Skip to content

CCSP - Certified Cloud Security Professional

Exam Overview

The Certified Cloud Security Professional (CCSP) is a joint certification from ISC2 and the Cloud Security Alliance (CSA). It validates advanced technical and managerial competence in cloud security architecture, design, operations, and service orchestration. CCSP is widely recognized for cloud security architects, cloud security engineers, and cloud-focused CISOs.

CCSP is accredited under ANSI/ISO/IEC 17024 and is approved for several US Department of Defense (DoD) cloud security workforce roles.

Exam Details: - Exam Code: CCSP - Format: Linear, fixed-form - Duration: 3 hours - Number of Questions: 150 - Question Types: Multiple choice - Passing Score: 700 out of 1000 (scaled) - Cost: $599 USD - Languages: English, Japanese, Chinese (Simplified), Korean, German - Delivery: Pearson VUE testing centers - Validity: 3 years (recertification via 90 CPE credits) - Prerequisites: 5 years cumulative paid IT work experience, including 3 years of information security and 1 year in one or more of the 6 CCSP CBK domains. CISSP holders may substitute it for the entire CCSP experience requirement. CCSK holders may substitute CCSK for the 1 year of CCSP-domain experience.

Six CCSP Domains

Domain 1: Cloud Concepts, Architecture, and Design (17%)

  • Cloud computing concepts: definition (NIST SP 800-145), characteristics, service models, deployment models
  • Cloud reference architecture
  • Security concepts relevant to cloud computing
  • Design principles for secure cloud computing
  • Trusted Cloud Services and certifications (CSA STAR, ISO 27017/27018, FedRAMP, BSI C5)

Domain 2: Cloud Data Security (20%)

  • Cloud data lifecycle (Create, Store, Use, Share, Archive, Destroy)
  • Cloud data storage architectures
  • Data security technologies and strategies
  • Data discovery and classification
  • Information rights management (IRM) / DRM
  • Data retention, deletion, and archiving
  • Data event auditability, traceability, accountability

Domain 3: Cloud Platform and Infrastructure Security (17%)

  • Cloud infrastructure components
  • Risk management for cloud infrastructure
  • Plan and implement security controls
  • Plan disaster recovery and BCP for cloud
  • Hypervisor security, container security
  • Network security in cloud (SDN, microsegmentation, zero trust)
  • Compute, storage, network virtualization

Domain 4: Cloud Application Security (17%)

  • Training and awareness for application security
  • Cloud application architecture
  • Cloud SDLC
  • Secure application architecture (sandboxing, application virtualization)
  • Cryptography in cloud applications
  • Identity and access management for cloud apps
  • API security
  • Verification and validation of cloud applications

Domain 5: Cloud Security Operations (16%)

  • Implement and build physical and logical infrastructure
  • Operate physical and logical infrastructure
  • Manage physical and logical infrastructure
  • Implement operational controls and standards (ITIL, ISO 20000)
  • Support digital forensics
  • Manage communication with stakeholders
  • Manage security operations (SOC, SIEM, log management, vulnerability management)
  • Legal requirements and unique risks within the cloud environment
  • Privacy issues and jurisdictional differences
  • Audit process, methodologies, and required adaptations for a cloud environment
  • Implications of cloud to enterprise risk management
  • Outsourcing and cloud contract design
  • Vendor management

Study Materials

Notes

Study Resources

Audience and Career Profile

CCSP targets practitioners with significant cloud security responsibility. Common roles:

  • Cloud Security Architect
  • Cloud Security Engineer
  • Cloud Security Consultant
  • Cloud Security Manager / CISO with cloud focus
  • Enterprise Architect with cloud security responsibility
  • Security Analyst working primarily in cloud
  • Compliance Officer focused on cloud

Official Resources

  • CCSP Certification Page: https://www.isc2.org/certifications/ccsp
  • CCSP Exam Outline: https://www.isc2.org/certifications/ccsp/ccsp-exam-outline
  • CSA Guidance v5: https://cloudsecurityalliance.org/research/guidance (free)
  • Cloud Controls Matrix (CCM) v4: https://cloudsecurityalliance.org/research/cloud-controls-matrix (free)
  • NIST SP 800-145: Cloud computing definition
  • NIST SP 500-291: Cloud Computing Standards Roadmap
  • NIST SP 800-144: Guidelines on Security and Privacy in Public Cloud
  • NIST SP 800-210: Access Control for Cloud
  • ISO/IEC 17788: Cloud computing overview and vocabulary
  • ISO/IEC 17789: Cloud computing reference architecture
  • ISO/IEC 27017: Code of practice for cloud information security
  • ISO/IEC 27018: Code of practice for protection of PII in public clouds
  • ISO/IEC 27701: Privacy information management system

Books

  1. (ISC)2 CCSP Official Study Guide, 4th Edition (Sybex) - primary text
  2. (ISC)2 CCSP Official Practice Tests, 3rd Edition (Sybex)
  3. CCSP All-in-One Exam Guide (McGraw Hill)
  4. CSA Security Guidance v5 (free PDF) - foundational reading

Video Courses

  1. Pete Zerger CCSP Exam Cram (free on YouTube)
  2. Destination Certification CCSP MasterClass
  3. Mike Chapple CCSP (LinkedIn Learning)
  4. Kelly Handerhan CCSP (Cybrary)

Practice Tests

  1. Boson ExSim CCSP - high-quality practice
  2. Sybex Official Practice Tests
  3. LearnZapp CCSP
  4. Pocket Prep CCSP

Relationship to Other Certifications

Certification Relationship to CCSP
CISSP Senior security generalist; CISSP credit waives full CCSP experience
CCSK Foundational cloud security; CCSK credit waives 1 year CCSP-domain experience
AWS Security Specialty AWS-specific, complements CCSP
Azure AZ-500 / SC-100 Azure-specific, complements CCSP
Google Professional Cloud Security Engineer GCP-specific, complements CCSP
ISACA CCAK Cloud auditing focus

CCSP is vendor-neutral and architectural; provider-specific certs validate hands-on skills with one cloud.

After You Pass

  • Submit endorsement application within 9 months (ISC2 member endorsement or ISC2 endorsement)
  • Pay first Annual Maintenance Fee ($135)
  • Earn 90 CPE credits over 3-year cycle (30 CPE/year minimum)
  • 60 CPEs must be Group A (security-related)
  • Adhere to ISC2 Code of Ethics

Mindset Tip

CCSP, like CISSP, rewards judgment over technical depth. Choose the answer that: 1. Addresses the cloud-specific nuance (shared responsibility, multi-tenancy, ephemeral workloads) 2. Reflects the cloud customer's responsibility correctly under the service model (IaaS/PaaS/SaaS) 3. Considers legal and jurisdictional implications 4. Aligns to vendor-neutral best practice (CSA, NIST, ISO), not single-vendor preference

CCSP is more technical than CISSP, but the same "manager-perspective best answer" approach applies.