Skip to main content

CCAK Certificate of Cloud Auditing Knowledge.

CCAK is the joint ISACA / Cloud Security Alliance credential for cloud auditors. Covers cloud governance, CCM, the STAR programme and hyperscaler-specific audit considerations. The natural extension for a CISA-holder whose scope went cloud-first.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyCertifications & credentialsAll entries

The Cyber Academy take

CCAK is the joint ISACA / Cloud Security Alliance credential for cloud auditors. Covers cloud governance, CCM, the STAR programme and hyperscaler-specific audit considerations. The natural extension for a CISA-holder whose scope went cloud-first.

What CCAK actually certifies

The Certificate of Cloud Auditing Knowledge is a joint credential from ISACA and the Cloud Security Alliance, and it answers a specific gap. Traditional IT audit training assumes you can walk the data centre, inspect the change tickets, and test controls the organisation owns end to end. In the cloud, that assumption breaks. The provider runs the physical infrastructure, the hypervisor, and large parts of the platform, and you never see them. CCAK is built around how you audit and assure that arrangement: how control responsibility is split between customer and provider, what evidence you can actually obtain, and how to reason about assurance when you cannot perform the test yourself.

It is a knowledge certificate rather than an experience-gated certification, so there is no multi-year work requirement attached the way there is with CISA. That makes it accessible earlier in a career, but it is positioned as a complement to deeper audit credentials rather than a replacement. The natural reader is someone who already understands audit method and now needs the cloud-specific layer on top.

What the body of knowledge covers

CCAK is anchored to CSA's own tooling rather than to a single provider's documentation, which is what keeps it vendor-neutral. The core reference points practitioners learn to work with include:

  • The Cloud Controls Matrix (CCM), CSA's control framework mapped across cloud domains and cross-referenced to standards such as ISO 27001 and the major regulatory regimes. It is the control catalogue you assess a cloud environment against.
  • The Consensus Assessments Initiative Questionnaire (CAIQ), the standardised set of questions a customer puts to a provider to understand which CCM controls the provider operates and how.
  • The STAR programme (Security, Trust, Assurance and Risk), CSA's assurance registry. STAR has tiers ranging from provider self-assessment through third-party certification, and CCAK teaches you to read what each tier does and does not prove.
  • Shared responsibility, control allocation, and provider-specific audit considerations across the main hyperscalers, so you know which controls you test, which the provider attests to, and where the seam between them sits.

Where CCAK sits next to CISA and CCSP

Practitioners regularly confuse CCAK with the two credentials it lives between, so the distinction is worth drawing cleanly. CISA establishes that you can audit information systems at all. CCSP, from (ISC)2, is a broad cloud security design and architecture credential. CCAK is narrower and more specific than either: it is about assuring cloud, not building it and not auditing systems in general.

CCAK compared to neighbouring credentials
CredentialPrimary focusPosture
CCAKAuditing and assuring cloud environmentsCloud-specific, knowledge-based, vendor-neutral
CISAAuditing information systems generallyBroad audit method, experience-gated
CCSPDesigning and securing cloud architectureSecurity architecture, not audit-focused

In practice the strongest pairing is CISA plus CCAK. CISA gives the audit discipline, the evidence standards, and the independence mindset; CCAK supplies the cloud overlay so that a CISA-holder whose scope has gone cloud-first can assess shared-responsibility boundaries and read STAR evidence without relearning audit from scratch. That is the progression CCAK is designed to serve.

Frequently asked questions

01Is CCAK a substitute for CISA?

No. CISA establishes that you can audit information systems and carries an experience requirement. CCAK is a narrower knowledge certificate focused on cloud assurance and has no such gate. They are designed to be held together, with CISA as the audit foundation and CCAK as the cloud layer.

02Does CCAK require work experience?

No. CCAK is a knowledge certificate, so it does not impose the multi-year experience requirement that credentials like CISA do. That makes it reachable earlier, though it is most useful to someone who already understands audit method.

03What is the difference between CCAK and CSA STAR?

CCAK certifies a person's cloud-auditing knowledge. STAR is CSA's assurance programme for cloud services themselves, with tiers from self-assessment to third-party certification. CCAK teaches you to evaluate STAR; you are not awarded STAR.

04Is CCAK tied to one cloud provider?

No. CCAK is vendor-neutral. It is built on CSA frameworks such as the Cloud Controls Matrix and the CAIQ, and it covers provider-specific considerations across the major hyperscalers rather than certifying you on a single platform.

05How does CCAK differ from CCSP?

CCSP, from (ISC)2, is a broad credential for designing and securing cloud architecture. CCAK is about auditing and assuring cloud environments. One builds and secures the cloud, the other assesses it.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.