Fast Track Bootcamps
 Crafted For Career-Ready Skills

CCSP Exam Changes Explained: A Complete Comparison

Quick Insights:

The CCSP exam’s biggest change since 2024 is the shift of the English-language test to Computerized Adaptive Testing. The exam now includes 100–150 questions, lasts up to three hours, and does not allow candidates to revisit submitted answers. The six domains, their weightings, and the 700-point passing score remain unchanged, but preparation must now focus more strongly on scenario-based decision-making, cloud-native security, automation, data protection, shared responsibility, privacy, and third-party risk.

The Certified Cloud Security Professional, or CCSP, has always been designed to test more than a candidate’s ability to memorize cloud terminology. It evaluates whether security professionals can apply governance, architecture, data protection, application security, operations, risk, and compliance principles across modern cloud environments.

CCSP Exam Updates What Changed from 2024 to 2026

Between 2024 and 2026, the CCSP exam evolved in two important ways. First, ISC2 changed how the English-language exam is delivered. Second, the exam content continued to mature to reflect how organizations now build, operate, and secure cloud services.

These updates do not turn CCSP into a completely different certification. The six-domain structure remains familiar, the exam remains vendor-neutral, and the passing standard continues to be 700 out of 1,000 points. However, candidates using older study plans need to understand how the exam experience and the expected depth of knowledge have changed.

CCSP Changes at a Glance

  • August 1, 2024: Exam reduced from 150 questions in four hours to 125 questions in three hours.
  • October 1, 2025: Fixed-form exam replaced by Computerized Adaptive Testing.
  • August 1, 2026: Revised CCSP exam outline takes effect.
  • 2026 domain change: Cloud Application Security decreases from 17% to 16%.
  • 2026 domain change: Cloud Security Operations increases from 16% to 17%.
  • Unchanged: Six domains, vendor-neutral focus, and 700-point passing standard.

The Major 2024 Change: CCSP Moved to Adaptive Testing

The most significant CCSP exam format update during the 2024–2026 period was the transition of the English-language examination to Computerized Adaptive Testing, commonly known as CAT, on October 1, 2025. Until September 30, 2025, candidates took the exam in a fixed, linear format with a predetermined set of questions. Under the CAT format, questions are presented one at a time and are selected in part based on the candidate’s demonstrated performance during the examination. This allows the testing system to assess competency more efficiently while tailoring the exam experience to each candidate.

The updated English CCSP exam typically contains 125 questions and has a maximum testing time of 180 minutes. The examination may finish before the maximum number of questions when the testing system has gathered enough evidence to determine the result. This replaced the earlier structure of a longer, fixed-question examination. The adaptive format also changes how candidates interact with the exam. Questions are presented one at a time, and candidates can not normally return to a previous question after submitting an answer. This makes decision-making and time management especially important.

Note: Candidates taking the exam in another language should check the current examination format when booking. Language availability and delivery methods may differ from the English CAT examination.

What the CAT Format Means for Candidates?

During a CAT examination, the scoring system reassesses the candidate’s estimated ability after every submitted response. The next question is selected to help the system measure that ability more precisely.

It is often said that every correct answer immediately produces a harder question and every incorrect answer produces an easier one. That is an oversimplification. The algorithm considers the difficulty of all questions already presented and the candidate’s complete response pattern before choosing the next item.

The examination ends when one of the following occurs:

  • The system reaches the required statistical confidence in the result after the minimum number of questions.
  • The candidate reaches the maximum of 150 questions.
  • The three-hour examination period expires.

The minimum-length CCSP CAT examination includes 100 items, of which 25 are unscored pretest questions used to evaluate possible future exam content. Candidates cannot identify which questions are scored, so every item must be treated seriously.

No Backtracking or Answer Review

One of the most important practical changes introduced on October 1, 2025, was the removal of question review.

Questions are presented one at a time. Once the candidate confirms an answer, it cannot be changed or revisited. Candidates cannot skip a difficult item and return to it later.

This means candidates should:

  • Read qualifiers such as BEST, FIRST, MOST appropriate and PRIMARY carefully.
  • Identify the business, legal or security objective before reviewing the options.
  • Determine whether responsibility lies with the customer, the provider, or both.
  • Select the best available response instead of searching for a perfect answer.
  • Avoid spending excessive time trying to estimate how well the exam is going.

An examination ending at 100 questions does not automatically indicate a pass or failure. Similarly, receiving all 150 questions does not reveal the final result. It only shows how long the system required to reach its decision.

A New CCSP Exam Outline

The third change is a genuine content update. A revised CCSP exam outline became effective on August 1, 2026, following ISC2’s Job Task Analysis process. Candidates sitting the exam:

  • On or before July 31, 2026: Follow the October 1, 2025 outline.
  • On or after August 1, 2026: Follow the revised 2026 outline.

