- What CSSD Means Here
- Who Issues It and Which Exam Is Current
- Exam Format and Delivery
- The Five Exam Domains
- Concrete Topics You Must Master
- Cost, Access Keys, and Retakes
- Prerequisites and Who Should Sit the Exam
- Validity and Renewal
- Where the Credential Fits in a Career
- Sequencing Your Study by Domain
- Frequently Asked Questions
- CSSD means Cyber Secure Software Developer, a CertNexus credential assessed through the CSD-110 exam launched May 11, 2026.
- The exam has 25 multiple-choice and multiple-response questions, and the passing score is 80% (20 of 25).
- Develop Secure Code carries 33% of the blueprint, making it the single most important domain.
- There are no formal prerequisites, and one complimentary retake is included.
What CSSD Means Here
CSSD stands for Cyber Secure Software Developer. It is a vendor-issued certification aimed at people who write, review, test, and ship software and want to show they can do so with security built in rather than bolted on afterward. If you landed on this page after searching for the acronym, note that several unrelated credentials and job titles in other industries abbreviate to the same four letters. This article covers only the software-security credential from CertNexus.
If you want a quick terminology refresher, our short explainers on what CSSD stands for and the meaning of CSSD cover the naming question in a sentence or two. The rest of this guide goes deeper into what the certification actually tests and who it serves.
Who Issues It and Which Exam Is Current
The credential is issued by CertNexus. The current exam is CSD-110, which launched on May 11, 2026. Courseware for CSD-110 is identified by its publisher as replacing the earlier Cyber Secure Coder CSC-210 courseware. Treat those as separate exams with separate blueprints. If you find older study material built around CSC-210, do not assume it maps cleanly onto the current objectives.
Exam Format and Delivery
The CSD-110 assessment is compact compared with many security certifications. Here is the format at a glance:
| Attribute | CSD-110 Detail |
|---|---|
| Issuer | CertNexus |
| Delivery | Online through CHOICE |
| Questions | 25 multiple-choice and multiple-response |
| Passing score | 80% (20 of 25) |
| Estimated completion time | 30 to 60 minutes (an estimate, not a verified fixed exam timer) |
| Retake policy | One complimentary retake |
Two details deserve attention. First, the 80% threshold means you can miss only five questions, so there is little room to guess on a whole domain. Second, multiple-response items require you to select every correct option, which punishes half-knowledge. A candidate who understands why a control works will do better than one who has memorized a list of control names. For a closer look at how the cut score plays out, see our breakdown of the CSSD passing score.
The Five Exam Domains
The official CSD-110 blueprint (version 1.12) divides the exam into five weighted domains. Weighting matters because it tells you where the questions concentrate.
Domain 1: Understand the Fundamentals of Secure Software Development (15%)
The conceptual foundation. Expect questions on the principles that underpin every later domain.
- Confidentiality, integrity, and availability (CIA)
- Authentication, authorization, and accounting (AAA)
- Least privilege and related design principles
Domain 2: Explain the Secure Software Development Lifecycle (22%)
The second-heaviest domain. It asks how security activities fit into each phase of building software.
- Threat modeling and abuse cases during requirements and design
- Security testing and review integrated into development, testing, and deployment
- How lifecycle practices reduce defects before release
Domain 3: Develop Secure Code (33%)
The largest domain, and the one most directly tied to day-to-day developer work.
- Input validation and output encoding
- Authentication and authorization implementation
- Secrets management
- Reviewing AI-generated code for security flaws
Domain 4: Defending Against Cyberattacks (15%)
Connects coding decisions to the attacks they are meant to resist, including security testing and supply chain exposure.
- SAST, DAST, IAST, and SCA testing approaches
- Dependency security
- Software supply chain security
Domain 5: Engage in Governance, Risk Management, and Compliance (15%)
The organizational layer: policy, risk, and how development teams operate within governance expectations.
- Governance and risk management concepts applied to software
- Compliance considerations for development teams
- Secure CI/CD as a controlled delivery pipeline
Because domain placement of individual topics can shift between blueprint revisions, read the official document directly and use our complete guide to all five CSSD content areas for a plain-language walkthrough of each one.
Concrete Topics You Must Master
The blueprint lists supported topics, and CertNexus notes that its detailed examples are not an exhaustive list of everything that may be tested. Treat the list below as a floor, not a ceiling.
Design-Time Thinking
Threat modeling and abuse cases flip the usual requirements mindset. Instead of asking what a user should be able to do, you ask what an attacker could try to do with the same feature. Be ready to recognize which artifact or activity belongs in which lifecycle phase.
Code-Level Defenses
Input validation and output encoding are paired defenses against injection-style flaws, but they operate at different points: one constrains what enters your system, the other controls how data is rendered or interpreted on the way out. Exam questions often test whether you can pick the right control for a described scenario. Add authentication, authorization, and secrets management to the same bucket, and make sure you can distinguish proving identity from deciding permissions, and storing credentials safely from simply hiding them.
Automated Security Testing
The four testing acronyms are easy to confuse under time pressure:
- SAST analyzes source or compiled code without running it.
- DAST probes a running application from the outside.
