Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about ISC2's cloud security certification as of 2026, covering the six domains, exam format, experience requirements, career paths, DoD 8140 status, and how CCSP compares to CISSP and CCSK. A complete reference guide for anyone weighing the CCSP or trying to understand what it covers.
Cloud models, reference architecture, and the shared responsibility model. 17% of the exam.
Data lifecycle, encryption, key management, and classification. The heaviest domain at 20%.
Securing compute, storage, networking, and virtualization. 17% of the exam.
Secure development, testing, API security, and DevSecOps. 17% of the exam.
Running cloud infrastructure: monitoring, logging, and incident handling. 16% of the exam.
Privacy, jurisdiction, audit, and cloud risk management. 13% of the exam.
CCSP is ISC2's cloud security certification, launched in 2015 with the Cloud Security Alliance and held by cloud security professionals worldwide.
It validates the ability to design, operate, and secure data, applications, and infrastructure in the cloud across six domains. The credential is deliberately vendor-neutral. Rather than testing one provider's console, it tests the principles that hold across AWS, Azure, Google Cloud, and anywhere else an organization runs workloads, built around the shared responsibility model.
The credential is ANAB-accredited under ISO/IEC 17024, approved under DoD 8140, and gated behind a five-year experience requirement. It sits a tier above foundational cloud credentials. CCSP is issued and maintained by ISC2, which developed the program with the Cloud Security Alliance in 2015.
Four things that have made CCSP the credential most often named when employers describe a cloud security hire.
CCSP isn't tied to AWS, Azure, or Google Cloud. It validates the principles that hold across all of them, built around the shared responsibility model. That breadth is exactly what multi-cloud and hybrid environments need, and it sits a tier above foundational cloud credentials.
CCSP was developed jointly by ISC2, the body behind CISSP, and the Cloud Security Alliance, the group that defines much of the cloud security guidance the industry follows. That pedigree is why it carries weight the moment it lands on a resume.
As of 2026, CCSP holders in the US commonly land around $170,000, with cloud security architects going higher. Our look at the highest-paid cybersecurity jobs puts it in context.
CCSP is an approved qualification under DoD Manual 8140.03, mapped to fifteen work roles in the DoD Cyber Workforce Framework (DCWF). It qualifies at the Intermediate or Advanced proficiency level depending on the role, across the IT, Software Engineering, Cybersecurity, and Cyberspace Enabler elements.
With element-level qualification now mandatory across the department, an approved credential like CCSP is what lets people fill those cloud and security roles. Current qualification matrices are published at the DoD Cyber Exchange.
Everything you need to know about the certification, the exam structure, and how to maintain CCSP as of 2026.
CCSP proves vendor-neutral cloud security expertise. From there, professionals tend to broaden into general security leadership or go deep on a specific cloud platform. These credentials most often come next.
ISC2's flagship CISSP adds broad security depth across eight domains. Many professionals pair the two: CISSP for the wide enterprise view, CCSP for the cloud specialty. It requires five years of experience.
Where CCSP is vendor-neutral, the AWS Certified Security Specialty goes deep on one platform. It is a strong add for teams running critical workloads in AWS who need provider-specific depth.
The Microsoft Azure Security Engineer (AZ-500) is the Azure counterpart, validating platform-specific security skills. A natural pairing with CCSP for organizations standardized on Microsoft cloud.
CCSP is the specialist credential for people who live in cloud environments. It builds on general IT and security literacy and leads into broad security leadership or platform-specific cloud depth.
Build the baseline
The specialty
Two questions to answer before you commit: can you certify, and should you pursue CCSP specifically. Here's a straight answer to both.
You can certify in full.
You have five years of cumulative IT experience, with three years in cybersecurity and one year in one or more of the six CCSP domains. A relevant degree or the CCSK certificate can cover one year, and an active CISSP waives the entire requirement. Pass the exam, get endorsed, and you hold the full CCSP.
You can still pass now.
Sit the exam without the experience, and once you pass you become an Associate of ISC2. From there you have six years to earn the five years of experience and convert to full CCSP status, so the exam never has to wait on your resume.
CCSP maps to cloud security roles across the private sector and the federal cyber workforce. Several of these are DCWF work roles where CCSP qualifies at the Intermediate level.
Designs secure cloud environments across providers, from network and identity to data protection. CCSP is the credential most often named for the role, because it is vendor-neutral by design.
Implements and operates the controls that protect cloud workloads: IAM policies, encryption, monitoring, and cloud-native security tooling across AWS, Azure, and Google Cloud.
Designs the security controls and frameworks an organization is built on. DCWF work role 652, where CCSP qualifies at the Intermediate proficiency level.
Analyzes and maintains the security of systems and their environments. DCWF work role 461, where CCSP qualifies at the Intermediate level.
Advises organizations on cloud security posture, compliance, and migration risk. CCSP is the credential clients most often expect for vendor-neutral cloud guidance.
Investigates and responds to security incidents, increasingly in cloud and hybrid environments. DCWF work role 531, where CCSP qualifies at the Intermediate level.
All three touch cloud security, but at different depths: broad security, professional cloud, and foundational cloud. Here's how they line up.
| CCSP | CISSP | CCSK | |
|---|---|---|---|
| Issuer | ISC2 | ISC2 | Cloud Security Alliance |
| Focus | Cloud security (professional) | Broad security across 8 domains | Cloud security (foundational) |
| Exam Format | Adaptive, 100 to 150 items, 3 hrs | Adaptive, 100 to 150 items, 3 hrs | Open book, 60 items, 2 hrs |
| Experience | 5 yrs IT (3 security, 1 in domain) | 5 yrs in 2+ domains | None required |
| Passing Score | 700 / 1000 | 700 / 1000 | 80% |
| Renewal | 90 CPEs over 3 years | 120 CPEs over 3 years | None (no expiration) |
| DoD 8140 Approved | Yes (Int. to Advanced) | Yes (Advanced) | No |
| Best For | Cloud security professionals | Architects and senior generalists | Foundational cloud knowledge |
Pricing and renewal details vary by region and membership status. Many practitioners start with CCSK, then earn CCSP, and pair it with CISSP over time.
