ISC2 CCSP Study Guide: 2026 Exam Outline and Study Plan

Prepare for ISC2 CCSP with the outline effective August 2026: six domains, exam weights, experience requirements, and a cloud security study plan.

The ISC2 Certified Cloud Security Professional (CCSP) is for professionals responsible for cloud security architecture, design, operations, and compliance. It focuses on applying security principles across cloud environments rather than operating one provider’s products.

This guide follows the exam outline effective August 1, 2026. ISC2 revised the domain scope and weights, so use the current official CCSP exam outline when choosing study materials.

Who is this exam for?

CCSP suits people with experience in IT, security, software development, or cloud platforms who want a structured cloud security credential. Related roles include cloud architect, cloud engineer, cloud security analyst, administrator, consultant, and auditor. If you are new to both security and cloud computing, first build a foundation in networking, identity, encryption, and basic cloud services.

Experience requirements and exam format

To earn the CCSP, candidates generally need five years of cumulative, full-time IT experience, including three years in cybersecurity and one year in one or more of the six current CCSP domains. A bachelor’s or master’s degree in computer science, IT, or a related field may substitute for up to one year. The CSA CCSK certificate may also substitute for one year, but only one year total may be waived. An active CISSP can substitute for the full CCSP experience requirement. Candidates who pass before meeting the experience requirement may become an Associate of ISC2 and have a set period to complete it. Check ISC2’s official experience requirements for details and eligibility decisions.

The current CCSP exam uses Computerized Adaptive Testing (CAT). It lasts 3 hours and has 100–150 items, including multiple-choice and advanced item types. The passing score is 700 out of 1,000. Exam languages include English, Chinese, Japanese, and German; Chinese exams are available only during select appointment windows. Confirm the official exam information before booking.

Six domains and exam weights

Domain Main topics Weight
1. Cloud Concepts, Architecture and Design Cloud models, reference architecture, secure design, provider assessment 17%
2. Cloud Data Security Data lifecycle, classification, encryption, keys, retention, and deletion 20%
3. Cloud Platform and Infrastructure Security Data centers, networks, compute, virtualization, infrastructure risk 17%
4. Cloud Application Security Secure development, threat modeling, APIs, application testing 16%
5. Cloud Security Operations Operations controls, monitoring, incident response, forensics, continuity 17%
6. Legal, Risk and Compliance Privacy, jurisdiction, legal duties, risk, and compliance 13%

Cloud Data Security has the largest weight, followed by architecture, infrastructure, and operations. Allocate study time accordingly, while covering all six domains.

How to study the six domains

1. Cloud Concepts, Architecture and Design

Understand the service boundaries of IaaS, PaaS, and SaaS, and deployment models such as public, private, hybrid, and multicloud. Focus on the shared responsibility model: responsibilities change with the service type, and neither the provider nor the customer owns every security task by default.

Review cloud reference architectures, tenant isolation, portability, interoperability, availability, and resilience. For scenario questions, identify the business goal, data sensitivity, and service model before deciding who should implement each control.

2. Cloud Data Security

Use the data lifecycle to connect creation, storage, use, sharing, archiving, and destruction. Study data discovery and classification, protection at rest and in transit, encryption and key management, hashing, masking, anonymization, tokenization, and data loss prevention.

Also understand data residency, data flows, retention periods, legal holds, deletion evidence, and auditability. Ask where the data is, who can access it, who controls the keys, when it must be retained or deleted, and how the organization can demonstrate appropriate handling.

3. Cloud Platform and Infrastructure Security

Review physical facilities, networks, compute, storage, virtualization, and the management plane. Understand tenant isolation, VM and container security, management interface protection, host hardening, patching, and audit logs.

Risk analysis should cover misconfiguration, excessive privileges, shared technology weaknesses, service outages, and supply chain concerns. Business continuity and disaster recovery start with business impact analysis. Know how Recovery Time Objectives (RTOs), Recovery Point Objectives (RPOs), and plan testing guide recovery design.

4. Cloud Application Security

Build security into the software development life cycle: threat model during design, use secure coding and dependency controls during development, test code and applications before release, then monitor and remediate issues in production.

Focus on API security, identity federation, single sign-on, multifactor authentication, secrets and certificate management, and SaaS access governance. Know what static, dynamic, interactive application security testing, and software composition analysis can each reveal; no single tool provides complete assurance.

5. Cloud Security Operations

Study day-to-day controls throughout the cloud service lifecycle: configuration baselines, change control, vulnerability and patch management, centralized logging, alert analysis, backup and recovery, access reviews, and availability monitoring. The management plane is a high-value target and needs strict access limits and ongoing auditing.

Incident response must account for the provider/customer boundary. Define logging, evidence access, escalation, and communication procedures in advance. Forensics requires evidence integrity and chain of custody; incident handling should follow a controlled process to contain, investigate, eradicate, recover, and review.

Understand how cross-border data, residency, privacy obligations, jurisdiction, and e-discovery affect cloud design. A provider’s certification or audit report can support an assessment, but it does not automatically make the customer’s own configuration and processes compliant.

Translate legal and contractual requirements into verifiable controls. Clarify data processing roles, notification duties, audit rights, subcontractor management, and data return or destruction terms. In scenario questions, identify the applicable obligation and data location first, then determine how contract terms, technical controls, and operations work together.

Concepts that are easy to confuse

  • Service models and deployment models: IaaS/PaaS/SaaS describe service capabilities; public/private/hybrid describe deployment.
  • Provider certification and customer compliance: Provider evidence helps an assessment, while the customer remains responsible for its own identities, data, settings, and processes.
  • Encryption and key management: Encryption does not replace secure key generation, storage, rotation, authorization, and destruction.
  • Business continuity and disaster recovery: Continuity keeps critical business functions operating; disaster recovery restores systems and data.
  • Retention and deletion: Retention meets business and legal needs; data should be securely disposed of when the period ends, subject to legal holds.

Six-week study plan

Week Focus Suggested outcome
1 Cloud concepts, service/deployment models, shared responsibility Assign responsibilities in realistic scenarios
2 Data security, classification, encryption, keys, lifecycle Choose protections for data with different sensitivities
3 Cloud platform, networks, virtualization, infrastructure risk Identify key risks in multitenant and management-plane scenarios
4 Application security, SDLC, APIs, testing methods Map controls to development and release phases
5 Operations, continuity, incident response, and forensics Explain response, recovery, and evidence-handling steps
6 Law, privacy, risk, compliance, and review Connect obligations to owners and verifiable controls

Practice questions for each domain every week and keep an error log. Classify each miss as a concept boundary, responsibility assignment, or overlooked scenario constraint. In the final week, check every outline section and revisit weak areas.

Exam readiness checklist

  • Explain all six domains and their weights using materials based on the August 2026 outline.
  • Assign shared responsibilities correctly in IaaS, PaaS, and SaaS scenarios.
  • Connect data classification, encryption, key management, retention, deletion, and auditability.
  • Compare security controls across cloud infrastructure, applications, and operations.
  • Turn privacy, legal, contractual, and compliance obligations into accountable, testable controls.
  • Verify current experience eligibility, exam language, and appointment availability.

What to practice next

Do more than recall control names. Identify the asset, responsible party, risk, and business constraint in each scenario, then select a control that reduces risk and meets the requirement. After each set, map missed questions back to a domain and outline section. Start CCSP practice

WeChat mini program

IT知习 mini program QR code

Search WeChat for: IT知习