CCSP Domains Explained - Visual guide to all 6 ISC2 CCSP certification domains

CCSP Domains Explained: Complete 2026 Guide to All 6 Domains

Updated February 2026 · 12 min read

The ISC2 Certified Cloud Security Professional (CCSP) exam tests your knowledge across six distinct domains of cloud security. Each domain carries a different weight on the exam, and understanding what they cover — and how they connect — is critical to passing.

This guide breaks down every CCSP domain, its exam weight, key topics, and practical study strategies. Whether you're just starting your CCSP journey or doing final review, this is your roadmap.

⚠️ Exam Outline Change Coming ISC2 has announced a new CCSP exam outline effective August 1, 2026. If you're planning to sit the exam before that date, the current outline (covered in this guide) applies. We'll update this article once ISC2 publishes the full new outline.

📋 Table of Contents

  1. CCSP Domain Overview & Weights
  2. Domain 1: Cloud Concepts, Architecture and Design (17%)
  3. Domain 2: Cloud Data Security (19%)
  4. Domain 3: Cloud Platform and Infrastructure Security (17%)
  5. Domain 4: Cloud Application Security (17%)
  6. Domain 5: Cloud Security Operations (16%)
  7. Domain 6: Legal, Risk and Compliance (14%)
  8. Which Domains to Prioritize
  9. Study Tips by Domain
  10. Exam Format & Requirements

CCSP Domain Overview & Weights

The CCSP exam contains 150 questions (125 scored, 25 unscored pretest items) and you have 4 hours to complete it. The six domains are not weighted equally — Cloud Data Security carries the most weight at 19%, while Legal, Risk and Compliance carries the least at 14%.

CCSP Domain Weights at a Glance

The passing score is 700 out of 1000. ISC2 uses a scaled scoring model, so there's no simple percentage threshold — focus on being strong across all domains rather than gambling on specific ones.

Domain 1: Cloud Concepts, Architecture and Design (17%)

This is your foundation. Domain 1 establishes the conceptual framework for everything else on the exam. If you don't nail this domain, the rest will feel disconnected.

What It Covers

💡 Key Concept: Shared Responsibility Model This appears across multiple domains. In IaaS, you manage everything from the OS up. In PaaS, you manage applications and data. In SaaS, you mainly manage user access and data. Know these boundaries cold — the exam loves testing them.

Study Focus

Memorize the NIST cloud computing definitions. Understand the shared responsibility model across all three service models. Know the difference between cloud-native and cloud-enabled architectures. Be comfortable with business requirements driving cloud decisions.

Domain 2: Cloud Data Security (19%)

This is the highest-weighted domain on the CCSP exam, and for good reason — data protection is the core reason cloud security exists. Expect to see the most questions from this domain.

What It Covers

✅ Exam Tip Crypto-shredding (destroying the encryption key instead of the data itself) is a critical concept for cloud environments where you can't guarantee physical media destruction. Expect questions on when and why to use it.

Study Focus

Master the cloud data lifecycle — it's the backbone of this domain. Understand key management options and their trade-offs. Know the difference between tokenization and encryption. Be clear on data residency vs. data sovereignty.

Domain 3: Cloud Platform and Infrastructure Security (17%)

Domain 3 gets into the technical infrastructure that runs cloud services. This is where your understanding of networking, virtualization, and physical security in cloud data centers gets tested.

What It Covers

Study Focus

Understand the different isolation mechanisms in cloud (physical, virtual, logical). Know your DR metrics (RPO, RTO, MTBF, MTTR). Be clear on how network security differs between on-premises and cloud — especially the management plane, which is unique to cloud environments.

Domain 4: Cloud Application Security (17%)

This domain focuses on building and deploying secure applications in the cloud. If you have a development background, you'll find familiar territory here. If not, pay extra attention.

What It Covers

💡 Key Concept: DevSecOps The CCSP exam expects you to understand how security integrates into CI/CD pipelines. Know the concept of "shifting left" — bringing security testing earlier in the development cycle rather than treating it as a final gate.

Study Focus

Focus on the SSDLC phases and what security activities happen at each stage. Understand identity federation protocols (SAML vs OAuth vs OIDC — know the differences). Be familiar with common cloud application threats and their mitigations.

Domain 5: Cloud Security Operations (16%)

Operations is where theory meets reality. This domain tests your ability to implement, manage, and maintain cloud security on a day-to-day basis.

What It Covers

Study Focus

Understand cloud forensics challenges — you can't just pull a hard drive when the infrastructure is virtualized and shared. Know the differences between cloud-aware and traditional incident response. Master the operational concepts: change management, configuration baselines, and patch management workflows.

Domain 6: Legal, Risk and Compliance (14%)

The lowest-weighted domain, but don't underestimate it. Legal and compliance questions can be tricky because they require understanding specific regulations and frameworks.

What It Covers

⚠️ Watch Out GDPR questions are common. Know the key roles (data controller vs data processor), the 72-hour breach notification requirement, data subject rights (right to erasure, portability, access), and cross-border transfer mechanisms (Standard Contractual Clauses, adequacy decisions).

Study Focus

Don't try to memorize every law — focus on the principles. Understand data controller vs processor responsibilities. Know the major compliance frameworks and what they certify. Be clear on audit types and what each SOC report covers.

Which Domains to Prioritize

While you need competency across all six domains, here's a strategic prioritization based on exam weight and difficulty:

🎯 High Priority

  • Domain 2: Cloud Data Security (19%) Highest weight, broad scope
  • Domain 1: Cloud Concepts (17%) Foundation for everything else

📊 Medium Priority

  • Domain 3: Platform & Infrastructure (17%) Technical but manageable
  • Domain 4: Application Security (17%) Easier if you have dev experience

📋 Don't Neglect

  • Domain 5: Operations (16%) Practical, often overlooked
  • Domain 6: Legal & Compliance (14%) Lowest weight but tricky

⏱️ Time Allocation Tip

  • Spend ~25% of study time on Domains 1 & 2 They set the foundation and carry the most weight
  • Spend ~15% on each remaining domain Even coverage prevents weak spots

Study Tips by Domain

General Strategy

Domain-Specific Tips

Exam Format & Requirements

CCSP Exam Quick Facts

✅ Don't Have the Experience Yet? You can still take and pass the exam. ISC2 will grant you the Associate of ISC2 designation. You'll have 6 years to earn the required experience and complete the endorsement process.

The CCSP is a challenging certification, but with structured study across all six domains, it's absolutely achievable. The key is understanding concepts and their relationships rather than rote memorization. Cloud security is fundamentally about making informed risk decisions — and that's exactly what the exam tests.

Ready to Start Preparing?

Practice with thousands of expert-verified CCSP and CISSP questions. AI-powered gap analysis tells you exactly where to focus.

Start Free 7-Day Trial →

📚 Related CCSP Guides