Our official ISC2 CCSP boot camp covers all six domains over six days, with your exam voucher, official courseware, and a free retake guarantee included, so experienced practitioners leave exam-ready.
Certification decisions, the CCSP and CISSP relationship, cloud careers, and salary data.
The question candidates ask most. CISSP goes wide across all of security; CCSP goes deep on cloud. A clear read on which fits where you are and where you want to be.
CISSP is the wide-angle lens on enterprise security, CCSP the zoom lens on cloud. When holding both makes sense, and when one is enough for the career you want.
For people broadening from general security into cloud, CCSP is the natural specialization. A look at where it fits among the credentials that follow a CISSP.
Where cloud security roles land on the pay scale, with CCSP holders sitting around $170,000 and cloud security engineers among the most in-demand hires in the field.
A full walkthrough of ISC2's flagship credential and how it relates to CCSP, useful for anyone deciding whether to lead with broad security or go straight to cloud.
How vendor-specific cloud credentials pay and where they fit. A useful counterpoint for weighing CCSP's vendor-neutral approach against platform-specific certifications.
Where a security career often starts, and how cloud credentials like CCSP build on that Security+ foundation to raise both salary and the roles open to you.
The CCSP Common Body of Knowledge is organized into six domains, each carrying its own weight on the exam. Click any domain for what it covers.
Cloud computing definitions and roles, the reference architecture, service and deployment models, the shared responsibility model, and secure-by-design principles for cloud environments.
The heaviest domain. The cloud data lifecycle, storage architectures, encryption and key management, data classification, rights management, and retention and deletion in someone else's data center.
Securing the physical and virtual cloud infrastructure: compute, storage, networking, virtualization, identity and access, and the controls that protect the platform layer.
Secure software development in the cloud, application security testing, supply chain and API security, identity and access management for applications, and DevSecOps practices.
Building, running, and managing cloud infrastructure day to day: operational controls, monitoring and logging, incident handling, and digital forensics in cloud environments.
Legal and regulatory requirements, privacy, jurisdiction, audit processes, cloud risk management, and the contractual and vendor management side of cloud security.
Domains and weights reflect the ISC2 CCSP Exam Outline effective October 1, 2025. A new exam outline takes effect August 1, 2026.
The questions candidates ask most often when researching the Certified Cloud Security Professional certification.
CCSP is ISC2's cloud security certification, developed with the Cloud Security Alliance. It validates the ability to design, operate, and secure data, applications, and infrastructure in the cloud across six domains, and it's built to be vendor-neutral rather than tied to one provider.
CCSP fits experienced security professionals whose work centers on cloud: architects, engineers, and consultants securing workloads across AWS, Azure, and Google Cloud. It isn't an entry-level certification. If you're starting out, Security+ or SSCP is usually the better first step.
The CCSP exam costs approximately $599 USD as of 2026, set by ISC2 and varying slightly by region. The fee covers the exam itself, not training or study materials. Many boot camps fold the exam voucher into the course price, so check what's included before you pay separately.
Since October 2025 the CCSP uses Computerized Adaptive Testing (CAT) with 100 to 150 items over a maximum of three hours. Alongside standard multiple choice, expect advanced item types. You need a scaled score of 700 out of 1000 to pass.
CCSP requires five years of cumulative IT experience, with three years in cybersecurity and one year in one or more of the six CCSP domains. A relevant degree or the CCSK certificate can waive one year, and an active CISSP satisfies the entire experience requirement.
Yes. You can sit and pass the exam before you have the required experience and become an Associate of ISC2. From there you have six years to earn the five years of experience needed to convert to full CCSP status.
The six CCSP domains are Cloud Concepts, Architecture and Design; Cloud Data Security; Cloud Platform and Infrastructure Security; Cloud Application Security; Cloud Security Operations; and Legal, Risk and Compliance. Cloud Data Security carries the heaviest weight at 20 percent.
CCSP is valid for three years. To renew, you earn 90 Continuing Professional Education (CPE) credits across the cycle and pay an annual maintenance fee to ISC2. At least 60 of those credits must relate directly to the CCSP domains.
Yes. CCSP appears on the DoD 8140 Approved Qualifications Matrix V2.1, mapped to fifteen DCWF work roles such as Security Architect, Systems Security Analyst, and Cyber Defense Incident Responder. It qualifies at the Intermediate or Advanced level depending on the role. See the full DoD 8140 work role paths.
Both are ISC2 credentials, but CISSP goes wide across eight security domains while CCSP goes deep on cloud across six. CISSP is the broad credential hiring managers look for first; CCSP is the specialist credential for people who work in cloud environments. Many professionals earn CISSP first and add CCSP to specialize.
Yes. The current outline took effect October 1, 2025, when the exam moved to adaptive testing. ISC2 has confirmed a new CCSP exam outline effective August 1, 2026, following its latest Job Task Analysis. If you test on or after that date, make sure your study materials match the new outline.
For security professionals working in or moving into cloud, CCSP remains one of the strongest credentials available in 2026. It carries broad employer recognition, satisfies DoD 8140, and is consistently tied to senior cloud security pay. It's less useful for those early in their careers or on a purely on-premises track.
Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.