CSSD logo
Focused certification exam prep
Start practice

What Is A CSSD?

TL;DR
  • CSSD means Cyber Secure Software Developer, a CertNexus credential tested through the current CSD-110 exam.
  • The exam has 25 multiple-choice and multiple-response questions, and 80% (20 of 25) is the passing score.
  • Develop Secure Code carries 33% of the blueprint, and the secure software development lifecycle follows at 22%.
  • There are no formal registration prerequisites, but secure-coding and development experience is strongly recommended.

The Short Answer: What a CSSD Actually Is

CSSD stands for Cyber Secure Software Developer. It is a certification aimed at people who write, review, test, and ship software and who need to prove they can do it without introducing avoidable security weaknesses. The credential is not a general cybersecurity survey and it is not a network-defense certification. Its center of gravity is the developer's daily work: writing code, handling data, managing dependencies, and moving changes through a build pipeline.

Because the acronym is shared with other credentials in unrelated fields, searchers sometimes land on material that has nothing to do with software security. Everything in this article refers only to the Cyber Secure Software Developer credential. If you want a quick orientation on naming, our pages on what CSSD stands for and the meaning of CSSD cover the terminology, while this guide focuses on what the certification contains and how to approach it.

Identity check: If a page mentions sterile processing, surgical instruments, or hospital departments, it is describing a different field entirely. The CSSD discussed on this site is the developer-security credential issued by CertNexus.

Who Issues It and What the Current Exam Is

The credential is issued by CertNexus. The current exam is CSD-110, which launched on May 11, 2026. CertNexus publishes an official blueprint for it, and that blueprint is the authoritative statement of what is tested. The version this article relies on is v1.12, originally issued December 15, 2024 and modified June 1, 2026.

One point that trips up candidates doing their own research: CertNexus courseware for CSD-110 is identified by the publisher as replacing the older Cyber Secure Coder CSC-210 courseware. Those are separate exams with separate blueprints. If you find study material labeled for the earlier coder exam, treat it as adjacent background at best, not as a substitute for the CSD-110 blueprint. You may also see stray references to a "CSD-210" in some product descriptions. The issuer's own title and blueprint say CSD-110, so that is the exam to prepare for.

For a broader overview of the credential as a whole, see our page on CSSD certification and the companion explainer on what CSSD certification is.

How the Assessment Works

The format is compact compared with many security certifications. It is worth understanding precisely, because the style of questioning shapes how you should study.

ElementCSSD (CSD-110)
DeliveryOnline, through CHOICE
Number of questions25
Question typesMultiple-choice and multiple-response
Passing score80% (20 of 25)
Estimated completion time30 to 60 minutes (an estimate, not a verified fixed timer)
RetakeOne complimentary retake

What the 80% threshold implies

With 25 questions and an 80% passing score, you can miss at most five. That sounds forgiving until you account for multiple-response items, where partial knowledge of which options apply can cost you the whole question. The narrow margin rewards candidates who understand why a control works, not just what it is called. Our dedicated page on the CSSD passing score walks through the arithmetic in more detail.

A note on timing

The 30 to 60 minute figure is an estimated completion time rather than a confirmed hard timer, so avoid building your pacing plan around a specific countdown you have not verified in your own exam interface. Read the instructions presented at the start of your session.

The Five Domains in Detail

The blueprint organizes the exam into five weighted domains. Weighting tells you where questions concentrate, so it should drive where your study hours go. A fuller walkthrough lives in our complete guide to all five CSSD content areas; the summary below shows how each one maps to developer work.

Domain 1: Understand the Fundamentals of Secure Software Development (15%)

The conceptual foundation. Candidates need fluency in the principles that every later domain builds on.

  • Confidentiality, integrity, and availability (CIA)
  • Authentication, authorization, and accounting (AAA)
  • Least privilege and why it limits blast radius

Domain 2: Explain the Secure Software Development Lifecycle (22%)

The second-heaviest domain. It tests whether you can place security activities at the right points in a development process rather than bolting them on at the end.

