CSSD logo
Focused certification exam prep
Start practice

CSSD Study Guide 2026: How to Pass on Your First Attempt

TL;DR
  • The current exam is CertNexus CSD-110, with 25 questions and an 80% passing score, meaning 20 correct answers.
  • Develop Secure Code carries 33% of the blueprint, making it the single biggest area to master.
  • The secure software development lifecycle domain is second at 22%; the other three domains are 15% each.
  • One complimentary retake is included, but treat your first attempt as the real one.

What the CSD-110 Exam Actually Is

The Cyber Secure Software Developer credential is issued by CertNexus, and the current exam is CSD-110, which launched on May 11, 2026. It is aimed at people who write, review, test, and ship software and who need to demonstrate that they can build security into that work rather than bolt it on afterward. If you want the plain-language basics first, our overview of what CSSD certification is covers the credential at a higher level.

One point of confusion is worth clearing up immediately. The publisher of the courseware states that CSD-110 materials replace the older Cyber Secure Coder CSC-210 courseware. Those are distinct exams with distinct blueprints. Some product descriptions reference "CSD-210," but that conflicts with the issuer's own CSD-110 title and blueprint, so build your preparation around CSD-110 and the official blueprint, not around anything that cites a different code. If you are searching for a study guide and find material for a different certification that happens to share the "CSSD" acronym, set it aside; it will not map to this exam.

There are no formal registration prerequisites, no application fee, no supporting documentation, and no eligibility verification step. CertNexus recommends foundational security knowledge plus experience across software development, design, testing, and deployment, but it does not prescribe a programming language. Our CSSD requirements guide goes deeper on what "recommended but not required" means in practice.

Format, Scoring, and the Retake

The exam is delivered online through CHOICE, and the course access key includes the CHOICE credential process. The assessment consists of 25 questions, a mix of multiple-choice and multiple-response. The passing score is 80%, which works out to 20 of 25 correct. CertNexus gives an estimated completion time of 30 to 60 minutes, but that is an estimate and not a verified fixed exam timer, so do not plan around a hard clock you cannot confirm. One complimentary retake is included.

ItemWhat the Published Facts Say
Exam codeCSD-110 (launched May 11, 2026)
DeliveryOnline through CHOICE
Questions25, multiple-choice and multiple-response
Passing score80% (20 of 25)
Estimated time30 to 60 minutes (an estimate, not a verified timer)
RetakeOne complimentary retake
PrerequisitesNone formal; security and development experience recommended

The math deserves attention. With only 25 questions, each item is worth 4 percentage points, and you can miss at most five. That is a tight margin: a handful of misread multiple-response questions can end the attempt. Multiple-response items are particularly unforgiving because you must identify every correct option, not just the most obvious one. For a closer look at the arithmetic, see our guide to the CSSD passing score, and for realistic expectations about difficulty, read how hard the CSSD exam is.

Why the retake is not a safety net: A complimentary retake removes the financial sting of a miss, but it does not change the 80% bar. Candidates who plan on "learning the format" during attempt one tend to burn their best preparation momentum. Treat the first sitting as the one that counts and use the retake only as insurance.

Where the Points Live: Domain Weights

The five domains below are the official weighted exam objectives from the CertNexus Cyber Secure Software Developer Exam CSD-110 Blueprint, version 1.12 (issued December 15, 2024 and modified June 1, 2026). Read the blueprint itself alongside this guide; it is the authoritative source.

DomainWeight
1. Understand the Fundamentals of Secure Software Development15%
2. Explain the Secure Software Development Lifecycle22%
3. Develop Secure Code33%
4. Defending Against Cyberattacks15%
5. Engage in Governance, Risk Management, and Compliance15%

Domains 2 and 3 together account for 55% of the exam. If your time is limited, those two should absorb the majority of it. Still, with a pass line at 80%, you cannot afford to ignore the 15% domains: weakness across all three of them could cost you more than the margin allows. The complete guide to all five CSSD content areas breaks each domain down further.

Mastering Develop Secure Code (33%)

This is the heart of the exam and the area where hands-on developers have an advantage. Expect questions that present a scenario, a code behavior, or a design decision and ask which control or fix is appropriate.

Domain 3: Develop Secure Code

The blueprint's supported topics in this area center on handling untrusted data, proving identity, and protecting sensitive material.

  • Input validation: know the difference between allow-list and deny-list approaches, and why validation belongs on the server side regardless of client checks.
  • Output encoding: understand that encoding must match the output context (HTML, attribute, script, URL) to neutralize injection-style flaws.
  • Authentication: credential handling, session management, and multi-factor concepts as they apply to application design.
  • Authorization: enforcing access decisions on every request, and avoiding reliance on hidden UI elements.
  • Secrets management: keeping keys, tokens, and passwords out of source code and configuration committed to repositories.

Think in contexts, not slogans

A common trap is memorizing "validate input, encode output" as a slogan without understanding where each belongs. Validation reduces the set of acceptable data coming in; encoding protects the interpreter receiving data going out. Questions often test whether you can tell which one solves the problem described. Likewise, authentication answers "who are you," while authorization answers "what may you do," and exam scenarios frequently blur them to see if you can separate the two.

