CCSP Exam Outline Update: What Changed on August 1 and Where AI Fits in the Six Domains

ISC2 revised the CCSP outline on August 1, 2026. See the six domains, reported weights, where AI appears in the outline, and a study plan for candidates who studied before.

CCSP exam outline update
On this page
  1. Quick Facts
  2. What Changed at a Glance
  3. The weights
  4. The date ladder
  5. The AI Map: Where ISC2 Puts AI in the Outline
  6. Domain by Domain: What ISC2’s Outline Lists
  7. Domain 1: Cloud Concepts, Architecture and Design (reported 17%)
  8. Domain 2: Cloud Data Security (reported 20%)
  9. Domain 3: Cloud Platform and Infrastructure Security (reported 17%)
  10. Domain 4: Cloud Application Security (reported 16%
  11. Domain 5: Cloud Security Operations (reported 17%)
  12. Domain 6: Legal, Risk and Compliance (reported 13%)
  13. Official Outline vs Third-Party Lists: Where They Differ
  14. Format: What We Know About the CAT Exam
  15. Cost, Experience and Maintenance
  16. Should You Take CCSP? A Decision Table
  17. If You Studied Before August: The Gap Table
  18. An Eight Week Study Plan
  19. Five practice prompts from the new outline
  20. Common Mistakes
  21. Career Value
  22. What We Don’t Know Yet
  23. FAQS

Guide overview

What this article covers

TL;DR: ISC2’s revised Certified Cloud Security Professional (CCSP) exam outline is dated August 1, 2026, and it keeps the same six domains. The weights barely moved. Two third-party breakdowns show only Cloud Application Security slipping from 17% to 16% and Cloud Security Operations rising from 16% to 17%. The real change is content. ISC2’s outline now builds AI and machine learning into four subdomains (1.2, 1.6, 2.9 and 5.6) and names the OWASP Top 10 for LLM Applications in subdomain 4.1. ISC2 does not publish domain weights on the outline page we could read, and several third-party sites list extra topics (zero trust, SBOMs, EU AI Act, NIS2, DORA) that do not appear as named subdomains, so this guide separates what ISC2’s page shows from what other sites report. If you studied before August, the gap is small in percentages but real in content.

CCSP candidates tend to ask one question after an outline change: “Do I need to start over?” For most people the answer is no. You need to add a layer of AI and application security topics on top of what you already know. This guide shows exactly where.

Quick Facts

ItemWhat the sources say
ExamISC2 Certified Cloud Security Professional (CCSP)
Revised outline dateAugust 1, 2026 (shown on ISC2’s outline page and announced by ISC2 in June 2026)
Domains6, unchanged in name
Required work experience5 years (stated on ISC2’s CCSP page)
Reported weights (new outline)17%, 20%, 17%, 16%, 17%, 13% for domains 1 to 6
Reported weights (old outline)17%, 20%, 17%, 17%, 16%, 13% for domains 1 to 6
FormatComputerized adaptive testing (CAT), reported as 100 to 150 questions in up to 3 hours
Passing score700 out of 1,000 (reported)
Reported fee$599 per attempt in the Americas
Reported annual maintenance fee$125 per year
Reported continuing education90 credits per 3 year cycle, 60 of them cloud specific

Items marked “reported” come from third-party sources. ISC2’s CCSP page and outline page, as we could read them, did not list the format, fee or weights.

What Changed at a Glance

The weights

DomainOld outlineNew outlineChange
1. Cloud Concepts, Architecture and Design17%17%None
2. Cloud Data Security20%20%None
3. Cloud Platform and Infrastructure Security17%17%None
4. Cloud Application Security17%16%Down 1 point
5. Cloud Security Operations16%17%Up 1 point
6. Legal, Risk and Compliance13%13%None

These figures come from two third-party sources that agree with each other, and a third site lists the older set. Neither ISC2 page we read showed the weights, so treat them as reported until you check ISC2’s materials.

