CCSP vs CISSP: the cloud one is a sequel, not an alternative
The quickest way to understand how CCSP and CISSP relate is to read one line of ISC2's CCSP requirements: an active CISSP credential satisfies the entire CCSP experience requirement. Not part of it — all of it. CCSP is built as the specialisation you add, and ISC2 says so in the eligibility rules rather than in marketing copy.
The exams, compared
Both are three hours and both run 100 to 150 questions with a pass mark of 700 out of 1000 points. CISSP is delivered by computerised adaptive testing; ISC2 describes the CCSP format as multiple choice and advanced item types. CISSP is offered in Chinese, English, German, Japanese and Spanish; CCSP in English, Chinese, Japanese and German.
On fees, ISC2 lists CCSP at $599 against CISSP's $749 for the Americas, Asia Pacific, the Middle East and Africa, with CCSP at €575.04 for EMEA and £485.19 in the UK.
What CCSP weighs most heavily
CCSP domain weightings, ISC2 exam outline
- 20%Cloud Data Security
- 17%Cloud Concepts, Architecture and Design
- 17%Cloud Platform & Infrastructure Security
- 17%Cloud Security Operations
- 16%Cloud Application Security
- 13%Legal, Risk and Compliance
- 100% in total — the weightings add up, which is how we check we copied them correctly.
ISC2 publishes six CCSP domains with weightings, and the spread is even flatter than CISSP's. Cloud Data Security at 20% leads. Cloud Concepts, Architecture and Design, Cloud Platform & Infrastructure Security and Cloud Security Operations sit at 17% each. Cloud Application Security at 16% follows, and Legal, Risk and Compliance at 13% closes the list. The six add to 100.
Five of the six domains fall between 16% and 20%, which makes CCSP unusually unforgiving of gaps. There is no low-weight domain to trade away.
The experience rule, and its unusual generosity
ISC2 asks for a minimum of five years cumulative, full-time experience in information technology, of which three years must be in cybersecurity and one year must be in one or more of the six CCSP domains. That is a narrower requirement than it first appears — the one year of cloud-specific work is the part most candidates have to wait for.
The substitutions are where CCSP differs from everything else in this space. A post-secondary degree in computer science, IT or a related field waives up to one year. The Cloud Security Alliance's CCSK certificate substitutes for one year. An active CISSP satisfies the whole requirement. Only one year can be waived in total, except for the CISSP route, which replaces the requirement rather than reducing it. Part-time work and internships count towards the total.
As with CISSP, candidates without the experience can pass and become an Associate of ISC2, with six years to earn the five years required.
The part that makes the pair cheap
ISC2 charges a single annual maintenance fee of $135 regardless of how many of its certifications you hold. That is the quiet economics of this decision: the first ISC2 credential costs $749 plus $135 a year, and the second costs its exam fee and nothing more per year. Adding CCSP to an existing CISSP is a $599 decision, full stop.
Running the arithmetic over a first three-year cycle: CISSP alone is $1,154, CCSP alone is $1,004, and the pair — sat by somebody who already holds CISSP — is the $749, the $599 and one $135 fee a year rather than two.
Which first, honestly
If your work is broad security across a mixed estate, CISSP first, every time. It is the credential hiring processes recognise, it is the one that satisfies CCSP's experience rule outright, and it leaves CCSP available as a cheap, fast second step whenever the cloud part of your job grows.
If your work is exclusively cloud — you have never configured a physical anything, your estate is entirely somebody else's data centre, and your risk conversations are about shared responsibility models — CCSP first is defensible. You will need the one year in a CCSP domain either way, and you may reach it long before you reach five broad years.
What is not defensible is treating CCSP as an easier CISSP. The fee is lower and the domain count is smaller, but the weighting spread is tighter and the material is no gentler. If you are still working out which credential fits the layer you defend, start with the comparison by career stage; if the blocker is experience rather than subject, the CISSP experience clause covers the same ground in detail.
The one year in a domain is the real bottleneck
Read the CCSP requirement carefully and the binding constraint is not the five years — most people aiming at this credential have those — it is the year of work in one or more of the six cloud domains. Designing cloud data protection, running cloud security operations, owning the legal and compliance side of a cloud migration: any of those counts, and ISC2 states that part-time work and internships count towards the total.
If your cloud exposure so far has been using a provider's console rather than securing what runs on it, that year has not started yet. It is a much better reason to delay CCSP than any feeling about difficulty, and it is a reason with a clear remedy: ask for the cloud-facing work.
What the CISSP substitution really signals
ISC2 could have written the CCSP rule as a partial credit. It did not; it made an active CISSP satisfy the whole experience requirement. That is a statement about how the two credentials are meant to sit together — CCSP is a depth credential layered on a breadth one, not a competing general certification with a cloud flavour.
It also has a practical consequence for sequencing. Somebody two years from CISSP eligibility who is already doing cloud security full-time could reach CCSP first, hold it while the broader years accumulate, and then sit CISSP later. Somebody one year from CISSP eligibility should wait and take the substitution, because it converts a five-year wait into no wait at all.
Neither is a replacement for a provider certification
A recurring confusion is worth settling: CCSP is vendor-neutral, and it does not teach you a platform. It is about cloud security as a discipline — shared responsibility, data lifecycle, portability, legal exposure across jurisdictions. If your employer needs somebody who can configure one provider's identity service correctly this quarter, that provider's own certification track answers the question and CCSP does not.
CCSP questions
Does CISSP really cover the whole CCSP experience requirement?
How much does CCSP cost?
Is CCSP the same exam format as CISSP?
Should I do a cloud provider's own certification instead?
Still deciding between credentials? Work through which cybersecurity certification fits the stage you are at, or read how every figure on this site is checked. Fees, formats and eligibility rules change without warning — open the certifying body’s page before you pay for anything.