The CAT format remains in place after the new outline becomes effective. The exam will still contain 100–150 questions, last up to three hours, and require a passing standard of 700 out of 1,000.

CCSP Domain Weight Changes Effective August 1, 2026

The revised outline retains all six domains, but the weightings of two domains change.

  • Domain 1: Cloud Concepts, Architecture and Design — 17%
    No change
  • Domain 2: Cloud Data Security — 20%
    No change
  • Domain 3: Cloud Platform and Infrastructure Security — 17%
    No change
  • Domain 4: Cloud Application Security — 16%
    Decreases from 17%
  • Domain 5: Cloud Security Operations — 17%
    Increases from 16%
  • Domain 6: Legal, Risk and Compliance — 13%
    No change

Cloud Data Security remains the highest-weighted domain. The one-percentage-point shift from application security to security operations suggests a modest increase in emphasis on running, monitoring, and protecting cloud environments after deployment.

Confirmed 2026 Content Changes by Domain

The 2026 revision does not replace the familiar CCSP structure. Instead, it updates individual objectives to reflect AI adoption, cloud-native development, modern operations, changing privacy requirements and evolving security practices.

Domain 1: Cloud Concepts, Architecture and Design

Effective August 1, 2026, Domain 1 remains weighted at 17%, but it receives one of the most visible content additions. A new objective, “Comprehend Artificial Intelligence and Machine Learning,” introduces:

  • Cloud-based threat detection and analysis
  • Data-source validation and verification
  • Security Orchestration, Automation and Response
  • Ethical concerns involving AI
  • Regulatory requirements affecting AI and ML

Other refinements include:

  • Secure-by-design architecture
  • Isolation in virtualized environments
  • Immutable architecture
  • Expanded cloud hardening concepts
  • Continued coverage of AI, ML, quantum computing, edge computing and confidential computing

Candidates should understand AI and ML from a cloud security perspective. The objective is not to become a Data Scientist, but to recognize the governance, infrastructure, data, and operational risks associated with hosting these technologies in the cloud.

Domain 2: Cloud Data Security

Domain 2 remains the largest domain at 20%.

The most significant addition is a new objective covering the protection of AI and ML data, including:

  • Dataset privacy
  • Model privacy
  • Dataset security
  • Model security
  • Validation and verification

The revised outline also expands or clarifies:

  • Object and volume storage
  • Data integrity and non-repudiation
  • Data labeling and tagging
  • Legal-hold access and deletion-prevention requirements

Candidates must understand that AI security is closely connected to data security. Training datasets, model files, inference data, secrets and supporting storage services all require appropriate classification, access control, integrity protection and lifecycle management.

Domain 3: Cloud Platform and Infrastructure Security

Domain 3 remains weighted at 17%.

The 2026 outline mainly refines existing infrastructure and risk concepts rather than introducing a separate new subdomain. Updates include:

  • Clearer resilience requirements for power, cooling and connectivity
  • Greater clarity around physical, network, compute, virtualization, storage and management-plane components
  • Use of the broader term risk treatment instead of only risk mitigation
  • Continued focus on identity, authentication, authorization and audit mechanisms
  • Business continuity and disaster-recovery planning

Candidates should continue studying cloud infrastructure as an interconnected system. A control applied to networking, virtualization, or the management plane can affect availability, isolation, and security across the entire cloud environment.

Domain 4: Cloud Application Security

From August 1, 2026, Domain 4 decreased from 17% to 16%. Despite the lower weighting, several modern application-security topics become more explicit.

Important additions and refinements include:

  • OWASP API security risks
  • OWASP Top 10 for Large Language Model Applications
  • Application Security Verification Standard
  • CI/CD security
  • Static Application Security Testing
  • Dynamic Application Security Testing
  • Software Composition Analysis
  • Supply-chain integrity and authenticity
  • Docker and Kubernetes
  • Load balancers and API gateways
  • Expanded secrets, key and certificate management

The change reflects how cloud applications are now built through APIs, containers, automated pipelines, open-source components and third-party services. Candidates should understand how security is integrated throughout the software lifecycle rather than applied only before production deployment.

Domain 5: Cloud Security Operations

Domain 5 increases from 16% to 17% on August 1, 2026.

The revised outline strengthens several operational areas:

  • Secure-by-default infrastructure
  • Management-plane tools
  • Network segmentation
  • Threat intelligence
  • Incident response
  • Penetration testing
  • Configuration management
  • Cloud hardening
  • Security monitoring and log analysis

It also references a broader range of operational and governance frameworks, including NIST, ISO, COBIT, CIS Controls, COSO and ITIL.