The lesson is that a one-point shift means almost nothing for study planning. What matters is what sits inside each domain.

The date ladder

DateEventSource
August 1, 2024Exam reduced from 150 questions in four hours to 125 questions in three hoursReported by one third-party source
October 1, 2025English exam moved to computerized adaptive testingReported by two sources, including CertMage’s own earlier post
June 2026ISC2 announced the revised outlineISC2 article, “ISC2 Refreshes CCSP Exam”
August 1, 2026Revised outline takes effectISC2’s outline page and announcement

ISC2’s June announcement cites its Cybersecurity Workforce Study, which says cloud security is the second most in-demand skill, behind only AI. That context explains why the update leans so heavily on AI.

The AI Map: Where ISC2 Puts AI in the Outline

This is the most useful table in the post. We read ISC2’s outline page and listed every place it names AI, ML or LLM topics in an enumerated subdomain.

SubdomainWhat the outline saysDomain
1.2 Cloud reference architectureIncludes the impact of AI, ML and related technologies1. Cloud Concepts, Architecture and Design
1.6 AI/MLThreat detection, SOAR, ethics and regulatory requirements1. Cloud Concepts, Architecture and Design
2.9 AI/ML data protectionDataset and model privacy and security2. Cloud Data Security
4.1 Application security trainingOWASP Top 10, ASVS, OWASP API Top 10 and the OWASP Top 10 for LLM Applications4. Cloud Application Security
5.6 Security operationsSOC, SIEM, incident response, vulnerability assessment and penetration testing, including AI-based monitoring5. Cloud Security Operations

Three details are worth noting.

  1. AI and ML are named in four subdomains (1.2, 1.6, 2.9 and 5.6), and subdomain 4.1 adds the LLM list. Domains 3 and 6 have no enumerated AI subdomain.
  2. LLM appears only once, through the OWASP Top 10 for LLM Applications in subdomain 4.1.
  3. The word “agentic” does not appear in the enumerated subdomains we read.

ISC2’s page also contains narrative sections about AI in each domain, mentioning ideas such as homomorphic encryption, differential privacy, prompt injection, model drift and the EU AI Act. None of those terms appear in the enumerated subdomains. A careful reader should treat them as descriptive commentary and not as guaranteed test objectives unless ISC2 says otherwise. Still, they are worth a short read, because a topic described in the outline’s narrative can show up in scenario wording.

Domain by Domain: What ISC2’s Outline Lists

Domain 1: Cloud Concepts, Architecture and Design (reported 17%)

SubdomainTopicWhat changed
1.1Cloud computing conceptsCore
1.2Cloud reference architectureNow includes AI and ML impact
1.3Cloud security conceptsCore
1.4Secure cloud design principlesIncludes DevOps security
1.5Evaluating cloud service providersCore
1.6AI/MLThreat detection, SOAR, ethics, regulatory requirements

Domain 2: Cloud Data Security (reported 20%)

SubdomainTopicWhat changed
2.1Data concepts and flowsCore
2.2Storage architectures and threatsCore
2.3Encryption, hashing, obfuscation, tokenization, DLP, key managementCore
2.4Data discoveryCore
2.5ClassificationCore
2.6Information Rights ManagementCore
2.7Retention, deletion, archiving, legal holdCore
2.8Auditability, traceability, accountabilityCore
2.9AI/ML data protectionDataset and model privacy and security

Domain 2 remains the heaviest domain at a reported 20%, and subdomain 2.9 is the AI addition.

Domain 3: Cloud Platform and Infrastructure Security (reported 17%)

SubdomainTopic
3.1Infrastructure and platform components
3.2Secure data center design
3.3Cloud risk analysis
3.4Security controls
3.5Business continuity and disaster recovery

Domain 3 has no named AI subdomain. One third-party source reports clearer resilience requirements and “risk treatment” wording here. We could not match that to ISC2’s page, so treat it as reported.

