Certified Cloud Security Professional

ISC2 · CCSP · Expert

ISC2 · ISC2

Certified Cloud Security Professional

CCSPactiveExpert
Official ISC2 source · isc2.org

CCSP · ● Active · Expert · ISC2

ISC2's flagship cloud security certification — the industry-standard credential for security architects and senior engineers specializing in public cloud (AWS, Azure, GCP, OCI). Requires 5 years cumulative IT experience (3 years information security + 1 year in cloud security, networking, or related domains). CISSP or CSA holders waive the experience requirement.


Exam facts

FieldValue
Cost$599 USD
Duration4 hours
Questions150 (all scored)
Passing700/1000 scaled
FormatMultiple choice
DeliveryPearson VUE
LanguagesEnglish (primary); regional availability varies
Valid3 years
Renewal90 CPE credits over 3 years + annual maintenance fee
Prerequisites5 years cumulative IT experience (3 years information security + 1 year CCSP CBK domain); CISSP/CSA holders waive requirement
Released2015 (current CBK v2022 revision)
RetiringN/A

Vendor source — ISC2 CCSP Certification ↗

Official exam guide — CCSP Exam Blueprint ↗

Exam objectives — CCSP Common Body of Knowledge (CBK) ↗


About

The CCSP (Certified Cloud Security Professional) is ISC2's premier cloud security credential, launched in 2015 to address the explosion of cloud adoption across enterprises. Unlike general cloud certifications from hyperscalers (AWS, Azure), CCSP is vendor-neutral and focuses on security governance, architecture, and risk management across multi-cloud environments. The current CBK (2022 edition) reflects modern threats: container orchestration, serverless security, API-first architecture, zero-trust models, and rapid infrastructure-as-code deployments. CCSP is increasingly required for cloud security architects, senior engineers, and compliance leads at financial services, healthcare, and regulated industries. The credential stacks well with CISSP (many professionals hold both) and is recognized by government agencies and Fortune 500 companies as a benchmark for cloud security expertise.


Domain context — Cloud Security

Cloud security spans identity and access management, data protection, application security, and infrastructure hardening across AWS, Azure, GCP, and hybrid environments. CCSP sits at the expert level — validating deep technical knowledge and strategic risk thinking on public and private cloud platforms.

Read full deep dive — ISC2 Ecosystem ↗


Topics covered

CCSP's six Common Body of Knowledge (CBK) domains, weighted by exam emphasis (2022 update):

  • Cloud Concepts, Architecture, and Design (17%) — Cloud service models (IaaS, PaaS, SaaS), deployment models (public, private, hybrid), cloud computing characteristics (elasticity, multi-tenancy, resilience), infrastructure-as-code, scalability, and architectural risk management.
  • Cloud Data Security (20%) — Data classification and handling, encryption at rest and in transit, data loss prevention (DLP), tokenization, key management, secure data lifecycle, privacy-preserving techniques, compliance with data residency requirements.
  • Cloud Platform & Infrastructure Security (17%) — Host hardening, hypervisor security, container security (Docker, Kubernetes), network segmentation, firewall rules, virtual private clouds (VPC), logging and monitoring, infrastructure-as-code security, API security.
  • Cloud Application Security (17%) — Secure SDLC in cloud contexts, application containerization, serverless security, API gateway design, secure coding for cloud (OWASP Top 10 + cloud variants), secrets management, DevSecOps integration.
  • Cloud Security Operations (16%) — Incident detection and response, threat monitoring, SIEM in cloud environments, forensics and logging, security automation, orchestration, automated remediation, managed detection and response (MDR) in cloud.
  • Legal, Risk, and Compliance (13%) — Cloud compliance frameworks (SOC 2, ISO 27001, HIPAA, FedRAMP, GDPR, CCPA), risk assessment and management, vendor management, contracts and SLAs, liability and incident disclosure, privacy regulations specific to cloud.

Source: ISC2 CCSP CBK Overview ↗


Common skills at Cloud Security · Expert

Shared competencies across the cloud security domain at expert level — not specific to CCSP, but foundational for the role.

