CCSP
Certified Cloud Security Professional
This track is built for the August 2026 CCSP exam outline. Learn how ISC2 frames cloud security — shared responsibility, data protection, and operational controls — so you can think through scenarios the way the exam expects.
Exam Details
| Detail | CCSP |
|---|---|
| Format | 100–150 multiple-choice and advanced items (CAT) |
| Time | 3 hours |
| Cost | $599 USD |
| Passing Score | 700 out of 1000 |
| Experience | 5 years in IT, 3 in information security, 1 in cloud security (or CCSK waives 1 year) |
| Renewal | 40 CPE credits/year, annual fee $125 |
| Exam Outline | August 2026 ISC2 CCSP outline (includes AI security) |
What You'll Learn
- Understand how ISC2 frames cloud security across architecture, data, platform, application, operations, and legal domains
- Think through shared responsibility scenarios — who owns what in SaaS, PaaS, and IaaS
- Apply cloud data security concepts including encryption, DLP, rights management, and legal holds
- Navigate AI security, container security, DevSecOps, and emerging cloud technologies as tested on the 2026 exam
Domain 1 — Cloud Concepts, Architecture & Design (17%)
Cloud computing concepts, reference architecture, security principles, design patterns, and evaluating cloud service providers.
Section A — Cloud Fundamentals
- 1 Cloud Computing Definitions and Roles Free
- 2 Key Cloud Characteristics
- 3 Building Block Technologies
- 4 Cloud Service Categories (SaaS, IaaS, PaaS)
- ✓ Section A Review: Cloud Fundamentals
Section B — Architecture & Deployment
- 5 Cloud Deployment Models
- 6 Shared Considerations and SLAs
- 7 Related Technologies (AI, IoT, Containers, Quantum)
- 8 Cryptography and Key Management in the Cloud
- ✓ Section B Review: Architecture & Deployment
Section C — Security Design
- 9 Identity and Access Control
- 10 Network and Virtualization Security
- 11 Cloud Secure Data Lifecycle and Design Principles
- 12 Evaluating Cloud Service Providers
- ✓ Section C Review: Security Design
Domain 1 Review
- ★ Capstone Review: CLOUD CONCEPTS, ARCHITECTURE & DESIGN
Domain 2 — Cloud Data Security (20%)
Data lifecycle, storage architectures, encryption, DLP, classification, rights management, retention, and auditability in cloud environments.
Section A — Data Fundamentals
- 13 Cloud Data Concepts and Data Lifecycle Free
- 14 Data Flows and Data Dispersion
- 15 Cloud Data Storage Architectures
- 16 Threats to Cloud Storage
- ✓ Section A Review: Data Fundamentals
Section B — Data Protection
- 17 Encryption and Key Management
- 18 Hashing, Tokenization, and Data Obfuscation
- 19 Data Loss Prevention (DLP)
- 20 Data Discovery and Classification
- 21 Data Labeling and Mapping
- ✓ Section B Review: Data Protection
Section C — Data Governance
- 22 Information Rights Management (IRM)
- 23 Data Retention, Deletion, and Archiving
- 24 Legal Hold and Data Preservation
- 25 Auditability, Traceability, and Accountability
- 26 Chain of Custody and Non-Repudiation
- ✓ Section C Review: Data Governance
Domain 2 Review
- ★ Capstone Review: CLOUD DATA SECURITY
Domain 3 — Cloud Platform & Infrastructure Security (17%)
Infrastructure components, secure data center design, risk assessment, security controls, and business continuity in cloud platforms.
Section A — Infrastructure Components
- 27 Cloud Infrastructure Components Free
- 28 Network and Communications Security
- 29 Compute and Virtualization Security
- ✓ Section A Review: Infrastructure Components
Section B — Data Center & Risk
- 30 Secure Data Center Design
- 31 Physical and Environmental Security
- 32 Risk Assessment for Cloud Infrastructure
- 33 Vulnerability and Threat Analysis
- ✓ Section B Review: Data Center & Risk
Section C — Controls & Continuity
- 34 Security Controls Implementation
- 35 Identification, Authentication, and Authorization
- 36 Business Continuity and Disaster Recovery
- ✓ Section C Review: Controls & Continuity
Domain 3 Review
- ★ Capstone Review: CLOUD PLATFORM & INFRASTRUCTURE SECURITY
Domain 4 — Cloud Application Security (17%)
Application security awareness, secure SDLC, threat modeling, testing, API security, supply chain, and IAM for cloud applications.
