Exam Details
ISC2 · CCSP
Prepare for CCSP: Design, manage, and secure data, applications, and infrastructure in cloud environments.
Overview
Related Roadmaps
Approved links shared by the community. Earn credits when yours gets approved!
No community resources yet. Be the first to suggest one!
Know a strong article, guide, or explainer for this exam? Submit it for review and earn credits when it gets approved.
ExamOS may provide links to third-party websites, books, videos, courses, and other materials ("External Resources") for your convenience and reference. These resources are not created, owned, or controlled by ExamOS unless explicitly stated.
For official and up-to-date information, always refer to the certification provider website.
No resources have been linked to this exam yet.
Video Library
No video resources are available for this exam yet.
Found a strong walkthrough, lesson, or exam breakdown on YouTube? Submit it here and earn credits if it gets approved.
FAQ
The CCSP certification validates your ability to design, manage, and secure data, applications, and infrastructure in the cloud using best practices, policies, and procedures. This professional-level certification targets cloud security architects, engineers, and consultants who implement security across cloud architecture, data, platform infrastructure, applications, and operations. You'll demonstrate expertise in cloud-specific security challenges including shared responsibility, data sovereignty, cloud-native security controls, and legal compliance. As organizations move critical workloads to the cloud, certified professionals who secure cloud environments across all layers are essential.
You're a fit for CCSP if you:
Not sure if you're ready? Try a free sample quiz: 10 questions, instant results, identify weak areas.
| Domain | Weight | What This Means |
|---|---|---|
| Cloud Concepts, Architecture and Design | 17% | Understand cloud computing concepts, reference architectures, and design secure cloud solutions |
| Cloud Data Security | 20% | Implement data classification, encryption, tokenization, DLP, and data lifecycle management in the cloud |
| Cloud Platform and Infrastructure Security | 17% | Secure cloud compute, network, and storage infrastructure using cloud-native and third-party controls |
| Cloud Application Security | 17% | Apply secure SDLC for cloud apps, implement API security, and manage application-level controls |
| Cloud Security Operations | 16% | Manage incident response, monitoring, logging, and business continuity for cloud environments |
| Legal, Risk and Compliance | 13% | Navigate cloud contracts, audit requirements, data sovereignty, and regulatory compliance frameworks |
You're probably ready if you can:
You might need more prep if:
If this feels too advanced:
If you know the basics but want to build confidence:
As of the August 2024 update, the CCSP exam now consists of 150 multiple-choice questions (increased from 125). You are given 4 hours to complete the examination. Out of these 150 items, 100 are operational (scored) and 50 are pre-test items (unscored) used for statistical purposes.
The passing score is 700 out of 1000 points. ISC2 uses a scaled scoring model, which means that the number of correct answers required to pass can vary slightly depending on the difficulty of the specific version of the exam you receive. ExamOS offers scenario-based practice quizzes that build real exam confidence and help you gauge your readiness against this high benchmark.
The exam is divided into six domains. Following the 2024 refresh, the weightings are:
Preparation should be multifaceted. Recommended resources include:
The standard exam fee is $599 USD. This fee covers a single attempt. Note that prices may vary based on your local currency and regional taxes. Retake attempts require the payment of the full registration fee again.
If you do not pass on your first attempt, you must wait 30 days before retaking the exam. If you fail a second time, the waiting period increases to 60 days. For a third failure and any subsequent attempts, you must wait 90 days. You are limited to a maximum of four attempts within a single 12-month period.
The CCSP certification is valid for three years. To maintain your status, you must:
Candidates must have at least five years of cumulative, paid work experience in information technology, with three of those years in information security and one year in one or more of the six CCSP domains.
The CCSP is the industry's premier cloud security credential. It qualifies you for senior roles such as Cloud Security Architect, Chief Information Security Officer (CISO), and Compliance Lead. In a market where organizations are moving to hybrid and multi-cloud environments, the CCSP proves you can manage security holistically across providers like AWS, Azure, and GCP.
Once you have mastered cloud security architecture, you might consider: