- How the CSD-110 Blueprint Is Organized
- Domain Weights at a Glance
- Domain 1: Fundamentals of Secure Software Development (15%)
- Domain 2: The Secure Software Development Lifecycle (22%)
- Domain 3: Develop Secure Code (33%)
- Domain 4: Defending Against Cyberattacks (15%)
- Domain 5: Governance, Risk Management, and Compliance (15%)
- What the Domains Look Like on Exam Day
- Sequencing Your Preparation by Domain
- Where These Domains Show Up in Real Roles
- Frequently Asked Questions
- The CSD-110 exam covers five weighted domains defined in CertNexus's blueprint version 1.12, modified June 1, 2026.
- Develop Secure Code carries 33%, the largest share, so code-level skills deserve the biggest slice of your study time.
- The secure software development lifecycle domain adds another 22%, bringing Domains 2 and 3 to 55% combined.
- The exam has 25 questions and an 80% passing score, meaning you need 20 correct answers.
How the CSD-110 Blueprint Is Organized
The Cyber Secure Software Developer (CSSD) credential from CertNexus is tied to exam CSD-110, which launched on May 11, 2026. Every question on the exam maps back to one of five weighted domains in the official Cyber Secure Software Developer (CSSD) Exam CSD-110 Blueprint, version 1.12. The blueprint was issued December 15, 2024 and modified June 1, 2026, so make sure any study material you use reflects the current revision.
One point of caution: the publisher identifies CSD-110 courseware as replacing the older Cyber Secure Coder CSC-210 courseware. These are distinct exams with distinct blueprints. If you find old forum posts or notes about CSC-210, treat them as a different exam rather than a source for CSD-110 domain content. You may also see references to "CSD-210" in some product descriptions; the issuer's own title and blueprint use CSD-110, and that is the exam this guide covers.
If you are still deciding whether this credential suits your goals, start with What Is CSSD Certification? for the big picture, then return here for the domain-level detail.
Domain Weights at a Glance
Domain weights tell you how the exam's attention is distributed. With only 25 questions, the weighting is not just academic: it indicates roughly where most of your questions will come from. The following table summarizes the official weights.
| Domain | Name | Weight |
|---|---|---|
| 1 | Understand the Fundamentals of Secure Software Development | 15% |
| 2 | Explain the Secure Software Development Lifecycle | 22% |
| 3 | Develop Secure Code | 33% |
| 4 | Defending Against Cyberattacks | 15% |
| 5 | Engage in Governance, Risk Management, and Compliance | 15% |
Notice the shape of the distribution. Domain 3 alone is a third of the blueprint, and Domains 2 and 3 together account for 55%. The remaining three domains split the other 45% evenly at 15% each. That makes the exam hands-on and process-oriented rather than a purely theoretical security test.
Domain 1: Fundamentals of Secure Software Development (15%)
The first domain, Understand the Fundamentals of Secure Software Development, lays the vocabulary and mental models that every other domain builds on. Expect questions that test whether you can apply core security principles to a development scenario rather than simply define them.
Core Concepts to Master
The foundational principles that CertNexus lists as supported topics for the exam.
- CIA triad: confidentiality, integrity, and availability, and how a design decision can favor one at the expense of another.
- AAA: authentication, authorization, and accounting, and how they differ in purpose and placement within an application.
- Least privilege: granting only the access required, applied to users, services, processes, and pipelines.
- Threat modeling and abuse cases: thinking like an attacker before code is written, and expressing misuse as structured scenarios.
Abuse Cases Versus Use Cases
Many developers are comfortable writing use cases but have less practice with abuse cases. An abuse case describes how a malicious actor might misuse a feature, such as a password reset flow being used to enumerate valid accounts. Being able to read a short scenario and identify the abuse, the affected principle (confidentiality, integrity, or availability), and a sensible mitigation is exactly the kind of applied reasoning this domain rewards.
Principles Under Pressure
Scenario questions often present two principles in tension. A design that maximizes availability by granting broad access violates least privilege; a design that locks everything down may hurt availability. Practice articulating the trade-off and choosing the response that best matches the stated requirement in the question.
Domain 2: The Secure Software Development Lifecycle (22%)
Explain the Secure Software Development Lifecycle is the second-largest domain at 22%. Where Domain 1 gives you principles, Domain 2 asks where and when those principles are applied across planning, design, build, test, and deployment. The key idea is that security is integrated into each phase rather than bolted on at the end.
Lifecycle Topics to Expect
Think in terms of activities mapped to phases.
- Requirements and design: security requirements, threat modeling, and abuse-case analysis done early, when fixes are cheapest.
- Build and test: the testing families listed in the blueprint's supported topics, including SAST, DAST, IAST, and SCA.
- Deployment: secure CI/CD practices and protecting the pipeline itself as an attack surface.
- Software supply chain security: understanding how third-party components and build systems introduce risk.
Choosing the Right Testing Technique
A recurring theme is knowing which testing approach fits which situation. Static analysis (SAST) examines source or compiled code without running it, dynamic analysis (DAST) probes a running application from the outside, interactive analysis (IAST) observes behavior from inside a running application during testing, and software composition analysis (SCA) focuses on known issues in third-party components. A strong candidate can match a described weakness or phase to the technique most likely to find it.
For a sense of how the lifecycle domain compares with the others in difficulty, see How Hard Is the CSSD Exam? Complete Difficulty Guide 2026.
Domain 3: Develop Secure Code (33%)
Develop Secure Code is the heart of the exam. At 33%, roughly one in three questions will come from this domain, and it is where practical development experience pays off most. The CertNexus topic list for this area centers on the controls that prevent the most common implementation flaws.
Input Validation and Output Encoding
These two controls are frequently confused, so be able to distinguish them precisely.
- Input validation: checking that data conforms to expected type, length, format, and range before it is processed.
- Output encoding: transforming data for the context in which it will be displayed or interpreted, so that it is treated as data rather than executable content.
- Know why validation alone does not replace encoding, and why the correct encoding depends on the output context.
Authentication, Authorization, and Secrets Management
Identity and credential handling account for many real-world breaches and many exam scenarios.
- Authentication: verifying who a user or service is, including sound handling of credentials and sessions.
- Authorization: deciding what an authenticated identity may do, enforced on the server side and at every relevant layer.
- Secrets management: keeping API keys, tokens, and passwords out of source code and configuration files, and storing them in appropriate secure mechanisms.
Reviewing AI-Generated Code
One topic that sets this blueprint apart from older secure-coding material is AI-generated code review. The blueprint lists it as a supported topic, reflecting how many developers now use code assistants. The skill being tested is critical review: recognizing that generated code can contain missing validation, insecure defaults, hard-coded secrets, or outdated and vulnerable dependencies, and that it deserves the same scrutiny as any other contribution. Expect questions that present a snippet or scenario and ask you to identify the security concern or the right review practice.
Dependency Security
Modern applications are mostly assembled from third-party components, so dependency security is part of secure coding, not just supply chain policy. Understand why unpinned or unvetted dependencies create risk, how SCA tooling surfaces known issues, and why timely updates matter. This topic bridges Domain 3 and the lifecycle material in Domain 2, which is a good example of how the domains overlap in practice.
Key Takeaway
Because Domain 3 is 33% of the exam, write and review real code while you study. Take a small web endpoint, add validation, apply context-appropriate output encoding, remove any hard-coded secret, and check its dependencies. Hands-on repetition builds the pattern recognition that scenario questions reward.
Domain 4: Defending Against Cyberattacks (15%)
Defending Against Cyberattacks connects the code you write to the attacks it must withstand. At 15%, it is a smaller domain, but it rewards candidates who understand attacker behavior well enough to recognize which defensive control fits which threat.
The useful way to study this domain is by pairing weaknesses with their defenses. Rather than memorizing attack names in isolation, ask three questions for each: what condition makes the attack possible, which principle or control from Domains 1 and 3 closes that gap, and which testing method from Domain 2 would detect it. For example, an injection-style weakness ties back to input validation and output encoding, while a broken-access weakness ties back to authorization and least privilege.
Domain 5: Governance, Risk Management, and Compliance (15%)
Engage in Governance, Risk Management, and Compliance moves from code to the organizational context around it. Developers do not work in a vacuum: policies, risk decisions, and regulatory expectations shape how software is built and released. The blueprint's supported topics include governance, and this domain asks you to understand how security activities are justified, measured, and kept consistent.
What Candidates Should Be Ready to Do
- Explain why organizations adopt secure development policies and standards, and how those translate into developer responsibilities.
- Reason about risk in practical terms: identifying a threat, estimating its impact, and choosing among acceptance, mitigation, transfer, or avoidance.
- Recognize that compliance obligations influence requirements, documentation, and evidence, and that secure pipelines can help produce that evidence.
- Understand how supply chain and dependency practices fit into broader governance expectations.
Developers sometimes under-prepare for this domain because it feels less technical. Resist that instinct. Its questions are usually reasoning-based and can be answered reliably with a clear grasp of terminology and the purpose of each governance activity. Since all five domains sit under an 80% passing bar, an easy 15% is worth locking in.
What the Domains Look Like on Exam Day
The CSD-110 assessment contains 25 multiple-choice and multiple-response questions, delivered online through CHOICE. The passing score is 80%, which means 20 of 25 correct. CertNexus indicates an estimated completion time of 30 to 60 minutes, but that is an estimate rather than a verified fixed exam timer, so avoid building your strategy around a specific countdown. One complimentary retake is included. For a deeper look at scoring, read CSSD Passing Score 2026: Exactly What You Need to Pass.
