The CCSP exam is evolving to reflect how cloud is actually used in 2026 — and the biggest change is the addition of AI and machine-learning security. If you’re sitting CCSP under the updated outline, expect questions that go well beyond traditional cloud controls. Here’s what to know.
Why AI is now on the CCSP
Organizations run AI workloads on the same shared-responsibility cloud platforms CCSP already covers, so securing models, training data, and AI services is now core cloud security. The exam treats AI as another class of cloud asset with its own attack surface and governance needs.
The new topics to study
- GenAI/LLM security — prompt injection, insecure output handling, jailbreaks, and guardrails.
- Model & data attacks — training-data poisoning, model inversion, membership inference, and model extraction.
- RAG & data privacy — protecting the data that flows into retrieval-augmented generation and prompts (PII leakage).
- AI-as-a-Service shared responsibility — who secures what when you consume a managed model.
- AI governance — the NIST AI Risk Management Framework (Govern/Map/Measure/Manage), ISO/IEC 42001 (AI management systems), and the EU AI Act risk tiers.
How to prepare
Blend the new AI material with the classic six domains — most AI questions map to data security, platform security, application security, and legal/risk. The fastest way to internalize the new content is repetition on exam-style AI questions with explanations, so the reasoning (why prompt injection is mitigated by treating retrieved content as untrusted, for example) sticks.