- Identity Check: Which CSSD This Is
- The Exam at a Glance
- Domain Weights on One Page
- Develop Secure Code (33%): The Heavy Hitter
- Secure SDLC (22%): Where Security Gets Built In
- Fundamentals, Defense, and Governance (15% Each)
- Newer Topics: AI-Generated Code and Supply Chain
- Cost, Registration, and Renewal Facts
- A Domain-Ordered Review Sequence
- Who Benefits From This Credential
- Frequently Asked Questions
- CSSD means Cyber Secure Software Developer, issued by CertNexus; the current exam is CSD-110, launched May 11, 2026.
- The exam has 25 multiple-choice/multiple-response questions, and you need 80% (20 of 25) to pass.
- Develop Secure Code is the largest domain at 33%, followed by the secure SDLC at 22%.
- Delivery is online through CHOICE, with one complimentary retake and no formal registration prerequisites.
Identity Check: Which CSSD This Is
The acronym CSSD is shared by several unrelated credentials, so a cheat sheet is only useful if it is about the right one. On this site, CSSD means Cyber Secure Software Developer, a CertNexus credential aimed at people who design, write, test, and ship software. If you are unsure how the name breaks down, the explainers at What Does CSSD Stand For? and What Is CSSD Certification? cover the basics.
One more distinction matters. CertNexus's courseware for CSD-110 replaces its earlier Cyber Secure Coder CSC-210 courseware. They are separate exams with separate blueprints, so do not mix study materials between them. Also, some product descriptions mention "CSD-210"; that conflicts with the issuer's own CSD-110 exam title and blueprint, so treat CSD-110 as the exam you are preparing for.
The Exam at a Glance
Here is the one-glance version of the assessment mechanics. These are the facts worth memorizing before anything else.
| Item | What to Know |
|---|---|
| Issuer | CertNexus |
| Current exam | CSD-110 (launched May 11, 2026) |
| Delivery | Online through CHOICE |
| Format | 25 multiple-choice and multiple-response questions |
| Passing score | 80% (20 of 25) |
| Estimated completion time | 30-60 minutes (an estimate, not a verified fixed exam timer) |
| Retake | One complimentary retake |
| Prerequisites | None formally required; foundational security knowledge and software development experience recommended |
The format has a practical consequence. With only 25 questions and an 80% bar, you can miss just five. Every question carries roughly four percentage points, so a single weak domain can sink an attempt. For a deeper look at the scoring math, see CSSD Passing Score 2026: Exactly What You Need to Pass.
Domain Weights on One Page
The five domains below come from the official CSD-110 blueprint (version 1.12, issued December 15, 2024 and modified June 1, 2026). Weights tell you where the questions concentrate, so they should drive where your hours go.
| Domain | Weight |
|---|---|
| 1. Understand the Fundamentals of Secure Software Development | 15% |
| 2. Explain the Secure Software Development Lifecycle | 22% |
| 3. Develop Secure Code | 33% |
| 4. Defending Against Cyberattacks | 15% |
| 5. Engage in Governance, Risk Management, and Compliance | 15% |
Note that Domains 2 and 3 together account for 55% of the exam. If you only have limited time, that is where it should go first. For a full breakdown of each content area, read CSSD Exam Domains 2026: Complete Guide to All 5 Content Areas.
Develop Secure Code (33%): The Heavy Hitter
This is the domain where a developer's hands-on instincts meet exam wording. The blueprint's supported topics point to the concrete coding defenses you should be able to recognize and apply in scenario questions.
Domain 3: Develop Secure Code
Expect scenario-style questions where you pick the control that prevents a specific class of flaw.
- Input validation: validate on the server side, prefer allow-lists over block-lists, and treat all external data as untrusted.
- Output encoding: encode data for its destination context (HTML, attribute, URL, script) to defuse injection and cross-site scripting.
- Authentication: proving identity, including how credentials and sessions should be handled.
- Authorization: enforcing what an authenticated identity may do, applied on every request rather than only at the front door.
- Secrets management: keep credentials, keys, and tokens out of source code and repositories; use proper storage and rotation.
- Dependency security: third-party components inherit risk into your application.