Domain 4: Cloud Application Security (reported 16%

SubdomainTopicWhat changed
4.1Application security trainingNames OWASP Top 10, ASVS, OWASP API Top 10 and OWASP Top 10 for LLM Applications
4.2Secure SDLCCore
4.3Applying the SDLCThreat modeling, secure coding, configuration management
4.4Software assurance and testingSAST, DAST, SCA, IAST
4.5Verified secure software and supply chainCore
4.6Cloud application architectureCore
4.7Identity and access managementCore

This domain dropped one reported point, and subdomain 4.1 now names the LLM application risk list. If your study notes stop at the classic OWASP Top 10, add the API and LLM lists.

Domain 5: Cloud Security Operations (reported 17%)

SubdomainTopicWhat changed
5.1Building infrastructureCore
5.2Operating infrastructureCore
5.3Operational controls and standardsITIL, ISO, NIST and others
5.4Digital forensicsCore
5.5Stakeholder communicationCore
5.6Security operationsSOC, SIEM, incident response, vulnerability assessment, penetration testing, now including AI-based monitoring
SubdomainTopic
6.1Legal requirements and eDiscovery
6.2Privacy
6.3Audit processes
6.4Enterprise risk management
6.5Outsourcing and contract design

Domain 6 is the smallest domain and has no named AI subdomain, though the narrative text refers to AI regulation.

Official Outline vs Third-Party Lists: Where They Differ

Several sites list more topics than ISC2’s enumerated subdomains show. Here is how to read the difference.

Topic reported by third partiesWhere we found it in ISC2’s outlineVerdict
AI and ML objectives in Domain 1Yes, subdomains 1.2 and 1.6Confirmed
AI/ML dataset and model protection in Domain 2Yes, subdomain 2.9Confirmed
OWASP API and LLM risks in Domain 4Yes, subdomain 4.1Confirmed
SAST, DAST, SCAYes, subdomain 4.4Confirmed
AI-based monitoring in Domain 5Yes, subdomain 5.6Confirmed
Zero trust as a distinct topic (ZTNA, micro-segmentation, SASE, CISA maturity model)Not an enumerated subdomainReported only
SBOMs and build pipeline securitySoftware supply chain appears in 4.5, but SBOM is not namedPartly reported
Containers, Kubernetes and serverless securityNot named in the subdomain list we readReported only
EU AI Act, NIS2, DORA, NIST AI RMFNot named in the enumerated subdomains. The narrative mentions the EU AI ActReported or narrative only
Data stewards, risk and control self-assessments, more privacy laws in Domain 6Not named in the enumerated subdomainsReported only

The safe approach: study every confirmed item, then treat the “reported only” items as extras worth a quick review. Cloud security candidates will probably meet most of them at work anyway.

Format: What We Know About the CAT Exam

FeatureReport
Testing methodComputerized adaptive testing
Length100 to 150 questions
Typical lengthOne source says the exam typically contains 125 questions
Time limitUp to 3 hours
Unscored itemsOne source says the minimum-length exam includes 25 unscored pretest items
ReviewQuestions are presented one at a time, and submitted answers cannot be changed or revisited
Early finishThe exam ends once the system reaches the required confidence after the minimum length
Passing score700 out of 1,000
LanguagesOne source lists English, Chinese, Japanese and German

An adaptive exam rewards a calm pace. You cannot skip a question and return, so decide, answer and move on. The format has been in place since October 2025, so it is not new in this update.

ISC2’s own pages, as we could read them, did not state the question count, time or passing score. These details come from third-party sources, so check ISC2’s exam policy page before you book.

Cost, Experience and Maintenance

ItemReportSource type
Exam fee$599 per attempt (Americas), full fee again for retakesThird party
Required work experience5 yearsISC2’s CCSP page
Experience breakdownFive years cumulative full-time IT experience, including three in information security and one in one or more CCSP domainsThird party
Degree waiverA relevant degree can waive up to one yearThird party
CCSKCan substitute for one year, with only one year waived in totalThird party
Active CISSPWaives the entire CCSP experience requirementThird party
Without the experienceYou can pass and become an Associate of ISC2, with six years to meet the requirementThird party
Annual maintenance fee$125 per yearThird party
Continuing education90 credits per 3 year cycle, 60 cloud specificThird party

The experience breakdown and waivers are widely repeated, but ISC2’s page, as we read it, showed only “5 years.” Confirm the waiver details on ISC2’s site before relying on them.