Multiple-response items deserve special attention. When a question asks you to select more than one answer, partial understanding is risky; you need to evaluate each option independently against the scenario. Slow down on these and eliminate options that violate a principle you know cold.
| Exam Feature | What to Know |
|---|---|
| Question count | 25 multiple-choice and multiple-response |
| Passing score | 80% (20 of 25) |
| Delivery | Online through CHOICE |
| Estimated time | 30 to 60 minutes (an estimate, not a verified fixed timer) |
| Retake | One complimentary retake |
| Prerequisites | None formal; security foundations and development experience recommended |
There are no formal registration prerequisites, application fee, supporting documentation, or eligibility verification. CertNexus recommends foundational security knowledge and experience across software development, design, testing, and deployment, without prescribing a programming language. Details are covered in CSSD Requirements 2026: Eligibility, Prerequisites & How to Qualify.
On cost, the published student digital course-bundle prices are USD 514.50 without lab and USD 561.75 with lab. These are courseware-bundle prices, not separately verified exam-only fees, and the course access key includes the CHOICE credential process. See CSSD Certification Cost 2026: Complete Pricing Breakdown for the full picture.
Sequencing Your Preparation by Domain
Because the domains build on one another, the order in which you study them matters. The timeline below ties each week to the domain weights rather than to a generic schedule. Adjust the pace to your own experience level.
Domain 1 Foundations
- Lock in CIA, AAA, and least privilege with real examples.
- Practice writing two or three abuse cases for a feature you know well.
Domain 2 Lifecycle
- Map threat modeling, SAST, DAST, IAST, and SCA to lifecycle phases.
- Review secure CI/CD and supply chain risks.
Domain 3 Secure Code
- Spend the most time here: validation, encoding, authentication, authorization, secrets, and dependencies.
- Practice reviewing AI-generated code for security flaws.
Domains 4 and 5
- Pair attacks with defenses and with the detecting test technique.
- Review governance, risk, and compliance terminology.
Finish with timed practice questions across all five domains to expose weak spots, then revisit the lowest-scoring areas. A full walkthrough of this approach appears in the CSSD Study Guide 2026: How to Pass on Your First Attempt, and the CSSD Cheat Sheet 2026: One-Page Review of Must-Know Facts works well as a final-week refresher. When you are ready to test yourself, try the CSSD practice tests and use your results to guide which domain to revisit.
Where These Domains Show Up in Real Roles
The five domains mirror the responsibilities of developers who ship security-conscious software. Domain 3 skills are daily work for application developers and anyone doing code review. Domain 2 knowledge matters to DevOps and platform engineers who own build and release pipelines, as well as to security champions embedded in engineering teams. Domain 5 resonates with technical leads and managers who must justify and document security decisions.
Employers who value this kind of credential tend to be organizations building their own software, software vendors, and teams adopting DevSecOps practices. If you are weighing the career angle, explore CSSD Jobs and Is the CSSD Certification Worth It? Complete ROI Analysis 2026 for a closer look at the value proposition, and keep in mind that salary outcomes depend heavily on role, location, and experience rather than on the credential alone.
Finally, remember that certification is not permanent. CertNexus's general maintenance policy states a three-year validity period, with renewal by passing the current exam and continuing education available to eligible holders. That page does not establish CSSD-specific continuing-education requirements, so confirm details with CertNexus directly when your renewal window approaches.
Key Takeaway
Allocate effort in proportion to the blueprint: build deep, hands-on competence in Domain 3, solid process knowledge in Domain 2, and reliable conceptual coverage in Domains 1, 4, and 5. The blueprint's examples are not exhaustive, so aim to understand why each control works rather than memorizing lists.
Frequently Asked Questions
There are five weighted domains: Fundamentals of Secure Software Development (15%), the Secure Software Development Lifecycle (22%), Develop Secure Code (33%), Defending Against Cyberattacks (15%), and Governance, Risk Management, and Compliance (15%).
Develop Secure Code is the largest at 33%. It covers topics such as input validation, output encoding, authentication, authorization, secrets management, AI-generated code review, and dependency security.
No. CertNexus notes that the blueprint's detailed examples are not an exhaustive list of everything that may be tested. Study the underlying concepts so you can handle scenarios that do not mirror a listed example.
The exam has 25 questions and an 80% passing score, so you need 20 correct answers. That means you can miss no more than five questions.
No. The publisher identifies CSD-110 courseware as replacing Cyber Secure Coder CSC-210 courseware, but the exams and blueprints are distinct. Use the CSD-110 blueprint, version 1.12, as your reference for domain content.