Skip to main content
CertRampLearning

ISC2 · Exam guide

CCSP Exam Guide

The CCSP (Certified Cloud Security Professional) is ISC2's certification for experienced security professionals who design, manage and secure data, applications and infrastructure in the cloud. Since 1 August 2026 the exam follows a new exam outline. It is a computerized adaptive test of 100 to 150 items in up to three hours, covering six domains.

Updated October 1, 2026 · Exam information verified October 1, 2026 against official ISC2 sources

Who the CCSP is for

  • Security architects, engineers and consultants who work with cloud platforms
  • Security managers responsible for cloud governance, risk and compliance
  • Experienced IT and security professionals moving into cloud security roles

CCSP exam facts

Certified Cloud Security Professional (ISC2)

Exam provider
ISC2
Format
Computerized adaptive testing (CAT)
Questions
100 to 150
Duration
3 hours
Exam languages
English, Chinese, Japanese, German
Prerequisites
5 years cumulative full-time IT experience: 3 in cybersecurity and 1 in one or more CCSP domains (waivers and Associate path: see ISC2)
Exam version
Exam outline effective 1 August 2026

The 6 exam domains

Domains and objectives as published in the official ISC2 exam outline. Check the official outline for the current domain weighting.

  1. Domain 1Cloud Concepts, Architecture and Design

    • 1.1 Understand cloud computing concepts
    • 1.2 Describe cloud reference architecture
    • 1.3 Understand security concepts relevant to cloud computing
    • 1.4 Understand design principles of secure cloud computing
    • 1.5 Evaluate Cloud Service Providers
    • 1.6 Comprehend Artificial Intelligence/Machine Learning
  2. Domain 2Cloud Data Security

    • 2.1 Describe cloud data concepts
    • 2.2 Design and implement cloud data storage architectures
    • 2.3 Design and apply data security technologies and strategies
    • 2.4 Implement data discovery
    • 2.5 Plan and implement data classification
    • 2.6 Design and implement Information Rights Management
    • 2.7 Plan and implement data retention, deletion, and archiving policies
    • 2.8 Design and implement auditability, traceability, and accountability of data events
    • 2.9 Comprehend data protection of Artificial Intelligence and Machine Learning data
  3. Domain 3Cloud Platform and Infrastructure Security

    • 3.1 Comprehend cloud infrastructure and platform components
    • 3.2 Design a secure data center
    • 3.3 Analyze risks associated with cloud infrastructure and platforms
    • 3.4 Plan and implementation of security controls
    • 3.5 Plan business continuity and disaster recovery
  4. Domain 4Cloud Application Security

    • 4.1 Advocate training and awareness for application security
    • 4.2 Describe the Secure Software Development Life Cycle process
    • 4.3 Apply the Secure Software Development Life Cycle
    • 4.4 Apply cloud software assurance and validation
    • 4.5 Use verified secure software
    • 4.6 Comprehend and apply the specifics of cloud application architecture
    • 4.7 Design appropriate Identity and Access Management solutions
  5. Domain 5Cloud Security Operations

    • 5.1 Build and implement physical and logical infrastructure for cloud environment
    • 5.2 Operate and maintain physical and logical infrastructure for cloud environment
    • 5.3 Implement operational controls and standards
    • 5.4 Support digital forensics
    • 5.5 Manage communication with relevant parties
    • 5.6 Manage security operations
  6. Domain 6Legal, Risk and Compliance

    • 6.1 Articulate legal requirements and unique risks within the cloud environment
    • 6.2 Understand privacy issues
    • 6.3 Understand audit process, methodologies, and required adaptations for a cloud environment
    • 6.4 Understand implications of cloud to enterprise risk management
    • 6.5 Understand outsourcing and cloud contract design

How the adaptive exam works

ISC2 delivers the CCSP exam as a computerized adaptive test (CAT). According to ISC2, every candidate starts with an item well below the passing standard, and with each answer the computer's estimate of the candidate's ability becomes more precise. The exam therefore does not have a fixed length: you will see between 100 and 150 items within the three-hour limit.