  • Multi-cloud architecture security — Design and evaluate security postures across AWS, Azure, GCP, and hybrid environments; assess trade-offs between cloud vendor ecosystems.
  • Cloud-native threat modeling — Identify attack surfaces unique to cloud (API abuse, metadata services, overpermissioned IAM roles, supply chain attacks in container registries).
  • Automated security controls and policy-as-code — Enforce security guardrails via infrastructure-as-code (Terraform, CloudFormation); detect and remediate drift in real-time.
  • Regulatory compliance at scale — Map frameworks (FedRAMP, HIPAA, PCI-DSS in cloud contexts) to cloud-native controls; audit and evidence collection across distributed cloud infrastructure.
  • Cloud cost vs. security trade-offs — Advise on cost implications of security decisions (redundancy, encryption overhead, compliance tooling); optimize spending without compromising posture.
  • Vendor risk and SLA negotiation — Evaluate cloud provider security offerings; negotiate SLAs for incident response, backup/recovery, and audit rights.

Recommended courses at Cloud Security · Expert

ProviderTitleCostURL
ISC2 OfficialCCSP Training Bootcamp (5 days)$1,795
Destination CertificationCCSP MasterClass (Rob Witcher)$695–$995
CybraryCCSP (Official ISC2 Content)Free / $99/month premium
Kelly Handerhan (Cybrary)CCSP Deep Dive (Domain-by-domain)Free / Premium
Udemy (Adrian Cantrill)CCSP Certification & Cloud Security$12–$99
INE (Information Security)CCSP Bootcamp (OnDemand)$199–$399

Course-selection rule: Destination Cert's Rob Witcher MasterClass and Cybrary's free curriculum (especially Kelly Handerhan) are gold standards. ISC2's official bootcamp is pricey but direct. Adrian Cantrill's Udemy course is popular for hands-on cloud security labs.


Practice exams

ProviderTitleCostURL
BosonExSim-Max CCSP (200+ questions, adaptive)$99–$149
Destination CertificationCCSP Practice Exams (250+ questions)$69–$99
WhizlabsCCSP Practice Tests (1500+ questions)$99
ISC2 OfficialOfficial CCSP Practice Exams$50–$100

Books

TitleAuthorPublisherYearISBNURL
CCSP Study Guide (2nd Edition)Mike Chapple, James StewartSybex2022978-1119896777
CCSP All-in-One Exam Guide (1st Edition)Diana Kelley, Gabriel KramerMcGraw-Hill2021978-1260462746
The Official (ISC)² CCSP CBK Reference(ISC)² Staff(ISC)² Press2020978-1492089322

Book rule: Sybex Study Guide (2nd Edition, 2022) and McGraw-Hill (1st Edition, 2021) are current and aligned with the 2022 CBK update. The official (ISC)² CBK Reference is dense and authoritative but best paired with a study guide.


Typical job titles at Cloud Security · Expert

Cloud Security Architect · Senior Cloud Security Engineer · Cloud Compliance Manager · Cloud Incident Response Manager · DevSecOps Lead · Cloud Risk & Governance Manager · Cloud Infrastructure Security Manager · Cloud Security Operations Manager

(Job titles drawn from current job-board postings (LinkedIn, Indeed, Glassdoor) that list CCSP as required or strongly preferred.)


Salary

Salary note: CCSP holders command premiums in cloud-heavy industries (fintech, SaaS, healthcare cloud migration). The credential is increasingly required for architect and senior engineer roles at organizations with >50% infrastructure in public cloud. Regional data reflects 2024–2025 surveys; ZAR adjusted for PPP and South African cloud adoption rates.


Skills validated

Concrete cloud platforms, security technologies, and practices tested by the CCSP exam — distinct from general domain competencies.

  • Cloud identity and access management (IAM) — Role-based access control (RBAC) in AWS/Azure/GCP, cross-account assume roles, service principals, federated identity (SAML, OAuth 2.0).
  • Encryption and key management — Key management services (AWS KMS, Azure Key Vault, GCP Cloud KMS), client-side encryption, envelope encryption, TDE (Transparent Data Encryption).
  • Container and Kubernetes security — Pod security policies, network policies, secrets management in containers, image scanning, runtime monitoring, admission controllers.
  • Cloud network security — Virtual Private Cloud (VPC) design, security groups, network ACLs, VPN and Direct Connect, DDoS protection, WAF configuration.
  • Infrastructure-as-code (IaC) security — Terraform, CloudFormation, cloud-native templating; scanning for misconfigurations, supply chain security in IaC pipelines.
  • Serverless security — AWS Lambda, Azure Functions, Google Cloud Functions; least-privilege execution, cold-start abuse, API Gateway authentication/authorization.
  • Incident detection and response in cloud — CloudTrail (AWS), Azure Activity Log (Azure), Cloud Logging (GCP); SIEM integration, forensics collection, log retention and immutability.
  • Data protection and DLP — Sensitive data discovery in cloud storage (S3, Azure Blob, GCS), encryption at rest/in transit, DLP rules, tokenization, PII handling.
  • Cloud compliance automation — Continuous compliance monitoring (Config, Azure Policy, Cloud Asset Inventory), automated remediation, audit trail collection for compliance frameworks (SOC 2, HIPAA, FedRAMP).
  • Vendor management and SLA negotiation — Risk assessment of cloud providers, incident response SLAs, audit rights, disaster recovery commitments.

