VERGLEICHE
CCSP or CCSK? Two Rungs of the Same Ladder
The two best-known vendor-neutral cloud security credentials compete less than their names suggest: on one side a knowledge certificate with no entry requirement and no expiry date, on the other the comprehensive personnel certification with an experience requirement and a maintenance regime. The comparison, with the numbers and the ladder logic behind it.
By Daniel Thomas HeesselLast updated: August 12, 20266 min read
"CCSP or CCSK" is the question asked by cloud and security professionals looking for a vendor-neutral credential in cloud security. The honest answer: the two are less often competitors than the question implies. One is a knowledge-level entry point, the other a professional credential, and the two providers have even formally linked the ladder.
The names themselves reveal the difference if you look closely: the CCSK is a "Certificate of Knowledge", a knowledge certificate. The CCSP is an accredited personnel certification with an experience requirement. What fundamentally separates the two is explained in our foundational article on personnel certification; what matters here is what it means in practice.
What the two stand for
The CCSP (Certified Cloud Security Professional) from ISC2 covers all six domains of cloud security, from architecture and design to legal and compliance. It is explicitly aimed at experienced professionals: five years of IT experience are an admission requirement, and since October 2025 the exam runs in an adaptive CAT format. Since August 1, 2026, a revised exam outline with recalibrated domain weights applies; the six domains and the adaptive format remain unchanged.
The CSA CCSK (Certificate of Cloud Security Knowledge) from the Cloud Security Alliance is one of the most widespread vendor-neutral cloud security certificates. Since version 5 it has been based on the CSA Security Guidance and the Cloud Controls Matrix, requires no professional experience whatsoever, and is taken entirely online as an open-book exam. Once passed, it never expires.
The numbers in direct comparison
| Provider | ISC2 | Cloud Security Alliance |
|---|---|---|
| Acquisition cost (exam, EUR) | €551 | €363 |
| Total cost over 5 years (EUR)i | €13,172 | €363 |
| Prerequisites | 5 years IT experience, including 3 years in IT security and 1 year in cloud security. Active CISSP replaces all experience requirements. | None |
| Exam format | CAT-based, 125–150 questions, 3 hours, proctored via Pearson VUE. Passing score: 700/1000. | Online, open-book, 60 questions, 90 minutes, 80% passing score |
| Validity | 3 years | |
| CPE effort | 30 hrs/year | 0 |
| CertMap scoreHow we score → | 11 / 12Market strength 6/6 Substance5/6 | 4 / 12Market strength 4/6 Substance0/6 |
Values live from the CertMap cost methodology (USD fees converted to EUR, totals include annual fees, recertification and CPE time value). Same data basis as the comparison tool.
Two patterns stand out in the table, and they make the ladder logic visible:
- The cost profiles are opposites. The CCSK is paid for once and free of follow-up costs after that: no annual fee, no continuing-education obligation, no expiry date. The flip side: it documents the state of knowledge at exam time, and there is no currency requirement. The CCSP inverts this: an annual fee (which covers all of a person's ISC2 certifications together) and ongoing continuing education keep the profile current, but over the years cost a multiple of the acquisition price. How CertMap calculates such lifetime costs is explained in the cost methodology.
- Admission and exam format mark the target audiences. The CCSK is open to everyone and is tested online, open-book; the bar is deliberately low. The CCSP requires five years of professional experience (an active CISSP substitutes for the entire requirement, according to ISC2), is proctored at a test center, and is also available in German; the CCSK is available only in English.
And the two providers have formally linked the ladder: according to ISC2, a passed CCSK substitutes for one year of the professional experience required for the CCSP. Starting with the CCSK therefore shortens the path to the larger certification.
Not competitors, but rungs. The CCSK documents cloud security knowledge, the CCSP a cloud security profession, and the lower rung formally counts toward the upper one.
Requirements: open door versus experience requirement
The admission models could hardly be further apart:
- CCSP: Five years of IT experience, three of them in IT security and one in cloud security. An active CISSP substitutes for the entire experience requirement, a passed CCSK, according to ISC2, for the cloud year.
- CCSK: No requirements. The certificate is explicitly designed as an entry point, including for people from adjacent roles such as architecture, GRC, or data protection.
In practice this means: for many, the CCSP is the goal and the CCSK the first step toward it.
The exams
The CCSK exam is built to be low-threshold: 60 questions in 90 minutes, online and open-book, passing threshold 80 percent, in English. The CCSP exam is a different league: an adaptive CAT format with 125 to 150 questions in three hours, proctored via Pearson VUE, passing threshold 700 out of 1,000 points, available in several languages including German. The CCSK's open-book format lowers the bar, but it also means a weaker proof of performance than a proctored exam with an experience requirement.
Our assessment
What our rating says: The gap in the CertMap rating is the largest in the comparison series so far, and it is not an accident but by design: the CCSP, with full market strength and high substance, belongs to the top group of the catalog, while the CCSK, as a pure knowledge certificate without practical proof, without a maintenance regime, and without accreditation, is deliberately built lean. Our rating measures quality as a professional credential, not usefulness as a learning step; as an entry point, the CCSK serves its purpose. How the rating axes are constructed is explained in the rating methodology.
The decision becomes simple once you frame it as a question of rungs:
- If you are entering cloud security, want to document foundational knowledge, or come from an adjacent role, start with the CCSK: inexpensive, no entry barrier, no follow-up costs.
- If you are an experienced professional aiming for architecture, consulting, or leadership roles in cloud security, you need the CCSP: it is the credential that employers in this segment know and demand.
- The sequence is the normal case: first the CCSK as an entry point and experience building block, then the CCSP once the years of professional experience add up. If you already hold an active CISSP, you can skip the detour and go straight to the CCSP.
Frequently asked questions
Does the CCSK substitute for professional experience toward the CCSP?
Yes. According to ISC2, a passed CCSK substitutes for one year of the required experience, specifically the cloud security year. An active CISSP even substitutes for the entire experience requirement. The two credentials are thus formally linked rungs, not competitors.
Does the CCSK expire?
No. The CCSK has no expiry date and no follow-up costs, neither an annual fee nor a continuing-education obligation. The flip side: it documents the state of knowledge at exam time. The CCSP, by contrast, requires ongoing continuing education and thus remains a maintained, current profile.
Are the exams available in German?
The CCSP, yes: it is offered in several languages including German. The CCSK is available only in English.
Read next:CISSP or CISM? Two Careers, One Decision →Certification vs. Certificate: What's the Difference? →