For preparation this has two consequences. First, you cannot plan around a fixed number of questions — practise keeping a steady pace instead. Three hours for up to 150 items leaves a little over a minute per item. Second, items are drawn from all six domains of the outline, so plan to cover every domain rather than relying on your strongest ones.

What the 2026 exam outline emphasises

The outline effective 1 August 2026 keeps the six familiar domains, from cloud concepts to legal, risk and compliance. It includes dedicated objectives on artificial intelligence and machine learning: Objective 1.6 lists cloud threat detection and analysis, data source validation and verification, SOAR, ethical concerns and regulatory requirements; objective 2.9 covers the privacy and security of data sets and models.

ISC2 publishes the full list of objectives and sub-topics in the official exam outline. Use it as your checklist: every objective you cannot explain in your own words is a gap.

A six-step preparation plan

  1. Step 1

    Read the official outline first

    Download the CCSP exam outline from ISC2 and mark every objective as strong, unsure or unknown. This is your baseline before you open a book.

  2. Step 2

    Measure where you stand

    Take a diagnostic practice test before studying. The score matters less than the pattern: which domains cost you the most points?

  3. Step 3

    Study by domain, weakest first

    Work through one domain at a time with the official study material or a reputable study guide. Start where the diagnostic showed the biggest gaps.

  4. Step 4

    Practise after every domain

    Answer domain-specific questions straight after studying and read every explanation — including for the questions you got right.

  5. Step 5

    Simulate the real exam

    Take full-length timed practice exams. Practise holding your concentration for three hours and keeping a steady pace.

  6. Step 6

    Close the last gaps, then book

    Book the exam once you score consistently above your target on exam-level practice tests — not after a single good result.

The CertRamp CCSP practice exams follow the same idea: six tests whose difficulty rises from a diagnostic to beyond exam level. See how the CCSP practice exams work.

Common preparation mistakes

  • Studying one cloud provider's services instead of vendor-neutral concepts. The CCSP tests principles that apply across providers.
  • Neglecting Domain 6. Legal, privacy, audit and contract topics are unfamiliar to many technical candidates and need dedicated time.
  • Memorising definitions without applying them. Practise choosing the best option in a scenario, not just recognising a term.
  • Answering as a hands-on engineer only. Many questions are about risk, governance and responsibility — think about who is accountable.
  • Skipping the explanations. The reasoning behind wrong options is where most of the learning happens.
  • Only practising in short sessions. A three-hour adaptive exam needs stamina that only full-length practice builds.

How to approach scenario questions

  • Identify the role you are asked to take — customer, provider, auditor or manager.
  • Look for qualifiers such as BEST, FIRST, MOST and PRIMARY; several options may be correct, but only one fits the qualifier.
  • Map the scenario to the cloud service model (IaaS, PaaS, SaaS) before deciding who is responsible.
  • Prefer answers that address the root cause or follow due process over quick technical fixes.

Test yourself now

Try 24 free, original CCSP practice questions — every one with the answer and an explanation for each option.

CCSP exam FAQ

How many questions are on the CCSP exam?

Between 100 and 150. The CCSP is a computerized adaptive test, so the number of items depends on how you answer. The time limit is three hours.

Which languages is the CCSP exam available in?

ISC2 lists English, Chinese, Japanese and German.

What changed in the CCSP exam on 1 August 2026?

A new exam outline took effect. It keeps six domains and includes dedicated objectives on artificial intelligence and machine learning (objectives 1.6 and 2.9). Check the official ISC2 outline for the full list of objectives.

What experience do I need for the CCSP?

ISC2 requires at least five years of cumulative, full-time IT work experience. Three of those years must be in cybersecurity and one year in one or more of the six CCSP exam domains. According to ISC2, an active CISSP can replace the entire requirement, and CSA's CCSK or a relevant bachelor's or master's degree can each replace one year. Candidates without enough experience can pass the exam and become an Associate of ISC2. See ISC2's CCSP experience requirements page for details.

Are CertRamp's CCSP questions real exam questions?

No. All CertRamp questions are original practice questions written against ISC2's published exam outline. They are not taken from the real exam, and nobody can legitimately offer real exam questions.