CCSP · ● Active · Expert · ISC2
ISC2's flagship cloud security certification — the industry-standard credential for security architects and senior engineers specializing in public cloud (AWS, Azure, GCP, OCI). Requires 5 years cumulative IT experience (3 years information security + 1 year in cloud security, networking, or related domains). CISSP or CSA holders waive the experience requirement.
Exam facts
| Field | Value |
|---|---|
| Cost | $599 USD |
| Duration | 4 hours |
| Questions | 150 (all scored) |
| Passing | 700/1000 scaled |
| Format | Multiple choice |
| Delivery | Pearson VUE |
| Languages | English (primary); regional availability varies |
| Valid | 3 years |
| Renewal | 90 CPE credits over 3 years + annual maintenance fee |
| Prerequisites | 5 years cumulative IT experience (3 years information security + 1 year CCSP CBK domain); CISSP/CSA holders waive requirement |
| Released | 2015 (current CBK v2022 revision) |
| Retiring | N/A |
Vendor source — ISC2 CCSP Certification ↗
Official exam guide — CCSP Exam Blueprint ↗
Exam objectives — CCSP Common Body of Knowledge (CBK) ↗
About
The CCSP (Certified Cloud Security Professional) is ISC2's premier cloud security credential, launched in 2015 to address the explosion of cloud adoption across enterprises. Unlike general cloud certifications from hyperscalers (AWS, Azure), CCSP is vendor-neutral and focuses on security governance, architecture, and risk management across multi-cloud environments. The current CBK (2022 edition) reflects modern threats: container orchestration, serverless security, API-first architecture, zero-trust models, and rapid infrastructure-as-code deployments. CCSP is increasingly required for cloud security architects, senior engineers, and compliance leads at financial services, healthcare, and regulated industries. The credential stacks well with CISSP (many professionals hold both) and is recognized by government agencies and Fortune 500 companies as a benchmark for cloud security expertise.
Domain context — Cloud Security
Cloud security spans identity and access management, data protection, application security, and infrastructure hardening across AWS, Azure, GCP, and hybrid environments. CCSP sits at the expert level — validating deep technical knowledge and strategic risk thinking on public and private cloud platforms.
Read full deep dive — ISC2 Ecosystem ↗
Topics covered
CCSP's six Common Body of Knowledge (CBK) domains, weighted by exam emphasis (2022 update):
- Cloud Concepts, Architecture, and Design (17%) — Cloud service models (IaaS, PaaS, SaaS), deployment models (public, private, hybrid), cloud computing characteristics (elasticity, multi-tenancy, resilience), infrastructure-as-code, scalability, and architectural risk management.
- Cloud Data Security (20%) — Data classification and handling, encryption at rest and in transit, data loss prevention (DLP), tokenization, key management, secure data lifecycle, privacy-preserving techniques, compliance with data residency requirements.
- Cloud Platform & Infrastructure Security (17%) — Host hardening, hypervisor security, container security (Docker, Kubernetes), network segmentation, firewall rules, virtual private clouds (VPC), logging and monitoring, infrastructure-as-code security, API security.
- Cloud Application Security (17%) — Secure SDLC in cloud contexts, application containerization, serverless security, API gateway design, secure coding for cloud (OWASP Top 10 + cloud variants), secrets management, DevSecOps integration.
- Cloud Security Operations (16%) — Incident detection and response, threat monitoring, SIEM in cloud environments, forensics and logging, security automation, orchestration, automated remediation, managed detection and response (MDR) in cloud.
- Legal, Risk, and Compliance (13%) — Cloud compliance frameworks (SOC 2, ISO 27001, HIPAA, FedRAMP, GDPR, CCPA), risk assessment and management, vendor management, contracts and SLAs, liability and incident disclosure, privacy regulations specific to cloud.
Source: ISC2 CCSP CBK Overview ↗
Common skills at Cloud Security · Expert
Shared competencies across the cloud security domain at expert level — not specific to CCSP, but foundational for the role.
- Multi-cloud architecture security — Design and evaluate security postures across AWS, Azure, GCP, and hybrid environments; assess trade-offs between cloud vendor ecosystems.
- Cloud-native threat modeling — Identify attack surfaces unique to cloud (API abuse, metadata services, overpermissioned IAM roles, supply chain attacks in container registries).
- Automated security controls and policy-as-code — Enforce security guardrails via infrastructure-as-code (Terraform, CloudFormation); detect and remediate drift in real-time.
- Regulatory compliance at scale — Map frameworks (FedRAMP, HIPAA, PCI-DSS in cloud contexts) to cloud-native controls; audit and evidence collection across distributed cloud infrastructure.
- Cloud cost vs. security trade-offs — Advise on cost implications of security decisions (redundancy, encryption overhead, compliance tooling); optimize spending without compromising posture.
- Vendor risk and SLA negotiation — Evaluate cloud provider security offerings; negotiate SLAs for incident response, backup/recovery, and audit rights.
