Prepare for CCSP by checking which security tasks a provider performs and which remain with the customer. The worked managed-service example shows why provider assurance does not, by itself, complete a customer’s data-access review.
What does the current CCSP outline cover?
The Certified Cloud Security Professional (CCSP) outline effective from 1 August 2026 covers six domains, from cloud architecture and data protection to operations and legal, risk and compliance issues.
Managed cloud services change the boundary between customer and provider tasks. Use the official outline to review those boundaries alongside the whole syllabus, rather than treating the provider’s infrastructure controls as the complete security program.
Artificial intelligence and machine learning (AI/ML) topics are integrated into the existing domains, including threat detection, data-source validation and data protection. There is no separate published AI domain weight.
Sources: CCSP official English exam outline (effective August 1, 2026) — ISC2 CCSP Exam Outline PDF, English, v1/2026; Review the ISC2 CCSP Certification Exam Outline — ISC2 CCSP exam outline page, dated August 1, 2026
What should you review in the six domains?
Use the complete outline alongside this map. The published average weights guide coverage; they are not fixed question counts or a mandatory study timetable.
| Domain | Average weight | A useful review task |
|---|---|---|
| Cloud Concepts, Architecture and Design | 17% | Review service and deployment models, reference architecture, provider evaluation, shared responsibility and the listed AI/ML topics. |
| Cloud Data Security | 20% | Trace data through its lifecycle; review storage, classification, protection, key management, retention and AI/ML datasets. |
| Cloud Platform and Infrastructure Security | 17% | Review infrastructure components, risk analysis, data-center controls and business continuity and disaster recovery. |
| Cloud Application Security | 16% | Review secure development, threat modeling, testing, application interfaces and software supply chains. |
| Cloud Security Operations | 17% | Review operational controls, identity and access management, incident handling and forensics support. |
| Legal, Risk and Compliance | 13% | Review cloud contracts, privacy considerations, audit evidence and enterprise risk implications. |
Practise checking a managed-service review
A provider’s infrastructure assurance does not supply evidence that the customer reviewed access to its own data. Identify the exact checklist item that remains open.
This original exercise uses Amazon S3 and AWS’s published shared-responsibility model. The review checklist and records below are fictional, complete scenario inputs; they are not AWS-mandated approval paperwork.
Practice exercise
A team stores reports in Amazon S3. Its fictional review checklist requires all four recorded items before sign-off: provider infrastructure assurance; customer data classification; a documented customer encryption decision; and review of customer identity and access management (IAM) permissions. The complete record contains the first three items, but the IAM review has not been performed or recorded. Under the given company policy, the customer’s security owner can sign off only when all four items are complete. The team proposes signing off because AWS manages S3’s underlying infrastructure. Which item remains open, who is responsible for addressing it, and does the proposal meet the checklist?
Show answer
The customer IAM-permissions review remains open. The customer must review and record its own data-access permissions, then submit the completed evidence to the named security owner. The proposal does not meet the checklist: provider infrastructure assurance cannot substitute for the missing customer review.
AWS operates S3’s underlying infrastructure, operating system and platform, while the customer retains data and access-configuration responsibilities. The scenario separately records classification and the encryption decision, so only the fourth checklist item is missing. Missing review evidence does not itself prove that permissions are excessive, data was disclosed or a specific breach occurred. Completing this fictional checklist would establish only its listed requirements, not every possible security or legal obligation.
How can you study beyond provider-assurance claims?
For each scenario, connect the security objective, the relevant service boundary and the evidence needed for the decision.
Begin with the current outline and check your resources against all six domains. For older materials, inspect the explanations and exercises for changed or missing coverage, including the listed AI/ML tasks; a date or an added chapter alone does not demonstrate alignment.
In your practice notes, keep provider-operated infrastructure, customer configuration and organizational approval separate. A document covering one responsibility may leave a different responsibility untested.
After an error, identify whether you misunderstood the service, a requirement, the evidence or the approval role. Review the matching objective and explain why each alternative fails under the facts.
