Exampractice
Cybersecurity

CCSP Certification Guide

What the ISC2 CCSP covers, who qualifies, what it costs and how certification works — the six domains, experience rules and exam process explained.

Alexander Novak · 10 min read
Cloud-shaped shield divided into six labelled segments representing the CCSP exam domains and their weights

The Certified Cloud Security Professional (CCSP) is ISC2's vendor-neutral certification for people who design, manage and secure cloud environments. To earn it you pass a computerised adaptive exam covering six cloud security domains, prove five years of qualifying IT experience (three of them in information security), and complete ISC2's endorsement process. As of 2026 the exam costs $599 USD in the Americas, with regional pricing elsewhere.

This guide covers what the certification is, what the exam tests, who qualifies, what it costs from first booking to ongoing renewal, and the exact sequence of steps between deciding to pursue CCSP and holding the credential. Questions this guide deliberately leaves to companion articles: how difficult the exam actually is, how to structure your study, and whether the certification pays off for your situation.

What is the CCSP certification?

CCSP stands for Certified Cloud Security Professional. It is issued by ISC2, the same membership body behind the CISSP, and it validates hands-on ability to secure cloud data, applications and infrastructure regardless of which cloud provider you use. Unlike an AWS, Azure or Google Cloud security certification, the CCSP is platform-agnostic: it tests cloud security architecture, governance and operations concepts that apply across providers.

That vendor-neutral position is the core of the credential's identity. A Google-specific credential such as the Professional Cloud Security Engineer proves you can secure one platform; the CCSP proves you understand the discipline of cloud security itself — shared responsibility, data lifecycle protection, legal exposure across jurisdictions, and how to operate securely at scale. Many professionals eventually hold both types.

The relationship between the pieces is worth making explicit, because ISC2's terminology trips people up. ISC2 is the provider. CCSP is the certification. The CCSP exam is one requirement for the certification, but passing it alone does not make you certified — experience validation and endorsement come after. Once certified, you become an ISC2 member and maintain the credential through continuing education. The certification is aimed at roles such as cloud security engineer, cloud architect, security consultant and security operations lead.

What are the six CCSP exam domains?

The CCSP exam is built on six domains defined in ISC2's official exam outline. The outline page lists an effective date of August 1, 2026, so if you are reading this close to your exam date, download the current outline from ISC2 before you build any study materials around it.

DomainWeight
1. Cloud Concepts, Architecture and Design17%
2. Cloud Data Security20%
3. Cloud Platform and Infrastructure Security17%
4. Cloud Application Security16%
5. Cloud Security Operations17%
6. Legal, Risk and Compliance13%

A few observations that matter more than the raw percentages:

  • Cloud Data Security is the heavyweight at 20%. Data lifecycle, classification, encryption and key management, data loss prevention and retention policies carry more exam weight than any other single area. If your background is network-centric, this is usually the domain that demands the most new learning.
  • Four of the six domains sit within one point of each other (16–17%). The exam is deliberately balanced — you cannot safely write off architecture, infrastructure, application security or operations as minor topics.
  • Legal, Risk and Compliance is the smallest at 13% but punishes assumptions. Jurisdiction, privacy regimes, audit mechanisms and contract language are areas where technical candidates often rely on intuition rather than study, and intuition is unreliable here.

Who qualifies? CCSP experience requirements

ISC2 requires five years of cumulative, full-time paid work experience in information technology. Within those five years, three must be in information security, and one must be in one or more of the six CCSP domains. The requirement is cumulative rather than consecutive, so career breaks do not reset the clock.

There are three recognised ways to reduce or satisfy the requirement:

  1. CCSK substitution. The Cloud Security Alliance's Certificate of Cloud Security Knowledge (CCSK) can substitute for one year of experience.
  2. Degree waiver. A relevant degree can waive one year. Note that only one waiver applies in total — you cannot stack the CCSK substitution and the degree waiver.
  3. CISSP shortcut. An active CISSP satisfies the entire CCSP experience requirement. If you already hold CISSP, eligibility is simply not an obstacle — the only question is whether the additional credential adds enough to justify the effort, which is a separate decision we examine in do you need CCSP if you have CISSP.

What if you don't have the experience yet?

You can still sit the exam. Pass it without the qualifying experience and you become an Associate of ISC2, which gives you six years to accumulate the five years of experience. This is a legitimate route for someone moving into cloud security from adjacent IT work: the pass is banked, and each qualifying role you hold counts down the requirement. Associates pay a reduced annual fee of $50 USD and must earn 15 continuing professional education (CPE) credits per year while working towards full certification.

If five years in IT feels distant, be honest with yourself about whether CCSP is the right first target at all. Candidates early in a security career are often better served starting on ISC2's lower rungs — the ISC2 certifications explained overview maps where each credential sits on the ladder.

What is the CCSP exam format?

Since October 1, 2025, the CCSP uses Computerized Adaptive Testing (CAT) — the linear, fixed-form version has been retired. Under CAT:

  • You answer 100 to 150 items with a maximum of 3 hours.
  • Questions are multiple choice plus advanced item types.
  • The exam adapts to your performance: answer well and the questions get harder; the algorithm ends the exam once it has enough evidence of your ability, which is why the length varies.
  • You cannot skip questions or return to previous ones. Every answer is final the moment you submit it. If your test-taking habits were built on flagging questions for review, this format change matters more than it sounds.

The exam is delivered at Pearson VUE test centres and is available in English, Chinese, Japanese and German.

What score do you need to pass?

The passing standard is scaled at 700 out of 1000. In practice, CAT results are reported simply as pass/fail — you will not receive a numerical score. Candidates who fail receive domain-level proficiency feedback rather than a mark, which at least tells you where to focus a retake.

