CSSD logo
Focused certification exam prep
Start practice

What Is CSSD?

TL;DR
  • CSSD means Cyber Secure Software Developer, a CertNexus credential assessed through the CSD-110 exam launched May 11, 2026.
  • The exam has 25 multiple-choice and multiple-response questions, and the passing score is 80% (20 of 25).
  • Develop Secure Code carries 33% of the blueprint, making it the single most important domain.
  • There are no formal prerequisites, and one complimentary retake is included.

What CSSD Means Here

CSSD stands for Cyber Secure Software Developer. It is a vendor-issued certification aimed at people who write, review, test, and ship software and want to show they can do so with security built in rather than bolted on afterward. If you landed on this page after searching for the acronym, note that several unrelated credentials and job titles in other industries abbreviate to the same four letters. This article covers only the software-security credential from CertNexus.

If you want a quick terminology refresher, our short explainers on what CSSD stands for and the meaning of CSSD cover the naming question in a sentence or two. The rest of this guide goes deeper into what the certification actually tests and who it serves.

Who Issues It and Which Exam Is Current

The credential is issued by CertNexus. The current exam is CSD-110, which launched on May 11, 2026. Courseware for CSD-110 is identified by its publisher as replacing the earlier Cyber Secure Coder CSC-210 courseware. Treat those as separate exams with separate blueprints. If you find older study material built around CSC-210, do not assume it maps cleanly onto the current objectives.

A Note on Exam Codes: You may occasionally see a product description that refers to a different exam number. The issuer's own title and blueprint identify the current exam as CSD-110, so anchor your preparation to that code and to the CertNexus blueprint rather than to third-party listings.

Exam Format and Delivery

The CSD-110 assessment is compact compared with many security certifications. Here is the format at a glance:

AttributeCSD-110 Detail
IssuerCertNexus
DeliveryOnline through CHOICE
Questions25 multiple-choice and multiple-response
Passing score80% (20 of 25)
Estimated completion time30 to 60 minutes (an estimate, not a verified fixed exam timer)
Retake policyOne complimentary retake

Two details deserve attention. First, the 80% threshold means you can miss only five questions, so there is little room to guess on a whole domain. Second, multiple-response items require you to select every correct option, which punishes half-knowledge. A candidate who understands why a control works will do better than one who has memorized a list of control names. For a closer look at how the cut score plays out, see our breakdown of the CSSD passing score.

The Five Exam Domains

The official CSD-110 blueprint (version 1.12) divides the exam into five weighted domains. Weighting matters because it tells you where the questions concentrate.

Domain 1: Understand the Fundamentals of Secure Software Development (15%)

The conceptual foundation. Expect questions on the principles that underpin every later domain.

  • Confidentiality, integrity, and availability (CIA)
  • Authentication, authorization, and accounting (AAA)
  • Least privilege and related design principles

Domain 2: Explain the Secure Software Development Lifecycle (22%)

The second-heaviest domain. It asks how security activities fit into each phase of building software.

  • Threat modeling and abuse cases during requirements and design
  • Security testing and review integrated into development, testing, and deployment
  • How lifecycle practices reduce defects before release

Domain 3: Develop Secure Code (33%)

The largest domain, and the one most directly tied to day-to-day developer work.

  • Input validation and output encoding
  • Authentication and authorization implementation
  • Secrets management
  • Reviewing AI-generated code for security flaws

Domain 4: Defending Against Cyberattacks (15%)

Connects coding decisions to the attacks they are meant to resist, including security testing and supply chain exposure.

  • SAST, DAST, IAST, and SCA testing approaches
  • Dependency security
  • Software supply chain security

Domain 5: Engage in Governance, Risk Management, and Compliance (15%)

The organizational layer: policy, risk, and how development teams operate within governance expectations.

  • Governance and risk management concepts applied to software
  • Compliance considerations for development teams
  • Secure CI/CD as a controlled delivery pipeline

Because domain placement of individual topics can shift between blueprint revisions, read the official document directly and use our complete guide to all five CSSD content areas for a plain-language walkthrough of each one.

Concrete Topics You Must Master

The blueprint lists supported topics, and CertNexus notes that its detailed examples are not an exhaustive list of everything that may be tested. Treat the list below as a floor, not a ceiling.

Design-Time Thinking

Threat modeling and abuse cases flip the usual requirements mindset. Instead of asking what a user should be able to do, you ask what an attacker could try to do with the same feature. Be ready to recognize which artifact or activity belongs in which lifecycle phase.

Code-Level Defenses

Input validation and output encoding are paired defenses against injection-style flaws, but they operate at different points: one constrains what enters your system, the other controls how data is rendered or interpreted on the way out. Exam questions often test whether you can pick the right control for a described scenario. Add authentication, authorization, and secrets management to the same bucket, and make sure you can distinguish proving identity from deciding permissions, and storing credentials safely from simply hiding them.

Automated Security Testing

The four testing acronyms are easy to confuse under time pressure:

  • SAST analyzes source or compiled code without running it.
  • DAST probes a running application from the outside.
  • IAST instruments the application while it runs to observe behavior from the inside.
  • SCA inventories third-party components and flags known-vulnerable dependencies.

Pipeline and Supply Chain

Secure CI/CD, dependency security, and software supply chain security reflect how modern software actually gets built: from many external components, assembled and deployed by automated pipelines. Know what can go wrong at each stage and which control addresses it.

