- CSSD means Cyber Secure Software Developer, a CertNexus credential assessed through exam CSD-110, launched May 11, 2026.
- The exam has 25 multiple-choice/multiple-response questions, and the passing score is 80% (20 of 25).
- Develop Secure Code is the heaviest domain at 33%, followed by the secure software development lifecycle at 22%.
- No formal prerequisites or application fee exist for registration, and one complimentary retake is included.
The Short Answer: What CSSD Means Here
On this site, CSSD stands for Cyber Secure Software Developer. It is a certification offered by CertNexus that validates whether a person can build software with security designed in from the start rather than bolted on at the end. The current exam is CSD-110, which launched on May 11, 2026.
If you landed here looking for a definition, that is the whole answer in one sentence. The rest of this article explains what the name implies, what the exam actually measures, and how the credential fits into a software career. For other quick-reference angles on the same question, see our pages on what CSSD stands for and the meaning of CSSD.
Why the Acronym Confuses People
A short search for "CSSD" returns results from healthcare, supply-chain, and other credentialing programs that happen to compress to the same four letters. That overlap is the single biggest source of bad information about this certification. A candidate who reads a different program's exam length, fee, or renewal rules and applies them to the software-security credential will plan around facts that simply do not exist for it.
Two practical habits prevent this:
- Always confirm the issuer. For this credential, the issuer is CertNexus, and the exam code is CSD-110.
- Treat the exam blueprint as the source of truth for scope. The blueprint is the official document describing the weighted objectives, and it is the right anchor for any claim about what is tested.
There is also a naming wrinkle worth knowing. The courseware publisher states that CSD-110 materials replace the earlier Cyber Secure Coder CSC-210 courseware. Those are distinct exams with distinct blueprints, so do not mix study materials or objectives between them. Some product descriptions also mention "CSD-210," which conflicts with the issuer's own CSD-110 title and blueprint; the issuer's naming is the one to trust.
What the Credential Covers
Read literally, the name has three working parts. "Cyber Secure" signals that security is the organizing principle. "Software" narrows the scope to code and the systems that build and ship it. "Developer" tells you the target audience is the person writing and reviewing that code, not only the security analyst who audits it later.
In practice, the blueprint's supported topics span a wide arc:
- Foundations: the CIA triad (confidentiality, integrity, availability), AAA (authentication, authorization, accounting), and least privilege.
- Design-time thinking: threat modeling and abuse cases, which force you to imagine how a feature could be misused before it ships.
- Code-level defenses: input validation, output encoding, authentication, authorization, and secrets management.
- Modern realities: reviewing AI-generated code, dependency security, and software supply chain security.
- Pipeline and tooling: SAST, DAST, IAST, and SCA testing approaches, plus secure CI/CD.
- Governance: risk management and compliance responsibilities that surround the engineering work.
The blueprint's detailed examples are not an exhaustive list of everything that may be tested, so treat the topic list as a floor rather than a ceiling. For a fuller walkthrough of what the certification represents, our overview What Is CSSD Certification? covers the credential at a higher level.
How the Exam Works
The CSD-110 assessment is compact compared with many security certifications. Here are the facts that matter:
| Feature | CSD-110 Detail |
|---|---|
| Issuer | CertNexus |
| Launch | May 11, 2026 |
| Delivery | Online through CHOICE |
| Question count | 25 multiple-choice/multiple-response |
| Passing score | 80% (20 of 25) |
| Estimated completion time | 30 to 60 minutes (an estimate, not a verified fixed exam timer) |
| Retake | One complimentary retake |
| Formal prerequisites | None required for registration |
What the format implies
With only 25 questions and an 80% bar, each item carries real weight. You can miss at most five. The "multiple-response" style matters too: some questions ask you to select more than one correct answer, which punishes partial understanding. Knowing that a control is "generally good" is not enough; you need to distinguish, for example, which of several mitigations actually addresses a described attack versus which merely sounds security-flavored.
The Five Domains in Detail
The official blueprint (version 1.12, issued December 15, 2024 and modified June 1, 2026) divides the exam into five weighted domains. The weights tell you where questions are concentrated.
Domain 1: Understand the Fundamentals of Secure Software Development (15%)
The conceptual bedrock. Expect questions that test whether you can apply core principles to a scenario rather than recite definitions.
- CIA triad and how a given flaw maps to confidentiality, integrity, or availability
- AAA: authentication versus authorization versus accounting
- Least privilege and why over-broad permissions amplify damage
Domain 2: Explain the Secure Software Development Lifecycle (22%)
The second-largest domain. It asks where security activities belong across planning, design, build, test, and deploy.
- Threat modeling during design
- Abuse cases alongside traditional use cases
- Placing security checkpoints so defects are caught early, when they are cheaper to fix
Domain 3: Develop Secure Code (33%)
The largest single domain, and the one most directly tied to day-to-day developer work. One in three questions lands here.
- Input validation and output encoding, and when each applies
- Authentication and authorization implementation choices
- Secrets management, such as keeping credentials out of source code
- Reviewing AI-generated code for insecure patterns before it is merged
Domain 4: Defending Against Cyberattacks (15%)
Connects code-level decisions to the attacks they prevent or enable, including testing and supply-chain exposure.
- SAST, DAST, IAST, and SCA: what each finds and where it fits
- Dependency security and software supply chain security
- Secure CI/CD practices that protect the build and release path
Domain 5: Engage in Governance, Risk Management, and Compliance (15%)
The organizational layer. Developers who ignore this domain tend to lose points they could have kept.
