- What the Acronym Stands For
- Who Issues It and What Exam It Maps To
- Reading the Name Word by Word
- The Five Domains Behind the Name
- What the Exam Looks Like
- Topics Hiding Inside the Title
- Who the Credential Is Built For
- Cost, Access, and Registration Mechanics
- Keeping the Credential Current
- Pacing Your Prep by Domain
- Frequently Asked Questions
- CSSD stands for Cyber Secure Software Developer, a CertNexus credential tested through exam CSD-110.
- The exam has 25 multiple-choice/multiple-response questions, and 80% (20 of 25) is required to pass.
- Develop Secure Code is the heaviest domain at 33%, followed by the secure SDLC at 22%.
- There are no formal registration prerequisites, and one complimentary retake is included.
What the Acronym Stands For
CSSD means Cyber Secure Software Developer. It is a professional certification from CertNexus aimed at people who build, test, and ship software and want to prove they can do it with security designed in rather than bolted on. If you landed here after seeing the four letters on a job posting, a course listing, or a colleague's email signature, that is the full expansion.
The acronym is deliberately compact, but each word carries a distinct meaning. This guide unpacks all of it: the issuing body, the exam, the five weighted domains, the topics that sit under the title, and the practical mechanics of getting certified. If you want shorter takes on the same question, our pages on what CSSD stands for and what CSSD is cover the basics, while this article goes deeper into what the name actually implies about the exam.
Who Issues It and What Exam It Maps To
The credential is issued by CertNexus. The current exam is CSD-110, which launched on May 11, 2026. Delivery is online through CHOICE, and the course access key includes the CHOICE credential process, so the learning path and the credentialing step are connected rather than purchased in separate silos.
One point of confusion deserves a direct answer. The publisher identifies CSD-110 courseware as replacing Cyber Secure Coder CSC-210 courseware. Those are separate exams with separate blueprints, and you should keep them distinct when searching for study materials. Some product descriptions also reference "CSD-210," which conflicts with the issuer's own CSD-110 title and blueprint. The issuer's naming is the one to trust: the exam for this credential is CSD-110.
| Item | What it is |
|---|---|
| Credential name | Cyber Secure Software Developer (CSSD) |
| Issuing body | CertNexus |
| Current exam | CSD-110, launched May 11, 2026 |
| Delivery | Online through CHOICE |
| Predecessor courseware | Cyber Secure Coder CSC-210 (separate exam, separate blueprint) |
Reading the Name Word by Word
It helps to treat the title as a compressed job description.
Cyber
The credential lives in the security discipline. It is not a general programming certificate. Expect questions framed around attackers, abuse, defense, and risk rather than around syntax or framework trivia.
Secure
Security is the adjective that modifies everything else. The exam rewards candidates who think about trust boundaries, failure modes, and misuse from the first design conversation onward, not only at the penetration-test stage.
Software Developer
The target audience writes code and ships software. That is why the blueprint covers design, testing, deployment, and pipelines alongside pure coding. No specific programming language is prescribed, so the content is concept-driven and language-agnostic rather than tied to one ecosystem.
The Five Domains Behind the Name
CertNexus publishes the official weighted objectives in its Cyber Secure Software Developer (CSSD) Exam CSD-110 Blueprint, version 1.12, issued December 15, 2024 and modified June 1, 2026. The five domains and weights are below. For a full walkthrough, see our complete guide to all five CSSD content areas.
| Domain | Weight |
|---|---|
| Domain 1: Understand the Fundamentals of Secure Software Development | 15% |
| Domain 2: Explain the Secure Software Development Lifecycle | 22% |
| Domain 3: Develop Secure Code | 33% |
| Domain 4: Defending Against Cyberattacks | 15% |
| Domain 5: Engage in Governance, Risk Management, and Compliance | 15% |
Domain 3: Develop Secure Code (33%)
This is the largest slice of the exam, roughly a third of the content, and the clearest expression of the "Developer" in the credential's name.
- Input validation and output encoding
- Authentication and authorization implementation
- Secrets management
- Reviewing AI-generated code for security flaws
Domain 2: Explain the Secure Software Development Lifecycle (22%)
The second-heaviest domain asks how security fits into each phase of building software, from requirements through release.
- Threat modeling and abuse cases
- Security testing approaches across the lifecycle
- Secure CI/CD practices
Domains 1, 4, and 5 (15% each)
These three equal-weight domains cover the conceptual foundation, active defense, and the organizational layer.
- Domain 1: core security principles that anchor everything else
- Domain 4: defending against cyberattacks
- Domain 5: governance, risk management, and compliance
Notice what the weighting says about the meaning of the title. Developing secure code and understanding the secure lifecycle together account for more than half of the exam. The credential is about how you build, with the rest wrapped around that core.
What the Exam Looks Like
The assessment is compact by certification standards.
- Format: 25 multiple-choice and multiple-response questions
- Passing score: 80%, which means 20 of 25 correct
- Estimated completion time: 30 to 60 minutes (an estimate, not a verified fixed exam timer)
- Retake: one complimentary retake is included
- Delivery: online through CHOICE
With only 25 questions and an 80% bar, you can miss at most five. Multiple-response items reward complete understanding, since partial recognition of a concept is not enough when you must identify every correct option. For more on the cut score arithmetic, read our breakdown of the CSSD passing score, and for a realistic sense of difficulty, see how hard the CSSD exam is.
