Get the Zoom link

Cloud Security Certifications Compared

The major cloud security certifications side-by-side. What each one is worth, who should take it, what it costs, and what comes next. Vendor-neutral guidance from practitioners.

· · Vendor-neutral · View source on GitHub

Quick guidance: Start with CCSK if you want a vendor-neutral foundation. Add a provider-specific cert (AWS, Azure, or GCP) for the cloud you actually work with. CCSP is the gold-standard senior credential - pursue it once you have a few years of cloud experience. CKS if Kubernetes is your day job. Don't pay for a bootcamp until you've tried the free official material.

On this page

  1. Side-by-side comparison
  2. Vendor-neutral certifications
  3. AWS-specific certifications
  4. Microsoft Azure certifications
  5. Google Cloud certifications
  6. Kubernetes security certifications
  7. Recommended paths by role
  8. FAQ

Side-by-side comparison

Prices, exam formats, and question counts all change, sometimes mid-year - confirm both the fee and the current exam format with the certifying body before you book a sitting.

Cert Issuer Vendor-neutral? Approx. cost (USD) Format Best for
CCSKCSAYes~$445 (2 attempts)Online, open-book, 120 minFoundation; first cert
CCSPISC2Yes~$599 + endorsementProctored, 3 hrs (CAT)Senior practitioners
AWS Security Specialty (SCS-C03)AWSNo (AWS)~$300Proctored, 170 minAWS-focused engineers
Microsoft SC-500MicrosoftNo (Azure)~$165Proctored, 120 minAzure security engineers
Microsoft SC-100MicrosoftNo (Microsoft)~$165ProctoredCybersecurity architects
Google PCSEGoogleNo (GCP)~$200Proctored, 2 hrsGCP security engineers
CKSCNCF / Linux FoundationYes (K8s)~$445Hands-on lab, 2 hrsKubernetes practitioners
GIAC GCSA / GCPNSANS / GIACMostly$$$$ProctoredEmployer-funded; deep technical

Vendor-neutral certifications

CCSK - Certificate of Cloud Security Knowledge (CSA)

The classic vendor-neutral starter cert. Open-book online exam against the CSA Security Guidance and ENISA Cloud Risk Assessment. Genuinely useful study material - the v5 guidance is a solid baseline for the field. Recommended as a first cert for almost everyone, including people who already work in security and need to formalize their cloud knowledge.

CCSP - Certified Cloud Security Professional (ISC2)

The senior-level vendor-neutral credential, often paired with CISSP. Six domains covering architecture, data security, platform/infrastructure, applications, operations, and legal/compliance. Requires five years of IT experience (three in security, one in cloud) - though one CSA cert can substitute for the cloud year.

AWS-specific certifications

AWS Certified Security - Specialty (SCS-C03)

The deepest AWS-focused security cert. Covers IAM, threat detection, infrastructure security, identity federation, data protection, and incident response. Now an associate-level prerequisite is no longer required, so anyone can take it cold - though SAA-C03 (Solutions Architect Associate) study makes it materially easier.

Microsoft Azure certifications

SC-500 - Microsoft Cloud and AI Security Engineer Associate

Implementation-focused: identity, access and governance (Entra, Key Vault, Azure Policy), storage, databases and networking, compute, and posture management in Defender for Cloud and Sentinel. Practical, hands-on flavor, 120 minutes, pass mark 700. The natural next step for anyone running Defender for Cloud, Sentinel, and Entra at work. The block that is genuinely new is securing AI workloads: Purview DSPM for Copilot risk, Entra Agent ID, and Defender for AI Services.

AZ-500 retired on 31 August 2026 and can no longer be earned or renewed. If you already hold it, it stays on your transcript as an active certification until it expires, then moves to the historical section. SC-500 has taken its place in the Microsoft security track: it covers the same Azure security engineer role with AI workload security added, and it now sits where AZ-500 used to in SC-100's prerequisite list.

