ISC2 Certification

CCSP

Certified Cloud Security Professional

ISC2 | 6 domains · 94 lessons and reviews | Free Preview

This track follows the current ISC2 CCSP exam outline, effective August 1, 2026. It covers the updated domain weights and the cloud, AI, data, application, operational, and legal-security topics in that outline. The lessons focus on applying those concepts to realistic decisions instead of memorizing isolated terms.

Exam Details

CCSP exam details
Detail CCSP
Format 100–150 multiple-choice and advanced items (CAT)
Time 3 hours
Standard Exam Fee (USD; verify regional price) $599 USD
Passing Score 700 out of 1000
Experience 5 years in IT, including 3 in cybersecurity and 1 in a CCSP domain. An applicable post-secondary degree or CCSK can satisfy up to 1 year in total; an active CISSP can satisfy the full experience requirement
Renewal 90 CPE credits per 3-year cycle; annual AMF $135
Exam Outline Current outline effective August 1, 2026

Source and Scope Note

Track scope checked August 24, 2026. The reference was the ISC2 CCSP Certification Exam Outline, effective August 1, 2026.

This note records the outline used for the track; it does not mean ISC2 reviewed or endorsed the lessons. The practice material is original and does not reproduce live exam items. Report a content issue.

What You'll Learn

  • Understand how ISC2 frames cloud security across architecture, data, platform, application, operations, and legal domains
  • Think through shared responsibility scenarios — who owns what in SaaS, PaaS, and IaaS
  • Apply cloud data security concepts including encryption, DLP, rights management, and legal holds
  • Navigate AI security, container security, DevSecOps, and emerging cloud technologies as tested on the 2026 exam
Start a Free Lesson →
Domain 1 — Cloud Concepts, Architecture & Design (17%)

Cloud computing concepts, reference architecture, security principles, design patterns, and evaluating cloud service providers.

Section A — Cloud Fundamentals

  1. 1 Cloud Computing Definitions and Roles Free Free Preview
  2. 2 Key Cloud Characteristics Full Access
  3. 3 Building Block Technologies Full Access
  4. 4 Cloud Service Categories (SaaS, IaaS, PaaS) Full Access
  5. Section A Review: Cloud Fundamentals Full Access

Section B — Architecture & Deployment

  1. 5 Cloud Deployment Models Full Access
  2. 6 Shared Considerations and SLAs Full Access
  3. 7 Related Technologies (AI, IoT, Containers, Quantum) Full Access
  4. 8 Cryptography and Key Management in the Cloud Full Access
  5. Section B Review: Architecture & Deployment Full Access

Section C — Security Design

  1. 9 Identity and Access Control Full Access
  2. 10 Network and Virtualization Security Full Access
  3. 11 Cloud Secure Data Lifecycle and Design Principles Full Access
  4. 12 Evaluating Cloud Service Providers Full Access
  5. Section C Review: Security Design Full Access

Domain 1 Review

  1. Capstone Review: CLOUD CONCEPTS, ARCHITECTURE & DESIGN Full Access
Domain 2 — Cloud Data Security (20%)

Data lifecycle, storage architectures, encryption, DLP, classification, rights management, retention, and auditability in cloud environments.

Section A — Data Fundamentals

  1. 13 Cloud Data Concepts and Data Lifecycle Free Free Preview
  2. 14 Data Flows and Data Dispersion Full Access
  3. 15 Cloud Data Storage Architectures Full Access
  4. 16 Threats to Cloud Storage Full Access
  5. Section A Review: Data Fundamentals Full Access

Section B — Data Protection

  1. 17 Encryption and Key Management Full Access
  2. 18 Hashing, Tokenization, and Data Obfuscation Full Access
  3. 19 Data Loss Prevention (DLP) Full Access
  4. 20 Data Discovery and Classification Full Access
  5. 21 Data Labeling and Mapping Full Access
  6. Section B Review: Data Protection Full Access

Section C — Data Governance

  1. 22 Information Rights Management (IRM) Full Access
  2. 23 Data Retention, Deletion, and Archiving Full Access
  3. 24 Legal Hold and Data Preservation Full Access
  4. 25 Auditability, Traceability, and Accountability Full Access
  5. 26 Chain of Custody and Non-Repudiation Full Access
  6. Section C Review: Data Governance Full Access

Domain 2 Review

  1. Capstone Review: CLOUD DATA SECURITY Full Access
Domain 3 — Cloud Platform & Infrastructure Security (17%)

Infrastructure components, secure data center design, risk assessment, security controls, and business continuity in cloud platforms.

