Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2

Certified Cloud Security Professional

The Certified Cloud Security Professional (CCSP) certification validates your advanced technical skills to design, manage, and secure data, applications, and infrastructure in the cloud. It is ideal for experienced IT and cybersecurity professionals responsible for cloud security architecture, operations, and compliance. Earning the CCSP demonstrates you can apply best practices and policies established by ISC2's global community of cybersecurity experts to protect critical assets in the cloud.

Exam formatMultiple choice and advanced item types
Duration180 minutes
DeliveryPearson VUE
Passing score700 out of 1000 points
Free questions1030

Content last reviewed 30 July 2026 · Up to date

The certification

What Certified Cloud Security Professional proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

6domains
38objectives
310concepts
US $599exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The Certified Cloud Security Professional (CCSP) certification from ISC2 is a globally recognized credential that proves you have the advanced technical skills and knowledge to design, manage, and secure data, applications, and infrastructure in the cloud. It is built on a comprehensive body of knowledge that covers cloud concepts, architecture, data security, platform and infrastructure security, application security, operations, and legal, risk, and compliance. The CCSP demonstrates your ability to apply best practices, policies, and procedures established by ISC2's certified members and cybersecurity experts around the globe.

Earning the CCSP validates your competence in cloud security design, implementation, architecture, operations, controls, and compliance with regulatory frameworks. It is designed for experienced professionals who apply information security expertise to cloud computing environments and demonstrates your ability to secure complex cloud environments and lead cloud security initiatives. As a CCSP, you join a community of cybersecurity leaders and gain access to ongoing professional development and networking opportunities.

Who it’s for

The CCSP is ideal for IT, cyber, information, and software security leaders responsible for applying best practices to cloud security architecture, design, operations, and service orchestration. This includes professionals in roles such as Cloud Architect, Cloud Engineer, Cloud Consultant, Cloud Administrator, Cloud Security Analyst, Cloud Specialist, Auditor of Cloud Computing Services, and Professional Cloud Developer. If you are an experienced security practitioner looking to demonstrate your expertise in cloud security and advance your career, the CCSP is designed for you. It is also suitable for professionals who want to validate their skills in securing cloud environments and gain a globally recognized credential that is respected by employers across industries.

Recommended experience

A minimum of five years of cumulative, full-time IT experience, including three years in cybersecurity and one year in one or more of the six CCSP domains. A bachelor's or master's degree in computer science, IT, or a related field may waive up to one year of experience, and the CSA's CCSK certificate can substitute for one year. An active CISSP credential waives the entire experience requirement. Five years cumulative, full-time IT experience; Three years of cybersecurity experience; One year in one or more of the six CCSP domains; A post-secondary degree (bachelors or masters) in computer science, IT, or related fields may satisfy up to one year of experience; CSA's CCSK certificate can substitute for one year of experience; Part-time work and internships may count towards the experience requirement

The syllabus

What you’ll learn

Every domain and objective ISC2 measures, with the weight they carry on the exam.