Section A — AppSec Fundamentals
- 37 Cloud Application Security Awareness Free
- 38 Common Cloud Vulnerabilities (OWASP, SANS)
- 39 Secure SDLC: Business Requirements and Design
- 40 Secure SDLC: Coding and Testing
- ✓ Section A Review: AppSec Fundamentals
Section B — Assurance & Supply Chain
- 41 Cloud-Specific Risks and Threat Modeling
- 42 Secure Coding Practices
- 43 Software Assurance and Validation
- 44 Security Testing Methodologies
- ✓ Section B Review: Assurance & Supply Chain
Section C — Architecture & IAM
- 45 API Security
- 46 Supply Chain and Third-Party Software Management
- 47 Cloud Application Architecture and Security Components
- 48 IAM Solutions for Cloud Applications
- ✓ Section C Review: Architecture & IAM
Domain 4 Review
- ★ Capstone Review: CLOUD APPLICATION SECURITY
Domain 5 — Cloud Security Operations (16%)
Physical and logical infrastructure, operational controls (ITIL), digital forensics, SOC management, and security monitoring.
Section A — Infrastructure Operations
- 49 Physical and Logical Infrastructure Free
- 50 Hardware Security (HSM, TPM)
- 51 Access Controls and Secure Connectivity
- 52 Network Security Controls
- ✓ Section A Review: Infrastructure Operations
Section B — Maintenance & Standards
- 53 OS Hardening and Patch Management
- 54 Infrastructure as Code (IaC)
- 55 High Availability and Resilience
- 56 Monitoring and Capacity Management
- ✓ Section B Review: Maintenance & Standards
Section C — Operations & Forensics
- 57 ITIL and Operational Standards
- 58 Change, Incident, and Problem Management
- 59 Digital Forensics in the Cloud
- 60 Security Operations Center (SOC) and SIEM
- ✓ Section C Review: Operations & Forensics
Domain 5 Review
- ★ Capstone Review: CLOUD SECURITY OPERATIONS
Domain 6 — Legal, Risk & Compliance (13%)
Legal requirements, privacy, audit processes, enterprise risk management, outsourcing, and cloud contract design.
Section A — Legal & Privacy
- 61 International Legal Requirements Free
- 62 eDiscovery and Forensics Requirements
- 63 Privacy Issues and Data Protection
- 64 Privacy Standards (GDPR, ISO 27018)
- ✓ Section A Review: Legal & Privacy
Section B — Audit & Risk
- 65 Audit Processes and Methodologies
- 66 Audit Reports and Compliance (SOC, SSAE)
- 67 Enterprise Risk Management in the Cloud
- 68 Risk Treatment and Frameworks
- ✓ Section B Review: Audit & Risk
Section C — Contracts & Vendors
- 69 Outsourcing and Cloud Contracts
- 70 Vendor Management and Supply Chain Security
- ✓ Section C Review: Contracts & Vendors
Domain 6 Review
- ★ Capstone Review: LEGAL, RISK & COMPLIANCE
Career Benefits
- Average salary: $130,000–$170,000 (varies by region and experience)
- The leading cloud security certification, recognized by ISC2 alongside CISSP
- Required or preferred for Cloud Security Architect, Cloud Engineer, and Security Consultant roles
- Complements CISSP — demonstrates specialized cloud security expertise
How It Compares
CCSP focuses specifically on cloud security architecture, operations, and compliance, while CISSP covers the full breadth of information security. If you work with cloud infrastructure, SaaS platforms, or cloud migration, CCSP is your best fit. If you need the broadest senior-level credential, start with CISSP. Many professionals hold both. See the full comparison →