A reliable way to think about this domain: for each vulnerability class, know the root cause and the primary control. Injection comes from mixing untrusted data with commands, and the control is validation plus safe interfaces and encoding. Broken access comes from missing or inconsistent checks, and the control is consistent server-side authorization. The exam rewards matching the right control to the right flaw rather than listing every possible defense.
Key Takeaway
Distinguish authentication from authorization and validation from encoding. These four terms are easy to blur under time pressure, and answer choices are often built around exactly that confusion.
The difficulty of this material depends heavily on your background. If you are weighing how demanding it will feel, How Hard Is the CSSD Exam? Complete Difficulty Guide 2026 covers what to expect.
Secure SDLC (22%): Where Security Gets Built In
Domain 2 asks you to explain how security is woven through the whole development lifecycle instead of bolted on at the end. The key idea is "shifting left": finding and fixing issues earlier, when they are cheaper to correct.
Threat Modeling and Abuse Cases
Threat modeling is a structured way to ask what can go wrong before code exists. Abuse cases flip the usual use-case mindset: instead of describing how a legitimate user achieves a goal, you describe how an attacker might misuse the same feature. Expect questions about when in the lifecycle these activities belong (early, during design and requirements) and what they produce.
Testing Tools: SAST, DAST, IAST, SCA
The four acronyms below appear in the blueprint's supported topics, and a classic exam move is asking which tool fits a given situation.
| Technique | What It Examines | Memory Hook |
|---|---|---|
| SAST | Source or compiled code without running it | Static: code at rest |
| DAST | A running application from the outside | Dynamic: black-box attacker view |
| IAST | A running application with instrumentation inside it | Interactive: combines both viewpoints |
| SCA | Third-party and open-source components and their known vulnerabilities | Composition: what you pulled in |
Secure CI/CD
Pipelines are themselves an attack surface. Know that securing CI/CD means protecting build systems, controlling who can change pipeline definitions, managing secrets used by builds, and embedding automated security checks as gates so that insecure code is caught before deployment.
Fundamentals, Defense, and Governance (15% Each)
These three domains share equal weight and are often underestimated. Together they make up 45% of the exam, so neglecting them is a common route to falling short of 80%.
Domain 1: Understand the Fundamentals of Secure Software Development (15%)
The vocabulary and principles that every later domain builds on.
- CIA triad: confidentiality, integrity, availability. Be able to map a scenario to which property is at risk.
- AAA: authentication, authorization, and accounting (auditing); know what each contributes.
- Least privilege: grant only the access needed for the task, and no more.
Domain 4: Defending Against Cyberattacks (15%)
Recognizing attack patterns and selecting defensive responses at the application level.
- Connect common attack types to the secure-coding control that blunts them.
- Think in layers: no single control should be the only thing standing between an attacker and the data.
- Understand how your supply chain and dependencies can become the entry point.
Domain 5: Engage in Governance, Risk Management, and Compliance (15%)
The organizational side of secure development: policy, risk decisions, and regulatory obligations.
- Know that risk is managed through decisions (mitigate, transfer, accept, avoid) rather than only eliminated.
- Understand how policies and standards shape what developers must do.
- Recognize why documentation and evidence matter for compliance.
Developers sometimes skim Domain 5 because it feels less technical. Resist that. Questions here tend to be conceptual and answerable with clear vocabulary, which makes them some of the most efficient points to secure. The CSSD Study Guide 2026: How to Pass on Your First Attempt explains how to balance technical and governance preparation.
Newer Topics: AI-Generated Code and Supply Chain
Two topics distinguish CSD-110 from older secure-coding credentials: AI-generated code review and software supply chain security. Both reflect how modern software is actually built.
Reviewing AI-Generated Code
The core principle is that AI-produced code deserves the same scrutiny as code from any other contributor, and often more. It can look polished while embedding insecure patterns such as weak validation, hard-coded secrets, or outdated dependency choices. The right habit is to run it through the same review, SAST, and testing processes as everything else, and never to assume correctness because it compiled or "looks right."
Software Supply Chain Security
Your application is only as trustworthy as the components and build processes behind it. Key ideas to know:
- Dependencies bring inherited vulnerabilities, which is why SCA exists.
- Build and delivery pipelines must be protected from tampering.
- Knowing exactly what components are in your software supports faster response when a vulnerability is disclosed.
