An established exam that just got rewired underneath everyone
CCSP has been around since 2015, which makes it a very different animal from a brand-new credential — except right now it isn't behaving like a settled, mature exam. ISC2 rolled out a revised exam outline effective August 1, 2026, following a fresh Job Task Analysis, and if you're studying for this exam today, you're already on the new version whether you realize it or not. The six domains kept their names, but two domain weights shifted, and AI/ML security content got folded directly into every single domain rather than added as a bolt-on section. Anyone using study material published before mid-2026 is working from a partially outdated blueprint without knowing it.
The mechanics that make CCSP feel different from a typical certification exam
Since October 1, 2025, official CCSP exam has run on Computerized Adaptive Testing rather than a fixed question set. That means the exam adjusts question difficulty based on how you're performing in time, your question count varies between 100 and 150 depending on the algorithm's read of your ability, and once you submit an answer, you cannot go back and change it. This is a meaningfully different experience than working through a static 125-question exam at your own pace, and if your practice habit is to skip hard questions and return to them later, that habit won't transfer to exam day.
Scoring uses a fixed 700-out-of-1,000 passing standard — unlike ISACA's scaled range on some cybersecurity exams, this number hasn't moved through any of CCSP's recent format changes. You get three hours to complete it, at a Pearson VUE testing center, in English, Simplified Chinese, German, or Japanese.
The domain weights, current as of the August 2026 outline
Six domains, and two of them just changed weight for the first time since 2022:
Domain 2: Cloud Data Security — 20%. The heaviest domain by a clear margin, and it now folds in explicit AI/ML data protection content — dataset and model privacy, training data validation, and data remanence risk in ephemeral AI compute storage.
Domain 1: Cloud Concepts, Architecture and Design — 17%. Cloud fundamentals, reference architecture, and design principles, now extended to cover AI-as-a-Service shared responsibility boundaries and infrastructure-as-code for AI environments.
Domain 3: Cloud Platform and Infrastructure Security — 17%. Data center design, infrastructure risk analysis, and security controls, now including virtualization and container hardening specific to hosting ML models.
Domain 5: Cloud Security Operations — 17%. This one moved up a point from 16% in the refresh — operations, incident response, and monitoring, with new emphasis on using AI/ML for threat hunting and detecting security-relevant "model drift."
Domain 4: Cloud Application Security — 16%. This one moved down a point from 17% — secure SDLC, testing methodologies, and API security, now covering prompt injection and inference-attack risks in AI-integrated applications.
Domain 6: Legal, Risk and Compliance — 13%. The lightest domain by percentage, but the one that separates CCSP from a purely technical certification — now extended to cover AI explainability requirements under frameworks like the EU AI Act.
If you studied from material published before the outline refresh, the domain names and rough weights will look familiar, but don't assume the underlying content is identical — the task and knowledge statements inside each domain changed meaningfully even where the percentage barely moved.
Eligibility works differently here than on most security certifications
CCSP requires five years of cumulative, full-time IT experience, with three of those years specifically in cybersecurity and one year in one or more of the six CCSP domains. A relevant bachelor's or master's degree can satisfy up to one year of that requirement, and so can CSA's CCSK certificate — though only one year total can be waived this way. The detail that changes the calculus for a lot of candidates: holding an active CISSP waives the entire experience requirement outright, turning CCSP into a pure knowledge exam. This is a big part of why so many CISSP holders treat CCSP as the natural next step when they specialize into cloud — the experience gate that stops other candidates simply doesn't apply to them.
Who's actually sitting for this CCSP exam
The CCSP candidate pool splits into two groups that study differently. One group already holds CISSP and is using CCSP to formalize a cloud specialization they're already practicing day to day — for them, the exam is mostly about mapping existing security judgment onto cloud-specific scenarios. The other group is building toward CCSP through direct IT and cybersecurity experience without CISSP first, and for them the exam tests genuinely new material across all six domains rather than an extension of something they already know cold. If you're in the first group, don't assume your CISSP knowledge transfers cleanly to Domain 2's data security content or Domain 6's cloud-specific legal material — both go well beyond what CISSP covers.
Common mistakes candidates make on this CCSP exam
The most consequential mistake right now is studying from a guide that hasn't been updated for the August 2026 outline. Because the domain names and most percentages didn't change, it's easy to assume old material still applies — but the AI/ML content woven into every domain, plus the point-shift between Domains 4 and 5, means a pre-2026 study guide will leave gaps that don't announce themselves until exam day.
A second common mistake is treating the CAT format like the old fixed exam with a different name. Since you can't review or revise earlier answers, second-guessing a question after you've moved on is wasted effort — practicing under conditions where you can't go back trains the discipline the actual format demands.
A third mistake, especially among CISSP holders: underestimating Domain 6. It's the lightest-weighted domain, but its cloud-specific legal, privacy, and audit content — cross-border data transfer rules, cloud-specific attestation reports, jurisdictional conflicts — doesn't overlap much with CISSP's more general risk management domain, and candidates who assume it does tend to lose points there.
How to use the free practice test effectively
Since Domain 2 carries the most weight at 20%, prioritize it, but don't neglect Domain 6 just because it's the smallest — its content is narrow enough that focused review closes the gap quickly, and skipping it entirely is a common way to lose points that were genuinely recoverable. Practice under simulated time pressure without the option to revisit earlier questions, since that's the actual condition you'll face under CAT. If you're coming in with a CISSP background, deliberately weight your practice toward Domains 2 and 6, since those are where your existing knowledge will transfer the least.
Study tips specific to this CCSP exam's current state
Confirm which outline your scheduled exam date falls under before you study anything. If your test date is on or after August 1, 2026, you need material aligned to the revised outline — pull the actual outline PDF from ISC2's site rather than trusting a study guide's summary of it, since the exact task and knowledge statements are what tell you where to spend your hours. Build a specific review pass around the AI/ML content that's now embedded in each domain rather than treating it as a separate topic; it's not.
If you're a CISSP holder using the experience waiver, resist the urge to under-study relative to non-CISSP candidates — you're skipping an experience gate, not a knowledge requirement, and the exam doesn't ease up on domains just because you hold a related certification.
Where to go from here
Work through the practice questions below organized by the current six-domain weighting, and pay attention to whether your gaps sit in the AI/ML content that's new to this outline or in the traditional cloud security material that's been stable since 2022 — that distinction will tell you whether you need a targeted update pass or a broader review before you book your Pearson VUE appointment.