Answer 5 quick questions and get a personalized recommendation, plus a full side-by-side comparison, decision matrix, and study plans for both certifications.
Two of the most recognized cloud security credentials — built for very different career stages.
5 questions. Get a personalized recommendation in under a minute.
All the facts you need, in one table.
| Criteria | CCSP | CCSK |
|---|---|---|
| Issuing body | ISC2 | Cloud Security Alliance (CSA) |
| Exam cost | $599 (one attempt) | $445 (1 token = 2 attempts, 2-yr window) |
| Prerequisites | 5 yrs IT experience (3 in security, 1 in a CCSP domain); CISSP waives it entirely; CCSK waives 1 year | None — open to anyone |
| Exam format | Proctored, closed-book, Computerized Adaptive Testing (CAT) | Online, open-book, self-scheduled |
| Questions / time | 100–150 items / 3 hours | 60 items / 120 minutes |
| Passing score | 700 / 1000 | 80% |
| Domains covered | 6 domains | 12 domains (v5) |
| Depth of focus | Deep, applied: architecture, ops, legal/risk for hands-on practitioners | Broad, foundational: shared responsibility, CCM, governance basics |
| Renewal / validity | 3-year cycle; 90 CPEs (60 Group A) required | Does not expire; no mandatory renewal |
| Annual fees | $135 Annual Maintenance Fee | None |
| Accreditation | ANAB / ISO-IEC 17024; DoD 8140.03 approved | Industry-standard, vendor-neutral; aligned to CSA's Cloud Controls Matrix |
| 2026 update | New exam outline (Aug 1, 2026) adds explicit AI/ML security across all domains | v5 consolidated content into 12 domains, added AI/agentic-cloud guidance |
| Typical roles | Cloud Architect, Cloud Security Engineer, Cloud Consultant, Auditor | Security Analyst, DevOps, Compliance/Audit, Sales Engineer, IT Generalist |
| Reported avg. salary | ~$148,000/yr | ~$122,000/yr |
Rate how important each statement is to you, from 1 (not important) to 5 (very important).
A realistic prep timeline for each certification.
Verify your experience meets the 5-year requirement (or plan for Associate of ISC2). Take a diagnostic practice exam to find weak domains.
Cloud Concepts & Architecture, Cloud Data Security, Cloud Platform & Infrastructure Security. Pair the Official ISC2 CBK with hands-on labs in a cloud sandbox.
Cloud Application Security, Cloud Security Operations, Legal/Risk/Compliance. These domains are dense — budget extra time for compliance frameworks.
Run full-length timed CAT-style practice exams. Review wrong answers by domain, then schedule at a Pearson VUE center or OnVUE remote.