Secrets are a recurring theme

Secrets management shows up in both the code domain and the pipeline discussion. Be ready to recognize why hardcoded credentials are dangerous, how they leak through version control history, and what better patterns look like at a conceptual level. You do not need a specific vendor's vault product; you need the principle.

The Secure SDLC Domain (22%)

Domain 2 asks you to explain how security fits into each phase of software delivery. This is where threat modeling and abuse cases live.

Domain 2: Explain the Secure Software Development Lifecycle

Security activities map to lifecycle phases, from requirements through deployment and maintenance.

  • Threat modeling: identifying assets, entry points, trust boundaries, and likely attackers during design.
  • Abuse cases: the adversarial counterpart to use cases; describing how a feature could be misused on purpose.
  • Security requirements: translating risk into testable requirements early, when change is cheapest.
  • Phase mapping: knowing which activity belongs where, such as design review versus testing versus release gating.

The skill being tested is placement and reasoning. A question might describe a flaw discovered late and ask which earlier activity would have caught it. Practice asking, for every security activity you learn, "in which phase does this happen and what does it prevent?" Abuse cases in particular are easy to confuse with ordinary functional use cases; remember that they deliberately imagine a hostile actor.

Key Takeaway

Combine Domains 2 and 3 in your study: for each secure-coding control, name the lifecycle phase where you would verify it. That cross-mapping mirrors how scenario questions are written and gives you two points of recall per concept.

Fundamentals, Defense, and Governance

Domain 1: Fundamentals (15%)

This domain establishes vocabulary and first principles. The supported topics include the CIA triad (confidentiality, integrity, availability), AAA (authentication, authorization, accounting), and least privilege. These are foundational, so questions can be deceptively simple, yet multiple-response formatting can still trip you up. Be able to map a described control to the property it protects: encryption primarily supports confidentiality, hashing and signatures support integrity, redundancy supports availability.

Domain 4: Defending Against Cyberattacks (15%)

Here the focus turns to recognizing attack patterns and selecting defenses at the application and delivery level. Software supply chain security and dependency security belong in your mental toolkit here as much as in the pipeline discussion below. Think about how an attacker reaches your code indirectly, through a compromised library, a tampered build, or a poisoned package, and what defenders do about it.

Domain 5: Governance, Risk Management, and Compliance (15%)

Candidates from pure engineering backgrounds often under-prepare for this domain. Learn how risk is assessed and treated, why policies and standards exist, and how compliance obligations shape development practices. You are not expected to be a lawyer, but you should understand how governance drives requirements that developers then implement and evidence.

Do not skip the 15% domains: Because the pass line is 80%, a weak Domain 5 can quietly cost you three or four questions. Developers who dominate Domain 3 sometimes fail narrowly because they treated governance as common sense. Give each smaller domain a dedicated review pass.

Testing Tools, Dependencies, and Pipeline Security

The blueprint's supported topics name four testing approaches that candidates must distinguish: SAST, DAST, IAST, and SCA. Learn each by what it examines and when it runs.

ApproachWhat It ExaminesTypical Strength
SAST (static analysis)Source or compiled code without running itFinds flaws early, before deployment
DAST (dynamic analysis)A running application from the outsideSurfaces runtime and configuration issues
IAST (interactive analysis)Application behavior observed from inside during testingCombines runtime context with code-level insight
SCA (composition analysis)Third-party and open-source componentsIdentifies vulnerable or risky dependencies

Exam questions in this area usually describe a goal or a problem and ask which technique fits. "We need to find vulnerable libraries we did not write" points to SCA. "We want to test the deployed app as an outsider would" points to DAST. Rehearse these matches until they are automatic.

Secure CI/CD and supply chain

Secure CI/CD means treating the build and release pipeline as an attack surface of its own: protecting pipeline credentials, controlling who can change build definitions, verifying the integrity of dependencies and artifacts, and inserting security checks as automated gates. Software supply chain security extends the concern outward to everything your software consumes. Dependency security, covering updates, pinning, and vulnerability monitoring, ties these threads together.

Reviewing AI-Generated Code

One notable topic in the supported list is AI-generated code review. The core idea is simple but important: code produced by an AI assistant is untrusted until reviewed, just like code from any unknown contributor. Such code can contain injection flaws, weak authentication logic, hardcoded secrets, or outdated and vulnerable dependencies. The right posture is to apply the same validation, encoding, authorization, and scanning discipline you would to human-written code, and to run it through your SAST and SCA tooling before it merges.

Expect conceptual questions here rather than tool-specific ones: what to check, why review is non-negotiable, and how automated testing complements human judgment. If you are tempted to treat generated code as "probably fine," the exam will reward the opposite instinct.