- Read the complete worked checklist before revealing the answer, and name the single missing item.
- Practise other domains as well as shared responsibility: data lifecycle, applications, operations, contracts and risk all remain in scope.
- Use mixed timed practice and commit to answers without review, matching the adaptive-test navigation rules.
Sources: CCSP official English exam outline (effective August 1, 2026) — ISC2 CCSP Exam Outline PDF, English, v1/2026; Review the ISC2 CCSP Certification Exam Outline — ISC2 CCSP exam outline page, dated August 1, 2026; Computerized Adaptive Testing — ISC2 CAT page and FAQ
What do you need to earn CCSP?
Passing the exam and completing certification are separate steps.
The experience baseline is five cumulative years of full-time IT work, including three in cybersecurity and one in a current CCSP domain. Qualifying part-time work and internships may also count under ISC2’s published rules.
A qualifying degree or the Cloud Security Alliance’s CCSK certificate may waive one year, with only one year waived in total. An active CISSP satisfies the entire experience requirement; it does not waive the CCSP exam.
If you pass without the required experience, you can pursue the Associate of ISC2 route, with six years to gain the required five years. Associate status is separate from full CCSP certification.
Submit the certification application within nine months of the exam date, after receiving official passing notification. Experience must be endorsed; an ISC2 professional in good standing can do this, or ISC2 can endorse with the required employment evidence. Complete the ethics and first annual maintenance fee requirements.
Sources: Experience Needed for the ISC2 CCSP Certification — ISC2 CCSP experience requirements page; Endorsement | Online Endorsement Application | ISC2 — ISC2 endorsement page; What To Do After Your ISC2 Certification Exam — ISC2 after-your-exam page
What should you expect on the exam?
CCSP allows 180 minutes for 100–150 items at Pearson VUE testing centers. It uses computerized adaptive testing (CAT), which selects items as you respond.
Once you finalize an answer, you cannot return to review or change it. Content is not presented in separate domain sections. The minimum-length exam includes 25 unscored pretest items, which you cannot identify. Read each item carefully and practise committing to an answer.
The published passing grade is 700 out of 1000; it is not a raw 70% or a fixed correct-answer count. ISC2 does not report numerical scores. Unsuccessful candidates receive domain proficiency information.
An unofficial result is normally provided at checkout, followed by official notification. Results can be delayed, so avoid planning around a guaranteed email turnaround.
Sources: CCSP official English exam outline (effective August 1, 2026) — ISC2 CCSP Exam Outline PDF, English, v1/2026; What To Do After Your ISC2 Certification Exam — ISC2 after-your-exam page; Computerized Adaptive Testing — ISC2 CAT page and FAQ
What should you check before booking?
Use ISC2’s current exam policies and your appointment instructions to check identification, accommodations and testing-center requirements.
Check regional pricing when you book. If a retake is needed, the waiting periods are 30 test-free days after the first attempt, 60 after the second and 90 after the third and subsequent attempts, with no more than four attempts per certification program in 12 months.
- Make sure your registration details match the required identification.
- Arrange any testing accommodations through ISC2 before scheduling.
- Review arrival instructions, permitted items and break rules; allowed breaks count against exam time.
- After passing, keep the exam date and application deadline with your experience records.
Sources: How to Get Ready, Prepare for Your ISC2 Certification Exam — ISC2 before-your-exam page; What To Do After Your ISC2 Certification Exam — ISC2 after-your-exam page; Computerized Adaptive Testing — ISC2 CAT page and FAQ
Sources
Key exam facts checked against ISC2's official outline and policy pages.:
- CCSP official English exam outline (effective August 1, 2026)
- Review the ISC2 CCSP Certification Exam Outline
- How to Get Ready, Prepare for Your ISC2 Certification Exam
- What To Do After Your ISC2 Certification Exam
- Endorsement | Online Endorsement Application | ISC2
- Member Policies
- Experience Needed for the ISC2 CCSP Certification
- Computerized Adaptive Testing
- Shared Responsibility Model - Amazon Web Services (AWS)
