- Why CSSD Doesn't Run on a Fixed Calendar
- The CSD-110 Timeline: Blueprint, Launch, and Current Status
- How Scheduling Works Through CHOICE
- What You Won't Face: Application Deadlines and Eligibility Gates
- Exam Format and Realistic Time Planning
- Choosing Your Test Date Around the Blueprint
- A Backward-Planned Calendar Tied to the Domains
- Retakes, Validity, and Renewal Timing
- Budgeting: Course Bundles and the Access Key
- Frequently Asked Questions
- The current Cyber Secure Software Developer exam is CSD-110, launched May 11, 2026, and delivered online through CHOICE.
- There is no application fee, supporting documentation, or eligibility verification gating registration, so no application deadline applies.
- The exam has 25 questions, an 80% passing score (20 of 25), and a published 30-60 minute estimated completion time.
- One complimentary retake is included, and certification validity is three years under CertNexus's general maintenance policy.
Why CSSD Doesn't Run on a Fixed Calendar
If you searched for "CSSD exam dates 2026" expecting a table of quarterly testing windows with hard registration cutoffs, here is the most useful thing to know up front: the Cyber Secure Software Developer credential from CertNexus is not published as a fixed-calendar event. The exam is delivered online through CHOICE, CertNexus's credential delivery process, and the course access key includes that CHOICE credential process. That delivery model changes how you think about "dates." Instead of circling a single national exam day, you choose when you are ready and work through the credential process on your own schedule.
This guide is specifically about the Cyber Secure Software Developer credential and its current exam, CSD-110. It explains what is actually known about timing, what is not, and how to turn that flexibility into a disciplined plan rather than an open-ended "someday." If you are still orienting yourself, start with What Is CSSD Certification? for the credential overview, then come back here to plan your timeline.
The CSD-110 Timeline: Blueprint, Launch, and Current Status
The "dates" that genuinely matter for this credential are the milestones around the exam itself. Understanding them tells you which version of the exam you are preparing for and how current your study materials are.
| Milestone | Date / Detail |
|---|---|
| Blueprint version 1.12 issued | December 15, 2024 |
| Blueprint last modified | June 1, 2026 |
| Current exam CSD-110 launched | May 11, 2026 |
| Delivery method | Online through CHOICE |
| Sources last checked for this article | October 5, 2026 |
Notice the sequence: the blueprint was originally issued in late 2024 and then modified in June 2026, after the May 2026 launch of CSD-110. That means you should always work from the current version of the blueprint on the CertNexus site rather than a PDF someone saved earlier. The official source for assessment and launch details is the CertNexus Cyber Secure Software Developer page, and the blueprint itself is published as a PDF on the CertNexus site.
Don't confuse CSD-110 with its predecessor
The publisher identifies CSD-110 courseware as replacing the earlier Cyber Secure Coder CSC-210 courseware. These are distinct exams with distinct blueprints. If you find older study materials, forum threads, or product listings referencing the previous exam, do not assume the objectives line up. You may also see product-description text referring to "CSD-210"; that conflicts with the issuer's CSD-110 title and blueprint, so rely on CSD-110 as the exam you are preparing for.
How Scheduling Works Through CHOICE
Because delivery runs through CHOICE, scheduling is about when you begin and complete the credential process rather than when you show up at a test center. Here is what the verified facts support:
- Delivery: online, through CHOICE.
- Access: the course access key includes the CHOICE credential process, so your learning access and your credential attempt are connected.
- Format: 25 multiple-choice and multiple-response questions.
- Time guidance: an estimated 30-60 minutes to complete. This is an estimate, not a verified fixed exam timer.
That last point deserves emphasis. Do not build a plan around a specific hard stop unless CertNexus communicates one for your attempt. Instead, plan to sit the assessment in a quiet block of time where you can comfortably work through all 25 questions without interruption, and read the instructions presented at the start of your attempt carefully.