  • Threat modeling and abuse cases during design
  • Security requirements and testing across phases
  • Integrating secure practices into delivery workflows

Domain 3: Develop Secure Code (33%)

The largest domain by a wide margin, covering the hands-on techniques that prevent vulnerabilities from being written in the first place.

  • Input validation and output encoding
  • Authentication and authorization implementation
  • Secrets management and review of AI-generated code

Domain 4: Defending Against Cyberattacks (15%)

How application-level weaknesses are exploited and how developers and their tooling reduce exposure.

  • Recognizing common attack patterns against applications
  • Testing approaches such as SAST, DAST, IAST, and SCA
  • Dependency and supply chain risk

Domain 5: Engage in Governance, Risk Management, and Compliance (15%)

The organizational layer: how security decisions are documented, justified, and aligned with policy and obligations.

  • Risk-based reasoning about which weaknesses to fix first
  • Governance expectations that shape development practice
  • Compliance considerations as inputs to secure design

Key Takeaway

Domains 2 and 3 together account for 55% of the blueprint. If your time is limited, those two are where the most points live, and Domain 3 alone outweighs Domains 4 and 5 combined.

Concrete Topics You Must Be Able to Apply

The blueprint's detailed examples are not an exhaustive list of everything that may be tested, so treat the topics below as a floor rather than a ceiling. They are the ones the published scope explicitly supports.

Design-time thinking

Threat modeling and abuse cases ask you to think like an attacker before code exists. A typical scenario-style question might describe a feature and ask which misuse path the design overlooks, or which control addresses a particular threat. Knowing the vocabulary is not enough; you need to connect a described weakness to the mitigation that actually closes it.

Implementation-time controls

  • Input validation: Treat all external input as untrusted and validate it against what is expected, rather than trying to enumerate everything that is bad.
  • Output encoding: Encode data for the context in which it will be rendered or interpreted, so that data cannot be reinterpreted as instructions.
  • Authentication and authorization: Understand the difference between proving who someone is and deciding what they may do, and where each check belongs.
  • Secrets management: Know why credentials and keys do not belong in source code, and what handling them properly looks like.

Verification tooling

Four testing approaches appear in the supported topics: SAST, DAST, IAST, and SCA. Candidates should be able to distinguish what each one examines, when in the lifecycle it fits, and what kinds of findings it is likely to miss. Expect questions that ask you to choose the most appropriate technique for a described situation.

Pipeline and supply chain

Dependency security, secure CI/CD, and software supply chain security reflect how modern software is actually built. A great deal of any application is code someone else wrote, and the pipeline that assembles it is itself an attack surface. Questions here tend to probe your judgment about trust: which inputs to the build can be relied on, and which controls reduce the chance of a poisoned component reaching production.

Why AI-Generated Code Review Matters Here

One of the more distinctive supported topics is reviewing AI-generated code. Developers increasingly accept suggestions from coding assistants, and those suggestions can contain the same classes of flaw as human-written code: missing validation, unsafe handling of secrets, or reliance on questionable dependencies. The exam expects you to treat generated output as untrusted until reviewed, applying the same secure-coding standards you would to any contribution.

Practical framing: Do not memorize this as a separate skill. It is Domain 3 knowledge applied to a new source of code. If you can spot an injection risk or a hard-coded secret in a colleague's pull request, you can spot it in a generated snippet.

Registration, Prerequisites, and Cost Mechanics

Prerequisites

There are no formal registration prerequisites, no application fee, no supporting documentation requirement, and no eligibility verification step. Recommended background is foundational security knowledge plus experience in software development, design, testing, and deployment. No particular programming language is prescribed, which means the exam is testing concepts and judgment rather than syntax in one ecosystem. For the full eligibility picture, see CSSD requirements and how to qualify.

What you can actually price

An honest note on cost: the verified published figures are for courseware bundles, not for a separately confirmed exam-only fee. The student digital course bundles are listed at USD 514.50 without lab and USD 561.75 with lab. The course access key includes the CHOICE credential process, which is why the courseware pricing is the relevant number to plan around. Do not assume a standalone exam price that you have not seen published. We break this down further on our CSSD certification cost page.