The official ISC2 exam outline · checked 30 July 2026 · See the source

Cloud Concepts, Architecture and Design
  • Understand cloud computing concepts
  • Describe cloud reference architecture
  • Understand security concepts relevant to cloud computing
  • Understand design principles of secure cloud computing
  • Evaluate Cloud Service Providers (CSP)
  • Comprehend Artificial Intelligence (AI)/Machine Learning (ML)
6 objectives · 227 free questions · 48 pages
Cloud Data Security
  • Describe cloud data concepts
  • Design and implement cloud data storage architectures
  • Design and apply data security technologies and strategies
  • Implement data discovery
  • Plan and implement data classification
  • Design and implement Information Rights Management (IRM)
  • Plan and implement data retention, deletion, and archiving policies
  • Design and implement auditability, traceability, and accountability of data events
  • Comprehend data protection of Artificial Intelligence (AI) and Machine Learning (ML) data
9 objectives · 237 free questions · 52 pages
Cloud Platform and Infrastructure Security
  • Comprehend cloud infrastructure and platform components
  • Design a secure data center
  • Analyze risks associated with cloud infrastructure and platforms
  • Plan and implementation of security controls
  • Plan business continuity (BC) and disaster recovery (DR)
5 objectives · 116 free questions · 25 pages
Cloud Application Security
  • Advocate training and awareness for application security
  • Describe the Secure Software Development Life Cycle (SDLC) process
  • Apply the Secure Software Development Life Cycle (SDLC)
  • Apply cloud software assurance and validation
  • Use verified secure software
  • Comprehend and apply the specifics of cloud application architecture
  • Design appropriate Identity and Access Management (IAM) solutions
7 objectives · 143 free questions · 32 pages
Cloud Security Operations
  • Build and implement physical and logical infrastructure for cloud environment
  • Operate and maintain physical and logical infrastructure for cloud environment
  • Implement operational controls and standards (e.g., National Institute Of Standards And Technology (NIST), International Organization For Standardization (ISO), Health Insurance Portability and Accountability Act (HIPPA), Control Objectives For Information And Related Technology (COBIT), Center For Internet Security (CIS) Controls, Comittee Of Sponsoring Organizations (COSO), Information Technology Infrastructure Library (ITIL) International Organization For Standardization/International Electrotechnical Commission (ISO/IEC) 20000-1)
  • Support digital forensics
  • Manage communication with relevant parties
  • Manage security operations
6 objectives · 162 free questions · 34 pages
Legal, Risk and Compliance
  • Articulate legal requirements and unique risks within the cloud environment
  • Understand privacy issues
  • Understand audit process, methodologies, and required adaptations for a cloud environment
  • Understand implications of cloud to enterprise risk management
  • Understand outsourcing and cloud contract design
5 objectives · 145 free questions · 30 pages
On the day

The exam itself

Everything ISC2 publishes about sitting it, and nothing we inferred.

Prerequisites

Minimum of five years cumulative, full-time IT experience, including three years in cybersecurity and one year in one or more of the six CCSP domains.

CertificationCertified Cloud Security Professional
Exam formatMultiple choice and advanced item types
Duration180 minutes
Questions100–150 questions
Passing score700 out of 1000 points
DeliveryPearson VUE
LanguagesEnglish, Chinese, Japanese, German
PricingUS $599
Certification levelProfessional
After you pass

Where this credential goes next

The path ISC2 lays out, how the credential is kept, and where to book.

Step-by-step path to Certified Cloud Security Professional

PrerequisiteMinimum of five years cumulative, full-time IT experience, including three years in cybersecurity and one year in one or more of the six CCSP domains.
Certified Cloud Security Professional badgeCredential earnedCertified Cloud Security Professional Professional level certification
Renewal and maintenance

CCSP certification is valid for three years and must be renewed by earning continuing professional education (CPE) credits and paying an annual maintenance fee (AMF). Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. ISC2 maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by ISC2

Exam registration

Register for the exam through Pearson VUE, ISC2’s authorized testing partner.

Schedule your exam

Visit the official ISC2 certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the CCSP relate to the CISSP certification?

An active CISSP credential can be substituted for the entire CCSP experience requirement, making it a common pathway for CISSP holders to earn the CCSP.

Is there a new CCSP exam outline coming?

Yes, a new CCSP exam outline becomes effective August 1, 2026. Candidates should review the latest outline to ensure their study plan aligns with the updated domains and topics.

Can I take the CCSP exam before meeting the experience requirement?

Yes, you can take the exam and become an Associate of ISC2 if you pass but do not yet have the required experience. You will have six years to earn the five years of required experience.

What is the retake policy for the CCSP exam?

ISC2 exam retake policies apply. Candidates who purchase the exam with Peace of Mind Protection receive two exam attempts with a 30-day waiting period between attempts.

Are there any hands-on or lab components in the CCSP exam?

The CCSP exam uses Computerized Adaptive Testing (CAT) and consists of multiple choice and advanced item types. There is no hands-on lab component.

What job roles does the CCSP certification map to?

The CCSP is ideal for cloud architects, cloud engineers, cloud consultants, cloud administrators, cloud security analysts, cloud specialists, auditors of cloud computing services, and professional cloud developers.

Can I recertify by passing a different ISC2 exam?

ISC2 certifications are renewed by earning CPE credits and paying the annual maintenance fee. Passing a higher-level exam may not automatically renew the CCSP; you must meet the renewal requirements.

Is the CCSP exam available in all countries?

The CCSP exam is delivered at Pearson VUE testing centers worldwide. However, Chinese language exams are only available during specific appointment windows each year.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 1030 questions, free, no account needed.