azure Security Engineer

The Microsoft Azure Security Engineer (AZ-500) is the Azure counterpart, validating platform-specific security skills. A natural pairing with CCSP for organizations standardized on Microsoft cloud.

Certification Roadmap

Where Does CCSP Fit in Your Career?

CCSP is the specialist credential for people who live in cloud environments. It builds on general IT and security literacy and leads into broad security leadership or platform-specific cloud depth.

STAGE 02 You Are Here

Cloud Credential

The specialty

PRIMARY
CCSP
ISC2 · Certified Cloud Security Professional
Associate of ISC2
ISC2 · Pass first, earn experience after
STAGE 03

Specialize

Pick your path

Broad Security
Cloud Platform
Decision Point

Is CCSP Right For You?

Two questions to answer before you commit: can you certify, and should you pursue CCSP specifically. Here's a straight answer to both.

Q1

Do You Qualify for CCSP?

Path A

5+ Years in IT and Security

You can certify in full.

You have five years of cumulative IT experience, with three years in cybersecurity and one year in one or more of the six CCSP domains. A relevant degree or the CCSK certificate can cover one year, and an active CISSP waives the entire requirement. Pass the exam, get endorsed, and you hold the full CCSP.

Path B

Fewer Than 5 Years in the Field

You can still pass now.

Sit the exam without the experience, and once you pass you become an Associate of ISC2. From there you have six years to earn the five years of experience and convert to full CCSP status, so the exam never has to wait on your resume.

Q2

Is CCSP the Right Certification for Your Goals?

CCSP Is a Strong Fit If...

  • Your work centers on cloud architecture, data protection, or compliance across cloud environments
  • You run workloads in more than one cloud and want a vendor-neutral credential that spans all of them
  • You need a DoD 8140 approved credential for cloud or security work in federal or contractor settings
  • You already hold CISSP and want to prove specialized cloud expertise on top of it
  • You keep seeing CCSP listed as required or preferred for cloud security roles you want
  • You're aiming at cloud security architect, engineer, or consultant work

Consider Alternatives If...

  • You're early in your career without security fundamentals yet, start with Security+ or SSCP first
  • You want a broad security credential covering the whole field, where CISSP fits better
  • You work entirely in one cloud and need provider-specific depth, look at AWS Security Specialty or AZ-500
  • You want a foundational, entry-level cloud security credential rather than a professional one, where CCSK is the lighter start
  • You want to run a security program rather than secure cloud systems, where CISM is the management fit
  • You don't yet work in or near cloud and the domains would feel abstract
Career Paths

What Jobs Can You Get With CCSP?

CCSP maps to cloud security roles across the private sector and the federal cyber workforce. Several of these are DCWF work roles where CCSP qualifies at the Intermediate level.

Cloud Architecture

Cloud Security Architect

Designs secure cloud environments across providers, from network and identity to data protection. CCSP is the credential most often named for the role, because it is vendor-neutral by design.

Cloud Engineering

Cloud Security Engineer

Implements and operates the controls that protect cloud workloads: IAM policies, encryption, monitoring, and cloud-native security tooling across AWS, Azure, and Google Cloud.

Architecture

Security Architect

Designs the security controls and frameworks an organization is built on. DCWF work role 652, where CCSP qualifies at the Intermediate proficiency level.

Security Analysis

Systems Security Analyst

Analyzes and maintains the security of systems and their environments. DCWF work role 461, where CCSP qualifies at the Intermediate level.

Advisory

Cloud Security Consultant

Advises organizations on cloud security posture, compliance, and migration risk. CCSP is the credential clients most often expect for vendor-neutral cloud guidance.

Incident Response

Cyber Defense Incident Responder

Investigates and responds to security incidents, increasingly in cloud and hybrid environments. DCWF work role 531, where CCSP qualifies at the Intermediate level.

Comparison

How Does CCSP Compare to CISSP and CCSK?

All three touch cloud security, but at different depths: broad security, professional cloud, and foundational cloud. Here's how they line up.