What You Won't Face: Application Deadlines and Eligibility Gates
Many certifications force you to apply, submit documentation, wait for approval, and then book within a window. The Cyber Secure Software Developer credential does not work that way. There are no formal registration prerequisites, no application fee, no supporting documentation requirements, and no eligibility verification step. In plain terms, there is no approval queue that could delay your date.
That does not mean preparation is optional. CertNexus recommends foundational security knowledge along with software development, design, testing, and deployment experience. Notably, no specific programming language is prescribed. The full picture of what is and is not required is covered in CSSD Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Key Takeaway
Because nothing gates your registration, the only real deadline is the one you set yourself. Pick a target date tied to domain readiness, not to an administrative cutoff that does not exist.
Exam Format and Realistic Time Planning
Short exams reward precision more than endurance. With 25 questions and an 80% passing score, you need 20 correct answers. The mix of multiple-choice and multiple-response questions matters: multiple-response items require you to identify every correct option, which is where partial understanding gets exposed. A deeper breakdown of the scoring threshold is in CSSD Passing Score 2026: Exactly What You Need to Pass.
| Exam Element | CSD-110 Detail |
|---|---|
| Number of questions | 25 |
| Question types | Multiple-choice and multiple-response |
| Passing score | 80% (20 of 25) |
| Estimated completion time | 30-60 minutes (estimate, not a verified fixed timer) |
| Delivery | Online via CHOICE |
| Retake | One complimentary retake |
Because the exam is short but the pass bar is high, a single weak domain can cost you the attempt. With so few questions, each miss is worth 4 percentage points. That is why your scheduling decision should hinge on readiness across all five domains, not on how many hours you have logged.
Choosing Your Test Date Around the Blueprint
The blueprint is the best scheduling tool you have, because it tells you where the points are. Here are the five official domains with their weights:
Domain 3: Develop Secure Code (33%)
The largest domain by a wide margin. Treat it as the gate for your test date.
- Input validation and output encoding
- Authentication and authorization implementation
- Secrets management
- Reviewing AI-generated code for security flaws
Domain 2: Explain the Secure Software Development Lifecycle (22%)
The second-heaviest domain, covering how security is built into each phase of delivery.
- Threat modeling and abuse cases
- SAST, DAST, IAST, and SCA testing approaches
- Secure CI/CD pipelines
Domains 1, 4, and 5 (15% each)
Together these make up 45% of the exam, which is far too much to neglect.
- Domain 1, Understand the Fundamentals of Secure Software Development: CIA, AAA, and least privilege
- Domain 4, Defending Against Cyberattacks: defensive practices, including dependency security and software supply chain security
- Domain 5, Engage in Governance, Risk Management, and Compliance: governance and risk concepts
Keep in mind that the blueprint's detailed examples are not an exhaustive list of everything that may be tested. Treat the topic lists as strong signals, not boundaries. For a full walkthrough of each content area, see CSSD Exam Domains 2026: Complete Guide to All 5 Content Areas.
A Backward-Planned Calendar Tied to the Domains
Since you set your own date, work backward from it. The sequence below is organized by domain weight and dependency rather than generic study habits. Adjust the pacing to your experience; a working developer with security exposure may compress it, while someone newer to security may stretch it.
Foundations first (Domain 1)
- Lock down CIA, AAA, and least privilege so later domains build on solid vocabulary
- Read the current blueprint end to end and note unfamiliar terms
Lifecycle and threat thinking (Domain 2)
- Work through threat modeling and abuse cases
- Learn where SAST, DAST, IAST, and SCA each fit in the pipeline
The big one: secure coding (Domain 3)
- Practice input validation, output encoding, authentication, authorization, and secrets management
- Review AI-generated code for security weaknesses
- Give this domain two weeks because it carries 33% of the exam
Defense and governance (Domains 4 and 5)
- Cover dependency security, secure CI/CD, and software supply chain security
- Review governance, risk management, and compliance concepts
Readiness check, then attempt
- Take practice questions across all five domains
- Book your attempt only when you can clear 80% consistently
For a fuller approach to building this out, the CSSD Study Guide 2026: How to Pass on Your First Attempt goes deeper on resources and sequencing, and the CSSD Cheat Sheet 2026: One-Page Review of Must-Know Facts is useful for a final-week skim. You can also test yourself on the CSSD practice test platform to see which domains still need work before you commit to a date.
