Certification guide

CCSP

ISC2 CCSP: the honest guide

Everything ISC2 publishes about CCSP, in one place: what the exam asks, how the domains are weighted, and what it takes to be ready.

This guide page is built from the registry, not written yet.

Everything below comes from CCSP’s published exam data, and every figure links to the vendor page it came from. The researched version, with study plans and the parts nobody publishes, is still being written. This page is not submitted to search engines until it is.

See everything published on CCSP

What the exam actually asks you to do

Multiple choice and ISC2's advanced item types. There is no lab and no simulation, so the practice that matters is reading a scenario and choosing well.

Item formats

  • Multiple choice

Nothing here needs a lab. Reading carefully and eliminating options is the whole skill. ISC2, CCSP exam outline

Domain breakdown and official weightings

From the official ISC2 exam outlines. Cloud Data Security is the heaviest domain at 20 percent, followed by Cloud Concepts, Architecture and Design at 17 percent.

  • Cloud Concepts, Architecture and Design17%
  • Cloud Data Security20%
  • Cloud Platform & Infrastructure Security17%
  • Cloud Application Security16%
  • Cloud Security Operations17%
  • Legal, Risk and Compliance13%

Where to focus: Cloud Data Security is the heaviest domain at 20 percent, but the other five sit between 13 and 17 percent, so the CCSP spreads its questions widely and a weak domain is hard to hide. The exam outline that took effect on August 1, 2026 is the one being tested now, so check the effective date on any study material you buy. If you already hold an active CISSP, ISC2 substitutes it for the entire CCSP experience requirement, which leaves the exam as the only step.

ISC2: ISC2 exam outlines

What comes after passing

CCSP is valid for 3 years. ISC2 runs a three year certification cycle. CCSP holders must earn 90 CPE credits across that cycle, 60 of which must be Group A, and pay the annual maintenance fee of U.S. $135 each year on the anniversary of their certification date. ISC2 allows a 90 day grace period after the cycle expiration date to earn and submit required CPE credits.

Costs across the full renewal cycle are on the CCSP cost page.

Frequently asked questions

How much does the CCSP exam cost?

ISC2 lists standard registration for the CCSP exam at U.S. $599 in the Americas, Asia Pacific, the Middle East and Africa, EUR 575.04 in EMEA, and GBP 485.19 in the United Kingdom. ISC2 notes that pricing and taxes are based on the location of exam administration.

What experience does ISC2 require for the CCSP?

Five years of cumulative, full-time IT experience, of which three years must be in cybersecurity and one year in one or more of the six CCSP domains. A relevant post-secondary degree or CSA's CCSK certificate can each substitute for one year, and only one year can be waived. An active CISSP substitutes for the entire CCSP experience requirement.

Can I take the exam before I have five years of experience?

Yes. ISC2 says a candidate without the required experience may become an Associate of ISC2 by passing the CCSP exam, and then has six years to earn the five years of required experience.

What does it take to keep the CCSP active?

CCSP holders earn 90 CPE credits over the three year certification cycle, 60 of them Group A, and pay an annual maintenance fee of U.S. $135. Members pay a single AMF no matter how many ISC2 certifications they hold.

Keep reading

  • CCSP exam overview

    The format, the domain weights and the renewal terms, sourced line by line.

  • CCSP passing score

    The exact cut score, what kind of number it is, and the retake terms.

  • How hard is CCSP?

    An honest difficulty read from the format, the clock and the weights.

Every guide and cost breakdown, by vendor