Recommended courses at Cloud Security · Expert
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISC2 Official | CCSP Training Bootcamp (5 days) | $1,795 | ↗ |
| Destination Certification | CCSP MasterClass (Rob Witcher) | $695–$995 | ↗ |
| Cybrary | CCSP (Official ISC2 Content) | Free / $99/month premium | ↗ |
| Kelly Handerhan (Cybrary) | CCSP Deep Dive (Domain-by-domain) | Free / Premium | ↗ |
| Udemy (Adrian Cantrill) | CCSP Certification & Cloud Security | $12–$99 | ↗ |
| INE (Information Security) | CCSP Bootcamp (OnDemand) | $199–$399 | ↗ |
Course-selection rule: Destination Cert's Rob Witcher MasterClass and Cybrary's free curriculum (especially Kelly Handerhan) are gold standards. ISC2's official bootcamp is pricey but direct. Adrian Cantrill's Udemy course is popular for hands-on cloud security labs.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| Boson | ExSim-Max CCSP (200+ questions, adaptive) | $99–$149 | ↗ |
| Destination Certification | CCSP Practice Exams (250+ questions) | $69–$99 | ↗ |
| Whizlabs | CCSP Practice Tests (1500+ questions) | $99 | ↗ |
| ISC2 Official | Official CCSP Practice Exams | $50–$100 | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| CCSP Study Guide (2nd Edition) | Mike Chapple, James Stewart | Sybex | 2022 | 978-1119896777 | ↗ |
| CCSP All-in-One Exam Guide (1st Edition) | Diana Kelley, Gabriel Kramer | McGraw-Hill | 2021 | 978-1260462746 | ↗ |
| The Official (ISC)² CCSP CBK Reference | (ISC)² Staff | (ISC)² Press | 2020 | 978-1492089322 | ↗ |
Book rule: Sybex Study Guide (2nd Edition, 2022) and McGraw-Hill (1st Edition, 2021) are current and aligned with the 2022 CBK update. The official (ISC)² CBK Reference is dense and authoritative but best paired with a study guide.
Typical job titles at Cloud Security · Expert
Cloud Security Architect · Senior Cloud Security Engineer · Cloud Compliance Manager · Cloud Incident Response Manager · DevSecOps Lead · Cloud Risk & Governance Manager · Cloud Infrastructure Security Manager · Cloud Security Operations Manager
(Job titles drawn from current job-board postings (LinkedIn, Indeed, Glassdoor) that list CCSP as required or strongly preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $130,000–$210,000+ | Glassdoor Cloud Security Roles ↗ · Robert Half 2024 IT Salary Guide ↗ · Levels.fyi Cloud Security ↗ |
| ZAR | R2,400,000–R4,000,000 (annualized) | Pnet Cloud & Infrastructure Roles ↗ · PayScale South Africa ↗ |
| GBP | £95,000–£170,000 | IT Jobs Watch Cloud Security ↗ · Hays IT Salary Report ↗ |
| EUR | €105,000–€195,000 (DE/FR/NL) | Robert Half Europe ↗ · Salary.com Europe ↗ |
| AUD | A$160,000–A$280,000 | SEEK Australia ↗ · PageUp IT Salary Report ↗ |
Salary note: CCSP holders command premiums in cloud-heavy industries (fintech, SaaS, healthcare cloud migration). The credential is increasingly required for architect and senior engineer roles at organizations with >50% infrastructure in public cloud. Regional data reflects 2024–2025 surveys; ZAR adjusted for PPP and South African cloud adoption rates.
Skills validated
Concrete cloud platforms, security technologies, and practices tested by the CCSP exam — distinct from general domain competencies.
- Cloud identity and access management (IAM) — Role-based access control (RBAC) in AWS/Azure/GCP, cross-account assume roles, service principals, federated identity (SAML, OAuth 2.0).
- Encryption and key management — Key management services (AWS KMS, Azure Key Vault, GCP Cloud KMS), client-side encryption, envelope encryption, TDE (Transparent Data Encryption).
- Container and Kubernetes security — Pod security policies, network policies, secrets management in containers, image scanning, runtime monitoring, admission controllers.
- Cloud network security — Virtual Private Cloud (VPC) design, security groups, network ACLs, VPN and Direct Connect, DDoS protection, WAF configuration.
- Infrastructure-as-code (IaC) security — Terraform, CloudFormation, cloud-native templating; scanning for misconfigurations, supply chain security in IaC pipelines.
- Serverless security — AWS Lambda, Azure Functions, Google Cloud Functions; least-privilege execution, cold-start abuse, API Gateway authentication/authorization.
- Incident detection and response in cloud — CloudTrail (AWS), Azure Activity Log (Azure), Cloud Logging (GCP); SIEM integration, forensics collection, log retention and immutability.
