Security Notes
Study tracks

CCSP Track

The CCSP (Certified Cloud Security Professional, from ISC2) is the vendor-neutral cloud sibling of the CISSP. It tests cloud concepts, data protection, platform and application security, operations, and the legal and contractual side of using someone else's infrastructure. This track follows the exam outline in effect from 1 August 2026, which added AI and machine-learning subdomains (1.6 and 2.9). Weights below are from ISC2's announcement of that outline.

3 min read 6 sections verified 2026-10

Last verified2026-10

DomainWeight
1. Cloud Concepts, Architecture and Design17%
2. Cloud Data Security20%
3. Cloud Platform and Infrastructure Security17%
4. Cloud Application Security16%
5. Cloud Security Operations17%
6. Legal, Risk and Compliance13%
Tip

CCSP questions are vendor-neutral: answer with concepts (customer-managed keys, CASB, crypto-shredding), not product names. The AWS links below are concrete examples, not exam vocabulary.

Domain 1 — Cloud Concepts, Architecture and Design (17%)

Domain 2 — Cloud Data Security (20%)

Domain 3 — Cloud Platform and Infrastructure Security (17%)

Domain 4 — Cloud Application Security (16%)

Domain 5 — Cloud Security Operations (17%)