Expanded edition · Current

CCSP Study Guide

2026.2 EDITION · OUTLINE EFFECTIVE 1 AUGUST 2026

A comprehensive cloud-security companion connecting the complete ISC2 CCSP objective set with architecture, data, applications, operations, assurance, law, risk, contracts, and professional judgment.

ReleasedReviewed 15 Aug 2026CC BY-NC 4.0
6Exam domains
2026.2Expanded edition
Web + PDFPublic formats
FreeIndependent study

Advanced scope. Exam-directed depth.

The expanded edition adds deeper explanation, comparison, scenarios, implementation context, exam traps, and end-of-domain reinforcement without becoming an unfocused textbook.

CertificationISC2 Certified Cloud Security Professional (CCSP)
TargetExam outline effective 1 August 2026
Edition2026.2 · expanded final author-approved release
ExamCAT · 3 hours · 100–150 items · 700/1000
StatusReleased · current
IndependenceNot affiliated with, sponsored by, or endorsed by ISC2

Six domains. One cloud-security system.

Domain 2 carries the highest weight, but strong CCSP reasoning connects data, identity, architecture, operations, responsibility, evidence, and legal context across every domain.

0117%

Cloud Concepts, Architecture and Design

0220%

Cloud Data Security

0317%

Cloud Platform and Infrastructure Security

0416%

Cloud Application Security

0517%

Cloud Security Operations

0613%

Legal, Risk and Compliance

Built to support professional judgment.

The guide moves beyond isolated definitions and asks how security decisions change with the service model, actor, data role, contract, evidence, and jurisdiction.

ARCH

Architecture reasoning

Cloud models, reference architecture, design principles, provider evaluation, related technologies, and AI/ML security context.

DATA

Data lifecycle mastery

Storage, discovery, classification, rights, retention, cryptography, auditability, and model or dataset protection.

OPS

Operational depth

Infrastructure controls, resilience, secure delivery, monitoring, forensics, incident management, and continuous assurance.

GRC

Accountability and evidence

Privacy, jurisdiction, contracts, assurance reports, enterprise risk, outsourcing, and shared-responsibility decisions.

A decision framework. Not a slogan.

Responsibility changes with the service model, provider contract, control, data role, and applicable law. Never assume ownership without evidence.

AreaCustomer retainsProvider contribution varies
DataClassification, lawful purpose, retention, and access decisionsStorage or platform operation and provider-side media handling
IdentityUser and workload entitlement decisions and lifecycleConsumed identity services and platform authorization mechanisms
ApplicationBusiness logic, configuration, integrations, and IaaS/PaaS codeManaged runtimes and most of the SaaS application stack
InfrastructureConfiguration of exposed customer-side controlsPhysical, virtualization, and managed-platform layers
ComplianceObligations and evidence for its use of the serviceScoped assurance evidence and its own obligations

Architecture to assurance. One focused reader.

Study all 12 sections online with focused navigation, or open the controlled PDF for offline reading and annotation.

Open interactive edition Open the PDF
Need structured cloud-security support?Training, mentoring, workshops, and tailored team programs are available.
Explore training