ISC2 CISSP vs ISC2 CCSP: The Waiver That Changes Everything
Facts last verified against official sources: 2026-07-06
The verdict
CISSP is the broad security-expert credential; CCSP is the cloud-security specialization ISC2 built to stack on top of it. An active CISSP does not just trim CCSP's five-year experience requirement, it erases the entire thing, the only full waiver ISC2 offers anywhere in its own lineup.
- Vendor
- ISC2
- Cost
- $749
- Exam format
- 100 to 150 questions (CAT), 3 hours, multiple-choice + advanced item types; pass scaled at 700/1000
- Renewal
- Valid 3 years; 120 CPE credits (90 minimum Group A) plus a mandatory $135/year Annual Maintenance Fee
- Associated occupation
- Information Security Analysts, $129,180 median
- Experience level
- Advanced
- Vendor
- ISC2
- Cost
- $599
- Exam format
- 100 to 150 questions (CAT, effective October 1, 2025; previously a fixed 125-question linear exam), 3 hours; pass scaled at 700/1000
- Renewal
- Valid 3 years; 90 CPE credits (60 minimum Group A, 20/year minimum) plus a mandatory $135/year Annual Maintenance Fee shared across all ISC2 certifications
- Associated occupation
- Information Security Analysts, $129,180 median
- Experience level
- Advanced
Salary figures are U.S. Bureau of Labor Statistics medians for the occupation shown, not a measured premium for holding this certification. No one publishes causal cert premiums; anyone quoting one is guessing.
CISSP and CCSP share a vendor, a scaled pass mark of 700 out of 1,000, and an Annual Maintenance Fee that does not add up the way you would expect. Where they split is scope: CISSP certifies broad expertise across eight security domains, while CCSP certifies deep expertise across six cloud-specific ones. The interesting relationship between them is not really “which one” so much as “in what order,” because ISC2 built a waiver into CCSP that rewards CISSP holders specifically.
The waiver that changes everything
CCSP’s own experience requirement is five years of cumulative, full-time, paid IT experience, with three of those years specifically in cybersecurity and at least one year touching one or more of CCSP’s six domains. Up to one of the five years can be waived through a relevant computer science or IT degree, or through the Cloud Security Alliance’s CCSK certificate, but only one of those substitutions applies, capped at a single year.
Here is the fact worth getting exactly right: an active CISSP substitutes for CCSP’s entire five-year experience requirement, not a portion of it. Pass the CCSP exam while holding CISSP, and ISC2 awards full certification immediately, no cloud-specific work history required at all. That is a materially different shape than the waiver on the sibling page comparing CISSP against CISM on this site: CISSP only trims two of CISM’s five required years, since CISM keeps a mandatory three-year management floor no waiver can touch. Put the two side by side and the difference is stark: CISSP waives 100 percent of CCSP’s five-year requirement (5 of 5 years), against 40 percent of CISM’s (2 of 5 years). Same issuing habit, same word “waiver,” two entirely different arithmetic outcomes.
Who needs CISSP first
CISSP is the credential for people whose work already spans multiple security domains: architecture, governance, operations, software security, rather than one cloud specialty. It costs $749, tests through a three-hour computerized adaptive exam running 100 to 150 questions across eight weighted domains, and requires five years of experience across at least two of those domains before ISC2 awards it (one year waivable through an approved degree or credential). The Annual Maintenance Fee is $135 a year starting immediately.
Who needs CCSP
CCSP targets architects, engineers, and consultants securing workloads across AWS, Azure, GCP, or multi-cloud environments specifically, not general security practitioners who occasionally touch a cloud console. It costs $599, and since October 1, 2025 it tests through the same computerized adaptive format CISSP uses, 100 to 150 questions over three hours, having moved off a fixed 125-question linear exam that older study material still describes. Six domains make up the content: Cloud Data Security carries the largest single weight at 20 percent, followed by Cloud Concepts, Architecture and Design, Cloud Platform and Infrastructure Security, and Cloud Application Security at 17 percent each, Cloud Security Operations at 16 percent, and Legal, Risk and Compliance at 13 percent.
The AMF that does not stack
Both certifications carry ISC2’s higher-tier $135 Annual Maintenance Fee, and it is tempting to assume holding both means paying $270 a year. It does not. ISC2 bills one combined AMF across every ISC2 certification you hold, billed on the earliest anniversary among them, so a CISSP holder who adds CCSP still pays $135 a year total. Over nine years that is $1,215 in AMF regardless of whether CISSP is your only ISC2 credential or one of several.
Renewal load differs slightly past the fee: CISSP requires 120 CPE credits per three-year cycle (90 minimum from Group A), while CCSP asks for 90 (60 minimum Group A, with a 20-per-year floor so the cycle cannot be crammed into its last months). CCSP’s CPE load is 75 percent of CISSP’s, a lighter ask on top of an identical fee.
The honest sequencing answer
For someone who already holds CISSP and is moving into cloud-focused work, CCSP is close to a formality: sit the exam, and certification lands immediately per ISC2’s own experience-requirement page, with no cloud-specific work history to document. That is a genuinely rare shortcut in this industry. The waiver only runs one direction, though; nothing in ISC2’s published rules lets CCSP experience substitute for any part of CISSP’s own five-year requirement, so going CCSP first buys you nothing toward CISSP later.
For someone with neither credential and cloud security as the clear target, CCSP alone is defensible without ever sitting CISSP. CCSP is not gated behind holding CISSP; the waiver only accelerates a path that exists independently, through the same five-year requirement (with its own degree or CCSK waiver) or through ISC2’s Associate of ISC2 path, which gives six years to accumulate experience after an early exam pass.
Common mistake
Assuming ISC2’s certifications waive each other’s experience requirements the same way is the error to avoid here. CCSP’s CISSP waiver is total. CISM’s is capped at two years with a hard three-year management floor beneath it. Check the specific waiver language on the credential you are stacking rather than assuming one ISC2 rule generalizes to the next.
General information, not career or financial advice
CertiGuard documents costs, exam mechanics, and public salary data. Whether a certification pays off for you depends on your market, employer, and experience. Treat this as a starting point, not a promise.
Official sources
- ISC2: CISSP certification overview (experience requirement, Associate path)
- ISC2: CCSP certification overview (5-year experience requirement)
- ISC2: CCSP experience requirements (degree/CCSK waiver, full CISSP substitution, Associate path)
- ISC2: Annual Maintenance Fee overview ($135/year, one combined fee across ISC2 certifications)
Cite this page