← All certifications

Certified Cloud Security Professional (CCSP)

ISC2

ISC2's advanced credential validating expertise in designing, managing, and securing data, applications, and infrastructure in the cloud.

We have a course for this

Built from this exam's published objectives. The first module is free.

Baseline certification levels

This certification satisfies these DoD baseline levels — the IAT / IAM / IASAE / CSSP requirement many contracts still state. It's a separate question from the 8140 work roles above, and there is no official mapping between the two.

What this qualifies you for

Listed specifically for 10 work roles — up to Advanced proficiency. Because options cascade downward, a cert listed at Advanced also satisfies Intermediate and Basic for that role.

441Network Operations (NETOPS) SpecialistPlans, implements, and operates network services/systems, to include hardware and virtual environments.Advanced451System Administrator (SYSADMIN)Installs, configures, troubleshoots, and maintains hardware, software, and administers system accounts.Advanced531Cyber Defense Incident ResponderInvestigates, analyzes, and responds to cyber incidents within the network environment or enclave.Intermediate611Authorizing Official/Designated Representative (AO/DR)Senior official or executive with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation (CNSSI 4009).Intermediate631Information Systems Security DeveloperDesigns, develops, tests, and evaluates information system security throughout the systems development lifecycle.Intermediate641Systems Requirements PlannerConsults with customers to evaluate functional requirements and translate functional requirements into technical solutions.Intermediate651Enterprise ArchitectDevelops and maintains business, systems, and information processes to support enterprise mission needs; develops information technology (IT) rules and requirements that describe baseline and target architectures.Intermediate652Security ArchitectDesigns enterprise and systems security throughout the development lifecycle; translates technology and environmental conditions (e.g., law and regulation) into security designs and processes.Intermediate671System Testing and Evaluation (T&E) SpecialistPlans, prepares, and executes tests of systems to evaluate results against specifications and requirements as well as analyze/report test results.Advanced722Information Systems Security Manager (ISSM)Responsible for the cybersecurity of a program, organization, system, or enclave.Intermediate
Also listed for 14 Cyberspace Enablers roles — but so is every other certification

The Enablers matrix isn’t role-differentiated: the same certification options are listed for all 14 roles at every proficiency level. We verified that across all 14. So this is true, and it carries no information about this credential specifically — which is why it isn’t in the count above.

Renewal

3year cycle90CPE per cycle30minimum per year

Annual Maintenance Fee, USD 135/year

This is the issuer’s clock. 8140 runs a second one — 20 hours of CPD a year, at every proficiency level, which applies even if you hold no certification at all. How that works

Exam format changed from linear to CAT effective October 1, 2025; older study materials may still reference a 125-item, 4-hour linear format. Annual minimum CPE (30/year for CCSP) is the traditional ISC2 requirement; a 2025 ISC2 CPE policy update reportedly reframed the annual minimum as suggested rather than strictly required while keeping the 90-CPE 3-year total. Confirm current wording in the ISC2 Certification Maintenance Handbook before publishing. AMF confirmed at USD 135/year for professional certifications (raised from the older USD 125); a single AMF covers a member regardless of how many ISC2 certifications they hold.

Source: ISC2 CCSP Certification Exam Outline · dated 2026-07-17 · checked 2026-07-17

Verifying it

ISC2 has no public lookup a third party can use on their own — verification depends on a badge URL you share.

ISC2 digital badges are issued via Credly and are independently shareable/verifiable by badge URL. ISC2 also offers a member verification service, but it requires the holder's ISC2 member ID (or identifying details).

Exam format changed from linear to CAT effective October 1, 2025; older study materials may still reference a 125-item, 4-hour linear format. Annual minimum CPE (30/year for CCSP) is the traditional ISC2 requirement; a 2025 ISC2 CPE policy update reportedly reframed the annual minimum as suggested rather than strictly required while keeping the 90-CPE 3-year total. Confirm current wording in the ISC2 Certification Maintenance Handbook before publishing. AMF confirmed at USD 135/year for professional certifications (raised from the older USD 125); a single AMF covers a member regardless of how many ISC2 certifications they hold.

Source: ISC2 CCSP Certification Exam Outline · dated 2026-07-17 · checked 2026-07-17

Exam blueprint

Verified against ISC2’s published outline.

CCSP · Effective October 1, 2025 (CAT)

Current

100-150 items · 3 hours · passing score 700 of 1000

Cloud Concepts, Architecture and Design17%
Cloud Data Security20%
Cloud Platform & Infrastructure Security17%
Cloud Application Security17%
Cloud Security Operations16%
Legal, Risk and Compliance13%

Exam format changed from linear to CAT effective October 1, 2025; older study materials may still reference a 125-item, 4-hour linear format. Annual minimum CPE (30/year for CCSP) is the traditional ISC2 requirement; a 2025 ISC2 CPE policy update reportedly reframed the annual minimum as suggested rather than strictly required while keeping the 90-CPE 3-year total. Confirm current wording in the ISC2 Certification Maintenance Handbook before publishing. AMF confirmed at USD 135/year for professional certifications (raised from the older USD 125); a single AMF covers a member regardless of how many ISC2 certifications they hold.

Source: ISC2 CCSP Certification Exam Outline · dated 2026-07-17 · checked 2026-07-17