How to Pass the ISC2 CCSP in 2026: Format, Cost, Domains and Study Plan

What the CCSP tests under the August 2026 outline, how the adaptive format works, why candidates fail and a seven week plan by domain.

What the ISC2 CCSP is and who it is for

The Certified Cloud Security Professional is ISC2’s advanced cloud security certification. It is vendor neutral and globally recognised, and it validates that you can design, build and manage secure cloud architectures across all the major cloud providers rather than on one platform. It carries particular weight in enterprises, government and regulated industries.

The experience requirement is substantial: 5 years of IT experience, including 3 years in security and 1 year in one of the CCSP domains. You do not need all of that before you sit the exam, though. If you pass without the full experience, you become an Associate of ISC2 and earn the experience afterwards.

The current exam outline took effect on 1 August 2026. It reweighted the domains and refreshed the subdomains, with more attention to AI and machine learning in cloud environments, so check that any study material you use reflects it.

ISC2 CCSP at a glance

Item Detail
Exam code CCSP
Questions 100 to 150, computerised adaptive testing
Time allowed 3 hours (180 minutes)
Passing score 700 on a scale of 1000
Exam fee US$599 per attempt
Where you sit it Pearson VUE testing centres only
Certification valid for 3 years

What is on the exam

Six domains, and the weights are close together. Cloud data security is the largest at 20%, legal, risk and compliance the smallest at 13%, and the other four sit at 16% or 17%. There is no domain you can safely neglect.

Cloud concepts, architecture and design (17%). The foundations: cloud computing definitions, service and deployment models, shared responsibility, reference architectures and the design principles behind a secure cloud. Expect to choose the model that fits a requirement, not just name it.

Cloud data security (20%). The heaviest domain. It covers the data life cycle, storage types, encryption and key management, tokenisation and masking, data discovery and classification, rights management, retention and deletion, and auditing of data events. Questions often hinge on picking the control that protects data at a specific stage of its life.

Cloud platform and infrastructure security (17%). The physical and virtual infrastructure beneath the services: compute, network and storage components, virtualisation risks, designing and planning security controls, and business continuity and disaster recovery in the cloud.

Cloud application security (16%). Secure software development for the cloud: the secure development life cycle, common application vulnerabilities, testing, software assurance, verified supply chain components, identity and access management for applications and specialised architectures such as application gateways and firewalls.

Cloud security operations (17%). Running cloud infrastructure securely day to day: building and operating physical and logical infrastructure, operational controls and standards, digital forensics support, communication with stakeholders and security operations activities such as monitoring and incident management.

Legal, risk and compliance (13%). The smallest domain but often the least familiar. It covers legal requirements and risks unique to cloud, privacy issues across jurisdictions, audit processes, enterprise risk management and outsourcing and contract design with cloud providers.

Why people fail it

The CCSP is built on nuance. Many questions offer several answers that are all technically reasonable, and the one being marked is the best answer from the point of view of the scenario, usually a manager or architect weighing risk and business need. Knowing the right answer is not enough: you need to know why each of the other options is weaker, and candidates who study by memorising facts struggle to make that call consistently.

The adaptive format catches people too. The exam adjusts to how you are doing and ends anywhere between 100 and 150 items, so you cannot pace yourself against a fixed finish line. Some candidates panic when it keeps going or when it stops early, and neither tells you anything about the result.

Then there is breadth. The CCSP spans architecture, data protection, infrastructure, applications, operations and law, and most candidates are strong in some of those and thin in the rest. With weights this even, a weak domain costs you real marks. The revised outline adds a further trap: material written for the previous outline may not reflect the new weighting or the added AI and machine learning content.

A study plan that fits the exam

Seven weeks: one per domain, with the smallest domain sharing its week with a mixed review, and a final week of timed practice. Start with the domains you know least, not the ones you enjoy.

  1. Week 1: cloud concepts, architecture and design. Service and deployment models, shared responsibility and secure design principles. End the week with the free CCSP practice questions to get a feel for how ISC2 frames its scenarios.
  2. Week 2: cloud data security. The data life cycle, encryption and key management, classification, rights management and retention. This is the heaviest domain, so if you have spare time anywhere in the plan, put it here.
  3. Week 3: cloud platform and infrastructure security. Virtualisation, infrastructure components, security controls, and continuity and recovery planning.
  4. Week 4: cloud application security. Secure development, testing, supply chain assurance and application identity. Work the matching questions in the CCSP practice question pack and read the reasoning for every wrong option, not only the correct one.
  5. Week 5: cloud security operations. Operating infrastructure, operational controls, forensics and incident management.
  6. Week 6: legal, risk and compliance, then mixed review. Spend the first half on privacy, audit, risk and contracts, then switch to mixed question sets across all six domains to practise changing context quickly.
  7. Week 7: timed runs. Use the questions only PDF for long sittings against the 3 hour limit, score yourself by domain, and use the remaining days on whatever comes out weakest.

On exam day

You sit the CCSP at a Pearson VUE testing centre. ISC2 does not offer online proctoring for its exams, so there is no option to take it at home. Book your centre early and plan your journey so you arrive in good time for check in.

Because the exam is adaptive, each question depends on how you answered the previous ones. Read every question fully, decide, commit and move on. Do not read anything into the difficulty or the count. You have 3 hours for between 100 and 150 items, which is enough if you keep a steady rhythm and do not agonise over single questions. The passing score is 700 on a scale of 1000, and it is a scaled score, so there is nothing to gain from counting.

Frequently asked questions

Can I sit the CCSP without the full experience?

Yes. The requirement is 5 years of IT experience, including 3 years in security and 1 year in a CCSP domain, but you can pass the exam first and become an Associate of ISC2 while you build the rest.

What happens if I fail? Can I retake it?

You can, but each attempt costs the full US$599 again. ISC2 publishes its retake policy, including waiting periods between attempts, on its website, so read it before you rebook. The practice pack is refunded if you fail, the exam fee is not.

Is the practice question pack enough on its own?

No. The pack is 512 practice questions mapped to the CCSP objectives and aligned to the outline effective 1 August 2026, with the reasoning for every answer and every wrong option. It is practice: it makes the question style familiar, tests your judgement and shows you where you are weak. It is not a course, and it will not replace a proper study guide or hands on cloud experience.

When you want to test yourself properly, get the 512 question CCSP pack for US$39, pass or your money back.