If you have read older forum posts describing a 125-question, four-hour CCSP, that information is out of date — it describes the pre-2025 linear exam. Always sanity-check format details against ISC2's current outline page.

How the adaptive format feels to sit, and why capable candidates still walk out unsure whether they passed, is its own subject — we cover it in how hard is the CCSP exam.

How much does CCSP certification cost?

The exam fee is $599 USD in the Americas as of 2026. ISC2 prices exams by administration region — EMEA is priced in euros and the UK in pounds — and taxes vary by location, so confirm your local figure on ISC2's exam pricing page before budgeting.

The exam fee is only the entry ticket. A realistic multi-year budget looks like this:

Cost itemAmount (2026, USD, Americas)
Exam fee$599
Rescheduling (if needed)$50
Cancellation (if needed)$100
Retake (if needed)Full exam price again
Annual maintenance fee (AMF), once certified$135 per year
Study materials and trainingVaries widely — self-study is cheapest

Two budgeting notes deserve emphasis. First, retakes are full price — there is no discounted second attempt, which is a $599 argument for not booking the exam until practice results say you are ready. Second, the $135 AMF recurs every year you hold the certification, so the true cost of CCSP over a three-year cycle is the exam fee plus roughly $405 in maintenance fees plus whatever you spend on preparation. Whether that total is money well spent depends on your role and career stage — a question with its own dedicated analysis in is the CCSP worth it.

How to get CCSP certified: the process step by step

Here is the full sequence from decision to credential.

  1. Confirm your eligibility. Map your work history against the five-year requirement (three in security, one in a CCSP domain). Decide whether a waiver applies or whether you will take the Associate route.
  2. Create an ISC2 account and book the exam. Exams are scheduled through Pearson VUE. Pick a date far enough out to prepare properly — remember the $50 rescheduling fee if you move it.
  3. Prepare against the current exam outline. Download the official outline from ISC2 and study to it, not to a book's table of contents. A structured, domain-by-domain approach is laid out in our companion piece on how to prepare for the CCSP exam — this guide will not duplicate it.
  4. Benchmark before you book travel. Working through CCSP practice questions under timed conditions is the most honest readiness signal available: if you cannot sustain accuracy across a full-length session, the $599 fee can wait.
  5. Sit the exam at Pearson VUE. Arrive with valid ID; results are pass/fail on the day.
  6. Complete endorsement within nine months of passing. Your application must be endorsed by an ISC2-certified professional in good standing who can attest to your experience. If you do not know one, ISC2 itself can act as endorser with employment verification. Be accurate — ISC2 conducts random audits of applications.
  7. Pay your first AMF and accept the ISC2 Code of Ethics. Once endorsement is approved, you are certified and become an ISC2 member.

What happens after certification?

CCSP runs on a three-year certification cycle. To stay certified you must:

  • Earn 90 CPE credits over the three years, of which at least 60 must be Group A (activities directly related to the credential's domains).
  • Pay the $135 annual maintenance fee.

There is a 90-day grace period after the cycle ends to submit CPEs and pay the AMF, but treating that as a buffer rather than a plan is wiser. Thirty CPEs a year is very achievable through conference attendance, webinars, professional writing and coursework — the people who lose credentials to CPE shortfalls are almost always the ones who ignored the ledger for two years.

How does CCSP fit alongside other certifications?

CCSP sits in the advanced tier of ISC2's portfolio — above the entry-level Certified in Cybersecurity (CC) and the operationally focused Systems Security Certified Practitioner (SSCP), and alongside the CISSP in seniority, with a narrower, deeper focus on cloud. The full ISC2 ladder, including the CISSP concentrations, is mapped in ISC2 certifications explained.

Against the wider market: platform certifications (AWS, Azure, GCP security specialities) demonstrate depth on one provider, while CCSP demonstrates the transferable discipline — the strongest cloud security CVs usually pair one of each. For readers weighing CCSP against a foundational credential instead, the trade-offs are covered in CCSP vs Security+. Career trajectories the credential supports are mapped in the CCSP career path article, and current compensation evidence lives in the CCSP salary guide.

Frequently asked questions

Can I take the CCSP exam without any cloud experience?

Yes — anyone can sit the exam. Without the qualifying experience you become an Associate of ISC2 on passing, with six years to accumulate the five years of experience (three in security, one in a CCSP domain) before the full credential is issued.

Does CISSP really waive all CCSP experience requirements?

Yes. An active CISSP satisfies the entire CCSP experience requirement — no further documentation of years is needed. You still sit the same exam and complete endorsement.

How long is the CCSP certification valid?

Three years per cycle. You maintain it continuously with 90 CPE credits per cycle (at least 60 Group A) and a $135 annual maintenance fee, rather than re-sitting the exam.

What languages is the CCSP exam offered in?

English, Chinese, Japanese and German, delivered at Pearson VUE test centres.

Is there a waiting period if I fail?

ISC2 does have a retake policy with waiting periods between attempts, but the specifics change — check ISC2's current retake policy page before planning a second attempt. What is certain: a retake costs the full $599 fee.

Is CCSP the right target for you?

If you have (or are close to) five years of IT experience with a security core, work with cloud platforms in any serious capacity, and want a credential that outlives any single provider's ecosystem, CCSP is one of the most defensible choices in the field. The eligibility rules are strict but navigable — CCSK, a degree or an existing CISSP each shortens the road, and the Associate route means the exam itself is never gated.

Your next steps depend on where you are. If you are still weighing the commitment, read the difficulty assessment and the worth-it analysis linked above before spending anything. If you have decided, download the official exam outline, then start measuring yourself against it — the free CCSP sample questions are a zero-cost way to see the question style before you commit to a study programme.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like