Retakes, Validity, and Renewal Timing
Timing does not end at the first attempt. Two verified points shape how you plan around risk and longevity.
One complimentary retake
The credential includes one complimentary retake. That reduces the cost of a miss, but it is not a reason to attempt before you are ready. With 25 questions and a high threshold, the smarter move is to use any miss diagnostically: identify which domain dragged your score down, review it, and then use the retake with purpose. Specific retake waiting periods are not part of the verified facts here, so confirm any timing rules directly with CertNexus. Data on how often candidates succeed is discussed in CSSD Pass Rate 2026: What the Data Shows, and for a realistic sense of difficulty, read How Hard Is the CSSD Exam? Complete Difficulty Guide 2026.
Three-year validity
CertNexus's general maintenance policy states that certifications are valid for three years, with renewal by passing the current exam. Continuing education is available to eligible holders under the CertNexus continuing education program. However, that page does not establish CSSD-specific continuing-education eligibility or requirements, so do not assume a particular credit count or pathway applies to this credential. If you certify in 2026, the practical takeaway is to note your three-year mark and check the current policy well ahead of it.
Budgeting: Course Bundles and the Access Key
Your timeline and your budget are linked, because the course access key includes the CHOICE credential process. The published student digital course-bundle prices are:
| Bundle | Published Price (USD) | SKU |
|---|---|---|
| Student digital course bundle, without lab | 514.50 | CNX0022SEBU2 |
| Student digital course bundle, with lab | 561.75 | CNX0022SEBU |
These are courseware-bundle prices, not separately verified exam-only fees. One quirk worth knowing: the "without lab" listing is titled as a Student Digital Course Bundle even though its URL wording differs, so double-check what you are adding to your cart. The two listings are on the publisher's store, including the without-lab bundle and the with-lab bundle. Since the lab option adds hands-on practice, it is worth weighing if your Domain 3 coding experience is thin. For the full cost picture, see CSSD Certification Cost 2026: Complete Pricing Breakdown.
Once you have the credential, you may wonder about the career side. Is the CSSD Certification Worth It? Complete ROI Analysis 2026 weighs the investment, and CSSD Jobs covers the roles where secure development skills are in demand.
Frequently Asked Questions
The verified delivery model is online through CHOICE, not a published fixed calendar of testing windows. The exam you are preparing for, CSD-110, launched on May 11, 2026. Confirm any scheduling specifics with CertNexus and your course access key instructions.
No. The credential has no formal registration prerequisites, no application fee, no supporting documentation, and no eligibility verification. That means no approval step stands between you and your attempt.
The estimated completion time is 30-60 minutes for 25 multiple-choice and multiple-response questions. This is an estimate, not a verified fixed exam timer, so follow the instructions presented at the start of your attempt.
The credential includes one complimentary retake. You need 80% (20 of 25) to pass, so review the domain where you lost points before using it. Confirm any retake timing rules directly with CertNexus.
CertNexus's general maintenance policy states three-year validity, with renewal by passing the current exam. Continuing education is available to eligible holders, but CSSD-specific eligibility and requirements are not established by that page.
Setting your own date is a strength, not a loophole. Anchor it to the blueprint, give Develop Secure Code the time its 33% weight demands, and confirm everything time-sensitive against the CertNexus pages. For a broader foundation on the credential itself, see CSSD Certification, and when you are ready to gauge your readiness, try the CSSD practice tests.