  CCSP CISSP CCSK
Issuer ISC2 ISC2 Cloud Security Alliance
Focus Cloud security (professional) Broad security across 8 domains Cloud security (foundational)
Exam Format Adaptive, 100 to 150 items, 3 hrs Adaptive, 100 to 150 items, 3 hrs Open book, 60 items, 2 hrs
Experience 5 yrs IT (3 security, 1 in domain) 5 yrs in 2+ domains None required
Passing Score 700 / 1000 700 / 1000 80%
Renewal 90 CPEs over 3 years 120 CPEs over 3 years None (no expiration)
DoD 8140 Approved Yes (Int. to Advanced) Yes (Advanced) No
Best For Cloud security professionals Architects and senior generalists Foundational cloud knowledge

Pricing and renewal details vary by region and membership status. Many practitioners start with CCSK, then earn CCSP, and pair it with CISSP over time.

Ready to Get Certified?

Train for CCSP with Training Camp.

Our official ISC2 CCSP boot camp covers all six domains over six days, with your exam voucher, official courseware, and a free retake guarantee included, so experienced practitioners leave exam-ready.

View Boot Camp
Dive Deeper

CCSP Articles and Guides.

Certification decisions, the CCSP and CISSP relationship, cloud careers, and salary data.

Featured Comparison

CCSP vs CISSP: Comparing ISC2's Two Biggest Certifications

The question candidates ask most. CISSP goes wide across all of security; CCSP goes deep on cloud. A clear read on which fits where you are and where you want to be.

Read Article →
Decision Guide

CISSP vs CCSP: Do You Need Both?

CISSP is the wide-angle lens on enterprise security, CCSP the zoom lens on cloud. When holding both makes sense, and when one is enough for the career you want.

Read Article →
Career Path

What Comes After CISSP?

For people broadening from general security into cloud, CCSP is the natural specialization. A look at where it fits among the credentials that follow a CISSP.

Read Article →
Salary and Demand

Highest Paid Cybersecurity Jobs

Where cloud security roles land on the pay scale, with CCSP holders sitting around $170,000 and cloud security engineers among the most in-demand hires in the field.

Read Article →
ISC2 Foundation

The Complete CISSP Guide

A full walkthrough of ISC2's flagship credential and how it relates to CCSP, useful for anyone deciding whether to lead with broad security or go straight to cloud.

Read Article →
Cloud Careers

AWS Certified Solutions Architect Professional Salary

How vendor-specific cloud credentials pay and where they fit. A useful counterpoint for weighing CCSP's vendor-neutral approach against platform-specific certifications.

Read Article →
Foundation

CompTIA Security+ Salary Guide

Where a security career often starts, and how cloud credentials like CCSP build on that Security+ foundation to raise both salary and the roles open to you.

Read Article →
Curriculum

Inside the Six CCSP Domains.

The CCSP Common Body of Knowledge is organized into six domains, each carrying its own weight on the exam. Click any domain for what it covers.

Domains 01-03

Concepts to Platform
01 Cloud Concepts, Architecture and Design 17%

Cloud computing definitions and roles, the reference architecture, service and deployment models, the shared responsibility model, and secure-by-design principles for cloud environments.

02 Cloud Data Security 20%

The heaviest domain. The cloud data lifecycle, storage architectures, encryption and key management, data classification, rights management, and retention and deletion in someone else's data center.

03 Cloud Platform and Infrastructure Security 17%

Securing the physical and virtual cloud infrastructure: compute, storage, networking, virtualization, identity and access, and the controls that protect the platform layer.

Domains 04-06

Application to Compliance
04 Cloud Application Security 17%

Secure software development in the cloud, application security testing, supply chain and API security, identity and access management for applications, and DevSecOps practices.

05 Cloud Security Operations 16%

Building, running, and managing cloud infrastructure day to day: operational controls, monitoring and logging, incident handling, and digital forensics in cloud environments.