The increased weighting reinforces the importance of continuous cloud security. Designing a secure environment is only the beginning; professionals must also monitor configurations, manage vulnerabilities, detect incidents, preserve evidence and maintain security as cloud resources change.

Domain 6: Legal, Risk and Compliance

Domain 6 remains weighted at 13%, but the 2026 outline broadens several legal and privacy areas.

Notable refinements include:

  • More detailed digital-forensics standards
  • Expanded privacy-law examples
  • Recognition of data stewards alongside owners, controllers, custodians and processors
  • Risk and control self-assessments
  • Data ownership within cloud contracts
  • Explicit contractual security requirements
  • Continued focus on audit rights, breach notification and supply-chain management

Privacy examples now include frameworks and laws such as:

  • GDPR
  • HIPAA
  • FERPA
  • PIPEDA
  • India’s Digital Personal Data Protection Act

The domain continues to test a crucial principle: an organization may outsource cloud operations, but it cannot automatically outsource accountability for privacy, risk, contractual or regulatory obligations.

How to Prepare for the Updated CCSP Exam?

Taking the exam before August 1, 2026

Use material aligned with the outline effective from October 1, 2025. Practice under CAT conditions and prepare for:

  • 100–150 questions
  • A three-hour limit
  • No answer review
  • Variable question difficulty
  • Scenario-based decision-making

Taking the exam on or after August 1, 2026

Use the revised 2026 outline and add focused preparation in:

  • AI and ML security
  • AI dataset and model protection
  • OWASP LLM application risks
  • API security
  • CI/CD security
  • Docker and Kubernetes
  • Threat intelligence
  • Penetration testing
  • Secure-by-default architecture
  • Updated privacy and contractual requirements

Practical Preparation Checklist

  • Map every study topic to the applicable official outline.
  • Study all six domains rather than relying only on technical experience.
  • Practice selecting the best answer when several options appear valid.
  • Review shared responsibility across SaaS, PaaS and IaaS.
  • Understand the full cloud data lifecycle.
  • Study application and software supply-chain risks.
  • Review cloud contracts, audit rights and data ownership.
  • Practice questions without returning to earlier answers.
  • Complete timed practice sessions within three hours.
  • Review why each incorrect answer is unsuitable.

Conclusion

The CCSP exam has changed in clearly defined stages. The August 1, 2024 update shortened the exam. The October 1, 2025 update introduced adaptive testing. The August 1, 2026 update revises the content and domain weightings.

The central purpose of CCSP remains unchanged. Candidates must demonstrate the ability to evaluate cloud risks, protect data, support secure development, maintain resilient operations, and make decisions aligned with legal, regulatory, and business requirements.

The most effective preparation strategy is therefore not to memorize isolated terms. It is to understand which outline applies to your examination date and practice applying cloud security principles to realistic scenarios.

CCSP Cloud Security Certification Training

TRAINING CALENDAR of Upcoming Batches For CCSP Training

Start Date End Date Start - End Time Batch Type Training Mode Batch Status
27-Sep-2026 28-Nov-2026 09:00 - 13:00 IST Weekend Online [ Open ]
14-Nov-2026 03-Jan-2027 19:00 - 23:00 IST Weekend Online [ Open ]

Frequently Asked Questions

What changed in the CCSP exam on August 1, 2024?

The exam was reduced from 150 questions in four hours to 125 questions in three hours. The six domains and their weightings did not change.

When did CCSP move to Computerized Adaptive Testing?

The CCSP exam moved to CAT on October 1, 2025.

How many questions are on the CCSP exam?

The CAT examination contains between 100 and 150 questions.

Can candidates review previous CCSP answers?

No. Once an answer is submitted during the CAT exam, it cannot be reviewed or changed.

Does the 2025 CAT update change the CCSP syllabus?

No. The CAT transition changed the testing format, not the content outline or passing standard.

When does the new CCSP exam outline take effect?

The revised outline became effective on August 1, 2026.

Which CCSP domain weights change in 2026?

Cloud Application Security decreases from 17% to 16%, while Cloud Security Operations increases from 16% to 17%.

Does the 2026 CCSP exam include AI security?

Yes. The updated outline adds explicit AI and ML objectives, including threat detection, data validation, AI data protection, ethical concerns, and regulatory requirements.

What is the CCSP passing score?

The passing standard remains 700 out of 1,000 points.

Are older CCSP study materials still useful?

They remain useful for foundational concepts, but candidates taking the exam on or after August 1, 2026, should supplement them with material aligned to the new outline.

CCSP-Exam-Update-Practice-Questions
TOP