You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The Certified Cloud Security Professional (CCSP) certification validates your advanced technical skills to design, manage, and secure data, applications, and infrastructure in the cloud. It is ideal for experienced IT and cybersecurity professionals responsible for cloud security architecture, operations, and compliance. Earning the CCSP demonstrates you can apply best practices and policies established by ISC2's global community of cybersecurity experts to protect critical assets in the cloud.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The Certified Cloud Security Professional (CCSP) certification from ISC2 is a globally recognized credential that proves you have the advanced technical skills and knowledge to design, manage, and secure data, applications, and infrastructure in the cloud. It is built on a comprehensive body of knowledge that covers cloud concepts, architecture, data security, platform and infrastructure security, application security, operations, and legal, risk, and compliance. The CCSP demonstrates your ability to apply best practices, policies, and procedures established by ISC2's certified members and cybersecurity experts around the globe.
Earning the CCSP validates your competence in cloud security design, implementation, architecture, operations, controls, and compliance with regulatory frameworks. It is designed for experienced professionals who apply information security expertise to cloud computing environments and demonstrates your ability to secure complex cloud environments and lead cloud security initiatives. As a CCSP, you join a community of cybersecurity leaders and gain access to ongoing professional development and networking opportunities.
The CCSP is ideal for IT, cyber, information, and software security leaders responsible for applying best practices to cloud security architecture, design, operations, and service orchestration. This includes professionals in roles such as Cloud Architect, Cloud Engineer, Cloud Consultant, Cloud Administrator, Cloud Security Analyst, Cloud Specialist, Auditor of Cloud Computing Services, and Professional Cloud Developer. If you are an experienced security practitioner looking to demonstrate your expertise in cloud security and advance your career, the CCSP is designed for you. It is also suitable for professionals who want to validate their skills in securing cloud environments and gain a globally recognized credential that is respected by employers across industries.
A minimum of five years of cumulative, full-time IT experience, including three years in cybersecurity and one year in one or more of the six CCSP domains. A bachelor's or master's degree in computer science, IT, or a related field may waive up to one year of experience, and the CSA's CCSK certificate can substitute for one year. An active CISSP credential waives the entire experience requirement. Five years cumulative, full-time IT experience; Three years of cybersecurity experience; One year in one or more of the six CCSP domains; A post-secondary degree (bachelors or masters) in computer science, IT, or related fields may satisfy up to one year of experience; CSA's CCSK certificate can substitute for one year of experience; Part-time work and internships may count towards the experience requirement
Every domain and objective ISC2 measures, with the weight they carry on the exam.
The official ISC2 exam outline · checked 30 July 2026 · See the source
Everything ISC2 publishes about sitting it, and nothing we inferred.
Minimum of five years cumulative, full-time IT experience, including three years in cybersecurity and one year in one or more of the six CCSP domains.
The path ISC2 lays out, how the credential is kept, and where to book.
Step-by-step path to Certified Cloud Security Professional
CCSP certification is valid for three years and must be renewed by earning continuing professional education (CPE) credits and paying an annual maintenance fee (AMF). Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. ISC2 maintains this certification to validate current skills and industry relevance.
Register for the exam through Pearson VUE, ISC2’s authorized testing partner.
Schedule your examVisit the official ISC2 certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksAn active CISSP credential can be substituted for the entire CCSP experience requirement, making it a common pathway for CISSP holders to earn the CCSP.
Yes, a new CCSP exam outline becomes effective August 1, 2026. Candidates should review the latest outline to ensure their study plan aligns with the updated domains and topics.
Yes, you can take the exam and become an Associate of ISC2 if you pass but do not yet have the required experience. You will have six years to earn the five years of required experience.
ISC2 exam retake policies apply. Candidates who purchase the exam with Peace of Mind Protection receive two exam attempts with a 30-day waiting period between attempts.
The CCSP exam uses Computerized Adaptive Testing (CAT) and consists of multiple choice and advanced item types. There is no hands-on lab component.
The CCSP is ideal for cloud architects, cloud engineers, cloud consultants, cloud administrators, cloud security analysts, cloud specialists, auditors of cloud computing services, and professional cloud developers.
ISC2 certifications are renewed by earning CPE credits and paying the annual maintenance fee. Passing a higher-level exam may not automatically renew the CCSP; you must meet the renewal requirements.
The CCSP exam is delivered at Pearson VUE testing centers worldwide. However, Chinese language exams are only available during specific appointment windows each year.
Every domain, every objective, and every concept ISC2 measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official ISC2 exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
52 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 38 objectives, 310 concepts written under them, and free questions against every one. When ISC2 changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.