- What the Cyber Secure Software Developer Credential Is
- Exam Format: What 25 Questions Really Demand
- The Five Domains and Where the Points Live
- Inside the 33% Domain: Develop Secure Code
- The Secure SDLC Domain (22%)
- AI-Generated Code Review and Pipeline Security
- Access, Eligibility, and What You Actually Pay
- Who Benefits From This Credential
- A Domain-Weighted Study Sequence
- Validity and Renewal
- Frequently Asked Questions
- CSSD means Cyber Secure Software Developer, issued by CertNexus; the current exam is CSD-110, launched May 11, 2026.
- The exam has 25 multiple-choice/multiple-response questions, and you need 80% (20 of 25) to pass.
- Develop Secure Code is the heaviest domain at 33%; the secure software development lifecycle follows at 22%.
- No formal prerequisites or application fee exist, but software development, design, testing, and deployment experience is recommended.
What the Cyber Secure Software Developer Credential Is
The Cyber Secure Software Developer credential, abbreviated CSSD, is a CertNexus certification aimed at people who write, review, test, and ship software and want verifiable proof that they do it securely. The current exam is coded CSD-110 and launched on May 11, 2026. If you have seen other certifications that share the CSSD acronym, set them aside: this article covers only the CertNexus Cyber Secure Software Developer exam, and nothing here applies to any other credential with the same letters.
If you are still orienting yourself on the basics, the site has dedicated explainers on what CSSD certification is and what CSSD stands for. This guide goes a level deeper: how the exam is built, what it tests, how access works, and how to sequence your preparation around the blueprint.
One point of confusion deserves clearing up early. The publisher identifies CSD-110 courseware as replacing the earlier Cyber Secure Coder CSC-210 courseware. Those are separate exams with separate blueprints. If you find older study material labeled for CSC-210, treat it as a different product. Likewise, some product descriptions reference "CSD-210," which conflicts with the issuer's own CSD-110 title and blueprint; the issuer's naming is the one that matters.
Exam Format: What 25 Questions Really Demand
CSD-110 is delivered online through CertNexus's CHOICE platform. The assessment consists of 25 questions in multiple-choice and multiple-response formats. The passing score is 80%, which works out to 20 correct answers out of 25. CertNexus estimates completion time at 30 to 60 minutes, but treat that as a planning estimate rather than a verified fixed timer. One complimentary retake is included.
| Exam Element | CSD-110 Detail |
|---|---|
| Issuer | CertNexus |
| Launch | May 11, 2026 |
| Delivery | Online through CHOICE |
| Question count | 25 (multiple-choice and multiple-response) |
| Passing score | 80% (20 of 25) |
| Estimated completion time | 30 to 60 minutes (estimate, not a verified fixed timer) |
| Retake | One complimentary retake |
The short length is deceptive. With only 25 questions, each one carries 4% of your score, and the 80% threshold leaves room for just five misses. That has two practical consequences. First, there is little room to be weak in any area, because a handful of questions from a domain you skimmed can sink an attempt. Second, multiple-response items are unforgiving: selecting only some of the correct options, or adding one wrong option, typically means the item does not earn credit. Practice reading each stem for how many answers it wants.
For a deeper look at how demanding this format is in practice, see how hard the CSSD exam is and the breakdown of the CSSD passing score.
The Five Domains and Where the Points Live
The official weighting comes from CertNexus's Cyber Secure Software Developer (CSSD) Exam CSD-110 Blueprint, version 1.12, issued December 15, 2024 and modified June 1, 2026. The blueprint defines five domains:
| Domain | Weight |
|---|---|
| 1. Understand the Fundamentals of Secure Software Development | 15% |
| 2. Explain the Secure Software Development Lifecycle | 22% |
| 3. Develop Secure Code | 33% |
| 4. Defending Against Cyberattacks | 15% |
| 5. Engage in Governance, Risk Management, and Compliance | 15% |
Two domains, Develop Secure Code and the secure software development lifecycle, together account for 55% of the exam. That is the center of gravity. But the other three domains together make up the remaining 45%, which is far too much to ignore. For a domain-by-domain walkthrough, the complete guide to all five CSSD content areas expands on each.