SC-100 - Microsoft Cybersecurity Architect Expert

Design-focused, more senior. Zero-trust strategy, governance, regulatory compliance, infrastructure and data architecture. Requires you to already hold one of: SC-200, SC-300, or SC-500. Good for cybersecurity architects working in a Microsoft-heavy environment.

SC-200 / SC-300 / SC-401

Operational-tier certs - Defender/Sentinel operations (SC-200), Entra identity admin (SC-300), and information protection in Microsoft Purview (SC-401). Worth pursuing if those are your day job, but skippable if you're going straight to SC-500/SC-100. SC-400 and its Information Protection and Compliance Administrator certification retired on 31 May 2025; SC-401 replaced it as Information Security Administrator Associate, keeping information protection, DLP, retention and insider risk while dropping the compliance half.

Google Cloud certifications

Professional Cloud Security Engineer (PCSE)

Google's flagship security cert. Covers identity, data protection, network security, GCP Security Command Center, key management, and compliance. Two-year renewal cycle. Smaller community than AWS or Microsoft, but the cert itself is well-respected for GCP-specific roles.

Kubernetes security certifications

CKS - Certified Kubernetes Security Specialist

Hands-on lab exam - you SSH into a cluster and complete real tasks. Covers cluster hardening, system hardening, supply-chain security, runtime security, monitoring, and incident response. Requires a current CKA (Certified Kubernetes Administrator) to register. The CSOH Kubernetes & managed Kubernetes page covers the same topic areas at the depth the exam expects.

A student organizes notes and books in preparation for an exam
Photo by cottonbro studio on Pexels
Close-up of rolled diplomas tied with red ribbons on a wooden desk
Photo by Pavel Danilyuk on Pexels
Certifications get your résumé past the filter; the portfolio gets you the offer. - how to use this page

Recommended paths by role

Career switcher / new to cloud security

  1. CCSK (foundation, vendor-neutral)
  2. One associate cert in your target cloud (e.g., AWS Solutions Architect Associate)
  3. The provider security specialty (AWS Security Specialty, SC-500, or PCSE)
  4. CCSP after 3+ years of experience

Established security engineer adding cloud

  1. CCSK (fast on-ramp)
  2. Provider security specialty for whichever cloud you support
  3. CKS if you touch Kubernetes

Senior architect / consultant

  1. CCSP (signaling)
  2. SC-100 if Microsoft is in your portfolio
  3. Stay current via the provider specialty for your primary cloud

Detection / incident response specialist

  1. CCSK (foundation)
  2. SC-200 (Sentinel) or AWS Security Specialty
  3. GIAC GCSA or GCPN (employer-funded)

FAQ

Do certifications get you a job?

Not by themselves. They get you past resume filters and signal commitment. Pair every cert with hands-on work - labs, CTFs, side projects, write-ups. A CCSK plus a portfolio of CloudGoat write-ups is far more compelling than three certs and no lab work.

CCSK or CCSP first?

CCSK first, almost always. It's open-book, online, and prepares you for CCSP. Some people skip straight to CCSP if they already have years of cloud experience and just want the senior credential.

Are SANS / GIAC certifications worth the cost?

If your employer pays, yes - SANS courses are excellent. If you'd be paying out of pocket, the value-per-dollar is much better with CCSK + a provider specialty + practical lab work.

Do I need a cert for every cloud?

No. Pick the cloud you actually use. Most jobs are 80%+ one cloud. Cross-cloud knowledge from CCSK plus deep knowledge of one provider beats shallow knowledge of all three.

How current do these certs stay?

The provider specialties get refreshed every 1-3 years and the new versions matter (AWS replaced SCS-C02 with SCS-C03 in December 2025). CCSK gets revised when CSA publishes new guidance - v5 is the current generation. CCSP is the most stable.

Next steps

From the Friday sessions

This is not a settled topic. Here is where the CSOH community worked through it on the live Friday call:

Join the next Friday session to argue with us in real time, or browse all 111 recaps.