CCSP Exam Changes 2026: What's New in the Updated CBK
- #CCSP
- #Exam Changes
- #CBK
- #ISC2
- #2026 Update
Part of our CCSP Complete Guide series.
ISC2 periodically revises the CCSP Common Body of Knowledge (CBK) to reflect the evolving cloud security landscape. Candidates using outdated study materials risk encountering content on the exam that their preparation didn’t cover.
Here’s what’s changed in the CCSP curriculum for 2026 and what it means for your preparation.
How CCSP Updates Work
ISC2 conducts job task analyses — industry surveys of practicing cloud security professionals — to ensure the CCSP exam reflects what professionals actually do. CBK updates follow these surveys and are implemented with several months’ notice to allow study material publishers to update.
Significant CBK updates typically affect:
- Domain weight percentages (which domains are more heavily tested)
- New topic additions within existing domains
- Removal or de-emphasis of outdated content
- Updates to framework references (new NIST publications, updated ISO standards)
Always verify the current exam outline on ISC2’s website before purchasing study materials, as this article reflects the state as of 2026 and the CBK may continue to evolve.
2026 Domain Weights
| Domain | 2026 Weight | 2024 Weight (approx.) |
|---|---|---|
| 1: Cloud Concepts, Architecture and Design | 17% | 17% |
| 2: Cloud Data Security | 20% | 19% |
| 3: Cloud Platform and Infrastructure Security | 17% | 18% |
| 4: Cloud Application Security | 17% | 17% |
| 5: Cloud Security Operations | 16% | 17% |
| 6: Legal, Risk and Compliance | 13% | 12% |
Domain 2 (Cloud Data Security) has increased emphasis, reflecting the growing complexity of data management across multi-cloud environments, AI/ML training data, and data sovereignty requirements. Domain 6 weight has also increased slightly, reflecting expanded regulatory requirements globally.
New and Expanded Topic Areas
Artificial Intelligence and Machine Learning Security
This is the most significant new content area. The 2026 CBK incorporates security considerations specific to AI/ML workloads in cloud environments:
- Training data security: Access controls, data poisoning attack prevention, and provenance tracking for ML training datasets
- Model security: Protecting trained models from extraction attacks, adversarial inputs, and unauthorized inference
- AI governance: Risk assessment frameworks for AI systems, audit and accountability requirements, and compliance with emerging AI regulations (EU AI Act, NIST AI RMF)
- LLM security: Prompt injection, data leakage through model outputs, and security controls for large language model deployments
- MLOps security: Securing ML pipelines from data ingestion through model deployment, including CI/CD integration
This content falls primarily in Domains 2 (data security for training datasets) and 4 (application security for AI/ML deployments), with governance aspects in Domain 6.
Container and Serverless Security
Expanded significantly from prior CBK versions:
- Container security: Image scanning, runtime protection, container image signing and verification, registry security, and Kubernetes-specific controls (admission controllers, network policies, pod security standards)
- Serverless security: Function-level access control, cold start security implications, event-driven architecture security, and permissions management for serverless functions
- Infrastructure as Code (IaC) security: Terraform and CloudFormation security scanning, policy-as-code implementation, and drift detection
Container security content appears primarily in Domain 3 (Platform/Infrastructure Security).
Zero Trust Architecture
Zero trust has been formalized as a distinct topic area rather than a principle referenced across domains:
- Identity-centric access control: ZTNA (Zero Trust Network Access) implementation, continuous authentication, and risk-based access decisions
- Micro-segmentation: Software-defined perimeter design and implementation in cloud environments
- SASE (Secure Access Service Edge): Integration of network and security functions in cloud-delivered services
- Zero trust maturity model: CISA’s Zero Trust Maturity Model and its application to cloud environments
Zero trust content spans Domains 1, 3, and 5.
Supply Chain Security
Expanded following major supply chain incidents:
- Software Bill of Materials (SBOM): Mandatory SBOM generation, management, and vulnerability tracking
- Third-party risk management: Cloud service provider risk assessment, contractual security requirements, and continuous monitoring
- Open source security: Dependency scanning, license compliance, and secure package management in cloud application development
- Build pipeline security: CI/CD security controls, signed commits, and build environment integrity
Supply chain content is primarily in Domain 4 (Application Security).
Updated Regulatory Content
Domain 6 has expanded regulatory references:
- EU AI Act: Risk classification and compliance requirements for AI systems deployed in cloud
- NIS2 Directive: Updated EU cybersecurity requirements affecting cloud services and critical infrastructure
- DORA (Digital Operational Resilience Act): Financial sector cloud resilience requirements
- Updated NIST frameworks: NIST SP 800-207 (Zero Trust Architecture), NIST AI RMF, and updates to the Cybersecurity Framework
What This Means for Your Study Plan
If your materials are from 2023 or earlier:
Update or supplement before your exam. The AI/ML security and zero trust content in particular will appear on questions, and older study guides won’t cover them adequately. Supplementing a core course with current ISC2 resources or a recently updated Udemy course is more efficient than replacing all materials.
If your materials are from 2024 or 2025:
Check the ISC2 website for the current exam outline and confirm your materials cover the AI/ML and container security updates. Most 2024-2025 resources incorporated the major changes but may lack the most recent updates.
For all candidates:
Review the current ISC2 CCSP exam outline on the ISC2 website as part of your preparation. It lists the current CBK domains, topic areas, and weight percentages. The official outline is the authoritative source; any study material is an interpretation of it.
Stable Content (No Major Changes)
These areas have not changed significantly and continue to be heavily tested:
- Cloud data lifecycle management (Domain 2)
- Key management: BYOK, HYOK, CSP-managed (Domain 2)
- Jurisdiction and cross-border data transfer (Domain 6)
- CLOUD Act and legal frameworks (Domain 6)
- SOC 2, ISO 27001, CSA STAR compliance (Domain 6)
- Shared responsibility model (Domain 1)
- Incident response procedures in cloud (Domain 5)
Core governance and risk management concepts remain stable. The updates are additions to reflect new technology and regulatory developments, not replacements of foundational content.
Next: CCSP and AI/ML Security: 2026 Domain Focus | CCSP Salary in 2026
FAQ
Has the CCSP exam changed in 2026?
Yes. ISC2 periodically updates the CCSP Common Body of Knowledge (CBK) to reflect evolving cloud security practices. The 2026 curriculum places increased emphasis on AI/ML security, container and serverless security, zero trust architecture, and supply chain security. Verify current domain weights on the ISC2 website before purchasing study materials.
When was the CCSP CBK last updated?
ISC2 updates the CCSP CBK approximately every 3-4 years, with minor updates in between. The most recent major update incorporated AI/ML security content and expanded coverage of container, serverless, and zero trust topics. Always check the official ISC2 CCSP exam outline for the current version.
Do I need to re-study if I'm using older CCSP materials?
If your study materials are from before 2024, you should update your preparation to include AI/ML security, container security, serverless security, zero trust architecture, and expanded supply chain security content. Domain weights and topic emphasis may have shifted. ISC2 publishes the current exam outline on their website.
About the authors
Sekiko Jo
CISSP and CCSP-certified security specialist focused on cloud threat modeling and security governance. A Registered Information Security Specialist (情報処理安全確保支援士) in Japan, she writes from hands-on incident-response experience.
Registered Information Security Specialist (情報処理安全確保支援士), Japan