Topics Hiding Inside the Title
The phrase "Cyber Secure Software Developer" is shorthand for a specific body of knowledge. The supported topics include the following, grouped here by theme.
Security Fundamentals
Expect the foundations: the CIA triad (confidentiality, integrity, availability), AAA (authentication, authorization, accounting), and least privilege. These concepts underpin nearly every later question, so fluency here pays off across multiple domains.
Design-Time Thinking
Threat modeling and abuse cases shift security left, into design. Rather than asking "does this feature work," you ask "how could someone misuse it." Candidates should be comfortable turning a feature description into a list of plausible attacker behaviors.
Code-Level Defenses
Input validation, output encoding, authentication, authorization, and secrets management form the hands-on core. A reliable mental habit: validate what comes in, encode what goes out, verify identity, check permissions on every sensitive action, and never embed credentials in source.
AI-Generated Code Review
The blueprint explicitly supports reviewing AI-generated code. This reflects how developers now work. The skill being tested is not prompting but scrutiny: recognizing when generated code skips validation, mishandles secrets, or introduces insecure patterns that look plausible at a glance.
Testing and Analysis Tooling
Know the acronym family SAST, DAST, IAST, and SCA. Understand what each examines (source, running application, instrumented runtime behavior, and third-party components respectively) and where each fits in a pipeline.
Pipeline and Supply Chain
Dependency security, secure CI/CD, and software supply chain security reflect modern delivery realities. Your code is only part of what you ship; the libraries you pull in and the pipeline that builds them are part of your attack surface.
Governance
Governance, risk management, and compliance round out the list, tying technical decisions to organizational accountability. For a quick-reference version of all of this, our CSSD cheat sheet condenses the must-know facts.
Key Takeaway
When a question describes a scenario, identify which layer it tests: a principle (CIA, least privilege), a design activity (threat model, abuse case), a code control (validation, encoding, secrets), a tool category (SAST, DAST, IAST, SCA), or a governance concern. Naming the layer first narrows the correct answer fast.
Who the Credential Is Built For
The intended audience is practitioners who already touch the software lifecycle. CertNexus recommends foundational security knowledge plus experience in software development, design, testing, and deployment. There is no prescribed programming language, so a developer working in any stack can approach the material.
In practice, that describes several roles: application developers who want to formalize their security skills, engineers moving toward DevSecOps or application security, QA and test engineers who handle security testing, and technical leads responsible for secure design decisions. If you are curious about the employer side, our overview of CSSD-related jobs explores the kinds of roles where this credential is relevant, and the CSSD salary guide addresses earnings qualitatively. We do not quote specific salary figures here because none are established for this credential.
For the question of whether it justifies the effort, see our ROI analysis of the certification.
Cost, Access, and Registration Mechanics
There are no formal registration prerequisites, application fee, supporting documentation, or eligibility verification. You do not submit proof of experience to sit the exam. Our CSSD requirements guide covers this in more detail.
The course access key includes the CHOICE credential process, so the credentialing step travels with the courseware. Published student digital course-bundle prices are:
| Bundle | Price (USD) | SKU |
|---|---|---|
| Digital course bundle without lab | $514.50 | CNX0022SEBU2 |
| Digital course bundle with lab | $561.75 | CNX0022SEBU |
Keeping the Credential Current
CertNexus's general maintenance policy states that certifications are valid for three years and are renewed by passing the current exam. Continuing education is available to eligible holders under the CertNexus continuing education program. However, that program page does not establish CSSD-specific continuing-education eligibility or requirements, so treat any detail beyond the general three-year, renew-by-exam statement as something to confirm directly with CertNexus.
Pacing Your Prep by Domain
Study method matters less than aiming effort where the exam's weight sits. One reasonable ordering follows the dependencies between domains. Our full CSSD study guide goes further, and you can test your readiness with the CSSD practice tests.
Foundations (Domain 1, 15%)
- Lock down CIA, AAA, and least privilege so later scenarios make sense
- Practice classifying a described control by the principle it supports
Lifecycle (Domain 2, 22%)
- Walk a sample feature through threat modeling and abuse cases
- Map SAST, DAST, IAST, and SCA to lifecycle phases
Secure Code (Domain 3, 33%)
- Spend the most time here: validation, encoding, authentication, authorization, secrets
- Practice spotting flaws in AI-generated code samples
Defense and Governance (Domains 4 and 5, 15% each)
- Review attack defenses, supply chain, and secure CI/CD
- Connect risk and compliance language to technical decisions, then take a full practice set
Because Domain 3 carries a third of the exam, giving it two weeks is proportionate. Rushing the foundations is the more common mistake, since weak grasp of the core principles undermines the harder scenario questions later.
Frequently Asked Questions
CSSD stands for Cyber Secure Software Developer, a credential from CertNexus assessed through exam CSD-110. For related phrasing, see our pages on CSSD meaning and what CSSD means.
The exam has 25 multiple-choice and multiple-response questions. You need 80%, which is 20 of 25 correct, to pass. One complimentary retake is included.
Domain 3, Develop Secure Code, carries 33%. The secure software development lifecycle domain is next at 22%, and the other three domains are 15% each.
There are no formal registration prerequisites and no prescribed programming language. CertNexus recommends foundational security knowledge and experience across software development, design, testing, and deployment.
CertNexus's general maintenance policy states three-year validity, with renewal by passing the current exam. Confirm any continuing-education options directly with CertNexus, since the general program page does not spell out CSSD-specific requirements.