OptionPublished priceWhat to note
Student digital course bundle, without labUSD 514.50Courseware bundle price, not an exam-only fee
Student digital course bundle, with labUSD 561.75Adds lab access; also a courseware bundle price

The listing for the without-lab bundle carries wording differences between its title and URL, so confirm the product details on the retailer page before purchasing. For scheduling specifics, our guide to CSSD exam dates and scheduling covers the delivery side.

Who Benefits and Where the Credential Fits

The natural audience is working developers: application developers, full-stack and back-end engineers, and anyone whose commits end up in production. It also suits people adjacent to development, such as testers, DevOps and pipeline engineers, and technical leads who review code and make architecture decisions. Security-minded engineers who want a developer-focused credential rather than a broad operations certification are a close match.

On the employment side, the credential is most relevant to organizations that build their own software and care about demonstrable secure-development skills, including teams that handle sensitive data or operate under compliance expectations. We avoid quoting hiring volumes or pay numbers here because no verified figures are available to us for this credential; our pages on CSSD jobs and the CSSD salary guide discuss the qualitative picture, and our ROI analysis helps you weigh the investment against your own goals.

A Domain-Weighted Study Sequence

Rather than generic advice, the sensible approach is to sequence your preparation by blueprint weight and by dependency between topics. Foundations come first because later domains assume them; the largest domain gets the most time; governance comes last because it ties the rest together.

Week 1

Foundations and lifecycle framing

  • CIA, AAA, and least privilege (Domain 1)
  • Where security activities sit in the lifecycle (Domain 2)
  • Threat modeling and abuse cases
Weeks 2-3

Secure code, the 33% domain

  • Input validation and output encoding
  • Authentication, authorization, and secrets management
  • Reviewing AI-generated code with the same standards
Week 4

Defense, tooling, and governance

  • SAST, DAST, IAST, and SCA: what each finds and misses
  • Dependency, CI/CD, and supply chain security (Domain 4)
  • Governance, risk, and compliance (Domain 5)

Finish with timed practice on multiple-response items, since those are where partial understanding costs the most. Our CSSD study guide expands this into a fuller plan, the one-page cheat sheet is useful for last-day review, and our guide to CSSD training options compares ways to cover the material. For realistic question practice, use the CSSD Exam Prep practice tests.

Validity and Renewal

CertNexus's general maintenance policy states that certifications are valid for three years and can be renewed by passing the current exam, with continuing education available to eligible holders. That is the general policy. The published page does not establish CSSD-specific continuing-education eligibility or requirements, so confirm the specifics for your own credential directly with CertNexus rather than assuming rules from any other program.

Frequently Asked Questions

What does CSSD stand for?

On this site, CSSD stands for Cyber Secure Software Developer, a CertNexus credential assessed through the CSD-110 exam. It focuses on secure software development practices rather than general network or infrastructure security.

How many questions are on the exam and what score do I need?

The exam has 25 multiple-choice and multiple-response questions. The passing score is 80%, which means 20 of 25 correct. Estimated completion time is 30 to 60 minutes, though that is an estimate rather than a confirmed fixed timer.

Which domain is weighted most heavily?

Develop Secure Code is the largest at 33%. The secure software development lifecycle follows at 22%, and the remaining three domains each carry 15%. Prioritize accordingly, as covered in our difficulty guide.

Are there prerequisites to sit for it?

There are no formal registration prerequisites, application fee, documentation, or eligibility verification. Foundational security knowledge and hands-on development, design, testing, and deployment experience are recommended, and no specific programming language is required.

What happens if I do not pass the first time?

One complimentary retake is included. Because we cannot point to a verified published pass rate, see our pass rate discussion for what can and cannot be said responsibly, and use your first attempt's weak areas to guide a targeted review.

Ready to pass your CSSD exam?

Put this into practice with free CSSD questions across every exam domain.