DigiTrustAsia
CCSP

CCSP August 2026: What Changes in the New Exam Outline

From 1 August 2026 the CCSP runs on a new exam outline. Here is what actually changes, what stays, and how to choose which outline to study against.

ISC2 has confirmed it on the certification's official page: effective 1 August 2026, the CCSP exam is based on a new exam outline. If your test date falls on or after that day, you sit the new exam; a day earlier, the old one. That single sentence has been generating more candidate anxiety than it deserves — so here is what the change actually is, what it is not, and how to plan around it.

What kind of change this is

A new exam outline means ISC2 has completed a Job Task Analysis — a structured review of what working cloud security professionals actually do — and rewritten the exam content to match. That makes this a content refresh, distinct from the format changes of the last two years, when the exam was first shortened and then moved to Computerized Adaptive Testing (CAT) with 100–150 items in up to three hours and a passing scaled score of 700/1000.

So the sequence candidates have lived through is: format first, content now. The CAT engine, the timing and the pass mark are not what's changing in August — the body of knowledge is.

What changes and what stays

Based on the published outline, the six-domain structure survives. The familiar architecture — Cloud Concepts and Design, Data Security, Platform and Infrastructure, Application Security, Operations, Legal and Compliance — remains the skeleton of the exam.

The headline addition is explicit AI/ML coverage. The refreshed outline writes artificial intelligence and machine learning into the body of knowledge directly — comprehension of AI/ML in cloud security contexts (threat detection and analysis, automation and SOAR, data source validation, ethical concerns and AI regulatory requirements) and AI/ML data protection (dataset and model privacy, dataset and model security). Until now, candidates could treat AI as background noise; from August it is examinable subject matter with its own outline sections.

The shift mirrors what regulators and clients are already asking cloud teams: not "do you use AI?" but "can you govern the data that trains it and the decisions it makes?"

Two cautions worth stating plainly. First, third-party summaries of the new outline vary in detail — before you finalise a study plan, pull the official outline PDF from ISC2 itself and let its domain weights tell you where to spend hours. Second, treat any percentage you read elsewhere, including here, as provisional until you have that PDF in hand.

Should you book before or after the change?

This decision is simpler than it feels:

Your situationSensible move
Ready now, studying current materialBook before 1 August 2026 — your materials match your exam
3+ months from readyStudy to the new outline from the start
Mid-preparation, date undecidedPick a side now and commit; straddling outlines is the worst position
CISSP holder adding CCSPThe experience waiver still applies — but your outline is whichever side of 1 August you test

The trap is drift: studying old materials into September because "most of it carries over." Most of it does — but CAT exams probe your weakest areas by design, and an entirely absent topic like AI/ML governance is exactly the kind of gap the engine will find.

How to add the AI/ML material without starting over

If you've already built CCSP knowledge, the new content layers onto frames you have:

  1. Shared responsibility, extended. Ask of every AI service what you ask of every cloud service: who secures the model, who secures the training data, who is accountable for outputs? The reasoning pattern is identical; only the asset type is new.
  2. Data lifecycle, applied to datasets and models. Create–store–use–share–archive–destroy applies to training data and model artifacts as cleanly as to customer records. Classification, encryption and access control questions about models are lifecycle questions wearing new clothes.
  3. Governance instincts transfer. AI regulatory requirements slot into the same Domain 6 muscles you use for privacy law: identify the jurisdiction, identify the accountable party, evidence the control.

The practical takeaway

The August 2026 refresh is evolution, not upheaval: same domains, same CAT format, same pass mark — with the body of knowledge catching up to the AI-shaped reality of cloud operations. Confirm your test date's side of the line, study from the matching official outline, and treat the AI/ML sections as first-class material rather than an appendix. Candidates who do that will find the "new" exam tests the same thing the old one did: whether you can reason about responsibility, data and risk in someone else's infrastructure.

Put it into practice.

700+ exam-weighted questions, every one with a rationale. Your first practice exam is free.

Start free