Domain 1: Understand the Fundamentals of Secure Software Development (15%)
This domain establishes the vocabulary and mental models the rest of the exam builds on.
- The CIA triad: confidentiality, integrity, and availability, and how to recognize which property a scenario threatens
- AAA: authentication, authorization, and accounting as distinct functions
- Least privilege and why it shapes design decisions
Domain 4: Defending Against Cyberattacks (15%)
Expect scenario-style questions where you identify an attack pattern and choose the control that addresses it. This domain pairs naturally with the input and output handling covered in Domain 3, so studying them together reinforces both.
Domain 5: Engage in Governance, Risk Management, and Compliance (15%)
Developers often under-prepare here because it feels less like coding. Treat it as a first-class domain: governance and compliance questions are worth exactly as much as authentication questions on a per-item basis.
Inside the 33% Domain: Develop Secure Code
Develop Secure Code is the largest domain, and it is where the credential most clearly separates itself from a general security awareness certificate. The supported topics for the exam include input validation, output encoding, authentication, authorization, and secrets management. Each deserves hands-on familiarity rather than memorization.
Input validation and output encoding
These two are frequently confused, and the exam can exploit that. Input validation is about deciding what data your application will accept; output encoding is about making data safe for the context in which it is rendered or interpreted. Know why validating input alone does not eliminate injection risk, and be able to match an encoding approach to the output context in a scenario.
Authentication versus authorization
Authentication establishes who a caller is; authorization determines what that caller may do. Questions in this area often describe a flawed flow and ask you to identify which of the two failed. Pair this with least privilege from Domain 1: an authorization model that grants broad access by default violates it.
Secrets management
Know why credentials, tokens, and keys do not belong in source code, and be able to reason about better handling in a build and deployment context. This topic bridges Domain 3 and the pipeline material in the lifecycle domain.
Key Takeaway
Because a third of the exam lives in Develop Secure Code, practice by reading short code or design scenarios and naming the specific weakness and fix. Recognition speed matters more than definitions when you have roughly one to two minutes per question.
The Secure SDLC Domain (22%)
Explain the Secure Software Development Lifecycle is the second-largest domain. It covers how security is built into each phase of development rather than bolted on at the end. Supported topics include threat modeling and abuse cases, along with the testing approaches that verify security: SAST, DAST, IAST, and SCA.
Threat modeling and abuse cases
Abuse cases flip the usual requirements mindset: instead of asking what a legitimate user wants to do, you ask what a malicious one might attempt. Be prepared to distinguish a use case from an abuse case and to identify which lifecycle phase is the right place to surface each.
The testing alphabet
The four testing acronyms are easy to blur together under time pressure. A reliable way to separate them is by what they examine and when they run:
| Approach | What It Examines | Typical Question Angle |
|---|---|---|
| SAST | Source code without running it | Finding flaws early, before execution |
| DAST | A running application from the outside | Finding issues visible only at runtime |
| IAST | A running application with instrumentation inside | Combining runtime context with code-level insight |
| SCA | Third-party components and dependencies | Known-vulnerable libraries and license exposure |
Expect scenario questions asking which technique fits a stated situation. If you want a compact reference for this kind of distinction, the CSSD cheat sheet is useful for last-pass review.
AI-Generated Code Review and Pipeline Security
Two supported topics make this exam feel current rather than generic: AI-generated code review and software supply chain security.
Dependencies, CI/CD, and the supply chain
Dependency security, secure CI/CD, and software supply chain security connect the testing material (especially SCA) to how code actually reaches production. Be able to reason about where in a pipeline a control belongs, what a compromised dependency or build step could affect, and how secrets should be handled across stages. The blueprint's detailed examples are not an exhaustive list of everything that may be tested, so build understanding of the principles rather than only memorizing named items.