Prerequisites and qualification path

Standard path (5-year experience required):

  • 5 years cumulative paid professional work experience in Information Technology.
  • Minimum 3 years in information security roles (any domain).
  • Minimum 1 year in one of the six CCSP CBK domains (cloud concepts, data security, platform/infrastructure security, application security, operations, or legal/compliance).
  • Experience can span multiple employers and roles; government and military service counts if full-time equivalent.

Faster path (CISSP or CSA holders):

  • Active CISSP credential waives all experience requirements.
  • Active Cloud Security Alliance (CSA) CCSK (formerly "CCSK" — Cloud Security Knowledge) holder waives experience requirement.
  • If you hold neither, you must meet the standard 5-year requirement.

Associate of ISC2 status:

  • Pass the exam without meeting experience requirements.
  • Hold "Associate of ISC2" badge until you accumulate the required experience.
  • Once experience requirement is met, apply for associate-to-full-credential upgrade (no re-exam required).

Endorsement process

Unlike CISSP, CCSP does not require endorsement after passing the exam. However:

  • If you pass without meeting the experience requirement, you hold "Associate of ISC2" status.
  • Once you meet the 5-year requirement (or 3+1 breakdown), you upgrade to full CCSP via a simple application and verification of work history.
  • No third-party endorser signature required — ISC2 verifies employment dates against your application.

Related certifications

  • Stacks with: CISSP (ISC2) ↗ — many professionals hold both; CCSP deepens cloud expertise.
  • Stacks with: CAP (ISC2) ↗ — certifications and accreditation, often paired in government cloud roles.
  • Prerequisite for: CCSP-ISSAP (ISC2) ↗ — specialized cloud architecture track (if available, requires active CCSP).
  • Complements: AWS Certified Security Specialty ↗ — vendor-specific AWS depth, often paired with CCSP.
  • Complements: Azure Security Engineer Associate ↗ — vendor-specific Azure depth.
  • Equivalents at this level: No direct equivalent; CCSP is the vendor-neutral gold standard for cloud security expertise.
  • Vendor overview: ISC2 Overview ↗

Renewal and maintenance

After certification:

  • Valid for 3 years from the date ISC2 grants your CCSP status.
  • 90 CPE credits required over the 3-year cycle (average 30 CPEs/year).
  • Annual maintenance fee due each year to maintain active status (amount varies; check ISC2 website).
  • CPE sources: Training courses, conference attendance (Cloud Security Alliance summits, AWS re:Invent, Microsoft Ignite), published articles in security journals, volunteer work in cloud security organizations, advanced degrees with cloud security focus, or ISC2-approved webinars.
  • Renewal process: At year 3, submit CPE transcript and maintenance fee; ISC2 grants a new 3-year certificate.

Without renewal, your credential lapses and you lose the title; though many employers honor lapsed CCSP for a period if you maintain industry currency.


Career impact and trajectory

Pre-CCSP: Cloud security roles typically max out at senior engineer level without CCSP or equivalent credential. Mid-level engineers can reach senior individual-contributor roles but struggle to move into architecture or management without a recognized credential.

At CCSP: Opens doors to cloud security architect roles, cloud governance and compliance leadership, and advanced incident response positions. Financial services, healthcare, and government agencies increasingly mandate CCSP for cloud security leads. Recognized as equivalent or complementary to CISSP in cloud-native organizations.

Post-CCSP: Many professionals pursue specialized paths:

  • CISSP — for broader enterprise security leadership (many hold both CISSP and CCSP).
  • AWS/Azure/GCP security specialty certs — for deeper vendor-specific technical expertise.
  • Cloud Security Alliance (CSA) advanced certifications — for container security, API security, and supply-chain-in-cloud specialization.
  • GIAC certifications in cloud contexts — for technical depth (e.g., GPEN applied to cloud infrastructure testing).

Sources


Last verified: 2026-05-01
Parent ecosystem: ISC2 Ecosystem
Parent domain: Cloud Security Domain
Vendor overview: ISC2 Vendor Overview

Rate this cert
Was this helpful?
Comments ()
0/2000