- Risk-based reasoning about which findings to fix first
- Compliance obligations that shape engineering decisions
- Governance as a standing practice rather than a one-time checklist
Notice the shape: Domains 1, 4, and 5 each carry 15%, Domain 2 carries 22%, and Domain 3 carries 33%. The two largest domains together account for more than half the exam. For a deeper breakdown of each area, read our complete guide to all five CSSD content areas.
Who the Credential Is For
CertNexus lists no formal registration prerequisites, application fee, supporting documentation, or eligibility verification. That said, the recommendation is clear: you will be more comfortable with foundational security knowledge and some hands-on experience across software development, design, testing, and deployment. No particular programming language is prescribed, which fits the exam's concept-driven style. You are being tested on secure practice, not on syntax.
That profile points to several kinds of candidates:
- Working developers who want to formalize security habits they have picked up informally.
- QA and test engineers who touch SAST, DAST, and pipeline tooling and want a credential that names that work.
- DevOps and platform engineers responsible for CI/CD and supply chain controls.
- Career changers with some development background who are moving toward application security.
Employers that build or buy software, including product companies, consultancies, and teams operating regulated systems, are the natural audience for this skill set. The credential signals that you can talk about secure design, review code with a security lens, and understand the controls around a delivery pipeline. For the practical side of the job market, see CSSD jobs, and for pay expectations, our CSSD salary guide treats earnings qualitatively rather than promising figures. If you are weighing the investment, Is the CSSD Certification Worth It? walks through the reasoning.
If you want the formal eligibility picture spelled out, CSSD Requirements 2026 covers it.
Courseware and Cost Mechanics
This is the part most people get wrong, so precision helps. Published student digital course-bundle prices for CSD-110 courseware are:
| Bundle | Price (USD) | SKU |
|---|---|---|
| Digital course bundle without lab | 514.50 | CNX0022SEBU2 |
| Digital course bundle with lab | 561.75 | CNX0022SEBU |
These are courseware-bundle prices, not separately verified exam-only fees. The course access key includes the CHOICE credential process, which is how the assessment is delivered online. One listing is titled "Student Digital Course Bundle" even though its URL wording differs, so read the product page carefully before you buy. Because there is no separate application fee or documentation step, the courseware bundle is the main published cost line a candidate will encounter. For the fuller picture, including what to budget around, see CSSD Certification Cost 2026.
Key Takeaway
Do not treat the bundle price as "the exam fee." Treat it as the cost of courseware that includes the credential process. If a source quotes a standalone exam price for CSD-110, verify it against the issuer before relying on it.
Renewal and Longevity
CertNexus's general maintenance policy states a three-year certification validity, with renewal by passing the current exam. Continuing education is available to eligible holders under the broader CertNexus program. The important caveat: that policy page does not establish CSSD-specific continuing-education eligibility or requirements. So the safe reading is that the general policy applies, and you should confirm any CSSD-specific continuing-education question directly with CertNexus rather than assuming another credential's rules carry over.
Practically, three years is a sensible cadence for this field. Tooling, AI-assisted coding, and supply chain threats move quickly, and a credential that expects you to refresh against the current exam keeps pace with that.
Sequencing Your Prep by Domain
Rather than a generic plan, order your effort by weight and by dependency. Foundations come first because later domains assume you can reason in CIA and least-privilege terms. Develop Secure Code gets the most time because it holds a third of the exam.
Fundamentals and lifecycle framing
- Domain 1: CIA, AAA, least privilege applied to scenarios
- Start Domain 2: where threat modeling and abuse cases sit in the lifecycle
Lifecycle depth
- Finish Domain 2 (22%)
- Practice distinguishing design-time from build-time from release-time controls
Secure code, the big one
- Domain 3 (33%): input validation versus output encoding, authentication versus authorization, secrets management
- Practice reviewing AI-generated code for insecure patterns
Attacks, tooling, and governance
- Domain 4: SAST/DAST/IAST/SCA, dependency and supply chain security, secure CI/CD
- Domain 5: risk, compliance, and governance reasoning
Full-length review
- Timed mixed sets on the practice test site
- Revisit any domain where you miss multiple-response items
For a complete preparation framework, use our CSSD study guide, and keep the CSSD cheat sheet handy for last-day review. Because the exam is short, you can run realistic full-length sets on our CSSD practice tests in well under an hour, which makes frequent self-testing easy. If you want structured instruction, see CSSD training options.
Frequently Asked Questions
In this context, CSSD stands for Cyber Secure Software Developer, a CertNexus certification assessed through exam CSD-110. The same four letters are used by unrelated programs elsewhere, so always confirm the issuer and exam code.
The assessment has 25 multiple-choice/multiple-response questions, and the passing score is 80%, which is 20 of 25. One complimentary retake is included.
No formal registration prerequisites, application fee, supporting documentation, or eligibility verification are listed. Foundational security knowledge and software development, design, testing, and deployment experience are recommended, with no prescribed programming language.
Develop Secure Code is the largest at 33%, followed by the secure software development lifecycle at 22%. The remaining three domains are 15% each, so none can be safely ignored given the 80% passing bar.
CertNexus's general maintenance policy states three-year validity, with renewal by passing the current exam. CSSD-specific continuing-education requirements are not established by that policy page, so confirm any such question with CertNexus directly.