Access, Eligibility, and What You Actually Pay
Registration mechanics for CSD-110 are unusually light. There are no formal registration prerequisites, no application fee, no supporting documentation, and no eligibility verification. CertNexus does recommend foundational security knowledge plus experience in software development, design, testing, and deployment, without prescribing a particular programming language. That means you can approach the exam from whatever language stack you work in. See the CSSD requirements guide for more on qualifying.
On cost, the important distinction is between courseware and the exam itself. The course access key includes the CHOICE credential process. The published student digital course-bundle prices are:
| Bundle | Published Price (USD) | SKU |
|---|---|---|
| Digital course bundle without lab | 514.50 | CNX0022SEBU2 |
| Digital course bundle with lab | 561.75 | CNX0022SEBU |
These are courseware-bundle prices, not separately verified exam-only fees, so do not read them as "the exam costs $514.50." One quirk worth knowing: the listing for the first bundle is titled Student Digital Course Bundle even though its URL wording suggests otherwise. For a fuller treatment of budgeting, read the CSSD certification cost breakdown.
Who Benefits From This Credential
The natural audience is anyone whose daily work touches code: application developers, engineers who own build and deployment pipelines, testers who validate security behavior, and designers who make architectural decisions that determine how defensible a system will be. Because the exam spans design, development, testing, deployment, and governance, it also suits team leads who need a shared security vocabulary with their developers.
Employers who care about secure development practices, particularly organizations that build their own software, maintain internal platforms, or answer to compliance obligations, are the most likely to value it. The credential's signal is strongest when paired with demonstrable development experience, since the exam itself assumes you already build software. For role-oriented detail, see the CSSD jobs overview, and for pay questions the CSSD salary guide. If you are weighing the investment, the ROI analysis walks through the tradeoffs without relying on made-up numbers.
A Domain-Weighted Study Sequence
Generic study advice is plentiful; what matters here is allocating time according to the blueprint. The sequence below puts the heaviest and most interdependent material where it gets the most repetition. For a longer preparation framework, see the CSSD study guide.
Foundations (Domain 1)
- Lock in CIA, AAA, and least privilege so later domains make sense
- Take a short diagnostic to see where you start
Develop Secure Code (Domain 3, 33%)
- Work through input validation, output encoding, authentication, authorization, and secrets management
- Practice naming the weakness and the fix in short scenarios
Secure SDLC (Domain 2, 22%)
- Threat modeling, abuse cases, and SAST/DAST/IAST/SCA distinctions
- Review AI-generated code, CI/CD, and supply chain topics
Attacks and Governance (Domains 4 and 5)
- Pair attack patterns with the controls from Domain 3
- Give governance, risk, and compliance real study time
Mixed practice and review
- Take timed mixed sets on the CSSD practice test site
- Revisit every missed item and trace it back to a domain
Because you can only miss five questions, finish by running full-length mixed sessions, not isolated topic drills. Practice under realistic conditions on our practice tests and use the results to decide where your last week goes. The CSSD pass rate discussion explains why published figures should be treated cautiously.
Validity and Renewal
CertNexus's general maintenance policy states that certifications are valid for three years and are renewed by passing the current exam, with continuing education available to eligible holders. That policy page does not establish CSSD-specific continuing-education eligibility or requirements, so confirm the details directly with CertNexus rather than assuming rules from another credential apply. Plan on the three-year horizon, and keep your skills current, since the exam content reflects a fast-moving field. Scheduling specifics are covered in the CSSD exam dates guide.
Frequently Asked Questions
It stands for Cyber Secure Software Developer, a CertNexus credential. The current exam is CSD-110. See what CSSD stands for for more.
The exam has 25 multiple-choice and multiple-response questions. The passing score is 80%, meaning at least 20 of 25 correct. One complimentary retake is included.
Develop Secure Code is the largest at 33%, followed by Explain the Secure Software Development Lifecycle at 22%. The other three domains are 15% each.
No. There are no formal registration prerequisites and no prescribed language. CertNexus recommends foundational security knowledge and software-development, design, testing, and deployment experience.
CertNexus's general policy states three-year validity, with renewal by passing the current exam. Continuing education is available to eligible holders, but CSSD-specific requirements are not established on the policy page, so verify with CertNexus.