Cost, Registration, and Renewal Facts
Money and logistics questions come up constantly, so here is what the published facts actually support, and what they do not.
Pricing: Read the Fine Print
The published student digital course-bundle prices are USD 514.50 without lab and USD 561.75 with lab. These are courseware-bundle prices, not separately verified exam-only fees. The course access key includes the CHOICE credential process, which is why the bundle matters for how you sit the exam. For the full picture, see CSSD Certification Cost 2026: Complete Pricing Breakdown.
Registration and Eligibility
There are no formal registration prerequisites, application fee, supporting documentation, or eligibility verification. CertNexus recommends foundational security knowledge plus experience across software development, design, testing, and deployment, without prescribing a particular programming language. Details are in CSSD Requirements 2026: Eligibility, Prerequisites & How to Qualify, and scheduling context is in CSSD Exam Dates 2026: Testing Windows, Deadlines & Scheduling.
Validity and Renewal
CertNexus's general maintenance policy states three-year certification validity, with renewal by passing the current exam and continuing education available to eligible holders. The policy page does not establish CSSD-specific continuing-education eligibility or requirements, so check with CertNexus before planning around it rather than assuming rules from another credential.
A Domain-Ordered Review Sequence
Rather than a generic schedule, order your review by weight and dependency. Fundamentals first, because every other domain uses its vocabulary; then the two heavy domains; then the 15% domains that fill the gaps.
Fundamentals (Domain 1)
- Lock down CIA, AAA, and least privilege with your own examples.
- Start a one-page glossary of terms you confuse.
Secure SDLC (Domain 2)
- Practice threat modeling and writing abuse cases for a sample feature.
- Memorize the SAST/DAST/IAST/SCA distinctions and secure CI/CD concepts.
Develop Secure Code (Domain 3)
- Spend the most time here: validation, encoding, authentication, authorization, secrets, and dependencies.
- Review AI-generated code samples for flaws.
Domains 4 and 5, then practice
- Map attacks to controls; learn risk-treatment vocabulary and compliance basics.
- Finish with timed practice sets on the CSSD practice test site and revisit missed topics.
Since one complimentary retake exists, treat your first full practice run as diagnostic rather than a verdict. Use results to identify which domain costs you points, then target it. For a data-informed view of outcomes, see CSSD Pass Rate 2026: What the Data Shows.
Who Benefits From This Credential
The Cyber Secure Software Developer credential speaks to people whose daily work touches code and its delivery: application developers, engineers working in design, testing, and deployment, and teams that need a shared baseline in secure development practices. Employers building software, and organizations that depend on the software they buy or commission, value developers who can demonstrate that baseline. The credential is positioned as foundational, so it can also help early-career developers show security awareness.
Be careful with career expectations. This article does not cite salary or hiring figures because none are established in the verified facts. For analysis of career outcomes, see CSSD Salary Guide 2026: Complete Earnings Analysis, CSSD Jobs, and Is the CSSD Certification Worth It? Complete ROI Analysis 2026. Ready to test yourself against the real format? Start with the free questions at the CSSD Exam Prep practice tests.
Key Takeaway
Print or copy the weights table, the SAST/DAST/IAST/SCA table, and your own confusable-terms glossary. Those three items cover the highest-leverage facts for a 25-question exam where five misses is your limit.
Frequently Asked Questions
CSSD stands for Cyber Secure Software Developer, a CertNexus credential. The current exam is CSD-110, launched May 11, 2026. Other credentials share the acronym, so make sure any study material you use is specifically for this one.
The assessment has 25 multiple-choice and multiple-response questions, and the passing score is 80%, which means 20 of 25 correct. The 30-60 minute completion time is an estimate, not a verified fixed timer.
Develop Secure Code is the largest at 33%, followed by Explain the Secure Software Development Lifecycle at 22%. Together they make up 55% of the exam, so they deserve the most study time, while the three 15% domains still need solid coverage.
There are no formal registration prerequisites or application fees, though foundational security knowledge and software-development experience are recommended. Published student course-bundle prices are USD 514.50 without lab and USD 561.75 with lab; these are courseware prices, not verified exam-only fees.
One complimentary retake is included. CertNexus's general policy states three-year validity with renewal by passing the current exam, and continuing education is available to eligible holders, though CSSD-specific continuing-education requirements are not established by that policy page.