Should You Take CCSP? A Decision Table

Your situationSuggestionWhy
Security professional moving into cloud with 5 years of experienceCCSP is a strong fitIt matches the experience requirement and the cloud focus
Already hold CISSPCCSP is a natural next credentialOne source says an active CISSP waives the CCSP experience requirement. See CISSP vs CISM to compare broader paths
Under 5 years of experienceConsider CCSK firstSee our CCSK vs CCSP comparison
Working mainly in AWSCompare CCSP with a vendor credentialSee CCSP vs AWS Security Specialty
Early in your careerLook at entry points firstSee our best cybersecurity certifications ranking
Interested in offensive securityCCSP is not the best matchCompare with CISSP vs CEH

If You Studied Before August: The Gap Table

GapWhat to addWhere it lives
AI and ML in reference architectureThe impact of AI and ML on cloud designSubdomain 1.2
AI/ML as a topicThreat detection, SOAR, ethics and regulatory requirementsSubdomain 1.6
AI/ML data protectionDataset and model privacy and securitySubdomain 2.9
OWASP listsOWASP API Top 10 and OWASP Top 10 for LLM ApplicationsSubdomain 4.1
AI-based monitoringHow AI supports SOC, SIEM and incident responseSubdomain 5.6
Reported extrasZero trust, SBOMs, containers, EU AI Act, NIS2, DORAReported by third parties, not named as subdomains

ISC2 does not publish a line-by-line redline between the two outlines, so this table combines ISC2’s current outline with third-party comparisons of the old and new versions. If your study material predates the outline, the gap is about five specific items. You do not need to restart your preparation.

An Eight Week Study Plan

This plan assumes you already work in security and have some cloud exposure.

WeekFocusGoal
1Domain 1Cloud concepts, reference architecture, provider evaluation, and the AI/ML subdomains
2Domain 2Data lifecycle, encryption, key management, classification, and AI/ML data protection
3Domain 3Infrastructure, risk analysis, controls, continuity
4Domain 4Secure SDLC, testing methods, and the OWASP API and LLM lists
5Domain 5Operations, forensics, controls and standards, and AI-based monitoring
6Domain 6Legal, privacy, audit, risk and contracts
7Adaptive practiceAnswer one question at a time and review every miss
8Weak spots and restRevisit your lowest area and book the exam

For extra practice, our CCSP practice questions can supplement your own notes, as long as you check each topic against ISC2’s outline.

Five practice prompts from the new outline

These are study prompts, not real exam questions.

#PromptSubdomain
1A team wants to train a model on customer data in a public cloud. List three data protection controls you would require2.9
2Name two risks in the OWASP Top 10 for LLM Applications and one mitigation for each4.1
3Explain how AI-based monitoring could help a SOC, and one risk of relying on it5.6
4Compare two cloud providers for hosting an AI workload, and state the security criteria you would use1.5 and 1.2
5Describe the ethical and regulatory questions to ask before deploying an AI tool for threat detection1.6

Common Mistakes

MistakeWhy it hurts
Studying only from pre-August materialYou will miss five specific AI-related items
Overreacting to a one-point weight changeThe shift in Domains 4 and 5 is tiny
Memorizing every “reported only” topicThey are not named as subdomains. Prioritize confirmed items
Ignoring the OWASP API and LLM listsThey are named in subdomain 4.1
Skipping Domain 6 because it is the smallestIt is still a reported 13%
Forgetting you cannot revisit adaptive questionsPace yourself and commit to each answer
Assuming the fee and waiver rules are officialConfirm them on ISC2’s site
Treating narrative AI text as guaranteed objectivesIt is commentary unless ISC2 confirms

Career Value

CCSP targets security professionals who design, manage and secure cloud environments, and ISC2’s own workforce research says cloud security is among the most in-demand skills. The updated outline adds AI security topics, which keeps the credential aligned with where cloud work is heading.

