1.1 Current CCSP Exam Facts
Key Takeaways
- CCSP is an ISC2 credential focused on cloud security design, implementation, architecture, operations, controls, and regulatory compliance.
- The August 1, 2026 exam outline weights are Domain 1 17%, Domain 2 20%, Domain 3 17%, Domain 4 16%, Domain 5 17%, and Domain 6 13%.
- Domain 2 (Cloud Data Security) is the heaviest domain at 20% and should receive the largest share of study time.
- CCSP is ANAB-accredited to ISO/IEC 17024, which signals independent quality standards for certification programs.
- Compared with CISSP, CCSP is a cloud specialty credential rather than a broad enterprise security leadership cert.
Why CCSP Matters
The Certified Cloud Security Professional (CCSP) is an ISC2 credential built for practitioners who apply information security expertise inside cloud environments. ISC2 developed CCSP so that cloud security professionals demonstrate knowledge, skills, and abilities in cloud security design, implementation, architecture, operations, controls, and compliance with regulatory frameworks. A successful candidate shows competence in cloud security architecture, design, operations, and service orchestration — not only vocabulary about public cloud brands.
That framing matters for exam strategy. CCSP is not a pure vendor product quiz. Questions push you to reason about shared responsibility, data lifecycle controls, platform and infrastructure hardening, secure application delivery, security operations, and legal/risk/compliance trade-offs that appear when workloads, identity, and data leave traditional data-center boundaries.
What CCSP Is — and Is Not
CCSP sits in the ISC2 portfolio as a specialty cloud security certification. It assumes you already understand security fundamentals and then tests whether you can apply them when computing is multi-tenant, API-driven, elastically scaled, and contractually shared with a Cloud Service Provider (CSP).
| Aspect | CCSP focus |
|---|---|
| Owner | ISC2 (historically developed with CSA influence; exam outline is ISC2-owned) |
| Scope | Cloud security design, architecture, ops, controls, compliance |
| Depth | Specialty depth across six cloud domains |
| Style | Managerial/architectural judgment plus technical controls |
| Delivery | Pearson VUE CAT exam (see Section 1.2) |
CCSP is not a substitute for hands-on cloud engineering certifications that drill a single hyperscaler’s console. It is also not a broad generalist security leadership credential in the CISSP sense. Use that distinction when you read scenario stems: prefer answers that protect cloud data and shared-responsibility boundaries over answers that only restate general enterprise security slogans.
Six Domains on the August 1, 2026 Outline
Successful candidates must be competent across all six domains. Domain names and average weights for the CAT examination under the outline effective August 1, 2026 are:
| Domain | Title | Average weight |
|---|---|---|
| 1 | Cloud Concepts, Architecture and Design | 17% |
| 2 | Cloud Data Security | 20% |
| 3 | Cloud Platform and Infrastructure Security | 17% |
| 4 | Cloud Application Security | 16% |
| 5 | Cloud Security Operations | 17% |
| 6 | Legal, Risk and Compliance | 13% |
Total weight is 100%. Domain 2 is the single heaviest domain. Domains 1, 3, and 5 share a three-way tie at 17%. Domain 4 is close behind at 16%. Domain 6 is smallest at 13% but still material — legal, privacy, audit, risk, and contract design questions regularly decide borderline candidates because they reward precise role language (controller vs processor, right to audit, SLA vs MSA).
Outline Transition Note (Study This Carefully)
ISC2 refreshes the CCSP outline through a Job Task Analysis (JTA) process so the exam tracks current cloud security practice. For this guide:
- The October 1, 2025 outline applied through July 31, 2026.
- The August 1, 2026 outline is the current outline used throughout this study guide.
If you use third-party materials written for an older outline, reconcile every topic against the Aug 1, 2026 domain map. Notable content evolution on the 2026 outline includes explicit AI/ML security and AI/ML data protection topics inside Domains 1 and 2. Do not assume older practice banks already cover those subtopics at the same depth.
Accreditation and Professional Positioning
CCSP is in compliance with the requirements of the ANSI National Accreditation Board (ANAB) under ISO/IEC 17024. For candidates and employers, that accreditation is a quality signal: the certification program is held to internationally recognized standards for how personnel certifications are designed, assessed, and maintained. On exam day you will not be tested on ISO 17024 clauses, but the fact supports why CCSP is treated as a serious professional credential rather than a marketing badge.
Career Positioning Versus CISSP
| Credential | Best mental model |
|---|---|
| CISSP | Broad information security across enterprise domains; often associated with security leadership and program-wide judgment |
| CCSP | Specialty cloud security across architecture, data, platform, appsec, operations, and cloud legal/risk |
Many professionals hold both. An active CISSP can substitute the entire CCSP experience requirement (see Section 1.3), which is one reason the two credentials often travel together. Still, the exam content is different: CISSP expects breadth across general security domains; CCSP expects cloud-specific control ownership, data protection patterns, multi-tenant infrastructure risks, cloud-aware SDLC, cloud ops, and cloud contract/compliance nuances.
How to Use Domain Weights When Studying
Weights are average examination weights, not a promise that every candidate sees exactly the same mix. CAT adapts item difficulty and selection, so your personal item mix can vary. Even so, study time should still be proportional to domain weight:
- Prioritize Domain 2 (20%) — data lifecycle, storage architectures, encryption/key management, DLP, discovery/classification, IRM, retention/legal hold, auditability, and AI/ML data protection.
- Give strong equal blocks to Domains 1, 3, and 5 (17% each) — concepts/architecture/design, platform/infrastructure, and security operations.
- Cover Domain 4 (16%) thoroughly — secure SDLC, assurance testing, verified software, application architecture patterns, and IAM.
- Do not neglect Domain 6 (13%) — conflicting laws, privacy, audit adaptations for cloud, enterprise risk roles, and outsourcing/contract design.
Exam Traps in “About the Credential” Questions
- Trap: Treating CCSP as vendor-specific. Prefer vendor-neutral control and architecture answers unless the stem names a standard or framework.
- Trap: Memorizing only domain titles while ignoring weights. Domain 2 deserves more practice volume than Domain 6, even though both are mandatory.
- Trap: Using outdated outline weights from blog posts. Always reconcile to the August 1, 2026 weights in the table above.
- Trap: Confusing CCSP with CCSK. CCSK (Cloud Security Alliance) can waive one year of experience toward CCSP eligibility; it is not the same credential as CCSP.
Takeaway for the Rest of This Guide
This introduction chapter locks logistics and eligibility. Every later chapter maps to official outline subtopics under the six domains. Read each technical section with the domain weight in mind: when two equally plausible controls compete in a scenario, favor the control that best protects cloud data, respects shared responsibility, and remains operationally enforceable under CSP constraints.
According to the August 1, 2026 CCSP exam outline, which domain has the highest average weight?
Which statement best describes the professional scope of the CCSP credential?
For candidates using this study guide, which outline transition statement is correct?
What does ANAB ISO/IEC 17024 accreditation primarily signal about CCSP?