06 Legal, Risk and Compliance 13%

Legal and regulatory requirements, privacy, jurisdiction, audit processes, cloud risk management, and the contractual and vendor management side of cloud security.

Domains and weights reflect the ISC2 CCSP Exam Outline effective October 1, 2025. A new exam outline takes effect August 1, 2026.

Frequently Asked Questions

Common Questions About CCSP.

The questions candidates ask most often when researching the Certified Cloud Security Professional certification.

What is the CCSP certification?

CCSP is ISC2's cloud security certification, developed with the Cloud Security Alliance. It validates the ability to design, operate, and secure data, applications, and infrastructure in the cloud across six domains, and it's built to be vendor-neutral rather than tied to one provider.

Who should get the CCSP?

CCSP fits experienced security professionals whose work centers on cloud: architects, engineers, and consultants securing workloads across AWS, Azure, and Google Cloud. It isn't an entry-level certification. If you're starting out, Security+ or SSCP is usually the better first step.

How much does the CCSP exam cost in 2026?

The CCSP exam costs approximately $599 USD as of 2026, set by ISC2 and varying slightly by region. The fee covers the exam itself, not training or study materials. Many boot camps fold the exam voucher into the course price, so check what's included before you pay separately.

What is the CCSP exam like?

Since October 2025 the CCSP uses Computerized Adaptive Testing (CAT) with 100 to 150 items over a maximum of three hours. Alongside standard multiple choice, expect advanced item types. You need a scaled score of 700 out of 1000 to pass.

What experience do you need for the CCSP?

CCSP requires five years of cumulative IT experience, with three years in cybersecurity and one year in one or more of the six CCSP domains. A relevant degree or the CCSK certificate can waive one year, and an active CISSP satisfies the entire experience requirement.

Can you take the CCSP exam without experience?

Yes. You can sit and pass the exam before you have the required experience and become an Associate of ISC2. From there you have six years to earn the five years of experience needed to convert to full CCSP status.

What are the six CCSP domains?

The six CCSP domains are Cloud Concepts, Architecture and Design; Cloud Data Security; Cloud Platform and Infrastructure Security; Cloud Application Security; Cloud Security Operations; and Legal, Risk and Compliance. Cloud Data Security carries the heaviest weight at 20 percent.

How do I maintain my CCSP certification?

CCSP is valid for three years. To renew, you earn 90 Continuing Professional Education (CPE) credits across the cycle and pay an annual maintenance fee to ISC2. At least 60 of those credits must relate directly to the CCSP domains.

Is CCSP approved for DoD 8140?

Yes. CCSP appears on the DoD 8140 Approved Qualifications Matrix V2.1, mapped to fifteen DCWF work roles such as Security Architect, Systems Security Analyst, and Cyber Defense Incident Responder. It qualifies at the Intermediate or Advanced level depending on the role. See the full DoD 8140 work role paths.

What is the difference between CCSP and CISSP?

Both are ISC2 credentials, but CISSP goes wide across eight security domains while CCSP goes deep on cloud across six. CISSP is the broad credential hiring managers look for first; CCSP is the specialist credential for people who work in cloud environments. Many professionals earn CISSP first and add CCSP to specialize.

Is the CCSP exam changing in 2026?

Yes. The current outline took effect October 1, 2025, when the exam moved to adaptive testing. ISC2 has confirmed a new CCSP exam outline effective August 1, 2026, following its latest Job Task Analysis. If you test on or after that date, make sure your study materials match the new outline.

Is CCSP worth it in 2026?

For security professionals working in or moving into cloud, CCSP remains one of the strongest credentials available in 2026. It carries broad employer recognition, satisfies DoD 8140, and is consistently tied to senior cloud security pay. It's less useful for those early in their careers or on a purely on-premises track.

Get In Touch

Have Questions About CCSP?

Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.

+1
    100% Secure. NDA Compliant.
    ISC2 CCSP Boot Camp 6-Day Boot Camp · Exam Voucher Included
    View Boot Camp