Section A — Infrastructure Components

  1. 27 Cloud Infrastructure Components Free Free Preview
  2. 28 Network and Communications Security Full Access
  3. 29 Compute and Virtualization Security Full Access
  4. Section A Review: Infrastructure Components Full Access

Section B — Data Center & Risk

  1. 30 Secure Data Center Design Full Access
  2. 31 Physical and Environmental Security Full Access
  3. 32 Risk Assessment for Cloud Infrastructure Full Access
  4. 33 Vulnerability and Threat Analysis Full Access
  5. Section B Review: Data Center & Risk Full Access

Section C — Controls & Continuity

  1. 34 Security Controls Implementation Full Access
  2. 35 Identification, Authentication, and Authorization Full Access
  3. 36 Business Continuity and Disaster Recovery Full Access
  4. Section C Review: Controls & Continuity Full Access

Domain 3 Review

  1. Capstone Review: CLOUD PLATFORM & INFRASTRUCTURE SECURITY Full Access
Domain 4 — Cloud Application Security (16%)

Application security awareness, secure SDLC, threat modeling, testing, API security, supply chain, and IAM for cloud applications.

Section A — AppSec Fundamentals

  1. 37 Cloud Application Security Awareness Free Free Preview
  2. 38 Common Cloud Vulnerabilities (OWASP, SANS) Full Access
  3. 39 Secure SDLC: Business Requirements and Design Full Access
  4. 40 Secure SDLC: Coding and Testing Full Access
  5. Section A Review: AppSec Fundamentals Full Access

Section B — Assurance & Supply Chain

  1. 41 Cloud-Specific Risks and Threat Modeling Full Access
  2. 42 Secure Coding Practices Full Access
  3. 43 Software Assurance and Validation Full Access
  4. 44 Security Testing Methodologies Full Access
  5. Section B Review: Assurance & Supply Chain Full Access

Section C — Architecture & IAM

  1. 45 API Security Full Access
  2. 46 Supply Chain and Third-Party Software Management Full Access
  3. 47 Cloud Application Architecture and Security Components Full Access
  4. 48 IAM Solutions for Cloud Applications Full Access
  5. Section C Review: Architecture & IAM Full Access

Domain 4 Review

  1. Capstone Review: CLOUD APPLICATION SECURITY Full Access
Domain 5 — Cloud Security Operations (17%)

Physical and logical infrastructure, operational controls (ITIL), digital forensics, SOC management, and security monitoring.

Section A — Infrastructure Operations

  1. 49 Physical and Logical Infrastructure Free Free Preview
  2. 50 Hardware Security (HSM, TPM) Full Access
  3. 51 Access Controls and Secure Connectivity Full Access
  4. 52 Network Security Controls Full Access
  5. Section A Review: Infrastructure Operations Full Access

Section B — Maintenance & Standards

  1. 53 OS Hardening and Patch Management Full Access
  2. 54 Infrastructure as Code (IaC) Full Access
  3. 55 High Availability and Resilience Full Access
  4. 56 Monitoring and Capacity Management Full Access
  5. Section B Review: Maintenance & Standards Full Access

Section C — Operations & Forensics

  1. 57 ITIL and Operational Standards Full Access
  2. 58 Change, Incident, and Problem Management Full Access
  3. 59 Digital Forensics in the Cloud Full Access
  4. 60 Security Operations Center (SOC) and SIEM Full Access
  5. Section C Review: Operations & Forensics Full Access

Domain 5 Review

  1. Capstone Review: CLOUD SECURITY OPERATIONS Full Access
Domain 6 — Legal, Risk & Compliance (13%)

Legal requirements, privacy, audit processes, enterprise risk management, outsourcing, and cloud contract design.

Section A — Legal & Privacy

  1. 61 International Legal Requirements Free Free Preview
  2. 62 eDiscovery and Forensics Requirements Full Access
  3. 63 Privacy Issues and Data Protection Full Access
  4. 64 Privacy Standards (GDPR, ISO 27018) Full Access
  5. Section A Review: Legal & Privacy Full Access

Section B — Audit & Risk

  1. 65 Audit Processes and Methodologies Full Access
  2. 66 Audit Reports and Compliance (SOC, SSAE) Full Access
  3. 67 Enterprise Risk Management in the Cloud Full Access
  4. 68 Risk Treatment and Frameworks Full Access
  5. Section B Review: Audit & Risk Full Access

Section C — Contracts & Vendors

  1. 69 Outsourcing and Cloud Contracts Full Access
  2. 70 Vendor Management and Supply Chain Security Full Access
  3. Section C Review: Contracts & Vendors Full Access

Domain 6 Review

  1. Capstone Review: LEGAL, RISK & COMPLIANCE Full Access

Career Benefits

  • Relevant to cloud security architecture, engineering, governance, and operations roles
  • An ISC2 certification focused specifically on cloud security knowledge and decisions
  • Relevant preparation for cloud security architecture, engineering, and consulting work
  • Complements CISSP — demonstrates specialized cloud security expertise

How It Compares

CCSP focuses specifically on cloud security architecture, operations, and compliance, while CISSP covers a broader information-security body of knowledge. CySA+ V4 (CS0-004) instead develops analyst depth across security operations, vulnerability management, incident response, and reporting; its objectives can apply to cloud evidence without making it a cloud-specialist certification.

Choose CySA+ when SOC analysis and response are the closer fit, CCSP when cloud design and governance recur in your work, or CISSP when broad cross-domain experience best matches your goals. Holding more than one can be useful, but there is no required sequence. See the full comparison →