Courseware Bundles and Cost Mechanics

CertNexus does not charge an application fee, and there is no separate eligibility process. Cost questions therefore revolve around study materials. Two published student digital course-bundle prices are available through Logical Operations: USD 514.50 without a lab (SKU CNX0022SEBU2, revision 1.0) and USD 561.75 with a lab (SKU CNX0022SEBU, revision 1.0). Note that these are courseware-bundle prices, not separately verified exam-only fees, and the first listing is titled "Student Digital Course Bundle" even though its URL wording says otherwise. Because the course access key includes the CHOICE credential process, the bundle is the practical route into the exam for many candidates.

Whether you need the lab version depends on your background. If you already write and test code daily, the non-lab bundle plus the official blueprint may suffice; if hands-on exercises are how you learn, the lab is worth considering. Our CSSD certification cost breakdown walks through the pricing picture in more detail, and the ROI analysis helps you weigh it against career goals.

Validity and renewal

CertNexus's general maintenance policy states that certifications are valid for three years and can be renewed by passing the current exam, with continuing education available to eligible holders. That policy page does not establish CSSD-specific continuing-education eligibility or requirements, so confirm the details directly with CertNexus rather than assuming rules from another credential apply.

A Domain-Ordered Study Sequence

Generic scheduling advice matters less than ordering your study around the blueprint. The sequence below front-loads concepts that later domains depend on, then spends the most time where the points are. Adjust the pacing to your own calendar and background.

Week 1

Foundations (Domain 1)

  • Lock in CIA, AAA, and least privilege with real examples.
  • Read the full CSD-110 blueprint once, noting unfamiliar terms.
Week 2

Lifecycle (Domain 2)

  • Practice threat modeling and writing abuse cases for a sample feature.
  • Map each security activity to its lifecycle phase.
Weeks 3-4

Secure Code (Domain 3)

  • Drill input validation, output encoding, authentication, authorization, and secrets management.
  • Review AI-generated code samples for flaws.
Week 5

Defense and Governance (Domains 4 and 5)

  • Study SAST, DAST, IAST, SCA, secure CI/CD, and supply chain risks.
  • Cover risk management and compliance concepts.
Week 6

Full Review

  • Take timed practice sets and revisit every missed topic.
  • Rehearse multiple-response questions specifically.

The reason Domain 3 gets two weeks is simple: at 33% of the exam, it deserves roughly double the time of a 15% domain. Use the CSSD cheat sheet for a final-week refresher, and run realistic questions on the main practice test site to expose weak spots while there is still time to fix them. For a broader view of the same material, our CSSD study guide pairs well with this domain-ordered plan.

Handling the question styles

Because the exam mixes multiple-choice and multiple-response items, practice reading each stem for a count cue such as "select two" or "select all that apply." Eliminate options that violate a principle you know (for example, any answer that relies on client-side-only checks for a security decision), then compare the remaining choices against the exact scenario. With only five misses allowed, careful reading is worth as much as knowledge.

Who Benefits From This Credential

The credential is built for people who touch the software delivery process: application developers, engineers who review code, testers, DevOps and pipeline engineers, and technical leads who need to speak credibly about security practices. Employers building products where a breach carries real cost, including software vendors, financial and healthcare technology firms, and teams adopting AI coding assistants, have reason to value demonstrated secure-development skills. For a sense of the roles in play, see our overview of CSSD-relevant jobs, and for earnings context, the CSSD salary guide discusses compensation qualitatively without leaning on unverified figures.

If you are still orienting yourself, the explainers on what CSSD is and CSSD training options give useful background before you commit to a study plan.

Remember the blueprint caveat: The blueprint's detailed examples are not an exhaustive list of everything that may be tested. Learn the underlying concepts so you can reason about a scenario you have not seen before, rather than relying on pattern-matching against example lists.

Frequently Asked Questions

How many questions are on the CSD-110 exam, and what score do I need?

The exam has 25 multiple-choice and multiple-response questions. The passing score is 80%, which means 20 correct answers. CertNexus estimates 30 to 60 minutes to complete it, though that is an estimate rather than a verified fixed timer.

Which domain should I study first and longest?

Develop Secure Code is the largest domain at 33%, followed by the secure software development lifecycle at 22%. Spend the most time on those two, but give each 15% domain a dedicated review because the 80% pass line leaves little room for weak areas.

Are there prerequisites or an application fee?

No. There are no formal registration prerequisites, application fee, supporting documentation, or eligibility verification. Foundational security knowledge and experience with software development, design, testing, and deployment are recommended, and no specific programming language is prescribed.

What happens if I fail on my first attempt?

One complimentary retake is included. Even so, plan to pass the first time, since a missed attempt costs momentum and the 80% threshold is demanding with only 25 questions.

How long does the certification last?

CertNexus's general maintenance policy states three-year validity, with renewal by passing the current exam and continuing education available to eligible holders. That policy page does not spell out CSSD-specific continuing-education requirements, so verify details with CertNexus directly.

Pass on the first attempt by pairing the official blueprint with a domain-weighted plan, drilling scenario questions, and testing yourself under realistic conditions. When you are ready to check your readiness, start with the practice questions at the CSSD Exam Prep practice test site.

Ready to pass your CSSD exam?

Put this into practice with free CSSD questions across every exam domain.