CCSP Exam Changes August 2026: New Domains and Study Plan
A date-aware CCSP study guide for the revised outline effective 1 August 2026, with domain planning and scenario-led mock review.
Which CCSP outline applies to your exam date?
ISC2 has announced a revised CCSP exam outline effective 1 August 2026. Candidates testing before that date should use the outline in force for their appointment; candidates testing on or after it should prepare against the revised outline.
Do not blend two outlines into one vague checklist. Download the version that matches your exam date from the official CCSP exam-outline page, then verify the appointment if you reschedule across the changeover date.
The revised CCSP domain weights are:
- Cloud Concepts, Architecture and Design: 17%;
- Cloud Data Security: 20%;
- Cloud Platform and Infrastructure Security: 17%;
- Cloud Application Security: 16%;
- Cloud Security Operations: 17%; and
- Legal, Risk and Compliance: 13%.
Compared with the immediately preceding outline, one percentage point moves from Cloud Application Security to Cloud Security Operations. The more important change is the revised task and knowledge detail inside the domains, so updating only a weighting table is not enough.
What stays consistent in the 2026 CCSP exam?
CCSP continues to assess advanced cloud-security knowledge across architecture, data, platforms, applications, operations, and legal or risk considerations. ISC2 lists a computerized adaptive test lasting three hours with 100 to 150 items and a passing grade of 700 out of 1,000.
ISC2 also publishes professional-experience requirements for earning the certification. Candidates who pass without the required experience may be able to follow the Associate of ISC2 pathway under ISC2's current rules. Confirm eligibility and endorsement requirements on the official site; passing an exam and holding the certification are not necessarily the same milestone.
Build a CCSP study plan around cloud responsibility
The six domains should not be treated as separate vocabulary lists. Most cloud-security decisions depend on service model, deployment model, data sensitivity, contractual responsibility, jurisdiction, architecture, and operational evidence.
For each topic, ask:
- Which party owns the decision or control?
- Where is the data or workload in its lifecycle?
- What evidence demonstrates that the control works?
- Which legal, contractual, or risk constraint changes the answer?
- What should happen first when several actions appear useful?
Cloud concepts, architecture, and design
Review cloud roles, service and deployment models, shared considerations, reference architectures, virtualization, containers, orchestration, interoperability, portability, resilience, and design trade-offs. Connect architecture choices to business and security requirements rather than selecting a technology in isolation.
Cloud data security
Follow information from discovery and classification through storage, use, sharing, archiving, and destruction. Cover encryption, key management, tokenization, data loss prevention, access, retention, privacy, and auditability. State clearly who controls keys and where trust changes.
Platform, infrastructure, and application security
Study physical and logical infrastructure risks, secure design, network controls, workload protection, vulnerability management, business continuity, and disaster recovery. For applications, connect the software development lifecycle to identity, APIs, testing, supply-chain dependencies, and deployment controls.
ISC2's 2026 revision highlights the changing cloud environment, including risks and controls associated with AI-enabled applications and software dependencies. Use the official outline to determine the expected depth instead of relying on broad technology news.
Operations, legal, risk, and compliance
Review monitoring, logging, incident response, change management, configuration, forensics, continuity, privacy, contracts, e-discovery, audit, and regulatory responsibilities. Practise deciding which evidence or authority is needed before taking a technical action.
A six-week CCSP preparation schedule
Week 1: choose the correct outline and take a baseline
Map every objective from the applicable outline. Take a diagnostic and separate cloud-architecture gaps from security-governance gaps.
Weeks 2 and 3: architecture, data, platforms, and applications
Work through scenarios that follow one workload across the four domains. Draw trust boundaries, responsibility splits, data flows, and control evidence.
Week 4: operations and incident decisions
Practise monitoring, investigation, containment, recovery, and post-incident improvement in cloud contexts. Pay attention to evidence preservation and provider responsibilities.
Week 5: legal, risk, compliance, and mixed scenarios
Compare contractual, regulatory, privacy, and risk-management decisions. Avoid assuming that a technically strong response is automatically the correct governance response.
Week 6: adaptive pacing and mock review
Complete timed mixed practice without consulting notes. Review uncertain correct answers as seriously as incorrect ones, then return to authoritative sources for each repeated gap.
How to use a CCSP practice test responsibly
A CCSP mock exam can assess breadth, pacing, and judgement, but it cannot reproduce ISC2's adaptive algorithm or predict the official result. Classify errors by domain and by reasoning pattern: responsibility, lifecycle, evidence, risk priority, or misunderstood technology.
Open the CertGuru CCSP mock exam for a timed baseline. If your broader security-governance reasoning needs work, compare the CISSP preparation guide without treating the two credentials as interchangeable.
CertGuru is an independent exam-preparation platform and is not affiliated with or endorsed by ISC2. CCSP, ISC2, and associated marks belong to their respective owners. CertGuru does not provide official or recalled exam content, and practice results do not guarantee certification.
Authoritative references
- ISC2 CCSP certification and experience information
- ISC2 CCSP exam outlines
- ISC2 announcement: CCSP outline revised for August 2026
Confirm the outline tied to your scheduled date and review current ISC2 policies before registration.