- IAST instruments the application while it runs to observe behavior from the inside.
- SCA inventories third-party components and flags known-vulnerable dependencies.
Pipeline and Supply Chain
Secure CI/CD, dependency security, and software supply chain security reflect how modern software actually gets built: from many external components, assembled and deployed by automated pipelines. Know what can go wrong at each stage and which control addresses it.
AI-Generated Code Review
One notable feature of the blueprint is its attention to reviewing AI-generated code. The skill being tested is not how to prompt a code assistant, but how to treat its output as untrusted until reviewed, applying the same secure-coding expectations you would apply to any contributed code.
Key Takeaway
Because Domain 3 (33%) and Domain 2 (22%) together account for more than half the blueprint, a candidate who is fluent in secure coding practices and lifecycle activities is already positioned for the majority of the questions. Build depth there first, then fill in the other three domains.
Cost, Access Keys, and Retakes
CertNexus describes the registration process as straightforward: there is no formal application fee, no supporting documentation requirement, and no eligibility verification step. The course access key includes the CHOICE credential process, which is how candidates take the assessment online.
On pricing, the figures publicly listed are for digital course bundles, not for the exam alone:
| Bundle | Listed Price | SKU |
|---|---|---|
| Digital course bundle without lab | USD 514.50 | CNX0022SEBU2 |
| Digital course bundle with lab | USD 561.75 | CNX0022SEBU |
The included complimentary retake is worth noting. It lowers the financial risk of a first attempt, though with an 80% cut score you should still aim to pass the first time.
Prerequisites and Who Should Sit the Exam
There are no formal registration prerequisites. Anyone can enroll. That said, CertNexus recommends foundational security knowledge along with practical experience in software development, design, testing, and deployment. No particular programming language is prescribed, so the exam is built around concepts and practices rather than syntax in one language.
In practice, the credential suits several groups:
- Application developers who want a recognized signal that they write defensively.
- QA and test engineers expanding into security testing.
- DevOps and platform engineers responsible for CI/CD pipelines and dependency hygiene.
- Team leads who need shared vocabulary for threat modeling, risk, and compliance conversations.
For a fuller discussion of readiness, our guide to CSSD requirements and eligibility goes into more detail.
Validity and Renewal
CertNexus's general maintenance policy states that certifications are valid for three years, with renewal accomplished by passing the current exam. Continuing education is available to eligible holders under the CertNexus program. However, the policy page does not establish CSSD-specific continuing-education eligibility or requirements, so confirm the details with CertNexus before planning around them. Do not assume the maintenance rules of any other credential apply here.
Where the Credential Fits in a Career
Organizations that build their own software, maintain internal platforms, or deliver custom applications to clients have a recurring need for developers who can reason about security without being full-time security specialists. That is the niche this credential addresses. It is less a gateway into a dedicated penetration-testing role and more a way to demonstrate that your everyday engineering work reflects secure-by-design habits.
Roles where the knowledge applies include software developer, application engineer, DevSecOps-oriented engineer, and development lead. Because compensation depends heavily on region, seniority, and employer, we avoid quoting figures here. If you want to explore the market side, see CSSD jobs and the CSSD salary guide, and weigh them against the ROI analysis of the CSSD certification.
Sequencing Your Study by Domain
The only study advice worth repeating here is ordering. Start with the fundamentals so later vocabulary lands, spend the most hours where the weight is, and finish with timed practice. A four-week arrangement that mirrors the blueprint weights looks like this:
Foundations and Lifecycle
- Domain 1: CIA, AAA, least privilege
- Domain 2: threat modeling, abuse cases, where security fits in each phase
Secure Coding Depth
- Domain 3: input validation, output encoding, authentication, authorization
- Secrets management and reviewing AI-generated code
Defense and Governance
- Domain 4: SAST, DAST, IAST, SCA, dependency and supply chain security
- Domain 5: governance, risk management, compliance, secure CI/CD
Practice and Gap Repair
- Take timed 25-question sets against the 80% bar
- Revisit missed multiple-response items, especially in Domains 2 and 3
For a fuller plan, use the CSSD study guide, keep the one-page CSSD cheat sheet handy for last-minute review, and run realistic drills on our CSSD practice test platform. If you are wondering how demanding the assessment is, read how hard the CSSD exam is before you commit to a timeline.
Frequently Asked Questions
It stands for Cyber Secure Software Developer, a CertNexus certification assessed through the CSD-110 exam. It is unrelated to other credentials or job titles that share the same acronym.
The assessment has 25 multiple-choice and multiple-response questions. You need 80%, which means at least 20 correct answers. The estimated completion time is 30 to 60 minutes, though that is an estimate rather than a verified fixed timer.
There are no formal registration prerequisites, application fees, or eligibility checks. CertNexus recommends foundational security knowledge and experience across software development, design, testing, and deployment, with no specific programming language required.
Develop Secure Code is the largest at 33%, followed by the secure software development lifecycle at 22%. Together they make up over half of the blueprint, so they deserve the most study time.
CertNexus's general policy states three-year validity, with renewal by passing the current exam. Continuing education may be available to eligible holders, but CSSD-specific requirements are not established on the policy page, so confirm with CertNexus.