We have not included salary figures in this post. We could not find a figure that separates people holding CCSP from everyone else in a similar cloud security role. If you are comparing paths, our best cybersecurity certifications ranking compares credentials by return on investment.

What We Don’t Know Yet

Open questionWhy it matters
The official domain weightsWe rely on third-party sources that agree with each other
Whether the reported extras (zero trust, SBOMs, NIS2, DORA) are testedThey are not named as subdomains
The official question count, time and feeISC2’s pages as we read them did not state them
How the pass rate changes under the new outlineNo data published
Whether the narrative AI text produces scored questionsISC2 does not say
Whether weights will shift againOutlines can change
How ISC2 treats candidates who tested under the old outline and failedWe found no statement

FAQS

When did the CCSP exam outline change?

The revised outline is dated August 1, 2026 on ISC2’s outline page, and ISC2 announced it in June 2026.

Did the CCSP domains change?

No. The six domain names are the same: Cloud Concepts, Architecture and Design; Cloud Data Security; Cloud Platform and Infrastructure Security; Cloud Application Security; Cloud Security Operations; and Legal, Risk and Compliance.

Did the domain weights change?

Barely. Two third-party sources report Cloud Application Security falling from 17% to 16% and Cloud Security Operations rising from 16% to 17%. ISC2’s page did not show the weights we could read.

What is new in the CCSP outline?

AI and ML content appears in subdomains 1.2, 1.6, 2.9 and 5.6, and subdomain 4.1 names the OWASP API Top 10 and the OWASP Top 10 for LLM Applications.

Does the CCSP exam cover agentic AI?

The word does not appear in the enumerated subdomains we read, so we cannot say it is tested.

Is zero trust on the CCSP exam?

Some third-party sources list it as a distinct topic, but it is not an enumerated subdomain on ISC2’s page. Study it as general cloud security knowledge.

How many questions are on the CCSP exam?

Third-party sources report 100 to 150 questions in up to 3 hours using computerized adaptive testing, with about 125 typical. Check ISC2’s exam policy page for the official numbers.

What is the passing score?

700 out of 1,000, according to the sources we read.

How much does the CCSP exam cost?

One source reports $599 per attempt in the Americas and a $125 annual maintenance fee. Confirm current pricing with ISC2.

How much experience do I need?

ISC2’s CCSP page lists 5 years of required work experience. Third-party sources break it down as three years in information security and one year in a CCSP domain, with waivers for a degree, CCSK or an active CISSP.

Can I take CCSP without the experience?

One source says you can pass the exam and become an Associate of ISC2, with six years to meet the requirement. Confirm this with ISC2.

Do I need to restart if I studied before August?

No. Add the AI and ML items, the OWASP API and LLM lists, and AI-based monitoring. The rest of your preparation still applies.

How does CCSP compare with CCSK?

CCSP is a professional-level credential with a work experience requirement, while CCSK is often a first step. Our CCSK vs CCSP guide compares them in detail.

Put this guide into practice

Practice the exams in this guide

Start with free exam-style questions and explanations, then move to the full practice set when you are ready.

About this guide

This article is intended to help readers make a practical certification or career decision. It was published on October 7, 2026 and revised on October 8, 2026. No external references are included in this article, so confirm time-sensitive policies, prices, and requirements directly with the relevant provider.

Report a correction or outdated detail

Reader discussion

Questions, context, or corrections?

Share a relevant question or point out a detail that may need another look. Comments are moderated for usefulness.

Leave a Comment

Your email address will not be published. Required fields are marked *


Continue exploring

View all Cloud Certifications
Scroll to Top