AI-Generated Code Review

One notable feature of the blueprint is its attention to reviewing AI-generated code. The skill being tested is not how to prompt a code assistant, but how to treat its output as untrusted until reviewed, applying the same secure-coding expectations you would apply to any contributed code.

Key Takeaway

Because Domain 3 (33%) and Domain 2 (22%) together account for more than half the blueprint, a candidate who is fluent in secure coding practices and lifecycle activities is already positioned for the majority of the questions. Build depth there first, then fill in the other three domains.

Cost, Access Keys, and Retakes

CertNexus describes the registration process as straightforward: there is no formal application fee, no supporting documentation requirement, and no eligibility verification step. The course access key includes the CHOICE credential process, which is how candidates take the assessment online.

On pricing, the figures publicly listed are for digital course bundles, not for the exam alone:

BundleListed PriceSKU
Digital course bundle without labUSD 514.50CNX0022SEBU2
Digital course bundle with labUSD 561.75CNX0022SEBU
Read Pricing Carefully: These are courseware-bundle prices, and they have not been verified as exam-only fees. One listing is titled as a student bundle even though its web address uses different wording. Because prices change, confirm the current figure with the seller before budgeting. Our CSSD certification cost breakdown explains how to think about the total outlay.

The included complimentary retake is worth noting. It lowers the financial risk of a first attempt, though with an 80% cut score you should still aim to pass the first time.

Prerequisites and Who Should Sit the Exam

There are no formal registration prerequisites. Anyone can enroll. That said, CertNexus recommends foundational security knowledge along with practical experience in software development, design, testing, and deployment. No particular programming language is prescribed, so the exam is built around concepts and practices rather than syntax in one language.

In practice, the credential suits several groups:

  • Application developers who want a recognized signal that they write defensively.
  • QA and test engineers expanding into security testing.
  • DevOps and platform engineers responsible for CI/CD pipelines and dependency hygiene.
  • Team leads who need shared vocabulary for threat modeling, risk, and compliance conversations.

For a fuller discussion of readiness, our guide to CSSD requirements and eligibility goes into more detail.

Validity and Renewal

CertNexus's general maintenance policy states that certifications are valid for three years, with renewal accomplished by passing the current exam. Continuing education is available to eligible holders under the CertNexus program. However, the policy page does not establish CSSD-specific continuing-education eligibility or requirements, so confirm the details with CertNexus before planning around them. Do not assume the maintenance rules of any other credential apply here.

Where the Credential Fits in a Career

Organizations that build their own software, maintain internal platforms, or deliver custom applications to clients have a recurring need for developers who can reason about security without being full-time security specialists. That is the niche this credential addresses. It is less a gateway into a dedicated penetration-testing role and more a way to demonstrate that your everyday engineering work reflects secure-by-design habits.

Roles where the knowledge applies include software developer, application engineer, DevSecOps-oriented engineer, and development lead. Because compensation depends heavily on region, seniority, and employer, we avoid quoting figures here. If you want to explore the market side, see CSSD jobs and the CSSD salary guide, and weigh them against the ROI analysis of the CSSD certification.

Sequencing Your Study by Domain

The only study advice worth repeating here is ordering. Start with the fundamentals so later vocabulary lands, spend the most hours where the weight is, and finish with timed practice. A four-week arrangement that mirrors the blueprint weights looks like this:

Week 1

Foundations and Lifecycle

  • Domain 1: CIA, AAA, least privilege
  • Domain 2: threat modeling, abuse cases, where security fits in each phase
Week 2

Secure Coding Depth

  • Domain 3: input validation, output encoding, authentication, authorization
  • Secrets management and reviewing AI-generated code
Week 3

Defense and Governance

  • Domain 4: SAST, DAST, IAST, SCA, dependency and supply chain security
  • Domain 5: governance, risk management, compliance, secure CI/CD
Week 4

Practice and Gap Repair

  • Take timed 25-question sets against the 80% bar
  • Revisit missed multiple-response items, especially in Domains 2 and 3

For a fuller plan, use the CSSD study guide, keep the one-page CSSD cheat sheet handy for last-minute review, and run realistic drills on our CSSD practice test platform. If you are wondering how demanding the assessment is, read how hard the CSSD exam is before you commit to a timeline.

Frequently Asked Questions

What does CSSD stand for in this context?

It stands for Cyber Secure Software Developer, a CertNexus certification assessed through the CSD-110 exam. It is unrelated to other credentials or job titles that share the same acronym.

How many questions are on the exam and what score do I need?

The assessment has 25 multiple-choice and multiple-response questions. You need 80%, which means at least 20 correct answers. The estimated completion time is 30 to 60 minutes, though that is an estimate rather than a verified fixed timer.

Are there prerequisites to take the exam?

There are no formal registration prerequisites, application fees, or eligibility checks. CertNexus recommends foundational security knowledge and experience across software development, design, testing, and deployment, with no specific programming language required.

Which domain should I prioritize?

Develop Secure Code is the largest at 33%, followed by the secure software development lifecycle at 22%. Together they make up over half of the blueprint, so they deserve the most study time.

How long does the certification last?

CertNexus's general policy states three-year validity, with renewal by passing the current exam. Continuing education may be available to eligible holders, but CSSD-specific requirements are not established on the policy page, so confirm with CertNexus.

Ready to pass your CSSD exam?

Put this into practice with free CSSD questions across every exam domain.