- Data protection and DLP — Sensitive data discovery in cloud storage (S3, Azure Blob, GCS), encryption at rest/in transit, DLP rules, tokenization, PII handling.
- Cloud compliance automation — Continuous compliance monitoring (Config, Azure Policy, Cloud Asset Inventory), automated remediation, audit trail collection for compliance frameworks (SOC 2, HIPAA, FedRAMP).
- Vendor management and SLA negotiation — Risk assessment of cloud providers, incident response SLAs, audit rights, disaster recovery commitments.
Prerequisites and qualification path
Standard path (5-year experience required):
- 5 years cumulative paid professional work experience in Information Technology.
- Minimum 3 years in information security roles (any domain).
- Minimum 1 year in one of the six CCSP CBK domains (cloud concepts, data security, platform/infrastructure security, application security, operations, or legal/compliance).
- Experience can span multiple employers and roles; government and military service counts if full-time equivalent.
Faster path (CISSP or CSA holders):
- Active CISSP credential waives all experience requirements.
- Active Cloud Security Alliance (CSA) CCSK (formerly "CCSK" — Cloud Security Knowledge) holder waives experience requirement.
- If you hold neither, you must meet the standard 5-year requirement.
Associate of ISC2 status:
- Pass the exam without meeting experience requirements.
- Hold "Associate of ISC2" badge until you accumulate the required experience.
- Once experience requirement is met, apply for associate-to-full-credential upgrade (no re-exam required).
Endorsement process
Unlike CISSP, CCSP does not require endorsement after passing the exam. However:
- If you pass without meeting the experience requirement, you hold "Associate of ISC2" status.
- Once you meet the 5-year requirement (or 3+1 breakdown), you upgrade to full CCSP via a simple application and verification of work history.
- No third-party endorser signature required — ISC2 verifies employment dates against your application.
Related certifications
- Stacks with: CISSP (ISC2) ↗ — many professionals hold both; CCSP deepens cloud expertise.
- Stacks with: CAP (ISC2) ↗ — certifications and accreditation, often paired in government cloud roles.
- Prerequisite for: CCSP-ISSAP (ISC2) ↗ — specialized cloud architecture track (if available, requires active CCSP).
- Complements: AWS Certified Security Specialty ↗ — vendor-specific AWS depth, often paired with CCSP.
- Complements: Azure Security Engineer Associate ↗ — vendor-specific Azure depth.
- Equivalents at this level: No direct equivalent; CCSP is the vendor-neutral gold standard for cloud security expertise.
- Vendor overview: ISC2 Overview ↗
Renewal and maintenance
After certification:
- Valid for 3 years from the date ISC2 grants your CCSP status.
- 90 CPE credits required over the 3-year cycle (average 30 CPEs/year).
- Annual maintenance fee due each year to maintain active status (amount varies; check ISC2 website).
- CPE sources: Training courses, conference attendance (Cloud Security Alliance summits, AWS re:Invent, Microsoft Ignite), published articles in security journals, volunteer work in cloud security organizations, advanced degrees with cloud security focus, or ISC2-approved webinars.
- Renewal process: At year 3, submit CPE transcript and maintenance fee; ISC2 grants a new 3-year certificate.
Without renewal, your credential lapses and you lose the title; though many employers honor lapsed CCSP for a period if you maintain industry currency.
Career impact and trajectory
Pre-CCSP: Cloud security roles typically max out at senior engineer level without CCSP or equivalent credential. Mid-level engineers can reach senior individual-contributor roles but struggle to move into architecture or management without a recognized credential.
At CCSP: Opens doors to cloud security architect roles, cloud governance and compliance leadership, and advanced incident response positions. Financial services, healthcare, and government agencies increasingly mandate CCSP for cloud security leads. Recognized as equivalent or complementary to CISSP in cloud-native organizations.
Post-CCSP: Many professionals pursue specialized paths:
- CISSP — for broader enterprise security leadership (many hold both CISSP and CCSP).
- AWS/Azure/GCP security specialty certs — for deeper vendor-specific technical expertise.
- Cloud Security Alliance (CSA) advanced certifications — for container security, API security, and supply-chain-in-cloud specialization.
- GIAC certifications in cloud contexts — for technical depth (e.g., GPEN applied to cloud infrastructure testing).
Sources
- ISC2 CCSP Certification Page
- ISC2 CCSP CBK (2022)
- CCSP Exam Blueprint
- Destination Certification CCSP MasterClass
- Cybrary CCSP Free Course
- Boson ExSim-Max CCSP
- Sybex CCSP Study Guide (2E)
- McGraw-Hill CCSP All-in-One (1E)
- Glassdoor Cloud Security Salary Data
- Robert Half 2024 IT Salary Guide
- IT Jobs Watch UK Cloud Security
- Cloud Security Alliance
Last verified: 2026-05-01
Parent ecosystem: ISC2 Ecosystem
Parent domain: Cloud Security Domain
Vendor overview: ISC2 Vendor Overview